Skip to main content

security_headers

Function security_headers 

Source
pub fn security_headers() -> (SetResponseHeaderLayer<HeaderValue>, SetResponseHeaderLayer<HeaderValue>, SetResponseHeaderLayer<HeaderValue>)
Expand description

The three response-hardening headers both listeners apply.

A shared constructor rather than two copies: the admin router is not nested inside build_app and so inherits none of its layers, but these three are a security control, and two hand-written copies of one are a control that drifts. Everything genuinely per-listener — the admin’s Cache-Control, Referrer-Policy and CSP, this one’s admission and nonce layers — stays at its own call site.

A tuple because tower implements Layer for one, so the three still apply as three separate layers rather than being collapsed into a wrapper type. They set distinct headers, so their order among themselves carries no meaning.