Skip to content

Commit 4603c96

Browse files
authored
Merge pull request #2437 from OWASP/feature-fix-arcane
Feature fix arcane
2 parents bbeb071 + 3726f55 commit 4603c96

17 files changed

+25
-25
lines changed

.github/scripts/.bash_history

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -347,7 +347,7 @@ rm -rf jdk-18_linux-x64_bin.deb
347347
git rebase -i main
348348
git rebase -i master
349349
git stash
350-
export tempPassword="OeyxzcLdUbln0KxnhlQaT2wQKfpJpV/A7/ach+erH4M="
350+
export tempPassword="mVskm4vj9tBf4BqqQEyPaFtTAFJ+K9csVbQkwF3Kj04="
351351
mvn run tempPassword
352352
k6
353353
npx k6

Dockerfile

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
FROM bellsoft/liberica-openjre-debian:25-cds AS builder
22
WORKDIR /builder
33

4-
ARG argBasedVersion="1.13.1-alpha5"
4+
ARG argBasedVersion="1.13.1-alpha6"
55

66
COPY --chown=wrongsecrets target/wrongsecrets-${argBasedVersion}-SNAPSHOT.jar application.jar
77
RUN java -Djarmode=tools -jar application.jar extract --layers --destination extracted
@@ -59,7 +59,7 @@ RUN mkdir -p /var/run/secrets/kubernetes.io/serviceaccount && \
5959
chmod 600 /var/run/secrets/kubernetes.io/serviceaccount/token
6060

6161
# Create a dynamic archive
62-
RUN java --add-modules=jdk.unsupported -XX:ArchiveClassesAtExit=application.jsa -Dspring.context.exit=onRefresh -jar application.jar
62+
RUN java -XX:ArchiveClassesAtExit=application.jsa -Dspring.context.exit=onRefresh -jar application.jar
6363

6464
# Clean up the mocked token
6565
RUN rm -rf /var/run/secrets/kubernetes.io
@@ -71,5 +71,4 @@ RUN rm -rf /var/run/secrets/kubernetes.io
7171
RUN adduser -u 2000 -D wrongsecrets
7272
USER wrongsecrets
7373

74-
CMD java -Xms128m -Xmx128m -Xss512k -jar -Dserver.port=$PORT -XX:MaxRAMPercentage=75 -XX:MinRAMPercentage=25 -Dspring.profiles.active=without-vault -Dspringdoc.swagger-ui.enabled=${SPRINGDOC_UI} -Dspringdoc.api-docs.enabled=${SPRINGDOC_DOC} application.jar
75-
# CMD java -jar -XX:SharedArchiveFile=application.jsa -Dspring.profiles.active=$(echo ${SPRING_PROFILES_ACTIVE}) -Dspringdoc.swagger-ui.enabled=${SPRINGDOC_UI} -Dspringdoc.api-docs.enabled=${SPRINGDOC_DOC} -D application.jar
74+
CMD java -jar -XX:SharedArchiveFile=application.jsa -Dspring.profiles.active=$(echo ${SPRING_PROFILES_ACTIVE}) -Dspringdoc.swagger-ui.enabled=${SPRINGDOC_UI} -Dspringdoc.api-docs.enabled=${SPRINGDOC_DOC} -D application.jar

