pub struct FilterPolicy { /* private fields */ }Expand description
The configured checks, the rules over them, and how the middleware turns a peer address into a client address.
Cheap to clone behind the Arc it is always held in.
Implementations§
Source§impl FilterPolicy
impl FilterPolicy
Sourcepub fn new(
checks: Vec<(String, Arc<dyn Check>)>,
rules: Vec<Rule>,
default_effect: Effect,
proxy: ProxyPolicy,
) -> Self
pub fn new( checks: Vec<(String, Arc<dyn Check>)>, rules: Vec<Rule>, default_effect: Effect, proxy: ProxyPolicy, ) -> Self
Assembles a policy, deriving each rule’s stages from its checks.
The stage intersection is computed here rather than passed in, so the
one place that knows the rule is what fills it in. A rule naming a check
that does not exist gets StageSet::none and therefore never runs —
the builder refuses that configuration at startup, and this is only the
net under it.
Sourcepub fn proxy(&self) -> &ProxyPolicy
pub fn proxy(&self) -> &ProxyPolicy
How the middleware turns a peer address plus headers into a client IP.
Sourcepub fn default_effect(&self) -> Effect
pub fn default_effect(&self) -> Effect
What happens when a rule was applicable at a stage and none matched.
Sourcepub fn has_rules_at(&self, stage: Stage) -> bool
pub fn has_rules_at(&self, stage: Stage) -> bool
Whether any rule is evaluated at stage.
post_finalize asks about Stage::Identifiers to skip re-parsing the
CSR when nothing would look at the result.
Sourcepub fn checks(&self) -> Vec<CheckSummary<'_>>
pub fn checks(&self) -> Vec<CheckSummary<'_>>
Every configured check, for acme-proxy filter show and for working
out which checks an evaluation short-circuited past.
Sourcepub fn rules(&self) -> Vec<RuleSummary<'_>>
pub fn rules(&self) -> Vec<RuleSummary<'_>>
Every rule, in evaluation order.
Sourcepub fn needs_eab(&self) -> bool
pub fn needs_eab(&self) -> bool
Whether any check asks about the requesting account’s EAB credential.
The handlers gate the two database reads that resolve one on this, so a
policy with no eab check pays nothing for the field’s existence.
Sourcepub async fn evaluate_connection(
&self,
context: &ConnectionContext<'_>,
) -> Evaluation
pub async fn evaluate_connection( &self, context: &ConnectionContext<'_>, ) -> Evaluation
Evaluates the connection stage, keeping the whole trace.
The trace is what acme-proxy filter explain renders; a request path
wants FilterPolicy::check_connection, which logs the decision.
Sourcepub async fn evaluate_identifiers(
&self,
context: &IdentifierContext<'_>,
) -> Evaluation
pub async fn evaluate_identifiers( &self, context: &IdentifierContext<'_>, ) -> Evaluation
Evaluates the identifier stage, keeping the whole trace.
Sourcepub async fn check_connection(&self, context: &ConnectionContext<'_>) -> Outcome
pub async fn check_connection(&self, context: &ConnectionContext<'_>) -> Outcome
The connection stage’s answer, with the decision logged.
Sourcepub async fn check_identifiers(
&self,
context: &IdentifierContext<'_>,
) -> Outcome
pub async fn check_identifiers( &self, context: &IdentifierContext<'_>, ) -> Outcome
The identifier stage’s answer, with the decision logged.
The hook is logged as newOrder or CSR rather than identifiers,
because which of the two refused is the first thing an operator reading
the line wants to know.
Trait Implementations§
Source§impl Debug for FilterPolicy
impl Debug for FilterPolicy
Auto Trait Implementations§
impl !Freeze for FilterPolicy
impl !RefUnwindSafe for FilterPolicy
impl !UnwindSafe for FilterPolicy
impl Send for FilterPolicy
impl Sync for FilterPolicy
impl Unpin for FilterPolicy
impl UnsafeUnpin for FilterPolicy
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more