Exercise 1: Request Method & Path on the Real Debug Page — Possible Solution ==================================================================== THE EXTENDED MIDDLEWARE ------------------------------ def make_debug_middleware(app): def middleware(request, next_): try: return next_(request) except Exception: tb_text = traceback.format_exc() if app.debug: body = ( "

500 Internal Server Error

" f"

{html.escape(request.method)} {html.escape(request.path)}

" f"
{html.escape(tb_text)}
" ) return Response(body, status=500, content_type='text/html') return Response('500 Internal Server Error', status=500) return middleware VERIFIED, REAL RESULT ------------------------------ A real live request to GET /widgets/42 (a dynamic route whose handler deliberately raises an exception) returns a real 500 whose body contains the exact literal text "GET /widgets/42" - confirmed present directly in the client's own received response, not just logged server-side. WHY THIS WORKS AS AN ANSWER ------------------------------ Both request.method and request.path are run through html.escape() before being inserted, matching the exact same discipline already applied to the traceback text itself - a real path segment could, in principle, contain characters an attacker chose, so treating it as untrusted here is the correct default, not an unnecessary precaution.