# Copyright (C) 2025 James Brotosky, Brandon Wickline # # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU Affero General Public License as published # by the Free Software Foundation, either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Affero General Public License for more details. # # You should have received a copy of the GNU Affero General Public License # along with this program. If not, see . #Standard Libary Imports: import os def colorText(text: str, color: str) -> str: colors = { "red": "\033[91m", "green": "\033[92m", "yellow": "\033[93m", "blue": "\033[94m", "magenta": "\033[95m", "cyan": "\033[96m", "white": "\033[97m", "reset": "\033[0m" } return f"{colors.get(color, colors['reset'])}{text}{colors['reset']}" def style_dataframe_dark(df, output_html_path=None, overwrite=True): from datetime import datetime # Get current date and filename for subtitle today = datetime.now().strftime("%d %B %Y") # Changed to "Day Month Year" filename = output_html_path.replace('.html', '') if output_html_path else "Report" dark_css = """ """ header = f"""

Airlock Tools

{filename} - {today}

""" html_table = df.to_html(index=False, escape=False) styled_html = ( f"\n" f"Airlock Tools Report\n" f"\n" f"{dark_css}\n" f"{header}\n" f"
\n" f" {html_table}\n" f"
\n" f"\n" f"" ) if output_html_path: with open(output_html_path, "w", encoding="utf-8") as f: f.write(styled_html) print(f"✅ Styled table saved to '{output_html_path}'") elif overwrite: import tempfile temp_path = tempfile.mktemp(suffix=".html") with open(temp_path, "w", encoding="utf-8") as f: f.write(styled_html) print(f"✅ Styled table saved to temporary file: {temp_path}") else: return styled_html def displayIntro(): print(colorText(r""" ███ ████ ░████████ █████████████ ███████████████ █████████████████████ █████████████████████ ███████████████████ ██████████████████████▓ ███████████████████ ██████████████████████ █████████████████████ ███████████████████████ ████████████████████████████████████████████████████████ █████████ ██ ██ █████████ █████████ ██ ███ █ █████████ █████████ ██ ████ █████ █████████████ █████████ ██ ██████ █████████████ ████████ ██ ███████ ████████████░ ███████ ██ ██▓ ██████ ████████████ ██████ ██ ████ █████ ███████████ █████████████████████████████████████████████████ ▒████████████████████ ██████████████████ ███████████████████ ███████████████▒ ███████████████ █████████████ ██████████ ███████████ ████████ ████ """, "yellow")) print(colorText(r""" _____ .__ .__ __ ___________ .__ / _ \ |__|______| | ____ ____ | | __ \__ ___/___ ____ | | ______ / /_\ \| \_ __ \ | / _ \_/ ___\| |/ / | | / _ \ / _ \| | / ___/ / | \ || | \/ |_( <_> ) \___| < | |( <_> | <_> ) |__\___ \ \____|__ /__||__| |____/\____/ \___ >__|_ \ |____| \____/ \____/|____/____ > \/ \/ \/ \/ """, "cyan")) print(colorText("=================================================================================", "cyan")) print(colorText("======================== Welcome to the Airlock API Tool ========================", "cyan")) print(colorText("=================================================================================", "cyan")) def printEnforceChecklist(first_policy, second_policy, allowlist_child_name, allowlist_parent_name, destination_name): print(colorText("\n --------------------------------------------------------------------", "cyan")) print(colorText(" ------------- 🛠️ 🔒 Prepare to Enforce Policy 🛠️ 🔒 ------------------", "cyan")) print(colorText(" --------------------------------------------------------------------", "cyan")) print(colorText("\nSequentually follow these steps to prepare a policy for enforcement:", "white")) print(colorText("\n1. Choose which originating policy or policies to move to enforcement", "cyan")) if first_policy == " " and second_policy == " ": print(colorText(f" [✗] No policies have been chosen","red")) elif first_policy != " " and second_policy is first_policy: print(colorText(f" [✓] {first_policy} has been selected,", "green")) elif first_policy != " " and second_policy != " ": print(colorText(f" [✓] {first_policy} has been selected as Policy 