mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-09-02 20:28:50 +02:00
Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b6a0404efd | ||
|
|
a0e701f985 |
@@ -529,7 +529,7 @@ http:
|
|||||||
captchaSecretKey: FIXME
|
captchaSecretKey: FIXME
|
||||||
captchaGracePeriodSeconds: 1800
|
captchaGracePeriodSeconds: 1800
|
||||||
captchaHTMLFilePath: /captcha.html
|
captchaHTMLFilePath: /captcha.html
|
||||||
banHTMLFilePath: ban.html
|
banHTMLFilePath: /ban.html
|
||||||
```
|
```
|
||||||
|
|
||||||
#### Fill variable with value of file
|
#### Fill variable with value of file
|
||||||
|
|||||||
+3
-1
@@ -28,6 +28,7 @@ const (
|
|||||||
crowdsecAppsecHostHeader = "X-Crowdsec-Appsec-Host"
|
crowdsecAppsecHostHeader = "X-Crowdsec-Appsec-Host"
|
||||||
crowdsecAppsecVerbHeader = "X-Crowdsec-Appsec-Verb"
|
crowdsecAppsecVerbHeader = "X-Crowdsec-Appsec-Verb"
|
||||||
crowdsecAppsecHeader = "X-Crowdsec-Appsec-Api-Key"
|
crowdsecAppsecHeader = "X-Crowdsec-Appsec-Api-Key"
|
||||||
|
crowdsecAppsecUserAgent = "X-Crowdsec-Appsec-User-Agent"
|
||||||
crowdsecLapiHeader = "X-Api-Key"
|
crowdsecLapiHeader = "X-Api-Key"
|
||||||
crowdsecLapiRoute = "v1/decisions"
|
crowdsecLapiRoute = "v1/decisions"
|
||||||
crowdsecLapiStreamRoute = "v1/decisions/stream"
|
crowdsecLapiStreamRoute = "v1/decisions/stream"
|
||||||
@@ -586,7 +587,8 @@ func appsecQuery(bouncer *Bouncer, ip string, httpReq *http.Request) error {
|
|||||||
req.Header.Set(crowdsecAppsecIPHeader, ip)
|
req.Header.Set(crowdsecAppsecIPHeader, ip)
|
||||||
req.Header.Set(crowdsecAppsecVerbHeader, httpReq.Method)
|
req.Header.Set(crowdsecAppsecVerbHeader, httpReq.Method)
|
||||||
req.Header.Set(crowdsecAppsecHostHeader, httpReq.Host)
|
req.Header.Set(crowdsecAppsecHostHeader, httpReq.Host)
|
||||||
req.Header.Set(crowdsecAppsecURIHeader, httpReq.URL.Path)
|
req.Header.Set(crowdsecAppsecURIHeader, httpReq.URL.String())
|
||||||
|
req.Header.Set(crowdsecAppsecUserAgent, httpReq.Header.Get("User-Agent"))
|
||||||
|
|
||||||
res, err := bouncer.httpClient.Do(req)
|
res, err := bouncer.httpClient.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
+1
-1
@@ -12,7 +12,7 @@ services:
|
|||||||
- "--entrypoints.web.address=:80"
|
- "--entrypoints.web.address=:80"
|
||||||
|
|
||||||
- "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
- "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||||
- "--experimental.plugins.bouncer.version=v1.3.0-beta1"
|
- "--experimental.plugins.bouncer.version=v1.3.0-beta3"
|
||||||
volumes:
|
volumes:
|
||||||
- "/var/run/docker.sock:/var/run/docker.sock:ro"
|
- "/var/run/docker.sock:/var/run/docker.sock:ro"
|
||||||
# - './ban.html:/ban.html:ro'
|
# - './ban.html:/ban.html:ro'
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ This can be usefull as some browser (Firefox for instance) return a 403 blank we
|
|||||||
```yaml
|
```yaml
|
||||||
labels:
|
labels:
|
||||||
# Define ban HTML file path
|
# Define ban HTML file path
|
||||||
- "traefik.http.middlewares.crowdsec.plugin.bouncer.captchaHTMLFilePath=/ban.html"
|
- "traefik.http.middlewares.crowdsec.plugin.bouncer.banHtmlFilePath=/ban.html"
|
||||||
```
|
```
|
||||||
|
|
||||||
The ban HTML file must be present in the Traefik container (bind mounted or added during a custom build).
|
The ban HTML file must be present in the Traefik container (bind mounted or added during a custom build).
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ services:
|
|||||||
- "--entrypoints.web.address=:80"
|
- "--entrypoints.web.address=:80"
|
||||||
|
|
||||||
# - "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
# - "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||||
# - "--experimental.plugins.bouncer.version=v1.2.0"
|
# - "--experimental.plugins.bouncer.version=v1.3.0-beta3"
|
||||||
- "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
- "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
|||||||
Reference in New Issue
Block a user