detail.twig 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276
  1. {% extends 'layout.twig' %}
  2. {% block title %}{{ detail.ip }} — IRDB{% endblock %}
  3. {% macro flag(country) %}
  4. {%- set emoji = flag_emoji(country) -%}
  5. {%- if emoji -%}
  6. <span class="text-base leading-none">{{- emoji -}}</span>
  7. {%- else -%}
  8. <span class="rounded bg-slate-100 px-1.5 py-0.5 font-mono text-[0.65rem] text-slate-500 dark:bg-slate-800 dark:text-slate-400">??</span>
  9. {%- endif -%}
  10. {% endmacro %}
  11. {% macro status_pill(status) %}
  12. {%- set classes = {
  13. 'allowlisted': 'bg-emerald-100 text-emerald-900 dark:bg-emerald-900 dark:text-emerald-100',
  14. 'manually_blocked': 'bg-amber-100 text-amber-900 dark:bg-amber-900 dark:text-amber-100',
  15. 'scored': 'bg-red-100 text-red-900 dark:bg-red-900 dark:text-red-100',
  16. 'clean': 'bg-slate-100 text-slate-700 dark:bg-slate-800 dark:text-slate-300',
  17. } -%}
  18. <span class="rounded px-2.5 py-1 font-mono text-xs uppercase {{ classes[status]|default('bg-slate-100 text-slate-700 dark:bg-slate-800 dark:text-slate-300') }}">{{ status }}</span>
  19. {% endmacro %}
  20. {% block content %}
  21. {% import _self as h %}
  22. <div class="mx-auto max-w-5xl">
  23. <a href="/app/ips" class="text-sm text-slate-500 hover:underline dark:text-slate-400">← Back to IPs</a>
  24. <div class="mt-3 flex items-center justify-between">
  25. <h1 class="font-mono text-2xl font-semibold tracking-tight">{{ detail.ip }}</h1>
  26. {{ h.status_pill(detail.status) }}
  27. </div>
  28. <p class="mt-1 text-sm text-slate-500 dark:text-slate-400">{{ detail.isIpv4 ? 'IPv4' : 'IPv6' }}</p>
  29. {% if can_write|default(false) %}
  30. <div class="mt-4 flex flex-wrap items-center gap-2 text-sm">
  31. {% if detail.allowlist %}
  32. <form method="post" action="/app/allowlist/{{ detail.allowlist.id }}/delete" class="inline">
  33. <input type="hidden" name="csrf_token" value="{{ csrf_token }}">
  34. <input type="hidden" name="next" value="/app/ips/{{ detail.ip|url_encode }}">
  35. <button type="submit" class="rounded-md border border-emerald-300 px-3 py-1 text-xs font-medium text-emerald-700 hover:bg-emerald-50 dark:border-emerald-700 dark:text-emerald-300 dark:hover:bg-slate-800">Remove from allowlist</button>
  36. </form>
  37. {% else %}
  38. <div x-data="toggle" class="inline">
  39. <button type="button" x-on:click="show()" class="rounded-md border border-emerald-300 px-3 py-1 text-xs font-medium text-emerald-700 hover:bg-emerald-50 dark:border-emerald-700 dark:text-emerald-300 dark:hover:bg-slate-800">Add to allowlist…</button>
  40. <div x-show="open" x-cloak class="fixed inset-0 z-50 flex items-center justify-center bg-slate-900/60 px-4">
  41. <form method="post" action="/app/allowlist" x-on:click.outside="hide()" class="w-full max-w-sm rounded-2xl border border-slate-200 bg-white p-6 shadow-lg dark:border-slate-800 dark:bg-slate-900">
  42. <h2 class="text-base font-semibold">Add {{ detail.ip }} to allowlist</h2>
  43. <input type="hidden" name="csrf_token" value="{{ csrf_token }}">
  44. <input type="hidden" name="kind" value="ip">
  45. <input type="hidden" name="ip" value="{{ detail.ip }}">
  46. <label class="mt-3 block text-xs font-medium text-slate-600 dark:text-slate-400">Reason (optional)</label>
  47. <input type="text" name="reason" class="mt-1 w-full rounded-md border border-slate-300 bg-white px-2 py-1.5 text-sm dark:border-slate-700 dark:bg-slate-950">
