From c3c17ea9dcdfe518079d6c32f94f14bef59d6fd6 Mon Sep 17 00:00:00 2001 From: pofilo Date: Wed, 5 Mar 2025 22:31:51 +0100 Subject: [PATCH] add random timeout on deny --- geoblock.go | 11 ++++++++++- readme.md | 5 +++++ 2 files changed, 15 insertions(+), 1 deletion(-) diff --git a/geoblock.go b/geoblock.go index db4424b..251a193 100755 --- a/geoblock.go +++ b/geoblock.go @@ -7,6 +7,7 @@ import ( "io" "io/fs" "log" + "math/rand" "net" "net/http" "os" @@ -55,6 +56,7 @@ type Config struct { HTTPStatusCodeDeniedRequest int `yaml:"httpStatusCodeDeniedRequest"` LogFilePath string `yaml:"logFilePath"` RedirectURLIfDenied string `yaml:"redirectUrlIfDenied"` + DelayOnDenyMs int `yaml:"delayOnDenyMs"` } type ipEntry struct { @@ -94,6 +96,7 @@ type GeoBlock struct { logFile *os.File redirectURLIfDenied string name string + delayOnDenyMs int } // New created a new GeoBlock plugin. @@ -178,6 +181,7 @@ func New(ctx context.Context, next http.Handler, config *Config, name string) (h logFile: logFile, redirectURLIfDenied: config.RedirectURLIfDenied, name: name, + delayOnDenyMs: config.DelayOnDenyMs, }, nil } @@ -202,7 +206,12 @@ func (a *GeoBlock) ServeHTTP(rw http.ResponseWriter, req *http.Request) { rw.WriteHeader(http.StatusFound) return } - + // Introduce a delay before responding (with +-50%) + if a.delayOnDenyMs > 0 { + randomFactor := 0.5 + rand.Float64() // between 0.5 and 1.5 + randomDelay := time.Duration(float64(a.delayOnDenyMs) * randomFactor) + time.Sleep(time.Duration(randomDelay) * time.Millisecond) + } rw.WriteHeader(a.httpStatusCodeDeniedRequest) return } diff --git a/readme.md b/readme.md index 5438237..0b4c8a6 100755 --- a/readme.md +++ b/readme.md @@ -182,6 +182,7 @@ my-GeoBlock: unknownCountryApiResponse: "nil" blackListMode: false addCountryHeader: false + delayOnDenyMs: 2000 countries: - AF # Afghanistan - AL # Albania @@ -526,3 +527,7 @@ Basically tells GeoBlock to only allow/deny a request based on the first IP addr ### Define a custom log file `redirectUrlIfDenied` Allows returning a HTTP 301 status code, which indicates that the requested resource has been moved. The URL which can be specified is used to redirect the client to. So instead of "blocking" the client, the client will be redirected to the configured URL. + +### Define a custom delay on requests `delayOnDenyMs` + +Add a +-50% random delay for deny requests. This is useful to limit spam from forbidden IPs.