155 Commits

Author SHA1 Message Date
Nanne Baars
e1be080eea Forced browsing lesson does not show success #143 2016-01-06 18:47:59 +02:00
Nanne Baars
23a1f9e38e Removed obsolete classes 2015-12-08 22:58:33 +01:00
Nanne Baars
5dfd1c44e9 Moving lesson utilities to common project instead of AbstractLesson 2015-12-03 22:52:11 +01:00
Jason White
539985c59e #45 finally won't see two 'Stored XSS lessons hightlighted 2015-12-02 15:08:32 -05:00
Jason White
0628a27b34 clean up 2015-12-02 15:06:10 -05:00
Jason White
d4af09c72a #133 hiding hint on change of lesson/loesson load 2015-12-02 14:05:22 -05:00
mayhew64
023966fbb1 changed back to compile phase, package phase breaks the war-exec.jar construction 2015-11-30 08:51:53 -05:00
mayhew64
511ed91130 Merge pull request #147 from ilatypov/master
Tidy up CSRF lessons.
2015-11-24 19:44:24 -05:00
slav pilus
4c538ee398 #66 Fixing jar plugin lifecycle issue 2015-11-12 20:49:51 +00:00
Ilguiz Latypov
ea1d852cda Convert the message number parameter into the MVC route part. Correct the result of the restart lesson button. 2015-11-07 05:43:40 -05:00
Ilguiz Latypov
de71f2700e Let user-composed (CSRF) attacks send one-request actions, as opposed to the address bar MVC links requesting lessons. The lesson display servlets have javascript that requests data and actions. 2015-11-07 05:43:31 -05:00
Doug Morato
ba20f8d14b Fix javax.mail dependecy and update versions
Signed-off-by: Doug Morato <dm@corp.io>
2015-10-27 22:15:14 -04:00
Doug Morato
4a43a5572e Unregister JDBC drivers, Fixes #134
Upon calling the maven tomcat7:shutdown goal, a severe error message was thrown because of not unloading the JDBC drivers.

Signed-off-by: Doug Morato <dm@corp.io>
2015-10-26 18:23:27 -04:00
Nanne Baars
789a57e792 SEVERE: The web application [/WebGoat] appears to have started a thread named [pool-7-thread-5] but has failed to stop it. This is very likely to create a memory leak #124 2015-10-26 21:38:30 +01:00
Doug Morato
44d944bceb Merge pull request #129 from dougmorato/master
Maven-tomcat plugin fix and correct typo on JS file
2015-10-26 10:09:16 -04:00
Nanne Baars
94ae466dbd Cannot serialize session attribute #123 2015-10-26 07:52:26 +01:00
Doug Morato
345e3cc7cb Fix typo on JS file
Signed-off-by: Doug Morato <dm@corp.io>
2015-10-25 22:53:56 -04:00
Doug Morato
441543100f Revert tomcat7 maven plugin to 2.1
Knonw bug on version 2.2 of the tomcat7-maven-plugin on extracting the temp directories for exec jar

Info: https://issues.apache.org/jira/browse/MTOMCAT-211
https://fisheye6.atlassian.com/changelog/tomcat?cs=1539956
https://fisheye6.atlassian.com/changelog/tomcat?cs=1539209
Signed-off-by: Doug Morato <dm@corp.io>
2015-10-25 22:51:28 -04:00
Doug Morato
8bffb76e5b Merge pull request #127 from misfir3/master
items ommited from menu spinner and some more clean up
2015-10-25 22:28:17 -04:00
Doug Morato
7e2d36ee48 Coveralls should be on Parent Pom
moving the coverall plugin to the parent pom level

Signed-off-by: Doug Morato <dm@corp.io>
2015-10-24 20:26:17 -04:00
Doug Morato
cffb515851 Adding Coveralls support
Coveralls.IO is free service to report on Code Coverage for Open-Source projects. Enabling the reporting using the maven cobertura plugin

