feat(security): harden client IP and admin controls

This commit is contained in:
elky
2026-07-10 15:13:12 +08:00
parent 6e0dc3b59e
commit bc1da3bf3f
19 changed files with 976 additions and 378 deletions
@@ -37,10 +37,10 @@ pub(crate) use self::email_templates::{
};
pub(crate) use self::external_models::OFFICIAL_EXTERNAL_MODEL_PROVIDERS;
pub(crate) use self::normalize::{
deserialize_optional_json_patch, deserialize_optional_string_list_patch, ip_rules_allow,
json_ip_rules_allow, normalize_feature_settings, normalize_ip_rules, normalize_json_array,
normalize_json_object, normalize_string_list, normalize_user_self_feature_settings_update,
parse_json_ip_rules,
deserialize_optional_json_patch, deserialize_optional_string_list_patch,
ip_rule_pattern_matches, ip_rules_allow, json_ip_rules_allow, normalize_feature_settings,
normalize_ip_rules, normalize_json_array, normalize_json_object, normalize_string_list,
normalize_user_self_feature_settings_update, parse_json_ip_rules,
};
pub(crate) use self::payloads::{
InternalGatewayAuthContextRequest, InternalGatewayExecuteRequest,
@@ -257,7 +257,7 @@ fn valid_ipv4_wildcard_pattern(pattern: &str) -> bool {
.all(|part| *part == "*" || part.parse::<u8>().is_ok())
}
fn ip_rule_pattern_matches(pattern: &str, remote_ip: IpAddr) -> bool {
pub(crate) fn ip_rule_pattern_matches(pattern: &str, remote_ip: IpAddr) -> bool {
if pattern == "*" {
return true;
}