Skip to main content

request_allowed

Function request_allowed 

Source
pub fn request_allowed(
    origin: Option<&str>,
    fetch_site: Option<&str>,
    host: Option<&str>,
    allowed: &AllowedOrigins,
) -> bool
Expand description

Whether a request with these headers may proceed.

Sec-Fetch-Site is set by browsers only and cannot be set by page scripts, so it is trusted when present. Without it, Origin must name the host the request was sent to. A request with neither header did not come from a browser page.