mirror of
https://github.com/midoks/mdserver-web.git
synced 2026-10-10 04:19:26 +08:00
OP防火墙部分优化
This commit is contained in:
+107
-88
@@ -73,6 +73,10 @@ def getConf():
|
||||
return path
|
||||
|
||||
|
||||
def dstWafConfPath():
|
||||
return mw.getServerDir() + "/web_conf/nginx/vhost/opwaf.conf"
|
||||
|
||||
|
||||
def pSqliteDb(dbname='logs'):
|
||||
name = "waf"
|
||||
db_dir = getServerDir() + '/logs/'
|
||||
@@ -230,10 +234,6 @@ def initTotalInfo():
|
||||
mw.writeFile(path_total, cjson)
|
||||
|
||||
|
||||
def dstWafConf():
|
||||
return mw.getServerDir() + "/web_conf/nginx/vhost/opwaf.conf"
|
||||
|
||||
|
||||
def contentReplace(content):
|
||||
service_path = mw.getServerDir()
|
||||
waf_root = getServerDir()
|
||||
@@ -245,53 +245,65 @@ def contentReplace(content):
|
||||
return content
|
||||
|
||||
|
||||
def autoMakeLuaConfSingle(file):
|
||||
# path = getPluginDir() + "/waf/rule/" + file + ".json"
|
||||
def autoMakeLuaConfSingle(file, conf_reload=False):
|
||||
path = getServerDir() + "/waf/rule/" + file + ".json"
|
||||
to_path = getServerDir() + "/waf/conf/rule_" + file + ".lua"
|
||||
content = mw.readFile(path)
|
||||
# print(content)
|
||||
content = json.loads(content)
|
||||
listToLuaFile(to_path, content)
|
||||
dst_path = getServerDir() + "/waf/conf/rule_" + file + ".lua"
|
||||
if not os.path.exists(dst_path) or conf_reload:
|
||||
content = mw.readFile(path)
|
||||
# print(content)
|
||||
content = json.loads(content)
|
||||
listToLuaFile(dst_path, content)
|
||||
|
||||
|
||||
def autoMakeLuaImportSingle(file):
|
||||
def autoMakeLuaImportSingle(file, conf_reload=False):
|
||||
path = getServerDir() + "/waf/" + file + ".json"
|
||||
to_path = getServerDir() + "/waf/conf/waf_" + file + ".lua"
|
||||
content = mw.readFile(path)
|
||||
# print(content)
|
||||
content = json.loads(content)
|
||||
listToLuaFile(to_path, content)
|
||||
dst_path = getServerDir() + "/waf/conf/waf_" + file + ".lua"
|
||||
if not os.path.exists(dst_path) or conf_reload:
|
||||
content = mw.readFile(path)
|
||||
# print(content)
|
||||
content = json.loads(content)
|
||||
listToLuaFile(dst_path, content)
|
||||
|
||||
|
||||
def autoMakeLuaHtmlSingle(file):
|
||||
def autoMakeLuaHtmlSingle(file, conf_reload=False):
|
||||
path = getServerDir() + "/waf/html/" + file + ".html"
|
||||
to_path = getServerDir() + "/waf/html/html_" + file + ".lua"
|
||||
dst_path = getServerDir() + "/waf/html/html_" + file + ".lua"
|
||||
if not os.path.exists(dst_path) or conf_reload:
|
||||
# print(path)
|
||||
content = mw.readFile(path)
|
||||
htmlToLuaFile(dst_path, content)
|
||||
|
||||
|
||||
def autoCpHtml(file):
|
||||
path = getPluginDir() + "/waf/html/" + file + ".html"
|
||||
dst_path = getServerDir() + "/waf/html/" + file + ".html"
|
||||
content = mw.readFile(path)
|
||||
htmlToLuaFile(to_path, content)
|
||||
mw.writeFile(dst_path, content)
|
||||
|
||||
|
||||
def autoMakeLuaConf():
|
||||
def autoMakeLuaConf(conf_reload=False):
|
||||
conf_list = ['args', 'cookie', 'ip_black', 'ip_white',
|
||||
'ipv6_black', 'post', 'scan_black', 'url',
|
||||
'url_white', 'user_agent']
|
||||
for x in conf_list:
|
||||
autoMakeLuaConfSingle(x)
|
||||
autoMakeLuaConfSingle(x, conf_reload)
|
||||
|
||||
import_list = ['config', 'site', 'domains']
|
||||
for x in import_list:
|
||||
autoMakeLuaImportSingle(x)
|
||||
autoMakeLuaImportSingle(x, conf_reload)
|
||||
|
||||
html_list = ['get', 'post', 'safe_js', 'user_agent', 'cookie', 'other']
|
||||
for x in html_list:
|
||||
autoMakeLuaHtmlSingle(x)
|
||||
if conf_reload:
|
||||
autoCpHtml(x)
|
||||
autoMakeLuaHtmlSingle(x, conf_reload)
