pub struct HttpAuthLayer<R = EmptyRefusal> { /* private fields */ }tower only.Expand description
A tower::Layer that authenticates every request to the service it wraps,
for any http::Request<ReqBody> / http::Response<ResBody> service; see
the module docs. Cheap to clone (two Arcs).
R is what builds a refusal’s response: EmptyRefusal unless
HttpAuthLayerBuilder::on_reject set a callback.
Built once at startup. Nothing in it hot-reloads: a changed static token or OAuth config takes effect when a new layer is built, which in practice means a restart.
Implementations§
Source§impl HttpAuthLayer
impl HttpAuthLayer
Sourcepub fn builder() -> HttpAuthLayerBuilder
pub fn builder() -> HttpAuthLayerBuilder
Start building an enforcing layer. Give it a static token, an OAuth
validator, or both; optionally the credential sources (default:
Authorization: Bearer), the refusal body
(on_reject), and
optional. To honour
accept_static_bearer, finish with
build_with_decision and a
crate::static_token_policy decision.
§Examples
use http::HeaderName;
use oauth_resource_server::http_layer::{AuthLayerError, CredentialSource, HttpAuthLayer};
let auth = HttpAuthLayer::builder()
.static_token("example-static-key")
.sources([
CredentialSource::authorization_bearer(),
CredentialSource::Raw(HeaderName::from_static("x-api-key")),
])
.build()
.unwrap();
// Fail closed: no credential configured is an error, not a pass-through.
assert_eq!(
HttpAuthLayer::builder().build().unwrap_err(),
AuthLayerError::NoCredential
);Sourcepub fn allow_unauthenticated() -> Self
pub fn allow_unauthenticated() -> Self
A layer that lets EVERY request through, unauthenticated, and inserts no
credential into request extensions. The explicit opt-out; the only
other way to get it is a StaticTokenDecision::Unauthenticated handed
to HttpAuthLayer::from_decision or
HttpAuthLayerBuilder::build_with_decision.
§Security
Every request reaches the wrapped service. Use it only where something
else (a trusted network, a proxy that authenticates) stands in front.
It still marks every Authorization header value sensitive
(http::HeaderValue::set_sensitive), so a credential a client sends
anyway is not printed by a Debug of the request downstream.
Sourcepub fn from_decision(
decision: StaticTokenDecision,
oauth: Option<Arc<OAuthValidator>>,
) -> Result<Self, AuthLayerError>
pub fn from_decision( decision: StaticTokenDecision, oauth: Option<Arc<OAuthValidator>>, ) -> Result<Self, AuthLayerError>
The layer a crate::static_token_policy decision calls for, with the
default source and refusal body. Shorthand for
HttpAuthLayer::builder().optional_oauth(oauth).build_with_decision(decision).
§Errors
Source§impl<R> HttpAuthLayer<R>
impl<R> HttpAuthLayer<R>
Sourcepub fn allows_unauthenticated(&self) -> bool
pub fn allows_unauthenticated(&self) -> bool
Whether this is the HttpAuthLayer::allow_unauthenticated pass-through.
Sourcepub fn oauth(&self) -> Option<&Arc<OAuthValidator>>
pub fn oauth(&self) -> Option<&Arc<OAuthValidator>>
The OAuth validator, when one is configured.
Trait Implementations§
Source§impl<R> Clone for HttpAuthLayer<R>
impl<R> Clone for HttpAuthLayer<R>
Source§impl<R> Debug for HttpAuthLayer<R>
Hand-written so the static token never reaches a log line through {:?}.
impl<R> Debug for HttpAuthLayer<R>
Hand-written so the static token never reaches a log line through {:?}.