Expand description
Request ID, authentication, and rate limiting middleware. Cross-cutting middleware for the HTTP layer:
request_id_layer— emits anx-typesafe-request-idheader on every response (UUIDv4, generated server-side; the SDK reads this).auth_layer— optional `Authorization: Bearer *** gate.rate_limit_layer— fixed-window client-IP rate limiter.
Structs§
- Auth
Config - Optional bearer-auth state.
None⇒ no auth required. - Rate
Limit Config - Fixed-window per-client-IP rate limit configuration.
- Rate
Limiter - Shared fixed-window counter state for
rate_limit_layer. - Request
Id - Stored in request extensions by
request_id_layer. - Request
Limits - Shared transport budgets with an independent failed-authentication allowance.
Constants§
- AUTH_
HEADER - Authorization header.
- MAX_
REQUEST_ ID_ LEN - Maximum allowed length for an inbound client request ID.
- REQUEST_
ID_ HEADER - Name of the request-id header. Mirrors the SDK’s
request_idproperty.
Functions§
- auth_
layer - Stackable middleware function: gate
/v1/*requests on a bearer token when one is configured./healthand/metricsare always open so probes and scrapers don’t need credentials./playgroundis likewise open when the route is enabled: it serves an inert HTML shell, and evaluation plus/playground/api/*model controls remain gated (the UI collects an optional API key for those calls). - auth_
layer_ for - Build the auth middleware as a Layer for use with
.layer(). - is_
safe_ request_ id - Validate whether a request ID string contains only safe identifier characters.
- rate_
limit_ layer - Stackable middleware function: fixed-window rate limit on
/v1/*per client IP (taken from theConnectInfoextension, whichaxum::serveprovides when the router is served viainto_make_service_with_connect_info). Requests without connect info (unit tests, or any future non-TCP transport such as a Unix socket or a Windows named pipe) are passed through — per-IP limiting is only enforceable when the peer address is known. - request_
id_ layer - Stackable middleware function: stamp every response with a request id.
- secure_
token_ eq - Secure constant-time token comparison.