Xe Iaso
35b5e78a0d
chore: tag v1.25.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2026-02-18 15:56:28 +00:00
Xe Iaso
80a8e0a8ae
chore: add Databento as diamond tier sponsor
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-12-30 10:56:58 -05:00
Xe Iaso
6d9c0abe74
chore: tag v1.24.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-12-23 21:17:59 -05:00
Xe Iaso
ba8a1b7caf
fix(honeypot/naive): right, we want the client IP, not the load balancer IP
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-12-16 04:44:59 -05:00
Xe Iaso
40afc13d7f
fix(honeypot/naive): implement better IP parsing logic
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-12-16 04:32:45 -05:00
Xe Iaso
9c54aa852f
chore: v1.24.0-pre1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-12-02 07:58:29 -05:00
Xe Iaso
b836506785
chore: v1.23.1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-11-07 19:39:07 -05:00
Xe Iaso
62c1b80189
chore: tag v1.23.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-10-29 20:38:34 -04:00
Xe Iaso
ab8b91fc0c
chore: v1.23.0-pre2
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-10-26 19:23:16 -04:00
Xe Iaso
2fc3765340
chore: tag v1.23.0-pre1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-10-22 14:35:23 +00:00
Xe Iaso
8cdf58c9e6
ci(ssh): re-enable aarch64-16k
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-20 15:30:29 +00:00
Xe Iaso
9439466ff2
ci(ssh): disable aarch64-16k until my SFP connecter comes in on friday
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-17 16:00:10 +00:00
Xe Iaso
88b3e457ee
docs: update BotStopper docs based on new features
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-14 20:16:43 +00:00
Xe Iaso
f79d36d21e
docs: update CHANGELOG properly
...
It helps if you save your editor buffer!
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-11 14:07:52 +00:00
Xe Iaso
f5b5243b5e
docs: update CHANGELOG
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-11 14:04:32 +00:00
Xe Iaso
c43d7ca686
docs(botstopper): add HTML templating support
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-06 23:42:23 +00:00
Xe Iaso
5d5c39e123
chore: v1.22.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-06 11:54:36 -04:00
Xe Iaso
48b49a0190
docs(CHANGELOG): add changelog entry for v1.22.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-05 22:42:08 +00:00
Xe Iaso
489abb6b4d
chore: release v1.22.0-pre2
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-09-02 21:31:17 -04:00
Xe Iaso
f6a578787f
chore(docs): adjust anubis rules
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-29 23:04:32 +00:00
Xe Iaso
1a4b5cadcb
chore: fix spelling
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-29 20:31:20 +00:00
Xe Iaso
00afa72c4b
fix(blog/cpu-core-odd): make the diagram look decent in light mode
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-29 19:54:22 +00:00
Xe Iaso
eb50f59351
docs(changelog): fix mis-paste
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-29 19:54:02 +00:00
Xe Iaso
a7a61690fc
chore: commit for v1.22.0-pre1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-23 22:39:43 -04:00
Xe Iaso
f5afe8b6c8
chore: release v1.22.0-pre1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-24 02:38:54 +00:00
Xe Iaso
e43999f30c
chore: add libreapay
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-16 03:01:59 +00:00
Xe Iaso
22ee227f20
fix(anubis): use global cookie prefix variable
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-08-07 13:51:18 +00:00
Xe Iaso
b81c577106
chore(docs/anubis-cfg): update contact email
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-29 15:38:08 +00:00
Xe Iaso
987c1d7410
chore(go.mod): depend on at least go 1.24.2
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-29 04:06:16 +00:00
Xe Iaso
958992a69a
chore: release v1.21.3
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-25 10:30:44 -04:00
Xe Iaso
45ff8f526e
fix(lib): add additional validation logic for XSS protection
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-24 14:57:58 +00:00
Xe Iaso
5700512da5
chore: release v1.21.2
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-24 10:47:32 -04:00
Xe Iaso
1cb1352a44
fix(blog/v1.21.1): we avoid breaking changes
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-22 22:54:22 +00:00
Xe Iaso
d6298adc6d
chore: fix name of backoff-retry, expose in devcontainer
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-18 17:51:13 +00:00
Xe Iaso
2915c1d209
fix(docs/manifest): k8s typo
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-16 20:35:33 -04:00
Xe Iaso
0fd4bb81b8
ci(docs): fix docs image tag names in the right file
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-14 21:28:22 +00:00
Xe Iaso
603c68fd54
ci(docs): fix docs image tag names
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-14 21:25:36 +00:00
Xe Iaso
6d8b98eb3d
Revert "test: add git push smoke test"
...