  48. <div class="mt-4 flex justify-end gap-2">
  49. <button type="button" x-on:click="hide()" class="rounded-md border border-slate-300 px-3 py-1.5 text-sm hover:bg-slate-50 dark:border-slate-700 dark:hover:bg-slate-800">Cancel</button>
  50. <button type="submit" class="rounded-md bg-emerald-600 px-3 py-1.5 text-sm font-medium text-white hover:bg-emerald-500">Add</button>
  51. </div>
  52. </form>
  53. </div>
  54. </div>
  55. {% endif %}
  56. {% if detail.manualBlock %}
  57. <form method="post" action="/app/manual-blocks/{{ detail.manualBlock.id }}/delete" class="inline">
  58. <input type="hidden" name="csrf_token" value="{{ csrf_token }}">
  59. <input type="hidden" name="next" value="/app/ips/{{ detail.ip|url_encode }}">
  60. <button type="submit" class="rounded-md border border-amber-300 px-3 py-1 text-xs font-medium text-amber-700 hover:bg-amber-50 dark:border-amber-700 dark:text-amber-300 dark:hover:bg-slate-800">Remove manual block</button>
  61. </form>
  62. {% else %}
  63. <div x-data="toggle" class="inline">
  64. <button type="button" x-on:click="show()" class="rounded-md border border-amber-300 px-3 py-1 text-xs font-medium text-amber-700 hover:bg-amber-50 dark:border-amber-700 dark:text-amber-300 dark:hover:bg-slate-800">Manually block…</button>
  65. <div x-show="open" x-cloak class="fixed inset-0 z-50 flex items-center justify-center bg-slate-900/60 px-4">
  66. <form method="post" action="/app/manual-blocks" x-on:click.outside="hide()" class="w-full max-w-sm rounded-2xl border border-slate-200 bg-white p-6 shadow-lg dark:border-slate-800 dark:bg-slate-900">
  67. <h2 class="text-base font-semibold">Manually block {{ detail.ip }}</h2>
  68. <input type="hidden" name="csrf_token" value="{{ csrf_token }}">
  69. <input type="hidden" name="kind" value="ip">
  70. <input type="hidden" name="ip" value="{{ detail.ip }}">
  71. <label class="mt-3 block text-xs font-medium text-slate-600 dark:text-slate-400">Reason (optional)</label>
  72. <input type="text" name="reason" class="mt-1 w-full rounded-md border border-slate-300 bg-white px-2 py-1.5 text-sm dark:border-slate-700 dark:bg-slate-950">
  73. <label class="mt-3 block text-xs font-medium text-slate-600 dark:text-slate-400">Expires at (optional)</label>
  74. <input type="datetime-local" name="expires_at" class="mt-1 w-full rounded-md border border-slate-300 bg-white px-2 py-1.5 text-sm dark:border-slate-700 dark:bg-slate-950">
  75. <div class="mt-4 flex justify-end gap-2">
  76. <button type="button" x-on:click="hide()" class="rounded-md border border-slate-300 px-3 py-1.5 text-sm hover:bg-slate-50 dark:border-slate-700 dark:hover:bg-slate-800">Cancel</button>
  77. <button type="submit" class="rounded-md bg-amber-600 px-3 py-1.5 text-sm font-medium text-white hover:bg-amber-500">Block</button>
  78. </div>
  79. </form>
  80. </div>
  81. </div>
  82. {% endif %}
  83. </div>
  84. {% endif %}
  85. <section class="mt-6 grid grid-cols-1 gap-4 lg:grid-cols-2">
  86. <div class="rounded-2xl border border-slate-200 bg-white p-5 shadow-sm dark:border-slate-800 dark:bg-slate-900">
  87. <h2 class="text-sm font-semibold uppercase tracking-wider text-slate-500 dark:text-slate-400">Enrichment</h2>
  88. {% if detail.enrichment.country_code or detail.enrichment.asn %}
  89. <dl class="mt-3 grid grid-cols-3 gap-y-2 text-sm">
  90. <dt class="text-slate-500 dark:text-slate-400">Country</dt>
