Add lessons

This commit is contained in:
Marius Rometsch
2026-02-08 19:47:21 +01:00
parent 0068785924
commit a439873394
52 changed files with 9049 additions and 997 deletions
+5 -4
View File
@@ -64,6 +64,7 @@ CREATE TABLE lesson_progress (
score INTEGER DEFAULT 0,
attempts INTEGER DEFAULT 0,
current_step INTEGER DEFAULT 0,
activity_data JSONB DEFAULT '{}'::jsonb,
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
updated_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
UNIQUE(participant_id, event_lesson_id),
@@ -101,6 +102,7 @@ CREATE INDEX idx_event_lessons_order ON event_lessons(event_id, order_index);
CREATE INDEX idx_lesson_progress_participant ON lesson_progress(participant_id);
CREATE INDEX idx_lesson_progress_event_lesson ON lesson_progress(event_lesson_id);
CREATE INDEX idx_lesson_progress_status ON lesson_progress(status);
CREATE INDEX idx_lesson_progress_activity_data ON lesson_progress USING gin(activity_data);
CREATE INDEX idx_lesson_answers_progress ON lesson_answers(lesson_progress_id);
CREATE INDEX idx_lesson_answers_question ON lesson_answers(question_key);
@@ -123,10 +125,8 @@ CREATE TRIGGER update_lessons_updated_at BEFORE UPDATE ON lessons
CREATE TRIGGER update_lesson_progress_updated_at BEFORE UPDATE ON lesson_progress
FOR EACH ROW EXECUTE FUNCTION update_updated_at_column();
-- Insert default admin user (password: admin123 - CHANGE IN PRODUCTION!)
-- bcrypt hash for 'admin123' with 10 rounds
INSERT INTO admin_users (username, password_hash) VALUES
('admin', '$2b$10$mP8BvCik6In9lvWqxV57VuKglR3IqW4GfMoF.5fsT8HrTxRqscElW');
-- Admin user is automatically created on server startup using ADMIN_DEFAULT_PASSWORD from .env
-- See: backend/src/utils/initAdmin.js
-- Comments for documentation
COMMENT ON TABLE events IS 'Training events or sessions that participants can join';
@@ -134,5 +134,6 @@ COMMENT ON TABLE participants IS 'Anonymous participants identified by pseudonym
COMMENT ON TABLE lessons IS 'Catalog of available lesson modules';
COMMENT ON TABLE event_lessons IS 'Lessons assigned to specific events with custom configuration';
COMMENT ON TABLE lesson_progress IS 'Tracks individual participant progress through lessons';
COMMENT ON COLUMN lesson_progress.activity_data IS 'Custom lesson-specific state data (e.g., SQL injection discoveries, XSS attempts, etc.)';
COMMENT ON TABLE lesson_answers IS 'Stores submitted answers with scoring information';
COMMENT ON TABLE admin_users IS 'Administrative users with full system access';
+22
View File
@@ -0,0 +1,22 @@
-- Seed lessons into the database
-- This runs automatically when the database is first initialized
INSERT INTO lessons (lesson_key, title, description, module_path, config_path, difficulty_level, estimated_duration) VALUES
-- Existing lesson
('phishing-email-basics', 'Phishing Email Detection Basics', 'Learn to identify common phishing tactics in emails and protect yourself from email-based attacks', 'phishing-email-basics', 'phishing-email-basics.yaml', 'beginner', 15),
-- SQL Injection lesson
('sql-injection-shop', 'SQL Injection Attack - Online Shop Demo', 'Learn how SQL injection vulnerabilities work through a realistic online shop scenario', 'sql-injection-shop', 'sql-injection-shop.yaml', 'intermediate', 20),
-- Browser-in-the-Browser lesson
('browser-in-browser-attack', 'Browser-in-the-Browser Attack', 'Learn to recognize fake browser windows used in phishing attacks', 'browser-in-browser-attack', 'browser-in-browser-attack.yaml', 'advanced', 25),
-- New offensive security lessons
-- Combined XSS lesson (replaces xss-deeplink-demo and script-injection-forum)
('xss-comprehensive', 'Cross-Site Scripting (XSS) - Reflected & Stored Angriffe', 'Lernen Sie, wie XSS-Angriffe durch URL-Manipulation und benutzergenerierte Inhalte funktionieren und wie man sie erkennt', 'xss-comprehensive', 'xss-comprehensive.yaml', 'intermediate', 35),
('social-engineering-password', 'Social Engineering - Passwortsicherheit', 'Lernen Sie, wie persönliche Informationen aus sozialen Medien zu schwachen Passwörtern führen können', 'social-engineering-password', 'social-engineering-password.yaml', 'beginner', 20),
('idor-demo', 'IDOR - Insecure Direct Object Reference', 'Learn how insecure direct object references allow unauthorized access to other users'' data through URL manipulation', 'idor-demo', 'idor-demo.yaml', 'intermediate', 22)
ON CONFLICT (lesson_key) DO NOTHING;
+36
View File
@@ -0,0 +1,36 @@
-- Event Comments and Jackpot Discovery Tables
-- Part of the hidden "Jackpot" Easter egg feature
-- Event comments table (isolated per participant)
CREATE TABLE event_comments (
id SERIAL PRIMARY KEY,
participant_id INTEGER NOT NULL REFERENCES participants(id) ON DELETE CASCADE,
event_id INTEGER NOT NULL REFERENCES events(id) ON DELETE CASCADE,
content TEXT NOT NULL,
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
);
-- Indexes for performance
CREATE INDEX idx_event_comments_participant ON event_comments(participant_id);
CREATE INDEX idx_event_comments_event ON event_comments(event_id);
CREATE INDEX idx_event_comments_composite ON event_comments(participant_id, event_id);
COMMENT ON TABLE event_comments IS 'Participant feedback comments - visible only to poster (isolated per participant)';
-- Jackpot discoveries tracking table
CREATE TABLE jackpot_discoveries (
id SERIAL PRIMARY KEY,
participant_id INTEGER NOT NULL REFERENCES participants(id) ON DELETE CASCADE,
event_id INTEGER NOT NULL REFERENCES events(id) ON DELETE CASCADE,
discovered_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
payload TEXT,
score_before INTEGER,
score_after INTEGER,
UNIQUE(participant_id, event_id)
);
-- Indexes for jackpot discoveries
CREATE INDEX idx_jackpot_discoveries_event ON jackpot_discoveries(event_id);
CREATE INDEX idx_jackpot_discoveries_participant ON jackpot_discoveries(participant_id);
COMMENT ON TABLE jackpot_discoveries IS 'Tracks participants who discovered the SQL injection Easter egg';