CodeSampleX

サンプル

rack-protection 4.2.1: Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close is called on the upstream body object when the request is denied

検証済みサンプル — gem rack-protection 4.2.1: Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close…

sha256:0e86556535d6ba362304eaea4558d1cab7cc1f09057400391dcf66f67372532f

このネットワークが提供するのは一つだけです。ビルドされるサンプル。サンドボックスで実行し、署名済みの受領証を保管します。等級はつけず、何も保証しません — 同じコードがあなたの環境でビルドされるかは測定していません。 合格した契約受領証を提出した異なる署名鍵の数です。1 なら作者だけ、2 以上なら他の誰かもビルドしています。鍵は自己生成で背後に登録された身元がないため、数えているのは人ではなく鍵です。 MIT-0

実行証拠

宣言された環境と署名済みの実行を分けてあります。このサンプルが何をどこで実行したかをそのまま確認できます。

証拠の基準
署名済みコントラクト合格
検証レシート
2
ビルドした署名鍵
2
宣言された環境 ruby linux x64 ruby ruby bundler

検証実行環境

環境 コントラクト ステージ 実行日
ruby 3 · linux debian/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-17
ruby 3 · linux debian/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-18

ケース

HOW
ゴール
Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close is called on the upstream body object when the request is denied
パッケージ
シンボル
  • Rack::Protection::JsonCsrf
  • Rack::Protection::JsonCsrf#call
  • Rack::Protection::JsonCsrf#has_vector?
  • Rack::Protection::JsonCsrf#close_body
  • Rack::Protection::JsonCsrf#react_and_close
環境
ruby
作成日
2026-08-17T02:45:21Z

コントラクト

  1. JsonCsrf#call invokes app.call(env) unconditionally before deciding whether to deny, so the inner application executes — and its side effects occur — even when the middleware ultimately returns 403
  2. When JsonCsrf denies a request it calls body.close() on the object returned by the inner app, consuming the resource before the 403 response is passed upstream; the outer caller never receives that body
  3. For allowed requests JsonCsrf does not call body.close, leaving the caller responsible for closing the body
  4. JsonCsrf inspects the response Content-Type header, not the request method or Content-Type; a POST that returns text/html from a cross-origin referrer is not blocked

ファイル

  • Gemfile
  • Gemfile.lock
  • NOTES.md
  • csx.json
  • test/contract.rb

ソースアーティファクトをダウンロード (tar.gz)

オリジンシーダー

csx-seed