  91. <dd class="col-span-2 font-mono">{{ h.flag(detail.enrichment.country_code) }} <span>{{ detail.enrichment.country_code|default('—') }}</span></dd>
  92. <dt class="text-slate-500 dark:text-slate-400">ASN</dt>
  93. <dd class="col-span-2 font-mono">
  94. {% if detail.enrichment.asn %}
  95. <a href="https://bgp.he.net/AS{{ detail.enrichment.asn }}" target="_blank" rel="noopener" class="text-indigo-600 hover:underline dark:text-indigo-400">AS{{ detail.enrichment.asn }}</a>
  96. {% else %}—{% endif %}
  97. </dd>
  98. <dt class="text-slate-500 dark:text-slate-400">AS org</dt>
  99. <dd class="col-span-2">{{ detail.enrichment.as_org|default('—') }}</dd>
  100. </dl>
  101. {% if detail.enrichment.enriched_at %}
  102. <p class="mt-3 text-xs text-slate-400">Enriched <time class="irdb-dt" datetime="{{ detail.enrichment.enriched_at }}">{{ detail.enrichment.enriched_at }}</time></p>
  103. {% endif %}
  104. {% else %}
  105. <p class="mt-3 text-sm text-slate-400">
  106. <span class="rounded bg-slate-100 px-1.5 py-0.5 text-xs text-slate-500 dark:bg-slate-800">Unknown</span>
  107. not yet enriched.
  108. </p>
  109. {% endif %}
  110. {% if geoip_provider == 'dbip' %}
  111. <p class="mt-4 border-t border-slate-100 pt-3 text-[0.65rem] text-slate-400 dark:border-slate-800">IP Geolocation by <a href="https://db-ip.com" target="_blank" rel="noopener" class="hover:underline">DB-IP</a> (CC BY 4.0)</p>
  112. {% elseif geoip_provider == 'ipinfo' %}
  113. <p class="mt-4 border-t border-slate-100 pt-3 text-[0.65rem] text-slate-400 dark:border-slate-800">IP data powered by <a href="https://ipinfo.io" target="_blank" rel="noopener" class="hover:underline">IPinfo</a></p>
  114. {% endif %}
  115. </div>
  116. <div class="rounded-2xl border border-slate-200 bg-white p-5 shadow-sm dark:border-slate-800 dark:bg-slate-900">
  117. <h2 class="text-sm font-semibold uppercase tracking-wider text-slate-500 dark:text-slate-400">Override status</h2>
  118. {% if detail.allowlist %}
  119. <p class="mt-3 text-sm">Allowlisted since
  120. <time class="irdb-dt font-mono" datetime="{{ detail.allowlist.created_at }}">{{ detail.allowlist.created_at }}</time>.
  121. {% if detail.allowlist.reason %}<br><span class="text-slate-500 dark:text-slate-400">Reason:</span> {{ detail.allowlist.reason }}{% endif %}
  122. </p>
  123. {% elseif detail.manualBlock %}
  124. <p class="mt-3 text-sm">Manually blocked since
  125. <time class="irdb-dt font-mono" datetime="{{ detail.manualBlock.created_at }}">{{ detail.manualBlock.created_at }}</time>.
  126. {% if detail.manualBlock.reason %}<br><span class="text-slate-500 dark:text-slate-400">Reason:</span> {{ detail.manualBlock.reason }}{% endif %}
  127. </p>
  128. {% else %}
  129. <p class="mt-3 text-sm text-slate-400">No manual override on this IP.</p>
  130. {% endif %}
  131. </div>
  132. </section>
  133. <section class="mt-6 rounded-2xl border border-slate-200 bg-white p-5 shadow-sm dark:border-slate-800 dark:bg-slate-900">
  134. <h2 class="text-sm font-semibold uppercase tracking-wider text-slate-500 dark:text-slate-400">Score per category</h2>
  135. {% if detail.scores|length > 0 %}
  136. {% set max_score = detail.maxScore() %}
  137. <ul class="mt-3 space-y-3 text-sm">
  138. {% for s in detail.scores %}
  139. {% set width_pct = max_score > 0 ? (s.score / max_score * 100) : 0 %}
  140. {# SEC_REVIEW F62: bucket the dynamic width into 5%
  141. steps and render as a `data-score-width` attribute.
