mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 07:06:36 +08:00
fix(waf): correct whitelist logic to bypass and add config/IP-group edit broadcasts
- Transition WAF whitelist filter from strict block-on-miss to bypass-on-hit logic - Hook up broadcastIPGroupToAgents to CreateIPGroup and UpdateIPGroup WAF logics - Hook up BroadcastActiveConfig to PublishConfigVersion and ActivateConfigVersion version logics - Update WAF Lua tests in manager_test.go
This commit is contained in:
@@ -699,15 +699,12 @@ func TestManagedPowLuaFilesUseInternalChallengeFlow(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestManagedWAFLuaTreatsWhitelistAsAllowlist(t *testing.T) {
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "local function first_allowlist_group(groups)") {
|
||||
t.Fatal("expected waf runtime to detect allowlist rule groups")
|
||||
func TestManagedWAFLuaTreatsWhitelistAsBypass(t *testing.T) {
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "if ip_matches(group.ip_whitelist, ip)") {
|
||||
t.Fatal("expected waf runtime to bypass request when ip matches whitelist")
|
||||
}
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "local allowlist_group = first_allowlist_group(groups)") {
|
||||
t.Fatal("expected waf runtime to enter allowlist mode when whitelist rules exist")
|
||||
}
|
||||
if !strings.Contains(openRestyWAFRuntimeLua, "return exit_with_group(allowlist_group)") {
|
||||
t.Fatal("expected waf runtime to block requests that miss configured whitelists")
|
||||
if strings.Contains(openRestyWAFRuntimeLua, "first_allowlist_group") {
|
||||
t.Fatal("expected waf runtime not to block requests that miss configured whitelists")
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -219,17 +219,6 @@ local function exit_with_group(group)
|
||||
return ngx.exit(ngx.status)
|
||||
end
|
||||
|
||||
local function first_allowlist_group(groups)
|
||||
for _, group in ipairs(groups) do
|
||||
if table_has_items(group.ip_whitelist)
|
||||
or table_has_items(group.ip_whitelist_group_ids)
|
||||
or table_has_items(group.country_whitelist) then
|
||||
return group
|
||||
end
|
||||
end
|
||||
return nil
|
||||
end
|
||||
|
||||
local config = load_config()
|
||||
if not config then
|
||||
if config_dict:add("_missing_config_logged", true, 60) then
|
||||
@@ -264,11 +253,6 @@ for _, group in ipairs(groups) do
|
||||
end
|
||||
end
|
||||
|
||||
local allowlist_group = first_allowlist_group(groups)
|
||||
if allowlist_group then
|
||||
return exit_with_group(allowlist_group)
|
||||
end
|
||||
|
||||
for _, group in ipairs(groups) do
|
||||
if ip_matches(group.ip_blacklist, ip) or ip_matches_group_ids(group.ip_blacklist_group_ids, ip, ip_groups_config) then
|
||||
return exit_with_group(group)
|
||||
|
||||
Reference in New Issue
Block a user