From fd5121f4273b04301457d4890193a4940322904a Mon Sep 17 00:00:00 2001 From: Joakim Argillander Date: Mon, 7 Dec 2020 08:32:01 +0100 Subject: [PATCH] Updated challenge text's CSRF-token parameter name Changed the challenge text's POST parameter from csrf to csrfToken, which is what is actually validated on the server. --- ...80a63e55ebb8fef3209c5d648b54d1276813cd072815df3.jsp | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/src/main/webapp/challenges/7d79ea2b2a82543d480a63e55ebb8fef3209c5d648b54d1276813cd072815df3.jsp b/src/main/webapp/challenges/7d79ea2b2a82543d480a63e55ebb8fef3209c5d648b54d1276813cd072815df3.jsp index 37c172de1..9fe33b993 100644 --- a/src/main/webapp/challenges/7d79ea2b2a82543d480a63e55ebb8fef3209c5d648b54d1276813cd072815df3.jsp +++ b/src/main/webapp/challenges/7d79ea2b2a82543d480a63e55ebb8fef3209c5d648b54d1276813cd072815df3.jsp @@ -71,13 +71,13 @@ if (request.getSession() != null) Security Shepherd - <%= i18nLevelName %> - + - - - + + +

<%= i18nLevelName %>

@@ -87,7 +87,7 @@ if (request.getSession() != null)
POST /user/csrfchallengeseven/plusplus
- <%= bundle.getString("challenge.withTheseParameters") %> userId = <%= bundle.getString("challenge.userIdExample") %> & csrf = <%= bundle.getString("challenge.yourCsrfTokenCamelCase") %> + <%= bundle.getString("challenge.withTheseParameters") %> userId = <%= bundle.getString("challenge.userIdExample") %> & csrfToken = <%= bundle.getString("challenge.yourCsrfTokenCamelCase") %>

<%= bundle.getString("challenge.whereIdIsUserBeenIncremented.1") %> <%= bundle.getString("challenge.userIdExample") %><%= bundle.getString("challenge.whereIdIsUserBeenIncremented.2") %> <%=bundle.getString("challenge.yourIdIs") %> <%= userId %> <%= bundle.getString("challenge.yourIdIs.1") %>