waf.go 22.4 KB
Newer Older
qiuqunfeng's avatar
qiuqunfeng committed
1 2 3
package service

import (
qiuqunfeng's avatar
qiuqunfeng committed
4
	"bytes"
qiuqunfeng's avatar
qiuqunfeng committed
5
	"context"
qiuqunfeng's avatar
commit  
qiuqunfeng committed
6
	"crypto/tls"
qiuqunfeng's avatar
qiuqunfeng committed
7
	"encoding/json"
qiuqunfeng's avatar
commit  
qiuqunfeng committed
8
	"fmt"
9
	"io"
qiuqunfeng's avatar
qiuqunfeng committed
10
	"net/http"
11
	"net/url"
qiuqunfeng's avatar
commit  
qiuqunfeng committed
12
	"os"
qiuqunfeng's avatar
qiuqunfeng committed
13 14
	"strconv"
	"strings"
qiuqunfeng's avatar
qiuqunfeng committed
15

qiuqunfeng's avatar
commit  
qiuqunfeng committed
16
	"github.com/rs/zerolog/log"
qiuqunfeng's avatar
commit  
qiuqunfeng committed
17
	"gitlab.com/tensorsecurity-rd/waf-console/internal/model"
qiuqunfeng's avatar
qiuqunfeng committed
18
	"gitlab.com/tensorsecurity-rd/waf-console/internal/utils"
qiuqunfeng's avatar
qiuqunfeng committed
19 20 21
	"gitlab.com/tensorsecurity-rd/waf-console/pkg/apis/waf.security.io/v1alpha1"
	"gorm.io/gorm"
	metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
22
	"k8s.io/apimachinery/pkg/util/sets"
qiuqunfeng's avatar
qiuqunfeng committed
23 24 25
)

type wafService struct {
qiuqunfeng's avatar
qiuqunfeng committed
26 27
	clusterClientManager *utils.ClusterClientManager
	db                   *gorm.DB
28
	gatewayUrl           string
qiuqunfeng's avatar
qiuqunfeng committed
29 30
}

31 32
func NewWafService(clusterClientManager *utils.ClusterClientManager, db *gorm.DB, gatewayUrl string) Service {
	return &wafService{clusterClientManager: clusterClientManager, db: db, gatewayUrl: gatewayUrl}
qiuqunfeng's avatar
qiuqunfeng committed
33 34
}

qiuqunfeng's avatar
qiuqunfeng committed
35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
func (s *wafService) GetWaf(ctx context.Context, regionCode, namespace, gatewayName string) (*WafService, error) {
	wafService := &model.WafService{}
	err := s.db.Model(&model.WafService{}).Where("gateway_name = ? AND region_code = ? AND namespace = ?", gatewayName, regionCode, namespace).First(wafService).Error
	if err != nil {
		if err == gorm.ErrRecordNotFound {
			// Create new WAF service record if not found
			wafService = &model.WafService{
				RegionCode:  regionCode,
				Namespace:   namespace,
				GatewayName: gatewayName,
				Mode:        string(WafModeAlert),
			}
			if err := s.db.Create(wafService).Error; err != nil {
				return nil, fmt.Errorf("failed to create WAF service: %v", err)
			}
		} else {
			return nil, fmt.Errorf("failed to query WAF service: %v", err)
		}
qiuqunfeng's avatar
qiuqunfeng committed
53
	}
54 55 56 57 58 59 60 61 62 63 64 65 66 67
	listenerWafs, err := s.ListListenerWafStatus(ctx, &GatewateInfo{
		GatewayName: gatewayName,
		Namespace:   namespace,
		RegionCode:  regionCode,
	})
	if err != nil {
		return nil, fmt.Errorf("failed to list listener WAF status: %v", err)
	}
	listeners := []string{}
	for _, listener := range listenerWafs {
		hosts := strings.Join(listener.Hosts, "@")
		listeners = append(listeners, fmt.Sprintf("%s-%d", hosts, listener.Port))
	}

qiuqunfeng's avatar
qiuqunfeng committed
68 69 70 71 72
	return &WafService{
		GatewayName: wafService.GatewayName,
		Mode:        wafService.Mode,
		RuleNum:     wafService.RuleNum,
		AttackNum:   wafService.AttackNum,
73
		Listeners:   listeners,
qiuqunfeng's avatar
qiuqunfeng committed
74
	}, nil
qiuqunfeng's avatar
qiuqunfeng committed
75 76
}

77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125
func (s *wafService) GetWafGatewayInfo(ctx context.Context, req *GetWafGatewayInfoReq) (*WafService, error) {
	wafService := &model.WafService{}
	err := s.db.Model(&model.WafService{}).Where("gateway_name = ? AND namespace = ? AND region_code = ?", req.GatewayName, req.Namespace, req.RegionCode).First(wafService).Error
	if err != nil {
		if err == gorm.ErrRecordNotFound {
			httpRequst := http.Request{
				Method: http.MethodPost,
				URL:    &url.URL{Scheme: "https", Host: "console.tensorsecurity.com", Path: "/api/v1/waf/gateway"},
				Header: http.Header{
					"Cookie": []string{req.Cookie},
				},
				Body: io.NopCloser(strings.NewReader(fmt.Sprintf(`{"gateway_name": "%s", "namespace": "%s", "region_code": "%s"}`, req.GatewayName, req.Namespace, req.RegionCode))),
			}
			resp, err := http.DefaultClient.Do(&httpRequst)
			if err != nil {
				return nil, fmt.Errorf("failed to get WAF service: %v", err)
			}
			defer resp.Body.Close()
			body, err := io.ReadAll(resp.Body)
			if err != nil {
				return nil, fmt.Errorf("failed to read WAF service: %v", err)
			}
			var wafService model.WafService
			err = json.Unmarshal(body, &wafService)
			if err != nil {
				return nil, fmt.Errorf("failed to unmarshal WAF service: %v", err)
			}
			wafService.ID = 0
			wafService.RuleCategoryStatus = nil
			wafService.RuleNum = 0
			wafService.AttackNum = 0
			// wafService.Host = model.HostList([]string{"*"})
			wafService.Mode = string(WafModeAlert)
			err = s.db.Create(wafService).Error
			if err != nil {
				return nil, fmt.Errorf("failed to create WAF service: %v", err)
			}
		} else {
			return nil, fmt.Errorf("failed to query WAF service: %v", err)
		}
	}
	return &WafService{
		GatewayName: wafService.GatewayName,
		Mode:        wafService.Mode,
		RuleNum:     wafService.RuleNum,
		AttackNum:   wafService.AttackNum,
	}, nil
}

qiuqunfeng's avatar
commit  
qiuqunfeng committed
126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187
func (s *wafService) getRulesForService(req *CreateWafReq) ([]v1alpha1.Rule, error) {
	rules := []v1alpha1.Rule{}
	ruleCategories := []model.WafRuleCategory{}
	if err := s.db.Model(&model.WafRuleCategory{}).Where("status = ?", 0).Find(&ruleCategories).Error; err != nil {
		return nil, fmt.Errorf("failed to get rule categories: %v", err)
	}

	// Get existing WAF service config if any
	wafService := &model.WafService{}
	err := s.db.Model(&model.WafService{}).Where("gateway_name = ? AND namespace = ? AND region_code = ?", req.GatewayName, req.Namespace, req.RegionCode).First(wafService).Error
	if err != nil {
		if err == gorm.ErrRecordNotFound {
			// Create new WAF service record if not found
			wafService = &model.WafService{
				RegionCode:  req.RegionCode,
				Namespace:   req.Namespace,
				GatewayName: req.GatewayName,
				Mode:        string(WafModeAlert),
			}
			if err := s.db.Create(wafService).Error; err != nil {
				return nil, fmt.Errorf("failed to create WAF service: %v", err)
			}
		} else {
			return nil, fmt.Errorf("failed to query WAF service: %v", err)
		}
	}

	// Determine which rule categories to enable
	var enabledCategories []model.WafRuleCategory

	if wafService.RuleCategoryStatus != nil && len(wafService.RuleCategoryStatus.CategoryID) > 0 {
		// Only include categories not already enabled
		for _, category := range ruleCategories {
			for _, id := range wafService.RuleCategoryStatus.CategoryID {
				if id == category.CategoryID {
					enabledCategories = append(enabledCategories, category)
					continue
				}
			}
		}
	} else {
		// Enable all categories if none specified
		enabledCategories = ruleCategories
	}

	for _, category := range enabledCategories {
		for _, rule := range category.Rules {
			rules = append(rules, v1alpha1.Rule{
				ID:          rule.ID,
				Level:       rule.Level,
				Name:        rule.Name,
				Type:        rule.Type,
				Description: rule.Description,
				Expr:        rule.Expr,
				Mode:        rule.Mode,
			})
		}
	}

	return rules, nil
}

qiuqunfeng's avatar
qiuqunfeng committed
188 189 190
func (s *wafService) CreateWaf(ctx context.Context, req *CreateWafReq) (*WafService, error) {
	// Create the WAF service resource
	name := fmt.Sprintf("%s-%d", req.GatewayName, req.Port)
qiuqunfeng's avatar
qiuqunfeng committed
191 192
	service := &v1alpha1.Service{
		ObjectMeta: metav1.ObjectMeta{
qiuqunfeng's avatar
qiuqunfeng committed
193
			Name:      name,
qiuqunfeng's avatar
qiuqunfeng committed
194
			Namespace: req.Namespace,
qiuqunfeng's avatar
qiuqunfeng committed
195 196 197
			Labels: map[string]string{
				"apigateway_name": req.GatewayName,
			},
qiuqunfeng's avatar
qiuqunfeng committed
198 199 200 201 202 203 204 205 206 207
		},
		Spec: v1alpha1.ServiceSpec{
			HostNames:   req.Host,
			ServiceName: req.GatewayName,
			Port:        req.Port,
			Workload: v1alpha1.WorkloadRef{
				Kind:      "Deployment",
				Name:      req.GatewayName,
				Namespace: req.Namespace,
			},
qiuqunfeng's avatar
qiuqunfeng committed
208 209 210 211 212 213 214 215
			Uri: &v1alpha1.StringMatch{
				Prefix: "/",
			},
			LogConfig: &v1alpha1.LogConfig{
				Enable: 1,
				Level:  "info",
			},
			Mode: "block",
qiuqunfeng's avatar
qiuqunfeng committed
216 217
		},
	}
qiuqunfeng's avatar
qiuqunfeng committed
218

219
	rules, err := s.getRulesForService(req)
qiuqunfeng's avatar
qiuqunfeng committed
220
	if err != nil {
221
		return nil, fmt.Errorf("failed to get rules for service: %v", err)
qiuqunfeng's avatar
qiuqunfeng committed
222
	}
223
	service.Spec.Rules = rules
qiuqunfeng's avatar
qiuqunfeng committed
224

225 226 227 228
	if len(service.Spec.Rules) == 0 {
		return nil, fmt.Errorf("cannot create WAF service with no rules")
	}

qiuqunfeng's avatar
qiuqunfeng committed
229 230 231
	// Create the WAF service in Kubernetes
	client := s.clusterClientManager.GetClient(req.RegionCode)
	if client == nil {
232
		return nil, fmt.Errorf("failed to get cluster client for region %s", req.RegionCode)
qiuqunfeng's avatar
qiuqunfeng committed
233 234 235
	}
	if _, err := client.WafV1alpha1().Services(req.Namespace).Create(ctx, service, metav1.CreateOptions{}); err != nil {
		return nil, fmt.Errorf("failed to create WAF service: %v", err)
qiuqunfeng's avatar
qiuqunfeng committed
236 237
	}

238 239 240 241 242 243
	return &WafService{
		GatewayName: req.GatewayName,
		Mode:        service.Spec.Mode,
		RuleNum:     len(service.Spec.Rules),
		AttackNum:   0,
	}, nil
qiuqunfeng's avatar
qiuqunfeng committed
244
}
qiuqunfeng's avatar
commit  
qiuqunfeng committed
245

