codesamplex

Sample

Require explicit opt-in to enable session hijacking protection in Rack::Protection 4.x rather than relying on default middleware inclusion.

sha256:211d7395fda74de66490b727f70e99004de2ff33d235445d7c9a625f290745c2

PUBLISHED L3_CONTRACT_PASS MIT-0

Case

Goal
Require explicit opt-in to enable session hijacking protection in Rack::Protection 4.x rather than relying on default middleware inclusion. HOW
Packages
rack-protection 4.2.1
Environment
ruby
Created
2026-08-16T16:38:09Z

Commonly assumed

Initializing Rack::Protection with default options includes session hijacking defense that clears the session when a client user-agent header changes.

The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.

Contract

Files

Download the verified artifact (tar.gz) — the exact bytes the contract ran against

Origin Seeder

csx-seed

Verification receipts