Add FINGER_BAN_ALLOWLIST to exempt trusted front-end IPs from banning
CI / Build and Test (gcc, g++, ubuntu-latest) (push) Failing after 5m2s
CI / Code Coverage (push) Skipped
Build and Publish Docker Image / build-and-test (push) Failing after 6m13s
Build and Publish Docker Image / build-and-push-image (push) Skipped
Build and Publish Docker Image / security-scan (push) Skipped
CI / Build and Test (gcc, g++, ubuntu-latest) (push) Failing after 5m2s
CI / Code Coverage (push) Skipped
Build and Publish Docker Image / build-and-test (push) Failing after 6m13s
Build and Publish Docker Image / build-and-push-image (push) Skipped
Build and Publish Docker Image / security-scan (push) Skipped
The per-IP ban tracker treats every globally-routable client equally, but an aggregating front-end like the finger-web proxy funnels the whole internet's federated lookups through a single IP. A burst from any one client of the proxy (or a load test) is then attributed to the proxy's IP and, once it crosses the failure threshold, the daemon blocks the proxy — taking out finger lookups for everyone. Per-client abuse protection for the proxied path belongs in the proxy (which now rate-limits per real client IP), so the daemon should trust it. Add a FINGER_BAN_ALLOWLIST env var (comma-separated IPs). Allowlisted addresses are marked non-trackable in the listener, so their connections are never blocked and never recorded as offenses. Unset = unchanged behaviour. - parse_ip_allowlist() in ban.cpp (trims entries, skips blanks) + unit tests - listener() consults the set when computing 'trackable' - documented in docker-compose.yml and DOCKER.md
This commit is contained in:
@@ -119,6 +119,33 @@ TEST(BannableAddress, Ipv6Classification) {
|
||||
EXPECT_FALSE(bannable("fd12:3456::1")); // unique-local
|
||||
}
|
||||
|
||||
TEST(IpAllowlist, ParsesCommaSeparatedTrimmedEntries) {
|
||||
auto a = parse_ip_allowlist("147.182.255.203, 10.0.0.1 ,\t2a01:4f8:190:7447::2");
|
||||
EXPECT_EQ(a.size(), 3u);
|
||||
EXPECT_TRUE(a.count("147.182.255.203"));
|
||||
EXPECT_TRUE(a.count("10.0.0.1"));
|
||||
EXPECT_TRUE(a.count("2a01:4f8:190:7447::2"));
|
||||
}
|
||||
|
||||
TEST(IpAllowlist, SingleEntryNoCommas) {
|
||||
auto a = parse_ip_allowlist("147.182.255.203");
|
||||
EXPECT_EQ(a.size(), 1u);
|
||||
EXPECT_TRUE(a.count("147.182.255.203"));
|
||||
}
|
||||
|
||||
TEST(IpAllowlist, EmptyAndBlankYieldEmptySet) {
|
||||
EXPECT_TRUE(parse_ip_allowlist("").empty());
|
||||
EXPECT_TRUE(parse_ip_allowlist(" ").empty());
|
||||
EXPECT_TRUE(parse_ip_allowlist(",, ,\t,").empty()); // only separators/blanks
|
||||
}
|
||||
|
||||
TEST(IpAllowlist, IgnoresEmptyEntriesBetweenCommas) {
|
||||
auto a = parse_ip_allowlist("8.8.8.8,,9.9.9.9,");
|
||||
EXPECT_EQ(a.size(), 2u);
|
||||
EXPECT_TRUE(a.count("8.8.8.8"));
|
||||
EXPECT_TRUE(a.count("9.9.9.9"));
|
||||
}
|
||||
|
||||
int main(int argc, char **argv) {
|
||||
::testing::InitGoogleTest(&argc, argv);
|
||||
return RUN_ALL_TESTS();
|
||||
|
||||
Reference in New Issue
Block a user