1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
//! `Link: rel="index"` response middleware (RFC 8555 §7.1).
//!
//! §7.1: "The `index` link relation is present on all resources other than the
//! directory and indicates the URL of the directory." It is how a client that
//! holds only a resource URL — an order it stored months ago, say — finds its
//! way back to the endpoint that minted it.
//!
//! Two properties are load-bearing:
//!
//! - **The header is appended, never set.** `post_challenge` already sends
//! `Link: …;rel="up"` (RFC 8555 §7.5.1), which certbot's `acme` library
//! requires; overwriting it would break challenge validation for every
//! client that reads it.
//! - **The directory itself is skipped**, per the "other than the directory"
//! half of §7.1 — a directory pointing at itself says nothing.
//!
//! Living in the profile router means the path seen here is already
//! prefix-stripped by `Router::nest`, the same convention `verify_jws` relies
//! on, so the comparison is against the bare `/directory`.
use ;
use DIRECTORY;
/// Adds `Link: <directory>;rel="index"` to every response but the
/// directory's own.
pub async