-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclasswork5.js
More file actions
113 lines (100 loc) · 3.52 KB
/
Copy pathclasswork5.js
File metadata and controls
113 lines (100 loc) · 3.52 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
const express = require('express');
const router = express.Router();
const jwt = require('jsonwebtoken');
const { SECRET_KEY, SESSION_ID } = require('./config');
const validateRequest = (req, res, next) => {
const { 'content-type': contentType, 'user-agent': userAgent, 'x-custom-header': customHeader, authorization } = req.headers;
const cookie = req.cookies.sessionid;
if (userAgent?.toLowerCase().includes('mozilla')) {
return res.status(403).json({
error: 'Browser access blocked',
hint: 'Use API client'
});
}
if (contentType?.toLowerCase() !== 'application/json') {
return res.status(415).json({
error: 'Invalid Content-Type',
hint: 'Set Content-Type: application/json'
});
}
if (customHeader !== 'secretvalue') {
return res.status(400).json({
error: 'Invalid custom header',
hint: 'Add header: X-Custom-Header: secretvalue'
});
}
if (cookie !== SESSION_ID) {
return res.status(401).json({
error: 'Invalid session cookie',
hint: `Login first at /login to get cookie`
});
}
if (!authorization?.startsWith('Bearer ')) {
return res.status(401).json({
error: 'Missing Authorization header',
hint: 'Add header: Authorization: Bearer <token_from_login>'
});
}
try {
const token = authorization.split(' ')[1];
req.user = jwt.verify(token, SECRET_KEY);
next();
} catch {
return res.status(401).json({
error: 'Invalid or expired JWT token',
hint: 'Login again to get fresh token'
});
}
};
router.put('/', validateRequest, (req, res) => {
res.json({
flag: 'FLAG_CLASSWORK5_PUT=FLAG{patch_with_jwt_cookie_authorized!}',
message: '✅ PUT challenge passed!',
note: 'Try PATCH and DELETE methods too'
});
});
router.patch('/', validateRequest, (req, res) => {
res.json({
flag: 'FLAG_CLASSWORK5_PATCH=FLAG{patch_with_jwt_cookie_success}',
message: '✅ PATCH challenge passed!',
note: 'One more method to go!'
});
});
router.delete('/', validateRequest, (req, res) => {
res.json({
flag: 'FLAG_CLASSWORK5_DELETE=FLAG{patch_with_jwt_cookie_Complete!}',
message: '✅ DELETE challenge passed!',
nextChallenge: '/classwork6'
});
});
module.exports = router;
// This code defines an Express.js route that handles PUT, PATCH, and DELETE requests.
// It uses a middleware function `validateRequest` to check for the presence of specific headers,
// a valid JWT token in the Authorization header, and a valid session cookie.
// If any of these checks fail, it responds with an appropriate error message and hint.
// If all checks pass, it allows the request to proceed to the respective route handler,
// which responds with a flag and success message.
// The route is exported as a module for use in an Express application.
// To test these routes, you need to login
// to obtain a valid JWT token and session cookie.
/*
curl -X PUT http://localhost:3000/classwork5 \
-H "Content-Type: application/json" \
-H "X-Custom-Header: secretvalue" \
-H "Authorization: Bearer <token_from_login>" \
--cookie "sessionid=<session_id_from_login>"
*/
/*
curl -X PATCH http://localhost:3000/classwork5 \
-H "Content-Type: application/json" \
-H "X-Custom-Header: secretvalue" \
-H "Authorization: Bearer <token_from_login>" \
--cookie "sessionid=<session_id_from_login>"
*/
/*
curl -X DELETE http://localhost:3000/classwork5 \
-H "Content-Type: application/json" \
-H "X-Custom-Header: secretvalue" \
-H "Authorization: Bearer <token_from_login>" \
--cookie "sessionid=<session_id_from_login>"
*/