Skip to main content

FilterPolicy

Struct FilterPolicy 

Source
pub struct FilterPolicy { /* private fields */ }
Expand description

The configured checks, the rules over them, and how the middleware turns a peer address into a client address.

Cheap to clone behind the Arc it is always held in.

Implementations§

Source§

impl FilterPolicy

Source

pub fn new( checks: Vec<(String, Arc<dyn Check>)>, rules: Vec<Rule>, default_effect: Effect, proxy: ProxyPolicy, ) -> Self

Assembles a policy, deriving each rule’s stages from its checks.

The stage intersection is computed here rather than passed in, so the one place that knows the rule is what fills it in. A rule naming a check that does not exist gets StageSet::none and therefore never runs — the builder refuses that configuration at startup, and this is only the net under it.

Source

pub fn proxy(&self) -> &ProxyPolicy

How the middleware turns a peer address plus headers into a client IP.

Source

pub fn default_effect(&self) -> Effect

What happens when a rule was applicable at a stage and none matched.

Source

pub fn has_rules_at(&self, stage: Stage) -> bool

Whether any rule is evaluated at stage.

post_finalize asks about Stage::Identifiers to skip re-parsing the CSR when nothing would look at the result.

Source

pub fn is_active(&self) -> bool

Whether the policy would decide anything at all.

Source

pub fn checks(&self) -> Vec<CheckSummary<'_>>

Every configured check, for acme-proxy filter show and for working out which checks an evaluation short-circuited past.

Source

pub fn rules(&self) -> Vec<RuleSummary<'_>>

Every rule, in evaluation order.

Source

pub fn needs_eab(&self) -> bool

Whether any check asks about the requesting account’s EAB credential.

The handlers gate the two database reads that resolve one on this, so a policy with no eab check pays nothing for the field’s existence.

Source

pub async fn evaluate_connection( &self, context: &ConnectionContext<'_>, ) -> Evaluation

Evaluates the connection stage, keeping the whole trace.

The trace is what acme-proxy filter explain renders; a request path wants FilterPolicy::check_connection, which logs the decision.

Source

pub async fn evaluate_identifiers( &self, context: &IdentifierContext<'_>, ) -> Evaluation

Evaluates the identifier stage, keeping the whole trace.

Source

pub async fn check_connection(&self, context: &ConnectionContext<'_>) -> Outcome

The connection stage’s answer, with the decision logged.

Source

pub async fn check_identifiers( &self, context: &IdentifierContext<'_>, ) -> Outcome

The identifier stage’s answer, with the decision logged.

The hook is logged as newOrder or CSR rather than identifiers, because which of the two refused is the first thing an operator reading the line wants to know.

Trait Implementations§

Source§

impl Debug for FilterPolicy

Source§

fn fmt(&self, formatter: &mut Formatter<'_>) -> Result

dyn Check is not Debug, so show the names and conditions — which is the only part worth reading anyway.

Source§

impl Default for FilterPolicy

Source§

fn default() -> Self

No checks and no rules: every stage has an empty applicable set, so everything is allowed. This is what a server with no [filter] section and every test that does not care about filtering uses.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more