pixellint

Flashtalking FTrack checks the published legacy collector payload.

The pack covers the exact legacy /lgc collector and the device payload emitted by the inspected official d9core SDK. It checks one remaining encodeURIComponent layer after form decoding, native types and fixed empty containers.

These findings are producer warnings. Current /img and ft.stat collectors, private backend rules and browser fingerprint parity remain unvalidated.

The nested encoding preserves literal plus values.

The outer form layer applies query decoding. The inner encodeURIComponent layer uses strict percent and UTF-8 decoding, with a literal plus kept intact. Unknown fields remain open.

What this pack matches

Hosts
d9.flashtalking.com
Paths
/lgc
Vendor docs
d9.flashtalking.com/d9core

Rules

Codes are stable. A finding in CI, MCP, or the playground lands on the same id.

Field Required What it checks Rule ids Source
tbx optional Form value after the first URL/form decode still contains one encodeURIComponent layer. Presence diagnostic severity: warning. docs
https recommended The published d9core producer sends this collector request over HTTPS. vendor.flashtalking-ftrack.https docs
optional SDK d9legacy serializes one native device object. Unknown extra fields remain open. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. vendor.flashtalking-ftrack.body..invalid docs
D9_1 recommended Date.getTime() milliseconds, not a service recency limit. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. vendor.flashtalking-ftrack.body.D9_1.missing
vendor.flashtalking-ftrack.body.D9_1.invalid
docs
D9_6 recommended Flash version string or null, including mobile. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string or null. vendor.flashtalking-ftrack.body.D9_6.missing
vendor.flashtalking-ftrack.body.D9_6.invalid
docs
D9_7 recommended Acrobat plugin string or ActiveX parseFloat number, or null. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string or number or null. vendor.flashtalking-ftrack.body.D9_7.missing
vendor.flashtalking-ftrack.body.D9_7.invalid
docs
D9_8 recommended Silverlight version string or null. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string or null. vendor.flashtalking-ftrack.body.D9_8.missing
vendor.flashtalking-ftrack.body.D9_8.invalid
docs
D9_9 recommended MIME descriptions array or null on browser access failure. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: array or null. vendor.flashtalking-ftrack.body.D9_9.missing
vendor.flashtalking-ftrack.body.D9_9.invalid
docs
D9_10 recommended Plugin descriptions array or null on browser access failure. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: array or null. vendor.flashtalking-ftrack.body.D9_10.missing
vendor.flashtalking-ftrack.body.D9_10.invalid
docs
D9_61 recommended The published SDK assigns a 32-character lowercase hexadecimal literal. Its service-side meaning is unpublished. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_61.missing
vendor.flashtalking-ftrack.body.D9_61.empty
vendor.flashtalking-ftrack.body.D9_61.invalid
docs
D9_67 recommended The published SDK assigns a 32-character lowercase hexadecimal literal. Its service-side meaning is unpublished. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_67.missing
vendor.flashtalking-ftrack.body.D9_67.empty
vendor.flashtalking-ftrack.body.D9_67.invalid
docs
D9_18 recommended This SDK snapshot emits an empty object. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. Maximum object properties: 0. vendor.flashtalking-ftrack.body.D9_18.missing
vendor.flashtalking-ftrack.body.D9_18.invalid
docs
D9_16 recommended Date.getTimezoneOffset() integer minutes; no timezone registry inferred. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. vendor.flashtalking-ftrack.body.D9_16.missing
vendor.flashtalking-ftrack.body.D9_16.invalid
docs
D9_4 optional Screen object is conditional on screen width or timezone offset; undefined members are omitted. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. vendor.flashtalking-ftrack.body.D9_4.invalid docs
D9_4.width optional Screen width, when available. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. vendor.flashtalking-ftrack.body.D9_4.width.invalid docs
D9_4.height optional Screen height, when available. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. vendor.flashtalking-ftrack.body.D9_4.height.invalid docs
D9_14 optional navigator.platform when navigator is exposed on window. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_14.invalid docs
D9_15 optional navigator.language or legacy browserLanguage; no closed language enumeration. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_15.invalid docs
