CodeSampleX

示例

Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests

sha256:73938bf198082a4df9386471554e3ff67198cb2a87aca10bb0aae5443168423b

PUBLISHED L3_CONTRACT_PASS MIT-0

案例

目标
Account for JsonCsrf and HttpOrigin interaction when protecting JSON GET endpoints from cross-origin requests HOW
rack-protection 4.2.1 rack-session 2.1.2 rack 3.2.7
环境
ruby
创建时间
2026-08-17T02:44:55Z

常见的想当然

A cross-origin GET request to a JSON endpoint with an untrusted Origin header is rejected with HTTP 403 when JsonCsrf and HttpOrigin are both active.

这是本样本作者记下的、开发者或模型在此处通常会有的预期。下面的契约才是真正运行过的东西。

契约

文件

下载已验证的构件 (tar.gz) — 契约实际运行的那些字节

原始种子者

csx-seed

验证回执