Add lessons
This commit is contained in:
@@ -64,6 +64,7 @@ CREATE TABLE lesson_progress (
|
||||
score INTEGER DEFAULT 0,
|
||||
attempts INTEGER DEFAULT 0,
|
||||
current_step INTEGER DEFAULT 0,
|
||||
activity_data JSONB DEFAULT '{}'::jsonb,
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||
updated_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||
UNIQUE(participant_id, event_lesson_id),
|
||||
@@ -101,6 +102,7 @@ CREATE INDEX idx_event_lessons_order ON event_lessons(event_id, order_index);
|
||||
CREATE INDEX idx_lesson_progress_participant ON lesson_progress(participant_id);
|
||||
CREATE INDEX idx_lesson_progress_event_lesson ON lesson_progress(event_lesson_id);
|
||||
CREATE INDEX idx_lesson_progress_status ON lesson_progress(status);
|
||||
CREATE INDEX idx_lesson_progress_activity_data ON lesson_progress USING gin(activity_data);
|
||||
CREATE INDEX idx_lesson_answers_progress ON lesson_answers(lesson_progress_id);
|
||||
CREATE INDEX idx_lesson_answers_question ON lesson_answers(question_key);
|
||||
|
||||
@@ -123,10 +125,8 @@ CREATE TRIGGER update_lessons_updated_at BEFORE UPDATE ON lessons
|
||||
CREATE TRIGGER update_lesson_progress_updated_at BEFORE UPDATE ON lesson_progress
|
||||
FOR EACH ROW EXECUTE FUNCTION update_updated_at_column();
|
||||
|
||||
-- Insert default admin user (password: admin123 - CHANGE IN PRODUCTION!)
|
||||
-- bcrypt hash for 'admin123' with 10 rounds
|
||||
INSERT INTO admin_users (username, password_hash) VALUES
|
||||
('admin', '$2b$10$mP8BvCik6In9lvWqxV57VuKglR3IqW4GfMoF.5fsT8HrTxRqscElW');
|
||||
-- Admin user is automatically created on server startup using ADMIN_DEFAULT_PASSWORD from .env
|
||||
-- See: backend/src/utils/initAdmin.js
|
||||
|
||||
-- Comments for documentation
|
||||
COMMENT ON TABLE events IS 'Training events or sessions that participants can join';
|
||||
@@ -134,5 +134,6 @@ COMMENT ON TABLE participants IS 'Anonymous participants identified by pseudonym
|
||||
COMMENT ON TABLE lessons IS 'Catalog of available lesson modules';
|
||||
COMMENT ON TABLE event_lessons IS 'Lessons assigned to specific events with custom configuration';
|
||||
COMMENT ON TABLE lesson_progress IS 'Tracks individual participant progress through lessons';
|
||||
COMMENT ON COLUMN lesson_progress.activity_data IS 'Custom lesson-specific state data (e.g., SQL injection discoveries, XSS attempts, etc.)';
|
||||
COMMENT ON TABLE lesson_answers IS 'Stores submitted answers with scoring information';
|
||||
COMMENT ON TABLE admin_users IS 'Administrative users with full system access';
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
-- Seed lessons into the database
|
||||
-- This runs automatically when the database is first initialized
|
||||
|
||||
INSERT INTO lessons (lesson_key, title, description, module_path, config_path, difficulty_level, estimated_duration) VALUES
|
||||
-- Existing lesson
|
||||
('phishing-email-basics', 'Phishing Email Detection Basics', 'Learn to identify common phishing tactics in emails and protect yourself from email-based attacks', 'phishing-email-basics', 'phishing-email-basics.yaml', 'beginner', 15),
|
||||
|
||||
-- SQL Injection lesson
|
||||
('sql-injection-shop', 'SQL Injection Attack - Online Shop Demo', 'Learn how SQL injection vulnerabilities work through a realistic online shop scenario', 'sql-injection-shop', 'sql-injection-shop.yaml', 'intermediate', 20),
|
||||
|
||||
-- Browser-in-the-Browser lesson
|
||||
('browser-in-browser-attack', 'Browser-in-the-Browser Attack', 'Learn to recognize fake browser windows used in phishing attacks', 'browser-in-browser-attack', 'browser-in-browser-attack.yaml', 'advanced', 25),
|
||||
|
||||
-- New offensive security lessons
|
||||
-- Combined XSS lesson (replaces xss-deeplink-demo and script-injection-forum)
|
||||
('xss-comprehensive', 'Cross-Site Scripting (XSS) - Reflected & Stored Angriffe', 'Lernen Sie, wie XSS-Angriffe durch URL-Manipulation und benutzergenerierte Inhalte funktionieren und wie man sie erkennt', 'xss-comprehensive', 'xss-comprehensive.yaml', 'intermediate', 35),
|
||||
|
||||
('social-engineering-password', 'Social Engineering - Passwortsicherheit', 'Lernen Sie, wie persönliche Informationen aus sozialen Medien zu schwachen Passwörtern führen können', 'social-engineering-password', 'social-engineering-password.yaml', 'beginner', 20),
