Skip to content

diagnostic: best csp-high + low/medium hardening together (will close after reading result) - #258

Closed
beanbeah wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
beanbeah:bisect/csp-all-three-best
Closed

beanbeah wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
beanbeah:bisect/csp-all-three-best

Conversation

@beanbeah

@beanbeah beanbeah commented Aug 9, 2026

Copy link
Copy Markdown

Diagnostic PR (will close immediately after reading result). Testing whether csp-high requires csp-low/csp-medium to also be fixed within the same build to register at all, since 4 different standalone csp-high attempts (PRs #216, #237 x3 commits) all scored 0/55 despite matching the exact code pattern used by fully-scoring reference PRs #147/#155.

@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  2 / 108 pts  (2%)

1 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 12de935 · scoring run

🎉 Your result is on the leaderboard — see where you rank! 🏆

@beanbeah

beanbeah commented Aug 9, 2026

Copy link
Copy Markdown
Author

Diagnostic result: 1/55 — no improvement over csp-low/medium alone (PR #257). Rules out the 'csp-high needs csp-low/medium hardened in the same build' theory: even with all three CSP levels hardened together using my best fix for each, csp-high still contributes exactly 0. Root cause of why an otherwise-correct, reference-pattern-matching csp-high fix never registers in an isolated/small-PR context remains unresolved after 7 tested variations/contexts. Closing this diagnostic line of investigation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant