OP防火墙部分优化

This commit is contained in:
midoks
2023-08-11 12:56:07 +08:00
parent 2b2fc08120
commit 6eadad5db4
5 changed files with 126 additions and 112 deletions
+107 -88
View File
@@ -73,6 +73,10 @@ def getConf():
return path
def dstWafConfPath():
return mw.getServerDir() + "/web_conf/nginx/vhost/opwaf.conf"
def pSqliteDb(dbname='logs'):
name = "waf"
db_dir = getServerDir() + '/logs/'
@@ -230,10 +234,6 @@ def initTotalInfo():
mw.writeFile(path_total, cjson)
def dstWafConf():
return mw.getServerDir() + "/web_conf/nginx/vhost/opwaf.conf"
def contentReplace(content):
service_path = mw.getServerDir()
waf_root = getServerDir()
@@ -245,53 +245,65 @@ def contentReplace(content):
return content
def autoMakeLuaConfSingle(file):
# path = getPluginDir() + "/waf/rule/" + file + ".json"
def autoMakeLuaConfSingle(file, conf_reload=False):
path = getServerDir() + "/waf/rule/" + file + ".json"
to_path = getServerDir() + "/waf/conf/rule_" + file + ".lua"
content = mw.readFile(path)
# print(content)
content = json.loads(content)
listToLuaFile(to_path, content)
dst_path = getServerDir() + "/waf/conf/rule_" + file + ".lua"
if not os.path.exists(dst_path) or conf_reload:
content = mw.readFile(path)
# print(content)
content = json.loads(content)
listToLuaFile(dst_path, content)
def autoMakeLuaImportSingle(file):
def autoMakeLuaImportSingle(file, conf_reload=False):
path = getServerDir() + "/waf/" + file + ".json"
to_path = getServerDir() + "/waf/conf/waf_" + file + ".lua"
content = mw.readFile(path)
# print(content)
content = json.loads(content)
listToLuaFile(to_path, content)
dst_path = getServerDir() + "/waf/conf/waf_" + file + ".lua"
if not os.path.exists(dst_path) or conf_reload:
content = mw.readFile(path)
# print(content)
content = json.loads(content)
listToLuaFile(dst_path, content)
def autoMakeLuaHtmlSingle(file):
def autoMakeLuaHtmlSingle(file, conf_reload=False):
path = getServerDir() + "/waf/html/" + file + ".html"
to_path = getServerDir() + "/waf/html/html_" + file + ".lua"
dst_path = getServerDir() + "/waf/html/html_" + file + ".lua"
if not os.path.exists(dst_path) or conf_reload:
# print(path)
content = mw.readFile(path)
htmlToLuaFile(dst_path, content)
def autoCpHtml(file):
path = getPluginDir() + "/waf/html/" + file + ".html"
dst_path = getServerDir() + "/waf/html/" + file + ".html"
content = mw.readFile(path)
htmlToLuaFile(to_path, content)
mw.writeFile(dst_path, content)
def autoMakeLuaConf():
def autoMakeLuaConf(conf_reload=False):
conf_list = ['args', 'cookie', 'ip_black', 'ip_white',
'ipv6_black', 'post', 'scan_black', 'url',
'url_white', 'user_agent']
for x in conf_list:
autoMakeLuaConfSingle(x)
autoMakeLuaConfSingle(x, conf_reload)
import_list = ['config', 'site', 'domains']
for x in import_list:
autoMakeLuaImportSingle(x)
autoMakeLuaImportSingle(x, conf_reload)
html_list = ['get', 'post', 'safe_js', 'user_agent', 'cookie', 'other']
for x in html_list:
autoMakeLuaHtmlSingle(x)
if conf_reload:
autoCpHtml(x)
autoMakeLuaHtmlSingle(x, conf_reload)
def initDefaultInfo():
def initDefaultInfo(conf_reload=False):
path = getServerDir()
djson = path + "/waf/domains.json"
default_json = path + "/waf/default.json"
if os.path.exists(djson):
if not os.path.exists(djson) or conf_reload:
content = mw.readFile(djson)
content = json.loads(content)
@@ -310,53 +322,83 @@ def initDefaultInfo():
mw.writeFile(default_json, json.dumps(ddata))
def autoMakeConfig():
path = getServerDir()
initDomainInfo()
initSiteInfo()
initTotalInfo()
autoMakeLuaConf()
def autoMakeConfig(conf_reload=False):
initDomainInfo(conf_reload)
initSiteInfo(conf_reload)
initTotalInfo(conf_reload)
autoMakeLuaConf(conf_reload)
def restartWeb():
autoMakeConfig()
mw.opWeb('stop')
mw.opWeb('start')
def makeDstLua():
def makeOpDstRunLua(conf_reload=False):
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
path = getServerDir()
path_tpl = getPluginDir()
waf_common_tpl = path_tpl + "/waf/lua/waf_common.lua"
waf_common_dst = path + "/waf/lua/waf_common.lua"
content = mw.readFile(waf_common_tpl)
content = contentReplace(content)
mw.writeFile(waf_common_dst, content)
if os.path.exists(waf_common_dst) or conf_reload:
waf_common_tpl = path_tpl + "/waf/lua/waf_common.lua"
content = mw.readFile(waf_common_tpl)
content = contentReplace(content)
mw.writeFile(waf_common_dst, content)
waf_init_tpl = path_tpl + "/waf/lua/init_preload.lua"
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
content = mw.readFile(waf_init_tpl)
content = contentReplace(content)
mw.writeFile(waf_init_dst, content)
if os.path.exists(waf_init_dst) or conf_reload:
waf_init_tpl = path_tpl + "/waf/lua/init_preload.lua"
content = mw.readFile(waf_init_tpl)
content = contentReplace(content)
mw.writeFile(waf_init_dst, content)
init_worker_tpl = path_tpl + "/waf/lua/init_worker.lua"
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
content = mw.readFile(init_worker_tpl)
content = contentReplace(content)
mw.writeFile(init_worker_dst, content)
if os.path.exists(init_worker_dst) or conf_reload:
init_worker_tpl = path_tpl + "/waf/lua/init_worker.lua"
content = mw.readFile(init_worker_tpl)
content = contentReplace(content)
mw.writeFile(init_worker_dst, content)
access_file_tpl = path_tpl + "/waf/lua/init.lua"
access_file_dst = root_access_dir + '/opwaf_init.lua'
content = mw.readFile(access_file_tpl)
content = contentReplace(content)
mw.writeFile(access_file_dst, content)
if os.path.exists(access_file_dst) or conf_reload:
access_file_tpl = path_tpl + "/waf/lua/init.lua"
content = mw.readFile(access_file_tpl)
content = contentReplace(content)
mw.writeFile(access_file_dst, content)
mw.opLuaMakeAll()
return True
def makeOpDstStopLua():
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
if os.path.exists(waf_init_dst):
os.remove(waf_init_dst)
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
if os.path.exists(init_worker_dst):
os.remove(init_worker_dst)
access_file_dst = root_access_dir + '/opwaf_init.lua'
if os.path.exists(access_file_dst):
os.remove(access_file_dst)
wafconf = dstWafConfPath()
if os.path.exists(wafconf):
os.remove(wafconf)
import tool_task
tool_task.removeBgTask()
mw.opLuaMakeAll()
return True
def initDreplace():
@@ -378,13 +420,12 @@ def initDreplace():
content = mw.readFile(config)
content = json.loads(content)
wfDir = path + "/waf/html"
content['reqfile_path'] = wfDir
content['reqfile_path'] = path + "/waf/html"
mw.writeFile(config, mw.getJson(content))
makeDstLua()
makeOpDstRunLua()
waf_conf = dstWafConf()
waf_conf = dstWafConfPath()
if not os.path.exists(waf_conf):
waf_tpl = getPluginDir() + "/conf/luawaf.conf"
content = mw.readFile(waf_tpl)
@@ -401,6 +442,7 @@ def initDreplace():
if not mw.isAppleSystem():
mw.execShell("chown -R www:www " + path)
return path
def status():
@@ -408,7 +450,7 @@ def status():
if not os.path.exists(path):
return 'stop'
waf_conf = dstWafConf()
waf_conf = dstWafConfPath()
if not os.path.exists(waf_conf):
return 'stop'
return 'start'
@@ -425,31 +467,7 @@ def start():
def stop():
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
if os.path.exists(waf_init_dst):
os.remove(waf_init_dst)
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
if os.path.exists(init_worker_dst):
os.remove(init_worker_dst)
access_file_dst = root_access_dir + '/opwaf_init.lua'
if os.path.exists(access_file_dst):
os.remove(access_file_dst)
wafconf = dstWafConf()
if os.path.exists(wafconf):
os.remove(wafconf)
import tool_task
tool_task.removeBgTask()
mw.opLuaMakeAll()
