pub fn security_headers() -> (SetResponseHeaderLayer<HeaderValue>, SetResponseHeaderLayer<HeaderValue>, SetResponseHeaderLayer<HeaderValue>)Expand description
The three response-hardening headers both listeners apply.
A shared constructor rather than two copies: the admin router is not nested
inside build_app and so inherits none of its layers, but these three are
a security control, and two hand-written copies of one are a control that
drifts. Everything genuinely per-listener — the admin’s Cache-Control,
Referrer-Policy and CSP, this one’s admission and nonce layers — stays at
its own call site.
A tuple because tower implements Layer for one, so the
three still apply as three separate layers rather than being collapsed into
a wrapper type. They set distinct headers, so their order among themselves
carries no meaning.