pub struct PendingMfaSubmit(pub PendingMfa);Expand description
PendingMfa with the origin gate only, and no CSRF check.
The omission is deliberate, and is the same one POST /ui/login already
makes one step earlier: the challenge page is a plain form – sign-in must
work with JavaScript off, which tests/admin_pages.rs pins for login.html
– and check_csrf reads a header a form cannot set. Teaching it to read a
form field instead would be a second CSRF path, which is what
pages::auth’s whole shape exists to prevent.
What covers the route is check_origin, and the residual risk is nil: a
cross-site forger would need a valid code for a session they cannot read,
and success would only complete the victim’s own login.
Tuple Fields§
§0: PendingMfaTrait Implementations§
Source§impl Debug for PendingMfaSubmit
impl Debug for PendingMfaSubmit
Source§impl FromRequestParts<AdminState> for PendingMfaSubmit
impl FromRequestParts<AdminState> for PendingMfaSubmit
Source§type Rejection = AdminError
type Rejection = AdminError
If the extractor fails it’ll use this “rejection” type. A rejection is
a kind of error that can be converted into a response.
Source§async fn from_request_parts(
parts: &mut Parts,
state: &AdminState,
) -> Result<Self, Self::Rejection>
async fn from_request_parts( parts: &mut Parts, state: &AdminState, ) -> Result<Self, Self::Rejection>
Perform the extraction.
Auto Trait Implementations§
impl Freeze for PendingMfaSubmit
impl RefUnwindSafe for PendingMfaSubmit
impl Send for PendingMfaSubmit
impl Sync for PendingMfaSubmit
impl Unpin for PendingMfaSubmit
impl UnsafeUnpin for PendingMfaSubmit
impl UnwindSafe for PendingMfaSubmit
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<S, T> FromRequest<S, ViaParts> for T
impl<S, T> FromRequest<S, ViaParts> for T
Source§type Rejection = <T as FromRequestParts<S>>::Rejection
type Rejection = <T as FromRequestParts<S>>::Rejection
If the extractor fails it’ll use this “rejection” type. A rejection is
a kind of error that can be converted into a response.
Source§fn from_request(
req: Request<Body>,
state: &S,
) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
fn from_request( req: Request<Body>, state: &S, ) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
Perform the extraction.
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more