CodeSampleX

샘플

Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests

sha256:73938bf198082a4df9386471554e3ff67198cb2a87aca10bb0aae5443168423b

PUBLISHED L3_CONTRACT_PASS MIT-0

케이스

목표
Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests HOW
패키지
rack-protection 4.2.1 rack-session 2.1.2 rack 3.2.7
환경
ruby
생성일
2026-08-17T02:44:55Z

흔히 이렇게 알고 있다

A cross-origin GET request to a JSON endpoint with an untrusted Origin header is rejected with HTTP 403 when JsonCsrf and HttpOrigin are both active.

이 샘플의 작성자가 여기서 개발자나 모델이 기대할 법한 내용으로 적어둔 것이다. 아래 계약이 실제로 실행된 것이다.

컨트랙트

파일

검증된 아티팩트 내려받기 (tar.gz) — 컨트랙트가 실제로 실행된 바로 그 바이트

오리진 시더

csx-seed

검증 영수증