feat: enforce Framed-IP-Address presence in access decisions
Add hard validation to reject requests without assigned IP address, including clear rejection message for audit trail.
This commit is contained in:
@@ -426,13 +426,16 @@ authorize {
|
|||||||
|
|
||||||
# No assignment → reject
|
# No assignment → reject
|
||||||
if (&control:Tmp-String-0 == "") {
|
if (&control:Tmp-String-0 == "") {
|
||||||
|
update reply {
|
||||||
|
Reply-Message := "No node assignment - access denied"
|
||||||
|
}
|
||||||
reject
|
reject
|
||||||
}
|
}
|
||||||
|
|
||||||
# Wrong node → reject (string compare to avoid type mismatch)
|
# Wrong node → reject (string compare to avoid type mismatch)
|
||||||
if ("%{control:Tmp-String-0}" != "%{NAS-IP-Address}") {
|
if ("%{control:Tmp-String-0}" != "%{NAS-IP-Address}") {
|
||||||
update reply {
|
update reply {
|
||||||
Reply-Message := "Wrong node (%{NAS-IP-Address}) expected %{control:Tmp-String-0}"
|
Reply-Message := "Wrong node %{NAS-IP-Address} expected %{control:Tmp-String-0}"
|
||||||
}
|
}
|
||||||
reject
|
reject
|
||||||
}
|
}
|
||||||
@@ -796,7 +799,17 @@ post-auth {
|
|||||||
}
|
}
|
||||||
|
|
||||||
sqlippool
|
sqlippool
|
||||||
}
|
}
|
||||||
|
#
|
||||||
|
# HARD CHECK: must have IP
|
||||||
|
#
|
||||||
|
if (!&reply:Framed-IP-Address) {
|
||||||
|
update reply {
|
||||||
|
Reply-Message := "No IP assigned - access denied"
|
||||||
|
}
|
||||||
|
reject
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
# Create the CUI value and add the attribute to Access-Accept.
|
# Create the CUI value and add the attribute to Access-Accept.
|
||||||
# Uncomment the line below if *returning* the CUI.
|
# Uncomment the line below if *returning* the CUI.
|
||||||
|
|||||||
Reference in New Issue
Block a user