pub async fn auth_middleware(
__arg0: State<AppState>,
req: Request<Body>,
next: Next,
) -> Result<Response, ApiErrorResponse>Expand description
Axum middleware that validates the Authorization: Bearer <token> header.
This layer is mounted on the /api/v1 routes only; the unauthenticated root
routes (/healthz, /readyz, /llms.txt, /browse) never reach it. A
supplied credential must always be a single valid Bearer token. When no
credential is supplied, only explicitly granted read capabilities pass
through as anonymous requests.