feat(waf): complete composable rule orchestration

Add the React Flow rule editor, ordered graph APIs and runtime DAG execution.\n\nPublish rules only on OpenResty reload and reconcile checksum-driven IP group snapshots in bounded shared memory.
This commit is contained in:
ryan
2026-07-13 14:16:55 +08:00
parent d36409fbf9
commit a1a997bcda
72 changed files with 5897 additions and 3080 deletions
+157 -205
View File
@@ -3641,6 +3641,11 @@ definitions:
website:
type: string
type: object
waf.CreateRuleInput:
properties:
name:
type: string
type: object
waf.IDsRequest:
properties:
ids:
@@ -3762,94 +3767,69 @@ definitions:
updated_at:
type: string
type: object
waf.PoWConfig:
waf.RuleEdge:
properties:
algorithm:
id:
type: string
blacklist:
$ref: '#/definitions/waf.PoWListConfig'
challenge_ttl:
type: integer
difficulty:
type: integer
session_ttl:
type: integer
whitelist:
$ref: '#/definitions/waf.PoWListConfig'
type: object
waf.PoWListConfig:
properties:
ip_cidrs:
items:
type: string
type: array
ips:
items:
type: string
type: array
path_regexes:
items:
type: string
type: array
paths:
items:
type: string
type: array
user_agents:
items:
type: string
type: array
type: object
waf.RuleGroupInput:
properties:
block_response_body:
source:
type: string
block_status_code:
source_handle:
type: string
target:
type: string
type: object
waf.RuleGraph:
properties:
edges:
items:
$ref: '#/definitions/waf.RuleEdge'
type: array
nodes:
items:
$ref: '#/definitions/waf.RuleNode'
type: array
schema_version:
type: integer
country_blacklist:
items:
type: string
type: array
country_whitelist:
items:
type: string
type: array
enabled:
type: boolean
ip_blacklist:
items:
type: string
type: array
ip_blacklist_group_ids:
type: object
waf.RuleNode:
properties:
config:
items:
type: integer
type: array
ip_whitelist:
items:
type: string
type: array
ip_whitelist_group_ids:
items:
type: integer
type: array
name:
id:
type: string
pow_config:
items:
type: integer
type: array
pow_enabled:
type: boolean
region_blacklist:
items:
type: string
type: array
region_whitelist:
items:
type: string
type: array
label:
type: string
position:
$ref: '#/definitions/waf.RulePosition'
type:
$ref: '#/definitions/waf.RuleNodeType'
type: object
waf.RuleGroupView:
waf.RuleNodeType:
enum:
- start
- allow
- block
- ip_match
- geo_match
- pow
type: string
x-enum-varnames:
- RuleNodeStart
- RuleNodeAllow
- RuleNodeBlock
- RuleNodeIPMatch
- RuleNodeGeoMatch
- RuleNodePoW
waf.RulePosition:
properties:
x:
type: number
"y":
type: number
type: object
waf.RuleView:
properties:
applied_site_count:
type: integer
@@ -3857,59 +3837,30 @@ definitions:
items:
type: integer
type: array
block_response_body:
type: string
block_status_code:
type: integer
country_blacklist:
items:
type: string
type: array
country_whitelist:
items:
type: string
type: array
created_at:
type: string
enabled:
type: boolean
graph:
$ref: '#/definitions/waf.RuleGraph'
id:
type: integer
ip_blacklist:
items:
type: string
type: array
ip_blacklist_group_ids:
items:
type: integer
type: array
ip_whitelist:
items:
type: string
type: array
ip_whitelist_group_ids:
items:
type: integer
type: array
is_global:
type: boolean
name:
type: string
pow_config:
$ref: '#/definitions/waf.PoWConfig'
pow_enabled:
type: boolean
region_blacklist:
items:
type: string
type: array
region_whitelist:
items:
type: string
type: array
revision:
type: integer
updated_at:
type: string
type: object
waf.SaveRuleGraphInput:
properties:
graph:
$ref: '#/definitions/waf.RuleGraph'
revision:
type: integer
type: object
waf.SiteRuleGroupsView:
properties:
applied_ids:
@@ -3918,17 +3869,24 @@ definitions:
type: array
applied_rule_groups:
items:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
type: array
global_rule_group:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
route_id:
type: integer
rule_groups:
items:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
type: array
type: object
waf.UpdateRuleMetaInput:
properties:
enabled:
type: boolean
name:
type: string
type: object
zone.DomainInput:
properties:
cert_id:
@@ -10168,25 +10126,20 @@ paths:
- openflare-waf
/api/v1/d/waf/rule-groups:
get:
description: 返回全部 WAF 规则组,需要管理员权限
produces:
- application/json
responses:
"200":
description: 规则组列表
description: 规则列表
schema:
allOf:
- $ref: '#/definitions/response.Any'
- properties:
data:
items:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
type: array
type: object
"400":
description: 参数错误
schema:
$ref: '#/definitions/response.Any'
"401":
description: 未登录
schema:
@@ -10201,31 +10154,30 @@ paths:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 列出 WAF 规则组
summary: 列出 WAF 规则
tags:
