Skip to main content

auth_middleware

Function auth_middleware 

Source
pub async fn auth_middleware(
    __arg0: State<AppState>,
    req: Request<Body>,
    next: Next,
) -> Result<Response, ApiErrorResponse>
Expand description

Axum middleware that establishes the request’s Principal.

This layer authenticates; it does not authorize. A valid Bearer token makes the request Principal::SignedIn, an absent credential makes it Principal::Anyone, and a supplied credential that does not verify is always 401 — never quietly downgraded to anonymous, which is the rule that stops a typo’d token from silently becoming a public view.

It is mounted on the /api/v1 routes only. The unauthenticated root routes (/healthz, /readyz, /llms.txt) never reach it, and /browse resolves its own principal with the same rules because it is mounted outside this layer (see [crate::router::browse]).