文件
websafe-kb/06-case-studies/generated-runs/gitea-gitea--CVE-2018-18926-20260318034937/assets/proof-dom.html

26 行
1.1 KiB
HTML

<!DOCTYPE html><html lang="zh-CN"><head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Gitea Proxy Boundary Fixture - proof</title>
<style>
body { font-family: sans-serif; background: #0f172a; color: #e2e8f0; margin: 0; padding: 32px; }
main { max-width: 900px; margin: 0 auto; background: #111827; border: 1px solid #334155; border-radius: 16px; padding: 24px; }
.proof { padding: 14px; border-radius: 12px; background: #14532d; color: #dcfce7; }
.baseline { padding: 14px; border-radius: 12px; background: #1e3a8a; color: #dbeafe; }
code { background: rgba(255,255,255,0.08); padding: 2px 6px; border-radius: 6px; }
</style>
</head>
<body>
<main>
<h1>Gitea Proxy Boundary Fixture</h1>
<p>Forwarded header trust boundary and admin gate fixture.</p>
<div class="proof">Proof active: trusted forwarded headers crossed the boundary</div>
<p>System: <code>gitea</code> / Family: <code>proxy-boundary</code></p>
<section id="admin-proof">Admin boundary bypass confirmed.</section>
</main>
</body></html>