Debian
2ab9da8e36
fix(waf): CRS v4 Regeln extrahiert + Control-Flow-Regeln filtern — v1.2.82
...
- crsRules.ts neu: 331 echte CRS v4.7.0 Regeln aus installierten Dateien
(v3-Nummernschema war falsch, v4 hat andere IDs — 949152 war skip-Regel)
- spoe.go: Regeln ohne Message nicht als Alert speichern
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-03 13:25:46 +02:00
Debian
220d9d7050
feat(waf): Alerts — Regelübereinstimmungen in DB + UI — v1.2.77
...
- Migration 0038: waf_alerts-Tabelle
- AlertWriter (Buffered-Channel → async DB-Write)
- SPOE: MatchedRules → sendAlert() nach ProcessRequestHeaders()
- API: GET /waf/alerts + DELETE /waf/alerts
- WAF-Page: Tabs Domains | Alarme; Alarme-Tabelle mit Rule-ID,
Severity, Aktion (Detected/Blocked), URI, Client-IP + Purge-Button
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-03 10:40:43 +02:00
Debian
08119f8ccf
fix(waf): Engine nur bei Konfigurationsänderung neu bauen — v1.2.75
...
Manager.Reload() hat bisher bei jedem 30s-Tick alle Engines neu gebaut
(BuildEngine mit CRS = 2-5s). Fix: configKey (enabled, mode, paranoia_level,
updatedAt) cachen — Engine wird nur neu gebaut wenn sich der Key ändert.
Spart CPU und verhindert sporadische Latenzen im SPOE-Handling.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-03 07:07:30 +02:00
Debian
bf16ce6666
feat(waf): Phase 3 — HAProxy SPOE-Integration — v1.2.68
...
- haproxy.cfg.tpl: filter spoe + deny_status 403 + spoe-edgeguard-waf
Backend (nur gerendert wenn WAFEnabled=true)
- haproxy.go: WAFEnabled in View; WafRepo.ListEnabled() prüft ob WAF
aktiv; SPOE-Config-File (coraza-spoe.cfg) wird bei WAFEnabled
atomar geschrieben; SPOEConfigPath konfigurierbar
- waf/spoe.go: uri statt path+query (HAProxy url-Sample = volle URI)
SPOE-Config definiert:
- Agent: edgeguard-waf-agent, var-prefix=waf, timeout processing 50ms
- Message: src, method, uri=url, ver=req.ver, headers=req.hdrs,
host=req.hdr(host)
- Backend: spoe-edgeguard-waf → 127.0.0.1:9000
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-02 15:53:07 +02:00
Debian
bd32bc343a
feat(waf): Phase 2 — edgeguard-waf Binary + SPOE + Coraza Engine — v1.2.67
...
- cmd/edgeguard-waf/: neues Binary — lädt WAF-Configs aus DB, startet
SPOE-Agent auf 127.0.0.1:9000, refreshed Configs alle 30s
- internal/waf/engine.go: BuildEngine() — Coraza WAF aus WafConfig bauen
(SecLang-Direktiven: RuleEngine, PL, CRS-Include, Exclusions, Custom)
- internal/waf/manager.go: Manager — per-Hostname Coraza-Engine-Cache
(thread-safe, Lazy-Init via Reload(), Port-Strip, IPv6-Brackets)
- internal/waf/spoe.go: SPOEAgent — haproxy-go SPOE-Handler
(src/method/path/query/ver/host/headers aus HAProxy-Vars,
Coraza-Transaction, Blocking: txn.waf.status=403 setzen)
- services/waf/waf.go: ListAllWithDomain() — JOIN domains+waf_configs
- go.mod: coraza/v3 v3.7.0 + dropmorepackets/haproxy-go v0.0.8
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-06-02 15:43:15 +02:00