- openflare-waf
post:
consumes:
- application/json
description: 创建新的 WAF 规则组,需要管理员权限
parameters:
- description: 规则组参数
- description: 规则名称
in: body
name: request
required: true
schema:
$ref: '#/definitions/waf.RuleGroupInput'
$ref: '#/definitions/waf.CreateRuleInput'
produces:
- application/json
responses:
"200":
description: 创建成功的规则组
description: 创建成功
schema:
allOf:
- $ref: '#/definitions/response.Any'
- properties:
data:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
type: object
"400":
description: 参数错误
@@ -10245,14 +10197,13 @@ paths:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 创建 WAF 规则组
summary: 创建 WAF 规则
tags:
- openflare-waf
/api/v1/d/waf/rule-groups/{id}:
get:
description: 按 ID 返回 WAF 规则组详情,需要管理员权限
parameters:
- description: 规则组 ID
- description: 规则 ID
in: path
name: id
required: true
@@ -10261,13 +10212,13 @@ paths:
- application/json
responses:
"200":
description: 规则组详情
description: 规则详情
schema:
allOf:
- $ref: '#/definitions/response.Any'
- properties:
data:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
type: object
"400":
description: 参数错误
@@ -10278,7 +10229,7 @@ paths:
schema:
$ref: '#/definitions/response.Any'
"404":
description: 记录不存在
description: 无权限或不存在
schema:
$ref: '#/definitions/response.Any'
"500":
@@ -10287,14 +10238,13 @@ paths:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 获取 WAF 规则组详情
summary: 获取 WAF 规则详情
tags:
- openflare-waf
/api/v1/d/waf/rule-groups/{id}/delete:
post:
description: 按 ID 删除 WAF 规则组,需要管理员权限
parameters:
- description: 规则组 ID
- description: 规则 ID
in: path
name: id
required: true
@@ -10315,7 +10265,7 @@ paths:
schema:
$ref: '#/definitions/response.Any'
"404":
description: 记录不存在
description: 无权限或不存在
schema:
$ref: '#/definitions/response.Any'
"500":
@@ -10324,37 +10274,89 @@ paths:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 删除 WAF 规则组
summary: 删除 WAF 规则
tags:
- openflare-waf
/api/v1/d/waf/rule-groups/{id}/sites:
/api/v1/d/waf/rule-groups/{id}/graph:
post:
consumes:
- application/json
description: 替换 WAF 规则组关联的代理站点列表,需要管理员权限
parameters:
- description: 规则组 ID
- description: 规则 ID
in: path
name: id
required: true
type: integer
- description: 站点 ID 列表
- description: 规则图和修订号
in: body
name: request
required: true
schema:
$ref: '#/definitions/waf.IDsRequest'
$ref: '#/definitions/waf.SaveRuleGraphInput'
produces:
- application/json
responses:
"200":
description: 更新后的规则组
description: 保存成功
schema:
allOf:
- $ref: '#/definitions/response.Any'
- properties:
data:
$ref: '#/definitions/waf.RuleGroupView'
$ref: '#/definitions/waf.RuleView'
type: object
"400":
description: 参数或规则图错误
schema:
$ref: '#/definitions/response.Any'
"401":
description: 未登录
schema:
$ref: '#/definitions/response.Any'
"404":
description: 无权限或不存在
schema:
$ref: '#/definitions/response.Any'
"409":
description: 修订冲突
schema:
$ref: '#/definitions/response.Any'
"500":
description: 内部错误
schema:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 保存 WAF 规则图
tags:
- openflare-waf
/api/v1/d/waf/rule-groups/{id}/meta:
post:
consumes:
- application/json
parameters:
- description: 规则 ID
in: path
name: id
required: true
type: integer
- description: 规则元数据
in: body
name: request
required: true
schema:
$ref: '#/definitions/waf.UpdateRuleMetaInput'
produces:
- application/json
responses:
"200":
description: 更新成功
schema:
allOf:
- $ref: '#/definitions/response.Any'
- properties:
data:
$ref: '#/definitions/waf.RuleView'
type: object
"400":
description: 参数错误
@@ -10365,7 +10367,7 @@ paths:
schema:
$ref: '#/definitions/response.Any'
"404":
description: 记录不存在
description: 无权限或不存在
schema:
$ref: '#/definitions/response.Any'
"500":
@@ -10374,57 +10376,7 @@ paths:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 替换规则组站点绑定
tags:
- openflare-waf
/api/v1/d/waf/rule-groups/{id}/update:
post:
consumes:
- application/json
description: 按 ID 更新 WAF 规则组,需要管理员权限
parameters:
- description: 规则组 ID
in: path
name: id
required: true
type: integer
- description: 规则组参数
in: body
name: request
required: true
schema:
$ref: '#/definitions/waf.RuleGroupInput'
produces:
- application/json
responses:
"200":
description: 更新后的规则组
schema:
allOf:
- $ref: '#/definitions/response.Any'
- properties:
data:
$ref: '#/definitions/waf.RuleGroupView'
type: object
"400":
description: 参数错误
schema:
$ref: '#/definitions/response.Any'
"401":
description: 未登录
schema:
$ref: '#/definitions/response.Any'
"404":
description: 记录不存在
schema:
$ref: '#/definitions/response.Any'
"500":
description: 内部错误
schema:
$ref: '#/definitions/response.Any'
security:
- SessionCookie: []
summary: 更新 WAF 规则组
summary: 更新 WAF 规则元数据
tags:
- openflare-waf
/api/v1/d/waf/sites/{route_id}/rule-groups: