[优化] 添加自动 IP 组功能,支持按 Expr 规则聚合请求日志并更新 IP 列表

This commit is contained in:
ryan
2026-06-01 09:33:04 +08:00
parent dfb3972b15
commit bc1b861841
17 changed files with 665 additions and 41 deletions
+2 -1
View File
@@ -6,6 +6,7 @@ go 1.25.0
require (
github.com/bwmarrin/snowflake v0.3.0
github.com/dgraph-io/ristretto/v2 v2.2.0
github.com/expr-lang/expr v1.17.8
github.com/gin-contrib/cors v1.6.0
github.com/gin-contrib/sessions v0.0.5
github.com/gin-contrib/static v0.0.1
@@ -16,6 +17,7 @@ require (
github.com/go-redis/redis/v8 v8.11.5
github.com/google/uuid v1.6.0
github.com/oschwald/maxminddb-golang v1.13.1
github.com/robfig/cron/v3 v3.0.1
github.com/swaggo/files v1.0.1
github.com/swaggo/gin-swagger v1.6.1
github.com/swaggo/swag v1.16.4
@@ -71,7 +73,6 @@ require (
github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
github.com/pelletier/go-toml/v2 v2.1.1 // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
github.com/robfig/cron/v3 v3.0.1 // indirect
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
github.com/ugorji/go/codec v1.2.12 // indirect
golang.org/x/arch v0.7.0 // indirect
+2
View File
@@ -36,6 +36,8 @@ github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f h1:lO4WD4F/r
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f/go.mod h1:cuUVRXasLTGF7a8hSLbxyZXjz+1KgoB3wDUb6vlszIc=
github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto=
github.com/expr-lang/expr v1.17.8 h1:W1loDTT+0PQf5YteHSTpju2qfUfNoBt4yw9+wOEU9VM=
github.com/expr-lang/expr v1.17.8/go.mod h1:8/vRC7+7HBzESEqt5kKpYXxrxkr31SaO8r40VO/1IT4=
github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k=
github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0=
github.com/gabriel-vasile/mimetype v1.4.13 h1:46nXokslUBsAJE/wMsp5gtO500a4F3Nkz9Ufpk2AcUM=
@@ -130,6 +130,10 @@ func ListNodeAccessLogs(query NodeAccessLogQuery) (logs []*NodeAccessLog, err er
return all[start:end], nil
}
func ListNodeAccessLogsForWAFIPGroup(query NodeAccessLogQuery) ([]*NodeAccessLog, error) {
return listNodeAccessLogsAcrossShards(query)
}
func CountNodeAccessLogs(query NodeAccessLogQuery) (totalRecords int64, totalIPs int64, err error) {
all, err := listNodeAccessLogsAcrossShards(query)
if err != nil {
+2 -2
View File
@@ -119,9 +119,9 @@ func ListWAFIPGroupsByIDs(ids []uint) ([]*WAFIPGroup, error) {
return groups, err
}
func ListDueSubscriptionWAFIPGroups(now time.Time) ([]*WAFIPGroup, error) {
func ListDueWAFIPGroups(now time.Time) ([]*WAFIPGroup, error) {
var groups []*WAFIPGroup
err := DB.Where("type = ? AND enabled = ? AND subscription_url <> '' AND (next_sync_at IS NULL OR next_sync_at <= ?)", "subscription", true, now).
err := DB.Where("enabled = ? AND (type = ? OR (type = ? AND subscription_url <> '')) AND (next_sync_at IS NULL OR next_sync_at <= ?)", true, "automatic", "subscription", now).
Order("id asc").
