Skip to main content

Module middleware

Module middleware 

Source
Expand description

Request ID, authentication, and rate limiting middleware. Cross-cutting middleware for the HTTP layer:

  • request_id_layer — emits an x-typesafe-request-id header on every response (UUIDv4, generated server-side; the SDK reads this).
  • auth_layer — optional `Authorization: Bearer *** gate.
  • rate_limit_layer — fixed-window client-IP rate limiter.

Structs§

AuthConfig
Optional bearer-auth state. None ⇒ no auth required.
RateLimitConfig
Fixed-window per-client-IP rate limit configuration.
RateLimiter
Shared fixed-window counter state for rate_limit_layer.
RequestId
Stored in request extensions by request_id_layer.
RequestLimits
Shared transport budgets with an independent failed-authentication allowance.

Constants§

AUTH_HEADER
Authorization header.
MAX_REQUEST_ID_LEN
Maximum allowed length for an inbound client request ID.
REQUEST_ID_HEADER
Name of the request-id header. Mirrors the SDK’s request_id property.

Functions§

auth_layer
Stackable middleware function: gate /v1/* requests on a bearer token when one is configured. /health and /metrics are always open so probes and scrapers don’t need credentials. /playground is likewise open when the route is enabled: it serves an inert HTML shell, and evaluation plus /playground/api/* model controls remain gated (the UI collects an optional API key for those calls).
auth_layer_for
Build the auth middleware as a Layer for use with .layer().
is_safe_request_id
Validate whether a request ID string contains only safe identifier characters.
rate_limit_layer
Stackable middleware function: fixed-window rate limit on /v1/* per client IP (taken from the ConnectInfo extension, which axum::serve provides when the router is served via into_make_service_with_connect_info). Requests without connect info (unit tests, or any future non-TCP transport such as a Unix socket or a Windows named pipe) are passed through — per-IP limiting is only enforceable when the peer address is known.
request_id_layer
Stackable middleware function: stamp every response with a request id.
secure_token_eq
Secure constant-time token comparison.