This reverts commit b9d8275234 .
2025-07-14 10:26:47 -04:00
Xe Iaso
b9d8275234
test: add git push smoke test
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-14 10:25:40 -04:00
Xe Iaso
3f6750ac7d
chore(sponsors): add fabulous systems
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-12 23:08:30 +00:00
Xe Iaso
25d75b352a
chore: release v1.21.0-pre3
2025-07-12 17:29:18 -04:00
Xe Iaso
607c9791d8
chore(docs): add fly.toml file as a hail mary
...
Ref #799
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-10 06:05:17 -04:00
Xe Iaso
6b67be86a1
chore(docs/manifest): branded 404 page
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-09 17:06:23 -04:00
Xe Iaso
e02f017153
chore(docs/manifest): remove fastcgi from the nginx config
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-09 17:01:42 -04:00
Xe Iaso
ea2e76c6ee
chore: tag version 1.21.0-pre1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-06 19:35:06 -04:00
Xe Iaso
94db16c0df
docs: add emma.pet sponsor
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-06 14:25:27 +00:00
Xe Iaso
e870ede120
docs(known-instances): add git.aya.so
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-05 16:41:36 +00:00
Xe Iaso
592d1e3dfc
docs(known-instances): add Pluralpedia
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-05 16:40:32 +00:00
Xe Iaso
f6254b4b98
docs(installation): clarify BASE_PREFIX matches the /.within.website endpoints
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-05 13:47:02 +00:00
Xe Iaso
7b72c790ab
chore: spelling
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-05 12:29:19 +00:00
Xe Iaso
719a1409ca
test(lib/store/bbolt): disable this test case for now
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-05 04:56:19 +00:00
Xe Iaso
93bfe910d8
docs(user/faq): clarify Anubis not being a cryptocurrency miner
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-04 22:49:39 +00:00
Xe Iaso
19d8de784b
chore(docs/manifest): enable bbolt in an emptyDir
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-04 21:07:37 +00:00
Xe Iaso
845095c3f6
chore(robots.txt): don't block CCBot
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-04 00:23:21 +00:00
Xe Iaso
2f1e78cc6c
chore(docs/manifest): allow common crawl to test with the team
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-04 00:22:43 +00:00
Xe Iaso and GitHub
888b7d6e77
fix(run/anubis@.service): unique runtimedir per instance ( #750 )
...
* fix(run/anubis@.service): unique runtimedir per instance
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-03 10:29:05 +00:00
Xe Iaso
c981c23f7e
chore: npm run generate
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-02 05:25:10 +00:00
Xe Iaso and GitHub
9f0c5e974e
fix(web/main): remove the success interstitial ( #745 )
...
I'm gonna be totally honest here, I'm still not sure why #564 is still
an issue. This is really confusing and I'm going to totally throw out
how Anubis issues challenges and redo it with Valkey (#201 , #622 ).
The problem seems to be that I assume that the makeChallenge function in
package lib is idempotent for the same client. I have no idea why this
would be inconsistent, but for some reason it is and I'm just at a loss
for words as to why this is happening.
This stops the bleeding by improving the UX as a stopgap.
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-07-01 23:44:38 +00:00
Xe Iaso and GitHub
f5b3bf81bc
feat: dev container support ( #734 )
...
* chore: add devcontainer for Anubis
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(devcontainer): ensure user can write to $HOME
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(devcontainer): forward ports, add launch config
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(devcontainer): add playwright deps
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: document devcontainer usage
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* ci(devcontainer): fix action references
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(devcontainer): fix ko on arm64
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-29 23:41:29 -04:00
Xe Iaso
b1edf84a7c
docs(blog/v1.20.0): i am smart
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-27 21:10:02 -04:00
Xe Iaso
d47a3406db
docs(blog/v1.20.0): how did CI not catch this?
