mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
refactor(ban): drop ipinfo cgnat blast-radius guard (#3062)
This commit is contained in:
@@ -27,7 +27,7 @@ Fluxer builds each permission name from `ban:`, the list name with each hyphen w
|
||||
| avatar-hash<sup>7</sup> | Avatar hashes blocked from being set |
|
||||
| profile-substring<sup>3</sup> <sup>8</sup> | Substrings blocked from one named profile field |
|
||||
|
||||
<sup>1</sup> Fluxer refuses an address with 400 `IP_BAN_DECLINED` when it is on the instance exemption list, or when IP lookup data shows that a single address is on a mobile carrier network, and records both refusals in the Admin audit log
|
||||
<sup>1</sup> Fluxer refuses an address with 400 `IP_BAN_DECLINED` when it is on the instance exemption list, and records the refusal in the Admin audit log
|
||||
|
||||
<sup>2</sup> Stored lowercased, so a mixed-case value does not create a second row
|
||||
|
||||
@@ -367,7 +367,7 @@ Every write is an upsert on the canonical value. An omitted optional field is wr
|
||||
|
||||
A body field the selected blocklist does not accept is stripped and never produces that 400. A `url` Fluxer cannot canonicalise returns 400 `INVALID_FORM_BODY` naming `url` in the `errors` array.
|
||||
|
||||
Fluxer refuses to add an `ip` with 400 `IP_BAN_DECLINED` when the address is on the instance exemption list, and when a single address is classified as a high blast-radius mobile or carrier network. Fluxer runs that carrier network check only for a single address, so the check never refuses a CIDR range. When the IP lookup for the check fails, Fluxer writes the address.
|
||||
Fluxer refuses to add an `ip` with 400 `IP_BAN_DECLINED` when the address is on the instance exemption list.
|
||||
|
||||
The response has no body, so it does not report the canonical form that was stored. Read it back with [List blocklist entries](#list-blocklist-entries).
|
||||
|
||||
@@ -375,7 +375,7 @@ The response has no body, so it does not report the canonical form that was stor
|
||||
|
||||
Fluxer checks later requests against the written rows. For every list except `email`, other nodes see the rows after a short propagation delay. No Gateway Dispatch is emitted.
|
||||
|
||||
Fluxer records one [Admin audit entry](/admin-api/#admin-audit-entry-object) per written value, with that value in its metadata. It records an entry for a refused `ip` too, under the action `ban_ip_skipped_exempt` or `ban_ip_skipped_cgnat`, before it returns the 400.
|
||||
Fluxer records one [Admin audit entry](/admin-api/#admin-audit-entry-object) per written value, with that value in its metadata. It records an entry for a refused `ip` too, under the action `ban_ip_skipped_exempt`, before it returns the 400.
|
||||
|
||||
### Rate limit
|
||||
|
||||
|
||||
@@ -319,7 +319,6 @@ An entry with any other action has `access` set to `write`.
|
||||
| ban_email | An address was added to the email blocklist |
|
||||
| ban_file_sha | A file hash was added to the attachment blocklist |
|
||||
| ban_ip | An address was added to the IP blocklist |
|
||||
| ban_ip_skipped_cgnat | An IP blocklist entry was declined because IP intelligence reports the address as a mobile carrier network |
|
||||
| ban_ip_skipped_exempt | An IP blocklist entry was declined by the instance exemption list |
|
||||
| ban_member | An account was banned from a guild |
|
||||
| ban_phrase | A phrase was added to the message phrase blocklist |
|
||||
|
||||
@@ -988,10 +988,6 @@ Default `3310`. The scanner port. Integer. Compose forwards it from `.env`.
|
||||
|
||||
Default `false`. Behaviour when the scanner is unreachable. With scanning on and this off, an unreachable scanner rejects every upload. Compose forwards it from `.env`.
|
||||
|
||||
#### `FLUXER_IPINFO_API_KEY`
|
||||
|
||||
Default empty. The ipinfo key. Admin and guild IP bans use it to skip carrier-grade NAT and other shared addresses. Without it those checks treat every address as unknown. The previous name `FLUXER_RISK_IPINFO_API_KEY` is still read when this one is unset or empty. Compose forwards this name from `.env`, and not the previous one.
|
||||
|
||||
#### `FLUXER_BLOCKLIST_FEEDS_ENABLED`
|
||||
|
||||
Defaults to the inverse of `FLUXER_SELF_HOSTED`. Off by default on a self-hosted instance. With feeds on, the worker downloads the URLhaus and PhishTank URL lists every six hours, and MalwareBazaar file hashes every twelve hours. Fluxer checks posted links against the URLs and uploads against the hashes.
|
||||
@@ -1686,7 +1682,7 @@ Every `FLUXER_CASSANDRA_` name. The stack runs Postgres.
|
||||
|
||||
#### Older names of a forwarded setting
|
||||
|
||||
`FLUXER_NATS_CORE_URL`, `FLUXER_RISK_IPINFO_API_KEY`, `KLIPY_API_KEY` and `YOUTUBE_API_KEY`. A service reads each only when the name it replaces is unset or empty, and Compose forwards that name instead.
|
||||
`FLUXER_NATS_CORE_URL`, `KLIPY_API_KEY` and `YOUTUBE_API_KEY`. A service reads each only when the name it replaces is unset or empty, and Compose forwards that name instead.
|
||||
|
||||
#### Individual Stripe price names
|
||||
|
||||
|
||||
Reference in New Issue
Block a user