Skip to content

Add authorization gate for scan/capture scripts - #3

Merged
farazulhoda merged 1 commit into
masterfrom
feature/authorization-gate
Sep 27, 2026
Merged

farazulhoda merged 1 commit into
masterfrom
feature/authorization-gate

Conversation

@farazulhoda

Copy link
Copy Markdown
Owner

Summary

  • Scan/capture scripts (nmap.sh, host.sh, scanPlus.sh, live_network_monitor.sh) recorded activity via audit_log() but nothing stopped an unauthorized run before it happened.
  • Adds lib/authorization.sh: require_authorization() refuses to proceed unless AUTHORIZED_TICKET (a change/work-order reference) is set and the target matches an entry in config/approved_targets.txt (exact match or glob, e.g. 10.0.0.*).
  • Wired into all four scripts right after target validation and before any network action. Every grant and denial is itself audit-logged.

Test plan

  • bash -n on all modified scripts
  • shellcheck clean across the repo
  • gitleaks detect clean
  • Manually verified require_authorization: denies with no ticket, denies for a target not on the allowlist, allows an approved target+ticket, and each outcome is recorded in the audit log
  • Live run of each script against an approved target in a real environment (nmap/tcpdump/vnstat not exercised in this sandbox)

🤖 Generated with Claude Code

nmap.sh, host.sh, scanPlus.sh, and live_network_monitor.sh could
previously run against any target — audit_log() recorded what happened,
but nothing stopped an unauthorized run from happening in the first
place. CJIS-adjacent environments require scanning/monitoring to be
authorized up front, not just logged after the fact.

Added lib/authorization.sh: require_authorization() refuses to proceed
unless AUTHORIZED_TICKET (a change/work-order reference) is set and the
target matches an entry in config/approved_targets.txt (exact match or
glob, e.g. 10.0.0.*). Every grant and denial is itself audit-logged via
the existing audit_log() helper.

Wired into all four scan/capture scripts right after target validation
and before any network action. Verified locally: denies with no
ticket, denies for a target not on the allowlist, allows an approved
target+ticket combination, and each outcome lands in the audit log.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@farazulhoda
farazulhoda merged commit 56a4e75 into master Sep 27, 2026
3 of 4 checks passed
@farazulhoda farazulhoda mentioned this pull request Sep 27, 2026
4 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant