X-Git-Url: https://git.openstreetmap.org/chef.git/blobdiff_plain/caf459ca2a01126a9d78a5672716d846eb7a9700..02527c7a8ad98c62ea8b6ec2d7b0680bfc57d626:/cookbooks/tilecache/templates/default/squid.conf.erb diff --git a/cookbooks/tilecache/templates/default/squid.conf.erb b/cookbooks/tilecache/templates/default/squid.conf.erb index 2680bcfbb..8fe6cc432 100644 --- a/cookbooks/tilecache/templates/default/squid.conf.erb +++ b/cookbooks/tilecache/templates/default/squid.conf.erb @@ -27,6 +27,17 @@ acl osmtileScrapers browser ^app_name$ # User-Agent, but aren't. Re-block on/near 2016-08-29. #acl osmtileScrapers browser ^osmdroid$ # app using osmdroid library not setting app-specific User-Agent #acl osmtileScrapers browser ^Mozilla/5\.0 \(Windows NT 5\.1\)$ # Faked User-Agent +acl osmtileScrapers browser Firefox\/3\.0 +acl osmtileScrapers browser Firefox\/4\.0 +acl osmtileScrapers browser Firefox\/5\.0 +acl osmtileScrapers browser Firefox\/6\.0 +acl osmtileScrapers browser Firefox\/7\.0 +acl osmtileScrapers browser Firefox\/8\.0 +acl osmtileScrapers browser Firefox\/9\.0 +acl osmtileScrapers browser Firefox\/10\.0 +acl osmtileScrapers browser Firefox\/11\.0 +acl osmtileScrapers browser Firefox\/12\.0 +acl osmtileScrapers browser Firefox\/13\.0 acl is_fake_browser browser Firefox\/3\.0 acl is_fake_browser browser Firefox\/4\.0 @@ -51,7 +62,11 @@ http_access deny osmtile_sites osmtileOverusers # Delay pool when !has_referer and is_browser acl has_referer referer_regex . -acl is_browser browser Mozilla +acl is_browser browser Chrome\/ +acl is_browser browser Firefox\/ +acl is_browser browser Trident\/ +acl is_browser browser Safari\/ +acl is_browser browser AppleWebKit\/ acl whitelist_path urlpath_regex ^/cgi-bin/(export|debug) acl blacklist_path urlpath_regex ^/cgi-bin/ @@ -102,18 +117,18 @@ acl pool_unlimited src <%= address %> acl tile_caches src <%= address %> <% end -%> <% end -%> -#AOL External (London Hack Weekend) -acl pool_unlimited src 64.236.163.23 -#SoTM-US 2014 +# SoTM-US 2014 acl pool_unlimited src 66.78.217.141 -#SoTM-US 2014 Hack Day Red Cross +# SoTM-US 2014 Hack Day Red Cross acl pool_unlimited src 162.6.86.34 acl pool_unlimited src 162.6.86.35 acl pool_unlimited src 162.6.86.36 -#Telenav Whitelist - mvexel +# Telenav Whitelist - mvexel acl pool_unlimited src 108.60.98.6 -#SoTM-EU 2014 +# SoTM-EU 2014 acl pool_unlimited src 185.52.244.32/29 +# Juno Minsk office - me@komzpa.net +acl pool_unlimited src 212.98.173.54 #Allow tile_caches ICP access icp_access allow tile_caches @@ -131,16 +146,10 @@ delay_class <%= i %> 3 #bit mask # xxxxxxx- -------- xxxxxxxx xxxxxxxx -# small pools for faked browsers -<% (0..127).each do |i| -%> -delay_access <%= i+1 %> allow pool_<%= sprintf("%03d", 2*i) %> !pool_unlimited is_fake_browser osmtile_sites -delay_access <%= i+1 %> deny all -delay_parameters <%= i+1 %> -1/-1 <%= node[:tilecache][:net_bucket_refill] / 30 %>/<%= node[:tilecache][:net_bucket_size] / 30 %> <%= node[:tilecache][:ip_bucket_refill] / 30 %>/<%= node[:tilecache][:ip_bucket_size] / 30 %> -<% end %> - # small pools for !has_referer && is_browser - designed to slow down anyone # using no-referer to bypass blocks due to abusive levels of use. <% (0..127).each do |i| -%> +delay_access <%= i+1 %> allow pool_<%= sprintf("%03d", 2*i) %> !pool_unlimited is_fake_browser osmtile_sites delay_access <%= i+1 %> allow pool_<%= sprintf("%03d", 2*i) %> !pool_unlimited !has_referer is_browser osmtile_sites delay_access <%= i+1 %> deny all delay_parameters <%= i+1 %> -1/-1 <%= node[:tilecache][:net_bucket_refill] / 10 %>/<%= node[:tilecache][:net_bucket_size] / 10 %> <%= node[:tilecache][:ip_bucket_refill] / 10 %>/<%= node[:tilecache][:ip_bucket_size] / 10 %>