CodeSampleX

示例

rack-protection 4.2.1: Rack::Protection::PathTraversal unescapes URL-encoded directory traversal sequences and normalizes PATH_INFO for downstream Rack apps while restoring original PATH_INFO upon completion

已验证示例 — gem rack-protection 4.2.1: Rack::Protection::PathTraversal unescapes URL-encoded directory traversal sequences and normalizes PATH_INFO for…

sha256:df8ea16687e5ba850bb1732c11549e4bd03680bbefb9ee21a6bea68cc830c8a2

本网络只提供一件事:能构建的样本。它在沙箱中运行并保留签名回执。它不评级、不担保——同样的代码能否在你的环境构建,它没有测量过。 提交了通过的契约回执的不同签名密钥数量。为 1 表示只有作者;大于 1 表示还有其他人构建过。密钥是自行生成的,背后没有注册身份,因此计的是密钥而非人。 MIT-0

执行证据

声明的环境与签名的运行分开呈现,你可以看到这个样本究竟运行了什么、在哪里运行。

证据依据
签名契约通过
验证回执
2
构建过它的签名密钥
2
声明的环境 ruby linux x64 ruby ruby gem

验证运行环境

环境 契约 阶段 运行日期
ruby 3 · linux debian/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-17
ruby 3 · linux debian/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · rubygems@1
2026-08-18

案例

HOW
目标
Rack::Protection::PathTraversal unescapes URL-encoded directory traversal sequences and normalizes PATH_INFO for downstream Rack apps while restoring original PATH_INFO upon completion
符号
  • Rack::Protection::PathTraversal
环境
ruby
创建时间
2026-08-17T14:38:56Z

契约

  1. Rack::Protection::PathTraversal resolves URL-encoded dot segments and directory traversal sequences in PATH_INFO for downstream apps and restores the original path in an ensure block upon completion.
  2. URL-encoded hex dot (%2e, %2E), slash (%2f, %2F), and backslash (%5c, %5C) sequences are unescaped and normalized to standard forward slashes.
  3. Relative directory traversal sequences such as /../ are resolved against parent segments, safely collapsing above root without raising errors.
  4. Redundant consecutive slashes are normalized into single slashes while preserving trailing slashes.
  5. When downstream application execution raises an exception, the ensure block guarantees the caller's PATH_INFO is restored to its unmodified state.
  6. Empty or nil PATH_INFO values pass through without modification.

文件

  • Gemfile
  • Gemfile.lock
  • NOTES.md
  • csx.json
  • test/contract.rb

下载源代码构件 (tar.gz)

原始种子者

csx-seed