mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-07-21 11:38:59 +02:00
✨ Implement captcha protection (#139)
* ✨ Implement captcha protection * 🍱 fix lint * 🍱 fix lint * 🍱 fix lint * 📝 Update exemple doc Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Add doc for the captcha and update some exemples Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Update doc readme with some arguments Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Update doc Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 generic documentation in readme on catpcha feature Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Update exemple captcha Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Fix rendering and typos Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 🍱 fix readme * 📝 update doc ongoing Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Add doc on crowdsec config Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Add sequence diagram for captcha exemple Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * Fix rendering and typos Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 add mermaid basics graphs Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Update first diagram Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Update first seq diagram Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 🐛 Fix bug in diagram syntax Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 rework all diagrams Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 📝 Update a bit diagrams Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> * 🌐 Fix lang fr * 🚸 change advice on uniq lapi confusing for users * ✅ Fix test du to rework on cache interface * 🚨 Fix lint --------- Signed-off-by: Mathieu Hanotaux <mathieu@hanotaux.fr> Co-authored-by: max.lerebourg <max.lerebourg@monisnap.com> Co-authored-by: Mathieu Hanotaux <mathieu@hanotaux.fr>
This commit is contained in:
co-authored by
max.lerebourg
Mathieu Hanotaux
parent
c3e0c2d4c3
commit
497d1a2928
Vendored
+48
-49
@@ -12,13 +12,18 @@ import (
|
||||
)
|
||||
|
||||
const (
|
||||
cacheBannedValue = "t"
|
||||
cacheNoBannedValue = "f"
|
||||
// BannedValue Banned string.
|
||||
BannedValue = "t"
|
||||
// NoBannedValue No banned string.
|
||||
NoBannedValue = "f"
|
||||
// CaptchaValue Need captcha string.
|
||||
CaptchaValue = "c"
|
||||
// CaptchaDoneValue Captcha done string.
|
||||
CaptchaDoneValue = "d"
|
||||
// CacheMiss error string when cache is miss.
|
||||
CacheMiss = "cache:miss"
|
||||
)
|
||||
|
||||
// CacheMiss error string when cache is miss.
|
||||
const CacheMiss = "cache:miss"
|
||||
|
||||
//nolint:gochecknoglobals
|
||||
var (
|
||||
redis simpleredis.SimpleRedis
|
||||
@@ -27,55 +32,55 @@ var (
|
||||
|
||||
type localCache struct{}
|
||||
|
||||
func (localCache) getDecision(clientIP string) (bool, error) {
|
||||
banned, isCached := cache.Get(clientIP)
|
||||
bannedString, isValid := banned.(string)
|
||||
if isCached && isValid && len(bannedString) > 0 {
|
||||
return bannedString == cacheBannedValue, nil
|
||||
func (localCache) get(key string) (string, error) {
|
||||
value, isCached := cache.Get(key)
|
||||
valueString, isValid := value.(string)
|
||||
if isCached && isValid && len(valueString) > 0 {
|
||||
return valueString, nil
|
||||
}
|
||||
return false, fmt.Errorf(CacheMiss)
|
||||
return "", fmt.Errorf(CacheMiss)
|
||||
}
|
||||
|
||||
func (localCache) setDecision(clientIP string, value string, duration int64) {
|
||||
cache.Set(clientIP, value, duration)
|
||||
func (localCache) set(key, value string, duration int64) {
|
||||
cache.Set(key, value, duration)
|
||||
}
|
||||
|
||||
func (localCache) deleteDecision(clientIP string) {
