From d619deec964ff08c8974d3c6cf409e6c0bef66b6 Mon Sep 17 00:00:00 2001 From: ryan Date: Sat, 30 May 2026 15:46:34 +0800 Subject: [PATCH] =?UTF-8?q?[=E4=BC=98=E5=8C=96]=20=E6=B7=BB=E5=8A=A0=20WAF?= =?UTF-8?q?=20=E9=98=BB=E6=AD=A2=E9=80=BB=E8=BE=91=E4=BB=A5=E7=9F=AD?= =?UTF-8?q?=E8=B7=AF=20PoW=20=E5=A4=84=E7=90=86=EF=BC=8C=E6=9B=B4=E6=96=B0?= =?UTF-8?q?=E6=B5=8B=E8=AF=95=E4=BB=A5=E9=AA=8C=E8=AF=81=E6=96=B0=E8=A1=8C?= =?UTF-8?q?=E4=B8=BA?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- openflare_agent/internal/nginx/waf_assets.go | 1 + openflare_server/service/config_version.go | 3 +++ openflare_server/service/https_phase1_test.go | 4 ++-- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/openflare_agent/internal/nginx/waf_assets.go b/openflare_agent/internal/nginx/waf_assets.go index 86dfc318..e43306d7 100644 --- a/openflare_agent/internal/nginx/waf_assets.go +++ b/openflare_agent/internal/nginx/waf_assets.go @@ -158,6 +158,7 @@ local function active_groups(config, groups) end local function exit_with_group(group) + ngx.ctx.openflare_waf_blocked = true ngx.status = tonumber(group.block_status_code) or 418 local body = group.block_response_body or "" if body ~= "" then diff --git a/openflare_server/service/config_version.go b/openflare_server/service/config_version.go index c70cca45..c1ebf91f 100644 --- a/openflare_server/service/config_version.go +++ b/openflare_server/service/config_version.go @@ -1265,6 +1265,9 @@ func renderAccessBlock(siteName string, powEnabled bool) string { return fmt.Sprintf(` set $openflare_waf_site "%s"; access_by_lua_block { dofile("%s/waf/check.lua") + if ngx.ctx.openflare_waf_blocked then + return + end dofile("%s/pow/check.lua") } `, escapedSiteName, nginxLuaDirPlaceholder, nginxLuaDirPlaceholder) diff --git a/openflare_server/service/https_phase1_test.go b/openflare_server/service/https_phase1_test.go index f66b4729..7de98a9b 100644 --- a/openflare_server/service/https_phase1_test.go +++ b/openflare_server/service/https_phase1_test.go @@ -1025,8 +1025,8 @@ func TestPublishConfigVersionDetectsPoWChanges(t *testing.T) { if !strings.Contains(secondRelease.Version.RenderedConfig, "application/javascript js mjs;") { t.Fatal("expected rendered config to serve Anubis module scripts with a JavaScript MIME type") } - if !strings.Contains(secondRelease.Version.RenderedConfig, " dofile(\"__OPENFLARE_LUA_DIR__/waf/check.lua\")\n dofile(\"__OPENFLARE_LUA_DIR__/pow/check.lua\")") { - t.Fatal("expected combined WAF and PoW access handler to render at server scope") + if !strings.Contains(secondRelease.Version.RenderedConfig, " dofile(\"__OPENFLARE_LUA_DIR__/waf/check.lua\")\n if ngx.ctx.openflare_waf_blocked then\n return\n end\n dofile(\"__OPENFLARE_LUA_DIR__/pow/check.lua\")") { + t.Fatal("expected combined WAF and PoW access handler to short-circuit before PoW") } locationStart := strings.Index(secondRelease.Version.RenderedConfig, " location / {\n") if locationStart < 0 {