Removed errors introduced in previous checkin. String and integer conflicts in JSP

git-svn-id: http://webgoat.googlecode.com/svn/trunk/webgoat@374 4033779f-a91e-0410-96ef-6bf7bf53c507
This commit is contained in:
mayhew64 2009-02-03 17:55:27 +00:00
parent b8c1d13e50
commit 3cf801f58f

View File

@ -2,9 +2,9 @@
import="org.owasp.webgoat.session.*, org.owasp.webgoat.lessons.RoleBasedAccessControl.RoleBasedAccessControl" import="org.owasp.webgoat.session.*, org.owasp.webgoat.lessons.RoleBasedAccessControl.RoleBasedAccessControl"
errorPage="" %> errorPage="" %>
<% <%
WebSession webSession = ((WebSession)session.getAttribute("websession"));
Employee employee = (Employee) session.getAttribute("RoleBasedAccessControl." + RoleBasedAccessControl.EMPLOYEE_ATTRIBUTE_KEY); Employee employee = (Employee) session.getAttribute("RoleBasedAccessControl." + RoleBasedAccessControl.EMPLOYEE_ATTRIBUTE_KEY);
//int myUserId = webSession.getUserIdInLesson(); WebSession webSession = ((WebSession)session.getAttribute("websession"));
// int myUserId = getIntSessionAttribute(webSession, "RoleBasedAccessControl." + RoleBasedAccessControl.USER_ID);
%> %>
<div class="lesson_title_box"><strong>Welcome Back </strong><span class="lesson_text_db"><%=webSession.getUserNameInLesson()%></span> - View Profile Page</div> <div class="lesson_title_box"><strong>Welcome Back </strong><span class="lesson_text_db"><%=webSession.getUserNameInLesson()%></span> - View Profile Page</div>
<div class="lesson_text"> <div class="lesson_text">
@ -13,71 +13,71 @@
First Name: First Name:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getFirstName())%></span> <span class="lesson_text_db"><%=employee.getFirstName()%></span>
</TD> </TD>
<TD> <TD>
Last Name: Last Name:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getLastName())%></span> <span class="lesson_text_db"><%=employee.getLastName()%></span>
</TD> </TD>
</TR> </TR>
<TR><TD> <TR><TD>
Street: Street:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getAddress1())%></span> <span class="lesson_text_db"><%=employee.getAddress1()%></span>
</TD> </TD>
<TD> <TD>
City/State: City/State:
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getAddress2())%></span> <span class="lesson_text_db"><%=employee.getAddress2()%></span>
</TD> </TD>
</TR> </TR>
<TR><TD> <TR><TD>
Phone: Phone:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getPhoneNumber())%></span> <span class="lesson_text_db"><%=employee.getPhoneNumber()%></span>
</TD> </TD>
<TD> <TD>
Start Date: Start Date:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getStartDate())%></span> <span class="lesson_text_db"><%=employee.getStartDate()%></span>
</TD> </TD>
</TR> </TR>
<TR><TD> <TR><TD>
SSN: SSN:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getSsn())%></span> <span class="lesson_text_db"><%=employee.getSsn()%></span>
</TD> </TD>
<TD> <TD>
Salary: Salary:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getSalary())%></span> <span class="lesson_text_db"><%=employee.getSalary()%></span>
</TD> </TD>
</TR> </TR>
<TR><TD> <TR><TD>
Credit Card: Credit Card:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getCcn())%></span> <span class="lesson_text_db"><%=employee.getCcn()%></span>
</TD> </TD>
<TD> <TD>
Credit Card Limit: Credit Card Limit:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getCcnLimit())%></span> <span class="lesson_text_db"><%=employee.getCcnLimit()%></span>
</TD> </TD>
</TR> </TR>
<TR><TD> <TR><TD>
Comments: Comments:
</TD> </TD>
<TD colspan="3"> <TD colspan="3">
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getPersonalDescription())%></span> <span class="lesson_text_db"><%=employee.getPersonalDescription()%></span>
</TD> </TD>
</TR> </TR>
<TR> <TR>
@ -88,11 +88,11 @@
Disc. Dates: Disc. Dates:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getDisciplinaryActionDate())%></span> <span class="lesson_text_db"><%=employee.getDisciplinaryActionDate()%></span>
</TD> </TD>
<TR> <TR>
<TD colspan="4"> <TD colspan="4">
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getDisciplinaryActionNotes())%></span> <span class="lesson_text_db"><%=employee.getDisciplinaryActionNotes()%></span>
</TD> </TD>
</TR> </TR>
<TR> <TR>
@ -100,7 +100,7 @@
Manager: Manager:
</TD> </TD>
<TD> <TD>
<span class="lesson_text_db"><%=(employee == null ? "unknown" : employee.getManager())%></span> <span class="lesson_text_db"><%=employee.getManager()%></span>
</TD> </TD>
</TR> </TR>
</Table> </Table>
@ -114,7 +114,7 @@
{ {
%> %>
<form method="POST" action="<%=webSession.getCurrentLesson().getFormAction()%>"> <form method="POST" action="<%=webSession.getCurrentLesson().getFormAction()%>">
<input type="hidden" name="<%=RoleBasedAccessControl.EMPLOYEE_ID%>" value="<%=(employee == null ? "unknown" : employee.getId())%>"> <input type="hidden" name="<%=RoleBasedAccessControl.EMPLOYEE_ID%>" value="<%=employee.getId()%>">
<input type="submit" name="action" value="<%=RoleBasedAccessControl.LISTSTAFF_ACTION%>"/> <input type="submit" name="action" value="<%=RoleBasedAccessControl.LISTSTAFF_ACTION%>"/>
</form> </form>
<% <%
@ -126,7 +126,7 @@
{ {
%> %>
<form method="POST" action="<%=webSession.getCurrentLesson().getFormAction()%>"> <form method="POST" action="<%=webSession.getCurrentLesson().getFormAction()%>">
<input type="hidden" name="<%=RoleBasedAccessControl.EMPLOYEE_ID%>" value="<%=(employee == null ? "unknown" : employee.getId())%>"> <input type="hidden" name="<%=RoleBasedAccessControl.EMPLOYEE_ID%>" value="<%=employee.getId()%>">
<input type="submit" name="action" value="<%=RoleBasedAccessControl.EDITPROFILE_ACTION%>"/> <input type="submit" name="action" value="<%=RoleBasedAccessControl.EDITPROFILE_ACTION%>"/>
</form> </form>
<% <%
@ -139,7 +139,7 @@
{ {
%> %>
<form method="POST" action="<%=webSession.getCurrentLesson().getFormAction()%>"> <form method="POST" action="<%=webSession.getCurrentLesson().getFormAction()%>">
<input type="hidden" name="<%=RoleBasedAccessControl.EMPLOYEE_ID%>" value="<%=(employee == null ? "unknown" : employee.getId())%>"> <input type="hidden" name="<%=RoleBasedAccessControl.EMPLOYEE_ID%>" value="<%=employee.getId()%>">
<input type="submit" name="action" value="<%=RoleBasedAccessControl.DELETEPROFILE_ACTION%>"/> <input type="submit" name="action" value="<%=RoleBasedAccessControl.DELETEPROFILE_ACTION%>"/>
</form> </form>
<% <%