-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathallow.go
More file actions
153 lines (122 loc) · 2.9 KB
/
allow.go
File metadata and controls
153 lines (122 loc) · 2.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
package golangIPSentry
import (
"context"
"encoding/json"
"fmt"
"os"
"sync"
"time"
"github.com/redis/go-redis/v9"
)
type AllowIPManager struct {
Logger *Logger
Config *Config
Redis *redis.Client
Context context.Context
Mutex sync.RWMutex
Cache map[string]*IPItem
}
func (i *IPGuardian) newAllowManager() *AllowIPManager {
manager := &AllowIPManager{
Logger: i.Logger,
Config: i.Config,
Redis: i.Redis,
Context: i.Context,
Cache: make(map[string]*IPItem),
}
err := manager.load()
if err != nil {
i.Logger.Error(err, "Failed to load white list from file")
}
return manager
}
func (m *AllowIPManager) load() error {
m.Mutex.Lock()
defer m.Mutex.Unlock()
path := defaultWhiteListPath
// * custom path is exist, use it
if m.Config.Filepath.WhiteList != "" {
path = m.Config.Filepath.WhiteList
}
// * file is not exist, skip importing
if _, err := os.Stat(path); os.IsNotExist(err) {
return nil
}
data, err := os.ReadFile(path)
// * failed to read file, stop importing
if err != nil {
return err
}
var list []IPItem
// * failed to parse json, stop importing
if err := json.Unmarshal(data, &list); err != nil {
return err
}
pipe := m.Redis.Pipeline()
for _, item := range list {
data, err := json.Marshal(item)
// * failed to parse item, skip this item
if err != nil {
continue
}
// * add item to memory cache
m.Cache[item.IP] = &item
key := fmt.Sprintf(redisAllow, item.IP)
pipe.Set(m.Context, key, data, 0)
}
_, err = pipe.Exec(m.Context)
// * failed to execute pipeline, stop importing
if err != nil {
return m.Logger.Error(err, "Failed to store white list to redis")
}
return nil
}
func (m *AllowIPManager) Check(ip string) bool {
key := fmt.Sprintf(redisAllow, ip)
exist, err := m.Redis.Exists(m.Context, key).Result()
if err == nil && exist > 0 {
return true
}
m.Mutex.RLock()
defer m.Mutex.RUnlock()
_, cache := m.Cache[ip]
return cache
}
// * save white list to file
func (m *AllowIPManager) save() error {
path := defaultWhiteListPath
if m.Config.Filepath.WhiteList != "" {
path = m.Config.Filepath.WhiteList
}
var list []IPItem
for _, item := range m.Cache {
list = append(list, *item)
}
data, err := json.MarshalIndent(list, "", " ")
if err != nil {
return err
}
return os.WriteFile(path, data, 0644)
}
func (m *AllowIPManager) Add(ip string, tag string) error {
m.Mutex.Lock()
defer m.Mutex.Unlock()
item := &IPItem{
IP: ip,
Reason: tag,
AddedAt: time.Now().UTC().Unix(),
}
m.Cache[ip] = item
data, err := json.Marshal(item)
if err != nil {
return m.Logger.Error(err, "Failed to parse white ip")
}
key := fmt.Sprintf(redisAllow, ip)
if err := m.Redis.Set(m.Context, key, data, 0).Err(); err != nil {
return m.Logger.Error(err, "Failed to store white ip to redis")
}
if err := m.save(); err != nil {
return m.Logger.Error(err, "Failed to save white ip to file")
}
return nil
}