Skip to content

feat(lab2): Threagile threat model + secure variant + auth flow#1041

Open
ratteperk wants to merge 1 commit into
inno-devops-labs:mainfrom
ratteperk:feature/lab2
Open

feat(lab2): Threagile threat model + secure variant + auth flow#1041
ratteperk wants to merge 1 commit into
inno-devops-labs:mainfrom
ratteperk:feature/lab2

Conversation

@ratteperk

@ratteperk ratteperk commented Jun 12, 2026

Copy link
Copy Markdown

Goal

  • Generate a STRIDE-based threat model of OWASP Juice Shop with Threagile, then produce a secure-variant model and diff the risk reports.

Changes

  • submissions/lab2.md - risk analysis tables and STRIDE mapping
  • labs/lab2/threagile-model-secure.yaml - hardened model with HTTPS and encryption
  • labs/lab2/threagile-model-auth.yaml - smaller Threagile model focused on Juice Shop's authentication flow

Testing


Artifacts & Screenshots


  • Task 1 — Baseline risk table + top-5 with STRIDE mapping
  • Task 2 — Secure variant + risk diff table
  • Bonus — Auth-flow model + 3 auth-specific risks

@ratteperk ratteperk marked this pull request as ready for review June 12, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant