diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml old mode 100755 new mode 100644 diff --git a/.obsidian/app.json b/.obsidian/app.json old mode 100755 new mode 100644 diff --git a/.obsidian/appearance.json b/.obsidian/appearance.json old mode 100755 new mode 100644 diff --git a/.obsidian/community-plugins.json b/.obsidian/community-plugins.json old mode 100755 new mode 100644 diff --git a/.obsidian/core-plugins.json b/.obsidian/core-plugins.json old mode 100755 new mode 100644 diff --git a/.obsidian/daily-notes.json b/.obsidian/daily-notes.json old mode 100755 new mode 100644 diff --git a/.obsidian/graph.json b/.obsidian/graph.json old mode 100755 new mode 100644 diff --git a/.obsidian/hotkeys.json b/.obsidian/hotkeys.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/calendar/data.json b/.obsidian/plugins/calendar/data.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/calendar/main.js b/.obsidian/plugins/calendar/main.js old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/calendar/manifest.json b/.obsidian/plugins/calendar/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/copilot/data.json b/.obsidian/plugins/copilot/data.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/copilot/main.js b/.obsidian/plugins/copilot/main.js old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/copilot/manifest.json b/.obsidian/plugins/copilot/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/copilot/styles.css b/.obsidian/plugins/copilot/styles.css old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/dataview/main.js b/.obsidian/plugins/dataview/main.js old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/dataview/manifest.json b/.obsidian/plugins/dataview/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/dataview/styles.css b/.obsidian/plugins/dataview/styles.css old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/obsidian-annotator/main.js b/.obsidian/plugins/obsidian-annotator/main.js old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/obsidian-annotator/manifest.json b/.obsidian/plugins/obsidian-annotator/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/obsidian-excalidraw-plugin/data.json b/.obsidian/plugins/obsidian-excalidraw-plugin/data.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/obsidian-excalidraw-plugin/main.js b/.obsidian/plugins/obsidian-excalidraw-plugin/main.js old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/obsidian-excalidraw-plugin/manifest.json b/.obsidian/plugins/obsidian-excalidraw-plugin/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/obsidian-excalidraw-plugin/styles.css b/.obsidian/plugins/obsidian-excalidraw-plugin/styles.css old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/pdf-plus/data.json b/.obsidian/plugins/pdf-plus/data.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/pdf-plus/main.js b/.obsidian/plugins/pdf-plus/main.js old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/pdf-plus/manifest.json b/.obsidian/plugins/pdf-plus/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/plugins/pdf-plus/styles.css b/.obsidian/plugins/pdf-plus/styles.css old mode 100755 new mode 100644 diff --git a/.obsidian/snippets/styles.css b/.obsidian/snippets/styles.css old mode 100755 new mode 100644 diff --git a/.obsidian/templates.json b/.obsidian/templates.json old mode 100755 new mode 100644 diff --git a/.obsidian/themes/Obsidian gruvbox/manifest.json b/.obsidian/themes/Obsidian gruvbox/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/themes/Obsidian gruvbox/theme.css b/.obsidian/themes/Obsidian gruvbox/theme.css old mode 100755 new mode 100644 diff --git a/.obsidian/themes/Tokyo Night/manifest.json b/.obsidian/themes/Tokyo Night/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/themes/Tokyo Night/theme.css b/.obsidian/themes/Tokyo Night/theme.css old mode 100755 new mode 100644 diff --git a/.obsidian/themes/Wasp/manifest.json b/.obsidian/themes/Wasp/manifest.json old mode 100755 new mode 100644 diff --git a/.obsidian/themes/Wasp/theme.css b/.obsidian/themes/Wasp/theme.css old mode 100755 new mode 100644 diff --git a/.obsidian/types.json b/.obsidian/types.json old mode 100755 new mode 100644 diff --git a/.obsidian/workspace.json b/.obsidian/workspace.json old mode 100755 new mode 100644 index f2e73ab..1c9b4d2 --- a/.obsidian/workspace.json +++ b/.obsidian/workspace.json @@ -4,24 +4,39 @@ "type": "split", "children": [ { - "id": "6237ac476356142f", + "id": "8c2f58580563ad8b", "type": "tabs", "children": [ { - "id": "a343377e7b3c097f", + "id": "c8d96bab4185fef6", "type": "leaf", "state": { "type": "markdown", "state": { - "file": "Dailies/2026-05-29.md", + "file": "Career/Concepts.md", "mode": "source", "source": false }, "icon": "lucide-file", - "title": "2026-05-29" + "title": "Concepts" + } + }, + { + "id": "ecbbece3fdbe4ecf", + "type": "leaf", + "state": { + "type": "markdown", + "state": { + "file": "Technical/Android app.md", + "mode": "source", + "source": false + }, + "icon": "lucide-file", + "title": "Android app" } } - ] + ], + "currentTab": 1 } ], "direction": "vertical" @@ -53,7 +68,7 @@ "state": { "type": "search", "state": { - "query": "sql joins", + "query": "regex", "matchingCase": false, "explainSearch": false, "collapseAll": false, @@ -84,8 +99,7 @@ "title": "Calendar" } } - ], - "currentTab": 3 + ] } ], "direction": "horizontal", @@ -209,16 +223,28 @@ "templates:Insert template": false } }, - "active": "a343377e7b3c097f", + "active": "ecbbece3fdbe4ecf", "lastOpenFiles": [ - "Dailies/2026-06-01.md", - "Dailies/2026-06-02.md", + "Technical/Emacs/Emacs Config.md", + "Technical/Android app.md", + "Deen/Poetry.md", + "Dailies/2026-06-09.md", + "Dailies/2026-06-08.md", + "Career/Database - SQL/Using Joins, Constraints, Normalization, and Subqueries.md", + "Dailies/2026-06-05.md", + "Deen/Naats.md", + "Career/Microlise/Session Stored XSS PENTEST.md", + "Career/Concepts.md", "Career/Regex.md", "Dailies/2026-06-04.md", - "Career/Microlise/Session Stored XSS PENTEST.md", + "Inbox/Testing -.md", + "Inbox/Testing -.md~", + "Inbox", + "Career/Microlise/Session Stored XSS PENTEST.html", + "Dailies/2026-05-29.md", + "Dailies/2026-06-01.md", + "Dailies/2026-06-02.md", "Career/Security/Cross Site Scripting (XSS).md", - "Career/Concepts.md", - "Career/Database - SQL/Using Joins, Constraints, Normalization, and Subqueries.md", "copilot/memory/Recent Conversations.md", "copilot/copilot-conversations/Hello@20260603_222655.md", "copilot/memory", @@ -235,19 +261,7 @@ "Index.md", "Non Technical/z resources.md", "pdfs/_articles/The New Definition of Software Engineering in the Age of AI Is Already Here _ by Deep concept _ Let’s Code Future _ May, 2026 _ Medium.pdf", - "Articles/Redefining the Software Engineering Profession for AI.md", "pdfs/_articles/Opinion.pdf", - "Articles/I thought I knew system design.md", - "Articles/Every Senior Engineer has read these books.md", - "Books/Books MOC.md", - "Articles/Reason some people are likable.md", - "pdfs/_articles/reason-some-people-are-likable.pdf", - "Articles/Software Quality.md", - "pdfs/_articles/software-quality.pdf", - "Articles/Effects of insufficient sleep on circadian rhythmicity.md", - "Articles/Effect of Tiktok on teens.md", - "Career/Microlise/Seb Search Improvements.md", - "Career/Devops", "Career/Security/Attachments/Pasted image 20260603202316.png", "Career/Security/Attachments/Pasted image 20260603202301.png", "Books/Attachments/Pasted image 20260603145548.png", diff --git a/Articles/20 Software Engineering Laws.md b/Articles/20 Software Engineering Laws.md old mode 100755 new mode 100644 diff --git a/Articles/Articles MOC.md b/Articles/Articles MOC.md old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-01.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-01.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-02.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-02.