Uploaded by Kate Chumachenko

crAPI note

advertisement
{
LOGIN:"api/auth/login"
GET_USER:"api/v2/user/dashboard"
SIGNUP:"api/auth/signup"
RESET_PASSWORD:"api/v2/user/reset-password"
FORGOT_PASSWORD:"api/auth/forget-password"
VERIFY_OTP:"api/auth/v3/check-otp"
LOGIN_TOKEN:"api/auth/v4.0/user/login-with-token"
ADD_VEHICLE:"api/v2/vehicle/add_vehicle"
GET_VEHICLES:"api/v2/vehicle/vehicles"
RESEND_MAIL:"api/v2/vehicle/resend_email"
CHANGE_EMAIL:"api/v2/user/change-email"
VERIFY_TOKEN:"api/v2/user/verify-email-token"
UPLOAD_PROFILE_PIC:"api/v2/user/pictures"
UPLOAD_VIDEO:"api/v2/user/videos"
CHANGE_VIDEO_NAME:"api/v2/user/videos/<videoId>"
REFRESH_LOCATION:"api/v2/vehicle/<carId>/location"
CONVERT_VIDEO:"api/v2/user/videos/convert_video"
CONTACT_MECHANIC:"api/merchant/contact_mechanic"
RECEIVE_REPORT:"api/mechanic/receive_report"
GET_MECHANICS:"api/mechanic"
GET_PRODUCTS:"api/shop/products"
GET_SERVICES:"api/mechanic/service_requests"
BUY_PRODUCT:"api/shop/orders"
GET_ORDERS:"api/shop/orders/all"
GET_ORDER_BY_ID:"api/shop/orders/<orderId>"
RETURN_ORDER:"api/shop/orders/return_order"
APPLY_COUPON:"api/shop/apply_coupon"
ADD_NEW_POST:"api/v2/community/posts"
GET_POSTS:"api/v2/community/posts/recent"
GET_POST_BY_ID:"api/v2/community/posts/<postId>"
ADD_COMMENT:"api/v2/community/posts/<postId>/comment"
VALIDATE_COUPON:"api/v2/coupon/validate-coupon"
}
Authorization: Bearer eyJhbGciOiJSUzI1NiJ9eyJzdWIiOiJwaXBpQGdtYWlsLmNvbSIsInJvbGUiOiJhZG1pbiIsImlhdCI6MTY5NDExMDkwNSwiZXhwIjoxNjk0NzE1NzA1fQ==.AILAp2S1DjGdNiN4NxFki6owXhsnBapnFaeI6yAszrRiIv5UOQASuu8Bc7AVLwsbzp8aE24100UHBoLlGbeJUEUZFMORqc5HV5exKE3oCIIJoxSj6T25LqjbwlFUT4xtJgmU7EkVKnSMP5y2GayonTwhjFIjd7VCJZL8GUlv_aQ3EwDvBqALHLbN234nOZfezPG_BkOmsdcSWaaQqwJZhiLBOdZ6h5I8nCjLid3mb6p2PxRDpq_sb3kWZRJ5I_2mRbbh44dK4-qAk2Amt28JWVjKtEwaeqiHi6_gUowYEr2ZfEB9Qbi_RQAsyDu3r2sMgNvmN45xqh8DMSFCU3Lklg
Insecure Configuration & Data Exposure: PATH: /community/api/v2/community/posts/recent (localhost:8888/forum/)
{"id":"hS8TrbqU85azZV3mXvqXPo","title":"gg","content":"GG","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T17:14:42.83025998Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T17:14:42.830263891Z"}
{"id":"7s8ZfpGDmD5KNhUNq8RV7P","title":"asdfasdfasdfasdfasdfasdfasdfasdfasdf","content":"asdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdfasfasdfasdfasdf","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:41:28.698816193Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:41:28.698819895Z"}
{"id":"FScKiYUGGbueCiqh5NuAmh","title":"a","content":"a","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:41:56.030567365Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:41:56.030570787Z"}
{"id":"fQS8X9B4hmPtdeTo9hcj2Y","title":"Hello","content":"How are you doing guys?","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:42:19.100412868Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:42:19.100416639Z"}
{"id":"egKJBrnKePPDnu5VivxLnC","title":"Hello","content":"hello. My name is Hello.\nIt is my new post. I\u0026amp;#39;m just learning how to use your site. I like it already.","author":{"nickname":"Full Name","email":"email@email.com","vehicleid":"","profile_pic_url":"","created_at":"2023-09-11T18:43:04.911158138Z"},"comments":[],"authorid":13,"CreatedAt":"2023-09-11T18:43:04.911161421Z"}
