feat(security): Cloudflare-aware IP trust and admin-tunable anti-DDoS
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m50s
CI / tests-unit (push) Successful in 1m52s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m50s
CI / tests-unit (push) Successful in 1m52s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m32s
- resolveClientIp: trust cf-connecting-ip only behind cf-ray/cdn-loop, use nginx x-real-ip otherwise (anti-spoof) - antiddos-config: Redis-backed live config (antiddos:config) with 30s cache, 13 ANTI_DDOS_* env vars - ddos-guard: consume tunable rates/tiers via getAntiddosConfig - admin panel at /admin/devops/antiddos (save/reset/unban actions, PERMS.SETTINGS_VIEW) - register new admin page in housekeeping migration matrix (146 -> 147)
This commit is contained in:
1 parent
fd4d0fa1cb
commit
f0c27eb815
17 files changed
+1151
-63
No files matched your search
@@ -34,7 +34,7 @@ describe("normalized client IP addresses", () => {
|
||||
expect(normalizeClientIp(input)).toBeNull();
|
||||
});
|
||||
|
||||
it("uses the first forwarded address after an invalid higher-priority header", () => {
|
||||
it("falls back to the trusted ingress header when a spoofed Cloudflare header lacks cf-ray", () => {
|
||||
expect(
|
||||
resolveClientIp(
|
||||
new Headers({
|
||||
@@ -44,6 +44,20 @@ describe("normalized client IP addresses", () => {
|
||||
"x-real-client-ip": "198.51.100.99",
|
||||
}),
|
||||
),
|
||||
).toBe("192.0.2.30");
|
||||
});
|
||||
|
||||
it("ignores an invalid Cloudflare header on proxied traffic and uses the first forwarding entry", () => {
|
||||
expect(
|
||||
resolveClientIp(
|
||||
new Headers({
|
||||
"cf-ray": "8a9b-AMS",
|
||||
"cf-connecting-ip": "invalid",
|
||||
"x-forwarded-for": " 192.0.2.10, 192.0.2.20 ",
|
||||
"x-real-ip": "192.0.2.30",
|
||||
"x-real-client-ip": "198.51.100.99",
|
||||
}),
|
||||
),
|
||||
).toBe("192.0.2.10");
|
||||
});
|
||||
|
||||
|
||||
Reference in new issue
Block a user