feat: enforce Framed-IP-Address presence in access decisions

Add hard validation to reject requests without assigned IP address,
including clear rejection message for audit trail.
This commit is contained in:
2026-04-22 19:15:04 +02:00
parent 064bda9e20
commit 328ff7511c
+20 -7
View File
@@ -426,13 +426,16 @@ authorize {
# No assignment → reject # No assignment → reject
if (&control:Tmp-String-0 == "") { if (&control:Tmp-String-0 == "") {
update reply {
Reply-Message := "No node assignment - access denied"
}
reject reject
} }
# Wrong node → reject (string compare to avoid type mismatch) # Wrong node → reject (string compare to avoid type mismatch)
if ("%{control:Tmp-String-0}" != "%{NAS-IP-Address}") { if ("%{control:Tmp-String-0}" != "%{NAS-IP-Address}") {
update reply { update reply {
Reply-Message := "Wrong node (%{NAS-IP-Address}) expected %{control:Tmp-String-0}" Reply-Message := "Wrong node %{NAS-IP-Address} expected %{control:Tmp-String-0}"
} }
reject reject
} }
@@ -789,14 +792,24 @@ post-auth {
# Engineers → dynamic IP # Engineers → dynamic IP
# #
if (&control:Pool-Name =~ /^engineers-/) { if (&control:Pool-Name =~ /^engineers-/) {
update reply { update reply {
Session-Timeout := 3600 Session-Timeout := 3600
} }
sqlippool
}
#
# HARD CHECK: must have IP
#
if (!&reply:Framed-IP-Address) {
update reply {
Reply-Message := "No IP assigned - access denied"
}
reject
}
sqlippool
}
# Create the CUI value and add the attribute to Access-Accept. # Create the CUI value and add the attribute to Access-Accept.
# Uncomment the line below if *returning* the CUI. # Uncomment the line below if *returning* the CUI.