mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 05:56:38 +08:00
feat(waf): complete composable rule orchestration
Add the React Flow rule editor, ordered graph APIs and runtime DAG execution.\n\nPublish rules only on OpenResty reload and reconcile checksum-driven IP group snapshots in bounded shared memory.
This commit is contained in:
+10
-117
@@ -112,96 +112,10 @@ func RenderRouteConfig(doc Document, certificateFiles []SupportFile) (string, er
|
||||
// RenderWAFConfig serialises the WAF runtime configuration (rule groups and
|
||||
// per-site bindings) as a JSON string consumed by the OpenResty Lua runtime.
|
||||
func RenderWAFConfig(snapshot WAFDocument) (string, error) {
|
||||
type wafRuntimeRuleGroup struct {
|
||||
ID uint `json:"id"`
|
||||
Name string `json:"name"`
|
||||
IsGlobal bool `json:"is_global"`
|
||||
BlockStatusCode int `json:"block_status_code"`
|
||||
BlockResponseBody string `json:"block_response_body"`
|
||||
IPWhitelist []string `json:"ip_whitelist"`
|
||||
IPBlacklist []string `json:"ip_blacklist"`
|
||||
IPWhitelistGroups []uint `json:"ip_whitelist_group_ids,omitempty"`
|
||||
IPBlacklistGroups []uint `json:"ip_blacklist_group_ids,omitempty"`
|
||||
CountryWhitelist []string `json:"country_whitelist"`
|
||||
CountryBlacklist []string `json:"country_blacklist"`
|
||||
RegionWhitelist []string `json:"region_whitelist"`
|
||||
RegionBlacklist []string `json:"region_blacklist"`
|
||||
PoWEnabled bool `json:"pow_enabled"`
|
||||
PoWConfig *PoWConfig `json:"pow_config,omitempty"`
|
||||
}
|
||||
type wafRuntimeConfig struct {
|
||||
DefaultBlockStatusCode int `json:"default_block_status_code"`
|
||||
RuleGroups []wafRuntimeRuleGroup `json:"rule_groups"`
|
||||
SiteRuleGroups map[string][]uint `json:"site_rule_groups"`
|
||||
}
|
||||
groups := make([]wafRuntimeRuleGroup, 0, len(snapshot.RuleGroups))
|
||||
globalGroupIDs := make([]uint, 0)
|
||||
enabledGroupIDs := make(map[uint]struct{}, len(snapshot.RuleGroups))
|
||||
for _, group := range snapshot.RuleGroups {
|
||||
if !group.Enabled {
|
||||
continue
|
||||
}
|
||||
statusCode := group.BlockStatusCode
|
||||
if statusCode == 0 {
|
||||
statusCode = defaultWAFBlockStatus
|
||||
}
|
||||
if group.IsGlobal {
|
||||
globalGroupIDs = append(globalGroupIDs, group.ID)
|
||||
}
|
||||
enabledGroupIDs[group.ID] = struct{}{}
|
||||
powConfig := ensurePoWConfig(group.PoWEnabled, group.PoWConfig)
|
||||
groups = append(groups, wafRuntimeRuleGroup{
|
||||
ID: group.ID,
|
||||
Name: group.Name,
|
||||
IsGlobal: group.IsGlobal,
|
||||
BlockStatusCode: statusCode,
|
||||
BlockResponseBody: group.BlockResponseBody,
|
||||
IPWhitelist: sortedUniqueStrings(group.IPWhitelist),
|
||||
IPBlacklist: sortedUniqueStrings(group.IPBlacklist),
|
||||
IPWhitelistGroups: sortedUniqueUintIDs(group.IPWhitelistGroups),
|
||||
IPBlacklistGroups: sortedUniqueUintIDs(group.IPBlacklistGroups),
|
||||
CountryWhitelist: group.CountryWhitelist,
|
||||
CountryBlacklist: group.CountryBlacklist,
|
||||
RegionWhitelist: group.RegionWhitelist,
|
||||
RegionBlacklist: group.RegionBlacklist,
|
||||
PoWEnabled: group.PoWEnabled,
|
||||
PoWConfig: powConfig,
|
||||
})
|
||||
}
|
||||
sort.Slice(groups, func(i, j int) bool {
|
||||
if groups[i].IsGlobal != groups[j].IsGlobal {
|
||||
return groups[i].IsGlobal
|
||||
}
|
||||
return groups[i].ID < groups[j].ID
|
||||
})
|
||||
sort.Slice(globalGroupIDs, func(i, j int) bool { return globalGroupIDs[i] < globalGroupIDs[j] })
|
||||
siteRuleGroups := make(map[string][]uint, len(snapshot.Bindings))
|
||||
for _, binding := range snapshot.Bindings {
|
||||
ids := append([]uint{}, globalGroupIDs...)