  142. The bundled stylesheet (`resources/css/app.css`)
  143. ships one rule per bucket, so dropping
  144. `style-src 'unsafe-inline'` from CSP doesn't break
  145. the visual. 5% buckets are visually indistinguishable
  146. from per-pixel widths on this 1.5px-tall bar. #}
  147. {% set width_bucket = (width_pct / 5)|round * 5 %}
  148. <li>
  149. <div class="flex items-baseline justify-between">
  150. <span class="font-mono">{{ s.category|default('?') }}</span>
  151. <span class="font-mono text-slate-600 dark:text-slate-300">{{ s.score|number_format(2) }} <span class="text-xs text-slate-400">({{ s.report_count_30d }} in 30d)</span></span>
  152. </div>
  153. <div class="mt-1 h-1.5 overflow-hidden rounded bg-slate-100 dark:bg-slate-800">
  154. <div class="h-full bg-indigo-500" data-score-width="{{ width_bucket }}"></div>
  155. </div>
  156. </li>
  157. {% endfor %}
  158. </ul>
  159. {% else %}
  160. <p class="mt-3 text-sm text-slate-400">No scored categories.</p>
  161. {% endif %}
  162. </section>
  163. <section class="mt-6 rounded-2xl border border-slate-200 bg-white p-5 shadow-sm dark:border-slate-800 dark:bg-slate-900"
  164. x-data="scoreOverTime"
  165. data-score-chart="{{ {reports: score_chart.reports, categories: score_chart.categories, now: score_chart.now}|json_encode|e('html_attr') }}">
  166. <div class="flex flex-wrap items-center justify-between gap-3">
  167. <h2 class="text-sm font-semibold uppercase tracking-wider text-slate-500 dark:text-slate-400">Score over time</h2>
  168. <div class="inline-flex overflow-hidden rounded-md border border-slate-300 text-xs dark:border-slate-700">
  169. <template x-for="opt in ranges" :key="opt.id">
  170. <button type="button"
  171. x-on:click="setRange(opt.id)"
  172. :class="classForRange(opt.id)"
  173. x-text="opt.label"></button>
  174. </template>
  175. </div>
  176. </div>
  177. <template x-if="hasNoReports">
  178. <p class="mt-3 text-sm text-slate-400">No reports yet — nothing to plot.</p>
  179. </template>
  180. <template x-if="hasReports">
  181. <div>
  182. <svg viewBox="0 0 660 240" class="mt-3 w-full rounded border border-slate-200 bg-slate-50 dark:border-slate-800 dark:bg-slate-950" preserveAspectRatio="none">
  183. <g class="stroke-slate-200 dark:stroke-slate-800" stroke-width="1">
  184. <line x1="50" y1="20" x2="640" y2="20"/>
  185. <line x1="50" y1="65" x2="640" y2="65"/>
  186. <line x1="50" y1="110" x2="640" y2="110"/>
  187. <line x1="50" y1="155" x2="640" y2="155"/>
  188. </g>
  189. <line x1="50" y1="200" x2="640" y2="200" class="stroke-slate-300 dark:stroke-slate-700" stroke-width="1"/>
  190. <line x1="50" y1="20" x2="50" y2="200" class="stroke-slate-300 dark:stroke-slate-700" stroke-width="1"/>
  191. <template x-if="isFuture()">
  192. <rect x="50" y="20" width="590" height="180" class="fill-amber-50 dark:fill-amber-900/20" />
  193. </template>
  194. <g font-size="10" text-anchor="end" class="fill-slate-500 dark:fill-slate-400">
  195. <text x="46" y="23" x-text="yLabel(1.0)"></text>
  196. <text x="46" y="68" x-text="yLabel(0.75)"></text>
  197. <text x="46" y="113" x-text="yLabel(0.5)"></text>
  198. <text x="46" y="158" x-text="yLabel(0.25)"></text>
