INNER CODE UNIT · Python
dashboard
The-Art-of-Hacking/websploit · additional-labs/token-tower/app.py:554
def dashboard():
token = request.cookies.get('auth_token')
if not token:
return redirect('/login')
try:
# VULNERABILITY: Multiple algorithm vulnerabilities
data = verify_token_vulnerable(token)
if data is None:
raise Exception("Token verification failed")
user = data.get('user', 'unknown')
role = data.get('role', 'guest')
user_id = data.get('user_id', 0)
# Determine which flags to show based on role and attack method