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-03.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-03.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-04.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-04.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-05.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-05.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-06.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium-06.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium.png b/Articles/Attachments/2026-05-22-every-senior-engineer-i-respect-has-read-these-books-have-you-by-the-latency-gambler-mar-2026-medium.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-senior-books.png b/Articles/Attachments/2026-05-22-senior-books.png old mode 100755 new mode 100644 diff --git a/Articles/Attachments/2026-05-22-software-quality.png b/Articles/Attachments/2026-05-22-software-quality.png old mode 100755 new mode 100644 diff --git a/Articles/Effect of Tiktok on teens.md b/Articles/Effect of Tiktok on teens.md old mode 100755 new mode 100644 diff --git a/Articles/Effects of insufficient sleep on circadian rhythmicity.md b/Articles/Effects of insufficient sleep on circadian rhythmicity.md old mode 100755 new mode 100644 diff --git a/Articles/Every Senior Engineer has read these books.md b/Articles/Every Senior Engineer has read these books.md old mode 100755 new mode 100644 diff --git a/Articles/I thought I knew system design.md b/Articles/I thought I knew system design.md old mode 100755 new mode 100644 diff --git a/Articles/Reason some people are likable.md b/Articles/Reason some people are likable.md old mode 100755 new mode 100644 diff --git a/Articles/Redefining the Software Engineering Profession for AI.md b/Articles/Redefining the Software Engineering Profession for AI.md old mode 100755 new mode 100644 diff --git a/Articles/Software Quality.md b/Articles/Software Quality.md old mode 100755 new mode 100644 diff --git a/Articles/Substack Articles.md b/Articles/Substack Articles.md old mode 100755 new mode 100644 diff --git a/Books/Art of Computer Programming.md b/Books/Art of Computer Programming.md old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603143442.png b/Books/Attachments/Pasted image 20260603143442.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603143542.png b/Books/Attachments/Pasted image 20260603143542.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603143606.png b/Books/Attachments/Pasted image 20260603143606.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603144043.png b/Books/Attachments/Pasted image 20260603144043.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603144325.png b/Books/Attachments/Pasted image 20260603144325.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603144656.png b/Books/Attachments/Pasted image 20260603144656.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603145047.png b/Books/Attachments/Pasted image 20260603145047.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603145055.png b/Books/Attachments/Pasted image 20260603145055.png old mode 100755 new mode 100644 diff --git a/Books/Attachments/Pasted image 20260603145548.png b/Books/Attachments/Pasted image 20260603145548.png old mode 100755 new mode 100644 diff --git a/Books/Book Recs.md b/Books/Book Recs.md old mode 100755 new mode 100644 diff --git a/Books/Books Calibre.md b/Books/Books Calibre.md old mode 100755 new mode 100644 index 7ad2e9d..d8b5ffd --- a/Books/Books Calibre.md +++ b/Books/Books Calibre.md @@ -3,7 +3,7 @@ tags: - books - calibre - index -generated_at: 2026-06-04T00:00:02.018640 +generated_at: 2026-06-10T00:00:01.241276 --- # Career diff --git a/Books/Books MOC.md b/Books/Books MOC.md old mode 100755 new mode 100644 diff --git a/Books/Clean Code.md b/Books/Clean Code.md old mode 100755 new mode 100644 diff --git a/Books/Dose Effect.md b/Books/Dose Effect.md old mode 100755 new mode 100644 diff --git a/Books/Ikigai.md b/Books/Ikigai.md old mode 100755 new mode 100644 diff --git a/Books/Notes/Career Capital.md b/Books/Notes/Career Capital.md old mode 100755 new mode 100644 diff --git a/Books/Notes/Deliberate practice.md b/Books/Notes/Deliberate practice.md old mode 100755 new mode 100644 diff --git a/Books/Notes/Neuroplasticity.md b/Books/Notes/Neuroplasticity.md old mode 100755 new mode 100644 diff --git a/Books/Notes/Stanford marshmallow experiment.md b/Books/Notes/Stanford marshmallow experiment.md old mode 100755 new mode 100644 diff --git a/Books/So good they cant ignore you.md b/Books/So good they cant ignore you.md old mode 100755 new mode 100644 diff --git a/Books/The Book of Ichigo Ichie.md b/Books/The Book of Ichigo Ichie.md old mode 100755 new mode 100644 diff --git a/Books/The Clean Coder.md b/Books/The Clean Coder.md old mode 100755 new mode 100644 diff --git a/Books/The Science of Self-Discipline.md b/Books/The Science of Self-Discipline.md old mode 100755 new mode 100644 diff --git a/Career/AI/AI - Codex.md b/Career/AI/AI - Codex.md old mode 100755 new mode 100644 diff --git a/Career/AI/AI Moc.md b/Career/AI/AI Moc.md old mode 100755 new mode 100644 diff --git a/Career/AI/Data camp AI training.md b/Career/AI/Data camp AI training.md old mode 100755 new mode 100644 diff --git a/Career/API/API Architecture.md b/Career/API/API Architecture.md old mode 100755 new mode 100644 diff --git a/Career/API/ASP.NET Core Web API Fundamental Notes.md b/Career/API/ASP.NET Core Web API Fundamental Notes.md old mode 100755 new mode 100644 diff --git a/Career/API/Restful API.md b/Career/API/Restful API.md old mode 100755 new mode 100644 diff --git a/Career/Attachments/APIOps.png b/Career/Attachments/APIOps.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/Big-O-Notation-3130482830.png b/Career/Attachments/Big-O-Notation-3130482830.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/Screenshot 2026-01-14 154800.png b/Career/Attachments/Screenshot 2026-01-14 154800.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/adapter-pattern-2.png b/Career/Attachments/adapter-pattern-2.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/adapter-pattern.png b/Career/Attachments/adapter-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/command-pattern.png b/Career/Attachments/command-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/composite-pattern.png b/Career/Attachments/composite-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/decorator-pattern.png b/Career/Attachments/decorator-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/decorator-problem.png b/Career/Attachments/decorator-problem.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/facade-pattern.png b/Career/Attachments/facade-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/factory-pattern.png b/Career/Attachments/factory-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/iterator-pattern.png b/Career/Attachments/iterator-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/observer-pattern.png b/Career/Attachments/observer-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/proxy-pattern.png b/Career/Attachments/proxy-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/singleton-pattern.png b/Career/Attachments/singleton-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/state-pattern.png b/Career/Attachments/state-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/structure-pattern.png b/Career/Attachments/structure-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Attachments/template-method-pattern.png b/Career/Attachments/template-method-pattern.png old mode 100755 new mode 100644 diff --git a/Career/Big (O) - Time and Space Complexity.md b/Career/Big (O) - Time and Space Complexity.md old mode 100755 new mode 100644 diff --git a/Career/Bowling Kata.md b/Career/Bowling Kata.md old mode 100755 new mode 100644 diff --git a/Career/Career MOC.md b/Career/Career MOC.md old mode 100755 new mode 100644 diff --git a/Career/Concepts.md b/Career/Concepts.md old mode 100755 new mode 100644 index 50ce122..c583c65 --- a/Career/Concepts.md +++ b/Career/Concepts.md @@ -57,10 +57,8 @@ Some core programming concepts that are essential for software development. The # Misc - [[Windows Services]] - - [[DLL's]] - -- +- [[Regex]] # Security: - [[OWASP Top 10]] @@ -132,6 +130,7 @@ Some core programming concepts that are essential for software development. The - [ ] Turing machines - [ ] computability theory - [x] MVPs and MVTs + - [x] Regex # Data view query diff --git a/Career/DLL's.md b/Career/DLL's.