pub async fn auth_middleware(
__arg0: State<AppState>,
req: Request<Body>,
next: Next,
) -> Result<Response, ApiErrorResponse>Expand description
Axum middleware that establishes the request’s Principal.
This layer authenticates; it does not authorize. A valid Bearer token makes
the request Principal::SignedIn, an absent credential makes it
Principal::Anyone, and a supplied credential that does not verify is
always 401 — never quietly downgraded to anonymous, which is the rule that
stops a typo’d token from silently becoming a public view.
It is mounted on the /api/v1 routes only. The unauthenticated root routes
(/healthz, /readyz, /llms.txt) never reach it, and /browse resolves
its own principal with the same rules because it is mounted outside this
layer (see [crate::router::browse]).