|
||||
|
||||
('idor-demo', 'IDOR - Insecure Direct Object Reference', 'Learn how insecure direct object references allow unauthorized access to other users'' data through URL manipulation', 'idor-demo', 'idor-demo.yaml', 'intermediate', 22)
|
||||
|
||||
ON CONFLICT (lesson_key) DO NOTHING;
|
||||
@@ -0,0 +1,36 @@
|
||||
-- Event Comments and Jackpot Discovery Tables
|
||||
-- Part of the hidden "Jackpot" Easter egg feature
|
||||
|
||||
-- Event comments table (isolated per participant)
|
||||
CREATE TABLE event_comments (
|
||||
id SERIAL PRIMARY KEY,
|
||||
participant_id INTEGER NOT NULL REFERENCES participants(id) ON DELETE CASCADE,
|
||||
event_id INTEGER NOT NULL REFERENCES events(id) ON DELETE CASCADE,
|
||||
content TEXT NOT NULL,
|
||||
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
|
||||
-- Indexes for performance
|
||||
CREATE INDEX idx_event_comments_participant ON event_comments(participant_id);
|
||||
CREATE INDEX idx_event_comments_event ON event_comments(event_id);
|
||||
CREATE INDEX idx_event_comments_composite ON event_comments(participant_id, event_id);
|
||||
|
||||
COMMENT ON TABLE event_comments IS 'Participant feedback comments - visible only to poster (isolated per participant)';
|
||||
|
||||
-- Jackpot discoveries tracking table
|
||||
CREATE TABLE jackpot_discoveries (
|
||||
id SERIAL PRIMARY KEY,
|
||||
participant_id INTEGER NOT NULL REFERENCES participants(id) ON DELETE CASCADE,
|
||||
event_id INTEGER NOT NULL REFERENCES events(id) ON DELETE CASCADE,
|
||||
discovered_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||
payload TEXT,
|
||||
score_before INTEGER,
|
||||
score_after INTEGER,
|
||||
UNIQUE(participant_id, event_id)
|
||||
);
|
||||
|
||||
-- Indexes for jackpot discoveries
|
||||
CREATE INDEX idx_jackpot_discoveries_event ON jackpot_discoveries(event_id);
|
||||
CREATE INDEX idx_jackpot_discoveries_participant ON jackpot_discoveries(participant_id);
|
||||
|
||||
COMMENT ON TABLE jackpot_discoveries IS 'Tracks participants who discovered the SQL injection Easter egg';
|
||||
@@ -0,0 +1,10 @@
|
||||
-- Migration: Add activity_data column to lesson_progress
|
||||
-- This allows lessons to store custom state (e.g., SQL injection discoveries, XSS attempts, etc.)
|
||||
|
||||
ALTER TABLE lesson_progress
|
||||
ADD COLUMN activity_data JSONB DEFAULT '{}'::jsonb;
|
||||
|
||||
COMMENT ON COLUMN lesson_progress.activity_data IS 'Custom lesson-specific state data (e.g., discoveries, attempts, etc.)';
|
||||
|
||||
-- Create index for faster JSONB queries
|
||||
CREATE INDEX idx_lesson_progress_activity_data ON lesson_progress USING gin(activity_data);
|
||||
@@ -0,0 +1,4 @@
|
||||
-- Fix existing lesson_progress rows that might have NULL activity_data
|
||||
UPDATE lesson_progress
|
||||
SET activity_data = '{}'::jsonb
|
||||
WHERE activity_data IS NULL;
|
||||
@@ -0,0 +1,27 @@
|
||||
-- Migration: Add vulnerability_type column to jackpot_discoveries table
|
||||
-- Purpose: Track different Easter egg types (XSS, SQL injection, etc.)
|
||||
-- Date: 2026-02-08
|
||||
|
||||
-- Add column to distinguish vulnerability types
|
||||
ALTER TABLE jackpot_discoveries
|
||||
ADD COLUMN IF NOT EXISTS vulnerability_type VARCHAR(50) DEFAULT 'sql_injection';
|
||||
|
||||
-- Update existing constraint to allow multiple discoveries per participant
|
||||
ALTER TABLE jackpot_discoveries
|
||||
DROP CONSTRAINT IF EXISTS jackpot_discoveries_participant_id_event_id_key;
|
||||
|
||||
-- Add new unique constraint including vulnerability type
|
||||
-- This allows participants to discover multiple Easter eggs independently
|
||||
ALTER TABLE jackpot_discoveries
|
||||
DROP CONSTRAINT IF EXISTS jackpot_discoveries_unique;
|
||||
|
||||
ALTER TABLE jackpot_discoveries
|
||||
ADD CONSTRAINT jackpot_discoveries_unique
|
||||
UNIQUE (participant_id, event_id, vulnerability_type);
|
||||
|
||||
-- Create index for faster lookups
|
||||
CREATE INDEX IF NOT EXISTS idx_jackpot_vuln_type
|
||||
ON jackpot_discoveries(participant_id, event_id, vulnerability_type);
|
||||
|
||||
-- Add comment for documentation
|
||||
COMMENT ON COLUMN jackpot_discoveries.vulnerability_type IS 'Type of vulnerability discovered: xss, sql_injection, sql_filter, etc.';
|
||||
Reference in New Issue
Block a user