OWASP / OWASP/crAPI

Does crAPI's configuration allow it to be used as a Capture-the-flag (CTF) event?

Open
#97 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement hacktoberfest
Dominant language
Java
Stars
1.6k
Forks
645
Avg merge
37m
Merged PRs (30d)
1

Description

Is your feature request related to a problem? Please describe.
Curious to know if crAPI's configuration allows it to be used as Capture-the-flag (CTF) event

Describe the solution you'd like
A way to configure crAPI to return (e.g in the HTTP response body) a user configured custom flag when particular challenges are solved

Describe alternatives if any you've considered
None at the moment..

Additional context
Add any other context/screenshots/rough sketchs about the feature request here.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue does not name files, tests, or entry points. First map how crAPI configuration and solved challenges are handled, then define how a user-configured flag should appear in the HTTP response. Done means a documented configuration path and a verified custom flag for each targeted challenge.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.