Skip to content

Commit 7e65dfa

Browse files
committed
Update POM file with new version: heroku-tst-6
1 parent 92f77ce commit 7e65dfa

File tree

4 files changed

+3
-7
lines changed

4 files changed

+3
-7
lines changed

Dockerfile.web

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM jeroenwillemsen/wrongsecrets:heroku-tst-5-no-vault
1+
FROM jeroenwillemsen/wrongsecrets:heroku-tst-6-no-vault
22

33
ARG argBasedVersion="1.3.10"
44
ARG CANARY_URLS="http://canarytokens.com/terms/about/s7cfbdakys13246ewd8ivuvku/post.jsp,http://canarytokens.com/terms/about/y0all60b627gzp19ahqh7rl6j/post.jsp"

pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
</parent>
1010
<groupId>org.owasp</groupId>
1111
<artifactId>wrongsecrets</artifactId>
12-
<version>heroku-tst-5-SNAPSHOT</version>
12+
<version>heroku-tst-6-SNAPSHOT</version>
1313
<name>OWASP WrongSecrets</name>
1414
<description>Examples with how to not use secrets</description>
1515
<url>https://owasp.org/www-project-wrongsecrets/</url>

src/main/java/org/owasp/wrongsecrets/HerokuWebSecurityConfig.java

+1-4
Original file line numberDiff line numberDiff line change
@@ -7,16 +7,13 @@
77
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
88

99
@Configuration
10-
@EnableWebSecurity(debug = true)
1110
@Order(1)
1211
public class HerokuWebSecurityConfig extends WebSecurityConfigurerAdapter {
1312

1413
@Override
1514
protected void configure(HttpSecurity http) throws Exception {
1615
http.requiresChannel()
1716
.requestMatchers(r -> r.getHeader("x-forwarded-proto") != null || r.getHeader("X-Forwarded-Proto") != null)
18-
.requiresSecure()
19-
.and()
20-
.csrf().disable();
17+
.requiresSecure();
2118
}
2219
}

src/main/java/org/owasp/wrongsecrets/canaries/TokenCallbackSecurityConfiguration.java

-1
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,6 @@
77
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;
88

99
@Configuration
10-
@EnableWebSecurity(debug = true)
1110
@Order(0)
1211
public class TokenCallbackSecurityConfiguration extends WebSecurityConfigurerAdapter {
1312

0 commit comments

Comments
 (0)