{"userReducer":"{\"fetchingData\":false,\"isLoggedIn\":true,\"accessToken\":\"eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJwaXBpQGdtYWlsLmNvbSIsInJvbGUiOiJ1c2VyIiwiaWF0IjoxNjk0MTEwOTA1LCJleHAiOjE2OTQ3MTU3MDV9.AILAp2S1DjGdNiN4NxFki6owXhsnBapnFaeI6yAszrRiIv5UOQASuu8Bc7AVLwsbzp8aE24100UHBoLlGbeJUEUZFMORqc5HV5exKE3oCIIJoxSj6T25LqjbwlFUT4xtJgmU7EkVKnSMP5y2GayonTwhjFIjd7VCJZL8GUlv_aQ3EwDvBqALHLbN234nOZfezPG_BkOmsdcSWaaQqwJZhiLBOdZ6h5I8nCjLid3mb6p2PxRDpq_sb3kWZRJ5I_2mRbbh44dK4-qAk2Amt28JWVjKtEwaeqiHi6_gUowYEr2ZfEB9Qbi_RQAsyDu3r2sMgNvmN45xqh8DMSFCU3Lklg\",\"id\":11,\"name\":\"titi\",\"email\":\"pipi@gmail.com\",\"number\":\"29283929\",\"role\":\"ROLE_USER\",\"userData\":{\"available_credit\":90}}","profileReducer":"{\"videoId\":0,\"videoData\":null,\"videoName\":null,\"profilePicData\":null}","_persist":"{\"version\":-1,\"rehydrated\":true}"}
Password1!
emails:
hello@gmail.com
a@a.com
email@email.com
pipi@gmail.com
asdfasdf#zsa@asfaef.com
test@example.com
admin@example.com
UserA@email.com
admin@admin.com
admin@gmail.com
admin2@admin.com
admin3@admin.com
adam007@example.com
persist:reducers
{"userReducer":"{\"fetchingData\":false,\"isLoggedIn\":true,\"accessToken\":\"eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJhZGFtMDA3QGV4YW1wbGUuY29tIiwicm9sZSI6InByZWRlZmluZWQiLCJpYXQiOjE2OTQ4NjQ5MjIsImV4cCI6MTY5NTQ2OTcyMn0.V2ZsrFgb_rIOBkR0KCodPUyI-YdkShRXsUCLdLKI5RDVpM9vRC3B7lYaJ52m8iz3VerIh0gz-wHo_EOR45U05kaJyGcQit12OJmvsLcZZmH5GrXdrUThWNb2TeScH3jX_sgvi-bFlCnVHxNeCiNPNOuiXLtVO-BoKEUKLzoc2TL830MaRakRubbxuJq3M_7sOGrgmUH7JbMmpAeErKiQiNHT9J-gFv4SDjVHO6yqXqEsJNkaGZgeY5nRT9vT0OnheJsdm7xPn3JUom7raA52T6MBlAinXawcSnO0_jPOCAZ4Iu5c_644Wc2tuEiceyh5EZ7Y7ULSPzDQPUqhCjMajg\",\"id\":1,\"name\":\"Adam\",\"email\":\"adam007@example.com\",\"number\":\"9876895423\",\"role\":\"ROLE_PREDEFINE\"}","profileReducer":"{}","_persist":"{\"version\":-1,\"rehydrated\":true}"}
Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJhZGFtMDA3QGV4YW1wbGUuY29tIiwicm9sZSI6InByZWRlZmluZWQiLCJpYXQiOjE2OTQ4NjUxOTIsImV4cCI6MTY5NTQ2OTk5Mn0.jKlZ_ode4p4wCyVtVtYgYbCxDf_UZnNFoU7pF23T9-FiffrRHbaGvqPL5AynMDrT4EDVpO-L_ISQSCfi1GipooiCNZ4qjbdLUbkJQUIHhx2Yf_jGtN5kKA4tWwAhXcP5ITlzghELs9uv_QJQoTr_J7fqkAnb2UVHkCORtthHMdeu4mNj03XdY4a6P9JBlzNUFpTzUk0DRT7LzLh7J8BX12ji5-rjR8RY0a4ybxrJ3fj2a3GW4n1y-bA6VdDd1G8ZqAyYlWt4e1BiW-gCwMs53ftlwhK9xxxBzIu0hSIeI3Mqzi6kjoBb2sxIfmMr2rUfEb4ug8jq0MI8zmNDhE04XA
jhon@example.com
Authorization: Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJqaG9uQGV4YW1wbGUuY29tIiwicm9sZSI6Im1lY2hhbmljIiwiaWF0IjoxNjk0ODY0NTA0LCJleHAiOjE2OTU0NjkzMDR9.BS4ge4Z8H7zkx127f551LsFSInUBw1herN2JkPY0KK_DlbMYW9SbegP6v4uri8jChSnC6oXbqN7wMb7Xe6KHfunyLXsezbdlJWlipZqekPFIBVQV0wUbmj_Qg2LjSvpI6dC-HeUCMjJMAZQx2X7tTQUvUTIFradoGdU_S00yzis6s7L9dTBzPr2tgaBgeH_rVW5zuihEC0ROiwisTEj1oPTLkdPzNTSJzBWECJdf5WQGZ__e6m9tXSYU8ySK_RWS6z4iP071mRDTdf_RAdVAydiD9WBK4iy9s6Jss8-pLYmazQlkI2tOwrFsYkvm_Or1MtHP_SGEKIq-kPn9bCLe_g
jhon - mechanic - vehicle's vin disclosure at workshop/api/mechanic/mechanic_report?report_id=8 with the jhon's authorization token.
