Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,18 @@ public void doPost(HttpServletRequest request, HttpServletResponse response)
try {
String accountNumber = request.getParameter("accountNumber");
log.debug("Account Number - " + accountNumber);
Object boundAccount = ses.getAttribute("directObjectBankAccount");
if (boundAccount == null || !boundAccount.toString().equals(accountNumber)) {
log.warn(
levelName
+ " - Rejected balance lookup for account "
+ accountNumber
+ " requested by session bound to "
+ boundAccount
+ ". This is not their account.");
out.write(errors.getString("error.shouldNotBeHere"));
return;
}
String applicationRoot = getServletContext().getRealPath("");
String htmlOutput = new String();
long currentBalance =
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -81,9 +81,22 @@ public void doPost(HttpServletRequest request, HttpServletResponse response)
log.debug("Transfer Amount - " + transferAmountString);
float tranferAmount = Float.parseFloat(transferAmountString);

Object boundAccount = ses.getAttribute("directObjectBankAccount");

// Data Validation
// Positive Transfer Amount?
if (tranferAmount > 0) {
// Sender Account must be the account the session is actually signed in to. Funds may
// only ever be moved out of the account that was authenticated with, never an
// arbitrary account number supplied by the client.
if (boundAccount == null || !boundAccount.toString().equals(senderAccountNumber)) {
log.warn(
levelName
+ " - Rejected transfer attempt out of account "
+ senderAccountNumber
+ " by session bound to "
+ boundAccount
+ ". This is not their account.");
errorMessage = errors.getString("error.shouldNotBeHere");
} else if (tranferAmount > 0) {
// Sender Account Has necessary funds?
long senderFunds =
DirectObjectBankLogin.getAccountBalance(senderAccountNumber, applicationRoot);
Expand Down
Loading