feat(security): harden anti-DDoS gate with scanner triage, tiered blocks and in-process global halt
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m39s
CI / tests-integration (push) Successful in 1m42s
CI / tests-ui (push) Successful in 2m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m0s

This commit is contained in:
openhands committed 2026-09-22 21:57:09 +02:00
1 parent 98a184953a
commit fd4d0fa1cb
4 files changed
+142 -38

No files matched your search

+24 -1
View File
@@ -1,6 +1,6 @@
import { describe, expect, it } from "vitest";
import { classifyDdos } from "@/lib/ddos";
import { classifyDdos, isSuspiciousPath } from "@/lib/ddos";
describe("classifyDdos", () => {
it.each([
@@ -18,3 +18,26 @@ describe("classifyDdos", () => {
expect(classifyDdos(pathname)).toBe(expected);
});
});
describe("isSuspiciousPath", () => {
it.each([
["/wp-admin/index.php", true],
["/wp-login.php", true],
["/.env", true],
["/.git/config", true],
["/phpmyadmin/", true],
["/server-status", true],
["/index.php", true],
["/shell.aspx", true],
])(`flags scanner path %s`, (pathname, expected) => {
expect(isSuspiciousPath(pathname)).toBe(expected);
});
it("does not flag real app routes", () => {
expect(isSuspiciousPath("/")).toBe(false);
expect(isSuspiciousPath("/community")).toBe(false);
expect(isSuspiciousPath("/api/health")).toBe(false);
expect(isSuspiciousPath("/login")).toBe(false);
expect(isSuspiciousPath("/news/article/hello-world")).toBe(false);
});
});