|
||||
|
||||
|
||||
def initDefaultInfo():
|
||||
def initDefaultInfo(conf_reload=False):
|
||||
path = getServerDir()
|
||||
djson = path + "/waf/domains.json"
|
||||
default_json = path + "/waf/default.json"
|
||||
if os.path.exists(djson):
|
||||
if not os.path.exists(djson) or conf_reload:
|
||||
content = mw.readFile(djson)
|
||||
content = json.loads(content)
|
||||
|
||||
@@ -310,53 +322,83 @@ def initDefaultInfo():
|
||||
mw.writeFile(default_json, json.dumps(ddata))
|
||||
|
||||
|
||||
def autoMakeConfig():
|
||||
path = getServerDir()
|
||||
|
||||
initDomainInfo()
|
||||
initSiteInfo()
|
||||
initTotalInfo()
|
||||
autoMakeLuaConf()
|
||||
def autoMakeConfig(conf_reload=False):
|
||||
initDomainInfo(conf_reload)
|
||||
initSiteInfo(conf_reload)
|
||||
initTotalInfo(conf_reload)
|
||||
autoMakeLuaConf(conf_reload)
|
||||
|
||||
|
||||
def restartWeb():
|
||||
autoMakeConfig()
|
||||
mw.opWeb('stop')
|
||||
mw.opWeb('start')
|
||||
|
||||
|
||||
def makeDstLua():
|
||||
def makeOpDstRunLua(conf_reload=False):
|
||||
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
|
||||
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
|
||||
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
|
||||
path = getServerDir()
|
||||
path_tpl = getPluginDir()
|
||||
|
||||
waf_common_tpl = path_tpl + "/waf/lua/waf_common.lua"
|
||||
waf_common_dst = path + "/waf/lua/waf_common.lua"
|
||||
content = mw.readFile(waf_common_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(waf_common_dst, content)
|
||||
if os.path.exists(waf_common_dst) or conf_reload:
|
||||
waf_common_tpl = path_tpl + "/waf/lua/waf_common.lua"
|
||||
content = mw.readFile(waf_common_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(waf_common_dst, content)
|
||||
|
||||
waf_init_tpl = path_tpl + "/waf/lua/init_preload.lua"
|
||||
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
|
||||
content = mw.readFile(waf_init_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(waf_init_dst, content)
|
||||
if os.path.exists(waf_init_dst) or conf_reload:
|
||||
waf_init_tpl = path_tpl + "/waf/lua/init_preload.lua"
|
||||
content = mw.readFile(waf_init_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(waf_init_dst, content)
|
||||
|
||||
init_worker_tpl = path_tpl + "/waf/lua/init_worker.lua"
|
||||
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
|
||||
content = mw.readFile(init_worker_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(init_worker_dst, content)
|
||||
if os.path.exists(init_worker_dst) or conf_reload:
|
||||
init_worker_tpl = path_tpl + "/waf/lua/init_worker.lua"
|
||||
content = mw.readFile(init_worker_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(init_worker_dst, content)
|
||||
|
||||
access_file_tpl = path_tpl + "/waf/lua/init.lua"
|
||||
access_file_dst = root_access_dir + '/opwaf_init.lua'
|
||||
content = mw.readFile(access_file_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(access_file_dst, content)
|
||||
if os.path.exists(access_file_dst) or conf_reload:
|
||||
access_file_tpl = path_tpl + "/waf/lua/init.lua"
|
||||
content = mw.readFile(access_file_tpl)
|
||||
content = contentReplace(content)
|
||||
mw.writeFile(access_file_dst, content)
|
||||
|
||||
mw.opLuaMakeAll()
|
||||
return True
|
||||
|
||||
|
||||
def makeOpDstStopLua():
|
||||
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
|
||||
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
|
||||
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
|
||||
|
||||
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
|
||||
if os.path.exists(waf_init_dst):
|
