ipwhitelist

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 10 Imported by: 0

README

IP Whitelist Middleware

What it does

Allows only configured client IPs or CIDR ranges. It is useful for admin routes, partner callbacks, and internal endpoints.

How to implement

package main

import (
	"github.com/oarkflow/fh"
	"github.com/oarkflow/fh/mw/ipwhitelist"
)

func main() {
	app := fh.New()
	app.Use(ipwhitelist.New("10.0.0.0/8", "127.0.0.1"))

	app.Get("/", func(c fh.Ctx) error {
		return c.Status(fh.StatusOK).SendString("ok")
	})
}

Impact

Low overhead. Blocks unauthorized networks before expensive processing.

Ordering guidance

Run early, after real IP/proxy header middleware if behind a trusted proxy.

Production considerations

Only trust forwarded headers from known proxies. Keep allowlists updated and include monitoring for denied requests.

File-backed store

By default Config.Allowed/Config.Blocked build a kv.NewMemoryStore. To manage a list from a file, create any kv.Store, call ipwhitelist.LoadFile(store, path), then pass it as Config.Store or Config.BlockStore. Use ipwhitelist.StartFileWatcher(store, path, reloadInterval) to poll for changes; a malformed edit is ignored and the last known-good list keeps serving.

Documentation

Index

Constants

This section is empty.

Variables

View Source
var ErrForbidden = errors.New("ipwhitelist: forbidden")

Functions

func AllowedIP

func AllowedIP(store kv.Store, ip net.IP) bool

func DefaultForbiddenHandler

func DefaultForbiddenHandler(ctx fh.Ctx) error

func LoadFile

func LoadFile(store kv.Store, path string) error

func New

func New(allowed ...string) fh.HandlerFunc

func NewWithConfig

func NewWithConfig(config Config) fh.HandlerFunc

func SaveList

func SaveList(store kv.Store, allowed ...string) error

func StartFileWatcher

func StartFileWatcher(store kv.Store, path string, interval time.Duration) (func(), error)

Types

type Config

type Config struct {
	Allowed []string
	Blocked []string

	Store      kv.Store
	BlockStore kv.Store

	KeyFunc KeyFunc

	Forbidden ForbiddenHandler
}

type ForbiddenHandler

type ForbiddenHandler func(ctx fh.Ctx) error

type KeyFunc

type KeyFunc func(ctx fh.Ctx) string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL