secubox-deb/common
CyberMind-FR 27eacbcd24 feat(secubox-core+toolbox): Phase 3 transparency layer (whitelist + analysis-status + quality scoring) (ref #492)
## Goal

Make the cabine HONEST : tell the user not just what we inspected, but what
we deliberately BYPASSED and WHY (cert-pinning vendor, banking policy, E2E
opaque by design). Score each destination on passive observable signals.

This is the foundation for #493 (later) full reverse-WAF enforcement —
architecture intentionally aligned so action='block'/'redirect'/'strip' can
be added without refactoring.

## New shared code (common/secubox_core/)

  - whitelist.py : YAML loader with hot-reload. fnmatch glob patterns.
    Reads /usr/share/secubox/toolbox/whitelist-baseline.yaml +
    /etc/secubox/toolbox/whitelist.yaml (operator override). Returns
    (match dict | None) for any host.

  - classifiers/security_quality.py : grade A+/A/B/C/D/F per destination.
    Two modes :
      passive : TLS version + JA4 + SNI + ALPN + is_e2e_messaging
      active  : adds HSTS + CSP + X-Content-Type-Options + cookies attrs
                + mixed-content detection
    Returns {grade, score, mode, reasons[]} with each reason's weight.

## Curated whitelist baseline (47 patterns)

  - Apple ecosystem (push, iCloud, CDN, mzstatic, cloudkit, smoot)
  - Google/Android (googleapis, gstatic, fcm, android, play)
  - Messaging E2E (Signal, Threema, SimpleX, Matrix.org, Proton, Tutanota)
  - Banking FR (BanquePostale, SocGen, BNP, CA, CM, LCL, Boursorama, Revolut)
  - Government FR (service-public, impots.gouv, ameli, france-identite, francetravail, caf)
  - Health (Doctolib, Qare, MonEspaceSante)
  - Privacy tools (DDG, Qwant, Startpage, Proton, Tutanota, Mullvad, Tailscale)
  - Tor Project
  - OS updates (Windows Update, Microsoft, Debian, Ubuntu)

## local_store.py wiring

  - New _analysis_status(host, sni, decrypted) returns (status, reason).
    Order : decrypted > whitelist > E2E regex > pinned-failed fallback.
  - DPI events now carry analysis_status + analysis_reason fields.
  - New tls_failed_clienthello hook captures the SNI of bypassed/pinned
    flows so the report can be honest about them.

## Aggregator (secubox_toolbox/api.py)

  - New _build_transparency() builds the dict :
      breakdown        : raw counts {inspected: N, bypassed-whitelist: N, ...}
      breakdown_pct    : same as percentages
      total_events     : sum
      per_host[]       : worst-first grade table for the report UI
      whitelist_stats  : how many patterns are loaded

  - Exposed under 'transparency' key in /report and /report/me/html.
  - Backfill : legacy events (no analysis_status) get post-hoc tagged via
    whitelist match check so older sessions also show meaningful breakdowns.

## Reports

  - HTML live (report-live.html.j2) : new card 'INSPECTION : CE QUI A ETE
    REGARDE' with breakdown bar + 'QUALITE SECURITE PAR DESTINATION'
    sortable table. Inserts before the Support card.
  - PDF (reports.py) : matching sections rendered ASCII-safe via _ascii_safe.
    Top 10 worst-quality hosts.

## Verified on gk2 (2026-06-05)

  - whitelist loaded : 47 patterns, baseline OK
  - aggregator returns transparency.has_transparency=True
  - per_host populated with quality grades
  - PDF still generates clean

## Out of scope (deferred to #493 enforcement phase)

  - Action types : block/redirect/strip-cookies/downgrade
  - nftables sinkhole for known-bad destinations
  - dnsmasq hijack for whitelisted FQDN auto-direction
  - PhishTank + threat-intel feeds active blocking
  - Per-flow TLS version + headers capture (currently we only grade default
    'inspected' as C because no TLS metadata in the event yet — Phase 4 will
    extend local_store.response() to capture response headers + TLS info).

## Closes #492 (Phase 3 transparency foundation)
2026-06-05 08:13:45 +02:00
..
apparmor Add secubox-repo and secubox-hardening modules, CI/CD workflows 2026-03-22 22:15:01 +01:00
audit Add secubox-repo and secubox-hardening modules, CI/CD workflows 2026-03-22 22:15:01 +01:00
nginx fix(metrics): Make sibling imports work under uvicorn (post-#98 hotfix) (#100) 2026-05-12 16:50:43 +02:00
secubox_core feat(secubox-core+toolbox): Phase 3 transparency layer (whitelist + analysis-status + quality scoring) (ref #492) 2026-06-05 08:13:45 +02:00