Flashtalking FTrack checks the published legacy collector payload.
The pack covers the exact legacy /lgc collector and the device payload emitted by the inspected official d9core SDK. It checks one remaining encodeURIComponent layer after form decoding, native types and fixed empty containers.
These findings are producer warnings. Current /img and ft.stat collectors, private backend rules and browser fingerprint parity remain unvalidated.
The nested encoding preserves literal plus values.
The outer form layer applies query decoding. The inner encodeURIComponent layer uses strict percent and UTF-8 decoding, with a literal plus kept intact. Unknown fields remain open.
What this pack matches
Rules
Codes are stable. A finding in CI, MCP, or the playground lands on the same id.
| Field | Required | What it checks | Rule ids | Source |
|---|---|---|---|---|
tbx |
optional | Form value after the first URL/form decode still contains one encodeURIComponent layer. Presence diagnostic severity: warning. | docs | |
https |
recommended | The published d9core producer sends this collector request over HTTPS. | vendor.flashtalking-ftrack.https |
docs |
|
optional | SDK d9legacy serializes one native device object. Unknown extra fields remain open. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. | vendor.flashtalking-ftrack.body..invalid |
docs |
D9_1 |
recommended | Date.getTime() milliseconds, not a service recency limit. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. | vendor.flashtalking-ftrack.body.D9_1.missingvendor.flashtalking-ftrack.body.D9_1.invalid |
docs |
D9_6 |
recommended | Flash version string or null, including mobile. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string or null. | vendor.flashtalking-ftrack.body.D9_6.missingvendor.flashtalking-ftrack.body.D9_6.invalid |
docs |
D9_7 |
recommended | Acrobat plugin string or ActiveX parseFloat number, or null. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string or number or null. | vendor.flashtalking-ftrack.body.D9_7.missingvendor.flashtalking-ftrack.body.D9_7.invalid |
docs |
D9_8 |
recommended | Silverlight version string or null. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string or null. | vendor.flashtalking-ftrack.body.D9_8.missingvendor.flashtalking-ftrack.body.D9_8.invalid |
docs |
D9_9 |
recommended | MIME descriptions array or null on browser access failure. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: array or null. | vendor.flashtalking-ftrack.body.D9_9.missingvendor.flashtalking-ftrack.body.D9_9.invalid |
docs |
D9_10 |
recommended | Plugin descriptions array or null on browser access failure. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: array or null. | vendor.flashtalking-ftrack.body.D9_10.missingvendor.flashtalking-ftrack.body.D9_10.invalid |
docs |
D9_61 |
recommended | The published SDK assigns a 32-character lowercase hexadecimal literal. Its service-side meaning is unpublished. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_61.missingvendor.flashtalking-ftrack.body.D9_61.emptyvendor.flashtalking-ftrack.body.D9_61.invalid |
docs |
D9_67 |
recommended | The published SDK assigns a 32-character lowercase hexadecimal literal. Its service-side meaning is unpublished. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_67.missingvendor.flashtalking-ftrack.body.D9_67.emptyvendor.flashtalking-ftrack.body.D9_67.invalid |
docs |
D9_18 |
recommended | This SDK snapshot emits an empty object. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. Maximum object properties: 0. | vendor.flashtalking-ftrack.body.D9_18.missingvendor.flashtalking-ftrack.body.D9_18.invalid |
docs |
D9_16 |
recommended | Date.getTimezoneOffset() integer minutes; no timezone registry inferred. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. | vendor.flashtalking-ftrack.body.D9_16.missingvendor.flashtalking-ftrack.body.D9_16.invalid |
docs |
D9_4 |
optional | Screen object is conditional on screen width or timezone offset; undefined members are omitted. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. | vendor.flashtalking-ftrack.body.D9_4.invalid |
docs |
D9_4.width |
optional | Screen width, when available. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. | vendor.flashtalking-ftrack.body.D9_4.width.invalid |
docs |
D9_4.height |
optional | Screen height, when available. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. | vendor.flashtalking-ftrack.body.D9_4.height.invalid |
docs |
D9_14 |
optional | navigator.platform when navigator is exposed on window. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_14.invalid |
