#[non_exhaustive]pub struct SecurityMiddleware {
pub hsts_enabled: bool,
pub hsts_seconds: u32,
pub hsts_include_subdomains: bool,
pub hsts_preload: bool,
pub ssl_redirect: bool,
pub content_type_nosniff: bool,
pub referrer_policy: Option<String>,
pub cross_origin_opener_policy: Option<String>,
pub x_frame_options: Option<String>,
pub secure_proxy_ssl_header: Option<(String, String)>,
}middleware-security only.Expand description
Security middleware for HTTP security headers and redirects
§Construction
Use SecurityMiddleware::new for sensible defaults, or
SecurityMiddleware::from_security_settings to build from a
SecuritySettings fragment loaded via reinhardt-conf.
Individual fields can be customized via with_* builder methods:
use reinhardt_middleware::SecurityMiddleware;
let middleware = SecurityMiddleware::new()
.with_hsts_include_subdomains(true)
.with_hsts_preload(true)
.with_referrer_policy("strict-origin-when-cross-origin");Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.hsts_enabled: boolEnable HSTS (HTTP Strict Transport Security)
hsts_seconds: u32HSTS max-age in seconds (default: 31536000 = 1 year)
hsts_include_subdomains: boolInclude subdomains in HSTS
hsts_preload: boolInclude preload directive in HSTS
ssl_redirect: boolRedirect HTTP to HTTPS
content_type_nosniff: boolSet X-Content-Type-Options: nosniff
referrer_policy: Option<String>Referrer-Policy value
cross_origin_opener_policy: Option<String>Cross-Origin-Opener-Policy value
x_frame_options: Option<String>X-Frame-Options value (e.g., “DENY”, “SAMEORIGIN”)
secure_proxy_ssl_header: Option<(String, String)>Proxy SSL header name and expected value for identifying secure requests
Implementations§
Source§impl SecurityMiddleware
impl SecurityMiddleware
Sourcepub fn new() -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn new() -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Create a new SecurityMiddleware with default configuration
§Examples
use std::sync::Arc;
use reinhardt_middleware::SecurityMiddleware;
use reinhardt_http::{Handler, Middleware, Request, Response};
use hyper::{StatusCode, Method, Version, HeaderMap};
use bytes::Bytes;
struct TestHandler;
#[async_trait::async_trait]
impl Handler for TestHandler {
async fn handle(&self, _request: Request) -> reinhardt_core::exception::Result<Response> {
Ok(Response::new(StatusCode::OK))
}
}
let middleware = SecurityMiddleware::new();
let handler = Arc::new(TestHandler);
let request = Request::builder()
.method(Method::GET)
.uri("/api/data")
.version(Version::HTTP_11)
.headers(HeaderMap::new())
.secure(true)
.body(Bytes::new())
.build()
.unwrap();
let response = middleware.process(request, handler).await.unwrap();
assert!(response.headers.contains_key("Strict-Transport-Security"));
assert_eq!(response.headers.get("X-Content-Type-Options").unwrap(), "nosniff");Sourcepub fn from_security_settings(settings: &SecuritySettings) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn from_security_settings(settings: &SecuritySettings) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Create a new SecurityMiddleware from a SecuritySettings fragment
Maps security-related fields from SecuritySettings to the middleware
configuration. Middleware-specific defaults (e.g., content_type_nosniff,
referrer_policy) are preserved from SecurityMiddleware::default.
