Fix NPE in IDOR lesson
This commit is contained in:
		| @ -56,7 +56,8 @@ public class IDORViewOtherProfile extends AssignmentEndpoint { | |||||||
|   @ResponseBody |   @ResponseBody | ||||||
|   public AttackResult completed(@PathVariable("userId") String userId, HttpServletResponse resp) { |   public AttackResult completed(@PathVariable("userId") String userId, HttpServletResponse resp) { | ||||||
|  |  | ||||||
|     if (userSessionData.getValue("idor-authenticated-as").equals("tom")) { |     Object obj = userSessionData.getValue("idor-authenticated-as"); | ||||||
|  |     if (obj != null && obj.equals("tom")) { | ||||||
|       // going to use session auth to view this one |       // going to use session auth to view this one | ||||||
|       String authUserId = (String) userSessionData.getValue("idor-authenticated-user-id"); |       String authUserId = (String) userSessionData.getValue("idor-authenticated-user-id"); | ||||||
|       if (userId != null && !userId.equals(authUserId)) { |       if (userId != null && !userId.equals(authUserId)) { | ||||||
|  | |||||||
		Reference in New Issue
	
	Block a user