feat: Wahl-Phasen, Verantwortliche-Invites, Auth fixes, GRUPPE chat #1
@@ -0,0 +1,21 @@
|
||||
// TEMPORARY TEST FILE — intentionally vulnerable code to trigger CybeDefend scan
|
||||
// Safe to delete after the scan demo.
|
||||
|
||||
const AWS_ACCESS_KEY = "AKIAABCDEFGHIJKLMNOP"; // hardcoded secret (should trigger secret scanner)
|
||||
const DB_PASSWORD = "SuperSecret123!"; // hardcoded credential
|
||||
|
||||
const mysql = require('mysql');
|
||||
|
||||
function getUser(db, userId) {
|
||||
// SQL injection: string concatenation of user input directly into query
|
||||
const query = "SELECT * FROM users WHERE id = '" + userId + "'";
|
||||
return db.query(query);
|
||||
}
|
||||
|
||||
function runCommand(userInput) {
|
||||
const { exec } = require('child_process');
|
||||
// command injection: unsanitized user input passed to shell
|
||||
exec("echo " + userInput);
|
||||
}
|
||||
|
||||
module.exports = { getUser, runCommand, AWS_ACCESS_KEY, DB_PASSWORD };
|
||||
Reference in New Issue
Block a user