pub fn request_allowed(
origin: Option<&str>,
fetch_site: Option<&str>,
host: Option<&str>,
allowed: &AllowedOrigins,
) -> boolExpand description
Whether a request with these headers may proceed.
Sec-Fetch-Site is set by browsers only and cannot be set by page scripts, so it is
trusted when present. Without it, Origin must name the host the request was sent to.
A request with neither header did not come from a browser page.