From faad7d12b308a84f0ba54fb3a16b929684df7a9c Mon Sep 17 00:00:00 2001 From: Viet Huynh Date: Sat, 9 Sep 2023 23:17:32 +0700 Subject: [PATCH] refactored rule deletion --- cf_gateway_rule_delete.js | 52 +++------------------------------------ lib/api.js | 19 +++++++++++++- 2 files changed, 21 insertions(+), 50 deletions(-) diff --git a/cf_gateway_rule_delete.js b/cf_gateway_rule_delete.js index 9613d5a..c301611 100644 --- a/cf_gateway_rule_delete.js +++ b/cf_gateway_rule_delete.js @@ -1,58 +1,12 @@ -import 'dotenv/config'; -import fetch from 'node-fetch'; - -const API_TOKEN = process.env.CLOUDFLARE_API_KEY; -const ACCOUNT_ID = process.env.CLOUDFLARE_ACCOUNT_ID; -const ACCOUNT_EMAIL = process.env.CLOUDFLARE_ACCOUNT_EMAIL; - -// Function to read Cloudflare Zero Trust rules -async function getZeroTrustRules() { - const url = `https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/gateway/rules`; - - const response = await fetch(url, { - method: 'GET', - headers: { - 'Authorization': `Bearer ${API_TOKEN}`, - 'Content-Type': 'application/json', - 'X-Auth-Email': ACCOUNT_EMAIL, - 'X-Auth-Key': API_TOKEN, - }, - }); - - if (!response.ok) { - throw new Error(`HTTP error! status: ${response.status}`); - } - - const data = await response.json(); - return data.result; -} +import { deleteZeroTrustRule, getZeroTrustRules } from './lib/api.js'; ;(async() => { - const rules = await getZeroTrustRules(); + const { result: rules } = await getZeroTrustRules(); const [filtered_rule] = rules.filter(rule => rule.name === "CGPS Filter Lists"); if (!filtered_rule) return console.warn("No rule with matching name found - this is not an issue if you haven't run the create script yet. Exiting."); console.log(`Deleting rule`, process.env.CI ? "(redacted, running in CI)" : `${filtered_rule.name} with ID ${filtered_rule.id}`); - const url = `https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/gateway/rules/${filtered_rule.id}`; - - const resp = await fetch(url, { - method: 'DELETE', - headers: { - 'Authorization': `Bearer ${API_TOKEN}`, - 'Content-Type': 'application/json', - 'X-Auth-Email': ACCOUNT_EMAIL, - 'X-Auth-Key': API_TOKEN, - }, - }); - - const data = await resp.json(); - - console.log('Success: ', data.success); - await sleep(350); // Cloudflare API rate limit is 1200 requests per 5 minutes, so we sleep for 350ms to be safe + await deleteZeroTrustRule(filtered_rule.id); })(); - -async function sleep(ms) { - return new Promise(resolve => setTimeout(resolve, ms)); -} \ No newline at end of file diff --git a/lib/api.js b/lib/api.js index 91d30aa..f498e65 100644 --- a/lib/api.js +++ b/lib/api.js @@ -127,10 +127,17 @@ export const deleteZeroTrustListsAtOnce = async (lists) => { } }; +/** + * Gets Zero Trust rules. + * @returns {Promise} + */ +export const getZeroTrustRules = () => + requestGateway("/rules", { method: "GET" }); + /** * Creates a Zero Trust rule. * @param {string} wirefilterExpression The expression to be used for the rule. - * @returns {Promise} + * @returns {Promise} */ export const createZeroTrustRule = (wirefilterExpression) => requestGateway("/rules", { @@ -145,3 +152,13 @@ export const createZeroTrustRule = (wirefilterExpression) => traffic: wirefilterExpression, }), }); + +/** + * Deletes a Zero Trust rule. + * @param {number} id The ID of the rule to be deleted. + * @returns {Promise} + */ +export const deleteZeroTrustRule = (id) => + requestGateway(`/rules/${id}`, { + method: "DELETE", + });