makeOpDstStopLua()
restartWeb()
return 'ok'
@@ -460,16 +478,17 @@ def restart():
def reload():
stop()
mw.opWeb('stop')
makeDstLua()
makeOpDstRunLua(True)
autoMakeLuaConf(True)
initDefaultInfo(True)
errlog = mw.getServerDir() + "/openresty/nginx/logs/error.log"
mw.execShell('rm -rf ' + errlog)
elog = mw.getServerDir() + "/openresty/nginx/logs/error.log"
if os.path.exists(elog):
mw.execShell('rm -rf ' + elog)
start()
restartWeb()
mw.opWeb('start')
return 'ok'
-1
View File
@@ -36,7 +36,6 @@ Install_App(){
fi
# which luarocks
# if [ "$?" != "0" ];then
if [ ! -d $serverPath/op_waf/luarocks ];then
cd $serverPath/source/op_waf && tar xvf luarocks-3.5.0.tar.gz
# cd luarocks-3.9.1 && ./configure && make bootstrap
+11 -11
View File
@@ -19,7 +19,7 @@
<div class="main">
<div class="title">OP网站防火墙|安全校验</div>
<div class="content">
<p id="change">5</p>
<p id="change">3</p>
</div>
<div id="status" style="display: none;">false</div>
</div>
@@ -125,22 +125,22 @@ function ajax(type,bool){
return xhr;
}
ajax('JSON',true).post('{uri}',{'pass':"ok"}, function(data){
if (data['status'] == 0){
document.getElementById('status').innerHTML = 'ok';
location.reload();
}
});
var ok = setInterval(function(){
var id = document.getElementById('change').innerHTML;
id = id - 1;
if (id == 0){
document.getElementById('change').innerHTML = '稍等';
clearInterval(ok);
if (document.getElementById('status').innerHTML == 'ok'){
location.reload();
}
ajax('JSON',true).post('{uri}',{'pass':"ok"}, function(data){
if (data['status'] == 0 && data['msg'] == 'ok'){
document.getElementById('status').innerHTML = 'ok';
setTimeout(function(){
location.reload();
},500);
} else{
document.getElementById('change').innerHTML = '?';
}
});
} else {
document.getElementById('change').innerHTML = id;
}
+7 -11
View File
@@ -35,10 +35,8 @@ local cookie_rules = require "rule_cookie"
local url_rules = require "rule_url"
local url_white_rules = require "rule_url_white"
-- local server_name = string.gsub(C:get_sn(config_domains),'_','.')
local server_name = C:get_sn(config_domains)
local function initParams()
local data = {}
data['server_name'] = server_name
@@ -53,10 +51,12 @@ local function initParams()
data['user_agent'] = data['request_header']['user-agent']
data['cookie'] = ngx.var.http_cookie
data['time'] = ngx.time()
return data
end
local params = initParams()
-- C:D(C:to_json(params))
C:setParams(params)
local cpu_percent = ngx.shared.waf_limit:get("cpu_usage")
@@ -343,6 +343,7 @@ local function waf_cc_increase()
local make_uri_str = "?token="..make_token
local make_uri = "/"..make_uri_str
-- C:D("token:"..tostring(params['uri_request_args']['token']))
if params['uri_request_args']['token'] then
ngx.header.content_type = "application/json"
local args_token = params['uri_request_args']['token']
@@ -352,14 +353,9 @@ local function waf_cc_increase()
ngx.say(json.encode(data))
ngx.exit(200)
end
-- C:D("debug[args]:"..tostring(params['uri_request_args']['debug']))
-- if params['uri_request_args']['debug'] == 'ok' then
-- ngx.header.content_type = "application/json"
-- local data = get_return_state(0, "ok")
-- ngx.say(json.encode(data))
-- ngx.exit(200)
-- end
local data = get_return_state(0, "unset")
ngx.say(json.encode(data))
ngx.exit(200)
end
local cc_html = ngx.re.gsub(cc_safe_js_html, "{uri}", make_uri_str)
@@ -531,7 +527,7 @@ end
function waf()
if server_name == "unset" then ngx.exit(403) end
-- if server_name == "unset" then ngx.exit(403) end
min_route()
-- C:D("min_route")
+1 -1
View File
@@ -207,7 +207,7 @@ function _M.D(self, msg)
local _msg = ''
if type(msg) == 'table' then
for key, val in pairs(msg) do
_msg = tostring( key)..':'.."\n"
_msg = tostring(key)..':'.."\n"
end
elseif type(msg) == 'string' then
_msg = msg