mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 23:16:37 +08:00
[优化] 添加自定义状态码匹配方法
This commit is contained in:
@@ -57,6 +57,13 @@ Host 是否为“通过 IP 访问”按请求日志中的 `Host` 字段判断:
|
|||||||
|
|
||||||
比例字段都是 `0` 到 `1` 之间的小数。80% 应写成 `0.8`,50% 应写成 `0.5`。
|
比例字段都是 `0` 到 `1` 之间的小数。80% 应写成 `0.8`,50% 应写成 `0.5`。
|
||||||
|
|
||||||
|
### 自定义状态码匹配方法
|
||||||
|
|
||||||
|
如果内置的 `status_404_count` 和 `status_404_ratio` 不能满足您的需求,您可以使用以下内置方法来匹配任意状态码的请求数与占比:
|
||||||
|
|
||||||
|
* **`StatusCount(code)`**: 获取当前 IP 在回看窗口内返回指定状态码的请求数(如 `StatusCount(403) > 10`)
|
||||||
|
* **`StatusRatio(code)`**: 获取当前 IP 在回看窗口内返回指定状态码的请求数占该 IP 总请求数的比例(如 `StatusRatio(502) >= 0.5`)
|
||||||
|
|
||||||
## Expr 常用写法
|
## Expr 常用写法
|
||||||
|
|
||||||
自动 IP 组使用 Expr 语法,当前表达式必须返回布尔值。
|
自动 IP 组使用 Expr 语法,当前表达式必须返回布尔值。
|
||||||
|
|||||||
@@ -69,6 +69,21 @@ type wafIPGroupAutoRuleEnv struct {
|
|||||||
ClientErrorCount int `expr:"client_error_count"`
|
ClientErrorCount int `expr:"client_error_count"`
|
||||||
ServerErrorCount int `expr:"server_error_count"`
|
ServerErrorCount int `expr:"server_error_count"`
|
||||||
LastSeenUnix int64 `expr:"last_seen_unix"`
|
LastSeenUnix int64 `expr:"last_seen_unix"`
|
||||||
|
statusCounts map[int]int
|
||||||
|
}
|
||||||
|
|
||||||
|
func (env wafIPGroupAutoRuleEnv) StatusCount(code int) int {
|
||||||
|
if env.statusCounts == nil {
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
return env.statusCounts[code]
|
||||||
|
}
|
||||||
|
|
||||||
|
func (env wafIPGroupAutoRuleEnv) StatusRatio(code int) float64 {
|
||||||
|
if env.RequestCount <= 0 || env.statusCounts == nil {
|
||||||
|
return 0.0
|
||||||
|
}
|
||||||
|
return float64(env.statusCounts[code]) / float64(env.RequestCount)
|
||||||
}
|
}
|
||||||
|
|
||||||
type wafIPGroupAutoAccumulator struct {
|
type wafIPGroupAutoAccumulator struct {
|
||||||
@@ -79,6 +94,7 @@ type wafIPGroupAutoAccumulator struct {
|
|||||||
clientErrorCount int
|
clientErrorCount int
|
||||||
serverErrorCount int
|
serverErrorCount int
|
||||||
lastSeen time.Time
|
lastSeen time.Time
|
||||||
|
statusCounts map[int]int
|
||||||
}
|
}
|
||||||
|
|
||||||
type WAFIPGroupInput struct {
|
type WAFIPGroupInput struct {
|
||||||
@@ -755,10 +771,14 @@ func evaluateParsedWAFIPGroupAutoConfig(config wafIPGroupAutoConfig, now time.Ti
|
|||||||
}
|
}
|
||||||
acc := accumulators[ip]
|
acc := accumulators[ip]
|
||||||
if acc == nil {
|
if acc == nil {
|
||||||
acc = &wafIPGroupAutoAccumulator{ip: ip}
|
acc = &wafIPGroupAutoAccumulator{
|
||||||
|
ip: ip,
|
||||||
|
statusCounts: make(map[int]int),
|
||||||
|
}
|
||||||
accumulators[ip] = acc
|
accumulators[ip] = acc
|
||||||
}
|
}
|
||||||
acc.requestCount++
|
acc.requestCount++
|
||||||
|
acc.statusCounts[item.StatusCode]++
|
||||||
if item.StatusCode == http.StatusNotFound {
|
if item.StatusCode == http.StatusNotFound {
|
||||||
acc.status404Count++
|
acc.status404Count++
|
||||||
}
|
}
|
||||||
@@ -800,6 +820,7 @@ func (acc *wafIPGroupAutoAccumulator) toExprEnv() wafIPGroupAutoRuleEnv {
|
|||||||
IPHostCount: acc.ipHostCount,
|
IPHostCount: acc.ipHostCount,
|
||||||
ClientErrorCount: acc.clientErrorCount,
|
ClientErrorCount: acc.clientErrorCount,
|
||||||
ServerErrorCount: acc.serverErrorCount,
|
ServerErrorCount: acc.serverErrorCount,
|
||||||
|
statusCounts: acc.statusCounts,
|
||||||
}
|
}
|
||||||
if acc.requestCount > 0 {
|
if acc.requestCount > 0 {
|
||||||
env.Status404Ratio = float64(acc.status404Count) / float64(acc.requestCount)
|
env.Status404Ratio = float64(acc.status404Count) / float64(acc.requestCount)
|
||||||
|
|||||||
@@ -464,3 +464,50 @@ func seedWAFNodeAccessLogs(t *testing.T, loggedAt time.Time, remoteAddr string,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestSyncWAFIPGroupAutomaticCustomStatusRules(t *testing.T) {
|
||||||
|
setupServiceTestDB(t)
|
||||||
|
|
||||||
|
now := time.Now().UTC()
|
||||||
|
// Seed 10 requests from 203.0.113.50, where 3 return 403, 7 return 200
|
||||||
|
seedWAFNodeAccessLogsWithStatus(t, now, "203.0.113.50", "app.example.com", 7, http.StatusOK)
|
||||||
|
seedWAFNodeAccessLogsWithStatus(t, now, "203.0.113.50", "app.example.com", 3, http.StatusForbidden)
|
||||||
|
|
||||||
|
group, err := CreateWAFIPGroup(WAFIPGroupInput{
|
||||||
|
Name: "custom status code blacklist",
|
||||||
|
Type: WAFIPGroupTypeAutomatic,
|
||||||
|
Enabled: true,
|
||||||
|
AutoConfig: json.RawMessage(`{
|
||||||
|
"lookback_minutes": 60,
|
||||||
|
"rules": [
|
||||||
|
{"name":"高频 403 探测","expr":"StatusCount(403) >= 3 && StatusRatio(403) >= 0.3"}
|
||||||
|
]
|
||||||
|
}`),
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("CreateWAFIPGroup failed: %v", err)
|
||||||
|
}
|
||||||
|
result, err := SyncWAFIPGroup(group.ID)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("SyncWAFIPGroup failed: %v", err)
|
||||||
|
}
|
||||||
|
if result.IPCount != 1 || result.Group.IPList[0] != "203.0.113.50" {
|
||||||
|
t.Fatalf("expected 203.0.113.50 to be matched, got %#v", result)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func seedWAFNodeAccessLogsWithStatus(t *testing.T, loggedAt time.Time, remoteAddr string, host string, count int, statusCode int) {
|
||||||
|
t.Helper()
|
||||||
|
for i := 0; i < count; i++ {
|
||||||
|
if err := model.DB.Create(&model.NodeAccessLog{
|
||||||
|
NodeID: "node-waf-auto",
|
||||||
|
LoggedAt: loggedAt.Add(-time.Duration(i%30) * time.Second),
|
||||||
|
RemoteAddr: remoteAddr,
|
||||||
|
Host: host,
|
||||||
|
Path: "/probe",
|
||||||
|
StatusCode: statusCode,
|
||||||
|
}).Error; err != nil {
|
||||||
|
t.Fatalf("failed to seed access log: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -587,7 +587,7 @@ export function WAFIPGroupsPage() {
|
|||||||
</ResourceField>
|
</ResourceField>
|
||||||
<ResourceField
|
<ResourceField
|
||||||
label="自动配置 JSON"
|
label="自动配置 JSON"
|
||||||
hint="可用字段:request_count、status_404_count、status_404_ratio、ip_host_count、ip_host_ratio。支持 ttl(秒,默认 -1 永久拉黑)。"
|
hint="可用字段:request_count、status_404_count、status_404_ratio、ip_host_count、ip_host_ratio。方法:StatusCount(code)、StatusRatio(code)。支持 ttl(秒,默认 -1 永久拉黑)。"
|
||||||
>
|
>
|
||||||
<ResourceTextarea
|
<ResourceTextarea
|
||||||
value={draft.auto_config_text}
|
value={draft.auto_config_text}
|
||||||
|
|||||||
Reference in New Issue
Block a user