mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-07 16:16:37 +08:00
[优化] 重构 WAF 和 PoW 处理逻辑,使用 require 加载运行时模块,更新相关测试以验证新行为
This commit is contained in:
@@ -545,7 +545,7 @@ func TestManagerEnsureLuaAssetsWritesReadableFiles(t *testing.T) {
|
||||
if _, err := os.Stat(filepath.Join(manager.LuaDir, "pow", "check.lua")); err != nil {
|
||||
t.Fatalf("failed to stat pow lua file: %v", err)
|
||||
}
|
||||
data, err := os.ReadFile(filepath.Join(manager.LuaDir, "pow", "check.lua"))
|
||||
data, err := os.ReadFile(filepath.Join(manager.LuaDir, "pow", "runtime.lua"))
|
||||
if err != nil {
|
||||
t.Fatalf("failed to read pow lua file: %v", err)
|
||||
}
|
||||
@@ -667,11 +667,11 @@ func TestManagerCurrentChecksumIncludesPowConfig(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestManagedPowLuaFilesUseInternalChallengeFlow(t *testing.T) {
|
||||
if !strings.Contains(openRestyPowCheckLua, `return ngx.exec("/.within.website/x/cmd/anubis/api/make-challenge")`) {
|
||||
t.Fatal("expected check.lua to internally execute make-challenge instead of issuing a 302 redirect")
|
||||
if !strings.Contains(openRestyPowRuntimeLua, `return ngx.exec("/.within.website/x/cmd/anubis/api/make-challenge")`) {
|
||||
t.Fatal("expected pow runtime lua to internally execute make-challenge instead of issuing a 302 redirect")
|
||||
}
|
||||
if strings.Contains(openRestyPowCheckLua, "ngx.redirect(") {
|
||||
t.Fatal("expected check.lua to avoid external redirects for challenge rendering")
|
||||
if strings.Contains(openRestyPowRuntimeLua, "ngx.redirect(") {
|
||||
t.Fatal("expected pow runtime lua to avoid external redirects for challenge rendering")
|
||||
}
|
||||
if !strings.Contains(openRestyPowChallengeLua, `<h1 id="title" class="centered-div">`) {
|
||||
t.Fatal("expected challenge html to include Anubis-compatible title node")
|
||||
@@ -682,11 +682,11 @@ func TestManagedPowLuaFilesUseInternalChallengeFlow(t *testing.T) {
|
||||
if !strings.Contains(openRestyPowChallengeLua, `<script id="anubis_public_url" type="application/json">"__openflare_internal__"</script>`) {
|
||||
t.Fatal("expected challenge html to force Anubis frontend to reuse the current URL as redir target")
|
||||
}
|
||||
if !strings.Contains(openRestyPowCheckLua, `pow_sessions:set(session_key, "1", session_ttl)`) {
|
||||
t.Fatal("expected check.lua to refresh the PoW session TTL on each valid request")
|
||||
if !strings.Contains(openRestyPowRuntimeLua, `pow_sessions:set(session_key, "1", session_ttl)`) {
|
||||
t.Fatal("expected pow runtime lua to refresh the PoW session TTL on each valid request")
|
||||
}
|
||||
if !strings.Contains(openRestyPowCheckLua, `ngx.header["Set-Cookie"] = session_cookie(cookie_val, session_ttl)`) {
|
||||
t.Fatal("expected check.lua to refresh the browser session cookie on each valid request")
|
||||
if !strings.Contains(openRestyPowRuntimeLua, `ngx.header["Set-Cookie"] = session_cookie(cookie_val, session_ttl)`) {
|
||||
t.Fatal("expected pow runtime lua to refresh the browser session cookie on each valid request")
|
||||
}
|
||||
if !strings.Contains(openRestyPowChallengeLua, `local session_ttl = config.session_ttl or 600`) {
