Ban & Reputasi
Ban bukan boolean sederhana — tiap IP menyimpan reputasi & histori offense. Tabel security_ip_bans
menyimpan satu record per IP (di-upsert).
| Status | Keterangan |
|---|---|
active |
Ban aktif (sampai expires_at). |
expired |
Telah lewat expires_at. |
released |
Dirilis (manual atau challenge sukses). |
manual_block |
Ban manual, expires_at boleh null. |
Eskalasi offense
Section titled “Eskalasi offense”Durasi ban naik sesuai jumlah offense:
| Offense | Durasi default |
|---|---|
| 1 | 15 menit |
| 2 | 1 jam |
| 3 | 6 jam |
| 4 | 24 jam |
| 5+ | 24 jam + flag manual_review |
Konfigurasi: ban.durations.
Release tidak menghapus histori
Section titled “Release tidak menghapus histori”- Challenge sukses → status
released+challenge_passed_at. Histori offense dipertahankan. - Pelanggaran critical setelah release → di-ban lagi dengan offense_count naik (eskalasi lanjut).
- Manual release mencatat
reasondanactor(audit).
Risk decay
Section titled “Risk decay”RiskDecay menurunkan offense count / skor setelah periode tenang (default 24 jam untuk offense, 1 jam untuk
skor). IP yang lama tidak melanggar tidak dihukum selamanya.
Hot-path cache
Section titled “Hot-path cache”CachedBanRepository meng-cache findActiveByIp per IP dengan TTL performance.ban_cache_ttl_seconds
(default 30s) + null-sentinel. Mutasi apa pun (create/release/extend/challenge-pass/touch) menghapus cache
untuk IP terkait. Cache menyimpan bentuk array polos (BanRecord::toArray()) dan self-healing terhadap
payload korup/__PHP_Incomplete_Class.
Catatan: ban yang kedaluwarsa alami tetap terlihat di cache sampai TTL habis (≤ 30s) — IP sah bisa mendapat challenge singkat setelah masa ban berakhir.
Allowlist
Section titled “Allowlist”allowlist.hosts/paths/ips mengecualikan request dari pengolahan, tetapi tidak pernah mengecualikan rule
critical. Untuk melewati critical dibutuhkan keputusan eksplisit.
Powered by PT Ganadev Multi Solusi