Beispiel
Prevent Rack::Protection::AuthenticityToken from denying safe GET requests when session middleware is absent, while validating masked and unmasked CSRF tokens on unsafe requests
sha256:cbdc3c3ea3ec557a27fc8fb08067ec858f4e4f30056c1856d23e37bef67466a5
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Fall
- Ziel
- Prevent Rack::Protection::AuthenticityToken from denying safe GET requests when session middleware is absent, while validating masked and unmasked CSRF tokens on unsafe requests HOW
- Pakete
- rack-protection 4.2.1
- Umgebung
- ruby
- Erstellt
- 2026-08-16T16:29:45Z
Häufige Annahme
AuthenticityToken passes safe GET requests through to downstream handlers without requiring an active session store.
So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.
Contract
- AuthenticityToken responds with 403 Forbidden on safe GET requests when env lacks rack.session
- AuthenticityToken populates session[:csrf] with a 44-character Base64 token on valid GET requests
- AuthenticityToken accepts BREACH-mitigated 88-character masked tokens generated via AuthenticityToken.token
- AuthenticityToken accepts raw unmasked tokens matching session[:csrf] over HTTP_X_CSRF_TOKEN
- AuthenticityToken rejects unsafe POST requests with invalid tokens with 403 Forbidden and text/plain body
- AuthenticityToken restricts path-scoped per-form tokens strictly to matching request paths
Dateien
- Gemfile
- NOTES.md
- csx.json
- test/contract.rb
Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief
Ursprungs-Seeder
Verifizierungsbelege
- ruby 3 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · rubygems@1 · 2026-08-16 · ed25519:d91480838ac982c9