  199. <text x="46" y="203">0</text>
  200. </g>
  201. <g font-size="10" text-anchor="middle" class="fill-slate-500 dark:fill-slate-400">
  202. <text x="50" y="216" x-text="xLabel(0)"></text>
  203. <text x="197" y="216" x-text="xLabel(0.25)"></text>
  204. <text x="345" y="216" x-text="xLabel(0.5)"></text>
  205. <text x="492" y="216" x-text="xLabel(0.75)"></text>
  206. <text x="640" y="216" x-text="xLabel(1)"></text>
  207. </g>
  208. <text x="345" y="232" font-size="10" text-anchor="middle" class="fill-slate-500 dark:fill-slate-400" x-text="xAxisCaption()"></text>
  209. <path :d="path()" stroke="currentColor" class="text-indigo-500" fill="none" stroke-width="2"/>
  210. </svg>
  211. <p class="mt-2 text-xs text-slate-400">
  212. <span x-text="rangeLabel()"></span> · max: <span x-text="maxScoreLabel"></span>
  213. <template x-if="isFuture()">
  214. <span class="ml-2 text-amber-600 dark:text-amber-400">forecast assumes no new reports</span>
  215. </template>
  216. </p>
  217. </div>
  218. </template>
  219. </section>
  220. <section class="mt-6 rounded-2xl border border-slate-200 bg-white p-5 shadow-sm dark:border-slate-800 dark:bg-slate-900">
  221. <h2 class="text-sm font-semibold uppercase tracking-wider text-slate-500 dark:text-slate-400">History</h2>
  222. {% if detail.history|length > 0 %}
  223. <ol class="mt-3 space-y-3 text-sm">
  224. {% for ev in detail.history %}
  225. <li class="border-l-2 border-slate-200 pl-3 dark:border-slate-800">
  226. <div class="flex items-baseline justify-between">
  227. <span class="font-mono text-xs uppercase tracking-wider text-slate-500 dark:text-slate-400">
  228. {{ ev.type }}
  229. </span>
  230. <time class="irdb-dt font-mono text-xs text-slate-400" datetime="{{ ev.at }}">{{ ev.at }}</time>
  231. </div>
  232. {% if ev.type == 'report' %}
  233. <p class="mt-1">
  234. {% if ev.category %}<span class="font-mono">{{ ev.category }}</span>{% endif %}
  235. {% if ev.reporter %}<span class="text-slate-500 dark:text-slate-400"> via {{ ev.reporter }}</span>{% endif %}
  236. {% if ev.weight %}<span class="text-slate-400"> · w={{ ev.weight }}</span>{% endif %}
  237. </p>
  238. {% if ev.metadata %}
  239. <pre class="mt-1 overflow-x-auto rounded bg-slate-50 p-2 text-xs dark:bg-slate-950">{{ ev.metadata|json_encode(constant('JSON_PRETTY_PRINT')) }}</pre>
  240. {% endif %}
  241. {% elseif ev.type == 'manual_block_added' %}
  242. <p class="mt-1">Manual block added{% if ev.reason %}: <span class="text-slate-600 dark:text-slate-300">{{ ev.reason }}</span>{% endif %}</p>
  243. {% elseif ev.type == 'allowlist_added' %}
  244. <p class="mt-1">Allowlist entry added{% if ev.reason %}: <span class="text-slate-600 dark:text-slate-300">{{ ev.reason }}</span>{% endif %}</p>
  245. {% endif %}
  246. </li>
  247. {% endfor %}
  248. </ol>
  249. {% if detail.hasMore %}
  250. <p class="mt-3 text-xs text-slate-500 dark:text-slate-400">Showing the most recent 200 events. Older events are available via the API directly until the in-app pagination lands in a future milestone.</p>
  251. {% endif %}
  252. {% else %}
  253. <p class="mt-3 text-sm text-slate-400">No history yet.</p>
  254. {% endif %}
  255. </section>
  256. </div>
  257. {% endblock %}