ryan
aa4faddade
补齐 131 个 .go 文件的 SPDX license 头(repo 自带 make license 约定,早于约定新增的文件含 2 个生产文件;纯注释插入零行为影响),make license-check 转绿。go mod tidy -diff 确认干净。
...
Result: {"status":"keep","total_issues":8,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":8,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_usetesting":0,"golint_test_total":0,"golint_vetx_total":0,"eslint_problems":0,"eslint_errors":0,"eslint_warnings":0,"tsc_errors":0,"vitest_failed":0,"vitest_total":116,"measure_s":81}
2026-08-16 20:09:24 +08:00
ryan
86fad02c41
errorlint 12→1:3 处 cmd 入口 err!=context.Canceled→errors.Is(防御性,当前 runner 不 wrap 语义不变);2 处 strconv.NumError 断言、1 处 viper 断言、2 处 ==io.EOF、2 处 ==redis.Nil、1 处 ==gorm.ErrRecordNotFound→errors.As/Is;8 处 %v→%w 保留错误链。刻意保留 telegram.go 单处 %v(原始错误仅作上下文文本,wrap 会改变 errors.Is 匹配语义)。
...
Result: {"status":"keep","total_issues":22,"golint_canonicalheader":0,"golint_errname":1,"golint_errorlint":1,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":21,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":46}
2026-08-16 17:52:03 +08:00
ryan
699e95f12c
perfsprint 18→0:strconv.Itoa/FormatInt/FormatUint/FormatBool 替代 fmt.Sprintf、无动词 fmt.Errorf→errors.New、纯字符串拼接。全部语义等价(已核对 diff)。修正 fixer 遗留的 import 问题(引入 goimports 统一整理)。
...
Result: {"status":"keep","total_issues":56,"golint_canonicalheader":8,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":3,"golint_modernize":5,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":3,"golint_wastedassign":7,"golint_total":55,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":47}
2026-08-16 17:34:44 +08:00
ryan
0c22e76f4b
fix(frontend): optimization
2026-08-09 09:14:54 +08:00
ryan
6487ce666d
fix(security): harden PoW XSS, email header injection and UptimeKuma log redaction
2026-08-08 21:52:46 +08:00
Ryan
074edf17a1
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-08-08 20:30:36 +08:00
ryan
ca21ff3a5b
feat(option): add sw offline
...
fix(openresty): scope sw injection per cert partition
fix(lint): satisfy revive and biome format for sw offline feature
docs: sw offline scope changelog
fix(frontend): use scoped query key for sw scope zones
fix(frontend): hide preview link in sw contact page editor
feat(frontend): add sw scope domain picker and contact page fields
refactor(frontend): generalize html editor workspace for reuse
feat(openresty): scope sw offline injection by route domains
feat(openresty): add sw offline domains snapshot field
feat(option): add sw offline domains scope option
docs: fill html editor workspace generalization detail
docs: sw offline scope implementation plan
docs: sw offline scope design
test(openresty): assert single merged access block in sw enabled servers
fix(openresty): restrict sw intercept to https server blocks
fix(openresty): version sw offline cache by html content
fix(agent): escape redir in sw challenge page to prevent xss
fix(agent): return sw.runtime module table and add lua spec
docs: sw offline fallback changelog
fix(frontend): memoize option map to preserve unsaved contact page edits
feat(frontend): add response pages module with contact page tab
feat(agent): ship sw offline lua assets and placeholder substitution
feat(config): wire sw offline options into config snapshot
feat(openresty): render sw offline assets and challenge intercept
feat(openresty): add sw offline ConfigSnapshot fields and placeholder
feat(db): seed sw offline options
feat(option): add sw offline config keys and validation
docs: add service worker offline fallback implementation plan
docs: adopt global-option pattern for SW offline fallback (matches origin error page)
docs: unify offline contact page with error pages as response pages
docs: service worker offline fallback design (issue #23 )
2026-08-08 20:14:28 +08:00
ryan
68d8f786cc
feat(openresty): render origin error page directives
...
Wire origin error page into OpenResty proxy route rendering: ConfigSnapshot
fields, default HTML template SupportFile, proxy_intercept_errors + error_page
with status-preserving internal Lua location, and Agent placeholder substitution
for __OPENFLARE_ERROR_PAGE_TMPL__. Pages routes are excluded.
2026-08-06 13:52:40 +08:00
ryan
d99c5b7c43
refactor(pkg): merge pkg/utils into pkg/util
...
Consolidate pure helper packages under pkg/util and update imports.
2026-07-24 15:45:10 +08:00
ryan
7366832e12
fix(agent): 内嵌 resty.ipmatcher,移除无效 opm 依赖
...
OPM 无 api7/lua-resty-ipmatcher 账号导致镜像构建失败;改为 vendor
api7 v0.6.1 并随 ManagedWAFLuaFiles 部署到 lua 目录。
2026-07-19 14:57:51 +08:00
ryan
1a7e5e6c41
perf(waf): IP 匹配改为索引查询(ipmatcher / 预编译)
...
加载时编译 IP 组与节点 IP/CIDR 索引,优先 resty.ipmatcher 基数树,
否则 exact 哈希 + 预解析 CIDR,避免大名单线性扫描打满边缘 CPU。
2026-07-19 14:48:07 +08:00
ryan
46ce7de513
perf(waf): 收窄安全防护扫描面并优化 UA 热路径
...
注入类检测仅扫 Query/Cookie/Referer/有限 Body,避免全 Header 匹配拖垮边缘 CPU;
按开关采集输入、GET 跳过 read_body,UA 仅 lower 一次并用 set 匹配白名单。
2026-07-19 14:16:34 +08:00
ryan
ad6621fce9
fix(waf): 收紧安全防护特征,降低常见正常请求误伤
...