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Airflow Dags.md b/Career/Database - SQL/Airflow Dags.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Airflow Tasks.md b/Career/Database - SQL/Airflow Tasks.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Airflow.md b/Career/Database - SQL/Airflow.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Attachments/Pasted image 20260603221345.png b/Career/Database - SQL/Attachments/Pasted image 20260603221345.png old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Database MOC.md b/Career/Database - SQL/Database MOC.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Database Permissions, Roles, and Accounts.md b/Career/Database - SQL/Database Permissions, Roles, and Accounts.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Postgres.md b/Career/Database - SQL/Postgres.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/SQL Joins.md b/Career/Database - SQL/SQL Joins.md old mode 100755 new mode 100644 diff --git a/Career/Database - SQL/Using Joins, Constraints, Normalization, and Subqueries.md b/Career/Database - SQL/Using Joins, Constraints, Normalization, and Subqueries.md old mode 100755 new mode 100644 index e926ce4..3fe42d4 --- a/Career/Database - SQL/Using Joins, Constraints, Normalization, and Subqueries.md +++ b/Career/Database - SQL/Using Joins, Constraints, Normalization, and Subqueries.md @@ -265,5 +265,840 @@ genre | avg_cost Family | 2000000 ``` +# Constraints + +## Example Table (Promotions) + +``` +CREATE TABLE Promotions ( + id INT PRIMARY KEY, + name VARCHAR(100) NOT NULL, + category VARCHAR(50) NOT NULL, + CONSTRAINT unique_name_category + UNIQUE (name, category) +); +``` + +## Purpose of Constraints + +- Prevent **invalid or unwanted data** +- Enforce **rules on table columns** +- Improve **data integrity** + +## NOT NULL + +- Prevents a column from storing `NULL` values +- Use when a value is required + +`name VARCHAR(100) NOT NULL` + +## UNIQUE + +- Ensures all values in a column are **distinct** +- Prevents duplicate entries + +`name VARCHAR(100) UNIQUE` + +### Composite UNIQUE + +- Enforces uniqueness across multiple columns + +`UNIQUE (name, category)` + +- Same name allowed if category differs +- Same category allowed if name differs +- Duplicate combinations are not allowed + +## Multiple Constraints on a Column + +- You can combine constraints: + +`name VARCHAR(100) NOT NULL UNIQUE` + +## Named Constraints + +- Assign custom names for easier maintenance + +`CONSTRAINT unique_name UNIQUE (name)` + +## Column vs Table Constraints + +- Column constraint: defined inline +- Table constraint: defined separately + +Both work the same, except: + +- `NOT NULL` must be defined at the column level + +## PRIMARY KEY + +- Uniquely identifies each row +- Automatically enforces: + - NOT NULL + - UNIQUE + +`id INT PRIMARY KEY` + +### Key Rules + +- Only one primary key per table +- Can consist of one or multiple columns + +## PRIMARY KEY vs UNIQUE + NOT NULL + +- Both enforce uniqueness and no nulls +- Difference: + - PRIMARY KEY: only one per table + - UNIQUE + NOT NULL: can use multiple columns + +# Value Constraints (Foreign Key & CHECK) + +## Example Tables (Movies + Promotions) + + +``` +CREATE TABLE Movies ( + id INT PRIMARY KEY, + title VARCHAR(100) NOT NULL, + duration INT CHECK (duration > 0) +); + +CREATE TABLE Promotions ( + id INT PRIMARY KEY, + name VARCHAR(100) NOT NULL, + category VARCHAR(50) NOT NULL, + movie_id INT, + CONSTRAINT fk_movie + FOREIGN KEY (movie_id) + REFERENCES Movies(id), + CONSTRAINT unique_name_category + UNIQUE (name, category) +); +``` + +## Foreign Key (FK) + +### Definition + +- A **foreign key** is a column in one table that references a **primary key in another table** +- Used to **link tables** and avoid duplicating data + +`movie_id INT REFERENCES movies(id)` + +This is the same as: + +`movie_id INT REFERENCES movies` +## Naming Convention + +- Format: `referencedTable_singular + _id` + +Examples: + +- `movie_id` → references Movies(id) +- `user_id` → references Users(id) + +## Why Use Foreign Keys + +- Prevents **invalid references** +- Ensures **data integrity** +- Avoids **duplicating data across tables** + +## Behaviour Without FK + +- You can insert invalid data: + +`movie_id = 999 -- even if it doesn't exist` + +- Creates **bad data** + +## Behaviour With FK + +- Database **blocks invalid inserts** + +`INSERT INTO Promotions (id, name, category, movie_id)` +`VALUES (1, 'Half Off', 'Discount', 999); -- fails` + +- Error: violates foreign key constraint + +## Table Creation Order Rule + +- The referenced table **must be created first** + +`CREATE TABLE Movies (...)` + +`CREATE TABLE Promotions (... REFERENCES Movies)` +## Table Constraint Version + +``` +FOREIGN KEY (movie_id) REFERENCES movies +``` + +## Orphan Records + +### Definition + +- A row that references data that **no longer exists** + +Example: + +- Movie deleted +- Promotion still points to that movie_id + +## How FK Prevents Orphans + +- Prevents deleting parent rows if children exist + +`DELETE FROM Movies WHERE id = 6; -- fails if Promotions reference it` + +- You must: + 1. Delete child rows first + 2. Then delete parent + +## Dropping Tables + +- Cannot drop a table if another table depends on it + +`DROP TABLE Movies; -- fails if Promotions references it` + +- Must drop dependent tables first + +## CHECK Constraint + +### Definition + +- Validates column values using a condition + +`salary int CHECK (salary > 500)` + +## Purpose of CHECK + +- Prevent logically invalid data + +Example: +- Duration cannot be negative + +## Behaviour + +``` +INSERT INTO Movies (id, title, duration) +VALUES (1, 'Test Movie', -10); -- fails +``` + +## Example Inserts + +### Valid Movie + +``` +INSERT INTO Movies (id, title, duration) +VALUES (1, 'Gone With the Wind', 240); +``` + +### Valid Promotion + +``` +INSERT INTO Promotions (id, name, category, movie_id) +VALUES (1, 'Matinee', 'Discount', 1); +``` + +### Fails (invalid foreign key) + +``` +INSERT INTO Promotions (id, name, category, movie_id) +VALUES (2, 'Half Off', 'Discount', 999); +``` + +### Fails (negative duration) + +``` +INSERT INTO Movies (id, title, duration) +VALUES (2, 'Bad Movie', -10); +``` + +# SQL Relationships & Normalization (Level 3 Notes) + +## Overview + +- Focus: **Database relationships** and **normalization** to improve data integrity and flexibility. +- Example context: A **Movies application** where each movie can have **multiple genres**. + +## Problem with Current Design + +- Storing multiple genres in one column (e.g., `"Adventure, Fantasy"`) causes issues: + - Hard to query (e.g., finding all _Adventure_ movies). + - Difficult to update individual values. + - Violates normalization rules. + +### Example Issue + +`SELECT * FROM Movies WHERE genre = 'Adventure';` + +- Returns movies with only `"Adventure"`, but **misses movies** like `"Adventure, Fantasy"`. + +## Normalization Basics + +### First Normal Form (1NF) + +- Rule: **No repeating groups in a column**. +- Each field should contain a **single value (atomic)**. + +#### Fix + +Split rows so each genre is separate: + +|title|genre|duration| +|---|---|---| +|Peter Pan|Adventure|120| +|Peter Pan|Fantasy|120| + +- Eliminates multi-value columns. +- **Still problematic**: duplicate movie