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-27 19:55:58 -04:00
Xe Iaso
ff5991b5cf
docs(blog/v1.20.0): add cover image
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-27 19:20:12 -04:00
Xe Iaso
19f78f37ad
docs(blog/v1.20.0): fix typo
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-27 18:59:07 -04:00
Xe Iaso
b0b0a5c08a
feat(blog): v1.20.0 announcement post
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-27 18:56:09 -04:00
Xe Iaso
c2423d0688
chore: release v1.20.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-27 12:06:22 -04:00
Xe Iaso and GitHub
a1b7d2ccda
feat: dynamic cookie domains ( #722 )
...
* feat: dynamic cookie domains
Replaces #685
I was having weird testing issues when trying to merge #685 , so I
rewrote it from scratch to be a lot more minimal.
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-26 12:11:59 +00:00
Xe Iaso
f9259299b9
chore: release v1.20.0-pre2
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-23 15:17:13 -04:00
Xe Iaso and GitHub
16a4e04027
fix(lib): fix invalid response after success in Chrome ( #711 )
...
Closes #564
This one is really dumb. Take a seat and listen to my tale of woe.
While @victorvalenca was working on #693 we ran into a strange issue.
The tests would consistently pass on Firefox but instantly failed on
Chrome. After adding increasingly desperate debugging logs to the mix,
we found out that somehow Chrome was randomizing the contents of its
Accept-Language header. This was making the challenge string get
calculated differently, thus making things spuriously fail. I cannot
figure out what causes Chrome to do this other than you being in an
environment where you have more than one "system language" set.
Either way, this should finally fix this issue and bring peace to the
land forever*.
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-23 15:11:56 -04:00
Xe Iaso
4c74934e9f
fix(default-config): Techaro -> Zombocom
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-22 20:04:40 -04:00
Xe Iaso and GitHub
5870f7072c
feat: implement imprint/impressum support ( #706 )
...
* feat: implement imprint/impressum support
Closes #362
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(docs/anubis): enable an imprint
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: fix the end of the sentence, comment out a default impressum
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: link back to impressum page
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-22 18:09:37 -04:00
Xe Iaso and GitHub
3c1d95d61e
fix(default-config): off-by-one error in the default thresholds ( #701 )
...
I don't know how I missed this in testing.
2025-06-20 11:47:34 -04:00
Xe Iaso
ecc716940e
chore: release v1.20.0-pre1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-19 19:32:49 -04:00
Xe Iaso and GitHub
4948036f39
feat: add default OpenGraph tags to configuration file ( #694 )
...
* feat(config): opengraph passthrough configuration
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(ogtags): use config.OpenGraph for configuration
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: wire up ogtags config in most of the app
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(ogtags): return default tags if they are supplied
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: make OpenGraph legal so we have some sanity in reviewing
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): use OpenGraph.Enabled
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib): load default config file if one is not specified in spawnAnubis
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(config): fix ST1005
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: document open graph defaults and its new home in the policy file
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs(installation): point to weight threshold new home
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: rename default to override
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(default-config): add off-by-default opengraph settings to bot policy file
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(anubis): make build
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib): fix build
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-19 18:00:44 -04:00
Xe Iaso and GitHub
7aa732c700
fix(config): actually load threshold config ( #696 )
...
* fix(config): actually load threshold config
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib): fix test failures
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-19 17:13:01 -04:00
226cf36bf7
feat(config): custom weight thresholds via CEL ( #688 )
...
* feat(config): add Thresholds to the top level config file
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(config): make String() on ExpressionOrList join the component expressions
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(config): ensure unparseable json fails
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(config): if no thresholds are set, use the default thresholds
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(policy): half implement thresholds
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(policy): continue wiring things up
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(lib): wire up thresholds
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib): handle behavior from legacy configurations
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: document thresholds
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: update CHANGELOG, refer to threshold configuration
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): fix build
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(lib): fix U1000
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
Signed-off-by: Jason Cameron <git@jasoncameron.dev >
Co-authored-by: Jason Cameron <git@jasoncameron.dev >
2025-06-18 16:58:31 -04:00
Xe Iaso
ae064be710
chore(docs/manifest): it helps if you terminate strings properly
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-16 12:11:04 -04:00
Xe Iaso and GitHub
e3826df3ab
feat: implement a client for Thoth, the IP reputation database for Anubis ( #637 )
...
