pub struct SecretSubstitution {
pub headers: bool,
pub header_fields: Vec<String>,
pub query: bool,
pub body: bool,
}Expand description
Request locations where a placeholder can be substituted with its secret.
Fields§
§headers: boolSubstitute in HTTP headers (default: true).
header_fields: Vec<String>Restrict header substitution to these header field names.
Requires headers to be true; a non-empty list with
header substitution disabled is rejected as contradictory. An empty list
(the default) allows every header field. When non-empty, the
placeholder is substituted only in the named fields (matched ASCII
case-insensitively); a placeholder found in any other header field is
treated as a disabled location: on a verified allowed destination it is
forwarded unchanged, while other destinations follow the violation
policy.
Prefer an allowlist containing only the intended credential header
(typically Authorization). Substituting in every header lets an
untrusted guest place the placeholder in a header the upstream host
reflects back in its response (or otherwise exposes), which would let
the guest read the real secret out of that response.
Names must be valid HTTP field names (RFC 9110 token).
query: boolSubstitute in URL query parameters (default: false).
body: boolSubstitute in request body (default: false).
Fixed-length HTTP/1 bodies up to 16 MiB update Content-Length;
larger fixed-length bodies are blocked. Chunked HTTP/1 bodies are
decoded and re-encoded with fresh chunk sizes. Encoded bodies pass
through unchanged. HTTP/2 DATA-frame body substitution is not
supported; matching body placeholders are blocked.