Add FINGER_BAN_ALLOWLIST to exempt trusted front-end IPs from banning
CI / Build and Test (gcc, g++, ubuntu-latest) (push) Failing after 5m2s
CI / Code Coverage (push) Skipped
Build and Publish Docker Image / build-and-test (push) Failing after 6m13s
Build and Publish Docker Image / build-and-push-image (push) Skipped
Build and Publish Docker Image / security-scan (push) Skipped
CI / Build and Test (gcc, g++, ubuntu-latest) (push) Failing after 5m2s
CI / Code Coverage (push) Skipped
Build and Publish Docker Image / build-and-test (push) Failing after 6m13s
Build and Publish Docker Image / build-and-push-image (push) Skipped
Build and Publish Docker Image / security-scan (push) Skipped
The per-IP ban tracker treats every globally-routable client equally, but an aggregating front-end like the finger-web proxy funnels the whole internet's federated lookups through a single IP. A burst from any one client of the proxy (or a load test) is then attributed to the proxy's IP and, once it crosses the failure threshold, the daemon blocks the proxy — taking out finger lookups for everyone. Per-client abuse protection for the proxied path belongs in the proxy (which now rate-limits per real client IP), so the daemon should trust it. Add a FINGER_BAN_ALLOWLIST env var (comma-separated IPs). Allowlisted addresses are marked non-trackable in the listener, so their connections are never blocked and never recorded as offenses. Unset = unchanged behaviour. - parse_ip_allowlist() in ban.cpp (trims entries, skips blanks) + unit tests - listener() consults the set when computing 'trackable' - documented in docker-compose.yml and DOCKER.md
This commit is contained in:
@@ -5,7 +5,9 @@
|
||||
#include <cstddef>
|
||||
#include <deque>
|
||||
#include <string>
|
||||
#include <string_view>
|
||||
#include <unordered_map>
|
||||
#include <unordered_set>
|
||||
|
||||
// BanTracker records the timestamps of "offenses" -- requests that are
|
||||
// obviously not finger queries -- per client IP, over a rolling time window.
|
||||
@@ -73,3 +75,16 @@ private:
|
||||
// where pf rdr preserves it) and inert where it is not (Docker bridge), with no
|
||||
// deployment-specific configuration.
|
||||
bool is_bannable_address(const boost::asio::ip::address &addr);
|
||||
|
||||
// Parse a comma-separated list of IP addresses (the value of the
|
||||
// FINGER_BAN_ALLOWLIST env var) into a set of address strings. Whitespace
|
||||
// around each entry is trimmed and empty entries are skipped. The strings are
|
||||
// matched verbatim against boost::asio's address().to_string() output, so use
|
||||
// canonical forms (e.g. "147.182.255.203", "2a01:4f8:190:7447::2").
|
||||
//
|
||||
// Allowlisting exists for trusted aggregating front-ends — notably the
|
||||
// finger-web proxy, which funnels every federated lookup through one IP. Without
|
||||
// it, a burst from any single client of the proxy is attributed to the proxy's
|
||||
// IP and bans the proxy for everyone; per-client abuse protection for that path
|
||||
// lives in the proxy instead.
|
||||
std::unordered_set<std::string> parse_ip_allowlist(std::string_view csv);
|
||||
|
||||
Reference in New Issue
Block a user