-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclasswork1.js
More file actions
61 lines (53 loc) · 2.2 KB
/
Copy pathclasswork1.js
File metadata and controls
61 lines (53 loc) · 2.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
const express = require('express');
const router = express.Router();
router.all('/', (req, res) => {
const expectedMethod = 'GET';
const actualMethod = req.method;
const acceptHeader = req.headers['accept'];
const userAgent = req.headers['user-agent'];
const apiVersion = req.headers['x-api-version'];
if (userAgent && userAgent.toLowerCase().includes('mozilla')) {
return res.status(403).json({
error: 'Browser access denied',
hint: 'Use curl, Postman, or Thunder Client instead'
});
}
if (actualMethod !== expectedMethod) {
return res.status(405).json({
error: `Method ${actualMethod} not allowed`,
hint: 'Try a method used to retrieve data'
});
}
if (!acceptHeader || !acceptHeader.includes('application/json')) {
return res.status(406).json({
error: 'Missing Accept header',
hint: 'Set Accept: application/json'
});
}
if (!apiVersion || apiVersion !== 'v1') {
return res.status(400).json({
error: 'Missing or invalid API version',
hint: 'Add header: X-API-Version: v1'
});
}
res.json({
flag: 'FLAG_CLASSWORK1=FLAG{headers_unlock_the_door_2025}',
message: '✅ Challenge 1 completed!',
nextChallenge: '/classwork2'
});
});
module.exports = router;
// This code defines an Express.js route that checks the HTTP method and Content-Type header of incoming requests.
// If the method is not GET, it responds with a 405 status code and an error message.
// If the Content-Type is not application/json, it responds with a 415 status code and an error message.
// If both checks pass, it responds with a JSON object containing a flag and a success message.
// The route is exported as a module for use in an Express application.
// The code is designed to provide feedback to the user about the checks they need to pass, making it suitable for educational or challenge purposes.
// The flag is a placeholder and should be replaced with an actual flag value in a real application.
// The code is structured to be modular, allowing it to be easily integrated into a larger Express application.
/*
curl -X GET http://localhost:3000/classwork1 \
-H "Accept: application/json" \
-H "X-API-Version: v1" \
-H "User-Agent: curl/7.85.0"
*/