- SSRF 仅匹配 URL 形态,避免 Chrome/x.0.0.0 误中
- 命令注入去掉裸 &&/|| 与裸 shell 名
- SQL sleep/benchmark 要求数字参数
- XSS javascript:/eval 要求更像代码的上下文
- 路径穿越去掉过宽的 c:\windows;CRLF 去掉单独 %0a/%0d
2026-07-19 12:54:01 +08:00
ryan
1ba05ec0bd
fix(waf): 避免 SQL 特征 /* */ 误匹配 Accept: */*
...
开启 SQL 注入防护时不再把正常 Accept 头当成攻击。
2026-07-19 12:46:23 +08:00
ryan
b75f985815
feat(waf): 新增安全防护节点 security_check
...
基础特征检测九项可开关;默认开启路径穿越与文件包含;命中任意规则走 false。
2026-07-19 12:33:13 +08:00
ryan
d47ceb9971
feat(waf): UA 非正常不含爬虫,并支持自定义正则屏蔽
...
block_abnormal_ua 仅 Other/Unknown;新增 block_custom_ua 与 custom_ua_patterns。
2026-07-19 11:43:45 +08:00
ryan
28eef0bbcd
feat(waf): 新增 UA 检查节点 ua_check
...
支持要求携带 UA、浏览器/OS 白名单 and-or 匹配,以及优先屏蔽爬虫与非正常 UA。
2026-07-19 11:35:31 +08:00
ryan
f0e234df1f
feat(obs): 访问日志 SSOT 与 edge_health,去掉协议兼容层
...
Agent 仅上报 host_metrics/edge_health/access_logs;业务流量与 UV 由
Server 侧访问日志聚合。新增 of_node_edge_health 与 of_access_log_hourly,
删除 request_reports/openresty 吞吐路径;API 不再暴露 traffic_reports
与 openresty_rx|tx。心跳/离线默认阈值与回填迁移一并入库。
2026-07-18 11:53:11 +08:00
ryan
15e614b304
fix(waf): pow
2026-07-13 17:07:49 +08:00
ryan
46941f65d5
fix(waf): handle empty rule bindings
...
Encode empty site bindings as arrays and normalize legacy JSON null values in the OpenResty runtime to prevent request-time Lua failures.
2026-07-13 16:49:55 +08:00
ryan
1eff7878a1
prettier
2026-07-13 15:10:28 +08:00
ryan
a1a997bcda
feat(waf): complete composable rule orchestration
...
Add the React Flow rule editor, ordered graph APIs and runtime DAG execution.\n\nPublish rules only on OpenResty reload and reconcile checksum-driven IP group snapshots in bounded shared memory.
2026-07-13 14:17:15 +08:00
ryan
b89dc9ec7e
fix(waf): correct whitelist logic to bypass and add config/IP-group edit broadcasts
...
- Transition WAF whitelist filter from strict block-on-miss to bypass-on-hit logic
- Hook up broadcastIPGroupToAgents to CreateIPGroup and UpdateIPGroup WAF logics
- Hook up BroadcastActiveConfig to PublishConfigVersion and ActivateConfigVersion version logics
- Update WAF Lua tests in manager_test.go
2026-06-26 20:47:30 +08:00
ryan
49eae80c78
修复目录权限问题
2026-06-22 23:21:04 +08:00
ryan
895dec208f
fix(agent): write nginx pid and temp dirs under data_dir for non-root runtime
...
OpenResty running as openflare can no longer write pid or client/proxy temp
paths under the OpenResty install prefix. Templates and apply-time rendering
now use __OPENFLARE_PID_PATH__ and __OPENFLARE_NGINX_CACHE_DIR__ under
data_dir/var/run and data_dir/var/cache/nginx, with legacy pid path patched
at apply. Consolidate runtimeuser path helpers into the main package file so
IDEs resolve references across build tags.
2026-06-21 14:40:10 +08:00
ryan
40291136b7
fix(openresty): disable server version disclosure in main config template
...
Add server_tokens off to the default OpenResty main config template, seeded
option template, and agent safe fallback config so responses no longer
expose nginx/OpenResty version numbers in Server headers or error pages.
2026-06-21 14:25:32 +08:00
ryan
d3777eac2d
fix(agent): unify agent and openresty runtime user as openflare
...
Introduce the shared openflare service account for the agent process and
OpenResty workers, normalize data_dir ownership on startup, and ensure
managed paths are chowned with 0755/0644 during sync and apply. Docker
entrypoint fixes volume ownership before dropping privileges; local systemd
install runs the service as openflare with CAP_NET_BIND_SERVICE.
2026-06-21 14:25:20 +08:00
ryan
a343c7a605
fix: 修复 Agent 使用 volume 映射时 PoW/WAF 运行时配置无法加载
2026-06-21 10:15:18 +08:00
ryan
117d473c27
fix: 修复 WAF 规则组保存/绑定网站时报 of_waf_rule_group_bindings_pkey 冲突
2026-06-20 22:05:30 +08:00
ryan
889e79c8b8
fix: 收敛子代理站点标识双轨逻辑
2026-06-20 21:03:13 +08:00
ryan
32861c5db9
fix lint
2026-06-19 17:20:39 +08:00
ryan
63cd906cfc
refactor(repo): consolidate openflare-server to root and move subprojects to internal/apps
...
- Merge all files inside openflare-server to the repository root directory.
- Relocate agent, relay, and flared subprojects from internal/ to internal/apps/.
- Combine docker-compose files and update build context paths to root.
- Update GitHub workflows and Dockerfiles to refer to new directories and package names.
- Rewrite Go package imports across all files.
- Resolve database renew test race condition and clean up docs.
2026-06-19 14:23:29 +08:00