feat(security): Cloudflare-aware IP trust and admin-tunable anti-DDoS
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m50s
CI / tests-unit (push) Successful in 1m52s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m50s
CI / tests-unit (push) Successful in 1m52s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
- resolveClientIp: trust cf-connecting-ip only behind cf-ray/cdn-loop, use nginx x-real-ip otherwise (anti-spoof) - antiddos-config: Redis-backed live config (antiddos:config) with 30s cache, 13 ANTI_DDOS_* env vars - ddos-guard: consume tunable rates/tiers via getAntiddosConfig - admin panel at /admin/devops/antiddos (save/reset/unban actions, PERMS.SETTINGS_VIEW) - register new admin page in housekeeping migration matrix (146 -> 147)
This commit is contained in:
1 parent
fd4d0fa1cb
commit
f0c27eb815
17 files changed
+1151
-63
No files matched your search
+23
@@ -106,6 +106,29 @@ const schema = z
|
||||
.string()
|
||||
.optional()
|
||||
.transform((value) => value !== "false" && value !== "0"),
|
||||
// Anti-DDoS thresholds. These are the YAML-file boot defaults; the admin
|
||||
// panel can override them at runtime (Redis `antiddos:config`).
|
||||
ANTI_DDOS_PAGES_LIMIT: z.coerce.number().int().positive().default(300),
|
||||
ANTI_DDOS_PAGES_WINDOW_SEC: z.coerce.number().int().positive().default(60),
|
||||
ANTI_DDOS_API_LIMIT: z.coerce.number().int().positive().default(600),
|
||||
ANTI_DDOS_API_WINDOW_SEC: z.coerce.number().int().positive().default(60),
|
||||
ANTI_DDOS_AUTH_LIMIT: z.coerce.number().int().positive().default(20),
|
||||
ANTI_DDOS_AUTH_WINDOW_SEC: z.coerce.number().int().positive().default(60),
|
||||
ANTI_DDOS_GLOBAL_LIMIT: z.coerce.number().int().positive().default(18_000),
|
||||
ANTI_DDOS_GLOBAL_WINDOW_SEC: z.coerce.number().int().positive().default(60),
|
||||
ANTI_DDOS_VIOLATION_WINDOW_SEC: z.coerce
|
||||
.number()
|
||||
.int()
|
||||
.positive()
|
||||
.default(600),
|
||||
ANTI_DDOS_MAX_VIOLATIONS: z.coerce.number().int().positive().default(10),
|
||||
// Escalation tiers as "minViolations:ttlSeconds,minViolations:ttlSeconds".
|
||||
ANTI_DDOS_BLOCK_TIERS: z.string().optional(),
|
||||
ANTI_DDOS_GLOBAL_HALT_MS: z.coerce
|
||||
.number()
|
||||
.int()
|
||||
.positive()
|
||||
.default(10_000),
|
||||
// Logging level.
|
||||
LOG_LEVEL: z.enum(["debug", "info", "warn", "error"]).optional(),
|
||||
APP_VERSION: z.string().optional(),
|
||||
|
||||
Reference in new issue
Block a user