Signed-off-by: Doug Morato <dm@corp.io>
2015-10-24 19:40:39 -04:00
Jason White
ab29afec3c code cleanup 2015-10-24 13:15:14 -05:00
Jason White
fc2360b49b #41 ... one more 2015-10-24 13:12:44 -05:00
Jason White
e3df816fb9 #41 omitted on earlier commit 2015-10-24 13:10:43 -05:00
Jason White
45db051f30 removing redundant line, adding hasPlan to special challenge case handling 2015-10-24 11:45:49 -05:00
Jason White
d52dfe87c4 Merge remote-tracking branch 'upstream/master' 2015-10-24 09:12:02 -05:00
Jason White
3c1336a033 #41: spinner implemented for menu loading 2015-10-23 15:15:57 -05:00
Nanne Baars
060b0cd8fa Logging in sometimes goes to report card and misses category-menu #114 2015-10-23 06:54:14 +02:00
Jason White
648bd3bb95 code cleanup 2015-10-22 16:55:18 -05:00
Daniel Kvist
c1e836360f Fix #81 to activate close button in the modal footer 2015-10-22 22:14:09 +02:00
Daniel Kvist
325b964559 Fix #112 deployment descriptor elements in wrong order and off white spacing 2015-10-21 21:57:35 +02:00
Jason White
28ea340307 #103: removing ace directory, not in use 2015-10-21 11:11:43 -04:00
Nanne Baars
f6c2c4bacb The jar snapshot doesn't run #108 (2) 2015-10-07 22:47:39 +02:00
Nanne Baars
e1829e209c Implemented lesson information which gives a mapping between the menu and the actual WebGoat-Lessons project. 2015-10-04 11:56:12 +02:00
Nanne Baars
a6a1b32939 Removed credits from lessons 2015-10-03 18:21:54 +02:00
Nanne Baars
487bc71df1 Moved the logic to the plugin loader which makes the context listener obsolete 2015-09-30 23:08:10 +02:00
Nanne Baars
219b38315b Make sure WEB-INF/lib dir is available 2015-09-30 19:10:33 +02:00
Nanne Baars
2ca5dda37b Reloading finished 2015-09-30 19:03:49 +02:00
Nanne Baars
6a00d66f8b Plugins are now reloaded 2015-09-29 21:41:36 +02:00
Nanne Baars
33d251a147 Fixed goathills lesson with JSP now load correctly again(2) 2015-09-29 20:39:09 +02:00
Nanne Baars
d4450da5d7 Fixed goathills lesson with JSP now load correctly again 2015-09-28 23:27:58 +02:00
Nanne Baars
c0d727d1f2 Merge remote-tracking branch 'upstream/master' 2015-09-24 10:09:38 +02:00
Nanne Baars
86e4fd1c85 i8n highlighting #96 2015-09-24 10:09:07 +02:00
mayhew64
77f3c5135f Merge pull request #101 from misfir3/master
#97, updating controls for hints, source, solution and plans on lessons
2015-09-23 10:00:12 -04:00
Jason White
1bd6a9e0e7 #97, updating controls for hints, source, solution and plans on lessons in challenge roles 2015-09-23 09:01:45 -04:00
Nanne Baars
87d196c427 Return indication that plugins have been reloaded 2015-09-22 21:13:41 +02:00
Nanne Baars
6f8befd9a4 Merge remote-tracking branch 'upstream/master' 2015-09-22 20:40:02 +02:00
Nanne Baars
8d2771c108 Adding the ability to reload plugins directly from the interface instead of restarting Tomcat 2015-09-22 20:38:19 +02:00
Jason White
dc57827cfc #97, Hint controls for CHALLENGE Category lessons 2015-09-21 21:24:10 -04:00
Jason White
6e670c4ac5 #23, #24 - LessonInfo Service now used for TitleView and HelpControlsView 2015-09-20 00:09:38 -04:00