<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/feed.rss.xml" type="text/xsl" media="screen"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>cindyliu923</title>
    <description/>
    <link>https://speakerdeck.com/cindyliu923</link>
    <atom:link rel="self" type="application/rss+xml" href="https://speakerdeck.com/cindyliu923.rss"/>
    <lastBuildDate>2026-08-08 06:33:09 -0400</lastBuildDate>
    <item>
      <title>從 2026 年 3 月 Rails 安全更新看三個常見的設計陷阱</title>
      <description>2026 年 3 月 23 日，Rails 一次釋出 7.2.3.1、8.0.4.1、8.1.2.1 三個版本，修補了多個 CVE，涵蓋 XSS、ReDoS、記憶體耗盡、路徑穿越、glob 注入等漏洞，是近年規模最大的一次。 本場演講不會逐一拆解 CVE，而是退一步看：這些漏洞之間是否藏著共同的設計陷阱？我會挑出最具代表性的幾個，歸納成三類：信任邊界錯置（內部狀態與外部輸入混用）、檔案系統 API 接受未過濾輸入（path traversal 與 glob injection）、以及「修一次不夠」的不完整修補。 每個陷阱會搭配實際漏洞程式碼與修補方式解說，並提供可立即套用的檢查清單。聽眾不需要資安背景，只要寫過 Rails 應用就能理解。</description>
      <media:content url="https://files.speakerdeck.com/presentations/1d81dbe2d6e04e54850edc58990ab44f/preview_slide_0.jpg?40240709" type="image/jpeg" medium="image"/>
      <content:encoded>2026 年 3 月 23 日，Rails 一次釋出 7.2.3.1、8.0.4.1、8.1.2.1 三個版本，修補了多個 CVE，涵蓋 XSS、ReDoS、記憶體耗盡、路徑穿越、glob 注入等漏洞，是近年規模最大的一次。 本場演講不會逐一拆解 CVE，而是退一步看：這些漏洞之間是否藏著共同的設計陷阱？我會挑出最具代表性的幾個，歸納成三類：信任邊界錯置（內部狀態與外部輸入混用）、檔案系統 API 接受未過濾輸入（path traversal 與 glob injection）、以及「修一次不夠」的不完整修補。 每個陷阱會搭配實際漏洞程式碼與修補方式解說，並提供可立即套用的檢查清單。聽眾不需要資安背景，只要寫過 Rails 應用就能理解。</content:encoded>
      <pubDate>Sat, 08 Aug 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/cindyliu923/cong-2026-nian-3-yue-rails-an-quan-geng-xin-kan-san-ge-chang-jian-de-she-ji-xian-jing</link>
      <guid>https://speakerdeck.com/cindyliu923/cong-2026-nian-3-yue-rails-an-quan-geng-xin-kan-san-ge-chang-jian-de-she-ji-xian-jing</guid>
    </item>
  </channel>
</rss>
