[优化] 移除不必要的支持文件过滤函数,更新相关测试以验证 WAF 配置包含

This commit is contained in:
ryan
2026-05-30 15:39:18 +08:00
parent 1bff2dadd4
commit e094f4a3b7
5 changed files with 46 additions and 21 deletions
+3 -1
View File
@@ -19,7 +19,9 @@ RUN go build -trimpath -ldflags "-s -w -X 'openflare-agent/internal/config.Agent
FROM openresty/openresty:alpine
RUN apk add --no-cache ca-certificates tzdata \
RUN apk add --no-cache ca-certificates tzdata perl libmaxminddb \
&& ln -sf /usr/lib/libmaxminddb.so.0 /usr/lib/libmaxminddb.so \
&& opm get anjia0532/lua-resty-maxminddb \
&& mkdir -p /etc/openflare /data
ENV OPENFLARE_OPENRESTY_PATH=openresty \
@@ -169,11 +169,20 @@ end
local config = load_config()
if not config then
if config_dict:add("_missing_config_logged", true, 60) then
ngx.log(ngx.WARN, "openflare waf config is missing or invalid; requests will be allowed")
end
return
end
local ip = ngx.var.remote_addr or ""
local groups = active_groups(config)
if #groups == 0 then
if config_dict:add("_empty_groups_logged", true, 60) then
ngx.log(ngx.WARN, "openflare waf has no active rule group for site: ", ngx.var.openflare_waf_site or "")
end
return
end
for _, group in ipairs(groups) do
if ip_matches(group.ip_whitelist, ip) then
+2 -2
View File
@@ -383,8 +383,8 @@ func TestPhase1HTTPSAndCertificateImportLifecycle(t *testing.T) {
t.Fatalf("expected active config to expose main_config, got %#v", activeConfig["main_config"])
}
supportFiles, ok := activeConfig["support_files"].([]any)
if !ok || len(supportFiles) != 3 {
t.Fatalf("expected active config to expose 3 support files, got %#v", activeConfig["support_files"])
if !ok || len(supportFiles) != 4 {
t.Fatalf("expected active config to expose 4 support files, got %#v", activeConfig["support_files"])
}
}
-18
View File
@@ -230,7 +230,6 @@ func GetActiveConfigForAgent() (*AgentConfigResponse, error) {
return nil, err
}
}
supportFiles = filterAgentSupportFiles(supportFiles)
slog.Debug("agent fetched active config", "version", version.Version, "checksum", version.Checksum)
return &AgentConfigResponse{
Version: version.Version,
@@ -243,23 +242,6 @@ func GetActiveConfigForAgent() (*AgentConfigResponse, error) {
}, nil
}
func filterAgentSupportFiles(files []SupportFile) []SupportFile {
if len(files) == 0 {
return nil
}
filtered := make([]SupportFile, 0, len(files))
for _, file := range files {
path := strings.ToLower(strings.TrimSpace(file.Path))
switch {
case strings.HasSuffix(path, ".crt"), strings.HasSuffix(path, ".key"), strings.HasSuffix(path, ".pem"):
filtered = append(filtered, file)
case path == "pow_config.json":
filtered = append(filtered, file)
}
}
return filtered
}
func ReportApplyLog(payload ApplyLogPayload) (*model.ApplyLog, error) {
now := time.Now()
payload.NodeID = strings.TrimSpace(payload.NodeID)
+32
View File
@@ -43,6 +43,38 @@ func TestGetActiveConfigForAgentIncludesPoWConfig(t *testing.T) {
}
}
func TestGetActiveConfigForAgentIncludesWAFConfig(t *testing.T) {
setupServiceTestDB(t)
_, err := CreateProxyRoute(ProxyRouteInput{
Domain: "waf-agent.example.com",
OriginURL: "https://origin.internal",
Enabled: true,
})
if err != nil {
t.Fatalf("CreateProxyRoute failed: %v", err)
}
if _, err := PublishConfigVersion("root", false); err != nil {
t.Fatalf("PublishConfigVersion failed: %v", err)
}
activeConfig, err := GetActiveConfigForAgent()
if err != nil {
t.Fatalf("GetActiveConfigForAgent failed: %v", err)
}
for _, file := range activeConfig.SupportFiles {
if file.Path == "waf_config.json" {
if !strings.Contains(file.Content, `"rule_groups"`) {
t.Fatalf("expected waf_config.json content to include rule groups, got %s", file.Content)
}
return
}
}
t.Fatal("expected agent config to include waf_config.json support file")
}
func TestGetActiveConfigForAgentUsesTenMinutePoWSessionDefault(t *testing.T) {
setupServiceTestDB(t)