|
||||
t.Fatal("expected challenge.lua to default session TTL to 10 minutes")
|
||||
|
||||
@@ -10,7 +10,10 @@ import (
|
||||
//go:embed pow_static
|
||||
var powStaticFS embed.FS
|
||||
|
||||
const openRestyPowCheckLua = `local source = debug.getinfo(1, "S").source or ""
|
||||
const openRestyPowRuntimeLua = `local _M = {}
|
||||
|
||||
function _M.check()
|
||||
local source = debug.getinfo(1, "S").source or ""
|
||||
if string.sub(source, 1, 1) == "@" then
|
||||
local script_path = string.sub(source, 2)
|
||||
local base_dir = string.match(script_path, "^(.*)/pow/[^/]+%.lua$")
|
||||
@@ -158,6 +161,21 @@ ngx.req.set_uri_args({
|
||||
host = host
|
||||
})
|
||||
return ngx.exec("/.within.website/x/cmd/anubis/api/make-challenge")
|
||||
end
|
||||
|
||||
return _M
|
||||
`
|
||||
|
||||
const openRestyPowCheckLua = `local source = debug.getinfo(1, "S").source or ""
|
||||
if string.sub(source, 1, 1) == "@" then
|
||||
local script_path = string.sub(source, 2)
|
||||
local base_dir = string.match(script_path, "^(.*)/pow/[^/]+%.lua$")
|
||||
if base_dir and base_dir ~= "" then
|
||||
package.path = base_dir .. "/?.lua;" .. base_dir .. "/?/init.lua;" .. package.path
|
||||
end
|
||||
end
|
||||
|
||||
return require("pow.runtime").check()
|
||||
`
|
||||
|
||||
const openRestyPowChallengeLua = `local cjson = require "cjson.safe"
|
||||
@@ -473,6 +491,7 @@ return M
|
||||
|
||||
func ManagedPowLuaFiles() []protocol.SupportFile {
|
||||
return []protocol.SupportFile{
|
||||
{Path: "pow/runtime.lua", Content: openRestyPowRuntimeLua},
|
||||
{Path: "pow/check.lua", Content: openRestyPowCheckLua},
|
||||
{Path: "pow/challenge.lua", Content: openRestyPowChallengeLua},
|
||||
{Path: "pow/verify.lua", Content: openRestyPowVerifyLua},
|
||||
|
||||
@@ -2,7 +2,10 @@ package nginx
|
||||
|
||||
import "openflare-agent/internal/protocol"
|
||||
|
||||
const openRestyWAFCheckLua = `local cjson = require "cjson.safe"
|
||||
const openRestyWAFRuntimeLua = `local _M = {}
|
||||
|
||||
function _M.check()
|
||||
local cjson = require "cjson.safe"
|
||||
|
||||
local config_dict = ngx.shared.openflare_waf_config
|
||||
|
||||
@@ -215,10 +218,28 @@ for _, group in ipairs(groups) do
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
return "ok"
|
||||
end
|
||||
|
||||
return _M
|
||||
`
|
||||
|
||||
const openRestyWAFCheckLua = `local source = debug.getinfo(1, "S").source or ""
|
||||
if string.sub(source, 1, 1) == "@" then
|
||||
local script_path = string.sub(source, 2)
|
||||
local base_dir = string.match(script_path, "^(.*)/waf/[^/]+%.lua$")
|
||||
if base_dir and base_dir ~= "" then
|
||||
package.path = base_dir .. "/?.lua;" .. base_dir .. "/?/init.lua;" .. package.path
|
||||
end
|
||||
end
|
||||
|
||||
return require("waf.runtime").check()
|
||||
`
|
||||
|
||||
func ManagedWAFLuaFiles() []protocol.SupportFile {
|
||||
return []protocol.SupportFile{
|
||||
{Path: "waf/runtime.lua", Content: openRestyWAFRuntimeLua},
|
||||
{Path: "waf/check.lua", Content: openRestyWAFCheckLua},
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user