f02fd7c8-425f-4856-9fc0-d4cf0f4a456d
Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJVc2VyQUBlbWFpbC5jb20iLCJyb2xlIjoidXNlciIsImlhdCI6MTY5NDg1Mzk2NSwiZXhwIjoxNjk1NDU4NzY1fQ.a3wdv41DxdYkGlh-wqcz5uujWjsX9UhEdqQr2XB4sXVzMRpYNLStWYfI2LExIRRDiVEAq91lqRSRyGHndVbkHtN-eHSDfHVpom7th6tv5dC_fTe_rn5QJU3sSDgioNDvly_LgDSFkZWjY589Y79jw9GVSmEG-DkgG7j-8OKjzr3Z1i64Uu4LiFjxklrPNlQOKcLgY2R-4vOLTUoTlbOOdKzVIz_0GGVcXJYT7o4RsZkOk00KSRXGv83_EHbktC6qSD1-Cl-3MsmQgQBtBeRQYgvalj0-Txmmea9JyZ2Z96GdO02ilE8eLUjnncH2aPX3PcoZMJdMuVkT2pYlpvI_Dw
UserB@email.com
de2efd6c-ef46-4342-b4c1-03909155b736
Bearer eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJVc2VyQkBlbWFpbC5jb20iLCJyb2xlIjoidXNlciIsImlhdCI6MTY5NDg1NDA3MCwiZXhwIjoxNjk1NDU4ODcwfQ.M62B4QZjgVheSC_MDXSt4tqu1YLIZSXWdUmSv-xPQpSjif24Btd-JEAvs693xtFhlWASUbrcO6NtqZiFFMEeJF-y57YjbBcKA7MGcfv7X2ow_X8UeSh6wRBafZlZ5b3ZojdwTb5NlS4aPN8duk4-fuWxO6BggwJe6fJOG362tNDxviYMkUQ1y5rMCBz5aG2cmepVWcjASIw1p1k7I44Kyu3lEdQsrrEhM8-c8UyIb6ZQdpUHS8HVUp7YQzrCtkLMIRhPJ99NVcNtTX6eeY_ESYO652jymwbP5haHb41VdEAqb_EZ9cfm5xnjBBErHplizFDh61Rz6XKA6bgtLMJ61w
{ "keys": [ { "kty": "RSA", "e": "AQAB", "use": "sig", "kid": "MKMZkDenUfuDF2byYowDj7tW5Ox6XG4Y1THTEGScRg8", "alg": "RS256", "n": "sZKrGYja9S7BkO-waOcupoGY6BQjixJkg1Uitt278NbiCSnBRw5_cmfuWFFFPgRxabBZBJwJAujnQrlgTLXnRRItM9SRO884cEXn-s4Uc8qwk6pev63qb8no6aCVY0dFpthEGtOP-3KIJ2kx2i5HNzm8d7fG3ZswZrttDVbSSTy8UjPTOr4xVw1Yyh_GzGK9i_RYBWHftDsVfKrHcgGn1F_T6W0cgcnh4KFmbyOQ7dUy8Uc6Gu8JHeHJVt2vGcn50EDtUy2YN-UnZPjCSC7vYOfd5teUR_Bf4jg8GN6UnLbr_Et8HUnz9RFBLkPIf0NiY6iRjp9ooSDkml2OGql3ww" } ] }
http://localhost:8888/workshop/admin/login/?next=/workshop/admin/ http://localhost:8888/workshop/admin
Download