diff --git a/openflare_agent/Dockerfile b/openflare_agent/Dockerfile index 9bb6d334..b24bdf2f 100644 --- a/openflare_agent/Dockerfile +++ b/openflare_agent/Dockerfile @@ -19,7 +19,9 @@ RUN go build -trimpath -ldflags "-s -w -X 'openflare-agent/internal/config.Agent FROM openresty/openresty:alpine -RUN apk add --no-cache ca-certificates tzdata \ +RUN apk add --no-cache ca-certificates tzdata perl libmaxminddb \ + && ln -sf /usr/lib/libmaxminddb.so.0 /usr/lib/libmaxminddb.so \ + && opm get anjia0532/lua-resty-maxminddb \ && mkdir -p /etc/openflare /data ENV OPENFLARE_OPENRESTY_PATH=openresty \ diff --git a/openflare_agent/internal/nginx/waf_assets.go b/openflare_agent/internal/nginx/waf_assets.go index a256d9e2..86dfc318 100644 --- a/openflare_agent/internal/nginx/waf_assets.go +++ b/openflare_agent/internal/nginx/waf_assets.go @@ -169,11 +169,20 @@ end local config = load_config() if not config then + if config_dict:add("_missing_config_logged", true, 60) then + ngx.log(ngx.WARN, "openflare waf config is missing or invalid; requests will be allowed") + end return end local ip = ngx.var.remote_addr or "" local groups = active_groups(config) +if #groups == 0 then + if config_dict:add("_empty_groups_logged", true, 60) then + ngx.log(ngx.WARN, "openflare waf has no active rule group for site: ", ngx.var.openflare_waf_site or "") + end + return +end for _, group in ipairs(groups) do if ip_matches(group.ip_whitelist, ip) then diff --git a/openflare_server/router/api_phase1_test.go b/openflare_server/router/api_phase1_test.go index aa04177f..c3457bac 100644 --- a/openflare_server/router/api_phase1_test.go +++ b/openflare_server/router/api_phase1_test.go @@ -383,8 +383,8 @@ func TestPhase1HTTPSAndCertificateImportLifecycle(t *testing.T) { t.Fatalf("expected active config to expose main_config, got %#v", activeConfig["main_config"]) } supportFiles, ok := activeConfig["support_files"].([]any) - if !ok || len(supportFiles) != 3 { - t.Fatalf("expected active config to expose 3 support files, got %#v", activeConfig["support_files"]) + if !ok || len(supportFiles) != 4 { + t.Fatalf("expected active config to expose 4 support files, got %#v", activeConfig["support_files"]) } } diff --git a/openflare_server/service/agent.go b/openflare_server/service/agent.go index 484e921c..8a2bdcb4 100644 --- a/openflare_server/service/agent.go +++ b/openflare_server/service/agent.go @@ -230,7 +230,6 @@ func GetActiveConfigForAgent() (*AgentConfigResponse, error) { return nil, err } } - supportFiles = filterAgentSupportFiles(supportFiles) slog.Debug("agent fetched active config", "version", version.Version, "checksum", version.Checksum) return &AgentConfigResponse{ Version: version.Version, @@ -243,23 +242,6 @@ func GetActiveConfigForAgent() (*AgentConfigResponse, error) { }, nil } -func filterAgentSupportFiles(files []SupportFile) []SupportFile { - if len(files) == 0 { - return nil - } - filtered := make([]SupportFile, 0, len(files)) - for _, file := range files { - path := strings.ToLower(strings.TrimSpace(file.Path)) - switch { - case strings.HasSuffix(path, ".crt"), strings.HasSuffix(path, ".key"), strings.HasSuffix(path, ".pem"): - filtered = append(filtered, file) - case path == "pow_config.json": - filtered = append(filtered, file) - } - } - return filtered -} - func ReportApplyLog(payload ApplyLogPayload) (*model.ApplyLog, error) { now := time.Now() payload.NodeID = strings.TrimSpace(payload.NodeID) diff --git a/openflare_server/service/agent_test.go b/openflare_server/service/agent_test.go index a7126050..35170cf7 100644 --- a/openflare_server/service/agent_test.go +++ b/openflare_server/service/agent_test.go @@ -43,6 +43,38 @@ func TestGetActiveConfigForAgentIncludesPoWConfig(t *testing.T) { } } +func TestGetActiveConfigForAgentIncludesWAFConfig(t *testing.T) { + setupServiceTestDB(t) + + _, err := CreateProxyRoute(ProxyRouteInput{ + Domain: "waf-agent.example.com", + OriginURL: "https://origin.internal", + Enabled: true, + }) + if err != nil { + t.Fatalf("CreateProxyRoute failed: %v", err) + } + + if _, err := PublishConfigVersion("root", false); err != nil { + t.Fatalf("PublishConfigVersion failed: %v", err) + } + + activeConfig, err := GetActiveConfigForAgent() + if err != nil { + t.Fatalf("GetActiveConfigForAgent failed: %v", err) + } + + for _, file := range activeConfig.SupportFiles { + if file.Path == "waf_config.json" { + if !strings.Contains(file.Content, `"rule_groups"`) { + t.Fatalf("expected waf_config.json content to include rule groups, got %s", file.Content) + } + return + } + } + t.Fatal("expected agent config to include waf_config.json support file") +} + func TestGetActiveConfigForAgentUsesTenMinutePoWSessionDefault(t *testing.T) { setupServiceTestDB(t)