secDevLabs icon indicating copy to clipboard operation
secDevLabs copied to clipboard

Tic-tac-toe application - doesn't allow the users creation.

Open fabianbch opened this issue 8 months ago • 1 comments

What are the steps to reproduce this bug?

  1. All instructions for the implementation and deployment of the application were followed.
  2. When entering http://localhost:10005/login and clicking on the /create option, the registered users are not created.
  3. When entering /login with any user - created or not - the HTTP header remains blank with no information.

What happens?

Invalid CORS error messages are returned on user creation, the application Tic-tac-toe does not work correctly.

What were you expecting to happen?

The application does not work, when entering /statistics the page returns the invalid token message.

Any logs, error output, etc?

Image

Any other comments?

Thanks for your help, also the packages: npm, jackson, are in obsolete or outdated versions. When I run make install I get warning messages for deprecated software versions.

fabianbch avatar Apr 04 '25 19:04 fabianbch

Hi there!

After taking a look, looks like SECRET property ended up being empty after the deployment:

Image

So I hardcoded a specific SECRET on secDevLabs/owasp-top10-2021-apps/a1/tictactoe/deployments/generate-env.sh:

Image

After that, I deployed again and checked that SECRET had a value:

Image

I tried to create an account and login was successful:

Image

ElCyberCurioso avatar Aug 04 '25 19:08 ElCyberCurioso