data. + +### Second Normal Form (2NF) + +- Rule: **No redundancy (no repeated unnecessary data)**. +- Each piece of information should be stored **once**. + +#### Problem in 1NF Table + +- Movie details (e.g., duration) are duplicated across rows. + +## Solution: Table Decomposition + +### Step 1: Create a Movies Table + +- Store unique movies only. + +|id|title|duration| +|---|---|---| +|1|Don Juan|110| +|2|Peter Pan|120| + +### Step 2: Create a Genres Table + +- Store each genre once. + +|id|name| +|---|---| +|1|Romance| +|2|Adventure| +|3|Fantasy| + +### Step 3: Create a Join Table (Many-to-Many) + +- Name convention: `movies_genres` +- Purpose: Link movies to genres. + +|movie_id|genre_id| +|---|---| +|1|1| +|2|2| +|2|3| + +- `movie_id` → references `Movies.id` +- `genre_id` → references `Genres.id` +- Both are **foreign keys** + +## Benefits of This Design + +- No duplication (meets 2NF). +- Easy updates: + - Change movie duration in one place. + - Add/remove genres without affecting other data. +- Scalable for complex relationships. + +## Querying the Data + +### Step-by-step (manual approach) + +1. Get movie ID: + +`SELECT id FROM Movies WHERE title = 'Peter Pan';` + +2. Get associated genre IDs: + +`SELECT genre_id FROM movies_genres WHERE movie_id = 2;` + +3. Get genre names: + +`SELECT name FROM Genres WHERE id IN (2, 3);` + +### Simplified Query Using `IN` + +`SELECT name FROM Genres WHERE id IN (2, 3);` + +## Example Operation + +### Add a new genre to a movie + +``` +Add "Fantasy" to "Robin Hood": +INSERT INTO movies_genres (movie_id, genre_id) +VALUES (4, 3); +``` + +## Key Takeaways + +- Avoid storing multiple values in a single column. +- Use **normalization** to: + - Eliminate redundancy + - Improve data consistency +- Use **join tables** for many-to-many relationships. +- Trade-off: Queries become slightly more complex, but data becomes more robust and flexible. + +# Database Relationships + +## Overview + +There are three fundamental relationship types between tables: + +1. **One-to-One (1:1)** +2. **One-to-Many (1:N)** +3. **Many-to-Many (N:N)** + + +## 1. One-to-Many (1:N) + +### Definition + +- A single row in Table A can relate to **multiple rows** in Table B. +- A row in Table B relates to **only one row** in Table A. + +### Key Implementation + +- Add a **foreign key** in the "many" table. + +### Example + +- **Movies → Promotions** + - One movie can have many promotions. + - Each promotion belongs to one movie. + +`Movies (id) ← Promotions (movie_id)` + +### Diagram Representation + +- `1` on the "one" side +- `*` on the "many" side + +## 2. Many-to-Many (N:N) + +### Definition + +- Multiple rows in Table A can relate to multiple rows in Table B. + +### Key Implementation + +- Requires a **join table (junction table)** that holds foreign keys from both tables. + +### Example + +- **Movies ↔ Genres** + - A movie can have many genres. + - A genre can belong to many movies. + +``` +Movies_Genres +- movie_id +- genre_id +``` +### Diagram Representation + +- `*` on both sides +- Join table is typically implied (not always shown explicitly) + +## 3. One-to-One (1:1) + +### Definition + +- A row in Table A relates to exactly **one row** in Table B. + +### Use Case + +- Used to split large or complex tables into smaller ones. + +### Example + +- **Customers ↔ Addresses** + - Each customer has one address. + - Each address belongs to one customer. + +`Customers (address_id) → Addresses (id)` + +### Diagram Representation + +- `1` on both sides + +## Relationship Identification Examples + +### Example 1: Movies & Reviews + +- One movie can have many reviews. +- Each review belongs to one movie. + +**Relationship:** One-to-Many + +`Movies (id) ← Reviews (movie_id)` + + +### Example 2: Movies & Promotions + +- A promotion can apply to many movies. +- A movie can have many promotions. + +**Relationship:** Many-to-Many + +``` +Movies_Promotions +- movie_id +- promotion_id +``` + +## Summary + +|Relationship Type|Key Idea|Implementation| +|---|---|---| +|One-to-One|1 row ↔ 1 row|Foreign key on one side| +|One-to-Many|1 row → many rows|Foreign key in "many" table| +|Many-to-Many|Many ↔ many|Join table with two FKs| +- Always identify how entities relate **from a business perspective**, not just technically. +- Use: + - **Foreign keys** for 1:1 and 1:N + - **Join tables** for N:N +- Diagrams use: + - `1` = single + - `*` = many + + +# SQL INNER JOINs (Level 4 Notes) + +## Overview + +- **INNER JOIN** is used to combine rows from two (or more) tables based on a related column. +- It returns **only the matching records** between the tables (the overlapping part). +- Common use case: retrieving related data in a **single query instead of multiple queries**. + +## Key Concepts + +### 1. Problem Without JOIN + +- To get reviews and corresponding movie titles: + 1. Query reviews: SELECT review, movie_id FROM Reviews; + 2. Use returned `movie_id`s to query movies: SELECT title FROM Movies WHERE id IN (1, 3, 4); +- This requires **multiple queries**, which is inefficient. + +### 2. INNER JOIN Syntax + +``` +SELECT * +FROM Movies +INNER JOIN Reviews +ON Movies.id = Reviews.movie_id; +``` + +#### Explanation: + +- `INNER JOIN Reviews`: specifies the table to join. +- `ON Movies.id = Reviews.movie_id`: defines how rows relate: + - `Movies.id` = primary key + - `Reviews.movie_id` = foreign key + +### 3. Result Behaviour + +- Only rows with **matching keys in both tables** are returned. +- Examples: + - Movies without reviews → **excluded** + - Reviews without movies → **excluded** + - A movie with multiple reviews → appears **multiple times** + +#### Example: + +- Movie **"Don Juan"** with 3 reviews → appears 3 times. +- Movie **"Peter Pan"** with no reviews → does not appear. + +### 4. Order of Tables +Both queries return the same result: + +`FROM Movies INNER JOIN Reviews` + +or + +`FROM Reviews INNER JOIN Movies` + +- Because INNER JOIN returns only **matching data**, order doesn't change the result. + +### 5. Selecting Specific Columns + +Instead of retrieving all columns (`SELECT *`), specify only what you need: + +``` +SELECT Movies.title, Reviews.review +FROM Movies +INNER JOIN Reviews +ON Movies.id = Reviews.movie_id; +``` + +- Important: Prefix columns with table names to avoid ambiguity. + +## 6. INNER JOIN Across Multiple Tables + +You can join more than two tables in a single query. + +### Example: Get movie title and genres + +``` +SELECT Movies.title, Genres.name +FROM Movies +INNER JOIN Movies_Genres + ON Movies.id = Movies_Genres.movie_id +INNER JOIN Genres + ON Movies_Genres.genre_id = Genres.id +WHERE Movies.title = 'Peter Pan'; +``` +### How it works: + +1. Join **Movies → Movies_Genres** via `movie_id` +2. Join **Movies_Genres → Genres** via `genre_id` +3. Filter for `"Peter Pan"` + +## Visual Understanding + +- Think of INNER JOIN like the **intersection of two circles (Venn diagram)**: + - Left circle = Movies + - Right circle = Reviews + - Result = only the overlapping middle + +## Key Takeaways + +- Use **INNER JOIN** to retrieve related data from multiple tables in one query. +- It only returns **matching rows**. +- Always use the `ON` clause to define relationships. +- Specify columns for cleaner results. +- Multiple joins can be chained for more complex relationships. + +## Quick Example Summary + +``` +-- Basic join +SELECT Movies.title, Reviews.review +FROM Movies +INNER JOIN Reviews +ON Movies.id = Reviews.movie_id; + +-- Multi-table join +SELECT Movies.title, Genres.name +FROM Movies +INNER JOIN Movies_Genres + ON Movies.id = Movies_Genres.movie_id +INNER JOIN Genres + ON Movies_Genres.genre_id = Genres.id; +``` + +# SQL Aliases (Columns & Tables) + +## Column Aliases + +- Column aliases allow you to rename output column headers in your query results. +- Useful for making results more readable and user-friendly. +### Syntax + +``` +SELECT column_name AS alias_name +FROM table_name; +``` + +- The keyword `AS` is optional: + +``` +SELECT column_name alias_name +FROM table_name; +``` + +### Examples + +``` +SELECT Movies.title AS films, Reviews.review AS reviews +FROM Movies +INNER JOIN Reviews ON Movies.id = Reviews.movie_id; +``` + +- Without `AS`: +``` +SELECT Movies.title films, Reviews.review reviews +FROM Movies +INNER JOIN Reviews ON Movies.id = Reviews.movie_id; +``` + +### Using Multiple Words in Aliases + +- Use quotation marks when the alias contains spaces: + +``` +SELECT Movies.title AS "Weekly Movies", Reviews.review AS "Weekly Reviews" +FROM Movies +INNER JOIN Reviews ON Movies.id = Reviews.movie_id; +``` + +## Table Aliases + +- Table aliases shorten table names in queries. +- Helpful when: + - Working with long table names + - Writing complex joins + - Improving readability +### Syntax + +`FROM table_name alias` +### Example + +``` +SELECT m.title +FROM Movies m; +``` + +- Here, `m` is used instead of `Movies`. + +## Using Table Aliases in Joins + +- Once defined, aliases can be used throughout the query (SELECT, JOIN, WHERE, ORDER BY). + +### Example + +``` +SELECT m.title, r.review +FROM Movies m +INNER JOIN Reviews r ON m.id = r.movie_id; +``` + +### Example + +``` +SELECT m.title, g.name +FROM Movies m +INNER JOIN Movies_Genres mg ON m.id = mg.movie_id +INNER JOIN Genres g ON mg.genre_id = g.id; +``` + + + +# SQL Outer Joins (LEFT & RIGHT) + +## Overview + +Outer joins allow you to combine rows from two tables even when there is no match in one of them. They help ensure that you don’t lose data from one side of the relationship. + +## LEFT OUTER JOIN + +### Purpose + +- Returns **all records from the left table** (`Movies`) +- Returns **matching records from the right table** (`Reviews`) +- If no match exists, the right-side columns are filled with `NULL` + +### Syntax + +``` +SELECT * +FROM Movies +LEFT OUTER JOIN Reviews +ON Movies.id = Reviews.movie_id; +``` + +### Key Observations + +- Every movie appears in the result +- Movies with multiple reviews appear multiple times +- Movies with **no reviews still appear**, with `NULL` values for review columns + +### Example Output Insight + +- `Don Juan` appears **3 times** (3 reviews) +- `Peter Pan` appears **once** with no review (NULL values) + +## Refining the LEFT JOIN + +### Improvements + +1. Use table aliases +2. Select only relevant columns +3. Order results + +### Example Query + +``` +SELECT m.title, r.body +FROM Movies m +LEFT OUTER JOIN Reviews r +ON m.id = r.movie_id +ORDER BY r.id; +``` + +### Result Behaviour + +- Movies without reviews (e.g. `Peter Pan`) appear **last** due to ordering by `review id` + +## RIGHT OUTER JOIN + +### Purpose + +- Returns **all records from the right table** (`Reviews`) +- Returns **matching records from the left table** (`Movies`) +- If no match exists, the left-side columns are filled with `NULL` + +### Syntax + +``` +SELECT * +FROM Movies +RIGHT OUTER JOIN Reviews +ON Movies.id = Reviews.movie_id; +``` + +### Scenario Highlight + +- Some `movie_id` values in `Reviews` are set to `NULL` +- These reviews do not link to any movie + +### Key Observations + +- All reviews are included +- Reviews without a corresponding movie show `NULL` in movie fields + +## Refining the RIGHT JOIN + +### Example Query + +``` +SELECT m.title, r.body +FROM Movies m +RIGHT OUTER JOIN Reviews r +ON m.id = r.movie_id +ORDER BY r.id; +``` + +### Result Behaviour + +- All reviews listed +- Reviews with no associated movie have `NULL` titles + +## LEFT vs RIGHT JOIN Summary + +|Join Type|Includes All From|Missing Matches Show As| +|---|---|---| +|LEFT OUTER JOIN|Left table|NULLs in right columns| +|RIGHT OUTER JOIN|Right table|NULLs in left columns| + +## Key Takeaways + +- Use **LEFT JOIN** when you care about all records from the first (left) table +- Use **RIGHT JOIN** when you care about all records from the second (right) table +- `NULL` values indicate missing relationships +- Ordering can affect where unmatched rows appear in results + + +- Outer joins ensure you don’t lose unmatched data +- LEFT JOIN = “Show everything from the left” +- RIGHT JOIN = “Show everything from the right” +- Useful for identifying missing relationships and incomplete data + diff --git a/Career/Design Patterns.md b/Career/Design Patterns.md old mode 100755 new mode 100644 diff --git a/Career/Devops/CI-CD Example (site visits).md b/Career/Devops/CI-CD Example (site visits).md old mode 100755 new mode 100644 diff --git a/Career/Devops/CI-CD Summary.md b/Career/Devops/CI-CD Summary.md old mode 100755 new mode 100644 diff --git a/Career/Java Portswrigger Test.md b/Career/Java Portswrigger Test.md old mode 100755 new mode 100644 diff --git a/Career/Job applications.md b/Career/Job applications.md old mode 100755 new mode 100644 diff --git a/Career/MVP + MVT.md b/Career/MVP + MVT.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/APIM.md b/Career/Microlise/APIM.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Applications.md b/Career/Microlise/ESS ESP/ESP Applications.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Database.md b/Career/Microlise/ESS ESP/ESP Database.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Deploy Stages.md b/Career/Microlise/ESS ESP/ESP Deploy Stages.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Glossary.md b/Career/Microlise/ESS ESP/ESP Glossary.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Known Issues and Risks.md b/Career/Microlise/ESS ESP/ESP Known Issues and Risks.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Manifest.md b/Career/Microlise/ESS ESP/ESP Manifest.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP OQ.md b/Career/Microlise/ESS ESP/ESP OQ.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Pipeline.md b/Career/Microlise/ESS ESP/ESP Pipeline.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESP Scripts.md b/Career/Microlise/ESS ESP/ESP Scripts.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/ESS ESP Index.md b/Career/Microlise/ESS ESP/ESS ESP Index.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/ESS ESP/Microlise - ESS.md b/Career/Microlise/ESS ESP/Microlise - ESS.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/Microlise Assessment.md b/Career/Microlise/Microlise Assessment.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/Microlise MOC.md b/Career/Microlise/Microlise MOC.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/Pre work prep.md b/Career/Microlise/Pre work prep.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/Seb Search Improvements.md b/Career/Microlise/Seb Search Improvements.md old mode 100755 new mode 100644 diff --git a/Career/Microlise/Session Stored XSS PENTEST.html b/Career/Microlise/Session Stored XSS PENTEST.html new file mode 100644 index 0000000..b32d435 --- /dev/null +++ b/Career/Microlise/Session Stored XSS PENTEST.html @@ -0,0 +1,801 @@ + + + + + +
+The Microlise +TMC PO WA April 2026 v1.0.pdf lists 14 findings +total. Pages 33–34 (33-34.pdf) are the last +technical finding before “END OF DOCUMENT”:
+| Field | +Value | +
|---|---|
| Title | +Session stored XSS | +
| Severity | +Informational (lowest tier; 4 informational +findings in the report) | +
| Status | +Open | +
| CWE | +CWE-79 +— Improper Neutralization of Input | +
| Environment | +cert.microlise.com (cert/UAT), path prefix
+/PENTEST/TMCWebPortal/ |
+
Higher-severity items in the same report (SQLi, IDOR, BFLA, etc.) are +separate; this finding is documented as technically valid but +low business risk.
+Cross-Site Scripting (XSS) means untrusted data ends +up in a web page in a way the browser treats as executable +JavaScript, instead of inert text.
+The name “cross-site” is historical: classic attacks trick a +victim into loading a page on your app +so script runs in your origin (stealing session +cookies, performing actions as the user, etc.).
+Common types:
+| Type | +Persistence | +Typical delivery | +
|---|---|---|
| Reflected | +Not stored; one-off response | +Malicious link/query param | +
| Stored | +Saved server-side (DB, file, session) | +Victim loads a normal page later | +
| DOM-based | +Client-side only | +Unsafe innerHTML, eval, etc. | +
Defense in depth: validate input on the server +(whitelist formats), and encode output for the exact +context (HTML, attribute, JavaScript string, URL).
+| Role | +Path | +
|---|---|
| Page + inline JS | +ScheduleExecutionBoard.aspx | +
| WebMethod + page properties | +ScheduleExecutionBoard.aspx.cs | +
| Session storage | +SEBSessionState.cs | +
[WebMethod]
+SaveSearchCriteriaToSession on
+ScheduleExecutionBoard.aspxdate,
+orderID, time (also searchID,
+hours, quickSearch in the same flow)cert.microlise.com,
+path /PENTEST/TMCWebPortal/SEB/...flowchart LR
+ subgraph submit [Step1_Submit]
+ A[Tester sends POST directly]
+ B[SaveSearchCriteriaToSession]
+ C[Values stored in server session]
+ end
+ subgraph render [Step2_Render]
+ D[User loads ScheduleExecutionBoard.aspx]
+ E[Server embeds session values in script block]
+ F[Browser executes unescaped JS]
+ end
+ A --> B --> C
+ C --> D --> E --> F
+SaveSearchCriteriaToSession. The app saves search criteria
+into the server-side session.ScheduleExecutionBoard.aspx, those values are written into
+the HTML inside a <script> block, as
+JavaScript string literals.date can break
+out of the string and run arbitrary JS.1. Save — no server-side validation
+// ScheduleExecutionBoard.aspx.cs lines 336-348
+[WebMethod]
+public static void SaveSearchCriteriaToSession(string searchID, string orderID, string date, string time, int hours, bool displayPriorityJourneys, string quickSearch)
+{
+ var sebState = new SEBSessionState();
+ sebState.ComplexSearch = searchID;
+ sebState.OrderBy = orderID;
+ sebState.SearchDate = date;
+ sebState.SearchTime = time;
+ // ...
+}2. Persist — per-user ASP.NET session
+SEBSessionState.cs
+stores values under keys dateID, timeID,
+orderByID.
3. Load — on next full page GET
+// ScheduleExecutionBoard.aspx.cs lines 267-277
+private void SetupControls()
+{
+ var sebState = new SEBSessionState();
+ SessionOrderID = sebState.OrderBy;
+ SessionDate = sebState.SearchDate;
+ SessionTime = sebState.SearchTime;
+ // ...
+}4. Render — vulnerable inline JavaScript (root +cause)
+// ScheduleExecutionBoard.aspx lines 1853-1875
+if ("<%=SessionDate%>") {
+ $('#txtStart').val("<%= SessionDate %>");
+}
+if ("<%=SessionTime%>") {
+ $('#inputtime').val("<%=SessionTime%>");
+}
+if ("<%=SessionOrderID%>") {
+ $(orderBySelector + ' option[value="<%=SessionOrderID%>"]').attr('selected', 'selected');
+}Example payload in session:
+"); alert(document.domain); //
$('#txtStart').val(""); alert(document.domain); //");Related: QuickSearch at line ~1879 —
+fix in the same pass.
Pentesters bypassed browser validation via direct POST. No +server-side validation blocked arbitrary strings.
+Use this section to see the bug work on an +authorized environment (e.g. cert/UAT), then repeat the same +steps after fixes and compare outcomes.
+| Requirement | +Detail | +
|---|---|
| Authorization | +Pentest scope or internal security test policy only | +
| Permission | +Microlise:TMC:SEB:Read |
+
| URL | +e.g. https://<host>/TMCWebPortal/SEB/ScheduleExecutionBoard.aspx |
+
| Tools | +Browser + DevTools or Burp Suite | +
| Build | +Before-fix build first; redeploy with remediation for after-fix +runs | +
Must be logged in (valid session cookie on POST).
+sequenceDiagram
+ participant You as Tester_browser
+ participant API as SaveSearchCriteriaToSession
+ participant Sess as ASP.NET_session
+ participant Page as ScheduleExecutionBoard_GET
+
+ You->>API: POST JSON with malicious date
+ API->>Sess: Store raw date in session
+ You->>Page: Reload SEB page
+ Page->>You: HTML with unescaped date inside script
+ You->>You: alert or other JS runs
+DateValidation().alert).Self-XSS: only your session is poisoned.
+Step 1 — Baseline (optional)
+SaveSearchCriteriaToSession.application/json, body shape, Cookie
+header.Step 2 — Inject via direct POST (bypass UI)
+| Parameter | +Suggested test value | +
|---|---|
searchID |
+0.X |
+
orderID |
+0.X |
+
date |
+"); alert(document.domain);// |
+
time |
+00:00 |
+
hours |
+24 |
+
displayPriorityJourneys |
+false |
+
quickSearch |
+"" |
+
Burp: Repeater → replace JSON body → send.
+Browser console (on SEB page, same origin):
+fetch('ScheduleExecutionBoard.aspx/SaveSearchCriteriaToSession', {
+ method: 'POST',
+ credentials: 'include',
+ headers: { 'Content-Type': 'application/json; charset=utf-8' },
+ body: JSON.stringify({
+ searchID: '0.X',
+ orderID: '0.X',
+ date: '"); alert(document.domain);//',
+ time: '00:00',
+ hours: 24,
+ displayPriorityJourneys: false,
+ quickSearch: ''
+ })
+}).then(r => console.log('status', r.status));curl (replace host, path, cookies):
+curl -s -o /dev/null -w "%{http_code}" \
+ -X POST "https://<host>/<TMCWebPortal>/SEB/ScheduleExecutionBoard.aspx/SaveSearchCriteriaToSession" \
+ -H "Content-Type: application/json; charset=utf-8" \
+ -H "Cookie: <paste-session-cookies>" \
+ -d "{\"searchID\":\"0.X\",\"orderID\":\"0.X\",\"date\":\"\\\"); alert(document.domain);//\",\"time\":\"00:00\",\"hours\":24,\"displayPriorityJourneys\":false,\"quickSearch\":\"\"}"Step 3 — Trigger render (stored XSS)
+ScheduleExecutionBoard.aspx
+(F5).SetupControls() embeds session date
+(~lines 1854–1855).Step 4 — Confirm
+| Check | +Before fix (expected) | +
|---|---|
| Popup / console | +alert(document.domain) runs |
+
| View Source | +Literal "); alert(...) inside
+$('#txtStart').val("...") unescaped |
+
| Network on reload | +Normal GET only; XSS from inline script | +
| Other users | +No effect (different session) | +
Step 5 — Optional: malicious time or
+orderID.
Step 6 — Clean up: log out/in or POST valid +date/time.
+Run the same Steps 2–4 after each change:
+| Observation | +Before fix | +After encoding only | +After validation only | +After both | +
|---|---|---|---|---|
POST malicious date accepted? |
+Yes (200) | +Yes (200) | +No / not stored | +No | +
alert on reload? |
+Yes | +No | +Depends* | +No | +
| Executable JS in View Source? | +Yes | +No (escaped) | +Depends* | +No | +
#txtStart shows attack text? |
+Maybe | +Escaped/safe | +Default/empty | +Default/empty | +
| Normal UI search + reload works? | +Yes | +Yes | +Yes | +Yes | +
*If only validation: reload may show no XSS without encoding — still +apply both fixes.
+| Path | +DateValidation() runs? |
+Payload reaches session? | +
|---|---|---|
| Click Search in UI | +Yes | +No (normal typing) | +
| Direct POST / Burp / fetch | +No | +Yes | +
Reproduction must use direct POST to match the +pentest.
