b3541231bc 
					 
					
						
						
							
							#165  provide default and ability to override in lesson  
						
						
						
						
					 
					
						2016-01-14 09:01:47 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						1a7535e3e2 
					 
					
						
						
							
							Merge pull request  #164  from dougmorato/master  
						
						... 
						
						
						
						Remove Coverity Badge from README 
						
						
					 
					
						2016-01-09 09:35:54 +02:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						daed6a648f 
					 
					
						
						
							
							Remove Coverity Badge from README  
						
						... 
						
						
						
						WebGoat does not endorse any specificy Static Code Analysis Vendor, so removing Coverity Badge in order not to send mixed messages
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2016-01-08 12:59:15 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						241ed0f47a 
					 
					
						
						
							
							Merge pull request  #163  from nbaars/master  
						
						... 
						
						
						
						Seems the CI checks are not directly related to the code updates. Review of the code looks OK ... merging. 
						
						
					 
					
						2016-01-08 12:56:50 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						e1be080eea 
					 
					
						
						
							
							Forced browsing lesson does not show success  #143  
						
						
						
						
					 
					
						2016-01-06 18:47:59 +02:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						2be182f603 
					 
					
						
						
							
							Merge pull request  #155  from nbaars/master  
						
						... 
						
						
						
						Moving lesson utilities to common project instead of AbstractLesson 
						
						
					 
					
						2015-12-12 12:26:44 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						23a1f9e38e 
					 
					
						
						
							
							Removed obsolete classes  
						
						
						
						
					 
					
						2015-12-08 22:58:33 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						5dfd1c44e9 
					 
					
						
						
							
							Moving lesson utilities to common project instead of AbstractLesson  
						
						
						
						
					 
					
						2015-12-03 22:52:11 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						5bd348f975 
					 
					
						
						
							
							Merge pull request  #153  from misfir3/master  
						
						... 
						
						
						
						#133  hiding hint on change of lesson/loesson load 
					
						2015-12-02 21:34:32 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						539985c59e 
					 
					
						
						
							
							#45  finally won't see two 'Stored XSS lessons hightlighted  
						
						
						
						
					 
					
						2015-12-02 15:08:32 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						0628a27b34 
					 
					
						
						
							
							clean up  
						
						
						
						
					 
					
						2015-12-02 15:06:10 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						d4af09c72a 
					 
					
						
						
							
							#133  hiding hint on change of lesson/loesson load  
						
						
						
						
					 
					
						2015-12-02 14:05:22 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						e530be6e3e 
					 
					
						
						
							
							Update README.MD  
						
						
						
						
					 
					
						2015-11-30 08:58:23 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						78a19c9e80 
					 
					
						
						
							
							Update README.MD  
						
						
						
						
					 
					
						2015-11-30 08:58:04 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						eb46123cf2 
					 
					
						
						
							
							Merge pull request  #152  from mayhew64/master  
						
						... 
						
						
						
						changed back to compile phase, package phase breaks the war-exec.jar … 
						
						
					 
					
						2015-11-30 08:53:03 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						023966fbb1 
					 
					
						
						
							
							changed back to compile phase, package phase breaks the war-exec.jar construction  
						
						
						
						
					 
					
						2015-11-30 08:51:53 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						511ed91130 
					 
					
						
						
							
							Merge pull request  #147  from ilatypov/master  
						
						... 
						
						
						
						Tidy up CSRF lessons. 
						
						
					 
					
						2015-11-24 19:44:24 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						8284f08413 
					 
					
						
						
							
							Merge pull request  #149  from aravindc26/master  
						
						... 
						
						
						
						Fixes typo in README 
						
						
					 
					
						2015-11-20 12:38:06 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						62a4056d9b 
					 
					
						
						
							
							Fixes typo in README  
						
						
						
						
					 
					
						2015-11-20 00:07:04 +05:30 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						4c4753784d 
					 
					
						
						
							
							Merge pull request  #148  from slavP/eclipseImportFix  
						
						... 
						
						
						
						#66  Fixing jar plugin lifecycle issue 
					
						2015-11-12 16:43:54 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						4c538ee398 
					 
					
						
						
							
							#66  Fixing jar plugin lifecycle issue  
						
						
						
						
					 
					
						2015-11-12 20:49:51 +00:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						ea1d852cda 
					 
					
						
						
							
							Convert the message number parameter into the MVC route part.  Correct the result of the restart lesson button.  
						
						
						
						
					 
					
						2015-11-07 05:43:40 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						de71f2700e 
					 
					
						
						
							
							Let user-composed (CSRF) attacks send one-request actions, as opposed to the address bar MVC links requesting lessons.  The lesson display servlets have javascript that requests data and actions.  
						
						
						
						
					 
					
						2015-11-07 05:43:31 -05:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						05a1f5dd3a 
					 
					
						
						
							
							Merge pull request  #140  from dougmorato/master  
						
						... 
						
						
						
						Updated pom versions and cache .m2 on travis to speed build time 
						
						
					 
					
						2015-10-28 19:11:02 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						ba20f8d14b 
					 
					
						
						
							
							Fix javax.mail dependecy and update versions  
						
						... 
						
						
						
						Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-27 22:15:14 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						44b20bfc89 
					 
					
						
						
							
							Caching .m2 repository to speed the Travis build  
						
						... 
						
						
						
						Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-27 21:19:12 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						0997c860eb 
					 
					
						
						
							
							Merge pull request  #136  from dougmorato/master  
						
						... 
						
						
						
						Update dependency version, build number and unregister DB driver 
						
						
					 
					
						2015-10-27 19:52:32 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						e8e1e904ec 
					 
					
						
						
							
							Updating dependencies and plugin versions  
						
						... 
						
						
						
						Updated all the outdated dependencies and plugin versions not related to Spring and Java EE
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-26 18:47:18 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						4a43a5572e 
					 
					
						
						
							
							Unregister JDBC drivers,  Fixes   #134  
						
						... 
						
						
						
						Upon calling the maven tomcat7:shutdown goal, a severe error message was thrown because of not unloading the JDBC drivers.
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-26 18:23:27 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						cf84e674b7 
					 
					
						
						
							
							Fix typo on pom.xml  
						
						... 
						
						
						
						Bruce's developer id was mistyped.
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-26 18:18:31 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						bdc99f305a 
					 
					
						
						
							
							Travis build number now available from admin page  
						
						... 
						
						
						
						On the About page, the travis build numbers will be reflected on the build: property
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-26 18:18:07 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						10e2b044e9 
					 
					
						
						
							
							Merge pull request  #132  from nbaars/master  
						
						... 
						
						
						
						Shutdown threadPools after plugin loading 
						
						
					 
					
						2015-10-26 16:48:50 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						789a57e792 
					 
					
						
						
							
							SEVERE: The web application [/WebGoat] appears to have started a thread named [pool-7-thread-5] but has failed to stop it. This is very likely to create a memory leak  #124  
						
						
						
						
					 
					
						2015-10-26 21:38:30 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						5c3f77d84b 
					 
					
						
						
							
							Merge pull request  #131  from dougmorato/master  
						
						... 
						
						
						
						Do not clean before mvn cobertura and coveralls 
						
						
					 
					
						2015-10-26 10:48:57 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						ff6a9b0295 
					 
					
						
						
							
							Do not clean before mvn cobertura and coveralls  
						
						... 
						
						
						
						By cleaning before tbe cobertura goal, this was removing the exec.jar and the war file.
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-26 10:48:34 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						44d944bceb 
					 
					
						
						
							
							Merge pull request  #129  from dougmorato/master  
						
						... 
						
						
						
						Maven-tomcat plugin fix and correct typo on JS file 
						
						
					 
					
						2015-10-26 10:09:16 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						91ea844c7f 
					 
					
						
						
							
							Merge pull request  #130  from nbaars/master  
						
						... 
						
						
						
						Cannot serialize session attribute, fix  #123  
						
						
					 
					
						2015-10-26 09:59:20 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						94ae466dbd 
					 
					
						
						
							
							Cannot serialize session attribute  #123  
						
						
						
						
					 
					
						2015-10-26 07:52:26 +01:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						2803b7cd84 
					 
					
						
						
							
							Adding VersionEye  
						
						... 
						
						
						
						VersionEye is a free service for open-source repositories that track and report the versions of all dependencies in a project
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-26 00:33:20 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						398f918376 
					 
					
						
						
							
							Coveralls goal abreviation  
						
						... 
						
						
						
						Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-25 23:21:28 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						f9073e366d 
					 
					
						
						
							
							Tomcat7 maven plugin now uses 2.3-snapshot  
						
						... 
						
						
						
						Until a  production release of tomcat7-maven-plugin is made available, use a snapshot version
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-25 23:13:50 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						345e3cc7cb 
					 
					
						
						
							
							Fix typo on JS file  
						
						... 
						
						
						
						Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-25 22:53:56 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						441543100f 
					 
					
						
						
							
							Revert tomcat7 maven plugin to 2.1  
						
						... 
						
						
						
						Knonw bug on version 2.2 of the tomcat7-maven-plugin on extracting the temp directories for exec jar
Info: https://issues.apache.org/jira/browse/MTOMCAT-211 
https://fisheye6.atlassian.com/changelog/tomcat?cs=1539956 
https://fisheye6.atlassian.com/changelog/tomcat?cs=1539209 
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-25 22:51:28 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						8bffb76e5b 
					 
					
						
						
							
							Merge pull request  #127  from misfir3/master  
						
						... 
						
						
						
						items ommited from menu spinner and some more clean up 
						
						
					 
					
						2015-10-25 22:28:17 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						f6a938ffd1 
					 
					
						
						
							
							Merge pull request  #126  from dougmorato/master  
						
						... 
						
						
						
						Coveralls should be on Parent Pom 
						
						
					 
					
						2015-10-24 20:26:39 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						7e2d36ee48 
					 
					
						
						
							
							Coveralls should be on Parent Pom  
						
						... 
						
						
						
						moving the coverall plugin to the parent pom level
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-24 20:26:17 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						9eff95cf21 
					 
					
						
						
							
							Merge pull request  #125  from dougmorato/master  
						
						... 
						
						
						
						Adding badges for Coverity, Coveralls and Codacy 
						
						
					 
					
						2015-10-24 20:09:35 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						2f8ac1798b 
					 
					
						
						
							
							Adding Codacy Badge on README  
						
						... 
						
						
						
						Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-24 20:07:01 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						27479c9a62 
					 
					
						
						
							
							Fix typo on cobertura maven plugin pom.xml  
						
						... 
						
						
						
						Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-24 19:55:23 -04:00 
						 
				 
			
				
					
						
					 
					
						
						
							
						
						c8c3b75fbf 
					 
					
						
						
							
							Coverity scans only on specific branch  
						
						... 
						
						
						
						Instead of running coverity scans on every commit on the master branch, run scan only on the coverity_scan branch
Signed-off-by: Doug Morato <dm@corp.io > 
						
						
					 
					
						2015-10-24 19:49:20 -04:00