|
||||
cache.Del(clientIP)
|
||||
func (localCache) delete(key string) {
|
||||
cache.Del(key)
|
||||
}
|
||||
|
||||
type redisCache struct {
|
||||
log *logger.Log
|
||||
}
|
||||
|
||||
func (redisCache) getDecision(clientIP string) (bool, error) {
|
||||
banned, err := redis.Get(clientIP)
|
||||
bannedString := string(banned)
|
||||
if err == nil && len(bannedString) > 0 {
|
||||
return bannedString == cacheBannedValue, nil
|
||||
func (redisCache) get(key string) (string, error) {
|
||||
value, err := redis.Get(key)
|
||||
valueString := string(value)
|
||||
if err == nil && len(valueString) > 0 {
|
||||
return valueString, nil
|
||||
}
|
||||
if err.Error() == simpleredis.RedisMiss {
|
||||
return false, fmt.Errorf(CacheMiss)
|
||||
return "", fmt.Errorf(CacheMiss)
|
||||
}
|
||||
return false, err
|
||||
return "", err
|
||||
}
|
||||
|
||||
func (rc redisCache) setDecision(clientIP string, value string, duration int64) {
|
||||
if err := redis.Set(clientIP, []byte(value), duration); err != nil {
|
||||
func (rc redisCache) set(key, value string, duration int64) {
|
||||
if err := redis.Set(key, []byte(value), duration); err != nil {
|
||||
rc.log.Error(fmt.Sprintf("cache:setDecisionRedisCache %s", err.Error()))
|
||||
}
|
||||
}
|
||||
|
||||
func (rc redisCache) deleteDecision(clientIP string) {
|
||||
if err := redis.Del(clientIP); err != nil {
|
||||
func (rc redisCache) delete(key string) {
|
||||
if err := redis.Del(key); err != nil {
|
||||
rc.log.Error(fmt.Sprintf("cache:deleteDecisionRedisCache %s", err.Error()))
|
||||
}
|
||||
}
|
||||
|
||||
type cacheInterface interface {
|
||||
setDecision(clientIP string, value string, duration int64)
|
||||
getDecision(clientIP string) (bool, error)
|
||||
deleteDecision(clientIP string)
|
||||
set(key, value string, duration int64)
|
||||
get(key string) (string, error)
|
||||
delete(key string)
|
||||
}
|
||||
|
||||
// Client Cache client.
|
||||
@@ -84,8 +89,8 @@ type Client struct {
|
||||
log *logger.Log
|
||||
}
|
||||
|
||||
// Init Initialize cache client.
|
||||
func (c *Client) Init(log *logger.Log, isRedis bool, host, pass, database string) {
|
||||
// New Initialize cache client.
|
||||
func (c *Client) New(log *logger.Log, isRedis bool, host, pass, database string) {
|
||||
c.log = log
|
||||
if isRedis {
|
||||
redis.Init(host, pass, database)
|
||||
@@ -96,27 +101,21 @@ func (c *Client) Init(log *logger.Log, isRedis bool, host, pass, database string
|
||||
c.log.Debug(fmt.Sprintf("cache:New initialized isRedis:%v", isRedis))
|
||||
}
|
||||
|
||||
// DeleteDecision delete decision in cache.
|
||||
func (c *Client) DeleteDecision(clientIP string) {
|
||||
c.log.Debug(fmt.Sprintf("cache:DeleteDecision ip:%v", clientIP))
|
||||
c.cache.deleteDecision(clientIP)
|
||||
// Delete delete decision in cache.
|
||||
func (c *Client) Delete(key string) {
|
||||
c.log.Debug(fmt.Sprintf("cache:Delete key:%v", key))
|
||||
c.cache.delete(key)
|
||||
}
|
||||
|
||||
// GetDecision check in the cache if the IP has the banned / not banned value.
|
||||
// Get check in the cache if the IP has the banned / not banned value.
|
||||
// Otherwise return with an error to add the IP in cache if we are on.
|
||||
func (c *Client) GetDecision(clientIP string) (bool, error) {
|
||||
c.log.Debug(fmt.Sprintf("cache:GetDecision ip:%v", clientIP))
|
||||
return c.cache.getDecision(clientIP)
|
||||
func (c *Client) Get(key string) (string, error) {
|
||||
c.log.Debug(fmt.Sprintf("cache:Get key:%v", key))
|
||||
return c.cache.get(key)
|
||||
}
|
||||
|
||||
// SetDecision update the cache with the IP as key and the value banned / not banned.
