* better check on host and port for password reset and make context roots more flexible * spotless applied * removed hardcoded /WebGoat from js * removed hardcoded /WebGoat from js * fix spotless * fix scoreboard * upgrade WebWolf bootstrap version and icons and templates - part 1 * fixed more bootstrap 5 style issues and context path issues * organized WebSecurityConfig based on latest conventions and added basic support for oauth (more work needed) * spotless applied * added mock bean * requires updates to properties - commented for now * requires updates to properties - commented for now * oauth secrets through env values * user creation after oauth login * integration test against non default context paths * adjusted StartupMessage * add global model element username * conditionally show login oauth links * fixed WebWolf login --------- Co-authored-by: René Zubcevic <rene@Mac-mini-van-Rene.local>
46 lines
1.5 KiB
Java
46 lines
1.5 KiB
Java
/*
|
|
* This file is part of WebGoat, an Open Web Application Security Project utility. For details, please see http://www.owasp.org/
|
|
*
|
|
* Copyright (c) 2002 - 2021 Bruce Mayhew
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify it under the terms of the
|
|
* GNU General Public License as published by the Free Software Foundation; either version 2 of the
|
|
* License, or (at your option) any later version.
|
|
*
|
|
* This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without
|
|
* even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
* General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License along with this program; if
|
|
* not, write to the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA
|
|
* 02111-1307, USA.
|
|
*
|
|
* Getting Source
|
|
* ==============
|
|
*
|
|
* Source for this application is maintained at https://github.com/WebGoat/WebGoat, a repository for free software projects.
|
|
*/
|
|
|
|
package org.owasp.webgoat;
|
|
|
|
import java.util.Map;
|
|
import org.junit.jupiter.api.Test;
|
|
|
|
/**
|
|
* @author Angel Olle Blazquez
|
|
*/
|
|
class SessionManagementIT extends IntegrationTest {
|
|
|
|
private static final String HIJACK_LOGIN_CONTEXT_PATH = "HijackSession/login";
|
|
|
|
@Test
|
|
void hijackSessionTest() {
|
|
startLesson("HijackSession");
|
|
|
|
checkAssignment(
|
|
url(HIJACK_LOGIN_CONTEXT_PATH),
|
|
Map.of("username", "webgoat", "password", "webgoat"),
|
|
false);
|
|
}
|
|
}
|