Skip to main content

check_origin

Function check_origin 

Source
pub fn check_origin(
    headers: &HeaderMap,
    base_url: &str,
) -> Result<(), AdminError>
Expand description

Refuses a request whose Origin or Sec-Fetch-Site says it came from somewhere else.

Both headers are checked only when present: a non-browser client (curl, a script) sends neither and is not the threat this addresses. Its value is covering the login request, which carries no session and therefore no CSRF token to check.