Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 98 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
name: CI

on:
push:
branches: [main]
pull_request:
workflow_dispatch:

permissions:
contents: read

jobs:
unit:
name: Syntax check and unit tests (PHP ${{ matrix.php }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
php: ['8.1', '8.4']
steps:
- uses: actions/checkout@v7
- uses: shivammathur/setup-php@v2
with:
php-version: ${{ matrix.php }}
tools: phpunit:11
coverage: none
- name: Check PHP syntax
run: find . -name '*.php' -not -path './.git/*' -print0 | xargs -0 -n1 php -l
- name: Unit tests
# PHPUnit 11 needs PHP >= 8.2
if: matrix.php != '8.1'
run: phpunit -c tests/phpunit.xml.dist --testsuite unit

integration:
name: Joomla ${{ matrix.joomla }}, ${{ matrix.db }}, PHP ${{ matrix.php }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- { joomla: 5.4.8, php: '8.2', db: 'mysql:8.0' }
- { joomla: 5.4.8, php: '8.2', db: 'mariadb:10.11' }
- { joomla: 5.4.8, php: '8.2', db: 'postgres:12' }
- { joomla: 6.1.3, php: '8.4', db: 'mysql:8.4' }
- { joomla: 6.1.3, php: '8.4', db: 'mariadb:11.4' }
- { joomla: 6.1.3, php: '8.4', db: 'postgres:17' }
env:
JOOMLA_VERSION: ${{ matrix.joomla }}
DB_HOST: 127.0.0.1
DB_NAME: joomla
DB_PASS: bfstop-test
steps:
- name: Set paths
run: |
echo "JOOMLA_ROOT=$RUNNER_TEMP/joomla" >> "$GITHUB_ENV"
echo "COM_BFSTOP_ROOT=$RUNNER_TEMP/com_bfstop" >> "$GITHUB_ENV"
- uses: actions/checkout@v7

# the component is tested together with the plugin: use its branch of
# the same name if there is one (for changes spanning both), else main
- name: Determine com_bfstop branch
id: com
run: |
branch="${GITHUB_HEAD_REF:-$GITHUB_REF_NAME}"
if git ls-remote --exit-code --heads https://github.com/codeling/com_bfstop.git "$branch" > /dev/null; then
echo "ref=$branch" >> "$GITHUB_OUTPUT"
else
echo "ref=main" >> "$GITHUB_OUTPUT"
fi
- uses: actions/checkout@v7
with:
repository: codeling/com_bfstop
ref: ${{ steps.com.outputs.ref }}
path: com_bfstop
- name: Move com_bfstop checkout out of the plugin's
run: mv com_bfstop "$COM_BFSTOP_ROOT"

- uses: shivammathur/setup-php@v2
with:
php-version: ${{ matrix.php }}
extensions: mysqli, pdo_mysql, pgsql, pdo_pgsql, zip, mbstring, intl, gd
tools: phpunit:11
coverage: none

- name: Start database (${{ matrix.db }})
env:
DB_IMAGE: ${{ matrix.db }}
run: tests/ci/start-database.sh

- name: Install Joomla and bfstop
run: tests/ci/install-joomla.sh

- name: Tests
run: phpunit -c tests/phpunit.xml.dist

- name: Plugin log
if: failure()
run: cat "$JOOMLA_ROOT"/administrator/logs/*.php || true
5 changes: 5 additions & 0 deletions CHANGELOG
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,11 @@
two-factor auth when risk is high) would need to hook earlier in the
login pipeline than this plugin currently does and is left for a
separate, larger initiative
- PostgreSQL support (#206): install/uninstall scripts for PostgreSQL;
the plugin previously installed without creating its tables there and
then silently never blocked anything. IP subnet matching for block and
allow list entries is now done in PHP instead of with MySQL-only SQL
functions, and fixed-length time windows are computed in PHP

1.5.2 (2024-02-18)
- Note: Only component changes, no plugin changes
Expand Down
3 changes: 3 additions & 0 deletions bfstop.xml
Original file line number Diff line number Diff line change
Expand Up @@ -38,16 +38,19 @@
<install>
<sql>
<file driver="mysql" charset="utf8">sql/install.mysql.utf8.sql</file>
<file driver="postgresql" charset="utf8">sql/install.postgresql.utf8.sql</file>
</sql>
</install>
<uninstall>
<sql>
<file driver="mysql" charset="utf8">sql/uninstall.mysql.utf8.sql</file>
<file driver="postgresql" charset="utf8">sql/uninstall.postgresql.utf8.sql</file>
</sql>
</uninstall>
<update>
<schemas>
<schemapath type="mysql">sql/updates</schemapath>
<schemapath type="postgresql">sql/updates/postgresql</schemapath>
</schemas>
</update>
<config>
Expand Down
86 changes: 86 additions & 0 deletions sql/install.postgresql.utf8.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
-- install script for bfstop plugin, PostgreSQL version (issue #206);
-- see install.mysql.utf8.sql for a description of the tables. Keep both in sync!
--
-- differences to the MySQL schema:
-- - handled is a smallint, not a BOOLEAN: the code compares it with 0/1,
-- which PostgreSQL doesn't allow for boolean columns
-- - no unsigned integer types in PostgreSQL
-- - ipaddress in bannedip and allowlist is varchar(49) (as for MySQL
-- installs updated via 1.2.0.sql), to hold IPv6 subnets like
-- "ffff:ffff:ffff:ffff:ffff:ffff:255.255.255.255/128"

