I notice that ActionController::Session::AbstractStore is using
the environment keys 'rack.session' and 'rack.session.options' to
allow middleware in the stack to access the rails session.
This seems to be disallowed by the Rack specification http://rack.rubyforge.org/doc/fi...
"In addition to this, the Rack environment must include these
Rack-specific variables: rack.version rack.url_scheme rack.input
rack.errors rack.multithread rack.multiprocess rack.run_once
The server or the application can store their own data in the
environment, too. The keys must contain at least one dot, and
should be prefixed uniquely. The prefix rack. is reserved for use
with the Rack core distribution and must not be used
otherwise."
Although Rack::Lint does not enforce the absence of keys
prefixed by 'rack.' other than those listed, I think that's a bug
in Lint since it includes that last paragraph in its comments.
Is it possible to get the rack specification changed to bless
these two new environment variables in the rack namespace. If not,
should Rails change to use something within the spec before 2.3 is
officially released?