Skip to content

Commit 204f482

Browse files
committed
fix idor bug
1 parent 638288b commit 204f482

File tree

4 files changed

+12
-12
lines changed

4 files changed

+12
-12
lines changed

src/main/java/top/whgojp/modules/logic/idor/controller/VerticalController.java

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -22,16 +22,16 @@
2222
@RequestMapping("/logic/idor/vertical")
2323
public class VerticalController {
2424
@RequestMapping("")
25-
public String vertical(){
25+
public String vertical() {
2626
return "vul/logic/idor/vertical";
2727
}
2828

2929
@GetMapping("/vul")
30-
public String vul(){
31-
String currentUsername = SecurityContextHolder.getContext().getAuthentication().getName();
32-
if ("admin".equals(currentUsername)) {
33-
return "common/401";
34-
}else return "/vul/logic/idor/admin";
30+
public String vul() {
31+
String currentUsername = SecurityContextHolder.getContext().getAuthentication().getName();
32+
if ("admin".equals(currentUsername)) {
33+
return "/vul/logic/idor/admin";
34+
} else return "common/401";
3535
}
3636

3737
}

src/main/resources/static/js/staticcode.js

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1053,11 +1053,11 @@ const safeBlackList = "public String safe2(String payload) {\n" +
10531053
// 漏洞漏洞
10541054

10551055
// 越权漏洞
1056-
const vulHorizon = "public String vul(){\n" +
1056+
const vulHorizon = "public String vul() {\n" +
10571057
"\tString currentUsername = SecurityContextHolder.getContext().getAuthentication().getName();\n" +
10581058
"\tif (\"admin\".equals(currentUsername)) {\n" +
1059-
"\t\treturn \"common/401\";\n" +
1060-
"\t}else return \"/vul/logic/idor/admin\";\n" +
1059+
"\t\treturn \"/vul/logic/idor/admin\";\n" +
1060+
"\t} else return \"common/401\";\n" +
10611061
"}"
10621062
const safeHorizon = "public R safe(String username){\n" +
10631063
" // 获取当前登录的用户名\n" +

src/main/resources/templates/vul/logic/idor/horizontal.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -155,8 +155,8 @@ <h1><span class="iconfont icon-code"> 安全代码</span></h1>
155155
form = layui.form,
156156
upload = layui.upload;
157157

158-
common.formListenFun("vul-horizontal-button", "", "/logic/idor/getUserInfo", "vul-horizontal-result", "get");
159-
common.formListenFun("safe-horizontal-button", "", "/logic/idor/safe", "safe-horizontal-result", "get");
158+
common.formListenFun("vul-horizontal-button", "", "/logic/idor/horizontal/getUserInfo", "vul-horizontal-result", "get");
159+
common.formListenFun("safe-horizontal-button", "", "/logic/idor/horizontal/safe", "safe-horizontal-result", "get");
160160

161161

162162
miniTab.listen();

src/main/resources/templates/vul/logic/idor/vertical.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ <h1><span class="iconfont icon-bug"> 漏洞环境:垂直越权管理员</span>
3232
<div class="layui-tab-item layui-show">
3333
<blockquote class="layui-elem-quote main_btn">
3434
<p>这里简单模拟一下垂直越权</p>
35-
<a target="_blank" href="/logic/idor/vul">
35+
<a target="_blank" href="/logic/idor/vertical/vul">
3636
<button class="layui-btn layui-btn-normal" style="width: 100px; margin-left: 10px;">
3737
<span class="iconfont icon-zhihang">Run</span>
3838
</button>

0 commit comments

Comments
 (0)