policy

package
v1.27.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 10, 2026 License: MIT Imports: 26 Imported by: 0

Documentation

Index

Constants

View Source
const LogRotateTimeFormat = "2006-01-02T15-04-05Z0700"

LogRotateTimeFormat is the timestamp a rotated log file is named after.

It is RFC 3339 with the colons taken out. Windows reads a colon in a path as the separator before an alternate data stream, so a name containing one cannot be created: rotation would fail with ERROR_INVALID_NAME every time, and because the rotating logger has already closed the file by then, every subsequent line would cost another close, open and doomed rename while the log grew past its limit without bound.

The other characters Windows forbids in a name are < > " / \ | ? *, none of which a time format produces. A rotated log file is a backup rather than an interchange format, so nothing parses this.

Variables

View Source
var (
	Applications = promauto.NewCounterVec(prometheus.CounterOpts{
		Name: "anubis_policy_results",
		Help: "The results of each policy rule",
	}, []string{"rule", "action", "asn", "asn_description"})

	ErrChallengeRuleHasWrongAlgorithm = errors.New("config.Bot.ChallengeRules: algorithm is invalid")
)
View Source
var (
	ErrMisconfiguration = errors.New("[unexpected] policy: administrator misconfiguration")
)

Functions

func NewHeaderExistsChecker

func NewHeaderExistsChecker(key string) checker.Impl

func NewHeaderMatchesChecker

func NewHeaderMatchesChecker(header, rexStr string) (checker.Impl, error)

func NewHeadersChecker

func NewHeadersChecker(headermap map[string]string) (checker.Impl, error)

func NewPathChecker

func NewPathChecker(rexStr string, subrequestMode bool) (checker.Impl, error)

func NewRemoteAddrChecker

func NewRemoteAddrChecker(cidrs []string) (checker.Impl, error)

func NewUserAgentChecker

func NewUserAgentChecker(rexStr string) (checker.Impl, error)

Types

type Bot

type Bot struct {
	Rules     checker.Impl
	Challenge *config.ChallengeRules
	Weight    *config.Weight
	Name      string

	Action config.Rule
	// contains filtered or unexported fields
}

func (Bot) Hash

func (b Bot) Hash() string

Hash returns a stable identifier for this Bot derived from its Name and Rules. When the cached value is present (populated by ParseConfig) it is returned directly; otherwise the hash is recomputed on demand so callers do not have to know about the cache.

type CELChecker

type CELChecker struct {
	// contains filtered or unexported fields
}

func NewCELChecker

func NewCELChecker(cfg *config.ExpressionOrList, dnsObj *dns.Dns, subRequestMode bool) (*CELChecker, error)

func (*CELChecker) Check

func (cc *CELChecker) Check(r *http.Request) (bool, error)

func (*CELChecker) Hash

func (cc *CELChecker) Hash() string

type CELRequest

type CELRequest struct {
	*http.Request
	// contains filtered or unexported fields
}

func (*CELRequest) Parent

func (cr *CELRequest) Parent() cel.Activation

func (*CELRequest) ResolveName

func (cr *CELRequest) ResolveName(name string) (any, bool)

type CheckResult

type CheckResult struct {
	Name   string
	Rule   config.Rule
	Weight int
}

func (CheckResult) LogValue

func (cr CheckResult) LogValue() slog.Value

type HeaderMatchesChecker

type HeaderMatchesChecker struct {
	// contains filtered or unexported fields
}

func (*HeaderMatchesChecker) Check

func (hmc *HeaderMatchesChecker) Check(r *http.Request) (bool, error)

func (*HeaderMatchesChecker) Hash

func (hmc *HeaderMatchesChecker) Hash() string

type ParsedConfig

type ParsedConfig struct {
	Store store.Interface

	Impressum         *config.Impressum
	Honeypot          *config.Honeypot
	OpenGraph         config.OpenGraph
	Bots              []Bot
	Thresholds        []*Threshold
	StatusCodes       config.StatusCodes
	DefaultDifficulty int
	DNSBL             bool
	DnsCache          *dns.DnsCache
	Dns               *dns.Dns
	Logger            *slog.Logger
	Metrics           *config.Metrics
	ThothClient       *thoth.Client
	LogASN            bool
	NeedJA4H          bool
	// contains filtered or unexported fields
}

func ParseConfig

func ParseConfig(ctx context.Context, fin io.Reader, fname string, defaultDifficulty int, logLevel string, subrequestMode bool) (*ParsedConfig, error)

type PathChecker

type PathChecker struct {
	// contains filtered or unexported fields
}

func (*PathChecker) Check

func (pc *PathChecker) Check(r *http.Request) (bool, error)

func (*PathChecker) Hash

func (pc *PathChecker) Hash() string

type RemoteAddrChecker

type RemoteAddrChecker struct {
	// contains filtered or unexported fields
}

func (*RemoteAddrChecker) Check

func (rac *RemoteAddrChecker) Check(r *http.Request) (bool, error)

func (*RemoteAddrChecker) Hash

func (rac *RemoteAddrChecker) Hash() string

type Threshold

type Threshold struct {
	config.Threshold
	Program cel.Program
}

func ParsedThresholdFromConfig

func ParsedThresholdFromConfig(t config.Threshold) (*Threshold, error)

type ThresholdRequest

type ThresholdRequest struct {
	Weight int
}

func (*ThresholdRequest) Parent

func (tr *ThresholdRequest) Parent() cel.Activation

func (*ThresholdRequest) ResolveName

func (tr *ThresholdRequest) ResolveName(name string) (any, bool)

Directories

Path Synopsis
Package checker defines the Checker interface and a helper utility to avoid import cycles.
Package checker defines the Checker interface and a helper utility to avoid import cycles.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL