feat:spider deny strategy

This commit is contained in:
samwaf
2025-02-05 10:36:59 +08:00
parent 5270b838d8
commit eb23fb942e
3 changed files with 10 additions and 1 deletions
+1
View File
@@ -28,5 +28,6 @@ var (
GCONFIG_RECORD_DNS_BOT_EXPIRE_HOURS int64 = 24 //DNS bot有效期 单位小时 默认1天
GCONFIG_RECORD_DNS_NORMAL_EXPIRE_HOURS int64 = 7 * 24 //DNS 正常有效期 单位小时 默认7天
GCONFIG_RECORD_SPIDER_DENY int64 = 0 //爬虫禁止访问开关 默认 0 只检测不阻止访问 1 检测并阻止访问
)
+5 -1
View File
@@ -44,7 +44,11 @@ func (waf *WafEngine) CheckBot(r *http.Request, weblogbean *innerbean.WebLog, fo
weblogbean.GUEST_IDENTIFICATION = botResult.BotName
weblogbean.RISK_LEVEL = 1
result.IsBlock = true
if global.GCONFIG_RECORD_SPIDER_DENY == 1 {
result.IsBlock = true
} else {
result.IsBlock = false
}
result.Title = botResult.BotName
result.Content = "请正确访问"
return result
+4
View File
@@ -57,6 +57,9 @@ func setConfigIntValue(name string, value int64, change int) {
case "token_expire_time":
global.GCONFIG_RECORD_TOKEN_EXPIRE_MINTUTES = value
break
case "spider_deny":
global.GCONFIG_RECORD_SPIDER_DENY = value
break
default:
zlog.Warn("Unknown config item:", name)
}
@@ -166,5 +169,6 @@ func TaskLoadSetting(initLoad bool) {
updateConfigIntItem(initLoad, "system", "record_all_src_byte_info", global.GCONFIG_RECORD_ALL_SRC_BYTE_INFO, "启动记录原始请求BODY报文(1启动 0关闭)", "int", "")
updateConfigIntItem(initLoad, "system", "token_expire_time", global.GCONFIG_RECORD_TOKEN_EXPIRE_MINTUTES, "管理平台令牌有效期,单位分钟(默认5分钟)", "int", "")
updateConfigIntItem(initLoad, "system", "spider_deny", global.GCONFIG_RECORD_SPIDER_DENY, "爬虫禁止访问开关 默认 0 只检测不阻止访问 1 检测并阻止访问)", "int", "")
}