mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 20:41:51 +02:00
feat(report): rebuild reports on demand, from the CLI and the web
A PDF was only ever produced while a run was finishing. If `typst` was missing at that moment — or the template improved afterwards — the operator had no way to get one without re-running the whole engagement against the target. report::rebuild() regenerates every artifact (md · json · html · pdf) from the findings already on disk, exposed as `neurosploit rebuild <run-id|dir>` and as POST /api/runs/:id/report with a "Generate report" button in the run view. The endpoint shells out to the harness rather than reimplementing report generation in JavaScript, so there is one implementation instead of two that drift, and it says plainly when the PDF was skipped for want of `typst` instead of handing back a link to a file that was never produced. Also fixes write_all() to pass the run's pocs/ listing into the HTML report, so a rebuilt report links the scripts each finding cites — the run-time path already did this and the rebuild path silently did not. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
481a4eb1b9
commit
61ae3bc74d
@@ -784,6 +784,28 @@ function leaveLiveJob() {
|
||||
termSyncTargets();
|
||||
}
|
||||
$('#btnBackToBoard').addEventListener('click', () => { leaveLiveJob(); show($('#liveView'), false); show($('#dashView'), false); show($('#wizardView'), true); });
|
||||
// Regenerating from the evidence already on disk, rather than re-running the
|
||||
// engagement: a run whose PDF was never produced (no `typst` at the time, or a
|
||||
// since-improved template) would otherwise be unreportable.
|
||||
$('#btnBuildReport').addEventListener('click', async () => {
|
||||
const id = state.currentDetailId;
|
||||
if (!id) return;
|
||||
const btn = $('#btnBuildReport');
|
||||
const label = btn.textContent;
|
||||
btn.disabled = true;
|
||||
btn.textContent = 'Generating…';
|
||||
try {
|
||||
const r = await api(`/api/runs/${encodeURIComponent(id)}/report`, { method: 'POST' });
|
||||
toast(r.pdf ? 'Report rebuilt — PDF ready.' : (r.note || 'Report rebuilt.'), r.pdf ? 'ok' : 'warn', 7000);
|
||||
await loadDetail(id);
|
||||
} catch (e) {
|
||||
toast(`Couldn't generate the report: ${e.message}`, 'error', 9000);
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
btn.textContent = label;
|
||||
}
|
||||
});
|
||||
|
||||
$('#btnDetailBack').addEventListener('click', () => { clearInterval(state.detailPoll); show($('#detailView'), false); show($('#dashView'), false); show($('#wizardView'), true); });
|
||||
$('#btnNewEngagement').addEventListener('click', () => { leaveLiveJob(); clearInterval(state.detailPoll); show($('#detailView'), false); show($('#liveView'), false); show($('#dashView'), false); show($('#wizardView'), true); });
|
||||
|
||||
|
||||
@@ -306,6 +306,7 @@
|
||||
<div class="run-actions">
|
||||
<a class="btn" id="detailOpenReport" target="_blank" hidden>Open report</a>
|
||||
<a class="btn" id="detailOpenPdf" target="_blank" hidden>⤓ PDF</a>
|
||||
<button class="btn" id="btnBuildReport" title="Regenerate this run's report from its findings">Generate report</button>
|
||||
<a class="btn" id="detailOpenAudit" target="_blank" hidden title="Every action this run took, hash-chained">Audit trail</a>
|
||||
<button class="btn" id="btnDetailBack">← New engagement</button>
|
||||
</div>
|
||||
|
||||
@@ -1038,6 +1038,38 @@ const server = http.createServer(async (req, res) => {
|
||||
return;
|
||||
}
|
||||
|
||||
// ---- report rebuild (generate/refresh the PDF for a finished run) ----
|
||||
m = p.match(/^\/api\/runs\/([^/]+)\/report$/);
|
||||
if (req.method === 'POST' && m) {
|
||||
const id = decodeURIComponent(m[1]);
|
||||
const dir = safeRunDir(id);
|
||||
if (!dir || !fs.existsSync(dir)) return sendJson(res, 404, { error: 'run not found' });
|
||||
if (!BIN) return sendJson(res, 500, { error: 'neurosploit binary not found — run `cargo build --release` in neurosploit-rs/' });
|
||||
// The harness owns report generation (Typst template, severity ordering,
|
||||
// the evidence sections); shelling out to it keeps one implementation
|
||||
// instead of a second, drifting one in JavaScript.
|
||||
const out = await new Promise((resolve) => {
|
||||
const child = spawn(BIN, ['rebuild', dir], { cwd: ROOT, env: { ...process.env, ...envOverrides() } });
|
||||
let buf = '';
|
||||
child.stdout.on('data', (c) => { buf += c.toString('utf8'); });
|
||||
child.stderr.on('data', (c) => { buf += c.toString('utf8'); });
|
||||
child.on('close', (code) => resolve({ code, buf }));
|
||||
child.on('error', (e) => resolve({ code: -1, buf: e.message }));
|
||||
});
|
||||
const built = ['report.pdf', 'report.html', 'report.md', 'report.json'].filter((f) => fs.existsSync(path.join(dir, f)));
|
||||
if (out.code !== 0 && !built.includes('report.pdf')) {
|
||||
return sendJson(res, 502, { error: stripAnsi(out.buf).trim() || 'rebuild failed', built });
|
||||
}
|
||||
return sendJson(res, 200, {
|
||||
ok: true,
|
||||
built,
|
||||
// Typst is optional; saying so beats handing back a link to a file that
|
||||
// was never produced.
|
||||
pdf: built.includes('report.pdf'),
|
||||
note: built.includes('report.pdf') ? '' : 'PDF needs the `typst` binary on PATH — the HTML and Markdown reports were rebuilt.',
|
||||
});
|
||||
}
|
||||
|
||||
// ---- aggregate stats for the dashboard ----
|
||||
if (req.method === 'GET' && p === '/api/stats') {
|
||||
return sendJson(res, 200, await stats());
|
||||
|
||||
Reference in New Issue
Block a user