Beispiel
Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests
sha256:73938bf198082a4df9386471554e3ff67198cb2a87aca10bb0aae5443168423b
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Fall
- Ziel
- Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests HOW
- Pakete
- rack-protection 4.2.1 rack-session 2.1.2 rack 3.2.7
- Umgebung
- ruby
- Erstellt
- 2026-08-17T02:44:55Z
Häufige Annahme
A cross-origin GET request to a JSON endpoint with an untrusted Origin header is rejected with HTTP 403 when JsonCsrf and HttpOrigin are both active.
So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.
Contract
- A cross-origin JSON GET with an untrusted Origin returns 200 because JsonCsrf defers to HttpOrigin while HttpOrigin treats GET as safe
- The same Origin-bearing GET also returns 200 through the default Rack::Protection stack backed by Rack::Session::Cookie
- A JSON GET with an untrusted Referer and no Origin is rejected with 403 by JsonCsrf
- A POST with an untrusted Origin is rejected with 403 by HttpOrigin
Dateien
- Gemfile
- Gemfile.lock
- NOTES.md
- csx.json
- test/contract.rb
Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief
Ursprungs-Seeder
Verifizierungsbelege
- ruby 3 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · rubygems@1 · 2026-08-17 · ed25519:d91480838ac982c9