* feat(internal): add Thoth client and simple ASN checker
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(thoth): cached ip to asn checker
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: go mod tidy
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(thoth): minor testing fixups, ensure ASNChecker is Checker
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(thoth): make ASNChecker instances
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(thoth): add GeoIP checker
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(thoth): store a thoth client in a context
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: refactor Checker type to its own package
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(thoth): add thoth mocking package, ignore context deadline exceeded errors
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(thoth): pre-cache private ranges
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(lib/policy/config): enable thoth ASNs and GeoIP checker parsing
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(thoth): refactor to move checker creation to the checker files
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(policy): enable thoth checks
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(thothmock): test helper function for loading a mock thoth instance
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat: wire up Thoth, make thoth checks part of the default config
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(thoth): mend staticcheck errors
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs(admin): add Thoth docs
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(policy): update Thoth links in error messages
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: update CHANGELOG
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore(docs/manifest): enable Thoth
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: add THOTH_INSECURE for contacting Thoth over plain TCP in extreme circumstances
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(thoth): use mock thoth when credentials aren't detected in the environment
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(cmd/anubis): better warnings for half-configured Thoth setups
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs(botpolicies): link to Thoth geoip docs
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-16 11:57:32 -04:00
Xe Iaso
823d1be5d1
chore(docs/manifest): explicitly allow blog RSS feed
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-16 11:50:53 -04:00
Xe Iaso
0c6a820372
chore(docs/manifest): enable OG_PASSTHROUGH
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-16 09:31:56 -04:00
Xe Iaso and GitHub
81f6380dd4
Add the blog section back ( #670 )
...
* Revert "docs/blog: remove (#273 )"
This reverts commit df3509ec99 .
* chore: intro to the blog post
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-16 09:28:21 -04:00
Xe Iaso and GitHub
d1452b6d39
test(ssh-ci): re-enable GOARCH=ppc64le ( #651 )
...
This reverts commit 5e95da6b6c .
2025-06-11 14:01:48 -04:00
Xe Iaso
5e95da6b6c
test(ssh-ci): disable GOARCH=ppc64le for now
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-11 12:58:32 -04:00
Xe Iaso and GitHub
f5140ae57b
test: introduce SSH based CI for non-native test hosts ( #644 )
...
* feat: ssh based CI
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test: implement SSH ci with caches and github actions
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): fix known hosts secret
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): clone the repo, that's important
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): speed up ci by prebaking the SSH CI image
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): set -euo
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): enable pull_request_target so things work
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): oh goody it's broken
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): add cronjob to rebuild ci runner image
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): also run yeet
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): force git version for yeet
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): run set -x in the container
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): fix yeet?
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): remove yeet for now
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(ssh-ci): disable for PRs for now
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-11 12:50:01 -04:00
Xe Iaso and GitHub
c638653172
feat(lib): implement request weight ( #621 )
...
* feat(lib): implement request weight
Replaces #608
This is a big one and will be what makes Anubis a generic web
application firewall. This introduces the WEIGH option, allowing
administrators to have facets of request metadata add or remove
"weight", or the level of suspicion. This really makes Anubis weigh
the soul of requests.
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): maintain legacy challenge behavior
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): make weight have dedicated checkers for the hashes
Signed-off-by: Xe Iaso <me@xeiaso.net >
* feat(data): convert some rules over to weight points
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: document request weight
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(CHANGELOG): spelling error
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: fix links to challenge information
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs(policies): fix formatting
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(config): make default weight adjustment 5
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-09 15:25:04 -04:00
Xe Iaso
372b797f64
chore: go generate
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-08 20:52:22 -04:00
Xe Iaso
8eff57fcb6
chore(docs/manifest): try no-js challenge to see how it impacts false positive rate
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-06 21:40:28 -04:00
Xe Iaso and GitHub
4ac59c3a79
feat(lib/challenge): HTTP meta refresh challenge method ( #623 )
...