|
||||
for _, id := range binding.RuleGroupIDs {
|
||||
if _, ok := enabledGroupIDs[id]; ok {
|
||||
ids = append(ids, id)
|
||||
}
|
||||
}
|
||||
siteRuleGroups[binding.SiteName] = uniqueUintIDs(ids)
|
||||
}
|
||||
data, err := json.Marshal(wafRuntimeConfig{DefaultBlockStatusCode: defaultWAFBlockStatus, RuleGroups: groups, SiteRuleGroups: siteRuleGroups})
|
||||
data, err := json.Marshal(snapshot)
|
||||
return string(data), err
|
||||
}
|
||||
|
||||
func sortedUniqueStrings(values []string) []string {
|
||||
items := append([]string{}, values...)
|
||||
items = uniqueStrings(items)
|
||||
sort.Strings(items)
|
||||
return items
|
||||
}
|
||||
|
||||
func sortedUniqueUintIDs(values []uint) []uint {
|
||||
items := uniqueUintIDs(values)
|
||||
sort.Slice(items, func(i, j int) bool { return items[i] < items[j] })
|
||||
return items
|
||||
}
|
||||
|
||||
// ChecksumBundle returns a stable SHA-256 hex digest over the combined content
|
||||
// of the main config, route config, and deduplicated support files, excluding
|
||||
// the source config JSON file itself.
|
||||
@@ -313,7 +227,7 @@ func renderOpenRestyLimitZoneBlock() string {
|
||||
}
|
||||
|
||||
func renderOpenRestyObservabilityTemplateBlock() string {
|
||||
return fmt.Sprintf(" lua_shared_dict openflare_observability 10m;\n lua_shared_dict openflare_pow_challenges 10m;\n lua_shared_dict openflare_pow_sessions 10m;\n lua_shared_dict openflare_pow_config 1m;\n lua_shared_dict openflare_waf_config 1m;\n init_worker_by_lua_file %s/observability/init.lua;\n log_by_lua_file %s/observability/log.lua;\n\n server {\n listen %s;\n server_name openflare-observability;\n access_log off;\n\n location = /openflare/stub_status {\n stub_status;\n }\n\n location = /openflare/observability {\n default_type application/json;\n content_by_lua_file %s/observability/read.lua;\n }\n }\n\n", LuaDirPlaceholder, LuaDirPlaceholder, ObservabilityListenPlaceholder, LuaDirPlaceholder)
|
||||
return fmt.Sprintf(" lua_shared_dict openflare_observability 10m;\n lua_shared_dict openflare_pow_challenges 10m;\n lua_shared_dict openflare_pow_sessions 10m;\n lua_shared_dict openflare_pow_config 1m;\n lua_shared_dict openflare_waf_config 1m;\n lua_shared_dict openflare_waf_ip_groups 64m;\n init_worker_by_lua_file %s/observability/init.lua;\n log_by_lua_file %s/observability/log.lua;\n\n server {\n listen %s;\n server_name openflare-observability;\n access_log off;\n\n location = /openflare/stub_status {\n stub_status;\n }\n\n location = /openflare/observability {\n default_type application/json;\n content_by_lua_file %s/observability/read.lua;\n }\n }\n\n", LuaDirPlaceholder, LuaDirPlaceholder, ObservabilityListenPlaceholder, LuaDirPlaceholder)
|
||||
}
|
||||
|
||||
func renderHTTPProxyServer(serverNames string, siteName string, originURL string, originHost string, customHeaders []CustomHeader, cacheConfig routeCacheConfig, limitConfig routeLimitConfig, upstreamConfig routeUpstreamConfig, powEnabled bool, basicAuthEnabled bool, basicAuthUsername string, basicAuthPassword string, cfg ConfigSnapshot) string {
|
||||
@@ -771,7 +685,6 @@ func getPoWConfigForRoute(routeID uint, snapshot WAFDocument) (bool, *PoWConfig)
|
||||
globalGroupIDs = append(globalGroupIDs, group.ID)
|
||||
}
|
||||
}
|
||||
sort.Slice(globalGroupIDs, func(i, j int) bool { return globalGroupIDs[i] < globalGroupIDs[j] })
|
||||
|
||||
var boundGroupIDs []uint
|
||||
for _, binding := range snapshot.Bindings {
|
||||
@@ -789,23 +702,20 @@ func getPoWConfigForRoute(routeID uint, snapshot WAFDocument) (bool, *PoWConfig)
|
||||
activeGroupIDs := uniqueUintIDs(append(append([]uint{}, globalGroupIDs...), boundGroupIDs...))
|
||||
for _, groupID := range activeGroupIDs {
|
||||
group := enabledGroups[groupID]
|
||||
if group.PoWEnabled {
|
||||
config := ensurePoWConfig(true, group.PoWConfig)
|
||||
return true, config
|
||||
if graphContainsNodeType(group.Graph, "pow") {
|
||||
return true, nil
|
||||
}
|
||||
}
|
||||
return false, nil
|
||||
}
|
||||
|
||||
func ensurePoWConfig(enabled bool, config *PoWConfig) *PoWConfig {
|
||||
if !enabled {
|
||||
return nil
|
||||
func graphContainsNodeType(graph WAFRuleGraph, nodeType string) bool {
|
||||
for _, node := range graph.Nodes {
|
||||
if node.Type == nodeType {
|
||||
return true
|
||||
}
|
||||
}
|
||||
if config != nil {
|
||||
return config
|
||||
}
|
||||
defaultConfig := DefaultPoWConfig()
|
||||
return &defaultConfig
|
||||
return false
|
||||
}
|
||||
|
||||
func uniqueUintIDs(values []uint) []uint {
|
||||
@@ -824,23 +734,6 @@ func uniqueUintIDs(values []uint) []uint {
|
||||
return result
|
||||
}
|
||||
|
||||
func uniqueStrings(values []string) []string {
|
||||
seen := make(map[string]struct{}, len(values))
|
||||
result := make([]string, 0, len(values))
|
||||
for _, value := range values {
|
||||
item := strings.TrimSpace(value)
|
||||
if item == "" {
|
||||
continue
|
||||
}
|
||||
if _, ok := seen[item]; ok {
|
||||
continue
|
||||
}
|
||||
seen[item] = struct{}{}
|
||||
result = append(result, item)
|
||||
}
|
||||
return result
|
||||
}
|
||||
|
||||
func resolveUpstreamServerName(originURL string, originHost string) string {
|
||||
parsed, err := url.Parse(originURL)
|
||||
if err != nil || !strings.EqualFold(parsed.Scheme, "https") {
|
||||
|
||||
@@ -6,6 +6,16 @@ import (
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestRenderOpenRestyUsesDedicatedWAFIPGroupSharedDict(t *testing.T) {
|
||||
block := renderOpenRestyObservabilityTemplateBlock()
|
||||
if !strings.Contains(block, "lua_shared_dict openflare_waf_config 1m;") {
|
||||
t.Fatal("expected general WAF coordination dictionary to remain available")
|
||||
}
|
||||
if !strings.Contains(block, "lua_shared_dict openflare_waf_ip_groups 64m;") {
|
||||
t.Fatalf("expected dedicated 64m WAF IP group dictionary, got:\n%s", block)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRenderWAFConfigIncludesAllRouteSiteNames(t *testing.T) {
|
||||
doc := Document{
|
||||
Routes: []Route{
|
||||
@@ -15,11 +25,8 @@ func TestRenderWAFConfigIncludesAllRouteSiteNames(t *testing.T) {
|
||||
WAF: WAFDocument{
|
||||
RuleGroups: []WAFRuleGroup{
|
||||
{
|
||||
ID: 1,
|
||||
Name: "pow-group",
|
||||
Enabled: true,
|
||||
PoWEnabled: true,
|
||||
PoWConfig: &PoWConfig{Difficulty: 4, Algorithm: "fast", SessionTTL: 600, ChallengeTTL: 300},
|
||||
ID: 1, Name: "pow-group", Enabled: true,
|
||||
Graph: WAFRuleGraph{Entry: "pow", Nodes: map[string]WAFRuleNode{"pow": {Type: "pow"}}},
|
||||
},
|
||||
},
|
||||
Bindings: []WAFBinding{
|
||||
@@ -34,18 +41,13 @@ func TestRenderWAFConfigIncludesAllRouteSiteNames(t *testing.T) {
|
||||
t.Fatalf("RenderWAFConfig() error = %v", err)
|
||||
}
|
||||
|
||||
var decoded struct {
|
||||
