# recon-triage — Docker-only workflow. No host-side tool installs required.
#
# AUTHORIZED USE ONLY. Recon & triage scope: this tool enumerates and references
# findings; it never runs or generates exploits.

IMAGE       ?= recon-triage:latest
TEST_IMAGE  ?= recon-triage:test
SCOPE       ?= scope.yaml
TARGET      ?= example.com
OUT         ?= $(CURDIR)/out
FIXTURES    ?= tests/fixtures

DOCKER ?= docker

.PHONY: help build test replay scan lint schema clean

help:
	@echo "recon-triage — Docker-only targets:"
	@echo "  make build              Build the runtime image"
	@echo "  make test               Build the test stage and run pytest (fully offline)"
	@echo "  make replay             Run the fixture demo -> ./out (no network)"
	@echo "  make scan TARGET=t SCOPE=s   Live recon (requires ./\$$SCOPE)"
	@echo "  make lint               Run ruff inside the test image"
	@echo "  make schema             Export JSON Schema to ./schemas"
	@echo "  make clean              Remove ./out"

# Build the final runtime image from a clean checkout (no host tool installs).
build:
	$(DOCKER) build --target runtime -t $(IMAGE) .

# Build ONLY the test stage and run the suite. The pytest run happens during the
# image build (RUN pytest) and is fully offline — fixtures + injected stubs.
test:
	$(DOCKER) build --target test -t $(TEST_IMAGE) .

# Offline demo: full normalize -> ground -> report on committed fixtures.
replay: build
	@mkdir -p $(OUT)
	$(DOCKER) run --rm \
		-v $(CURDIR)/$(FIXTURES):/app/tests/fixtures:ro \
		-v $(OUT):/data/out \
		$(IMAGE) replay --fixtures /app/tests/fixtures --out /data/out --scope /app/tests/fixtures/scope.yaml

# Live scan. Connect scans run unprivileged — no --cap-add needed.
# For faster SYN scans you MAY add: --cap-add=NET_RAW --cap-add=NET_ADMIN (optional).
scan: build
	@mkdir -p $(OUT)
	$(DOCKER) run --rm \
		-v $(CURDIR)/$(SCOPE):/data/scope.yaml:ro \
		-v $(OUT):/data/out \
		$(IMAGE) scan --scope /data/scope.yaml --target $(TARGET) --out /data/out

lint:
	$(DOCKER) build --target test -t $(TEST_IMAGE) .
	$(DOCKER) run --rm $(TEST_IMAGE) ruff check src tests

schema:
	$(DOCKER) run --rm -v $(CURDIR)/schemas:/out $(IMAGE) schema --out /out

clean:
	rm -rf $(OUT)
