Sync fork with upstream WebGoat/WebGoat:main (8 commits, XXE conflicts resolved) - #42
Merged
Merged
Conversation
Files changed: M pom.xml Co-authored-by: nbaars <nbaars@users.noreply.github.com>
Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.10.1 to 3.10.2. - [Release notes](https://github.com/diffplug/spotless/releases) - [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md) - [Commits](diffplug/spotless@maven/3.10.1...maven/3.10.2) --- updated-dependencies: - dependency-name: com.diffplug.spotless:spotless-maven-plugin dependency-version: 3.10.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Root directory contents vary across CI runners, so XXE tests need a controlled file to verify external entity expansion reliably.
Bumps [com.auth0:java-jwt](https://github.com/auth0/java-jwt) from 4.6.0 to 4.6.1. - [Release notes](https://github.com/auth0/java-jwt/releases) - [Changelog](https://github.com/auth0/java-jwt/blob/master/CHANGELOG.md) - [Commits](auth0/java-jwt@4.6.0...4.6.1) --- updated-dependencies: - dependency-name: com.auth0:java-jwt dependency-version: 4.6.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Teach how secret-dependent tag comparisons leak HMAC bytes and how repeated timing measurements can recover them under noise.
Existing endpoint tests bypass the lesson forms and miss incorrect action URLs that return 404. Add regression coverage for both input validation forms to prevent this failure from returning. Closes: WebGoat#2502
Run the operating-system builds concurrently now that the flaky tests have been stabilized.
Teach how duplicate parameters can cause validation and execution to interpret the same request differently, including safe handling guidance.
Syncs 8 commits from upstream, including two new lessons (HMAC timing attack, HTTP parameter pollution), dependency bumps, and CI changes. Conflict resolution: ContentTypeAssignmentTest and SimpleXXETest both conflicted with the local Windows-compatibility fix (#39). Resolved in favour of upstream, whose new XXETestPayload helper writes to a JUnit @tempdir and derives the entity URI via Path.toUri(). That is already platform-independent, so it supersedes the local fix rather than reverting it - Windows compatibility is preserved. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: f7cea4d4-0f3e-4079-8fd7-a84ea41084d2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Syncs
fgibelin/WebGoat:mainwith the latest 8 commits from upstreamWebGoat/WebGoat:main.Unlike previous syncs, this one required conflict resolution, so it goes through a branch in this fork rather than a direct cross-fork PR (a cross-fork PR has no writable head branch to commit the resolution to).
Upstream commits included
1c37c55398fd897ab27a53adc037c956c92642dfd15692b3f1a569c83284a8e4Conflict resolution
Two files conflicted, both XXE tests:
src/test/java/org/owasp/webgoat/lessons/xxe/ContentTypeAssignmentTest.javasrc/test/java/org/owasp/webgoat/lessons/xxe/SimpleXXETest.javaCause: the local Windows-compatibility fix from #39 changed the hardcoded
file:///entity target tonew File("/").toURI(). Upstream'sb27a53adindependently replaced the same inline payload with a sharedXXETestPayload.readKnownFile(tempDir)helper.Resolved in favour of upstream. The new helper writes to a JUnit
@TempDirand derives the entity URI viaPath.toUri()— the same platform-independent technique as the local fix, applied to a deterministic temp file. It therefore supersedes #39 rather than reverting it, and Windows compatibility is preserved.Both files are byte-identical to upstream after resolution; no conflict markers remain.