Exercise 1: Request Method & Path on the Real Debug Page — Possible Solution ==================================================================== THE EXTENDED MIDDLEWARE ------------------------------ def make_debug_middleware(app): def middleware(request, next_): try: return next_(request) except Exception: tb_text = traceback.format_exc() if app.debug: body = ( "
{html.escape(request.method)} {html.escape(request.path)}
" f"{html.escape(tb_text)}"
)
return Response(body, status=500, content_type='text/html')
return Response('500 Internal Server Error', status=500)
return middleware
VERIFIED, REAL RESULT
------------------------------
A real live request to GET /widgets/42 (a dynamic route whose handler
deliberately raises an exception) returns a real 500 whose body
contains the exact literal text "GET /widgets/42" - confirmed present
directly in the client's own received response, not just logged
server-side.
WHY THIS WORKS AS AN ANSWER
------------------------------
Both request.method and request.path are run through html.escape()
before being inserted, matching the exact same discipline already
applied to the traceback text itself - a real path segment could, in
principle, contain characters an attacker chose, so treating it as
untrusted here is the correct default, not an unnecessary precaution.