CREATE TABLE IF NOT EXISTS "#__bfstop_failedlogin" (
"id" serial NOT NULL,
"username" varchar(150) NOT NULL,
"ipaddress" varchar(45) NOT NULL,
"logtime" timestamp without time zone NOT NULL,
"origin" integer NOT NULL,
"handled" smallint NOT NULL DEFAULT 0,
PRIMARY KEY ("id")
);
CREATE INDEX IF NOT EXISTS "#__bfstop_failedlogin_username_logtime" ON "#__bfstop_failedlogin" ("username", "logtime");


CREATE TABLE IF NOT EXISTS "#__bfstop_bannedip" (
"id" serial NOT NULL,
"ipaddress" varchar(49) NOT NULL,
"crdate" timestamp without time zone NOT NULL,
"duration" integer NOT NULL,
"attempts" integer NOT NULL DEFAULT 0,
"last_attempt" timestamp without time zone DEFAULT NULL,
PRIMARY KEY ("id")
);


CREATE TABLE IF NOT EXISTS "#__bfstop_unblock" (
"block_id" integer NOT NULL,
"source" integer NOT NULL,
"crdate" timestamp without time zone NOT NULL,
PRIMARY KEY ("block_id")
);


CREATE TABLE IF NOT EXISTS "#__bfstop_unblock_token" (
"token" varchar(40) NOT NULL,
"block_id" integer NOT NULL,
"crdate" timestamp without time zone NOT NULL,
PRIMARY KEY ("token")
);


CREATE TABLE IF NOT EXISTS "#__bfstop_allowlist" (
"id" serial NOT NULL,
"ipaddress" varchar(49) NOT NULL,
"notes" varchar(255) NOT NULL DEFAULT '',
PRIMARY KEY ("id")
);


CREATE TABLE IF NOT EXISTS "#__bfstop_knownip" (
"id" serial NOT NULL,
"ipaddress" varchar(45) NOT NULL,
"username" varchar(150) NOT NULL,
"first_success" timestamp without time zone NOT NULL,
"last_success" timestamp without time zone NOT NULL,
PRIMARY KEY ("id"),
CONSTRAINT "#__bfstop_knownip_ip_username" UNIQUE ("ipaddress", "username")
);


CREATE TABLE IF NOT EXISTS "#__bfstop_dnscache" (
"ipaddress" varchar(45) NOT NULL,
"hostname" varchar(255) DEFAULT NULL,
"checked_at" timestamp without time zone NOT NULL,
PRIMARY KEY ("ipaddress")
);


CREATE TABLE IF NOT EXISTS "#__bfstop_username_stats" (
"username" varchar(150) NOT NULL,
"attempts" integer NOT NULL DEFAULT 0,
"first_attempt" timestamp without time zone NOT NULL,
"last_attempt" timestamp without time zone NOT NULL,
PRIMARY KEY ("username")
);
CREATE INDEX IF NOT EXISTS "#__bfstop_username_stats_attempts" ON "#__bfstop_username_stats" ("attempts");
CREATE INDEX IF NOT EXISTS "#__bfstop_username_stats_last_attempt" ON "#__bfstop_username_stats" ("last_attempt");
17 changes: 17 additions & 0 deletions sql/uninstall.postgresql.utf8.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
-- uninstall script for bfstop plugin, PostgreSQL version

DROP TABLE IF EXISTS "#__bfstop_failedlogin";

DROP TABLE IF EXISTS "#__bfstop_bannedip";

DROP TABLE IF EXISTS "#__bfstop_unblock";

DROP TABLE IF EXISTS "#__bfstop_unblock_token";

DROP TABLE IF EXISTS "#__bfstop_allowlist";

DROP TABLE IF EXISTS "#__bfstop_knownip";

DROP TABLE IF EXISTS "#__bfstop_dnscache";

DROP TABLE IF EXISTS "#__bfstop_username_stats";
1 change: 1 addition & 0 deletions sql/updates/postgresql/2.0.0.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
-- PostgreSQL support starts with version 2.0.0, see install.postgresql.utf8.sql
1 change: 1 addition & 0 deletions sql/updates/postgresql/index.html
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
<html><body></body></html>
Loading
Loading