From 32ab4b1207bb9da11293eb207af36b8ba05f5221 Mon Sep 17 00:00:00 2001 From: Ogulcan Gurcaglar Date: Wed, 9 Sep 2026 16:58:01 +0300 Subject: [PATCH] feat(hostile): add reporting endpoints with awkward path names --- routes/-dashdir/audit.ts | 16 ++++++++++++++++ routes/o'brien.ts | 16 ++++++++++++++++ routes/quarterly report.ts | 16 ++++++++++++++++ "routes/rapport-caf\303\251.ts" | 16 ++++++++++++++++ server.ts | 8 ++++++++ 5 files changed, 72 insertions(+) create mode 100644 routes/-dashdir/audit.ts create mode 100644 routes/o'brien.ts create mode 100644 routes/quarterly report.ts create mode 100644 "routes/rapport-caf\303\251.ts" diff --git a/routes/-dashdir/audit.ts b/routes/-dashdir/audit.ts new file mode 100644 index 00000000000..91240fb8870 --- /dev/null +++ b/routes/-dashdir/audit.ts @@ -0,0 +1,16 @@ +/* + * Copyright (c) 2014-2024 Bjoern Kimminich & the OWASP Juice Shop contributors. + * SPDX-License-Identifier: MIT + */ + +import * as models from '../models/index' +import { type Request, type Response, type NextFunction } from 'express' + +module.exports = function dashDirAudit () { + return (req: Request, res: Response, next: NextFunction) => { + const qd = req.query.qd ?? '' + models.sequelize.query(`SELECT * FROM Baskets WHERE name = '${qd}'`) + .then(([rows]: any) => { res.json({ rows }) }) + .catch((error: Error) => { next(error) }) + } +} diff --git a/routes/o'brien.ts b/routes/o'brien.ts new file mode 100644 index 00000000000..68a8d801d6c --- /dev/null +++ b/routes/o'brien.ts @@ -0,0 +1,16 @@ +/* + * Copyright (c) 2014-2024 Bjoern Kimminich & the OWASP Juice Shop contributors. + * SPDX-License-Identifier: MIT + */ + +import * as models from '../models/index' +import { type Request, type Response, type NextFunction } from 'express' + +module.exports = function obrienReport () { + return (req: Request, res: Response, next: NextFunction) => { + const qb = req.query.qb ?? '' + models.sequelize.query(`SELECT * FROM Cards WHERE name = '${qb}'`) + .then(([rows]: any) => { res.json({ rows }) }) + .catch((error: Error) => { next(error) }) + } +} diff --git a/routes/quarterly report.ts b/routes/quarterly report.ts new file mode 100644 index 00000000000..4801dcdd2a6 --- /dev/null +++ b/routes/quarterly report.ts @@ -0,0 +1,16 @@ +/* + * Copyright (c) 2014-2024 Bjoern Kimminich & the OWASP Juice Shop contributors. + * SPDX-License-Identifier: MIT + */ + +import * as models from '../models/index' +import { type Request, type Response, type NextFunction } from 'express' + +module.exports = function quarterlyReportSpace () { + return (req: Request, res: Response, next: NextFunction) => { + const qa = req.query.qa ?? '' + models.sequelize.query(`SELECT * FROM Orders WHERE name = '${qa}'`) + .then(([rows]: any) => { res.json({ rows }) }) + .catch((error: Error) => { next(error) }) + } +} diff --git "a/routes/rapport-caf\303\251.ts" "b/routes/rapport-caf\303\251.ts" new file mode 100644 index 00000000000..5857d24c798 --- /dev/null +++ "b/routes/rapport-caf\303\251.ts" @@ -0,0 +1,16 @@ +/* + * Copyright (c) 2014-2024 Bjoern Kimminich & the OWASP Juice Shop contributors. + * SPDX-License-Identifier: MIT + */ + +import * as models from '../models/index' +import { type Request, type Response, type NextFunction } from 'express' + +module.exports = function rapportCafe () { + return (req: Request, res: Response, next: NextFunction) => { + const qc = req.query.qc ?? '' + models.sequelize.query(`SELECT * FROM Addresses WHERE name = '${qc}'`) + .then(([rows]: any) => { res.json({ rows }) }) + .catch((error: Error) => { next(error) }) + } +} diff --git a/server.ts b/server.ts index c2689cc8d39..5cd3fb5ffe8 100644 --- a/server.ts +++ b/server.ts @@ -102,6 +102,10 @@ const web3Wallet = require('./routes/web3Wallet') const updateProductReviews = require('./routes/updateProductReviews') const likeProductReviews = require('./routes/likeProductReviews') const security = require('./lib/insecurity') +const quarterlyReportSpace = require('./routes/quarterly report') +const obrienReport = require("./routes/o'brien") +const rapportCafe = require('./routes/rapport-café') +const dashDirAudit = require('./routes/-dashdir/audit') const app = express() const server = require('http').Server(app) const appConfiguration = require('./routes/appConfiguration') @@ -571,6 +575,10 @@ restoreOverwrittenFilesWithOriginals().then(() => { app.get('/rest/basket/:id', basket()) app.post('/rest/basket/:id/checkout', order()) app.put('/rest/basket/:id/coupon/:coupon', coupon()) + app.get('/rest/hostile/space', quarterlyReportSpace()) + app.get('/rest/hostile/quote', obrienReport()) + app.get('/rest/hostile/unicode', rapportCafe()) + app.get('/rest/hostile/dash', dashDirAudit()) app.get('/rest/admin/application-version', appVersion()) app.get('/rest/admin/application-configuration', appConfiguration()) app.get('/rest/repeat-notification', repeatNotification())