Find(&groups).Error
return groups, err
+245 -11
View File
@@ -6,13 +6,17 @@ import (
"errors"
"fmt"
"io"
"net"
"net/http"
"net/netip"
"net/url"
"openflare/model"
"sort"
"strings"
"time"
exprlang "github.com/expr-lang/expr"
"github.com/expr-lang/expr/vm"
"gorm.io/gorm"
)
@@ -25,11 +29,44 @@ const (
WAFIPGroupSubscriptionFormatJSON = "json"
defaultWAFIPGroupSyncIntervalMinutes = 1440
defaultWAFIPGroupAutoLookbackMinutes = 60
minWAFIPGroupSyncIntervalMinutes = 5
maxWAFIPGroupSyncIntervalMinutes = 43200
maxWAFIPGroupSubscriptionBytes = 2 * 1024 * 1024
)
type wafIPGroupAutoConfig struct {
LookbackMinutes int `json:"lookback_minutes"`
Rules []wafIPGroupAutoRule `json:"rules"`
}
type wafIPGroupAutoRule struct {
Name string `json:"name"`
Expr string `json:"expr"`
}
type wafIPGroupAutoRuleEnv struct {
IP string `expr:"ip"`
RequestCount int `expr:"request_count"`
Status404Count int `expr:"status_404_count"`
Status404Ratio float64 `expr:"status_404_ratio"`
IPHostCount int `expr:"ip_host_count"`
IPHostRatio float64 `expr:"ip_host_ratio"`
ClientErrorCount int `expr:"client_error_count"`
ServerErrorCount int `expr:"server_error_count"`
LastSeenUnix int64 `expr:"last_seen_unix"`
}
type wafIPGroupAutoAccumulator struct {
ip string
requestCount int
status404Count int
ipHostCount int
clientErrorCount int
serverErrorCount int
lastSeen time.Time
}
type WAFIPGroupInput struct {
Name string `json:"name"`
Type string `json:"type"`
@@ -160,7 +197,7 @@ func SyncWAFIPGroup(id uint) (*WAFIPGroupSyncResult, error) {
func SyncDueWAFIPGroups() error {
now := time.Now().UTC()
groups, err := model.ListDueSubscriptionWAFIPGroups(now)
groups, err := model.ListDueWAFIPGroups(now)
if err != nil {
return err
}
@@ -193,14 +230,11 @@ func buildWAFIPGroup(group *model.WAFIPGroup, input WAFIPGroupInput) (*model.WAF
subscriptionFormat = WAFIPGroupSubscriptionFormatText
mappingRule = ""
case WAFIPGroupTypeAutomatic:
raw := strings.TrimSpace(string(input.AutoConfig))
if raw == "" {
raw = "{}"
normalizedConfig, err := normalizeWAFIPGroupAutoConfig(input.AutoConfig)
if err != nil {
return nil, err
}
if !json.Valid([]byte(raw)) || strings.HasPrefix(raw, "[") {
return nil, errors.New("自动 IP 组配置必须是 JSON 对象")
}
autoConfig = raw
autoConfig = normalizedConfig
subscriptionFormat = WAFIPGroupSubscriptionFormatText
mappingRule = ""
case WAFIPGroupTypeSubscription:
@@ -278,9 +312,17 @@ func syncWAFIPGroup(group *model.WAFIPGroup, now time.Time) (*WAFIPGroupSyncResu
if group == nil {
return nil, errors.New("IP 组不存在")
}
if group.Type != WAFIPGroupTypeSubscription {
return nil, errors.New("只有订阅类型 IP 组支持同步")
switch group.Type {
case WAFIPGroupTypeSubscription:
return syncWAFIPGroupSubscription(group, now)
case WAFIPGroupTypeAutomatic:
return syncWAFIPGroupAutomatic(group, now)
default:
return nil, errors.New("只有自动和订阅类型 IP 组支持同步")
}
}
func syncWAFIPGroupSubscription(group *model.WAFIPGroup, now time.Time) (*WAFIPGroupSyncResult, error) {
content, err := downloadWAFIPGroupSubscription(group.SubscriptionURL)
if err != nil {
recordWAFIPGroupSyncFailure(group, now, err)
@@ -315,6 +357,36 @@ func syncWAFIPGroup(group *model.WAFIPGroup, now time.Time) (*WAFIPGroupSyncResu
}, nil
}
func syncWAFIPGroupAutomatic(group *model.WAFIPGroup, now time.Time) (*WAFIPGroupSyncResult, error) {
ips, err := evaluateWAFIPGroupAutoConfig(group.AutoConfig, now)
if err != nil {
recordWAFIPGroupSyncFailure(group, now, err)
return nil, err
}
ipListJSON, _ := json.Marshal(ips)
nextSyncAt := now.Add(time.Duration(normalizeWAFIPGroupSyncInterval(group.SyncIntervalMinutes)) * time.Minute)
group.IPList = string(ipListJSON)
group.LastSyncedAt = &now
group.NextSyncAt = &nextSyncAt
group.LastSyncStatus = "success"
group.LastSyncMessage = fmt.Sprintf("自动规则执行成功,共命中 %d 个 IP", len(ips))
if err := group.UpdateSyncResult(); err != nil {
return nil, err
}
view, err := GetWAFIPGroup(group.ID)
if err != nil {
return nil, err
}
return &WAFIPGroupSyncResult{
Group: *view,
IPCount: len(ips),
SyncedAt: now.Format(time.RFC3339),
NextSyncAt: nextSyncAt.Format(time.RFC3339),
Status: group.LastSyncStatus,
Message: group.LastSyncMessage,
}, nil
}
func recordWAFIPGroupSyncFailure(group *model.WAFIPGroup, now time.Time, syncErr error) {
nextSyncAt := now.Add(time.Duration(normalizeWAFIPGroupSyncInterval(group.SyncIntervalMinutes)) * time.Minute)
group.LastSyncedAt = &now
@@ -324,6 +396,168 @@ func recordWAFIPGroupSyncFailure(group *model.WAFIPGroup, now time.Time, syncErr
_ = group.UpdateSyncResult()
}
func normalizeWAFIPGroupAutoConfig(raw json.RawMessage) (string, error) {
text := strings.TrimSpace(string(raw))
if text == "" {
text = "{}"
}
var config wafIPGroupAutoConfig
if err := json.Unmarshal([]byte(text), &config); err != nil {
return "", errors.New("自动 IP 组配置必须是 JSON 对象")
}
var object map[string]any
if err := json.Unmarshal([]byte(text), &object); err != nil || object == nil {
return "", errors.New("自动 IP 组配置必须是 JSON 对象")
}
if config.LookbackMinutes <= 0 {
config.LookbackMinutes = defaultWAFIPGroupAutoLookbackMinutes
}
if config.LookbackMinutes < 5 {
config.LookbackMinutes = 5
}
if config.LookbackMinutes > 43200 {
config.LookbackMinutes = 43200
}
if config.Rules == nil {
config.Rules = []wafIPGroupAutoRule{}
}
for i, rule := range config.Rules {
rule.Name = strings.TrimSpace(rule.Name)
rule.Expr = strings.TrimSpace(rule.Expr)
if rule.Expr == "" {
return "", fmt.Errorf("自动规则 %d 的 Expr 表达式不能为空", i+1)
}
if _, err := exprlang.Compile(rule.Expr, exprlang.Env(wafIPGroupAutoRuleEnv{}), exprlang.AsBool()); err != nil {
return "", fmt.Errorf("自动规则 %s Expr 无效: %w", displayWAFIPGroupAutoRuleName(rule, i), err)
}
config.Rules[i] = rule
}
normalized, _ := json.Marshal(config)
return string(normalized), nil
}
func evaluateWAFIPGroupAutoConfig(raw string, now time.Time) ([]string, error) {
normalized, err := normalizeWAFIPGroupAutoConfig(json.RawMessage(raw))
if err != nil {
return nil, err
}
var config wafIPGroupAutoConfig
if err := json.Unmarshal([]byte(normalized), &config); err != nil {
return nil, err
}
if len(config.Rules) == 0 {
return []string{}, nil
}
programs := make([]*vm.Program, 0, len(config.Rules))
for i, rule := range config.Rules {
program, err := exprlang.Compile(rule.Expr, exprlang.Env(wafIPGroupAutoRuleEnv{}), exprlang.AsBool())
if err != nil {
return nil, fmt.Errorf("自动规则 %s Expr 无效: %w", displayWAFIPGroupAutoRuleName(rule, i), err)
}
programs = append(programs, program)
}
logs, err := model.ListNodeAccessLogsForWAFIPGroup(model.NodeAccessLogQuery{
Since: now.Add(-time.Duration(config.LookbackMinutes) * time.Minute),
Until: now,
})
if err != nil {
return nil, err
}
accumulators := make(map[string]*wafIPGroupAutoAccumulator)
for _, item := range logs {
if item == nil {
continue
}
ip, ok := normalizeIPLiteral(item.RemoteAddr)
if !ok {
continue
}
acc := accumulators[ip]
if acc == nil {
acc = &wafIPGroupAutoAccumulator{ip: ip}
accumulators[ip] = acc
}
acc.requestCount++
if item.StatusCode == http.StatusNotFound {
acc.status404Count++