docs |
D9_15 |
optional | navigator.language or legacy browserLanguage; no closed language enumeration. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_15.invalid |
docs |
D9_19 |
optional | navigator.appCodeName. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_19.invalid |
docs |
D9_123 |
optional | navigator.maxTouchPoints or zero. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. | vendor.flashtalking-ftrack.body.D9_123.invalid |
docs |
D9_33 |
recommended | Browser btoa of an indexed text fingerprint. It contains text, not JSON. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_33.missingvendor.flashtalking-ftrack.body.D9_33.emptyvendor.flashtalking-ftrack.body.D9_33.invalid |
docs |
D9_34 |
recommended | Murmurhash3 returns unsigned 32-bit h1 >>> 0. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. Maximum numeric value: 4294967295. | vendor.flashtalking-ftrack.body.D9_34.missingvendor.flashtalking-ftrack.body.D9_34.invalid |
docs |
D9_30 |
recommended | This SDK snapshot emits an empty array. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: array. Maximum array items: 0. | vendor.flashtalking-ftrack.body.D9_30.missingvendor.flashtalking-ftrack.body.D9_30.invalid |
docs |
D9_52 |
recommended | This SDK snapshot emits an empty object. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. Maximum object properties: 0. | vendor.flashtalking-ftrack.body.D9_52.missingvendor.flashtalking-ftrack.body.D9_52.invalid |
docs |
D9_57 |
recommended | Whether caller D9r.callback is a function. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: boolean. | vendor.flashtalking-ftrack.body.D9_57.missingvendor.flashtalking-ftrack.body.D9_57.invalid |
docs |
D9_58 |
optional | Caller-owned D9r. The source does not establish a server field inventory or enforce an object. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. | docs | |
D9_59 |
optional | Caller-owned D9v. Undefined values are omitted; account configuration stays opaque. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. | docs | |
D9_63 |
recommended | encodeURIComponent of top ancestor/current hostname, possibly empty, not an absolute URL. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_63.missingvendor.flashtalking-ftrack.body.D9_63.invalid |
docs |
D9_64 |
optional | devicePixelRatio when available, including fractional ratios. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: number. Minimum numeric value: 0. | vendor.flashtalking-ftrack.body.D9_64.invalid |
docs |
D9_66 |
recommended | encodeURIComponent of different referrer hostname or empty string. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body.D9_66.missingvendor.flashtalking-ftrack.body.D9_66.invalid |
docs |
|
optional | Each plugin or MIME entry is built by concatenating strings. Body scope: D9_9[]. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body..invalid |
docs |
|
optional | Each plugin or MIME entry is built by concatenating strings. Body scope: D9_10[]. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.body..invalid |
docs |
method |
optional | Both XHR and legacy XDomainRequest use POST. Complete HTTP capture contract. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.http.method.emptyvendor.flashtalking-ftrack.http.method.invalid |
docs |
content_type |
optional | XHR sends form MIME. XDomainRequest cannot set the header, so an absent MIME remains valid. Complete HTTP capture contract. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.http.content_type.emptyvendor.flashtalking-ftrack.http.content_type.invalid |
docs |
body_encoding |
optional | Complete HTTP capture contract. Applies when {"kind":"value_in","param":"body_encoding","values":["form"]}. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.http.body_encoding.invalid |
docs |
body.tbx |
recommended | SDK sends tbx in the form body. A bare URL has no body evidence and is not penalized. Complete HTTP capture contract. Applies when {"kind":"value_in","param":"body_encoding","values":["form"]}. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. | vendor.flashtalking-ftrack.http.body.tbx.missingvendor.flashtalking-ftrack.http.body.tbx.invalid |
docs |
Validate a payload
pixellint validate request @request.json --rulepack vendor/flashtalking-ftrack
Try this failing payload in the playground. An FTrack legacy capture with a malformed inner percent escape.
{
"url": "https://d9.flashtalking.com/lgc",
"method": "POST",
"headers": {
"content-type": "application/x-www-form-urlencoded"
},
"body": "tbx=%25GG"
}
cargo install pixellint
·
npm install pixellint