From 328ff7511cf51c726ab14794db5a28aad8fb4e53 Mon Sep 17 00:00:00 2001 From: "noussair.hamrit" Date: Wed, 22 Apr 2026 14:33:40 +0200 Subject: [PATCH] feat: enforce Framed-IP-Address presence in access decisions Add hard validation to reject requests without assigned IP address, including clear rejection message for audit trail. --- files/sites-available/default | 27 ++++++++++++++++++++------- 1 file changed, 20 insertions(+), 7 deletions(-) diff --git a/files/sites-available/default b/files/sites-available/default index 643fa91..5984673 100644 --- a/files/sites-available/default +++ b/files/sites-available/default @@ -426,13 +426,16 @@ authorize { # No assignment → reject if (&control:Tmp-String-0 == "") { + update reply { + Reply-Message := "No node assignment - access denied" + } reject } # Wrong node → reject (string compare to avoid type mismatch) if ("%{control:Tmp-String-0}" != "%{NAS-IP-Address}") { update reply { - Reply-Message := "Wrong node (%{NAS-IP-Address}) expected %{control:Tmp-String-0}" + Reply-Message := "Wrong node %{NAS-IP-Address} expected %{control:Tmp-String-0}" } reject } @@ -789,14 +792,24 @@ post-auth { # Engineers → dynamic IP # - if (&control:Pool-Name =~ /^engineers-/) { + if (&control:Pool-Name =~ /^engineers-/) { - update reply { - Session-Timeout := 3600 - } + update reply { + Session-Timeout := 3600 + } + + sqlippool + } + # + # HARD CHECK: must have IP + # + if (!&reply:Framed-IP-Address) { + update reply { + Reply-Message := "No IP assigned - access denied" + } + reject + } - sqlippool -} # Create the CUI value and add the attribute to Access-Accept. # Uncomment the line below if *returning* the CUI.