CodeSampleX

サンプル

Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests

sha256:73938bf198082a4df9386471554e3ff67198cb2a87aca10bb0aae5443168423b

PUBLISHED L3_CONTRACT_PASS MIT-0

ケース

ゴール
Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests HOW
パッケージ
rack-protection 4.2.1 rack-session 2.1.2 rack 3.2.7
環境
ruby
作成日
2026-08-17T02:44:55Z

よくある思い込み

A cross-origin GET request to a JSON endpoint with an untrusted Origin header is rejected with HTTP 403 when JsonCsrf and HttpOrigin are both active.

このサンプルの作者が、ここで開発者やモデルが期待するであろうこととして記録したもの。下の契約が実際に実行されたものだ。

コントラクト

ファイル

検証済みアーティファクトをダウンロード (tar.gz) — 契約が実行された正確なバイト列

オリジンシーダー

csx-seed

検証レシート