qiuqunfeng's avatar
qiuqunfeng committed
246 247 248
func (s *wafService) DeleteListenerWaf(ctx context.Context, req *DeleteListenerReq) error {
	client := s.clusterClientManager.GetClient(req.RegionCode)
	if client == nil {
249
		return fmt.Errorf("failed to get cluster client for region %s", req.RegionCode)
qiuqunfeng's avatar
qiuqunfeng committed
250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282
	}
	name := fmt.Sprintf("%s-%d", req.GatewayName, req.Port)
	if err := client.WafV1alpha1().Services(req.Namespace).Delete(ctx, name, metav1.DeleteOptions{}); err != nil {
		return fmt.Errorf("failed to delete WAF service: %v", err)
	}
	return nil
}

func (s *wafService) UpdateMode(ctx context.Context, req *UpdateModeReq) (*WafService, error) {
	// Check if WAF service exists
	wafService := &model.WafService{}
	err := s.db.Model(&model.WafService{}).Where("gateway_name = ?", req.GatewayName).First(wafService).Error
	if err != nil {
		if err == gorm.ErrRecordNotFound {
			// Create new WAF service record if not found
			wafService = &model.WafService{
				RegionCode:  req.RegionCode,
				Namespace:   req.Namespace,
				GatewayName: req.GatewayName,
				Mode:        string(req.Mode),
			}
			if err := s.db.Create(wafService).Error; err != nil {
				return nil, fmt.Errorf("failed to create WAF service: %v", err)
			}
		} else {
			return nil, fmt.Errorf("failed to query WAF service: %v", err)
		}
	} else {
		// Update mode if service exists
		if err := s.db.Model(wafService).Update("mode", string(req.Mode)).Error; err != nil {
			return nil, fmt.Errorf("failed to update WAF service mode: %v", err)
		}
	}
283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305
	// Update mode for each listener
	client := s.clusterClientManager.GetClient(req.RegionCode)
	if client == nil {
		return nil, fmt.Errorf("failed to get cluster client for region %s", req.RegionCode)
	}
	listenerList, err := client.WafV1alpha1().Services(req.Namespace).List(ctx, metav1.ListOptions{LabelSelector: fmt.Sprintf("apigateway_name=%s", req.GatewayName)})
	if err != nil {
		return nil, fmt.Errorf("failed to get listener list: %v", err)
	}
	for _, listener := range listenerList.Items {
		listener := listener // Create new variable for goroutine
		go func() {
			log.Info().Msgf("update WAF service mode: %v", listener.Name)
			_, err := client.WafV1alpha1().Services(req.Namespace).Update(ctx, &listener, metav1.UpdateOptions{})
			if err != nil {
				log.Error().Msgf("failed to update WAF service mode: %v", err)
			}
		}()
	}
	return &WafService{
		GatewayName: req.GatewayName,
		Mode:        string(req.Mode),
	}, nil
qiuqunfeng's avatar
commit  
qiuqunfeng committed
306
}
qiuqunfeng's avatar
commit  
qiuqunfeng committed
307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336

func (s *wafService) GetRuleCategories(ctx context.Context) ([]WafRuleCategory, error) {
	var categories []WafRuleCategory
	err := s.db.Table("waf_rule_categories").Find(&categories).Error
	if err != nil {
		return nil, err
	}
	return categories, nil
}

func (s *wafService) GetRules(ctx context.Context, categoryID string) ([]WafRule, error) {
	var rules []WafRule
	err := s.db.Table("waf_rules").Where("category_id = ?", categoryID).Find(&rules).Error
	if err != nil {
		return nil, err
	}
	return rules, nil
}

func (s *wafService) GetRule(ctx context.Context, ruleID int) (*WafRule, error) {
	var rule WafRule
	err := s.db.Table("waf_rules").Where("id = ?", ruleID).First(&rule).Error
	if err != nil {
		return nil, err
	}
	return &rule, nil
}

func (s *wafService) SaveRuleCategoryToDB(ctx context.Context) error {
	var categories []WafRuleCategory
337
	jsonFile, err := os.ReadFile("rules/waf-rules.json")
qiuqunfeng's avatar
commit  
qiuqunfeng committed
338 339 340 341
	if err != nil {
		return fmt.Errorf("error reading yaml file: %v", err)
	}

