Add authorization gate for scan/capture scripts - #3
Merged
Merged
Conversation
nmap.sh, host.sh, scanPlus.sh, and live_network_monitor.sh could previously run against any target — audit_log() recorded what happened, but nothing stopped an unauthorized run from happening in the first place. CJIS-adjacent environments require scanning/monitoring to be authorized up front, not just logged after the fact. Added lib/authorization.sh: require_authorization() refuses to proceed unless AUTHORIZED_TICKET (a change/work-order reference) is set and the target matches an entry in config/approved_targets.txt (exact match or glob, e.g. 10.0.0.*). Every grant and denial is itself audit-logged via the existing audit_log() helper. Wired into all four scan/capture scripts right after target validation and before any network action. Verified locally: denies with no ticket, denies for a target not on the allowlist, allows an approved target+ticket combination, and each outcome lands in the audit log. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
nmap.sh,host.sh,scanPlus.sh,live_network_monitor.sh) recorded activity viaaudit_log()but nothing stopped an unauthorized run before it happened.lib/authorization.sh:require_authorization()refuses to proceed unlessAUTHORIZED_TICKET(a change/work-order reference) is set and the target matches an entry inconfig/approved_targets.txt(exact match or glob, e.g.10.0.0.*).Test plan
bash -non all modified scriptsshellcheckclean across the repogitleaks detectcleanrequire_authorization: denies with no ticket, denies for a target not on the allowlist, allows an approved target+ticket, and each outcome is recorded in the audit log🤖 Generated with Claude Code