【问题标题】:OpenResty: Anonymise query parameterOpenResty:匿名查询参数
【发布时间】:2020-01-24 16:45:43
【问题描述】:

我正在尝试匿名化电子邮件地址(将其替换为 UUID)以避免在我的 nginx 访问日志中将它们保留为纯文本。目前,我只能通过覆盖 OpenResty's nginx.conf 将其替换为 *****

http {
    include       mime.types;
    default_type  application/octet-stream;


    log_format  main  '$remote_addr - $remote_user [$time_local] "$anonymized_request" '
                '$status $body_bytes_sent "$http_referer" '
                '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  logs/access.log  main;

     ....

    map $request $anonymized_request {
        default $request;
        ~([^\?]*)\?(.*)emailAddress=(?<email_address>[^&]*)(&?)(.*)(\s.*) "$1?$2emailAddress=*****$4$5$6"; # $email_address;
    }

    include /etc/nginx/conf.d/*.conf;
}

当前结果:

# curl http://localhost:8080/?emailAddress=dat@mail.de&attr=hello

127.0. 0.1 - - [24/Jan/2020:11:38:06 +0000] "GET /?emailAddress=*****&attr=hello HTTP/1.1" 200 649 "-" "curl/7.64.1" "-"

预期:

127.0. 0.1 - - [24/Jan/2020:11:38:06 +0000] "GET /?emailAddress=a556c480-3188-5181-8e9c-7ce4e391c1de&attr=hello HTTP/1.1" 200 649 "-" "curl/7.64.1" "-"

请问,是否可以将 email_address 变量传递给将其转换为 UUID 的脚本?或者,我们如何使用log_by_lua_block 获得相同的日志格式?

【问题讨论】:

  • 您以后需要从这个 UUID 中恢复原始电子邮件地址,还是只需要用一些随机 UUID 替换它们?
  • 是的,我想使用任何确定性的 UUID 生成方法。我的主要问题是“如何将电子邮件传递给脚本以应用任何方法”,或者如果不可能,我们如何用log_by_lua 替换 nginx 日志记录,我可以在其中应用我的哈希/UUID 生成

标签: nginx nginx-config openresty nginx-log sidecar


【解决方案1】:

可能这不是一个完全确定的方法,但this 是我通过 google 找到的第一个 Lua UUID 生成函数(所有学分都归于Jacob Rus)。我稍微修改了这个函数,使它使用随机种子,所以它总是会为同一个电子邮件地址生成相同的 UUID。您可以将其重写为更适合您需要的任何内容,这只是想法:

http {
    include       mime.types;
    default_type  application/octet-stream;

    log_format    main  '$remote_addr - $remote_user [$time_local] "$anonymized_request" '
                        '$status $body_bytes_sent "$http_referer" '
                        '"$http_user_agent" "$http_x_forwarded_for"';

    access_log    logs/access.log  main;

    ...

    map $request $anonymized_request {
        default $request;
        ~([^\?]*)\?(.*)emailAddress=(?<email_address>[^&]*)(&?)(.*)(\s.*) "$1?$2emailAddress=$uuid$4$5$6"; # $email_address;
    }

    ...

    server {

        ...

        set $uuid '';
        log_by_lua_block {
            local function uuid(seed)
                math.randomseed(seed)
                local template ='xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx'
                return string.gsub(template, '[xy]', function (c)
                    local v = (c == 'x') and math.random(0, 0xf) or math.random(8, 0xb)
                    return string.format('%x', v)
                end)
            end
            local email = ngx.var.arg_emailAddress
            if email == nil then email = '' end
            -- get CRC32 of 'email' query parameter for using it as a seed for lua randomizer
            -- using https://github.com/openresty/lua-nginx-module#ngxcrc32_short
            -- this will allow to always generate the same UUID for each unique email address
            local seed = ngx.crc32_short(email)
            ngx.var.uuid = uuid(seed)
        }
    }

}

【讨论】:

  • @Fcmam5 又看了一遍这段代码。当我写这段代码时是一个深夜:) 现在我认为出于性能原因,最好仅在指定 emailAddress 查询参数时计算 UUID,否则让它保持为空字符串(大多数请求不会包含这个参数),所以使用类似if email ~= nil then local seed = ngx.crc32_short(email) ngx.var.uuid = uuid(seed) end
猜你喜欢
  • 2013-02-07
  • 2019-09-20
  • 1970-01-01
  • 1970-01-01
  • 2021-04-17
  • 1970-01-01
  • 2016-08-23
  • 2021-02-19
相关资源
最近更新 更多