feat(web): visual rule builder with geo, CIDR and wildcard pickers
The rule editor no longer requires writing expr by hand. Conditions are rows of field + operator + values joined with AND or OR, each row negatable, and the generated expression is shown live and validated by the engine before a rule is accepted. Raw expression and YAML editing are still available. Fields cover the connection (protocol, source/destination IP and port), domains (TLS SNI, QUIC SNI, DNS query name), HTTP (host, path, method, User-Agent) and protocol detection. Operators cover CIDR membership, GeoIP countries, GeoSite categories, port ranges, wildcards, substrings and regular expressions. Multiple values in a row are OR-ed, so one row holds a whole domain or country list. Wildcards compile to the cheapest expression that matches them: *.x.com becomes endsWith, x.* startsWith, *ad* contains, and only a star in the middle falls back to a regular expression. Values are validated as they are typed, including a hint when a star is used with an operator that would match it literally. Country and category pickers are backed by the databases the engine actually loaded, via a new GET /api/v1/geo endpoint (cached, loaded on demand) built on new listing methods in the geo package. Country names and flags come from Intl.DisplayNames, so no name table is shipped. Note that the v2geo format has no AS numbers; the provider groups it does contain (cloudflare, google, telegram, ...) are listed alongside the countries. Opening an existing rule parses its expression back into conditions. Anything the builder cannot represent opens in the expression editor with a warning rather than being rewritten. ruleset/expr_test.go pins the canonical expressions the builder generates and compiles them with the real engine, and the devserver now uses the real ruleset compiler so the same errors show up during frontend work. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+47
-2
@@ -8,8 +8,9 @@ the OpenGFW binary and served by the `web` package.
|
||||
blocked destinations and triggered rules
|
||||
- **Events** — real-time feed of verdicts, rule logs and errors with filters and a
|
||||
detail view showing raw analyzer properties
|
||||
- **Rules** — visual rule editor and a raw YAML editor, both validated by the engine
|
||||
itself; saving writes the rule file and hot reloads the running engine
|
||||
- **Rules** — a visual condition builder, a raw expression editor and a YAML editor,
|
||||
all validated by the engine itself; saving writes the rule file and hot reloads the
|
||||
running engine
|
||||
- **Analyzers** — which analyzers are compiled in and how much traffic each one saw
|
||||
- **Settings** — theme (light/dark/system), language (English/中文) and instance info
|
||||
|
||||
@@ -30,6 +31,49 @@ web:
|
||||
|
||||
If `secret` is empty a random password is generated and printed to the log on startup.
|
||||
|
||||
## Rule builder
|
||||
|
||||
Rules are still plain expr expressions in the rule file; the builder is only a way to
|
||||
write them without memorising the syntax. Conditions are rows of *field + operator +
|
||||
values*, joined with AND or OR, each row negatable:
|
||||
|
||||
| Field group | Fields |
|
||||
| ----------- | --------------------------------------------------------------- |
|
||||
| Connection | transport protocol, source/destination IP, source/destination port |
|
||||
| Domain | TLS SNI, QUIC SNI, DNS query name |
|
||||
| HTTP | Host, path, method, User-Agent |
|
||||
| Protocol | detected protocol (any analyzer) |
|
||||
|
||||
Operators cover the things rules usually need:
|
||||
|
||||
| Operator | Generated expression |
|
||||
| ----------------------- | ---------------------------------------------------------- |
|
||||
| domain or subdomain of | `(S == "x.com" \|\| S endsWith ".x.com")` |
|
||||
| matches wildcard | `*.x.com` → `endsWith`, `x.*` → `startsWith`, `*ad*` → `contains`, `a.*.c` → `matches` |
|
||||
| in CIDR | `cidr(ip.dst, "10.0.0.0/8")`, validated as you type |
|
||||
| in GeoIP country | `geoip(ip.dst, "cn")`, picked from the loaded database |
|
||||
| in GeoSite category | `geosite(string(.name), "category-ads-all@cn")` |
|
||||
| in range | `(port.dst >= 1000 && port.dst <= 2000)` |
|
||||
| is / contains / starts / ends / regex | the matching expr operator |
|
||||
|
||||
Multiple values in one row are OR-ed together, so one row can hold a whole domain or
|
||||
country list. The generated expression is shown live and validated by the engine before
|
||||
the rule is accepted.
|
||||
|
||||
Opening an existing rule parses its expression back into conditions. Anything the
|
||||
builder cannot represent — hand written expressions, functions like `lookup()` — opens
|
||||
in the expression editor with a warning instead of being rewritten.
|
||||
|
||||
The GeoIP picker lists whatever the configured `geoip.dat` contains: country codes plus,
|
||||
with the default Loyalsoldier database, provider groups such as `cloudflare`, `google`
|
||||
and `telegram`. Matching by AS number is not something the v2geo data format supports,
|
||||
so use those groups or an explicit CIDR list instead.
|
||||
|
||||
`web/frontend/src/lib/rule/` holds the whole thing: `fields.ts` (catalog), `compile.ts`
|
||||
(builder → expr), `parse.ts` (expr → builder) and `validate.ts`. The canonical
|
||||
expressions are pinned in `ruleset/expr_test.go`, which compiles them with the real
|
||||
engine.
|
||||
|
||||
## Layout
|
||||
|
||||
```
|
||||
@@ -83,6 +127,7 @@ endpoints only accept the bearer token, which makes them immune to CSRF.
|
||||
| `POST` | `/logout` | invalidate the current session |
|
||||
| `GET` | `/info` | version, platform and engine configuration |
|
||||
| `GET` | `/meta` | available analyzers, modifiers, actions, functions |
|
||||
| `GET` | `/geo` | GeoIP/GeoSite entries for the rule builder pickers |
|
||||
| `GET` | `/metrics` | counters, time series and top N lists |
|
||||
| `GET` | `/events?limit=` | recent events from the ring buffer |
|
||||
| `GET` | `/live` | server-sent events: `event` and `metrics` frames |
|
||||
|
||||
Reference in New Issue
Block a user