Documentation
¶
Index ¶
Examples ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BlacklistListener ¶
BlacklistListener returns a new lister with IP blacklist. Connections are immediately closed when they were not allowed by the blacklist. Given ip addresses must be in valid form for net/netip.ParsePrefix or net/netip.ParseAddr. ln must not be nil.
func WhitelistListener ¶
WhitelistListener returns a new lister with IP whitelist. Connections are immediately closed when they were not allowed by the whitelist. Given ip addresses must be in valid form for net/netip.ParsePrefix or net/netip.ParseAddr. ln must not be nil.
Types ¶
type Blacklist ¶
type Blacklist struct {
// contains filtered or unexported fields
}
Blacklist is the IP blacklist.
Example (Ipv4) ¶
prefixes := []string{
"10.0.0.0/8", // 10.0.0.0–10.255.255.255 Private network
"100.64.0.0/10", // 100.64.0.0–100.127.255.255 Private network
"127.0.0.0/8", // 127.0.0.0–127.255.255.255 Host
"172.16.0.0/12", // 172.16.0.0–172.31.255.255 Private network
"192.0.0.0/24", // 192.0.0.0–192.0.0.255 Private network
"192.168.0.0/16", // 192.168.0.0–192.168.255.255 Private network
"198.18.0.0/15", // 198.18.0.0–198.19.255.255 Private network
}
bl := NewBlacklist()
err := bl.Disallow(prefixes...)
if err != nil {
panic(err)
}
targetIPs := []string{
"10.255.255.1", // NG
"127.0.0.1", // NG
"192.168.1.2", // NG
"192.88.10.20", // OK
"224.10.20.30", // OK
"255.255.10.20", // OK
}
for _, ip := range targetIPs {
fmt.Printf("%s --> %v\n", ip, bl.Allowed(ip))
}
Output: 10.255.255.1 --> false 127.0.0.1 --> false 192.168.1.2 --> false 192.88.10.20 --> true 224.10.20.30 --> true 255.255.10.20 --> true
func NewBlacklist ¶
func NewBlacklist() *Blacklist
NewBlacklist returns a new instance of Blacklist. Blacklist checks IPv4 and IPv6 addresses with blacklist.
func (*Blacklist) Allowed ¶
Allowed returns if the ip is allowed by the blacklist. Both IPv4 and IPv6 are accepted.
func (*Blacklist) AllowedAddr ¶
AllowedAddr returns if the addr is allowed by the blacklist. Both IPv4 and IPv6 are accepted.
func (*Blacklist) Disallow ¶
Disallow adds addresses to the blacklist. When an address contains "/" it will be parsed with net/netip.ParsePrefix, others will be parsed with net/netip.ParseAddr. Given addresses must be in valid form for the functions. If parsing an address encounters an error, add immediately returns the error without processing the remaining addresses. When using CIDR, "/0" matches to all IPs and "<IPv4>/32" or "<IPv6>/128" matches to the only specified IP.
func (*Blacklist) DisallowAddr ¶
DisallowAddr adds ipv4 and ipv6 addresses to the blacklist. Invalid, non-ipv4 nor non-ipv6, addresses are ignored.
func (*Blacklist) DisallowPrefix ¶
DisallowPrefix adds ipv4 and ipv6 addresses to the blacklist. Invalid, non-ipv4 nor non-ipv6, addresses are ignored.
type Whitelist ¶
type Whitelist struct {
// contains filtered or unexported fields
}
Whitelist is the IP whitelist.
