AFRC-1003: Flight Path Endpoints and Objects
Status
| Implemented with modifications | Draft Date: 2026-02-10 | Last Call Date: 2026-02-17 | Publication Date: 2026-02-24 | Version: 0.1 |
Abstract
Table of Contents
- Introduction
- Abstract
- Motivation
- Specification
- Security Considerations
- Backward Compatibility
- References
1. Introduction
The purpose of the Flight Path 2026 competition is to promote youth awareness. This documentation/request will include API endpoints and the registration workflow for the Flight Path 2026 competition.
Comments are notated with //. They might explain what something does or debate whether something is needed.
2. Abstract
There will be the following puzzle types:
- Programming puzzles
- Cybersecurity puzzles
- Web
- OSINT
- Forensics
- Binary exploitation (BinExp)
- Reverse Engineering (Rev)
- General Skills (generally, this is a mix of the above puzzles but easier)
- Linux Commands
3. Motivation
The Nature of the Flight Path Competition
The Flight Path competition requires capabilities that are not handled by the current API. These include (in brief):
- Puzzle implementation
- User profiles
- Team profiles
4. Specification
Object Structures
User Profile Structure
- participation-type (string of either: college, highschool, other) // college vs. high school
- school (string of school name or none)
- school-year (string of the school year: eg. “12th” / “Junior”)
- country (string of country name) // Is it only in the USA?
- subregion (string of state name) // Can be obtained with same API used in scopes and sequences
- city (string of city name)
- skills (array of string) // Example: {“C#”, “binary exploitation”}
Team Object Structure
- team-id (string)
- team-name (string)
- individual (bool) // if it’s an individual team with only one member; most will be the original team that the user joined in
- members (array of userEIDs)
- member-count (uint8)
- join-requests
- is-public (bool)
- details (array)
- status (string)
- school-name (string)
- looking-for (string)
Puzzle Object
Each puzzle object below has all items in the Puzzle Template object. T1: Static puzzles, text only puzzles T2: File puzzles, require a file attachment to solve T3: Instance puzzles, puzzles that require an instance to solve (eg. an XSS puzzle or a binary running on a server)
Puzzle Template
- puzzle-name (string)
- puzzle-description (string)
- current-point-value (uint)
- completed-by (array: team-ids with team-name in a subarray)
- solve-count (uint16)
- webshell-accessible (bool)
Type 1 Puzzle: Static
- puzzle-text (string)
Type 2 Puzzle: File
- file-URL (string) // Downloadable link to the puzzle file
Type 3 Puzzle: Instance
- team-instance-URL (string)
- team-id // Tie the puzzle instance to the team
Type 2 Puzzle: File
- file-URL (string) // Downloadable link to the puzzle file
Type 3 Puzzle: Instance
- puzzle-disabled (bool) // if the puzzle does not work, we can disable it for competitors and prevent instance startup
- team-instance-URL (string)
- team-id (string) // Tie the puzzle instance to the team itself
- instance-status (string) // The status of the puzzle instance: (started, shutting-down, stopped)
API Endpoints
5. Security Considerations
The following endpoints will all be authenticated with the following unless stated otherwise:
- Auth:
- Token
- X-Ayode-Asserted-Realm-EID
6. Backward Compatibility
This change is additive and does not change any existing endpoints.
7. References
Author
ĀYŌDÈ Development Team Codermerlin Flight Path Architecture