||||
os.remove(waf_init_dst)
|
||||
|
||||
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
|
||||
if os.path.exists(init_worker_dst):
|
||||
os.remove(init_worker_dst)
|
||||
|
||||
access_file_dst = root_access_dir + '/opwaf_init.lua'
|
||||
if os.path.exists(access_file_dst):
|
||||
os.remove(access_file_dst)
|
||||
|
||||
wafconf = dstWafConfPath()
|
||||
if os.path.exists(wafconf):
|
||||
os.remove(wafconf)
|
||||
|
||||
import tool_task
|
||||
tool_task.removeBgTask()
|
||||
|
||||
mw.opLuaMakeAll()
|
||||
return True
|
||||
|
||||
|
||||
def initDreplace():
|
||||
@@ -378,13 +420,12 @@ def initDreplace():
|
||||
content = mw.readFile(config)
|
||||
content = json.loads(content)
|
||||
|
||||
wfDir = path + "/waf/html"
|
||||
content['reqfile_path'] = wfDir
|
||||
content['reqfile_path'] = path + "/waf/html"
|
||||
mw.writeFile(config, mw.getJson(content))
|
||||
|
||||
makeDstLua()
|
||||
makeOpDstRunLua()
|
||||
|
||||
waf_conf = dstWafConf()
|
||||
waf_conf = dstWafConfPath()
|
||||
if not os.path.exists(waf_conf):
|
||||
waf_tpl = getPluginDir() + "/conf/luawaf.conf"
|
||||
content = mw.readFile(waf_tpl)
|
||||
@@ -401,6 +442,7 @@ def initDreplace():
|
||||
|
||||
if not mw.isAppleSystem():
|
||||
mw.execShell("chown -R www:www " + path)
|
||||
return path
|
||||
|
||||
|
||||
def status():
|
||||
@@ -408,7 +450,7 @@ def status():
|
||||
if not os.path.exists(path):
|
||||
return 'stop'
|
||||
|
||||
waf_conf = dstWafConf()
|
||||
waf_conf = dstWafConfPath()
|
||||
if not os.path.exists(waf_conf):
|
||||
return 'stop'
|
||||
return 'start'
|
||||
@@ -425,31 +467,7 @@ def start():
|
||||
|
||||
|
||||
def stop():
|
||||
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
|
||||
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
|
||||
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
|
||||
|
||||
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
|
||||
if os.path.exists(waf_init_dst):
|
||||
os.remove(waf_init_dst)
|
||||
|
||||
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
|
||||
if os.path.exists(init_worker_dst):
|
||||
os.remove(init_worker_dst)
|
||||
|
||||
access_file_dst = root_access_dir + '/opwaf_init.lua'
|
||||
if os.path.exists(access_file_dst):
|
||||
os.remove(access_file_dst)
|
||||
|
||||
wafconf = dstWafConf()
|
||||
if os.path.exists(wafconf):
|
||||
os.remove(wafconf)
|
||||
|
||||
import tool_task
|
||||
tool_task.removeBgTask()
|
||||
|
||||
mw.opLuaMakeAll()
|
||||
|
||||
makeOpDstStopLua()
|
||||
restartWeb()
|
||||
return 'ok'
|
||||
|
||||
@@ -460,16 +478,17 @@ def restart():
|
||||
|
||||
|
||||
def reload():
|
||||
stop()
|
||||
mw.opWeb('stop')
|
||||
|
||||
makeDstLua()
|
||||
makeOpDstRunLua(True)
|
||||
autoMakeLuaConf(True)
|
||||
initDefaultInfo(True)
|
||||
|
||||
errlog = mw.getServerDir() + "/openresty/nginx/logs/error.log"
|
||||
mw.execShell('rm -rf ' + errlog)
|
||||
elog = mw.getServerDir() + "/openresty/nginx/logs/error.log"
|
||||
if os.path.exists(elog):
|
||||
mw.execShell('rm -rf ' + elog)
|
||||
|
||||
start()
|
||||
|
||||
restartWeb()
|
||||
mw.opWeb('start')
|
||||
return 'ok'
|
||||
|
||||
|
||||
|
||||
@@ -36,7 +36,6 @@ Install_App(){
|
||||
fi
|
||||
|
||||
# which luarocks
|
||||
# if [ "$?" != "0" ];then
|
||||
if [ ! -d $serverPath/op_waf/luarocks ];then
|
||||
cd $serverPath/source/op_waf && tar xvf luarocks-3.5.0.tar.gz
|
||||
# cd luarocks-3.9.1 && ./configure && make bootstrap
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
<div class="main">
|
||||
<div class="title">OP网站防火墙|安全校验</div>
|
||||
<div class="content">
|
||||
<p id="change">5</p>
|
||||
