@@ -34,7 +34,7 @@ exports.index = function (req, res, next) {
34
34
} ) ;
35
35
} ;
36
36
37
- // Insert new vulnerable code:
37
+ // Vulnerable code:
38
38
39
39
40
40
exports . loginHandler = function ( req , res , next ) {
@@ -101,43 +101,6 @@ exports.loginHandler = function (req, res, next) {
101
101
};
102
102
*/
103
103
104
- // Add new vulnerable code
105
- /*
106
-
107
- exports.loginHandler = function (req, res, next) {
108
- if (validator.isEmail(req.body.username)) {
109
- User.find({ username: req.body.username, password: req.body.password }, function (err, users) {
110
- if (users.length > 0) {
111
- const redirectPage = req.body.redirectPage
112
- const session = req.session
113
- const username = req.body.username
114
- return adminLoginSuccess(redirectPage, session, username, res)
115
- } else {
116
- return res.status(401).send()
117
- }
118
- });
119
- } else {
120
- return res.status(401).send()
121
- }
122
- };
123
-
124
-
125
- if (validator.isEmail(req.body.username)) {
126
- User.find({ username: req.body.username, password: req.body.password }, function (err, users) {
127
- if (users.length > 0) {
128
- const redirectPage = req.body.redirectPage
129
- const session = req.session
130
- const username = req.body.username
131
- return adminLoginSuccess(redirectPage, session, username, res)
132
- } else {
133
- return res.status(401).send()
134
- }
135
- });
136
- } else {
137
- return res.status(401).send()
138
- };
139
- */
140
-
141
104
function adminLoginSuccess ( redirectPage , session , username , res ) {
142
105
session . loggedIn = 1
143
106
0 commit comments