342 343
	// err = yaml.Unmarshal(yamlFile, &categories)
	err = json.Unmarshal(jsonFile, &categories)
qiuqunfeng's avatar
commit  
qiuqunfeng committed
344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370
	if err != nil {
		return fmt.Errorf("error unmarshaling yaml: %v", err)
	}

	for _, category := range categories {
		rules := []model.WafRule{}
		for _, rule := range category.Rules {
			rules = append(rules, model.WafRule{
				ID:          rule.ID,
				CategoryID:  category.CategoryID,
				Level:       rule.Level,
				Name:        rule.Name,
				Type:        rule.Type,
				Description: rule.Description,
				Expr:        rule.Expr,
				Mode:        rule.Mode,
			})
		}
		model := model.WafRuleCategory{
			CategoryID:    category.CategoryID,
			Status:        category.Status,
			CategoryEN:    category.Catagory.EN,
			CategoryZH:    category.Catagory.Zh,
			DescriptionEN: category.Description.EN,
			DescriptionZH: category.Description.Zh,
			Rules:         model.RuleList(rules),
		}
qiuqunfeng's avatar
commit  
qiuqunfeng committed
371 372 373 374
		err = s.db.Table("waf_rule_categories").Create(&model).Error
		if err != nil {
			return err
		}
qiuqunfeng's avatar
commit  
qiuqunfeng committed
375 376 377 378
	}

	return nil
}
qiuqunfeng's avatar
qiuqunfeng committed
379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395

func (s *wafService) DeleteListener(ctx context.Context, req *DeleteListenerReq) error {
	listener := &model.GatewayListener{}
	err := s.db.Model(&model.GatewayListener{}).Where("gateway_name = ? AND namespace = ? AND region_code = ?", req.GatewayName, req.Namespace, req.RegionCode).First(listener).Error
	if err != nil {
		return err
	}

	err = s.db.Model(&model.GatewayListener{}).Where("gateway_name = ? AND namespace = ? AND region_code = ?", req.GatewayName, req.Namespace, req.RegionCode).Delete(listener).Error
	if err != nil {
		return err
	}

	return nil
}

func (s *wafService) EnableListenerWaf(ctx context.Context, req *EnableListenerWafReq) error {
396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415
	// listener := &model.GatewayListener{}
	// err := s.db.Model(&model.GatewayListener{}).Where("gateway_name = ? AND namespace = ? AND region_code = ?", req.GatewayName, req.Namespace, req.RegionCode).First(listener).Error
	// if err != nil {
	// 	if err == gorm.ErrRecordNotFound {
	// 		listener = &model.GatewayListener{
	// 			GatewayName: req.GatewayName,
	// 			Namespace:   req.Namespace,
	// 			RegionCode:  req.RegionCode,
	// 			Port:        int(req.Port),
	// 			Enable:      req.Enable,
	// 			Hosts:       req.Hosts,
	// 		}
	// 		err = s.db.Model(&model.GatewayListener{}).Create(listener).Error
	// 		if err != nil {
	// 			return err
	// 		}
	// 	} else {
	// 		return err
	// 	}
	// }
qiuqunfeng's avatar
qiuqunfeng committed
416

417 418 419 420 421
	// listener.Enable = req.Enable
	// err = s.db.Model(&model.GatewayListener{}).Where("gateway_name = ? AND namespace = ? AND region_code = ?", req.GatewayName, req.Namespace, req.RegionCode).Update("enable", req.Enable).Error
	// if err != nil {
	// 	return err
	// }
qiuqunfeng's avatar
qiuqunfeng committed
422