}
if item.StatusCode >= 400 && item.StatusCode < 500 {
acc.clientErrorCount++
}
if item.StatusCode >= 500 {
acc.serverErrorCount++
}
if hostIsIPLiteral(item.Host) {
acc.ipHostCount++
}
if item.LoggedAt.After(acc.lastSeen) {
acc.lastSeen = item.LoggedAt
}
}
matched := make([]string, 0)
for _, acc := range accumulators {
env := acc.toExprEnv()
for _, program := range programs {
output, err := exprlang.Run(program, env)
if err != nil {
return nil, fmt.Errorf("执行自动规则失败: %w", err)
}
if matchedRule, ok := output.(bool); ok && matchedRule {
matched = append(matched, acc.ip)
break
}
}
}
return normalizeWAFIPList(matched)
}
func (acc *wafIPGroupAutoAccumulator) toExprEnv() wafIPGroupAutoRuleEnv {
env := wafIPGroupAutoRuleEnv{
IP: acc.ip,
RequestCount: acc.requestCount,
Status404Count: acc.status404Count,
IPHostCount: acc.ipHostCount,
ClientErrorCount: acc.clientErrorCount,
ServerErrorCount: acc.serverErrorCount,
}
if acc.requestCount > 0 {
env.Status404Ratio = float64(acc.status404Count) / float64(acc.requestCount)
env.IPHostRatio = float64(acc.ipHostCount) / float64(acc.requestCount)
}
if !acc.lastSeen.IsZero() {
env.LastSeenUnix = acc.lastSeen.Unix()
}
return env
}
func displayWAFIPGroupAutoRuleName(rule wafIPGroupAutoRule, index int) string {
if rule.Name != "" {
return rule.Name
}
return fmt.Sprintf("#%d", index+1)
}
func normalizeIPLiteral(value string) (string, bool) {
host := strings.TrimSpace(value)
if host == "" {
return "", false
}
if parsedHost, _, err := net.SplitHostPort(host); err == nil {
host = parsedHost
}
host = strings.Trim(host, "[]")
addr, err := netip.ParseAddr(host)
if err != nil {
return "", false
}
return addr.String(), true
}
func hostIsIPLiteral(value string) bool {
_, ok := normalizeIPLiteral(value)
return ok
}
func downloadWAFIPGroupSubscription(rawURL string) ([]byte, error) {
if err := validateSubscriptionURL(rawURL); err != nil {
return nil, err
@@ -493,7 +727,7 @@ func normalizeWAFIPGroupSyncInterval(value int) int {
}
func nextWAFIPGroupSyncAt(groupType string, enabled bool, interval int, current *time.Time) *time.Time {
if groupType != WAFIPGroupTypeSubscription || !enabled {
if (groupType != WAFIPGroupTypeSubscription && groupType != WAFIPGroupTypeAutomatic) || !enabled {
return nil
}
if current != nil && current.After(time.Now().UTC()) {
+79
View File
@@ -4,8 +4,10 @@ import (
"encoding/json"
"net/http"
"net/http/httptest"
"openflare/model"
"strings"
"testing"
"time"
)
func TestWAFRuleGroupValidationAndNormalization(t *testing.T) {
@@ -211,6 +213,63 @@ func TestSyncWAFIPGroupDownloadsSubscription(t *testing.T) {
}
}
func TestSyncWAFIPGroupAutomaticExprRules(t *testing.T) {
setupServiceTestDB(t)
now := time.Now().UTC()
seedWAFNodeAccessLogs(t, now, "203.0.113.10", "app.example.com", 101, 81)
seedWAFNodeAccessLogs(t, now, "203.0.113.11", "198.51.100.10", 60, 0)
seedWAFNodeAccessLogs(t, now, "203.0.113.12", "app.example.com", 120, 10)
group, err := CreateWAFIPGroup(WAFIPGroupInput{
Name: "auto blacklist",
Type: WAFIPGroupTypeAutomatic,
Enabled: true,
AutoConfig: json.RawMessage(`{
"lookback_minutes": 60,
"rules": [
{"name":"单 IP 404 高频扫描","expr":"request_count > 100 && status_404_ratio >= 0.8"},
{"name":"单 IP 直连访问异常","expr":"ip_host_count > 50 && ip_host_ratio > 0.5"}
]
}`),
})
if err != nil {
t.Fatalf("CreateWAFIPGroup failed: %v", err)
}
result, err := SyncWAFIPGroup(group.ID)
if err != nil {
t.Fatalf("SyncWAFIPGroup failed: %v", err)
}
if result.IPCount != 2 {
t.Fatalf("expected two matched IPs, got %#v", result)
}
want := map[string]bool{"203.0.113.10": true, "203.0.113.11": true}
for _, item := range result.Group.IPList {
if !want[item] {
t.Fatalf("unexpected matched IP %s in %#v", item, result.Group.IPList)
}
delete(want, item)
}
if len(want) != 0 {
t.Fatalf("missing matched IPs: %#v", want)
}
}
func TestWAFIPGroupAutomaticRejectsInvalidExpr(t *testing.T) {
setupServiceTestDB(t)
if _, err := CreateWAFIPGroup(WAFIPGroupInput{
Name: "bad auto",
Type: WAFIPGroupTypeAutomatic,
Enabled: true,
AutoConfig: json.RawMessage(`{
"rules": [{"name":"bad","expr":"request_count > "}]
}`),
}); err == nil {
t.Fatal("expected invalid Expr to be rejected")
}
}
func TestPublishConfigVersionExpandsWAFIPGroupReferences(t *testing.T) {
setupServiceTestDB(t)
@@ -265,3 +324,23 @@ func TestPublishConfigVersionExpandsWAFIPGroupReferences(t *testing.T) {
t.Fatalf("expected expanded IP group in waf_config.json, got %#v", files)
}
}
func seedWAFNodeAccessLogs(t *testing.T, loggedAt time.Time, remoteAddr string, host string, total int, notFound int) {
t.Helper()
for i := 0; i < total; i++ {
statusCode := http.StatusOK
if i < notFound {
statusCode = http.StatusNotFound
}
if err := model.DB.Create(&model.NodeAccessLog{
NodeID: "node-waf-auto",
LoggedAt: loggedAt.Add(-time.Duration(i%30) * time.Second),
RemoteAddr: remoteAddr,
Host: host,
Path: "/probe",
StatusCode: statusCode,
}).Error; err != nil {
t.Fatalf("failed to seed access log: %v", err)
}
}
}
@@ -69,6 +69,17 @@ const typeLabels: Record<WAFIPGroupType, string> = {
subscription: '订阅',
};
const automaticPresetRules = [
{
name: '单 IP 404 高频扫描',
expr: 'request_count > 100 && status_404_ratio >= 0.8',
},
{
name: '单 IP 直连访问异常',
expr: 'ip_host_count > 50 && ip_host_ratio > 0.5',
},
];
function buildDraft(group: WAFIPGroup | null): IPGroupDraft {
if (!group) {
return { ...emptyIPGroupDraft };
@@ -112,6 +123,38 @@ function buildPayload(draft: IPGroupDraft): WAFIPGroupPayload {
};
}
function appendAutomaticPresetRule(
autoConfigText: string,
rule: (typeof automaticPresetRules)[number],
) {
const parsed = JSON.parse(autoConfigText || '{}') as unknown;
if (!parsed || Array.isArray(parsed) || typeof parsed !== 'object') {
throw new Error('自动配置必须是 JSON 对象。');
}
const config = parsed as Record<string, unknown>;
const rules = Array.isArray(config.rules) ? config.rules : [];
const exists = rules.some(
(item) =>
item &&
typeof item === 'object' &&
'expr' in item &&
(item as { expr?: unknown }).expr === rule.expr,
);
const nextRules = exists ? rules : [...rules, rule];
return JSON.stringify(
{
lookback_minutes:
typeof config.lookback_minutes === 'number'
? config.lookback_minutes
: 60,
...config,
rules: nextRules,
},
null,
2,
);
}
export function WAFIPGroupsPage() {
const router = useRouter();
const queryClient = useQueryClient();
@@ -280,19 +323,24 @@ export function WAFIPGroupsPage() {
title={selectedGroup ? selectedGroup.name : '新建 IP 组'}
description={
draft.type === 'automatic'
? '自动 IP 组第一版仅保存配置,暂不执行日志挖掘。'
? '自动 IP 组会按 Expr 规则定时从请求日志中聚合命中 IP。'
: '保存后可在 WAF 规则组黑白名单中引用。'
}
action={
<div className="flex flex-wrap gap-3">
{selectedGroup?.type === 'subscription' ? (
{selectedGroup?.type === 'subscription' ||
selectedGroup?.type === 'automatic' ? (
<SecondaryButton
type="button"
disabled={syncMutation.isPending}
onClick={() => syncMutation.mutate(selectedGroup.id)}
>
<Download className="mr-2 h-4 w-4" />
{syncMutation.isPending ? '同步中...' : '立即同步'}
{syncMutation.isPending
? '执行中...'
: selectedGroup.type === 'automatic'
? '立即执行'
: '立即同步'}
</SecondaryButton>
) : null}
<PrimaryButton
@@ -419,21 +467,56 @@ export function WAFIPGroupsPage() {
) : null}
{draft.type === 'automatic' ? (
<ResourceField
label="自动配置 JSON"
hint="当前版本只保存配置,不会执行请求日志挖掘。"
>
<ResourceTextarea
value={draft.auto_config_text}
className="min-h-64 font-mono"
onChange={(event) =>
setDraft((current) => ({
...current,
auto_config_text: event.target.value,
}))
}
/>
</ResourceField>
<div className="space-y-4">
<ResourceField
label="预设规则"
hint="表达式按单个 IP 的请求日志聚合指标计算。"
container="div"
>
<div className="flex flex-wrap gap-2">
{automaticPresetRules.map((rule) => (
<SecondaryButton
key={rule.expr}
type="button"
onClick={() => {
try {
setDraft((current) => ({
...current,
auto_config_text: appendAutomaticPresetRule(
current.auto_config_text,
rule,
),
}));
} catch (error) {
setFeedback({
tone: 'danger',
message: getErrorMessage(error),
});
}
}}
>
<Plus className="mr-2 h-4 w-4" />
{rule.name}
</SecondaryButton>
))}
</div>
</ResourceField>
<ResourceField
label="自动配置 JSON"
hint="可用字段:request_count、status_404_count、status_404_ratio、ip_host_count、ip_host_ratio。"
>
<ResourceTextarea
value={draft.auto_config_text}
className="min-h-64 font-mono"
onChange={(event) =>
setDraft((current) => ({
...current,
auto_config_text: event.target.value,
}))
}
/>
</ResourceField>
</div>
) : (
<ResourceField
label="IP / IP 段"
@@ -172,6 +172,38 @@ describe('WAF IP groups', () => {
await waitFor(() => expect(groups).toHaveLength(1));
});
it('adds automatic Expr preset rules', async () => {
vi.stubGlobal(
'fetch',
vi.fn((input: RequestInfo | URL) => {
const url = String(input);
if (url.includes('/waf/ip-groups')) {
return Promise.resolve(
new Response(
JSON.stringify({ success: true, message: '', data: [] }),
),
);
}
return Promise.reject(new Error(`Unhandled fetch: ${url}`));
}),
);
renderWithProviders(<WAFIPGroupsPage />);
await screen.findByText('暂无 IP 组');
await userEvent.click(screen.getByRole('button', { name: /新建 IP 组/ }));
await userEvent.selectOptions(screen.getByLabelText('类型'), 'automatic');
await userEvent.click(screen.getByText('单 IP 404 高频扫描'));
await userEvent.click(screen.getByText('单 IP 直连访问异常'));
const textarea = screen.getByLabelText(/自动配置 JSON/);
const value = (textarea as HTMLTextAreaElement).value;
expect(value).toContain('request_count > 100 && status_404_ratio >= 0.8');
expect(value).toContain('ip_host_count > 50 && ip_host_ratio > 0.5');
});
it('opens IP group management from WAF page and references an IP group', async () => {
vi.stubGlobal(
'fetch',