SiteRuleGroups map[string][]uint `json:"site_rule_groups"`
|
||||
}
|
||||
var decoded WAFDocument
|
||||
if err := json.Unmarshal([]byte(wafConfig), &decoded); err != nil {
|
||||
t.Fatalf("json.Unmarshal() error = %v", err)
|
||||
}
|
||||
|
||||
for _, route := range doc.Routes {
|
||||
siteName := resolveRouteSiteName(route)
|
||||
if _, ok := decoded.SiteRuleGroups[siteName]; !ok {
|
||||
t.Fatalf("site_rule_groups missing site %q, got %#v", siteName, decoded.SiteRuleGroups)
|
||||
}
|
||||
if len(decoded.Bindings) != 2 || decoded.Bindings[0].SiteName != "example.com" || decoded.Bindings[1].SiteName != "named-site" {
|
||||
t.Fatalf("bindings did not preserve route site names: %#v", decoded.Bindings)
|
||||
}
|
||||
|
||||
routeConfig, err := RenderRouteConfig(doc, nil)
|
||||
@@ -60,7 +62,7 @@ func TestRenderWAFConfigIncludesAllRouteSiteNames(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRenderWAFConfigUsesDefaultPoWConfigWhenEnabledWithoutPayload(t *testing.T) {
|
||||
func TestRenderWAFConfigDoesNotSynthesizeLegacyPoWConfig(t *testing.T) {
|
||||
doc := WAFDocument{
|
||||
RuleGroups: []WAFRuleGroup{
|
||||
{
|
||||
@@ -81,26 +83,15 @@ func TestRenderWAFConfigUsesDefaultPoWConfigWhenEnabledWithoutPayload(t *testing
|
||||
t.Fatalf("RenderWAFConfig() error = %v", err)
|
||||
}
|
||||
|
||||
var decoded struct {
|
||||
RuleGroups []struct {
|
||||
PoWEnabled bool `json:"pow_enabled"`
|
||||
PoWConfig *PoWConfig `json:"pow_config"`
|
||||
} `json:"rule_groups"`
|
||||
}
|
||||
var decoded WAFDocument
|
||||
if err := json.Unmarshal([]byte(wafConfig), &decoded); err != nil {
|
||||
t.Fatalf("json.Unmarshal() error = %v", err)
|
||||
}
|
||||
if len(decoded.RuleGroups) != 1 {
|
||||
t.Fatalf("expected 1 rule group, got %d", len(decoded.RuleGroups))
|
||||
}
|
||||
if !decoded.RuleGroups[0].PoWEnabled {
|
||||
t.Fatal("expected pow_enabled=true")
|
||||
}
|
||||
if decoded.RuleGroups[0].PoWConfig == nil {
|
||||
t.Fatal("expected default pow_config to be emitted")
|
||||
}
|
||||
if decoded.RuleGroups[0].PoWConfig.Difficulty != 4 {
|
||||
t.Fatalf("expected default difficulty 4, got %d", decoded.RuleGroups[0].PoWConfig.Difficulty)
|
||||
if decoded.RuleGroups[0].PoWConfig != nil {
|
||||
t.Fatalf("expected renderer not to synthesize legacy PoW config, got %#v", decoded.RuleGroups[0].PoWConfig)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -108,11 +99,8 @@ func TestGetPoWConfigForRouteUsesGlobalGroupWithoutExplicitBinding(t *testing.T)
|
||||
snapshot := WAFDocument{
|
||||
RuleGroups: []WAFRuleGroup{
|
||||
{
|
||||
ID: 1,
|
||||
Name: "global",
|
||||
Enabled: true,
|
||||
IsGlobal: true,
|
||||
PoWEnabled: true,
|
||||
ID: 1, Name: "global", Enabled: true, IsGlobal: true,
|
||||
Graph: WAFRuleGraph{Entry: "pow", Nodes: map[string]WAFRuleNode{"pow": {Type: "pow"}}},
|
||||
},
|
||||
},
|
||||
Bindings: []WAFBinding{
|
||||
@@ -124,8 +112,67 @@ func TestGetPoWConfigForRouteUsesGlobalGroupWithoutExplicitBinding(t *testing.T)
|
||||
if !enabled {
|
||||
t.Fatal("expected pow to be enabled via global rule group")
|
||||
}
|
||||
