mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-07 08:06:37 +08:00
[新增] 添加自动 IP 组规则测试功能,支持在保存前验证 Expr 规则命中情况
This commit is contained in:
@@ -110,6 +110,18 @@ type WAFIPGroupSyncResult struct {
|
||||
Message string `json:"message"`
|
||||
}
|
||||
|
||||
type WAFIPGroupAutoTestInput struct {
|
||||
AutoConfig json.RawMessage `json:"auto_config"`
|
||||
}
|
||||
|
||||
type WAFIPGroupAutoTestResult struct {
|
||||
MatchedIPs []string `json:"matched_ips"`
|
||||
MatchedCount int `json:"matched_count"`
|
||||
LookbackMinutes int `json:"lookback_minutes"`
|
||||
RuleCount int `json:"rule_count"`
|
||||
TestedAt string `json:"tested_at"`
|
||||
}
|
||||
|
||||
func ListWAFIPGroups() ([]WAFIPGroupView, error) {
|
||||
groups, err := model.ListWAFIPGroups()
|
||||
if err != nil {
|
||||
@@ -195,6 +207,25 @@ func SyncWAFIPGroup(id uint) (*WAFIPGroupSyncResult, error) {
|
||||
return syncWAFIPGroup(group, time.Now().UTC())
|
||||
}
|
||||
|
||||
func TestWAFIPGroupAutoConfig(input WAFIPGroupAutoTestInput) (*WAFIPGroupAutoTestResult, error) {
|
||||
config, err := parseWAFIPGroupAutoConfig(input.AutoConfig)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
now := time.Now().UTC()
|
||||
ips, err := evaluateParsedWAFIPGroupAutoConfig(config, now)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &WAFIPGroupAutoTestResult{
|
||||
MatchedIPs: ips,
|
||||
MatchedCount: len(ips),
|
||||
LookbackMinutes: config.LookbackMinutes,
|
||||
RuleCount: len(config.Rules),
|
||||
TestedAt: now.Format(time.RFC3339),
|
||||
}, nil
|
||||
}
|
||||
|
||||
func SyncDueWAFIPGroups() error {
|
||||
now := time.Now().UTC()
|
||||
groups, err := model.ListDueWAFIPGroups(now)
|
||||
@@ -397,17 +428,38 @@ func recordWAFIPGroupSyncFailure(group *model.WAFIPGroup, now time.Time, syncErr
|
||||
}
|
||||
|
||||
func normalizeWAFIPGroupAutoConfig(raw json.RawMessage) (string, error) {
|
||||
text := strings.TrimSpace(string(raw))
|
||||
if text == "" {
|
||||
text = "{}"
|
||||
}
|
||||
config, err := parseWAFIPGroupAutoConfig(json.RawMessage(text))
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
normalized, _ := json.Marshal(config)
|
||||
return string(normalized), nil
|
||||
}
|
||||
|
||||
func evaluateWAFIPGroupAutoConfig(raw string, now time.Time) ([]string, error) {
|
||||
config, err := parseWAFIPGroupAutoConfig(json.RawMessage(raw))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return evaluateParsedWAFIPGroupAutoConfig(config, now)
|
||||
}
|
||||
|
||||
func parseWAFIPGroupAutoConfig(raw json.RawMessage) (wafIPGroupAutoConfig, error) {
|
||||
text := strings.TrimSpace(string(raw))
|
||||
if text == "" {
|
||||
text = "{}"
|
||||
}
|
||||
var config wafIPGroupAutoConfig
|
||||
if err := json.Unmarshal([]byte(text), &config); err != nil {
|
||||
return "", errors.New("自动 IP 组配置必须是 JSON 对象")
|
||||
return wafIPGroupAutoConfig{}, errors.New("自动 IP 组配置必须是 JSON 对象")
|
||||
}
|
||||
var object map[string]any
|
||||
if err := json.Unmarshal([]byte(text), &object); err != nil || object == nil {
|
||||
return "", errors.New("自动 IP 组配置必须是 JSON 对象")
|
||||
return wafIPGroupAutoConfig{}, errors.New("自动 IP 组配置必须是 JSON 对象")
|
||||
}
|
||||
if config.LookbackMinutes <= 0 {
|
||||
config.LookbackMinutes = defaultWAFIPGroupAutoLookbackMinutes
|
||||
@@ -425,26 +477,17 @@ func normalizeWAFIPGroupAutoConfig(raw json.RawMessage) (string, error) {
|
||||
rule.Name = strings.TrimSpace(rule.Name)
|
||||
rule.Expr = strings.TrimSpace(rule.Expr)
|
||||
if rule.Expr == "" {
|
||||
return "", fmt.Errorf("自动规则 %d 的 Expr 表达式不能为空", i+1)
|
||||
return wafIPGroupAutoConfig{}, fmt.Errorf("自动规则 %d 的 Expr 表达式不能为空", i+1)
|
||||
}
|
||||
if _, err := exprlang.Compile(rule.Expr, exprlang.Env(wafIPGroupAutoRuleEnv{}), exprlang.AsBool()); err != nil {
|
||||
return "", fmt.Errorf("自动规则 %s Expr 无效: %w", displayWAFIPGroupAutoRuleName(rule, i), err)
|
||||
return wafIPGroupAutoConfig{}, fmt.Errorf("自动规则 %s Expr 无效: %w", displayWAFIPGroupAutoRuleName(rule, i), err)
|
||||
}
|
||||
config.Rules[i] = rule
|
||||
}
|
||||
normalized, _ := json.Marshal(config)
|
||||
return string(normalized), nil
|
||||
return config, nil
|
||||
}
|
||||
|
||||
func evaluateWAFIPGroupAutoConfig(raw string, now time.Time) ([]string, error) {
|
||||
normalized, err := normalizeWAFIPGroupAutoConfig(json.RawMessage(raw))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
var config wafIPGroupAutoConfig
|
||||
if err := json.Unmarshal([]byte(normalized), &config); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
func evaluateParsedWAFIPGroupAutoConfig(config wafIPGroupAutoConfig, now time.Time) ([]string, error) {
|
||||
if len(config.Rules) == 0 {
|
||||
return []string{}, nil
|
||||
}
|
||||
|
||||
@@ -255,6 +255,41 @@ func TestSyncWAFIPGroupAutomaticExprRules(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestWAFIPGroupAutoConfigReturnsMatchedIPs(t *testing.T) {
|
||||
setupServiceTestDB(t)
|
||||
|
||||
now := time.Now().UTC()
|
||||
seedWAFNodeAccessLogs(t, now, "203.0.113.10", "app.example.com", 101, 81)
|
||||
seedWAFNodeAccessLogs(t, now, "203.0.113.11", "198.51.100.10", 60, 0)
|
||||
seedWAFNodeAccessLogs(t, now, "203.0.113.12", "app.example.com", 120, 10)
|
||||
|
||||
result, err := TestWAFIPGroupAutoConfig(WAFIPGroupAutoTestInput{
|
||||
AutoConfig: json.RawMessage(`{
|
||||
"lookback_minutes": 60,
|
||||
"rules": [
|
||||
{"name":"单 IP 404 高频扫描","expr":"request_count > 100 && status_404_ratio >= 0.8"},
|
||||
{"name":"单 IP 直连访问异常","expr":"ip_host_count > 50 && ip_host_ratio > 0.5"}
|
||||
]
|
||||
}`),
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("TestWAFIPGroupAutoConfig failed: %v", err)
|
||||
}
|
||||
if result.MatchedCount != 2 || result.RuleCount != 2 || result.LookbackMinutes != 60 {
|
||||
t.Fatalf("unexpected test result: %+v", result)
|
||||
}
|
||||
want := map[string]bool{"203.0.113.10": true, "203.0.113.11": true}
|
||||
for _, item := range result.MatchedIPs {
|
||||
if !want[item] {
|
||||
t.Fatalf("unexpected matched IP %s in %#v", item, result.MatchedIPs)
|
||||
}
|
||||
delete(want, item)
|
||||
}
|
||||
if len(want) != 0 {
|
||||
t.Fatalf("missing matched IPs: %#v", want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWAFIPGroupAutomaticRejectsInvalidExpr(t *testing.T) {
|
||||
setupServiceTestDB(t)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user