Skip to content

Sync fork with upstream WebGoat/WebGoat:main (8 commits, XXE conflicts resolved) - #42

Merged
fgibelin merged 9 commits into
mainfrom
sync/upstream-2026-09-30
Sep 30, 2026
Merged

fgibelin merged 9 commits into
mainfrom
sync/upstream-2026-09-30

Conversation

@fgibelin

Copy link
Copy Markdown
Owner

Syncs fgibelin/WebGoat:main with the latest 8 commits from upstream WebGoat/WebGoat:main.

Unlike previous syncs, this one required conflict resolution, so it goes through a branch in this fork rather than a direct cross-fork PR (a cross-fork PR has no writable head branch to commit the resolution to).

Upstream commits included

SHA Date Summary
1c37c553 2026-09-22 chore: back to snapshot after v2026.4 (WebGoat#2540)
98fd897a 2026-09-22 chore: bump com.diffplug.spotless:spotless-maven-plugin (WebGoat#2536)
b27a53ad 2026-09-22 test(xxe): use deterministic entity targets (WebGoat#2547)
c037c956 2026-09-22 chore: bump com.auth0:java-jwt from 4.6.0 to 4.6.1 (WebGoat#2538)
c92642df 2026-09-23 feat(cryptography): add HMAC timing attack lesson (WebGoat#2548)
d15692b3 2026-09-23 test(sql-injection): cover mitigation form submissions
f1a569c8 2026-09-23 ci: run matrix builds in parallel
3284a8e4 2026-09-23 feat(http): add parameter pollution lesson

Conflict resolution

Two files conflicted, both XXE tests:

  • src/test/java/org/owasp/webgoat/lessons/xxe/ContentTypeAssignmentTest.java
  • src/test/java/org/owasp/webgoat/lessons/xxe/SimpleXXETest.java

Cause: the local Windows-compatibility fix from #39 changed the hardcoded file:/// entity target to new File("/").toURI(). Upstream's b27a53ad independently replaced the same inline payload with a shared XXETestPayload.readKnownFile(tempDir) helper.

Resolved in favour of upstream. The new helper writes to a JUnit @TempDir and derives the entity URI via Path.toUri() — the same platform-independent technique as the local fix, applied to a deterministic temp file. It therefore supersedes #39 rather than reverting it, and Windows compatibility is preserved.

Both files are byte-identical to upstream after resolution; no conflict markers remain.

github-actions Bot and others added 9 commits September 22, 2026 09:03
Files changed:
M	pom.xml

Co-authored-by: nbaars <nbaars@users.noreply.github.com>
Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.10.1 to 3.10.2.
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.10.1...maven/3.10.2)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Root directory contents vary across CI runners, so XXE tests need a controlled file to verify external entity expansion reliably.
Bumps [com.auth0:java-jwt](https://github.com/auth0/java-jwt) from 4.6.0 to 4.6.1.
- [Release notes](https://github.com/auth0/java-jwt/releases)
- [Changelog](https://github.com/auth0/java-jwt/blob/master/CHANGELOG.md)
- [Commits](auth0/java-jwt@4.6.0...4.6.1)

---
updated-dependencies:
- dependency-name: com.auth0:java-jwt
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Teach how secret-dependent tag comparisons leak HMAC bytes and how repeated timing measurements can recover them under noise.
Existing endpoint tests bypass the lesson forms and miss incorrect action URLs that return 404. Add regression coverage for both input validation forms to prevent this failure from returning.

Closes: WebGoat#2502
Run the operating-system builds concurrently now that the flaky tests have been stabilized.
Teach how duplicate parameters can cause validation and execution to interpret the same request differently, including safe handling guidance.
Syncs 8 commits from upstream, including two new lessons (HMAC timing
attack, HTTP parameter pollution), dependency bumps, and CI changes.

Conflict resolution: ContentTypeAssignmentTest and SimpleXXETest both
conflicted with the local Windows-compatibility fix (#39). Resolved in
favour of upstream, whose new XXETestPayload helper writes to a JUnit
@tempdir and derives the entity URI via Path.toUri(). That is already
platform-independent, so it supersedes the local fix rather than
reverting it - Windows compatibility is preserved.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f7cea4d4-0f3e-4079-8fd7-a84ea41084d2
@fgibelin
fgibelin merged commit 34a4c63 into main Sep 30, 2026
8 checks passed
@fgibelin
fgibelin deleted the sync/upstream-2026-09-30 branch September 30, 2026 10:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants