Ejemplo
Prevent Rack::Protection::AuthenticityToken from denying safe GET requests when session middleware is absent, while validating masked and unmasked CSRF tokens on unsafe requests
sha256:cbdc3c3ea3ec557a27fc8fb08067ec858f4e4f30056c1856d23e37bef67466a5
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Caso
- Objetivo
- Prevent Rack::Protection::AuthenticityToken from denying safe GET requests when session middleware is absent, while validating masked and unmasked CSRF tokens on unsafe requests HOW
- Paquetes
- rack-protection 4.2.1
- Entorno
- ruby
- Creado
- 2026-08-16T16:29:45Z
Lo que suele suponerse
AuthenticityToken passes safe GET requests through to downstream handlers without requiring an active session store.
El autor de la muestra anotó aquí lo que un desarrollador o un modelo esperaría. El contrato de abajo es lo que realmente se ejecutó.
Contrato
- AuthenticityToken responds with 403 Forbidden on safe GET requests when env lacks rack.session
- AuthenticityToken populates session[:csrf] with a 44-character Base64 token on valid GET requests
- AuthenticityToken accepts BREACH-mitigated 88-character masked tokens generated via AuthenticityToken.token
- AuthenticityToken accepts raw unmasked tokens matching session[:csrf] over HTTP_X_CSRF_TOKEN
- AuthenticityToken rejects unsafe POST requests with invalid tokens with 403 Forbidden and text/plain body
- AuthenticityToken restricts path-scoped per-form tokens strictly to matching request paths
Archivos
- Gemfile
- NOTES.md
- csx.json
- test/contract.rb
Descargar el artefacto verificado (tar.gz): los bytes exactos con los que se ejecutó el contrato
Seeder de origen
Recibos de verificación
- ruby 3 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · rubygems@1 · 2026-08-16 · ed25519:d91480838ac982c9