Example ¶
wl := NewWhitelist()
err := wl.Allow("127.0.0.0/8", "192.168.0.0/16", "fd00:0:0::/48")
if err != nil {
panic(err)
}
targetIPs := []string{
"127.0.0.1", // OK
"192.168.1.1", // OK
"126.0.0.1", // NG
"192.169.1.1", // NG
"fd00:0:0::1", // OK
"fd00:0:0:1::1", // OK
"fd00:0:1::1", // NG
"fc00:0:0::1", // NG
}
for _, ip := range targetIPs {
fmt.Printf("%s --> %v\n", ip, wl.Allowed(ip))
}
Output: 127.0.0.1 --> true 192.168.1.1 --> true 126.0.0.1 --> false 192.169.1.1 --> false fd00:0:0::1 --> true fd00:0:0:1::1 --> true fd00:0:1::1 --> false fc00:0:0::1 --> false
Example (Ipv4) ¶
prefixes := []string{
"10.0.0.0/8", // 10.0.0.0–10.255.255.255 Private network
"100.64.0.0/10", // 100.64.0.0–100.127.255.255 Private network
"127.0.0.0/8", // 127.0.0.0–127.255.255.255 Host
"172.16.0.0/12", // 172.16.0.0–172.31.255.255 Private network
"192.0.0.0/24", // 192.0.0.0–192.0.0.255 Private network
"192.168.0.0/16", // 192.168.0.0–192.168.255.255 Private network
"198.18.0.0/15", // 198.18.0.0–198.19.255.255 Private network
}
wl := NewWhitelist()
err := wl.Allow(prefixes...)
if err != nil {
panic(err)
}
targetIPs := []string{
"10.255.255.1", // OK
"127.0.0.1", // OK
"192.168.1.2", // OK
"192.88.10.20", // NG
"224.10.20.30", // NG
"255.255.10.20", // NG
}
for _, ip := range targetIPs {
fmt.Printf("%s --> %v\n", ip, wl.Allowed(ip))
}
Output: 10.255.255.1 --> true 127.0.0.1 --> true 192.168.1.2 --> true 192.88.10.20 --> false 224.10.20.30 --> false 255.255.10.20 --> false
Example (Ipv4Only) ¶
wl := NewWhitelist()
err := wl.Allow("0.0.0.0/0")
if err != nil {
panic(err)
}
targetIPs := []string{
"127.0.0.1", "192.168.1.1", "126.0.0.1", "192.169.1.1",
"fd00:0:0::1", "fd00:0:0:1::1", "fd00:0:1::1", "fc00:0:0::1",
}
for _, ip := range targetIPs {
fmt.Printf("%s --> %v\n", ip, wl.Allowed(ip))
}
Output: 127.0.0.1 --> true 192.168.1.1 --> true 126.0.0.1 --> true 192.169.1.1 --> true fd00:0:0::1 --> false fd00:0:0:1::1 --> false fd00:0:1::1 --> false fc00:0:0::1 --> false
Example (Ipv6Only) ¶
wl := NewWhitelist()
err := wl.Allow("::/0")
if err != nil {
panic(err)
}
targetIPs := []string{
"127.0.0.1", "192.168.1.1", "126.0.0.1", "192.169.1.1",
"fd00:0:0::1", "fd00:0:0:1::1", "fd00:0:1::1", "fc00:0:0::1",
}
for _, ip := range targetIPs {
fmt.Printf("%s --> %v\n", ip, wl.Allowed(ip))
}
Output: 127.0.0.1 --> false 192.168.1.1 --> false 126.0.0.1 --> false 192.169.1.1 --> false fd00:0:0::1 --> true fd00:0:0:1::1 --> true fd00:0:1::1 --> true fc00:0:0::1 --> true
func NewWhitelist ¶
func NewWhitelist() *Whitelist
NewWhitelist returns a new instance of Whitelist. Whitelist checks IPv4 and IPv6 addresses with whitelist.
func (*Whitelist) Allow ¶
Allow adds addresses to the whitelist. When an address contains "/" it will be parsed with net/netip.ParsePrefix, others will be parsed with net/netip.ParseAddr. Given addresses must be in valid form for the functions. If parsing an address encounters an error, add immediately returns the error without processing the remaining addresses. When using CIDR, "/0" matches to all IPs and "<IPv4>/32" or "<IPv6>/128" matches to the only specified IP.
func (*Whitelist) AllowAddr ¶
AllowAddr adds ipv4 and ipv6 addresses to the whitelist. Invalid, non-ipv4 nor non-ipv6, addresses are ignored.
func (*Whitelist) AllowPrefix ¶
AllowPrefix adds ipv4 and ipv6 addresses to the whitelist. Invalid, non-ipv4 nor non-ipv6, addresses are ignored.
Directories
¶
| Path | Synopsis |
|---|---|
|
examples
|
|
|
blacklist
command
|
|
|
blacklist-server
command
|
|
|
whitelist
command
|
|
|
whitelist-server
command
|