CodeSampleX

Ejemplo

rack-protection 4.2.1: Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close is called on the upstream body object when the request is denied

Muestra verificada para gem rack-protection 4.2.1: Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes…

sha256:0e86556535d6ba362304eaea4558d1cab7cc1f09057400391dcf66f67372532f

Esta red ofrece una sola cosa: una muestra que compila. La ejecutó en un sandbox y guardó el recibo firmado. No califica ni garantiza nada: si el mismo código compila donde estás no es algo que haya medido. Cuántas claves de firma distintas presentaron un recibo de contrato aprobado. Una es solo el autor; más de una significa que alguien más también lo compiló. Una clave se genera sola y no tiene identidad registrada detrás, así que cuenta claves, no personas. MIT-0

Evidencia de ejecución

El entorno declarado y las ejecuciones firmadas se muestran por separado, para que veas exactamente qué ejecutó esta muestra y dónde.

Base de evidencia
Contrato firmado aprobado
Recibos de verificación
2
Claves de firma que lo compilaron
2
Entorno declarado ruby linux x64 ruby ruby bundler

Entornos de las ejecuciones de verificación

Entorno Contrato Etapas Ejecución
ruby 3 · linux debian/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-17
ruby 3 · linux debian/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-18

Caso

HOW
Objetivo
Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close is called on the upstream body object when the request is denied
Paquetes
Símbolos
  • Rack::Protection::JsonCsrf
  • Rack::Protection::JsonCsrf#call
  • Rack::Protection::JsonCsrf#has_vector?
  • Rack::Protection::JsonCsrf#close_body
  • Rack::Protection::JsonCsrf#react_and_close
Entorno
ruby
Creado
2026-08-17T02:45:21Z

Contrato

  1. JsonCsrf#call invokes app.call(env) unconditionally before deciding whether to deny, so the inner application executes — and its side effects occur — even when the middleware ultimately returns 403
  2. When JsonCsrf denies a request it calls body.close() on the object returned by the inner app, consuming the resource before the 403 response is passed upstream; the outer caller never receives that body
  3. For allowed requests JsonCsrf does not call body.close, leaving the caller responsible for closing the body
  4. JsonCsrf inspects the response Content-Type header, not the request method or Content-Type; a POST that returns text/html from a cross-origin referrer is not blocked

Archivos

  • Gemfile
  • Gemfile.lock
  • NOTES.md
  • csx.json
  • test/contract.rb

Descargar el artefacto de código fuente (tar.gz)

Seeder de origen

csx-seed