[优化] 添加 WAF 阻止逻辑以短路 PoW 处理,更新测试以验证新行为

This commit is contained in:
ryan
2026-05-30 15:46:34 +08:00
parent e094f4a3b7
commit d619deec96
3 changed files with 6 additions and 2 deletions
@@ -158,6 +158,7 @@ local function active_groups(config, groups)
end
local function exit_with_group(group)
ngx.ctx.openflare_waf_blocked = true
ngx.status = tonumber(group.block_status_code) or 418
local body = group.block_response_body or ""
if body ~= "" then
@@ -1265,6 +1265,9 @@ func renderAccessBlock(siteName string, powEnabled bool) string {
return fmt.Sprintf(` set $openflare_waf_site "%s";
access_by_lua_block {
dofile("%s/waf/check.lua")
if ngx.ctx.openflare_waf_blocked then
return
end
dofile("%s/pow/check.lua")
}
`, escapedSiteName, nginxLuaDirPlaceholder, nginxLuaDirPlaceholder)
@@ -1025,8 +1025,8 @@ func TestPublishConfigVersionDetectsPoWChanges(t *testing.T) {
if !strings.Contains(secondRelease.Version.RenderedConfig, "application/javascript js mjs;") {
t.Fatal("expected rendered config to serve Anubis module scripts with a JavaScript MIME type")
}
if !strings.Contains(secondRelease.Version.RenderedConfig, " dofile(\"__OPENFLARE_LUA_DIR__/waf/check.lua\")\n dofile(\"__OPENFLARE_LUA_DIR__/pow/check.lua\")") {
t.Fatal("expected combined WAF and PoW access handler to render at server scope")
if !strings.Contains(secondRelease.Version.RenderedConfig, " dofile(\"__OPENFLARE_LUA_DIR__/waf/check.lua\")\n if ngx.ctx.openflare_waf_blocked then\n return\n end\n dofile(\"__OPENFLARE_LUA_DIR__/pow/check.lua\")") {
t.Fatal("expected combined WAF and PoW access handler to short-circuit before PoW")
}
locationStart := strings.Index(secondRelease.Version.RenderedConfig, " location / {\n")
if locationStart < 0 {