feat(security): mirror anti-DDoS blocks to Cloudflare edge via API
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m38s
CI / tests-unit (push) Failing after 1m40s
CI / tests-ui (push) Successful in 2m28s
CI / preflight (push) Skipped
CI / deploy (push) Skipped

- gate creates a zone IP Access Rule (block) for proxied offenders that hit the block threshold, deduped until the tiered block expires
- cloudflare-api lib: verified endpoints, create/delete/verify/list helpers, Redis-backed tracking + 30s TTL sweep (instrumentation worker + admin render)
- runtime toggle cloudflareAutoBlock in antiddos config; boot default CLOUDFLARE_AUTO_BLOCK_ENABLED
- admin panel: Cloudflare edge-blocks card with verify + remove-rule actions; unban also lifts the edge block
- credentials live in env only (CLOUDFLARE_API_TOKEN / CLOUDFLARE_ZONE_ID)
This commit is contained in:
openhands committed 2026-09-22 23:27:15 +02:00
1 parent f0c27eb815
commit 4479753160
9 files changed
+1157 -1

No files matched your search

+16
View File
@@ -132,6 +132,22 @@ const schema = z
// Logging level.
LOG_LEVEL: z.enum(["debug", "info", "warn", "error"]).optional(),
APP_VERSION: z.string().optional(),
// Cloudflare API — optional. When the API token + zone id are set, the
// anti-DDoS gate can automatically mirror escalated IP blocks to the
// zone's IP Access Rules so attackers are dropped at the edge. The token
// lives in env only and is never persisted into Redis-visible config.
CLOUDFLARE_API_BASE_URL: z
.string()
.url()
.default("https://api.cloudflare.com/client/v4"),
CLOUDFLARE_API_TOKEN: z.string().optional(),
CLOUDFLARE_ZONE_ID: z.string().optional(),
// Boot default for the runtime "auto-create Cloudflare blocks" toggle
// (overridable via the admin panel / antiddos:config).
CLOUDFLARE_AUTO_BLOCK_ENABLED: z
.string()
.optional()
.transform((value) => value !== "false" && value !== "0"),
})
.superRefine((data, ctx) => {
if (data.NODE_ENV !== "production") return;