From 35bf7ea1a6db64ca17b5cb95517faedad808e4ef Mon Sep 17 00:00:00 2001 From: CyberSecurityUP Date: Sun, 4 Oct 2026 00:51:20 -0300 Subject: [PATCH] fix(repl): /show displays the real authorized scope + authz ref + pinned agents + research MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit /show showed only the policy profile ('web') and hid the actual hard-scope allowlist, the authorization reference, the pinned agents (/class, /only) and research mode — so an operator couldn't confirm what was really configured. Now shows: authorized (the enforced hard-scope hosts, flagged when pinned), guardrails (rate/accounts/destructive/excludes), authz ref, pinned agent list, and research in opts. Co-Authored-By: Claude Opus 4.8 --- neurosploit-rs/app/src/repl.rs | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/neurosploit-rs/app/src/repl.rs b/neurosploit-rs/app/src/repl.rs index 08e3971..7f430f6 100644 --- a/neurosploit-rs/app/src/repl.rs +++ b/neurosploit-rs/app/src/repl.rs @@ -2507,9 +2507,22 @@ fn show(s: &Session) { println!(" │ user-agent: {}", s.user_agent.clone().unwrap_or_else(|| "NeuroSploit (default)".into())); println!(" │ focus : {}", s.instructions.clone().unwrap_or_else(|| "(none — tests everything)".into())); println!(" │ objective: {}", s.objective.clone().unwrap_or_else(|| "(none — /objective )".into())); + // The actual authorized hard scope (the allowlist enforced in code), not just + // the policy profile above — this is what /authorize, /scope-file and /inscope set. + let scope_desc = if s.policy.hard.is_empty() { + s.target.clone().map(|t| format!("(derived from target: {})", harness::scope::host_of(&t))) + .unwrap_or_else(|| "(none set — /authorize or /target)".into()) + } else { + let hosts: Vec = s.policy.hard.iter().map(|p| p.as_text()).collect(); + format!("{}{}", hosts.join(", "), if s.scope_pinned { " (pinned)" } else { "" }) + }; + println!(" │ authorized: {}", scope_desc); + println!(" │ guardrails: {}", s.policy.summary()); println!(" │ out-scope: {}", s.out_of_scope.clone().unwrap_or_else(|| "(none — /scope-out )".into())); - println!(" │ opts : mcp={} offline={} votes={} recon={} chain-depth={} max-agents={} idle-stop={} temp-email={}", - onoff(s.mcp), onoff(s.offline), s.vote_n, s.recon_intensity, s.chain_depth, s.max_agents, + if let Some(a) = &s.authorization { println!(" │ authz ref: {a}"); } + if !s.pinned.is_empty() { println!(" │ pinned : {} agent(s) — {} \x1b[2m(/only clear or /class clear to unpin)\x1b[0m", s.pinned.len(), s.pinned.join(", ")); } + println!(" │ opts : mcp={} offline={} votes={} recon={} chain-depth={} max-agents={} research={} idle-stop={} temp-email={}", + onoff(s.mcp), onoff(s.offline), s.vote_n, s.recon_intensity, s.chain_depth, s.max_agents, onoff(s.research), if s.idle_secs == 0 { "off".to_string() } else { format!("{}m", s.idle_secs / 60) }, onoff(s.temp_email)); // Integrations at a glance (see /integrations for detail). {