pub struct CsrfPlugin { /* private fields */ }Expand description
CSRF protection plugin.
Validates the Origin or Referer header on state-changing requests
(POST, PATCH, DELETE, PUT) against a list of allowed origins. This is
complementary to CORS: CORS controls which origins can read responses,
while CSRF protection ensures that state-changing requests originate from
trusted sources.
Implementations§
Source§impl CsrfPlugin
impl CsrfPlugin
Sourcepub fn new(allowed_origins: Vec<String>) -> Self
pub fn new(allowed_origins: Vec<String>) -> Self
Create a CSRF plugin with explicit allowed origins.
Sourcepub fn with_localhost(port: u16) -> Self
pub fn with_localhost(port: u16) -> Self
Convenience constructor for local development. Allows both localhost
and 127.0.0.1 on the given port.
Sourcepub fn check(
&self,
method: &str,
origin: Option<&str>,
referer: Option<&str>,
) -> Result<(), PluginError>
pub fn check( &self, method: &str, origin: Option<&str>, referer: Option<&str>, ) -> Result<(), PluginError>
Validate an incoming request.
For safe methods this always succeeds. For state-changing methods the
Origin header is checked first; if absent the origin is derived from
the Referer header. If neither header provides a trusted origin the
request is rejected.
Trait Implementations§
Source§impl Plugin for CsrfPlugin
impl Plugin for CsrfPlugin
Source§fn on_request(
&self,
_method: &str,
_path: &str,
_auth: &AuthContext,
) -> Result<(), PluginError>
fn on_request( &self, _method: &str, _path: &str, _auth: &AuthContext, ) -> Result<(), PluginError>
Called on every incoming request (middleware).
Source§fn on_init(&self, _ctx: &PluginContext)
fn on_init(&self, _ctx: &PluginContext)
Called once when the plugin is registered.
Source§fn routes(&self) -> Vec<PluginRoute>
fn routes(&self) -> Vec<PluginRoute>
Custom API routes this plugin handles.
Source§fn before_insert(
&self,
_entity: &str,
_data: &mut Value,
_auth: &AuthContext,
) -> Result<(), PluginError>
fn before_insert( &self, _entity: &str, _data: &mut Value, _auth: &AuthContext, ) -> Result<(), PluginError>
Called before an entity insert. Return Err to reject.
Source§fn after_insert(
&self,
_entity: &str,
_id: &str,
_data: &Value,
_auth: &AuthContext,
)
fn after_insert( &self, _entity: &str, _id: &str, _data: &Value, _auth: &AuthContext, )
Called after a successful insert.
Source§fn before_update(
&self,
_entity: &str,
_id: &str,
_data: &mut Value,
_auth: &AuthContext,
) -> Result<(), PluginError>
fn before_update( &self, _entity: &str, _id: &str, _data: &mut Value, _auth: &AuthContext, ) -> Result<(), PluginError>
Called before an entity update. Return Err to reject.
Source§fn after_update(
&self,
_entity: &str,
_id: &str,
_data: &Value,
_auth: &AuthContext,
)
fn after_update( &self, _entity: &str, _id: &str, _data: &Value, _auth: &AuthContext, )
Called after a successful update.
Source§fn before_delete(
&self,
_entity: &str,
_id: &str,
_auth: &AuthContext,
) -> Result<(), PluginError>
fn before_delete( &self, _entity: &str, _id: &str, _auth: &AuthContext, ) -> Result<(), PluginError>
Called before an entity delete. Return Err to reject.
Source§fn after_delete(&self, _entity: &str, _id: &str, _auth: &AuthContext)
fn after_delete(&self, _entity: &str, _id: &str, _auth: &AuthContext)
Called after a successful delete.
Source§fn on_request_with_meta(
&self,
method: &str,
path: &str,
auth: &AuthContext,
_meta: &RequestMeta<'_>,
) -> Result<(), PluginError>
fn on_request_with_meta( &self, method: &str, path: &str, auth: &AuthContext, _meta: &RequestMeta<'_>, ) -> Result<(), PluginError>
Richer variant of [
on_request] that also receives per-request
metadata (peer IP today; more fields may be added later). The
default implementation delegates to on_request so existing
plugins keep working without changes. Plugins that care about
IP — notably rate limiting — override this hook.Source§fn on_session_create(&self, _user_id: &str, _token: &str)
fn on_session_create(&self, _user_id: &str, _token: &str)
Called when a new session is created.
Source§fn entities(&self) -> Vec<ManifestEntity>
fn entities(&self) -> Vec<ManifestEntity>
Additional manifest entities this plugin contributes.
Auto Trait Implementations§
impl Freeze for CsrfPlugin
impl RefUnwindSafe for CsrfPlugin
impl Send for CsrfPlugin
impl Sync for CsrfPlugin
impl Unpin for CsrfPlugin
impl UnsafeUnpin for CsrfPlugin
impl UnwindSafe for CsrfPlugin
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more