dev– start dev serverbuild– bundle application for productionanalyze– analyzes application bundle with @next/bundle-analyzer
typecheck– checks TypeScript typeslint– runs ESLintprettier:check– checks files with Prettier
Challenge progress data is stored within ./challengeProgress.json; to reset it, simply delete the file and restart the app.
Here is the ideal flow for devs to complete the CTF:
- Dev lands on homepage and inspects
- Dev sees the
/users/meendpoint and notices theexpandedquery param - Dev attempts
/usersendpoint and gets results - Dev adds
expandedto/usersquery and gets additional results (including last name)- Dev may either see the
hasTempPasswordvalue OR may see the header
- Dev may either see the
- Dev attempts to sign into a user with their temp password set and sees error
- Dev successfully signs into user account (using the identified last name) and views items
- Dev sees (TODO)
/itemsendpoint in browser and notices value indicating some are hidden - Later, dev either paginates or uses all and identifies admin user
- Dev examines data and identifies admin with temp password and signs in as admin
- Dev queries ALL items using the same pagination associated with users (TODO)
- Dev identifies the secret item
- Dev attempts to make PUT/PATCH against the item to make it public
Enhancements:
- Confetti on progress
- Notification on sign in
- Add style to title of challenge and icon
- Add fake header/value to ctf response
- Add easter eggs to ctf response