423 424
	if req.Enable {
		log.Info().Msgf("Create WAF for listener %s", req.GatewayName)
qiuqunfeng's avatar
commit  
qiuqunfeng committed
425
		_, err := s.CreateWaf(ctx, &CreateWafReq{
qiuqunfeng's avatar
qiuqunfeng committed
426 427 428 429 430 431
			GatewateInfo: GatewateInfo{
				GatewayName: req.GatewayName,
				Namespace:   req.Namespace,
				RegionCode:  req.RegionCode,
			},
			Port: uint32(req.Port),
432
			Host: req.Hosts,
qiuqunfeng's avatar
qiuqunfeng committed
433
		})
qiuqunfeng's avatar
commit  
qiuqunfeng committed
434 435 436
		if err != nil {
			return err
		}
qiuqunfeng's avatar
qiuqunfeng committed
437
	} else {
438 439
		log.Info().Msgf("Delete WAF for listener %s", req.GatewayName)
		err := s.DeleteListenerWaf(ctx, &DeleteListenerReq{
qiuqunfeng's avatar
qiuqunfeng committed
440 441 442 443 444 445 446
			GatewateInfo: GatewateInfo{
				GatewayName: req.GatewayName,
				Namespace:   req.Namespace,
				RegionCode:  req.RegionCode,
			},
			Port: req.Port,
		})
qiuqunfeng's avatar
commit  
qiuqunfeng committed
447 448 449
		if err != nil {
			return err
		}
qiuqunfeng's avatar
qiuqunfeng committed
450 451 452 453
	}
	return nil
}

454 455 456 457 458 459
func getGatewayNameFromCrn(crn string) string {
	// crn:ucs::apigateway:lf-tst7:214613666997:instance/testaaa
	parts := strings.Split(crn, "/")
	return parts[len(parts)-1]
}

460
func (s *wafService) listListenerFromApiGateway(ctx context.Context, apiGatewayCrn string, regionCode string, cookie string) ([]GatewayRespListenerData, error) {
461 462 463 464 465 466 467
	body, err := json.Marshal(map[string]string{
		"apigateway_crn": apiGatewayCrn,
		"region_code":    regionCode,
	})
	if err != nil {
		return nil, fmt.Errorf("failed to marshal request body: %v", err)
	}
468
	request, err := http.NewRequestWithContext(ctx, "POST", "https://csm.console.test.tg.unicom.local/apigatewaymng/listener/lf-tst7/list_listeners", bytes.NewBuffer(body))
469 470 471 472
	if err != nil {
		return nil, fmt.Errorf("failed to create request: %v", err)
	}
	request.Header.Set("Cookie", cookie)
qiuqunfeng's avatar
commit  
qiuqunfeng committed
473 474 475 476 477 478 479 480
	// Create custom transport with TLS config
	tr := &http.Transport{
		TLSClientConfig: &tls.Config{
			InsecureSkipVerify: true, // Skip certificate verification for test environment
		},
	}
	client := &http.Client{Transport: tr}
	resp, err := client.Do(request)
481 482 483 484 485
	if err != nil {
		return nil, fmt.Errorf("failed to get listener list: %v", err)
	}
	defer resp.Body.Close()

486
	log.Info().Msgf("resp: %v", resp)
487 488 489 490 491 492
	// Parse response
	var response GatewayListenerResponseList

	if err := json.NewDecoder(resp.Body).Decode(&response); err != nil {
		return nil, fmt.Errorf("failed to parse listener list: %v", err)
	}
493
	log.Info().Msgf("response: %v", response)
494 495 496
	return response.Data, nil
}

qiuqunfeng's avatar
qiuqunfeng committed
497 498
func (s *wafService) EnableGatewayWaf(ctx context.Context, req *EnableGatewayWafReq) error {
	if req.Enable {
499
		listeners, err := s.listListenerFromApiGateway(ctx, req.ApiGatewayCrn, req.RegionCode, req.Cookie)
qiuqunfeng's avatar
qiuqunfeng committed
500 501 502
		if err != nil {
			return fmt.Errorf("failed to get listener list: %v", err)
		}
qiuqunfeng's avatar
commit  
qiuqunfeng committed
503
		log.Info().Msgf("listeners: %v", listeners)
qiuqunfeng's avatar
qiuqunfeng committed
504 505
		// Create WAF for each listener
		for _, listener := range listeners {
qiuqunfeng's avatar
commit  
qiuqunfeng committed
506 507
			gatewayName := getGatewayNameFromCrn(listener.ApiGatewayCrn)
			namespace := fmt.Sprintf("%s-%s", listener.CreateAccountName, listener.CreateAccountID)
qiuqunfeng's avatar
qiuqunfeng committed
508 509
			if _, err := s.CreateWaf(ctx, &CreateWafReq{
				GatewateInfo: GatewateInfo{
qiuqunfeng's avatar
commit  
qiuqunfeng committed
510 511
					GatewayName: gatewayName,
					Namespace:   namespace,
qiuqunfeng's avatar
qiuqunfeng committed
512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590
					RegionCode:  req.RegionCode,
				},
				Port: uint32(listener.Port),
				Host: listener.Hosts,
			}); err != nil {
				return fmt.Errorf("failed to create WAF for listener %d: %v", listener.Port, err)
			}
		}
	} else {
		s.DeleteGatewayWaf(ctx, &GatewateInfo{
			GatewayName: req.GatewayName,
			Namespace:   req.Namespace,
			RegionCode:  req.RegionCode,
		})
	}
	return nil
}

func (s *wafService) DeleteGatewayWaf(ctx context.Context, req *GatewateInfo) error {
	client := s.clusterClientManager.GetClient(req.RegionCode)
	if client == nil {
		return fmt.Errorf("failed to get cluster client")
	}
	labelSelector := fmt.Sprintf("apigateway_name=%s", req.GatewayName)
	if err := client.WafV1alpha1().Services(req.Namespace).DeleteCollection(ctx, metav1.DeleteOptions{}, metav1.ListOptions{LabelSelector: labelSelector}); err != nil {
		return fmt.Errorf("failed to delete WAF service: %v", err)
	}
	return nil
}

func (s *wafService) UpdateRule(ctx context.Context, req *RuleRequest) error {
	wafService := &model.WafService{}
	err := s.db.Model(&model.WafService{}).Where("gateway_name = ?", req.GatewayName).First(wafService).Error
	if err != nil {
		if err == gorm.ErrRecordNotFound {
			// Create new WAF service record if not found
			wafService = &model.WafService{
				RegionCode:  req.RegionCode,
				Namespace:   req.Namespace,
				GatewayName: req.GatewayName,
				Mode:        string(WafModeAlert),
				RuleCategoryStatus: &model.RuleCategoryStatus{
					CategoryID: req.CategoryID,
					Status:     req.Status,
				},
			}
			if err := s.db.Create(wafService).Error; err != nil {
				return fmt.Errorf("failed to create WAF service: %v", err)
			}
		} else {
			return fmt.Errorf("failed to query WAF service: %v", err)
		}
	} else {
		// Update mode if service exists
		if err := s.db.Model(wafService).Update("rule_category_status", model.RuleCategoryStatus{
			CategoryID: req.CategoryID,
			Status:     req.Status,
		}).Error; err != nil {
			return fmt.Errorf("failed to update WAF service mode: %v", err)
		}
	}
	return nil
}

func (s *wafService) ListListenerWafStatus(ctx context.Context, req *GatewateInfo) ([]*GatewayListener, error) {
	client := s.clusterClientManager.GetClient(req.RegionCode)
	if client == nil {
		return nil, fmt.Errorf("failed to get cluster client")
	}

	listenerList, err := client.WafV1alpha1().Services(req.Namespace).List(ctx, metav1.ListOptions{LabelSelector: fmt.Sprintf("apigateway_name=%s", req.GatewayName)})
	if err != nil {
		return nil, fmt.Errorf("failed to get listener list: %v", err)
	}

	listenerStatusList := []*GatewayListener{}
	for _, listener := range listenerList.Items {
		n := strings.LastIndex(listener.Name, "-")
		if n == -1 {
qiuqunfeng's avatar
commit  
qiuqunfeng committed
591
			return nil, fmt.Errorf("failed to get listener port: %v", listener.Name)
qiuqunfeng's avatar
qiuqunfeng committed
592 593 594 595
		}
		listenerPort := listener.Name[n+1:]
		listenerPortInt, err := strconv.Atoi(listenerPort)
		if err != nil {
qiuqunfeng's avatar
commit  
qiuqunfeng committed
596
			return nil, fmt.Errorf("failed to parse listener port: %v", err)
qiuqunfeng's avatar
qiuqunfeng committed
597 598
		}

