From 37e9359c9e138a107de2dcd869d2fed2c28fde68 Mon Sep 17 00:00:00 2001 From: Nanne Baars Date: Fri, 23 Oct 2020 09:47:36 +0200 Subject: [PATCH] #841: Clarify the lesson based on the comments - Output messages more clear - Replace success to failure (otherwise lesson is marked complete immediately) - Fix the layout of the lesson (remove whitespace update buttons) --- .../webgoat/xss/CrossSiteScriptingLesson5a.java | 4 ++-- .../main/resources/html/CrossSiteScripting.html | 17 ++++------------- .../resources/i18n/WebGoatLabels.properties | 6 +++--- .../en/CrossSiteScripting_content5a.adoc | 8 ++++---- 4 files changed, 13 insertions(+), 22 deletions(-) diff --git a/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/xss/CrossSiteScriptingLesson5a.java b/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/xss/CrossSiteScriptingLesson5a.java index 5984207fc..33a949f9e 100644 --- a/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/xss/CrossSiteScriptingLesson5a.java +++ b/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/xss/CrossSiteScriptingLesson5a.java @@ -63,7 +63,7 @@ public class CrossSiteScriptingLesson5a extends AssignmentEndpoint { userSessionData.setValue("xss-reflected1-complete", (Object) "false"); } - if (field1.toLowerCase().matches("