|
||||
func (c *Client) SetDecision(clientIP string, isBanned bool, duration int64) {
|
||||
c.log.Debug(fmt.Sprintf("cache:SetDecision ip:%v isBanned:%v duration:%vs", clientIP, isBanned, duration))
|
||||
var value string
|
||||
if isBanned {
|
||||
value = cacheBannedValue
|
||||
} else {
|
||||
value = cacheNoBannedValue
|
||||
}
|
||||
c.cache.setDecision(clientIP, value, duration)
|
||||
// Set update the cache with the IP as key and the value banned / not banned.
|
||||
func (c *Client) Set(key string, value string, duration int64) {
|
||||
c.log.Debug(fmt.Sprintf("cache:Set key:%v value:%v duration:%vs", key, value, duration))
|
||||
c.cache.set(key, value, duration)
|
||||
}
|
||||
|
||||
Vendored
+54
-34
@@ -8,97 +8,117 @@ import (
|
||||
logger "github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin/pkg/logger"
|
||||
)
|
||||
|
||||
func Test_GetDecision(t *testing.T) {
|
||||
func Test_Get(t *testing.T) {
|
||||
IPInCache := "10.0.0.10"
|
||||
IPNotInCache := "10.0.0.20"
|
||||
client := &Client{cache: &localCache{}, log: logger.New("INFO")}
|
||||
client.SetDecision(IPInCache, true, 10)
|
||||
client.Set(IPInCache, BannedValue, 10)
|
||||
type args struct {
|
||||
clientIP string
|
||||
}
|
||||
tests := []struct {
|
||||
name string
|
||||
args args
|
||||
want bool
|
||||
want string
|
||||
wantErr bool
|
||||
valueErr string
|
||||
}{
|
||||
{name: "Fetch Known valid IP", args: args{clientIP: IPInCache}, want: true, wantErr: false, valueErr: ""},
|
||||
{name: "Fetch Unknown valid IP", args: args{clientIP: IPNotInCache}, want: false, wantErr: true, valueErr: "cache:miss"},
|
||||
{name: "Fetch invalid value", args: args{clientIP: "test"}, want: false, wantErr: true, valueErr: "cache:miss"},
|
||||
{name: "Fetch empty value", args: args{clientIP: ""}, want: false, wantErr: true, valueErr: "cache:miss"},
|
||||
{name: "Fetch Known valid IP", args: args{clientIP: IPInCache}, want: BannedValue, wantErr: false, valueErr: ""},
|
||||
{name: "Fetch Unknown valid IP", args: args{clientIP: IPNotInCache}, want: "", wantErr: true, valueErr: CacheMiss},
|
||||
{name: "Fetch invalid value", args: args{clientIP: "test"}, want: "", wantErr: true, valueErr: CacheMiss},
|
||||
{name: "Fetch empty value", args: args{clientIP: ""}, want: "", wantErr: true, valueErr: CacheMiss},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
got, err := client.GetDecision(tt.args.clientIP)
|
||||
got, err := client.Get(tt.args.clientIP)
|
||||
if (err != nil) != tt.wantErr {
|
||||
t.Errorf("GetDecision() error = %v, wantErr %v", err, tt.wantErr)
|
||||
t.Errorf("Get() error = %v, wantErr %v", err, tt.wantErr)
|
||||
return
|
||||
}
|
||||
if got != tt.want {
|
||||
t.Errorf("GetDecision() = %v, want %v", got, tt.want)
|
||||
t.Errorf("Get() = %v, want %v", got, tt.want)
|
||||
return
|
||||
}
|
||||
if tt.valueErr != "" && tt.valueErr != err.Error() {
|
||||
t.Errorf("GetDecision() err = %v, want %v", err.Error(), tt.valueErr)
|
||||
t.Errorf("Get() err = %v, want %v", err.Error(), tt.valueErr)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func Test_SetDecision(t *testing.T) {
|
||||
func Test_Set(t *testing.T) {
|
||||
client := &Client{cache: &localCache{}, log: logger.New("INFO")}
|
||||
IPInCache := "10.0.0.11"
|
||||
type args struct {
|
||||
clientIP string
|
||||
value bool
|
||||
value string
|
||||
duration int64
|
||||
}
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
args args
|
||||
want bool
|
||||
name string
|
||||
