96
}
97
}
98
99
-void web_server_config_options(void) {
100
- web_client_timeout = (int) config_get_number(CONFIG_SECTION_WEB, "disconnect idle clients after seconds", web_client_timeout);
101
- web_client_first_request_timeout = (int) config_get_number(CONFIG_SECTION_WEB, "timeout for first request", web_client_first_request_timeout);
102
- web_client_streaming_rate_t = config_get_number(CONFIG_SECTION_WEB, "accept a streaming request every seconds", web_client_streaming_rate_t);
99
+int make_dns_decision(const char *section_name, const char *config_name, const char *default_value, SIMPLE_PATTERN *p)
100
+{
101
+ char *value = config_get(section_name,config_name,default_value);
102
+ if(!strcmp("yes",value))
103
+ return 1;
104
+ if(!strcmp("no",value))
105
+ return 0;
106
+ if(strcmp("heuristic",value))
107
+ error("Invalid configuration option '%s' for '%s'/'%s'. Valid options are 'yes', 'no' and 'heuristic'. Proceeding with 'heuristic'",
108
+ value, section_name, config_name);
109
+ return simple_pattern_is_potential_name(p);
110
+}
111
104
- respect_web_browser_do_not_track_policy = config_get_boolean(CONFIG_SECTION_WEB, "respect do not track policy", respect_web_browser_do_not_track_policy);
112
+void web_server_config_options(void)
113
+{
114
+ web_client_timeout =
115
+ (int)config_get_number(CONFIG_SECTION_WEB, "disconnect idle clients after seconds", web_client_timeout);
116
+ web_client_first_request_timeout =
117
+ (int)config_get_number(CONFIG_SECTION_WEB, "timeout for first request", web_client_first_request_timeout);
118
+ web_client_streaming_rate_t =
119
+ config_get_number(CONFIG_SECTION_WEB, "accept a streaming request every seconds", web_client_streaming_rate_t);
120
+
121
+ respect_web_browser_do_not_track_policy =
122
+ config_get_boolean(CONFIG_SECTION_WEB, "respect do not track policy", respect_web_browser_do_not_track_policy);
123
web_x_frame_options = config_get(CONFIG_SECTION_WEB, "x-frame-options response header", "");
106
- if(!*web_x_frame_options) web_x_frame_options = NULL;
107
-
108
- web_allow_connections_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow connections from", "localhost *"), NULL, SIMPLE_PATTERN_EXACT);
109
- web_allow_dashboard_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow dashboard from", "localhost *"), NULL, SIMPLE_PATTERN_EXACT);
110
- web_allow_badges_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow badges from", "*"), NULL, SIMPLE_PATTERN_EXACT);
111
- web_allow_registry_from = simple_pattern_create(config_get(CONFIG_SECTION_REGISTRY, "allow from", "*"), NULL, SIMPLE_PATTERN_EXACT);
112
- web_allow_streaming_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow streaming from", "*"), NULL, SIMPLE_PATTERN_EXACT);
113
- web_allow_netdataconf_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow netdata.conf from", "localhost fd* 10.* 192.168.* 172.16.* 172.17.* 172.18.* 172.19.* 172.20.* 172.21.* 172.22.* 172.23.* 172.24.* 172.25.* 172.26.* 172.27.* 172.28.* 172.29.* 172.30.* 172.31.*"), NULL, SIMPLE_PATTERN_EXACT);
114
- web_allow_mgmt_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow management from", "localhost"), NULL, SIMPLE_PATTERN_EXACT);
124
+ if(!*web_x_frame_options)
125
+ web_x_frame_options = NULL;
126
+
127
+ web_allow_connections_from =
128
+ simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow connections from", "localhost *"),
129
+ NULL, SIMPLE_PATTERN_EXACT);
130
+ web_allow_connections_dns =
131
+ make_dns_decision(CONFIG_SECTION_WEB, "allow connections by dns", "heuristic", web_allow_connections_from);
132
+ web_allow_dashboard_from =
133
+ simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow dashboard from", "localhost *"),
134
+ NULL, SIMPLE_PATTERN_EXACT);
135
+ web_allow_dashboard_dns =
136
+ make_dns_decision(CONFIG_SECTION_WEB, "allow dashboard by dns", "heuristic", web_allow_dashboard_from);
137
+ web_allow_badges_from =
138
+ simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow badges from", "*"), NULL, SIMPLE_PATTERN_EXACT);
139
+ web_allow_badges_dns =
140
+ make_dns_decision(CONFIG_SECTION_WEB, "allow badges by dns", "heuristic", web_allow_badges_from);
141
+ web_allow_registry_from =
142
+ simple_pattern_create(config_get(CONFIG_SECTION_REGISTRY, "allow from", "*"), NULL, SIMPLE_PATTERN_EXACT);
143
+ web_allow_registry_dns = make_dns_decision(CONFIG_SECTION_REGISTRY, "allow by dns", "heuristic",
144
+ web_allow_registry_from);
145
+ web_allow_streaming_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow streaming from", "*"),
146
+ NULL, SIMPLE_PATTERN_EXACT);
147
+ web_allow_streaming_dns = make_dns_decision(CONFIG_SECTION_WEB, "allow streaming by dns", "heuristic",
148
+ web_allow_streaming_from);
149
+ // Note the default is not heuristic, the wildcards could match DNS but the intent is ip-addresses.
150
+ web_allow_netdataconf_from = simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow netdata.conf from",
151
+ "localhost fd* 10.* 192.168.* 172.16.* 172.17.* 172.18.*"
152
+ " 172.19.* 172.20.* 172.21.* 172.22.* 172.23.* 172.24.*"
153
+ " 172.25.* 172.26.* 172.27.* 172.28.* 172.29.* 172.30.*"
154
+ " 172.31.*"), NULL, SIMPLE_PATTERN_EXACT);
155
+ web_allow_netdataconf_dns =
156
+ make_dns_decision(CONFIG_SECTION_WEB, "allow netdata.conf by dns", "no", web_allow_mgmt_from);
157
+ web_allow_mgmt_from =
158
+ simple_pattern_create(config_get(CONFIG_SECTION_WEB, "allow management from", "localhost"),
159
+ NULL, SIMPLE_PATTERN_EXACT);
160
+ web_allow_mgmt_dns =
161
+ make_dns_decision(CONFIG_SECTION_WEB, "allow management by dns","heuristic",web_allow_mgmt_from);
162
163
164
#ifdef NETDATA_WITH_ZLIB