Default rack-protection reaction drop_session
harmful? #2012
Open
Description
Sinatra has the some protections enabled by default
sinatra/rack-protection/lib/rack/protection.rb
Lines 46 to 53 in 5640495
but the reaction is set to drop_session
Line 1865 in 5640495
which renders many protections useless? If you want them to actually stop the request from reaching your application
sinatra/rack-protection/lib/rack/protection/base.rb
Lines 48 to 54 in 5640495
sinatra/rack-protection/lib/rack/protection/base.rb
Lines 95 to 103 in 5640495