core: block CH queries earlier (#973)

block chaos queries, unless the chaos or proxy middleware is loaded. We
respond with REFUSED.

This removes the need for each middleware to do this class != ClassINET
if-then.

Also make config.Registry non-public.
This commit is contained in:
Miek Gieben
2017-08-25 08:55:53 +01:00
committed by GitHub
parent 932639ac99
commit 55dafe6f59
8 changed files with 18 additions and 29 deletions

View File

@@ -2,7 +2,6 @@
package file
import (
"errors"
"fmt"
"io"
"log"
@@ -32,9 +31,6 @@ type (
func (f File) ServeDNS(ctx context.Context, w dns.ResponseWriter, r *dns.Msg) (int, error) {
state := request.Request{W: w, Req: r}
if state.QClass() != dns.ClassINET {
return dns.RcodeServerFailure, middleware.Error(f.Name(), errors.New("can only deal with ClassINET"))
}
qname := state.Name()
// TODO(miek): match the qname better in the map
zone := middleware.Zones(f.Zones.Names).Matches(qname)