+$('#txtStart').val(.alert(document.domain) over exfiltration
+demos.Use two layers: output encoding + server-side +validation.
+File: ScheduleExecutionBoard.aspx,
+SetupControls() (~1847–1884).
| Line (approx) | +Field | +Encode | +
|---|---|---|
| 1849–1850 | +SessionSearchID | +Yes | +
| 1854–1855 | +SessionDate | +Yes | +
| 1860–1861 | +SessionTime | +Yes | +
| 1872–1874 | +SessionOrderID | +Yes | +
| 1878–1879 | +QuickSearch | +Yes | +
Before:
+$('#txtStart').val("<%= SessionDate %>");After:
+$('#txtStart').val("<%= HttpUtility.JavaScriptStringEncode(SessionDate ?? string.Empty) %>");Encode if guards too, or use code-behind booleans
+(HasSessionDate).
File: ScheduleExecutionBoard.aspx.cs,
+SaveSearchCriteriaToSession (~337).
| Parameter | +Validation rule | +
|---|---|
date |
+Same regex as client DateValidation() |
+
time |
+^[0-2][0-9]:[0-5][0-9]$ |
+
orderID |
+^[0-9]+(\.X)?$ |
+
searchID |
+Same as orderID |
+
hours |
+Clamp 1–999 | +
[WebMethod]
+public static void SaveSearchCriteriaToSession(...)
+{
+ if (!IsValidSebDate(date) || !IsValidSebTime(time)
+ || !IsValidQueryComponentId(orderID) || !IsValidQueryComponentId(searchID))
+ {
+ return;
+ }
+ var sebState = new SEBSessionState();
+ // ...
+}Date regex:
+^[0-9]{4}-(((0[13578]|(10|12))-(0[1-9]|[1-2][0-9]|3[0-1]))|(02-(0[1-9]|[1-2][0-9]))|((0[469]|11)-(0[1-9]|[1-2][0-9]|30)))$
+DateValidation() alone.HtmlEncode in JS string literals.innerHTML; keep .val().Master procedure: Replicating the vulnerability +section above.
+Negative test:
+{
+ "searchID": "0.X",
+ "orderID": "0.X",
+ "date": "\"); alert(1);//",
+ "time": "00:00",
+ "hours": 24,
+ "displayPriorityJourneys": false,
+ "quickSearch": ""
+}Pass: No alert; escaped in source; invalid date not +stored (with Fix 2).
+Positive test: UI search + reload restores +criteria.
+| File | +Change | +
|---|---|
| ScheduleExecutionBoard.aspx | +JavaScriptStringEncode in
+SetupControls() |
+
| ScheduleExecutionBoard.aspx.cs | +Validation in SaveSearchCriteriaToSession |
+
References: OWASP XSS, PortSwigger +Stored XSS, JavaScriptStringEncode
+| Question | +Answer | +
|---|---|
| Real coding flaw? | +Yes (CWE-79) | +
| Cross-user session hijack? | +Not under normal use (self-XSS) | +
| Should it still be fixed? | +Yes, as hygiene | +
| Priority vs SQLi / IDOR? | +Much lower (informational) | +
fetch('ScheduleExecutionBoard.aspx/SaveSearchCriteriaToSession', {
+ method: 'POST',
+ credentials: 'include',
+ headers: { 'Content-Type': 'application/json; charset=utf-8' },
+ body: JSON.stringify({
+ searchID: '0.X', orderID: '0.X',
+ date: '2026-05-27', time: '00:00', hours: 24,
+ displayPriorityJourneys: false, quickSearch: ''
+ })
+}).then(() => location.reload());
+fetch('ScheduleExecutionBoard.aspx/SaveSearchCriteriaToSession', {
+ method: 'POST',
+ credentials: 'include',
+ headers: { 'Content-Type': 'application/json; charset=utf-8' },
+ body: JSON.stringify({
+ searchID: '0.X',
+ orderID: '0.X',
+ date: '"+alert(1)+"',
+ time: '00:00',
+ hours: 24,
+ displayPriorityJourneys: false,
+ quickSearch: ''
+ })
+}).then(r => console.log(r.status, r.statusText));
+function poisonSession(field, payload) {
+ const body = {
+ searchID: '0.X',
+ orderID: '0.X',
+ date: '2026-05-27',
+ time: '00:00',
+ hours: 24,
+ displayPriorityJourneys: false,
+ quickSearch: ''
+ };
+ body[field] = payload;
+ return fetch('ScheduleExecutionBoard.aspx/SaveSearchCriteriaToSession', {
+ method: 'POST',
+ credentials: 'include',
+ headers: { 'Content-Type': 'application/json; charset=utf-8' },
+ body: JSON.stringify(body)
+ }).then(r => console.log(field, r.status, r.statusText));
+}
+poisonSession('date', '"+confirm("XSS: SEB session poisoned")+"');
+poisonSession('date', '"+document.body.insertAdjacentHTML("afterbegin","<div style=\\"position:fixed;top:0;left:0;right:0;background:red;color:white;z-index:99999;padding:12px;text-align:center\\">XSS PoC — arbitrary script executed in SEB context</div>")+"');
+
+
+
diff --git a/Career/Microlise/Session Stored XSS PENTEST.md b/Career/Microlise/Session Stored XSS PENTEST.md
old mode 100755
new mode 100644
index 33d1870..7008413
--- a/Career/Microlise/Session Stored XSS PENTEST.md
+++ b/Career/Microlise/Session Stored XSS PENTEST.md
@@ -380,6 +380,60 @@ public static void SaveSearchCriteriaToSession(...)
^[0-9]{4}-(((0[13578]|(10|12))-(0[1-9]|[1-2][0-9]|3[0-1]))|(02-(0[1-9]|[1-2][0-9]))|((0[469]|11)-(0[1-9]|[1-2][0-9]|30)))$
+#### Explanation of regex:
+
+##### `SebDateRegex`
+
+`^[0-9]{4}-(((0[13578]|(10|12))-(0[1-9]|[1-2][0-9]|3[0-1]))|(02-(0[1-9]|[1-2][0-9]))|((0[469]|11)-(0[1-9]|[1-2][0-9]|30)))$`
+
+Overall shape: `YYYY-MM-DD` only — four digits, hyphen, month/day with structure checks.
+
+|Part|Meaning|
+|---|---|
+|`^` / `$`|Whole string must match (no extra characters).|
+|`[0-9]{4}-`|Four-digit year, then `-`.|
+|31-day months|`(0[13578]\|(10\|12))-(0[1-9]\|[1-2][0-9]\|3[0-1])` — Jan, Mar, May, Jul, Aug, Oct, Dec: day `01`–`31`.|
+|February|`02-(0[1-9]\|[1-2][0-9])` — day `01`–`29` (no Feb 30/31).|
+|30-day months|`(0[469]\|11)-(0[1-9]\|[1-2][0-9]\|30)` — Apr, Jun, Sep, Nov: day `01`–`30`.|
+
+Matches: `2026-05-27`, `2024-02-29`, `2024-04-30`
+Rejects: `2026-13-01`, `not-a-date`, `"); alert(1);//`, empty/null
+
+Note: This is format validation, not a full calendar check. It does not prove the date exists (e.g. `2025-02-30` can match the February branch). That matches the existing client `DateValidation()` in `ScheduleExecutionBoard.aspx` (line 4050).
+
+##### `SebTimeRegex`
+
+`^[0-2][0-9]:[0-5][0-9]$`
+
+Overall shape: two digits, `:`, two digits — same idea as `HH:mm` in the UI.
+
+|Part|Meaning|
+|---|---|
+|`[0-2][0-9]`|First hour digit 0–2, second 0–9 → allows `00`–`29` (looser than strict 00–23).|
+|`:`|Literal colon.|
+|`[0-5][0-9]`|Minutes `00`–`59`.|
+
+Matches: `00:00`, `12:30`, `23:59`
+Rejects: `25:99`, `9:00` (needs two hour digits), `"); alert(1);//`
+
+Note: Values like `29:00` match the pattern but are not real clock times; the pentest/UI convention is this simple pattern, not full time-of-day logic.
+
+##### `QueryComponentIdRegex`
+
+`^[0-9]+(\.X)?$`
+
+Overall shape: one or more digits, optionally followed by `.X` — the values SEB puts on search/order-by dropdowns.
+
+|Part|Meaning|
+|---|---|
+|`^` / `$`|Whole string only.|
+|`[0-9]+`|One or more digits (e.g. `0`, `123`).|
+|`(\.X)?`|Optional literal `.X` (shared / external query suffix in combo markup).|
+
+Matches: `0`, `0.X`, `123`, `123.X`
+Rejects: `abc`, `0.XY`, `"); alert(1);//`, empty/null
+
+This aligns with how items are built in `BuildSearchForComboBoxItems` / `BuildOrderByComboBoxItems` (e.g. `"0.X"` for “all journeys” / unspecified order-by).
### Fix 3 — What not to do
- Do not rely on client `DateValidation()` alone.
diff --git a/Career/Powershell MOC.md b/Career/Powershell MOC.md
old mode 100755
new mode 100644
diff --git a/Career/Regex.md b/Career/Regex.md
old mode 100755
new mode 100644
index 488d8f2..c337236
--- a/Career/Regex.md
+++ b/Career/Regex.md
@@ -3,4 +3,10 @@ note type:
- theory
date: 2026-06-04
done:
+link: https://www.rexegg.com/regex-quickstart.php
---
+Regular expressions (regex) are patterns used to match character combinations in strings, offering a powerful way to search and manipulate text that can replace dozens of lines of code. While the syntax can seem complex, understanding core components like **character classes** (e.g., `[0-9]` for digits, `\w` for word characters), **quantifiers** (e.g., `+` for one or more, `*` for zero or more), and **anchors** (e.g., `^` for start, `$` for end) allows for effective pattern matching.
+
+Check out the link, which is really useful in showcasing the rules.
+
+Use: https://regex101.com/ to build and validate.
\ No newline at end of file
diff --git a/Career/Security/Attachments/Pasted image 20260602161410.png b/Career/Security/Attachments/Pasted image 20260602161410.png
old mode 100755
new mode 100644
diff --git a/Career/Security/Attachments/Pasted image 20260603202301.png b/Career/Security/Attachments/Pasted image 20260603202301.png
old mode 100755
new mode 100644
diff --git a/Career/Security/Attachments/Pasted image 20260603202316.png b/Career/Security/Attachments/Pasted image 20260603202316.png
old mode 100755
new mode 100644
diff --git a/Career/Security/Cross Site Scripting (XSS).md b/Career/Security/Cross Site Scripting (XSS).md
old mode 100755
new mode 100644
diff --git a/Career/Security/OWASP Top 10.md b/Career/Security/OWASP Top 10.md
old mode 100755
new mode 100644
diff --git a/Career/Security/Output Encoding.md b/Career/Security/Output Encoding.md
old mode 100755
new mode 100644
diff --git a/Career/Security/Server-Side Request Forgery (SSRF).md b/Career/Security/Server-Side Request Forgery (SSRF).md
old mode 100755
new mode 100644
diff --git a/Career/Software Development Methodologies.md b/Career/Software Development Methodologies.md
old mode 100755
new mode 100644
diff --git a/Career/Solid Principles.md b/Career/Solid Principles.md
old mode 100755
new mode 100644
diff --git a/Career/Test Driven Development.md b/Career/Test Driven Development.md
old mode 100755
new mode 100644
diff --git a/Career/Windows Services.md b/Career/Windows Services.md
old mode 100755
new mode 100644
diff --git a/Career/XOR.md b/Career/XOR.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-14.md b/Dailies/2026-04-14.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-18.md b/Dailies/2026-04-18.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-20.md b/Dailies/2026-04-20.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-21.md b/Dailies/2026-04-21.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-28.md b/Dailies/2026-04-28.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-29.md b/Dailies/2026-04-29.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-04-30.md b/Dailies/2026-04-30.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-01.md b/Dailies/2026-05-01.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-05.md b/Dailies/2026-05-05.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-06.md b/Dailies/2026-05-06.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-12.md b/Dailies/2026-05-12.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-13.md b/Dailies/2026-05-13.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-20.md b/Dailies/2026-05-20.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-21.md b/Dailies/2026-05-21.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-22.md b/Dailies/2026-05-22.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-28.md b/Dailies/2026-05-28.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-05-29.md b/Dailies/2026-05-29.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-06-01.md b/Dailies/2026-06-01.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-06-02.md b/Dailies/2026-06-02.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-06-03.md b/Dailies/2026-06-03.md
old mode 100755
new mode 100644
diff --git a/Dailies/2026-06-04.md b/Dailies/2026-06-04.md
old mode 100755
new mode 100644
index 2eb98bd..26c650c
--- a/Dailies/2026-06-04.md
+++ b/Dailies/2026-06-04.md
@@ -6,9 +6,9 @@ date: "2026-06-04"
# 2026-06-04
## TODOs
-- [ ] Complete the fix, understand the regex
-- [ ]
-- [ ]
+- [ ] Complete the fix
+- [ ] Make the PR
+- [ ] understand the regex
- [ ] Reading (5 pages)
- [ ] Class 1
- [ ] Class 2
diff --git a/Dailies/2026-06-05.md b/Dailies/2026-06-05.md
new file mode 100644
index 0000000..696424b
--- /dev/null
+++ b/Dailies/2026-06-05.md
@@ -0,0 +1,18 @@
+---
+work day: false
+date: "2026-06-05"
+---
+
+# 2026-06-05
+
+## TODOs
+- [x] PR comments (XSS)
+- [x] Start new task (removal of DF)
+- [ ]
+- [ ] Reading (5 pages)
+- [ ] Class 1
+- [ ] Class 2
+- [ ] Class 3
+
+## Links
+- https://pewdiepie-archdaemon.github.io/odysseus/#start
\ No newline at end of file
diff --git a/Dailies/2026-06-08.md b/Dailies/2026-06-08.md
new file mode 100644
index 0000000..c79881d
--- /dev/null
+++ b/Dailies/2026-06-08.md
@@ -0,0 +1,19 @@
+---
+work day: false
+date: "2026-06-08"
+---
+
+# 2026-06-08
+
+## TODOs
+- [ ]
+- [ ]
+- [ ]
+- [ ] Reading (5 pages)
+- [ ] Class 1
+- [ ] Class 2
+- [ ] Class 3
+
+## Links
+https://www.youtube.com/watch?v=aIZGv4M_dwc
+https://darululoomnewcastle.co.za/the-founder/#
\ No newline at end of file
diff --git a/Dailies/2026-06-09.md b/Dailies/2026-06-09.md
new file mode 100644
index 0000000..7805fb4
--- /dev/null
+++ b/Dailies/2026-06-09.md
@@ -0,0 +1,17 @@
+---
+work day: false
+date: "2026-06-09"
+---
+
+# 2026-06-09
+
+## TODOs
+- [x] Uplift TMC.Data package in AVL service
+- [x] Run integration and sanity checks for AVL Service PR + update PR description
+- [ ] removal of bug DF
+- [ ] Reading (5 pages)
+- [ ] Class 1
+- [ ] Class 2
+- [ ] Class 3
+
+## Links
diff --git a/Daily Notes.md b/Daily Notes.md
old mode 100755
new mode 100644
diff --git a/Deen/Naats.md b/Deen/Naats.md
new file mode 100644
index 0000000..00ef7b4
--- /dev/null
+++ b/Deen/Naats.md
@@ -0,0 +1,179 @@
+# Tu Hai Banda Khuda Ka Khuda Ki Qasam ┇ Jameel Hansrot
+
+