Dockerfile.web

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
1-
FROM jeroenwillemsen/wrongsecrets:1.13.1-alpha5-no-vault
2-
ARG argBasedVersion="1.13.1-alpha5-no-vault"
1+
FROM jeroenwillemsen/wrongsecrets:1.13.1-alpha6-no-vault
2+
ARG argBasedVersion="1.13.1-alpha6-no-vault"
33
ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp"
44
ARG CTF_ENABLED=false
55
ARG HINTS_ENABLED=true
@@ -21,6 +21,7 @@ ENV K8S_ENV=Heroku(Docker)
2121
ENV canarytokenURLs=$CANARY_URLS
2222
ENV ctf_enabled=$CTF_ENABLED
2323
ENV ctf_key=$CTF_KEY
24+
ENV SPRING_PROFILES_ACTIVE=without-vault
2425
ENV hints_enabled=$HINTS_ENABLED
2526
ENV challengedockermtpath="/var/helpers"
2627
ENV keepasspath="/var/helpers/alibabacreds.kdbx"
@@ -36,8 +37,9 @@ ENV default_aws_value_challenge_10=$CHALLENGE_10_VALUE
3637
ENV default_aws_value_challenge_11=$CHALLENGE_11_VALUE
3738
ENV BASTIONHOSTPATH="/home/wrongsecrets/.ssh"
3839
ENV PROJECTSPECPATH="/var/helpers/project-specification.mdc"
40+
ENV funnybunny="This is a funny bunny"
3941
COPY .github/scripts/ /var/helpers
4042
COPY src/test/resources/alibabacreds.kdbx /var/helpers
4143
COPY src/test/resources/RSAprivatekey.pem /var/helpers
4244
COPY .ssh/ /home/wrongsecrets/.ssh/
43-
CMD java -jar -XX:SharedArchiveFile=application.jsa -Dspring.profiles.active=$(echo ${SPRING_PROFILES_ACTIVE}) -Dspringdoc.swagger-ui.enabled=${SPRINGDOC_UI} -Dspringdoc.api-docs.enabled=${SPRINGDOC_DOC} -D application.jar
45+
CMD java -jar -XX:SharedArchiveFile=application.jsa -Dspring.profiles.active=without-vault -Dserver.port=${PORT} -Dspringdoc.swagger-ui.enabled=${SPRINGDOC_UI} -Dspringdoc.api-docs.enabled=${SPRINGDOC_DOC} application.jar

aws/k8s/secret-challenge-vault-deployment.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ spec:
5858
volumeAttributes:
5959
secretProviderClass: "wrongsecrets-aws-secretsmanager"
6060
containers:
61-
- image: jeroenwillemsen/wrongsecrets:1.13.1-alpha5-k8s-vault
61+
- image: jeroenwillemsen/wrongsecrets:1.13.1-alpha6-k8s-vault
6262
imagePullPolicy: IfNotPresent
6363
name: secret-challenge
6464
command: ["/bin/sh"]

azure/k8s/secret-challenge-vault-deployment.yml.tpl

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ spec:
6161
volumeAttributes:
6262
secretProviderClass: "azure-wrongsecrets-vault"
6363
containers:
64-
- image: jeroenwillemsen/wrongsecrets:1.13.1-alpha5-k8s-vault
64+
- image: jeroenwillemsen/wrongsecrets:1.13.1-alpha6-k8s-vault
6565
imagePullPolicy: IfNotPresent
6666
name: secret-challenge
6767
command: ["/bin/sh"]

docs/VERSION_MANAGEMENT.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,9 @@ The project maintains version consistency between:
1212
## Version Schema
1313

1414
```
15-
pom.xml version: 1.13.1-alpha5-SNAPSHOT
16-
Dockerfile version: 1.13.1-alpha5
17-
Dockerfile.web version: 1.13.1-alpha5-no-vault
15+
pom.xml version: 1.13.1-alpha6-SNAPSHOT
16+
Dockerfile version: 1.13.1-alpha6
17+
Dockerfile.web version: 1.13.1-alpha6-no-vault
1818
```
1919

2020
## Automated Solutions

fly.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ app = "wrongsecrets"
88
primary_region = "ams"
99

1010
[build]
11-
image = "docker.io/jeroenwillemsen/wrongsecrets:1.13.1-alpha5-no-vault"
11+
image = "docker.io/jeroenwillemsen/wrongsecrets:1.13.1-alpha6-no-vault"
1212

1313
[env]
1414
K8S_ENV = "Fly(Docker)"

gcp/k8s/secret-challenge-vault-deployment.yml.tpl

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ spec:
5858
volumeAttributes:
5959
secretProviderClass: "wrongsecrets-gcp-secretsmanager"
6060
containers:
61-
- image: jeroenwillemsen/wrongsecrets:1.13.1-alpha5-k8s-vault
61+
- image: jeroenwillemsen/wrongsecrets:1.13.1-alpha6-k8s-vault
6262
imagePullPolicy: IfNotPresent
6363
name: secret-challenge
6464
command: ["/bin/sh"]

heroku.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,3 @@
11
build:
22
docker:
33
web: Dockerfile.web
4-
worker: Dockerfile

js/index.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11

22
function secret() {
3-
var password = "t5K69iQ=" + 9 + "IoOL" + 6 + "jYE=" + 2 + "/i5I" + 7;
3+
var password = "m2/lkfE=" + 9 + "DsPI" + 6 + "2yc=" + 2 + "BcHo" + 7;
44
return password;
55
}

0 commit comments

Comments
 (0)