fix: 收敛子代理站点标识双轨逻辑

This commit is contained in:
ryan
2026-06-20 21:03:03 +08:00
parent 9bf7e3cd1b
commit 889e79c8b8
17 changed files with 215 additions and 199 deletions
+2
View File
@@ -749,6 +749,8 @@ func (m *Manager) writeCertFiles(certFiles []protocol.SupportFile) error {
return m.writeManagedCertFiles(certFiles)
}
// writePowConfig persists legacy pow_config.json for backward compatibility.
// PoW runtime loads site config from waf_config.json; pow_config.json is deprecated.
func (m *Manager) writePowConfig(supportFiles []protocol.SupportFile) error {
if m.RuntimeConfigDir == "" {
return nil
+12 -2
View File
@@ -117,7 +117,7 @@ end
local site = ngx.var.openflare_waf_site or ""
if site == "" then
site = host
return
end
local config_raw = pow_config_dict:get(site)
@@ -230,7 +230,9 @@ local redir = args["redir"] or ""
local site = ngx.var.openflare_waf_site or ""
if site == "" then
site = host
ngx.status = 403
ngx.say("PoW site not resolved; openflare_waf_site is required")
return
end
local config_raw = pow_config_dict:get(site)
@@ -348,6 +350,14 @@ const openRestyPowVerifyLua = `local cjson = require "cjson.safe"
local pow_challenges = ngx.shared.openflare_pow_challenges
local pow_sessions = ngx.shared.openflare_pow_sessions
local site = ngx.var.openflare_waf_site or ""
if site == "" then
ngx.status = 403
ngx.header.content_type = "application/json"
ngx.say(cjson.encode({error = "PoW site not resolved; openflare_waf_site is required"}))
return
end
local args = ngx.req.get_uri_args()
local challenge_id = args["id"] or ""
local response = args["response"] or ""