fix(waf): correct whitelist logic to bypass and add config/IP-group edit broadcasts

- Transition WAF whitelist filter from strict block-on-miss to bypass-on-hit logic

- Hook up broadcastIPGroupToAgents to CreateIPGroup and UpdateIPGroup WAF logics

- Hook up BroadcastActiveConfig to PublishConfigVersion and ActivateConfigVersion version logics

- Update WAF Lua tests in manager_test.go
This commit is contained in:
ryan
2026-06-26 20:47:30 +08:00
parent 49eae80c78
commit b89dc9ec7e
6 changed files with 42 additions and 24 deletions
@@ -15,7 +15,9 @@ import (
"time"
"github.com/Rain-kl/Wavelet/internal/apps/openflare/routeidentity"
"github.com/Rain-kl/Wavelet/internal/apps/openflare/websocket"
"github.com/Rain-kl/Wavelet/internal/model"
pkgprotocol "github.com/Rain-kl/Wavelet/pkg/protocol"
openrestyrender "github.com/Rain-kl/Wavelet/pkg/render/openresty"
"gorm.io/gorm"
)
@@ -233,6 +235,10 @@ func PublishConfigVersion(ctx context.Context, createdBy string, force bool) (*m
}
return nil, err
}
websocket.BroadcastActiveConfig(pkgprotocol.ActiveConfigMeta{
Version: record.Version,
Checksum: record.Checksum,
})
return record, nil
}
@@ -246,6 +252,10 @@ func ActivateConfigVersion(ctx context.Context, id uint) (*model.ConfigVersion,
return nil, err
}
version.IsActive = true
websocket.BroadcastActiveConfig(pkgprotocol.ActiveConfigMeta{
Version: version.Version,
Checksum: version.Checksum,
})
return version, nil
}