599 600
		// hosts := strings.Join(listener.Spec.HostNames, "@")
		// log.Info().Msgf("hosts: %v", hosts)
qiuqunfeng's avatar
qiuqunfeng committed
601 602 603 604
		listenerStatusList = append(listenerStatusList, &GatewayListener{
			GatewayName: req.GatewayName,
			Namespace:   req.Namespace,
			RegionCode:  req.RegionCode,
605 606
			Port:        listenerPortInt,
			Hosts:       listener.Spec.HostNames,
qiuqunfeng's avatar
qiuqunfeng committed
607 608 609
		})
	}

610 611 612 613 614 615 616 617 618 619
	// for _, port := range portList {
	// 	listenerStatusList = append(listenerStatusList, &GatewayListener{
	// 		GatewayName: req.GatewayName,
	// 		Namespace:   req.Namespace,
	// 		RegionCode:  req.RegionCode,
	// 		Port:        port,
	// 		Enable:      true,
	// 	})
	// }

qiuqunfeng's avatar
qiuqunfeng committed
620 621
	return listenerStatusList, nil
}
622 623 624 625 626 627 628 629 630 631

func (s *wafService) EnableListenerWafs(ctx context.Context, req *EnableListenerWafsReq) error {

	client := s.clusterClientManager.GetClient(req.RegionCode)
	if client == nil {
		return fmt.Errorf("failed to get cluster client")
	}

	listenerList, err := client.WafV1alpha1().Services(req.Namespace).List(ctx, metav1.ListOptions{LabelSelector: fmt.Sprintf("apigateway_name=%s", req.GatewayName)})
	if err != nil {
632
		log.Error().Msgf("failed to get listener list: %v", err)
633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651
		return err
	}

	portList := []int{}
	for _, listener := range listenerList.Items {
		n := strings.LastIndex(listener.Name, "-")
		if n == -1 {
			return fmt.Errorf("failed to get listener port: %v", listener.Name)
		}
		listenerPort := listener.Name[n+1:]
		listenerPortInt, err := strconv.Atoi(listenerPort)
		if err != nil {
			return fmt.Errorf("failed to parse listener port: %v", err)
		}
		portList = append(portList, listenerPortInt)
	}
	currentPortSet := sets.NewInt(portList...)

	desiredPortSet := sets.NewInt()
652 653
	wafMap := map[int][]string{}
	for _, listener := range req.Listeners {
654
		// get port from listener.HostsAndPort, like hosts1@127.0.0.1@abc.com-8080
655
		index := strings.LastIndex(listener.HostsAndPort, "-")
656 657 658
		if index == -1 {
			return fmt.Errorf("failed to get listener port: %v", listener)
		}
659
		port := listener.HostsAndPort[index+1:]
660 661 662 663 664
		portInt, err := strconv.Atoi(port)
		if err != nil {
			return fmt.Errorf("failed to parse listener port: %v", err)
		}
		desiredPortSet.Insert(portInt)
665
		log.Info().Msgf("listener: %v", listener.Name)
666

667
		hosts := strings.Split(listener.HostsAndPort[:index], "@")
668
		wafMap[portInt] = hosts
669 670 671 672 673 674 675 676 677 678 679
	}

	// enable WAF for ports that are in the desired port set but not in the current port set
	addingPortSet := desiredPortSet.Difference(currentPortSet)
	for _, port := range addingPortSet.List() {
		err := s.EnableListenerWaf(ctx, &EnableListenerWafReq{
			GatewateInfo: GatewateInfo{
				GatewayName: req.GatewayName,
				Namespace:   req.Namespace,
				RegionCode:  req.RegionCode,
			},
680 681 682
			Port:   port,
			Hosts:  wafMap[port],
			Enable: true,
683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705
		})
		if err != nil {
			return fmt.Errorf("failed to enable listener WAF: %v", err)
		}
	}

	// delete WAF for ports that are not in the desired port set
	deletingPortSet := currentPortSet.Difference(desiredPortSet)
	for _, port := range deletingPortSet.List() {
		err := s.DeleteListenerWaf(ctx, &DeleteListenerReq{
			GatewateInfo: GatewateInfo{
				GatewayName: req.GatewayName,
				Namespace:   req.Namespace,
				RegionCode:  req.RegionCode,
			},
			Port: port,
		})
		if err != nil {
			return fmt.Errorf("failed to delete listener WAF: %v", err)
		}
	}
	return nil
}