mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-07-21 03:28:59 +02:00
The `sleep 4` / `sleep 3` after a decision change were magic numbers tied to updateIntervalSeconds / defaultDecisionSeconds. Replace them with waits on the actual condition: - After a ban/unban, poll with wait_for_status until the expected code shows up (stream propagation / live-mode cache TTL). - Captcha keeps status 200 before and after, so gate on the body marker via a new wait_for_body_contains helper. - Control assertions that must NOT change stay immediate (assert_status). Self-documenting, faster on the happy path (returns on the first poll that sees the change), and more robust under slow CI. No fixed sleeps remain. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
25 lines
871 B
Bash
Executable File
25 lines
871 B
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
# shellcheck source=../../lib/common.sh
|
|
source "$HERE/../../lib/common.sh"
|
|
|
|
SCENARIO=trusted-ips
|
|
|
|
body() {
|
|
echo "[$SCENARIO] banning the trusted IP 1.2.3.4 and an untrusted IP 5.6.7.8"
|
|
lapi_add_decision 1.2.3.4 ban 5m
|
|
lapi_add_decision 5.6.7.8 ban 5m
|
|
|
|
# The untrusted IP turning 403 is our signal that the bans have been polled;
|
|
# it also doubles as the control proving the bouncer is active.
|
|
echo "[$SCENARIO] untrusted banned IP must be blocked once the bans are polled (HTTP 403)"
|
|
wait_for_status "http://127.0.0.1:${WEB_PORT}/foo" 403 15 -H "X-Forwarded-For: 5.6.7.8"
|
|
|
|
echo "[$SCENARIO] trusted IP must bypass the bouncer even though it is banned"
|
|
assert_status "http://127.0.0.1:${WEB_PORT}/foo" 200 -H "X-Forwarded-For: 1.2.3.4"
|
|
}
|
|
|
|
run_scenario "$SCENARIO" "$HERE" body
|