WeebDataHoarder
6a6c3fef07
testdata: Initial action/challenges testing
2025-04-29 05:20:33 +02:00
WeebDataHoarder
467ad9c5a9
state: fix errors when loading network lists
2025-04-29 05:19:18 +02:00
WeebDataHoarder
e49c4ae72f
action/context: add capability to set response headers
2025-04-28 12:40:03 +02:00
WeebDataHoarder
b8bf35d4de
utils: fix radb fetching lines too long for scanner buffer size, allow caching empty results
2025-04-27 22:04:21 +02:00
WeebDataHoarder
b285c13e4c
state: do not cache network prefixes if they have zero entries
2025-04-27 21:49:44 +02:00
WeebDataHoarder
2bb8ec833d
challenges/refresh: change refresh-mode to refresh-via as examples show
2025-04-27 21:42:29 +02:00
WeebDataHoarder
a5d973dbaa
actions: fix context action stopping processing
2025-04-27 21:41:55 +02:00
WeebDataHoarder
1a9224e453
challenge: fix skipped challenged being logged as issued due to inner condition
2025-04-27 21:41:30 +02:00
WeebDataHoarder
3234c4e801
feature: Implement <meta> tag fetcher from backends with allow-listed entries to prevent unwanted keys to pass
2025-04-27 21:40:59 +02:00
WeebDataHoarder
666ffa574a
challenge: implement IPv6 Happy Eyeballs again, use errors to detect this within challenge, cleanup referrer tags
2025-04-27 18:49:58 +02:00
WeebDataHoarder
06c363e55a
context: add ip prefix on keyed cookie
2025-04-27 17:37:34 +02:00
WeebDataHoarder
62ece572d9
challenge: Use top /24 for IPv4 or top /64 for IPv6
2025-04-27 17:30:34 +02:00
WeebDataHoarder
c5ad9cdf03
context: add CONTEXT action to apply options on current request
2025-04-27 17:20:57 +02:00
WeebDataHoarder
0473109e60
http: allow specifying Go DNS resolver on config backends
2025-04-27 13:16:42 +02:00
WeebDataHoarder
c33531d7eb
cmd: log errors with ERROR severity via slog, additionally print newline string, fixes #12
2025-04-27 12:17:18 +02:00
WeebDataHoarder
01ef63abea
challenge: quote expected challenge name on error
2025-04-25 23:20:53 +02:00
WeebDataHoarder
0b9f077b6c
context: delete query parameters set by go-away
2025-04-25 22:48:34 +02:00
WeebDataHoarder
a85aa95dbd
cmd: support changing path from well-known prefix, allow configuring full path
2025-04-25 22:16:09 +02:00
WeebDataHoarder
a1f97adde8
metrics: fix global state reset on policy reload
2025-04-25 22:11:08 +02:00
WeebDataHoarder
bca5b25f28
docker: include default snippets onto Dockerfile, allow multiple snippets folders, closes #8
2025-04-25 18:09:25 +02:00
WeebDataHoarder
398675aa3c
config: Add string replacement for templates, add example config.yml ( close #10 )
2025-04-25 17:32:45 +02:00
WeebDataHoarder
4d7436c51b
cel: use generic env from https://codeberg.org/gone/http-cel
2025-04-25 12:08:55 +02:00
WeebDataHoarder
bc0eaeca21
metrics: Add rule action metrics
2025-04-25 11:40:39 +02:00
WeebDataHoarder
d6d69d0192
metrics: track DEFAULT rule hit
2025-04-25 11:40:38 +02:00
WeebDataHoarder
47f9f6fee6
metrics: Added prometheus metrics for rules and challenges
2025-04-25 11:27:42 +02:00
WeebDataHoarder
9541c58eeb
settings: introduce settings YAML file to complement cmd arguments
2025-04-24 18:26:06 +02:00
WeebDataHoarder
96870cc192
dnsbl: normal error handling on resolution error
2025-04-24 00:02:06 +02:00
WeebDataHoarder
3bbd50764a
challenge: add cookie prefix to cookies tied to host/pubkey to prevent reuse
2025-04-23 22:38:14 +02:00
WeebDataHoarder
49e46e7e9f
condition: fix http query values context
2025-04-23 22:29:17 +02:00
WeebDataHoarder
cd372e1512
challenge: Skip already issued challenges
2025-04-23 22:06:11 +02:00
WeebDataHoarder
cef915b353
http: use Query.Get instead of FormValue, allows POST through
2025-04-23 21:30:39 +02:00
WeebDataHoarder
cb02fb20e9
cmd: print current version name on cmd and Via header
2025-04-23 20:46:17 +02:00
WeebDataHoarder
57755112ea
ci: check example policy files
...
cmd: add check parameter
2025-04-23 20:35:20 +02:00
WeebDataHoarder
6bb7ca979d
Implement cache for networks
2025-04-23 20:35:20 +02:00
WeebDataHoarder
a0224cb21c
policy: allow fetching ASN directly via RADb WHOIS service
2025-04-23 20:35:20 +02:00
WeebDataHoarder
9719c0ff39
Support atomically swapping http handler for passhtrough
2025-04-23 20:35:20 +02:00
WeebDataHoarder
3b11792594
Implement policy snippets
2025-04-23 20:35:20 +02:00
WeebDataHoarder
ead41055ca
Condition, rules, state and action refactor / rewrite
...
Add nested rules
Add backend action, allow wildcard in backends
Remove poison from tree, update README with action table
Allow defining pass/fail actions on challenge,
Remove redirect/referer parameters on backend pass
Set challenge cookie tied to host
Rewrite DNSBL condition into a challenge
Allow passing an arbitrary path for assets to js challenges
Optimize programs exhaustively on compilation
Activation instead of map for CEL context, faster map access, new network override
Return valid host on cookie setting in case Host is an IP address.
bug: does not work with IPv6, see https://github.com/golang/go/issues/65521
Apply TLS fingerprinter on GetConfigForClient instead of GetCertificate
Cleanup go-away cookies before passing to backend
Code action for specifically replying with an HTTP code
2025-04-23 20:35:20 +02:00
WeebDataHoarder
c84c67439e
Only error when target network list is not reachable
2025-04-15 19:23:04 +02:00
WeebDataHoarder
b0aa9ff450
Status code 200 -> http.StatusOK
2025-04-15 19:19:34 +02:00
WeebDataHoarder
39fbcf92d2
Return in case of not matching poison
2025-04-13 20:39:47 +02:00
WeebDataHoarder
cc89b8657f
Only serve poison if encoding for it exists
2025-04-13 11:15:24 +02:00
WeebDataHoarder
f2005d5051
Ensure JA3N is stringified on logger
2025-04-12 15:36:54 +02:00
WeebDataHoarder
617e40099f
Check fingerprint ptr before usage
2025-04-12 13:56:25 +02:00
WeebDataHoarder
ca49c99cad
Add support for JA3N / JA4 TLS fingerprinting
2025-04-12 02:13:05 +02:00
WeebDataHoarder
87c2845952
Send request data early
2025-04-11 06:22:48 +02:00
WeebDataHoarder
7829eece77
Added backend IP header support
2025-04-11 06:02:01 +02:00
WeebDataHoarder
ca4101df7c
Use self-redirect on cookie challenge
2025-04-10 05:27:44 +02:00
WeebDataHoarder
527f1342e8
Issue token then redirect to verify under cookie challenge
2025-04-10 05:15:48 +02:00
WeebDataHoarder
ce111f6ae9
Add DNSBL querying in conditions
2025-04-08 22:11:58 +02:00