§Examples
use reinhardt_conf::SecuritySettings;
use reinhardt_middleware::SecurityMiddleware;
let settings = SecuritySettings {
secure_ssl_redirect: true,
secure_hsts_seconds: Some(31536000),
..Default::default()
};
let middleware = SecurityMiddleware::from_security_settings(&settings);Sourcepub fn with_hsts(self, enabled: bool) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_hsts(self, enabled: bool) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set whether HSTS is enabled
Sourcepub fn with_hsts_seconds(self, seconds: u32) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_hsts_seconds(self, seconds: u32) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set the HSTS max-age in seconds
Sourcepub fn with_hsts_include_subdomains(self, include: bool) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_hsts_include_subdomains(self, include: bool) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set whether to include subdomains in HSTS
Sourcepub fn with_hsts_preload(self, preload: bool) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_hsts_preload(self, preload: bool) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set whether to include preload directive in HSTS
Sourcepub fn with_ssl_redirect(self, redirect: bool) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_ssl_redirect(self, redirect: bool) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set whether to redirect HTTP to HTTPS
Sourcepub fn with_content_type_nosniff(self, nosniff: bool) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_content_type_nosniff(self, nosniff: bool) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set whether to add X-Content-Type-Options: nosniff
Sourcepub fn with_referrer_policy(
self,
policy: impl Into<String>,
) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_referrer_policy( self, policy: impl Into<String>, ) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set the Referrer-Policy header value
Sourcepub fn without_referrer_policy(self) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn without_referrer_policy(self) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Remove the Referrer-Policy header
Sourcepub fn with_cross_origin_opener_policy(
self,
policy: impl Into<String>,
) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_cross_origin_opener_policy( self, policy: impl Into<String>, ) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set the Cross-Origin-Opener-Policy header value
Sourcepub fn without_cross_origin_opener_policy(self) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn without_cross_origin_opener_policy(self) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Remove the Cross-Origin-Opener-Policy header
Sourcepub fn with_x_frame_options(
self,
value: impl Into<String>,
) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_x_frame_options( self, value: impl Into<String>, ) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set the X-Frame-Options header value
Sourcepub fn without_x_frame_options(self) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn without_x_frame_options(self) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Remove the X-Frame-Options header
Sourcepub fn with_secure_proxy_ssl_header(
self,
header: impl Into<String>,
value: impl Into<String>,
) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn with_secure_proxy_ssl_header( self, header: impl Into<String>, value: impl Into<String>, ) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Set the proxy SSL header name and expected value
Sourcepub fn without_secure_proxy_ssl_header(self) -> SecurityMiddleware
Available on native and crate feature security and (crate features middleware or standard) only.
pub fn without_secure_proxy_ssl_header(self) -> SecurityMiddleware
native and crate feature security and (crate features middleware or standard) only.Remove the proxy SSL header configuration
Trait Implementations§
Source§impl Clone for SecurityMiddleware
impl Clone for SecurityMiddleware
Source§fn clone(&self) -> SecurityMiddleware
fn clone(&self) -> SecurityMiddleware
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SecurityMiddleware
impl Debug for SecurityMiddleware
Source§impl Default for SecurityMiddleware
impl Default for SecurityMiddleware
Source§fn default() -> SecurityMiddleware
fn default() -> SecurityMiddleware
Source§impl Middleware for SecurityMiddleware
impl Middleware for SecurityMiddleware
Source§fn process<'life0, 'async_trait>(
&'life0 self,
request: Request,
handler: Arc<dyn Handler>,
) -> Pin<Box<dyn Future<Output = Result<Response, Error>> + Send + 'async_trait>>where
'life0: 'async_trait,
SecurityMiddleware: 'async_trait,
fn process<'life0, 'async_trait>(
&'life0 self,
request: Request,
handler: Arc<dyn Handler>,
) -> Pin<Box<dyn Future<Output = Result<Response, Error>> + Send + 'async_trait>>where
'life0: 'async_trait,
SecurityMiddleware: 'async_trait,
Auto Trait Implementations§
impl Freeze for SecurityMiddleware
impl RefUnwindSafe for SecurityMiddleware
impl Send for SecurityMiddleware
impl Sync for SecurityMiddleware
impl Unpin for SecurityMiddleware
impl UnsafeUnpin for SecurityMiddleware
impl UnwindSafe for SecurityMiddleware
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::RequestSource§impl<T> IntoResult<T> for T
impl<T> IntoResult<T> for T
type Err = !
fn into_result(self) -> Result<T, <T as IntoResult<T>>::Err>
Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<R, P> ReadPrimitive<R> for P
impl<R, P> ReadPrimitive<R> for P
Source§fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
ReadEndian::read_from_little_endian().Source§impl<E> ServerFnErrorAssertions<E> for Ewhere
E: Debug,
impl<E> ServerFnErrorAssertions<E> for Ewhere
E: Debug,
Source§fn should_contain_message(&self, expected: &str)where
E: Display,
fn should_contain_message(&self, expected: &str)where
E: Display,
Source§fn should_have_message(&self, expected: &str)where
E: Display,
fn should_have_message(&self, expected: &str)where
E: Display,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.