if config == nil || config.Difficulty != 4 {
|
||||
t.Fatalf("expected default pow config, got %#v", config)
|
||||
if config != nil {
|
||||
t.Fatalf("expected node config to stay in runtime graph, got legacy config %#v", config)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRenderRouteConfigEnablesPoWLocationsFromRuntimeGraph(t *testing.T) {
|
||||
doc := Document{
|
||||
Routes: []Route{{ID: 1, SiteName: "pow.example.com", Domains: []string{"pow.example.com"}, OriginURL: "http://127.0.0.1:8080", Enabled: true}},
|
||||
WAF: WAFDocument{
|
||||
RuleGroups: []WAFRuleGroup{{
|
||||
ID: 1, Name: "graph-pow", Enabled: true, IsGlobal: true,
|
||||
Graph: WAFRuleGraph{Entry: "start", Nodes: map[string]WAFRuleNode{
|
||||
"start": {Type: "start", Next: map[string]string{"next": "pow"}},
|
||||
"pow": {Type: "pow", Config: json.RawMessage(`{"algorithm":"fast","difficulty":4,"session_ttl":600,"challenge_ttl":300}`), Next: map[string]string{"next": "allow"}},
|
||||
"allow": {Type: "allow"},
|
||||
}},
|
||||
}},
|
||||
Bindings: []WAFBinding{{RouteID: 1, SiteName: "pow.example.com", RuleGroupIDs: []uint{}}},
|
||||
},
|
||||
}
|
||||
|
||||
rendered, err := RenderRouteConfig(doc, nil)
|
||||
if err != nil {
|
||||
t.Fatalf("RenderRouteConfig() error = %v", err)
|
||||
}
|
||||
for _, expected := range []string{
|
||||
`location = /.within.website/x/cmd/anubis/api/make-challenge`,
|
||||
`location = /.within.website/x/cmd/anubis/api/pass-challenge`,
|
||||
`location /.within.website/x/cmd/anubis/static/`,
|
||||
} {
|
||||
if !strings.Contains(rendered, expected) {
|
||||
t.Fatalf("expected graph PoW route to contain %q, got:\n%s", expected, rendered)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestRenderWAFConfigPreservesRuntimeGraphAndBindingOrder(t *testing.T) {
|
||||
doc := WAFDocument{
|
||||
RuleGroups: []WAFRuleGroup{{
|
||||
ID: 9, Name: "graph", Enabled: true,
|
||||
Graph: WAFRuleGraph{Entry: "start", Nodes: map[string]WAFRuleNode{
|
||||
"start": {Type: "start", Next: map[string]string{"next": "allow"}},
|
||||
"allow": {Type: "allow"},
|
||||
}},
|
||||
}},
|
||||
Bindings: []WAFBinding{{RouteID: 3, SiteName: "ordered.example.com", RuleGroupIDs: []uint{9, 4, 7}}},
|
||||
}
|
||||
|
||||
raw, err := RenderWAFConfig(doc)
|
||||
if err != nil {
|
||||
t.Fatalf("RenderWAFConfig() error = %v", err)
|
||||
}
|
||||
var decoded WAFDocument
|
||||
if err := json.Unmarshal([]byte(raw), &decoded); err != nil {
|
||||
t.Fatalf("json.Unmarshal() error = %v", err)
|
||||
}
|
||||
if decoded.RuleGroups[0].Graph.Entry != "start" {
|
||||
t.Fatalf("runtime graph was not preserved: %#v", decoded.RuleGroups[0].Graph)
|
||||
}
|
||||
if got := decoded.Bindings[0].RuleGroupIDs; len(got) != 3 || got[0] != 9 || got[1] != 4 || got[2] != 7 {
|
||||
t.Fatalf("binding order changed: %#v", got)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
package openresty
|
||||
|
||||
import "encoding/json"
|
||||
|
||||
// Placeholder constants used as sentinel values in rendered OpenResty config
|
||||
// files; the deploy process replaces them with real paths before reload.