1","green")) print(colorText(f" [✓] {second_policy} has been selected as Policy 2","green")) print(colorText("2. Pull and stage event history, combine the histories, add hash info, then categorize the hashes", "cyan")) if os.path.exists(f"parquet\\execution_history_{first_policy}.parquet"): print(colorText(f" [✓] Execution history has been compiled for {first_policy}","green")) elif not os.path.exists(f"parquet\\execution_history_{first_policy}.parquet"): print(colorText(f" [✗] Execution history has not been compiled for {first_policy}","red")) elif second_policy is not first_policy and os.path.exists(f"parquet\\execution_history_{second_policy}.parquet"): print(colorText(f" [✓] Execution history has been compiled for {second_policy}","green")) elif second_policy is not first_policy and not os.path.exists(f"parquet\\execution_history_{second_policy}.parquet"): print(colorText(f" [✗] Execution history has not been compiled for {second_policy}","red")) if os.path.exists(f"parquet\\combined_hashlist_{first_policy}_{second_policy}.parquet"): print(colorText(f" [✓] Hash Info has been added to the combined execution history", "green")) else: print(colorText(f" [✗] Hash Info has not been added to the combined execution history", "red")) if os.path.exists(f"parquet\\hashes_rep_unknown_{first_policy}_{second_policy}.parquet") and os.path.exists(f"parquet\\hashes_rep_good_{first_policy}_{second_policy}.parquet") and os.path.exists(f"parquet\\hashes_rep_bad_{first_policy}_{second_policy}.parquet"): print(colorText(f" [✓] Hashes have been cateogrized", "green")) else: print(colorText(f" [✗] Hashes have not been cateogrized", "red")) if os.path.exists(f"parquet\\condensed_executions_{first_policy}_{second_policy}.parquet"): print(colorText(f" [✓] Execution history has been_combined_for {first_policy} and_{second_policy}", "green")) else: print(colorText(f" [✗] Execution history has not been_combined_for {first_policy} and_{second_policy}", "red")) print(colorText(f"3. Manually review the files:","cyan")) print(colorText(" 'needs_approved\\hashes_rep_good_{first_policy}_{second_policy}.csv' and 'needs_approved\\hashes_rep_unknown_{first_policy}_{second_policy}.csv'", "cyan")) print(colorText(" Remove the rows containing hashes you do not approve of, and those you would not approve of without metarules.", "cyan")) print(colorText(" If metarules need to be created, please make note of them, and remove the row from the csv.", "cyan")) print(colorText(" When complete, save both csv files to the directory 'approved' and choose this option.","cyan")) print(colorText(" This will combine these approved hashes with the automatically approved hashes and generate a list of paths to be reviewed", "cyan")) if os.path.exists(f"approved\\hashes_rep_good_{first_policy}_{second_policy}.csv") and os.path.exists(f"approved\\hashes_rep_unknown_{first_policy}_{second_policy}.csv"): print(colorText(" [✓] Reviewed hashes have been loaded","green")) else: print(colorText(" [✗] Reviewed hashes have not been loaded","red")) if os.path.exists(f"parquet\\all_approved_hashes_{first_policy}_{second_policy}.parquet"): print(colorText(" [✓] The combined approved hashes list has been generated","green")) else: print(colorText(" [✗] The combined approved hashes list has not been generated","red")) if os.path.exists(f"needs_approved\\path_needs_approved_{first_policy}_{second_policy}.csv"): print(colorText(" [✓] Path review list created","green")) else: print(colorText(" [✗] Path review list has not been created","red")) print(colorText(f"4. Manually review the file 'needs_approved\\paths_needing_review_{first_policy}_{second_policy}.csv'", "cyan")) print(colorText(" Remove the rows containing path exclusions you do not approve of" , "cyan")) print(colorText(" When complete, save the csv file to the directory 'approved'", "cyan")) print(colorText(" Do the same process with the list of publishers forthe same directories", "cyan")) print(colorText(" Preflight Lists will be generated", "cyan")) if os.path.exists(f"approved\\path_needs_approved_{first_policy}_{second_policy}.csv"): print(colorText(" [✓] Reviewed path