CodeSampleX

Beispiel

Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close is called on the upstream body object when the request is denied

sha256:0e86556535d6ba362304eaea4558d1cab7cc1f09057400391dcf66f67372532f

PUBLISHED L3_CONTRACT_PASS MIT-0

Fall

Ziel
Rack::Protection::JsonCsrf calls app.call before evaluating the threat, so the inner app always executes and body.close is called on the upstream body object when the request is denied HOW
Pakete
rack-protection 4.2.1
Umgebung
ruby
Erstellt
2026-08-17T02:45:21Z

Häufige Annahme

Protection middleware short-circuits the request pipeline before the inner app runs, so an app behind JsonCsrf only executes when the request is allowed

So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.

Contract

Dateien

Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief

Ursprungs-Seeder

csx-seed

Verifizierungsbelege