mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 12:31:43 +02:00
feat: wire capability tokens and the audit trail through CLI, REPL and web
The risk model, grants and hash-chained trail existed as modules nothing called. Now every engagement runs under them. Capability - `neurosploit capability issue|verify` mints and inspects grants. - `--capability-token` (global, so the REPL takes it too), `--in-scope`, `--environment`, `--policy` on `run`; verification happens at the command line, so an invalid grant fails with a readable message instead of halfway through an engagement. - The pipeline verifies before anything else and REFUSES to run on a token that does not verify — proceeding would mean acting on an authorization nobody can prove was issued. `effective_scope` then applies the grant as a ceiling. - Web: an Authorization tab carrying the token, extra hosts, environment and policy profile. The browser decodes the claims for display and says plainly that it is not verifying them — a "valid" badge from a party without the key would be the UI vouching for something it cannot check. A hole the smoke test found: `/inscope evil.test` inside a session under a grant WIDENED the scope past it — the one thing a capability token exists to prevent. The run itself would still have been constrained (the pipeline re-applies the grant), but `/policy` reported a boundary that was not real, and a tool that misreports its own limits is worse than one with none. Scope mutations now re-apply the ceiling and name what it refused. Session authorization also arrives from argv rather than a `/`-command, because a session that can widen its own grant is not constrained by one. Audit - One hash-chained record per action in `<run>/audit.jsonl`, in the specified shape, covering engagement start/end, validator rejections, findings that reach the report (with the hash of the evidence behind them) and findings withheld for being out of scope. - The run verifies its own chain at the end and says loudly if it is broken. - `/audit [n]` tails the trail and verifies it; the web offers it as a download next to the report, so "show me what the tool did" is a link. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
3456c32f4d
commit
481a4eb1b9
@@ -306,6 +306,7 @@
|
||||
<div class="run-actions">
|
||||
<a class="btn" id="detailOpenReport" target="_blank" hidden>Open report</a>
|
||||
<a class="btn" id="detailOpenPdf" target="_blank" hidden>⤓ PDF</a>
|
||||
<a class="btn" id="detailOpenAudit" target="_blank" hidden title="Every action this run took, hash-chained">Audit trail</a>
|
||||
<button class="btn" id="btnDetailBack">← New engagement</button>
|
||||
</div>
|
||||
</header>
|
||||
@@ -372,6 +373,7 @@
|
||||
<button class="modal-tab active" data-mtab="target">Target auth</button>
|
||||
<button class="modal-tab" data-mtab="keys">API keys</button>
|
||||
<button class="modal-tab" data-mtab="creds">Creds file</button>
|
||||
<button class="modal-tab" data-mtab="authz">Authorization</button>
|
||||
</div>
|
||||
<div class="modal-body">
|
||||
<div class="modal-panel" data-mpanel="target">
|
||||
@@ -391,6 +393,45 @@
|
||||
<div class="field-help" style="margin-bottom:12px;">Keys are kept in this server process's memory only — never written to disk. Cleared on restart.</div>
|
||||
<div id="providerKeyList"></div>
|
||||
</div>
|
||||
<div class="modal-panel" data-mpanel="authz" hidden>
|
||||
<div class="field-group">
|
||||
<label class="field-label" for="capToken">Capability token</label>
|
||||
<input id="capToken" type="text" placeholder="ns-cap.v1.…" spellcheck="false" />
|
||||
<div class="field-status" id="capStatus"></div>
|
||||
<div class="field-help">
|
||||
The signed grant for this engagement: who authorized it, which hosts, which environment, until when.
|
||||
It is verified by the harness (<code>NEUROSPLOIT_CAPABILITY_KEY</code>) and acts as a <strong>ceiling</strong> —
|
||||
the settings below can narrow the scope, never widen it. Mint one with
|
||||
<code>neurosploit capability issue</code>.
|
||||
</div>
|
||||
</div>
|
||||
<div class="field-group">
|
||||
<label class="field-label" for="inScope">Additional authorized hosts</label>
|
||||
<input id="inScope" type="text" placeholder="app.example.com, *.api.example.com, 10.0.0.0/24" />
|
||||
<div class="field-help">Without this the engagement is authorized against the target and nothing else — discovering a host is not permission to test it.</div>
|
||||
</div>
|
||||
<div class="field-row">
|
||||
<div class="field-group">
|
||||
<label class="field-label" for="envSelect">Environment</label>
|
||||
<select id="envSelect">
|
||||
<option value="production" selected>production</option>
|
||||
<option value="staging">staging</option>
|
||||
<option value="development">development</option>
|
||||
<option value="lab">lab</option>
|
||||
<option value="ot-production">ot-production (ICS/SCADA)</option>
|
||||
</select>
|
||||
<div class="field-help">Scales every risk score — the same action is a different act on a lab bench and on a live substation.</div>
|
||||
</div>
|
||||
<div class="field-group">
|
||||
<label class="field-label" for="policySelect">Policy profile</label>
|
||||
<select id="policySelect">
|
||||
<option value="web" selected>web — standard</option>
|
||||
<option value="ot">ot — read-only, paced, industrial writes blocked</option>
|
||||
</select>
|
||||
<div class="field-help">OT blocks writes, disruptive actions, fuzzing and exploit payloads over industrial protocols, and caps the rate at ~1 req/s.</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="modal-panel" data-mpanel="creds" hidden>
|
||||
<div class="field-group">
|
||||
<label class="field-label" for="credsPath">creds.yaml path (overrides target auth above)</label>
|
||||
|
||||
Reference in New Issue
Block a user