args args
|
||||
want string
|
||||
wantErr bool
|
||||
valueErr string
|
||||
}{
|
||||
{name: "Set valid IP in local cache for 0 sec", args: args{clientIP: IPInCache, value: true, duration: 0}, want: false},
|
||||
{name: "Set valid IP in local cache for 10 sec", args: args{clientIP: IPInCache, value: true, duration: 10}, want: true},
|
||||
{name: "Set valid IP in local cache for 10 sec", args: args{clientIP: IPInCache, value: false, duration: 10}, want: false},
|
||||
{name: "Set valid IP in local cache for 0 sec", args: args{clientIP: IPInCache, value: BannedValue, duration: 0}, want: "", wantErr: true, valueErr: CacheMiss},
|
||||
{name: "Set valid IP in local cache for 10 sec", args: args{clientIP: IPInCache, value: BannedValue, duration: 10}, want: BannedValue, wantErr: false, valueErr: ""},
|
||||
{name: "Set valid IP in local cache for 10 sec", args: args{clientIP: IPInCache, value: NoBannedValue, duration: 10}, want: NoBannedValue, wantErr: false, valueErr: ""},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
client.SetDecision(tt.args.clientIP, tt.args.value, tt.args.duration)
|
||||
got, _ := client.GetDecision(tt.args.clientIP)
|
||||
if got != tt.want {
|
||||
t.Errorf("SetDecision() = %v, want %v", got, tt.want)
|
||||
client.Set(tt.args.clientIP, tt.args.value, tt.args.duration)
|
||||
got, err := client.Get(tt.args.clientIP)
|
||||
if (err != nil) != tt.wantErr {
|
||||
t.Errorf("Set() error = %v, wantErr %v", err, tt.wantErr)
|
||||
return
|
||||
}
|
||||
if got != tt.want {
|
||||
t.Errorf("Set() = %v, want %v", got, tt.want)
|
||||
return
|
||||
}
|
||||
if tt.valueErr != "" && tt.valueErr != err.Error() {
|
||||
t.Errorf("Set() err = %v, want %v", err.Error(), tt.valueErr)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func Test_DeleteDecision(t *testing.T) {
|
||||
func Test_Delete(t *testing.T) {
|
||||
IPInCache := "10.0.0.12"
|
||||
IPNotInCache := "10.0.0.22"
|
||||
client := &Client{cache: &localCache{}, log: logger.New("INFO")}
|
||||
client.SetDecision(IPInCache, true, 10)
|
||||
client.Set(IPInCache, BannedValue, 10)
|
||||
type args struct {
|
||||
clientIP string
|
||||
}
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
args args
|
||||
want bool
|
||||
name string
|
||||
args args
|
||||
want string
|
||||
wantErr bool
|
||||
valueErr string
|
||||
}{
|
||||
{name: "Delete Known valid IP", args: args{clientIP: IPInCache}, want: false},
|
||||
{name: "Delete Unknown valid IP", args: args{clientIP: IPNotInCache}, want: false},
|
||||
{name: "Delete Known valid IP", args: args{clientIP: IPInCache}, want: "", wantErr: true, valueErr: CacheMiss},
|
||||
{name: "Delete Unknown valid IP", args: args{clientIP: IPNotInCache}, want: "", wantErr: true, valueErr: CacheMiss},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
client.DeleteDecision(tt.args.clientIP)
|
||||
got, _ := client.GetDecision(tt.args.clientIP)
|
||||
if got != tt.want {
|
||||
t.Errorf("DeleteDecision() = %v, want %v", got, tt.want)
|
||||
client.Delete(tt.args.clientIP)
|
||||
got, err := client.Get(tt.args.clientIP)
|
||||
if (err != nil) != tt.wantErr {
|
||||
t.Errorf("Delete() error = %v, wantErr %v", err, tt.wantErr)
|
||||
return
|
||||
}
|
||||
if got != tt.want {
|
||||
t.Errorf("Delete() = %v, want %v", got, tt.want)
|
||||
return
|
||||
}
|
||||
if tt.valueErr != "" && tt.valueErr != err.Error() {
|
||||
t.Errorf("Delete() err = %v, want %v", err.Error(), tt.valueErr)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user