mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-05 23:26:38 +08:00
fix(waf): correct whitelist logic to bypass and add config/IP-group edit broadcasts
- Transition WAF whitelist filter from strict block-on-miss to bypass-on-hit logic - Hook up broadcastIPGroupToAgents to CreateIPGroup and UpdateIPGroup WAF logics - Hook up BroadcastActiveConfig to PublishConfigVersion and ActivateConfigVersion version logics - Update WAF Lua tests in manager_test.go
This commit is contained in:
@@ -15,7 +15,9 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/routeidentity"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/websocket"
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
pkgprotocol "github.com/Rain-kl/Wavelet/pkg/protocol"
|
||||
openrestyrender "github.com/Rain-kl/Wavelet/pkg/render/openresty"
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
@@ -233,6 +235,10 @@ func PublishConfigVersion(ctx context.Context, createdBy string, force bool) (*m
|
||||
}
|
||||
return nil, err
|
||||
}
|
||||
websocket.BroadcastActiveConfig(pkgprotocol.ActiveConfigMeta{
|
||||
Version: record.Version,
|
||||
Checksum: record.Checksum,
|
||||
})
|
||||
return record, nil
|
||||
}
|
||||
|
||||
@@ -246,6 +252,10 @@ func ActivateConfigVersion(ctx context.Context, id uint) (*model.ConfigVersion,
|
||||
return nil, err
|
||||
}
|
||||
version.IsActive = true
|
||||
websocket.BroadcastActiveConfig(pkgprotocol.ActiveConfigMeta{
|
||||
Version: version.Version,
|
||||
Checksum: version.Checksum,
|
||||
})
|
||||
return version, nil
|
||||
}
|
||||
|
||||
|
||||
@@ -454,6 +454,7 @@ func CreateIPGroup(ctx context.Context, input IPGroupInput) (*IPGroupView, error
|
||||
if err = model.CreateOpenFlareWAFIPGroup(ctx, group); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
broadcastIPGroupToAgents(ctx, group.ID)
|
||||
return GetIPGroup(ctx, group.ID)
|
||||
}
|
||||
|
||||
@@ -470,6 +471,7 @@ func UpdateIPGroup(ctx context.Context, id uint, input IPGroupInput) (*IPGroupVi
|
||||
if err = model.UpdateOpenFlareWAFIPGroup(ctx, group); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
broadcastIPGroupToAgents(ctx, group.ID)
|
||||
return GetIPGroup(ctx, group.ID)
|
||||
}
|
||||
|
||||
|
||||
@@ -152,6 +152,28 @@ func BroadcastWAFIPGroups(payload any) int {
|
||||
return success
|
||||
}
|
||||
|
||||
// BroadcastActiveConfig pushes active config metadata to all connected agents.
|
||||
func BroadcastActiveConfig(payload any) int {
|
||||
if payload == nil {
|
||||
return 0
|
||||
}
|
||||
message := Message{Type: agentMessageTypeActiveConfig, Payload: payload}
|
||||
defaultAgentHub.mu.RLock()
|
||||
clients := make([]*agentClient, 0, len(defaultAgentHub.clients))
|
||||
for _, client := range defaultAgentHub.clients {
|
||||
clients = append(clients, client)
|
||||
}
|
||||
defaultAgentHub.mu.RUnlock()
|
||||
|
||||
success := 0
|
||||
for _, client := range clients {
|
||||
if client.enqueue(message) {
|
||||
success++
|
||||
}
|
||||
}
|
||||
return success
|
||||
}
|
||||
|
||||
// SendForceSyncConfig notifies an agent to force sync configuration.
|
||||
func SendForceSyncConfig(nodeID string, payload any) bool {
|
||||
return sendAgentMessage(nodeID, Message{Type: agentMessageTypeForceSyncConfig, Payload: payload})
|
||||
|
||||
Reference in New Issue
Block a user