feat: enforce Framed-IP-Address presence in access decisions
Add hard validation to reject requests without assigned IP address, including clear rejection message for audit trail.
This commit is contained in:
@@ -426,13 +426,16 @@ authorize {
|
||||
|
||||
# No assignment → reject
|
||||
if (&control:Tmp-String-0 == "") {
|
||||
update reply {
|
||||
Reply-Message := "No node assignment - access denied"
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
# Wrong node → reject (string compare to avoid type mismatch)
|
||||
if ("%{control:Tmp-String-0}" != "%{NAS-IP-Address}") {
|
||||
update reply {
|
||||
Reply-Message := "Wrong node (%{NAS-IP-Address}) expected %{control:Tmp-String-0}"
|
||||
Reply-Message := "Wrong node %{NAS-IP-Address} expected %{control:Tmp-String-0}"
|
||||
}
|
||||
reject
|
||||
}
|
||||
@@ -797,6 +800,16 @@ post-auth {
|
||||
|
||||
sqlippool
|
||||
}
|
||||
#
|
||||
# HARD CHECK: must have IP
|
||||
#
|
||||
if (!&reply:Framed-IP-Address) {
|
||||
update reply {
|
||||
Reply-Message := "No IP assigned - access denied"
|
||||
}
|
||||
reject
|
||||
}
|
||||
|
||||
|
||||
# Create the CUI value and add the attribute to Access-Accept.
|
||||
# Uncomment the line below if *returning* the CUI.
|
||||
|
||||
Reference in New Issue
Block a user