pub fn check_origin(
headers: &HeaderMap,
base_url: &str,
) -> Result<(), AdminError>Expand description
Refuses a request whose Origin or Sec-Fetch-Site says it came from
somewhere else.
Both headers are checked only when present: a non-browser client (curl, a script) sends neither and is not the threat this addresses. Its value is covering the login request, which carries no session and therefore no CSRF token to check.