pub struct HttpAuthentication<T, F>where
T: FromRequest,{ /* private fields */ }Expand description
Middleware for checking HTTP authentication.
By default, if the extractor T fails (for example because the Authorization header is
missing), this middleware returns an error immediately, without calling the F callback.
To make authentication optional (or to implement multiple auth methods), wrap the extractor
in Option<T> or Result<T, T::Error>. In those cases, extraction never fails, so the
validator always runs and can decide how to proceed.
Otherwise, it will pass both the request and the parsed credentials into it. In case of
successful validation F callback is required to return the ServiceRequest back.
Implementations§
Source§impl<T, F, O> HttpAuthentication<T, F>where
T: FromRequest,
F: Fn(ServiceRequest, T) -> O,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>>,
impl<T, F, O> HttpAuthentication<T, F>where
T: FromRequest,
F: Fn(ServiceRequest, T) -> O,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>>,
Sourcepub fn with_fn(process_fn: F) -> HttpAuthentication<T, F>
pub fn with_fn(process_fn: F) -> HttpAuthentication<T, F>
Construct HttpAuthentication middleware with the provided auth extractor T and
validation callback F.
This function can be used to implement optional authentication and/or custom responses to missing authentication.
§Examples
§Required Basic Auth
async fn validator(
req: ServiceRequest,
credentials: BasicAuth,
) -> Result<ServiceRequest, (actix_web::Error, ServiceRequest)> {
eprintln!("{credentials:?}");
if credentials.user_id().contains('x') {
return Err((actix_web::error::ErrorBadRequest("user ID contains x"), req));
}
Ok(req)
}§Optional Bearer Auth (fallback to other auth methods)
async fn validator(
req: ServiceRequest,
credentials: Option<BearerAuth>,
) -> Result<ServiceRequest, (actix_web::Error, ServiceRequest)> {
let Some(credentials) = credentials else {
// No Authorization header; allow other auth methods (eg cookies/sessions) to proceed.
return Ok(req);
};
eprintln!("{credentials:?}");
if credentials.token().contains('x') {
return Err((actix_web::error::ErrorBadRequest("token contains x"), req));
}
Ok(req)
}Source§impl<F, O> HttpAuthentication<BasicAuth, F>where
F: Fn(ServiceRequest, BasicAuth) -> O,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>>,
impl<F, O> HttpAuthentication<BasicAuth, F>where
F: Fn(ServiceRequest, BasicAuth) -> O,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>>,
Sourcepub fn basic(process_fn: F) -> Self
pub fn basic(process_fn: F) -> Self
Construct HttpAuthentication middleware for the HTTP “Basic” authentication scheme.
§Examples
// In this example validator returns immediately, but since it is required to return
// anything that implements `IntoFuture` trait, it can be extended to query database or to
// do something else in a async manner.
async fn validator(
req: ServiceRequest,
credentials: BasicAuth,
) -> Result<ServiceRequest, (Error, ServiceRequest)> {
// All users are great and more than welcome!
Ok(req)
}
let middleware = HttpAuthentication::basic(validator);Source§impl<F, O> HttpAuthentication<BearerAuth, F>where
F: Fn(ServiceRequest, BearerAuth) -> O,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>>,
impl<F, O> HttpAuthentication<BearerAuth, F>where
F: Fn(ServiceRequest, BearerAuth) -> O,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>>,
Sourcepub fn bearer(process_fn: F) -> Self
pub fn bearer(process_fn: F) -> Self
Construct HttpAuthentication middleware for the HTTP “Bearer” authentication scheme.
§Examples
async fn validator(
req: ServiceRequest,
credentials: BearerAuth
) -> Result<ServiceRequest, (Error, ServiceRequest)> {
if credentials.token() == "mF_9.B5f-4.1JqM" {
Ok(req)
} else {
let config = req.app_data::<bearer::Config>()
.cloned()
.unwrap_or_default()
.scope("urn:example:channel=HBO&urn:example:rating=G,PG-13");
Err((AuthenticationError::from(config).into(), req))
}
}
let middleware = HttpAuthentication::bearer(validator);Trait Implementations§
Source§impl<T, F: Clone> Clone for HttpAuthentication<T, F>where
T: FromRequest + Clone,
impl<T, F: Clone> Clone for HttpAuthentication<T, F>where
T: FromRequest + Clone,
Source§fn clone(&self) -> HttpAuthentication<T, F>
fn clone(&self) -> HttpAuthentication<T, F>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl<T, F: Debug> Debug for HttpAuthentication<T, F>where
T: FromRequest + Debug,
impl<T, F: Debug> Debug for HttpAuthentication<T, F>where
T: FromRequest + Debug,
Source§impl<S, B, T, F, O> Transform<S, ServiceRequest> for HttpAuthentication<T, F>where
S: Service<ServiceRequest, Response = ServiceResponse<B>, Error = Error> + 'static,
S::Future: 'static,
F: Fn(ServiceRequest, T) -> O + 'static,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>> + 'static,
T: FromRequest + 'static,
B: MessageBody + 'static,
impl<S, B, T, F, O> Transform<S, ServiceRequest> for HttpAuthentication<T, F>where
S: Service<ServiceRequest, Response = ServiceResponse<B>, Error = Error> + 'static,
S::Future: 'static,
F: Fn(ServiceRequest, T) -> O + 'static,
O: Future<Output = Result<ServiceRequest, (Error, ServiceRequest)>> + 'static,
T: FromRequest + 'static,
B: MessageBody + 'static,
Source§type Response = ServiceResponse<EitherBody<B>>
type Response = ServiceResponse<EitherBody<B>>
Source§type Transform = AuthenticationMiddleware<S, F, T>
type Transform = AuthenticationMiddleware<S, F, T>
TransformService value created by this factory