<p id="change">3</p>
|
||||
</div>
|
||||
<div id="status" style="display: none;">false</div>
|
||||
</div>
|
||||
@@ -125,22 +125,22 @@ function ajax(type,bool){
|
||||
return xhr;
|
||||
}
|
||||
|
||||
ajax('JSON',true).post('{uri}',{'pass':"ok"}, function(data){
|
||||
if (data['status'] == 0){
|
||||
document.getElementById('status').innerHTML = 'ok';
|
||||
location.reload();
|
||||
}
|
||||
});
|
||||
|
||||
var ok = setInterval(function(){
|
||||
var id = document.getElementById('change').innerHTML;
|
||||
id = id - 1;
|
||||
if (id == 0){
|
||||
document.getElementById('change').innerHTML = '稍等';
|
||||
clearInterval(ok);
|
||||
if (document.getElementById('status').innerHTML == 'ok'){
|
||||
location.reload();
|
||||
}
|
||||
ajax('JSON',true).post('{uri}',{'pass':"ok"}, function(data){
|
||||
if (data['status'] == 0 && data['msg'] == 'ok'){
|
||||
document.getElementById('status').innerHTML = 'ok';
|
||||
setTimeout(function(){
|
||||
location.reload();
|
||||
},500);
|
||||
} else{
|
||||
document.getElementById('change').innerHTML = '?';
|
||||
}
|
||||
});
|
||||
} else {
|
||||
document.getElementById('change').innerHTML = id;
|
||||
}
|
||||
|
||||
@@ -35,10 +35,8 @@ local cookie_rules = require "rule_cookie"
|
||||
local url_rules = require "rule_url"
|
||||
local url_white_rules = require "rule_url_white"
|
||||
|
||||
|
||||
-- local server_name = string.gsub(C:get_sn(config_domains),'_','.')
|
||||
local server_name = C:get_sn(config_domains)
|
||||
|
||||
local function initParams()
|
||||
local data = {}
|
||||
data['server_name'] = server_name
|
||||
@@ -53,10 +51,12 @@ local function initParams()
|
||||
data['user_agent'] = data['request_header']['user-agent']
|
||||
data['cookie'] = ngx.var.http_cookie
|
||||
data['time'] = ngx.time()
|
||||
|
||||
return data
|
||||
end
|
||||
|
||||
local params = initParams()
|
||||
-- C:D(C:to_json(params))
|
||||
C:setParams(params)
|
||||
|
||||
local cpu_percent = ngx.shared.waf_limit:get("cpu_usage")
|
||||
@@ -343,6 +343,7 @@ local function waf_cc_increase()
|
||||
local make_uri_str = "?token="..make_token
|
||||
local make_uri = "/"..make_uri_str
|
||||
|
||||
-- C:D("token:"..tostring(params['uri_request_args']['token']))
|
||||
if params['uri_request_args']['token'] then
|
||||
ngx.header.content_type = "application/json"
|
||||
local args_token = params['uri_request_args']['token']
|
||||
@@ -352,14 +353,9 @@ local function waf_cc_increase()
|
||||
ngx.say(json.encode(data))
|
||||
ngx.exit(200)
|
||||
end
|
||||
|
||||
-- C:D("debug[args]:"..tostring(params['uri_request_args']['debug']))
|
||||
-- if params['uri_request_args']['debug'] == 'ok' then
|
||||
-- ngx.header.content_type = "application/json"
|
||||
-- local data = get_return_state(0, "ok")
|
||||
-- ngx.say(json.encode(data))
|
||||
-- ngx.exit(200)
|
||||
-- end
|
||||
local data = get_return_state(0, "unset")
|
||||
ngx.say(json.encode(data))
|
||||
ngx.exit(200)
|
||||
end
|
||||
|
||||
local cc_html = ngx.re.gsub(cc_safe_js_html, "{uri}", make_uri_str)
|
||||
@@ -531,7 +527,7 @@ end
|
||||
|
||||
|
||||
function waf()
|
||||
if server_name == "unset" then ngx.exit(403) end
|
||||
-- if server_name == "unset" then ngx.exit(403) end
|
||||
min_route()
|
||||
-- C:D("min_route")
|
||||
|
||||
|
||||
@@ -207,7 +207,7 @@ function _M.D(self, msg)
|
||||
local _msg = ''
|
||||
if type(msg) == 'table' then
|
||||
for key, val in pairs(msg) do
|
||||
_msg = tostring( key)..':'.."\n"
|
||||
_msg = tostring(key)..':'.."\n"
|
||||
end
|
||||
elseif type(msg) == 'string' then
|
||||
_msg = msg
|
||||
|
||||
Reference in New Issue
Block a user