113 lines
3.5 KiB
Plaintext
113 lines
3.5 KiB
Plaintext
init_by_lua_block {
|
|
|
|
local dataloader = require "dataloader"
|
|
local logger = require "logger"
|
|
local cjson = require "cjson"
|
|
local remoteapi = require "remoteapi"
|
|
|
|
local use_redis = {% if USE_REDIS == "yes" %}true{% else %}false{% endif +%}
|
|
|
|
local use_proxies = {% if has_value("BLOCK_PROXIES", "yes") %}true{% else %}false{% endif +%}
|
|
local use_abusers = {% if has_value("BLOCK_ABUSERS", "yes") %}true{% else %}false{% endif +%}
|
|
local use_tor_exit_nodes = {% if has_value("BLOCK_TOR_EXIT_NODE", "yes") %}true{% else %}false{% endif +%}
|
|
local use_user_agents = {% if has_value("BLOCK_USER_AGENT", "yes") %}true{% else %}false{% endif +%}
|
|
local use_referrers = {% if has_value("BLOCK_REFERRER", "yes") %}true{% else %}false{% endif +%}
|
|
|
|
local use_remote_api = {% if has_value("USE_REMOTE_API", "yes") %}true{% else %}false{% endif +%}
|
|
|
|
if not use_redis then
|
|
if use_proxies then
|
|
dataloader.load_ip("/etc/nginx/proxies.list", ngx.shared.proxies_data)
|
|
end
|
|
|
|
if use_abusers then
|
|
dataloader.load_ip("/etc/nginx/abusers.list", ngx.shared.abusers_data)
|
|
end
|
|
|
|
if use_tor_exit_nodes then
|
|
dataloader.load_ip("/etc/nginx/tor-exit-nodes.list", ngx.shared.tor_exit_nodes_data)
|
|
end
|
|
|
|
if use_user_agents then
|
|
dataloader.load_raw("/etc/nginx/user-agents.list", ngx.shared.user_agents_data)
|
|
end
|
|
|
|
if use_referrers then
|
|
dataloader.load_raw("/etc/nginx/referrers.list", ngx.shared.referrers_data)
|
|
end
|
|
end
|
|
|
|
-- Load plugins
|
|
ngx.shared.plugins_data:safe_set("plugins", nil, 0)
|
|
local p = io.popen("find /opt/bunkerized-nginx/plugins -maxdepth 1 -type d ! -path /opt/bunkerized-nginx/plugins")
|
|
for dir in p:lines() do
|
|
-- read JSON
|
|
local file = io.open(dir .. "/plugin.json")
|
|
if file then
|
|
-- store settings
|
|
local data = cjson.decode(file:read("*a"))
|
|
for k, v in pairs(data.settings) do
|
|
ngx.shared.plugins_data:safe_set(data.id .. "_" .. k, v, 0)
|
|
end
|
|
file:close()
|
|
-- call init
|
|
local plugin = require(data.id .. "/" .. data.id)
|
|
local init = true
|
|
if plugin["init"] ~= nil then
|
|
init = plugin.init()
|
|
end
|
|
-- store plugin
|
|
if init then
|
|
local plugins, flags = ngx.shared.plugins_data:get("plugins")
|
|
if plugins == nil then
|
|
ngx.shared.plugins_data:safe_set("plugins", data.id, 0)
|
|
else
|
|
ngx.shared.plugins_data:safe_set("plugins", plugins .. " " .. data.id, 0)
|
|
end
|
|
logger.log(ngx.ERR, "PLUGINS", "*NOT AN ERROR* plugin " .. data.name .. "/" .. data.version .. " has been loaded")
|
|
else
|
|
logger.log(ngx.ERR, "PLUGINS", "init failed for plugin " .. data.name .. "/" .. data.version)
|
|
end
|
|
else
|
|
logger.log(ngx.ERR, "PLUGINS", "Can't load " .. dir .. "/plugin.json")
|
|
end
|
|
|
|
end
|
|
p:close()
|
|
|
|
-- Remote API
|
|
if use_remote_api then
|
|
|
|
-- Save server
|
|
ngx.shared.remote_api:set("server", "{{ REMOTE_API_SERVER }}", 0)
|
|
|
|
-- Save version
|
|
local f = io.open("/opt/bunkerized-nginx/VERSION", "r")
|
|
ngx.shared.remote_api:set("version", f:read("*all"), 0)
|
|
f:close()
|
|
|
|
-- Save and ask a machine ID if needed
|
|
local f = io.open("/etc/nginx/machine.id", "rw")
|
|
if f == nil then
|
|
id = nil
|
|
logger.log(ngx.ERR, "REMOTE API", "USE_REMOTE_API is set to yes but machine ID is not generated - communication with {{ REMOTE_API_SERVER }} won't work")
|
|
else
|
|
id = f:read("*all")
|
|
logger.log(ngx.ERR, "REMOTE API", "*NOT AN ERROR* Machine ID = " .. id)
|
|
end
|
|
f:close()
|
|
|
|
-- Test the machine ID
|
|
if id ~= nil then
|
|
local res, pong = remoteapi.ping()
|
|
if not res or pong ~= "pong" then
|
|
logger.log(ngx.ERR, "REMOTE API", "Ping failed, the remote server may be down or your machine ID is invalid")
|
|
else
|
|
logger.log(ngx.ERR, "REMOTE API", "*NOT AN ERROR* Ping successful")
|
|
end
|
|
end
|
|
|
|
end
|
|
|
|
}
|