|
||||
const (
|
||||
@@ -177,25 +179,39 @@ type PagesDeployment struct {
|
||||
LocalRoot string `json:"local_root"`
|
||||
}
|
||||
|
||||
// WAFRuleGroup defines a WAF rule group with IP/country/region lists, PoW
|
||||
// integration, and per-group block status configuration.
|
||||
// WAFRuleGraph is the compact graph executed by the OpenResty WAF runtime.
|
||||
type WAFRuleGraph struct {
|
||||
Entry string `json:"entry"`
|
||||
Nodes map[string]WAFRuleNode `json:"nodes"`
|
||||
}
|
||||
|
||||
// WAFRuleNode contains one compiled node and its handle-to-target edges.
|
||||
type WAFRuleNode struct {
|
||||
Type string `json:"type"`
|
||||
Config json.RawMessage `json:"config,omitempty"`
|
||||
Next map[string]string `json:"next,omitempty"`
|
||||
}
|
||||
|
||||
// WAFRuleGroup defines one enabled runtime graph. Legacy flattened fields are
|
||||
// retained only for decoding older stored snapshots during rolling upgrades.
|
||||
type WAFRuleGroup struct {
|
||||
ID uint `json:"id"`
|
||||
Name string `json:"name"`
|
||||
Enabled bool `json:"enabled"`
|
||||
IsGlobal bool `json:"is_global"`
|
||||
BlockStatusCode int `json:"block_status_code"`
|
||||
BlockResponseBody string `json:"block_response_body,omitempty"`
|
||||
IPWhitelist []string `json:"ip_whitelist,omitempty"`
|
||||
IPBlacklist []string `json:"ip_blacklist,omitempty"`
|
||||
IPWhitelistGroups []uint `json:"ip_whitelist_group_ids,omitempty"`
|
||||
IPBlacklistGroups []uint `json:"ip_blacklist_group_ids,omitempty"`
|
||||
CountryWhitelist []string `json:"country_whitelist,omitempty"`
|
||||
CountryBlacklist []string `json:"country_blacklist,omitempty"`
|
||||
RegionWhitelist []string `json:"region_whitelist,omitempty"`
|
||||
RegionBlacklist []string `json:"region_blacklist,omitempty"`
|
||||
PoWEnabled bool `json:"pow_enabled,omitempty"`
|
||||
PoWConfig *PoWConfig `json:"pow_config,omitempty"`
|
||||
ID uint `json:"id"`
|
||||
Name string `json:"name"`
|
||||
Enabled bool `json:"enabled"`
|
||||
IsGlobal bool `json:"is_global"`
|
||||
BlockStatusCode int `json:"block_status_code"`
|
||||
BlockResponseBody string `json:"block_response_body,omitempty"`
|
||||
IPWhitelist []string `json:"ip_whitelist,omitempty"`
|
||||
IPBlacklist []string `json:"ip_blacklist,omitempty"`
|
||||
IPWhitelistGroups []uint `json:"ip_whitelist_group_ids,omitempty"`
|
||||
IPBlacklistGroups []uint `json:"ip_blacklist_group_ids,omitempty"`
|
||||
CountryWhitelist []string `json:"country_whitelist,omitempty"`
|
||||
CountryBlacklist []string `json:"country_blacklist,omitempty"`
|
||||
RegionWhitelist []string `json:"region_whitelist,omitempty"`
|
||||
RegionBlacklist []string `json:"region_blacklist,omitempty"`
|
||||
PoWEnabled bool `json:"pow_enabled,omitempty"`
|
||||
PoWConfig *PoWConfig `json:"pow_config,omitempty"`
|
||||
Graph WAFRuleGraph `json:"graph"`
|
||||
}
|
||||
|
||||
// WAFIPGroup is a named, reusable list of IP addresses or CIDRs that can be
|
||||
|
||||
Reference in New Issue
Block a user