pub async fn auth_middleware(
__arg0: State<AppState>,
req: Request<Body>,
next: Next,
) -> ResponseExpand description
Axum middleware that establishes the request’s Principal.
This layer authenticates; it does not authorize. A credential the
notedthat_core::Authenticator accepts makes the request
Principal::SignedIn, an absent credential makes it Principal::Anyone,
and a supplied credential that does not verify is always 401 — never
quietly downgraded to anonymous, which is the rule that stops a typo’d token
from silently becoming a public view.
Every 401 that leaves this layer — its own, or one a handler answered —
carries the bearer challenge when the deployment publishes protected-
resource metadata, so an MCP client can find the authorization server.
It is mounted on the /api/v1 routes only. The unauthenticated root routes
(/healthz, /readyz, /llms.txt) never reach it, and /browse resolves
its own principal through the same authenticator because it is mounted
outside this layer (see [crate::router::browse]).