* feat(lib/challenge): HTTP meta refresh challenge method
Closes #95
This challenge method enables users that don't (or won't) support
JavaScript to pass Anubis challenges. It works by using HTML meta
refresh directives to ensure that the client is a browser.
This is OFF by default. In order to enable it, an administrator MUST
choose to make the default challenge method `metarefresh`.
TODO(Xe):
- [ ] Documentation on this challenge method
- [ ] Amend wording around Anubis being a proof of work proxy in the docs
- [ ] Add configuration file syntax for the default challenge method and settings
- [ ] Test with early customers
Signed-off-by: Xe Iaso <me@xeiaso.net >
* chore: spelling
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib/challenge/metarefresh): use this value of err
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: add metarefresh challenge info, Web AI Firewall Utility
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-06 21:18:55 -04:00
Xe Iaso and GitHub
5a7499ea3b
fix(lib/challenge): allow challenges to register HTTP routes ( #620 )
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-06 00:26:23 +00:00
Xe Iaso and GitHub
f2db43ad4b
feat: implement challenge registry ( #607 )
...
* feat: implement challenge method registry
This paves the way for implementing a no-js check method (#95 ) by making
the challenge providers more generic.
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib/challenge): rename proof-of-work package to proofofwork
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): make validated challenges a CounterVec
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): annotate jwts with challenge method
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib/challenge/proofofwork): implement tests
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib): add smoke tests for known good and known bad config files
Signed-off-by: Xe Iaso <me@xeiaso.net >
* docs: update CHANGELOG
Signed-off-by: Xe Iaso <me@xeiaso.net >
* fix(lib): use challenge.Impl#Issue when issuing challenges
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-04 02:01:58 +00:00
Xe Iaso
ba4412c907
chore(sponsors): add Raptor Computing Systems
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-03 17:49:28 -04:00
Xe Iaso and GitHub
f184cd81e7
docs(faq): anubis does not mine bitcoin ( #609 )
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-03 07:14:41 -04:00
Xe Iaso
59bfced8bf
docs(admin/environments): update suggested HTTP headers
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-03 06:57:37 -04:00
Xe Iaso
780a935cb8
chore(sponsors): add wildbase
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-03 06:18:40 -04:00
Xe Iaso
f4bc1df797
chore(sponsors): add Uberspace
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-02 09:42:13 -04:00
Xe Iaso
ec733e93a5
v1.19.1
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-01 17:17:24 -04:00
Xe Iaso
51c384eefd
fix(data/bots): bring back ai-robots-txt.yaml
...
Closes #599
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-01 17:15:00 -04:00
Xe Iaso
44d5ec0b6e
chore: release version v1.19.0
...
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-01 16:35:03 -04:00
Xe Iaso
3bc9040a96
chore: bump yeet to v0.6.0
...
Gives us many nice things like:
* Windows support for yeet (modulo TecharoHQ/yeet#29 )
* Removes the dependency on /bin/sh or /bin/bash thanks to
mvdan.cc/sh/v3
* Checksum-compliant reproducible builds by default
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-06-01 16:33:08 -04:00
Xe Iaso and GitHub
fbbab5a035
feat(lib): annotate cookies with what rule was passed ( #576 )
...
* feat(lib): annotate cookies with what rule was passed
Anubis JWTs now contain a policyRule claim with the cryptographic hash
of the rule that it passed. This is intended to help with a future move
away from proof of work being the default.
Signed-off-by: Xe Iaso <me@xeiaso.net >
* test(lib): fix cookie storage logic
Signed-off-by: Xe Iaso <me@xeiaso.net >
---------
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-05-30 14:42:02 -04:00
Xe Iaso and GitHub
497005ce3e
fix(lib): only use the first five characters of Accept-Language header values ( #588 )
...
For some reason, Google Chrome will randomly send a "full"
Accept-Language header, and other times it will send a "partial"
Accept-Language header. This makes the challenge construction
inconsistent.
This commit fixes this issue by only considering up to the first five
characters of the Accept-Language header when making a challenge string.
Signed-off-by: Xe Iaso <me@xeiaso.net >
2025-05-30 13:15:03 -04:00