-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclasswork6.js
More file actions
108 lines (94 loc) · 3.67 KB
/
Copy pathclasswork6.js
File metadata and controls
108 lines (94 loc) · 3.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
const express = require('express');
const router = express.Router();
const jwt = require('jsonwebtoken');
const { SECRET_KEY, SESSION_ID } = require('./config');
router.all('/', (req, res) => {
const expectedMethod = 'DELETE';
const actualMethod = req.method;
const contentType = req.headers['content-type'];
const userAgent = req.headers['user-agent'];
const customHeader = req.headers['x-custom-header'];
const cookie = req.cookies.sessionid;
const authHeader = req.headers['authorization'];
if (userAgent && userAgent.toLowerCase().includes('mozilla')) {
return res.status(403).json({
error: 'Browser access blocked',
hint: 'Use API client'
});
}
if (actualMethod !== expectedMethod) {
return res.status(405).json({
error: `Method ${actualMethod} not allowed`,
hint: 'This challenge requires DELETE method'
});
}
if (!contentType || contentType.toLowerCase() !== 'application/json') {
return res.status(415).json({
error: 'Invalid Content-Type',
hint: 'Set Content-Type: application/json'
});
}
if (!customHeader || customHeader.toLowerCase() !== 'secretvalue') {
return res.status(400).json({
error: 'Invalid custom header',
hint: 'Add header: X-Custom-Header: secretvalue'
});
}
if (!cookie || cookie !== SESSION_ID) {
return res.status(401).json({
error: 'Invalid session cookie',
hint: `Expected sessionid=${SESSION_ID}`
});
}
if (!authHeader || !authHeader.startsWith('Bearer ')) {
return res.status(401).json({
error: 'Missing Authorization header',
hint: 'Add header: Authorization: Bearer <token>'
});
}
const token = authHeader.split(' ')[1];
try {
jwt.verify(token, SECRET_KEY);
} catch (err) {
return res.status(401).json({
error: 'Invalid or expired JWT token',
hint: 'Login again for fresh token'
});
}
res.json({
flag: 'FLAG_CLASSWORK6=FLAG{full_auth_stack_jwt_cookie_delete}',
message: '✅ Challenge 6 completed!',
nextChallenge: '/classwork7',
difficulty: 'Increasing...'
});
});
module.exports = router;
// This code defines an Express.js route that handles DELETE requests.
// It checks for the presence of specific headers, a valid JWT token in the Authorization header,
// and a valid session cookie. If any of these checks fail, it responds with an appropriate error message and hint.
// If all checks pass, it responds with a JSON object containing a flag and a success message.
// The route is exported as a module for use in an Express application.
/*
curl -X DELETE http://localhost:4000/classwork6 \
-H "Content-Type: application/json" \
-H "X-Custom-Header: secretvalue" \
-H "Authorization: Bearer <token_from_login>" \
--cookie "sessionid=<session_id_from_login>"
*/
// To test this route, you need to login to obtain a valid JWT token and session cookie.
/*
1. First, login to get the token and session cookie:
curl -X POST http://localhost:4000/login \
-H "Content-Type: application/json" \
-d '{"username": "daniel", "password": "securepassword"}' \
-c cookies.txt
2. Extract the token from the login response and the sessionid from cookies.txt.
3. Then, use the token and sessionid to access this DELETE route:
curl -X DELETE http://localhost:4000/classwork6 \
-H "Content-Type: application/json" \
-H "X-Custom-Header: secretvalue" \
-H "Authorization: Bearer <token_from_login>" \
--cookie "sessionid=<session_id_from_login>"
*/
// The code is designed to provide feedback to the user about the checks they need to pass, making it suitable for educational or challenge purposes.
// The code is structured to be modular, allowing it to be easily integrated into a larger Express application.