D9_19 optional navigator.appCodeName. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_19.invalid docs
D9_123 optional navigator.maxTouchPoints or zero. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. vendor.flashtalking-ftrack.body.D9_123.invalid docs
D9_33 recommended Browser btoa of an indexed text fingerprint. It contains text, not JSON. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_33.missing
vendor.flashtalking-ftrack.body.D9_33.empty
vendor.flashtalking-ftrack.body.D9_33.invalid
docs
D9_34 recommended Murmurhash3 returns unsigned 32-bit h1 >>> 0. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: integer. Minimum numeric value: 0. Maximum numeric value: 4294967295. vendor.flashtalking-ftrack.body.D9_34.missing
vendor.flashtalking-ftrack.body.D9_34.invalid
docs
D9_30 recommended This SDK snapshot emits an empty array. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: array. Maximum array items: 0. vendor.flashtalking-ftrack.body.D9_30.missing
vendor.flashtalking-ftrack.body.D9_30.invalid
docs
D9_52 recommended This SDK snapshot emits an empty object. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: object. Maximum object properties: 0. vendor.flashtalking-ftrack.body.D9_52.missing
vendor.flashtalking-ftrack.body.D9_52.invalid
docs
D9_57 recommended Whether caller D9r.callback is a function. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: boolean. vendor.flashtalking-ftrack.body.D9_57.missing
vendor.flashtalking-ftrack.body.D9_57.invalid
docs
D9_58 optional Caller-owned D9r. The source does not establish a server field inventory or enforce an object. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. docs
D9_59 optional Caller-owned D9v. Undefined values are omitted; account configuration stays opaque. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. docs
D9_63 recommended encodeURIComponent of top ancestor/current hostname, possibly empty, not an absolute URL. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_63.missing
vendor.flashtalking-ftrack.body.D9_63.invalid
docs
D9_64 optional devicePixelRatio when available, including fractional ratios. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: number. Minimum numeric value: 0. vendor.flashtalking-ftrack.body.D9_64.invalid docs
D9_66 recommended encodeURIComponent of different referrer hostname or empty string. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body.D9_66.missing
vendor.flashtalking-ftrack.body.D9_66.invalid
docs
optional Each plugin or MIME entry is built by concatenating strings. Body scope: D9_9[]. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body..invalid docs
optional Each plugin or MIME entry is built by concatenating strings. Body scope: D9_10[]. Decoded body source: tbx. Encoding: percent_encoded_json. Strict percent and UTF-8 decoding preserves literal plus after the outer transport layer. Decoding diagnostic severity: warning. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.body..invalid docs
method optional Both XHR and legacy XDomainRequest use POST. Complete HTTP capture contract. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.http.method.empty
vendor.flashtalking-ftrack.http.method.invalid
docs
content_type optional XHR sends form MIME. XDomainRequest cannot set the header, so an absent MIME remains valid. Complete HTTP capture contract. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.http.content_type.empty
vendor.flashtalking-ftrack.http.content_type.invalid
docs
body_encoding optional Complete HTTP capture contract. Applies when {"kind":"value_in","param":"body_encoding","values":["form"]}. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.http.body_encoding.invalid docs
body.tbx recommended SDK sends tbx in the form body. A bare URL has no body evidence and is not penalized. Complete HTTP capture contract. Applies when {"kind":"value_in","param":"body_encoding","values":["form"]}. Presence diagnostic severity: warning. Evidence: vendor template. Native JSON type: string. vendor.flashtalking-ftrack.http.body.tbx.missing
vendor.flashtalking-ftrack.http.body.tbx.invalid
docs

Validate a payload

pixellint validate request @request.json --rulepack vendor/flashtalking-ftrack

Try this failing payload in the playground. An FTrack legacy capture with a malformed inner percent escape.

{
  "url": "https://d9.flashtalking.com/lgc",
  "method": "POST",
  "headers": {
    "content-type": "application/x-www-form-urlencoded"
  },
  "body": "tbx=%25GG"
}

cargo install pixellint · npm install pixellint