From e094f4a3b796ba1580f564778808926c09616067 Mon Sep 17 00:00:00 2001 From: ryan Date: Sat, 30 May 2026 15:39:18 +0800 Subject: [PATCH] =?UTF-8?q?[=E4=BC=98=E5=8C=96]=20=E7=A7=BB=E9=99=A4?= =?UTF-8?q?=E4=B8=8D=E5=BF=85=E8=A6=81=E7=9A=84=E6=94=AF=E6=8C=81=E6=96=87?= =?UTF-8?q?=E4=BB=B6=E8=BF=87=E6=BB=A4=E5=87=BD=E6=95=B0=EF=BC=8C=E6=9B=B4?= =?UTF-8?q?=E6=96=B0=E7=9B=B8=E5=85=B3=E6=B5=8B=E8=AF=95=E4=BB=A5=E9=AA=8C?= =?UTF-8?q?=E8=AF=81=20WAF=20=E9=85=8D=E7=BD=AE=E5=8C=85=E5=90=AB?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- openflare_agent/Dockerfile | 4 ++- openflare_agent/internal/nginx/waf_assets.go | 9 ++++++ openflare_server/router/api_phase1_test.go | 4 +-- openflare_server/service/agent.go | 18 ----------- openflare_server/service/agent_test.go | 32 ++++++++++++++++++++ 5 files changed, 46 insertions(+), 21 deletions(-) diff --git a/openflare_agent/Dockerfile b/openflare_agent/Dockerfile index 9bb6d334..b24bdf2f 100644 --- a/openflare_agent/Dockerfile +++ b/openflare_agent/Dockerfile @@ -19,7 +19,9 @@ RUN go build -trimpath -ldflags "-s -w -X 'openflare-agent/internal/config.Agent FROM openresty/openresty:alpine -RUN apk add --no-cache ca-certificates tzdata \ +RUN apk add --no-cache ca-certificates tzdata perl libmaxminddb \ + && ln -sf /usr/lib/libmaxminddb.so.0 /usr/lib/libmaxminddb.so \ + && opm get anjia0532/lua-resty-maxminddb \ && mkdir -p /etc/openflare /data ENV OPENFLARE_OPENRESTY_PATH=openresty \ diff --git a/openflare_agent/internal/nginx/waf_assets.go b/openflare_agent/internal/nginx/waf_assets.go index a256d9e2..86dfc318 100644 --- a/openflare_agent/internal/nginx/waf_assets.go +++ b/openflare_agent/internal/nginx/waf_assets.go @@ -169,11 +169,20 @@ end local config = load_config() if not config then + if config_dict:add("_missing_config_logged", true, 60) then + ngx.log(ngx.WARN, "openflare waf config is missing or invalid; requests will be allowed") + end return end local ip = ngx.var.remote_addr or "" local groups = active_groups(config) +if #groups == 0 then + if config_dict:add("_empty_groups_logged", true, 60) then + ngx.log(ngx.WARN, "openflare waf has no active rule group for site: ", ngx.var.openflare_waf_site or "") + end + return +end for _, group in ipairs(groups) do if ip_matches(group.ip_whitelist, ip) then diff --git a/openflare_server/router/api_phase1_test.go b/openflare_server/router/api_phase1_test.go index aa04177f..c3457bac 100644 --- a/openflare_server/router/api_phase1_test.go +++ b/openflare_server/router/api_phase1_test.go @@ -383,8 +383,8 @@ func TestPhase1HTTPSAndCertificateImportLifecycle(t *testing.T) { t.Fatalf("expected active config to expose main_config, got %#v", activeConfig["main_config"]) } supportFiles, ok := activeConfig["support_files"].([]any) - if !ok || len(supportFiles) != 3 { - t.Fatalf("expected active config to expose 3 support files, got %#v", activeConfig["support_files"]) + if !ok || len(supportFiles) != 4 { + t.Fatalf("expected active config to expose 4 support files, got %#v", activeConfig["support_files"]) } } diff --git a/openflare_server/service/agent.go b/openflare_server/service/agent.go index 484e921c..8a2bdcb4 100644 --- a/openflare_server/service/agent.go +++ b/openflare_server/service/agent.go @@ -230,7 +230,6 @@ func GetActiveConfigForAgent() (*AgentConfigResponse, error) { return nil, err } } - supportFiles = filterAgentSupportFiles(supportFiles) slog.Debug("agent fetched active config", "version", version.Version, "checksum", version.Checksum) return &AgentConfigResponse{ Version: version.Version, @@ -243,23 +242,6 @@ func GetActiveConfigForAgent() (*AgentConfigResponse, error) { }, nil } -func filterAgentSupportFiles(files []SupportFile) []SupportFile { - if len(files) == 0 { - return nil - } - filtered := make([]SupportFile, 0, len(files)) - for _, file := range files { - path := strings.ToLower(strings.TrimSpace(file.Path)) - switch { - case strings.HasSuffix(path, ".crt"), strings.HasSuffix(path, ".key"), strings.HasSuffix(path, ".pem"): - filtered = append(filtered, file) - case path == "pow_config.json": - filtered = append(filtered, file) - } - } - return filtered -} - func ReportApplyLog(payload ApplyLogPayload) (*model.ApplyLog, error) { now := time.Now() payload.NodeID = strings.TrimSpace(payload.NodeID) diff --git a/openflare_server/service/agent_test.go b/openflare_server/service/agent_test.go index a7126050..35170cf7 100644 --- a/openflare_server/service/agent_test.go +++ b/openflare_server/service/agent_test.go @@ -43,6 +43,38 @@ func TestGetActiveConfigForAgentIncludesPoWConfig(t *testing.T) { } } +func TestGetActiveConfigForAgentIncludesWAFConfig(t *testing.T) { + setupServiceTestDB(t) + + _, err := CreateProxyRoute(ProxyRouteInput{ + Domain: "waf-agent.example.com", + OriginURL: "https://origin.internal", + Enabled: true, + }) + if err != nil { + t.Fatalf("CreateProxyRoute failed: %v", err) + } + + if _, err := PublishConfigVersion("root", false); err != nil { + t.Fatalf("PublishConfigVersion failed: %v", err) + } + + activeConfig, err := GetActiveConfigForAgent() + if err != nil { + t.Fatalf("GetActiveConfigForAgent failed: %v", err) + } + + for _, file := range activeConfig.SupportFiles { + if file.Path == "waf_config.json" { + if !strings.Contains(file.Content, `"rule_groups"`) { + t.Fatalf("expected waf_config.json content to include rule groups, got %s", file.Content) + } + return + } + } + t.Fatal("expected agent config to include waf_config.json support file") +} + func TestGetActiveConfigForAgentUsesTenMinutePoWSessionDefault(t *testing.T) { setupServiceTestDB(t)