list detected","green")) else: print(colorText(" [✗] Path review list has not been detected","red")) if os.path.exists(f"preflight\\final_path_exclusions_{first_policy}_{second_policy}.html"): print(colorText(" [✓] Preflight Path Exclusion List has been generated","green")) else: print(colorText(" [✗] Preflight Path Exclusion List has not been generated","red")) if os.path.exists(f"preflight\\final_hash_approvals_{first_policy}_{second_policy}.html"): print(colorText(" [✓] Preflight hash approval list has been generated","green")) else: print(colorText(" [✗] Preflight hash approval list has not been generated","red")) print(colorText(f"5. Choose the destination policy and parent and child allow list", "cyan")) if allowlist_child_name == " " and allowlist_parent_name== " ": print(colorText(f" [✗] No allowlists have been chosen","red")) elif allowlist_parent_name != " " and allowlist_child_name != " " and allowlist_parent_name is allowlist_child_name: print(colorText(f" [✓] [✗] Only {allowlist_parent_name} has been selected this is unusual, but potentially valid case, double check before proceeding,", "yellow")) elif allowlist_parent_name != " " and allowlist_child_name != " " and allowlist_parent_name is not allowlist_child_name: print(colorText(f" [✓] {allowlist_parent_name} has been selected as Parent Policy","green")) print(colorText(f" [✓] {allowlist_child_name} has been selected as Child Policy","green")) if destination_name == " ": print(colorText(f" [✗] No destination policy has been chosen","red")) else: print(colorText(f" [✓] destination policy is {destination_name}","green")) print(colorText(f"6. Test ------------------------------------------------------", "cyan")) print(colorText(f" Print rather than apply selected data.", "cyan")) print(colorText(f"7. Liftoff ------------------------------------------------------", "cyan")) print(colorText(f" Apply path exclusions according to allowed and approved paths", "cyan")) print(colorText(f" Apply signed or attested hashes to Parent Allow List", "cyan")) print(colorText(f" Apply approved, but unsigned hashes to the Child Allow List", "cyan")) print(colorText("R. Remove/Reset Generated data - will prompt to allow keeping execution history", "cyan")) print(colorText("Q. Quit", "cyan")) def areYouSure(): print(colorText(f"🛑*****************************************************************************************************************************************🛑","red")) print(colorText(f"⚠️=========================================================================================================================================⚠️","yellow")) print(colorText(f"🛑========================================================================================================================================🛑","red")) print(colorText(f"⚠️-------------This program will now begin to make changes to the Airlock Console. Do you understand and agree to proceed? ----------------⚠️", "yellow")) print(colorText(f"🛑=========================================================================================================================================🛑","red")) print(colorText(f"⚠️=========================================================================================================================================⚠️","yellow")) print(colorText(f"🛑******************************************************************************************************************************************🛑","red")) def locked(): print(colorText(r""" ████████████████████████████████████████████████████████████████ ███ ██ ██ ██████ ███ ██ ████████████ ███ ██ ████ ███ ███ ██ ███ ███ ███ ██ ███ ███ ███ ██ ▒████████████████████ ███ ██ ██████████████████████ ███ ██ ██████████████████████ ███ ██ ██████████████████████ ███ ██ ██████████████████████ ███ ██ ██████████████████████ ███ ██ ███ ███ ███ ████████████████████████████████████████████████████████████████████ ▒██████████████████████████████████████████████████████████████████▒ ▒████ ▒████ ▓██████████████████████████████████████████ █████████████████████████████████████████████░ """, "yellow"))