Skip to main content

SecurityMiddleware

Struct SecurityMiddleware 

Source
#[non_exhaustive]
pub struct SecurityMiddleware { pub hsts_enabled: bool, pub hsts_seconds: u32, pub hsts_include_subdomains: bool, pub hsts_preload: bool, pub ssl_redirect: bool, pub content_type_nosniff: bool, pub referrer_policy: Option<String>, pub cross_origin_opener_policy: Option<String>, pub x_frame_options: Option<String>, pub secure_proxy_ssl_header: Option<(String, String)>, }
Available on crate feature middleware-security only.
Expand description

Security middleware for HTTP security headers and redirects

§Construction

Use SecurityMiddleware::new for sensible defaults, or SecurityMiddleware::from_security_settings to build from a SecuritySettings fragment loaded via reinhardt-conf.

Individual fields can be customized via with_* builder methods:

use reinhardt_middleware::SecurityMiddleware;

let middleware = SecurityMiddleware::new()
    .with_hsts_include_subdomains(true)
    .with_hsts_preload(true)
    .with_referrer_policy("strict-origin-when-cross-origin");

Fields (Non-exhaustive)§

This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.
§hsts_enabled: bool

Enable HSTS (HTTP Strict Transport Security)

§hsts_seconds: u32

HSTS max-age in seconds (default: 31536000 = 1 year)

§hsts_include_subdomains: bool

Include subdomains in HSTS

§hsts_preload: bool

Include preload directive in HSTS

§ssl_redirect: bool

Redirect HTTP to HTTPS

§content_type_nosniff: bool

Set X-Content-Type-Options: nosniff

§referrer_policy: Option<String>

Referrer-Policy value

§cross_origin_opener_policy: Option<String>

Cross-Origin-Opener-Policy value

§x_frame_options: Option<String>

X-Frame-Options value (e.g., “DENY”, “SAMEORIGIN”)

§secure_proxy_ssl_header: Option<(String, String)>

Proxy SSL header name and expected value for identifying secure requests

Implementations§

Source§

impl SecurityMiddleware

Source

pub fn new() -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Create a new SecurityMiddleware with default configuration

§Examples
use std::sync::Arc;
use reinhardt_middleware::SecurityMiddleware;
use reinhardt_http::{Handler, Middleware, Request, Response};
use hyper::{StatusCode, Method, Version, HeaderMap};
use bytes::Bytes;

struct TestHandler;

#[async_trait::async_trait]
impl Handler for TestHandler {
    async fn handle(&self, _request: Request) -> reinhardt_core::exception::Result<Response> {
        Ok(Response::new(StatusCode::OK))
    }
}

let middleware = SecurityMiddleware::new();
let handler = Arc::new(TestHandler);

let request = Request::builder()
    .method(Method::GET)
    .uri("/api/data")
    .version(Version::HTTP_11)
    .headers(HeaderMap::new())
    .secure(true)
    .body(Bytes::new())
    .build()
    .unwrap();

let response = middleware.process(request, handler).await.unwrap();
assert!(response.headers.contains_key("Strict-Transport-Security"));
assert_eq!(response.headers.get("X-Content-Type-Options").unwrap(), "nosniff");
Source

pub fn from_security_settings(settings: &SecuritySettings) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Create a new SecurityMiddleware from a SecuritySettings fragment

Maps security-related fields from SecuritySettings to the middleware configuration. Middleware-specific defaults (e.g., content_type_nosniff, referrer_policy) are preserved from SecurityMiddleware::default.

§Examples
use reinhardt_conf::SecuritySettings;
use reinhardt_middleware::SecurityMiddleware;

let settings = SecuritySettings {
    secure_ssl_redirect: true,
    secure_hsts_seconds: Some(31536000),
    ..Default::default()
};

let middleware = SecurityMiddleware::from_security_settings(&settings);
Source

pub fn with_hsts(self, enabled: bool) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set whether HSTS is enabled

Source

pub fn with_hsts_seconds(self, seconds: u32) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set the HSTS max-age in seconds

Source

pub fn with_hsts_include_subdomains(self, include: bool) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set whether to include subdomains in HSTS

Source

pub fn with_hsts_preload(self, preload: bool) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set whether to include preload directive in HSTS

Source

pub fn with_ssl_redirect(self, redirect: bool) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set whether to redirect HTTP to HTTPS

Source

pub fn with_content_type_nosniff(self, nosniff: bool) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set whether to add X-Content-Type-Options: nosniff

Source

pub fn with_referrer_policy( self, policy: impl Into<String>, ) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set the Referrer-Policy header value

Source

pub fn without_referrer_policy(self) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Remove the Referrer-Policy header

Source

pub fn with_cross_origin_opener_policy( self, policy: impl Into<String>, ) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set the Cross-Origin-Opener-Policy header value

Source

pub fn without_cross_origin_opener_policy(self) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Remove the Cross-Origin-Opener-Policy header

Source

pub fn with_x_frame_options( self, value: impl Into<String>, ) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set the X-Frame-Options header value

Source

pub fn without_x_frame_options(self) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Remove the X-Frame-Options header

Source

pub fn with_secure_proxy_ssl_header( self, header: impl Into<String>, value: impl Into<String>, ) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Set the proxy SSL header name and expected value

Source

pub fn without_secure_proxy_ssl_header(self) -> SecurityMiddleware

Available on native and crate feature security and (crate features middleware or standard) only.

Remove the proxy SSL header configuration

Trait Implementations§

Source§

impl Clone for SecurityMiddleware

Source§

fn clone(&self) -> SecurityMiddleware

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SecurityMiddleware

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for SecurityMiddleware

Source§

fn default() -> SecurityMiddleware

Returns the “default value” for a type. Read more
Source§

impl Middleware for SecurityMiddleware

Source§

fn process<'life0, 'async_trait>( &'life0 self, request: Request, handler: Arc<dyn Handler>, ) -> Pin<Box<dyn Future<Output = Result<Response, Error>> + Send + 'async_trait>>
where 'life0: 'async_trait, SecurityMiddleware: 'async_trait,

Processes a request through this middleware. Read more
Source§

fn should_continue(&self, _request: &Request) -> bool

Determines whether this middleware should be executed for the given request. Read more
Source§

fn di_registrations(&self) -> Vec<(TypeId, Arc<dyn Any + Send + Sync>)>

Returns DI singleton registrations contributed by this middleware. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Any for T
where T: Any,

Source§

fn into_any(self: Box<T>) -> Box<dyn Any>

Source§

fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>

Source§

fn type_name(&self) -> &'static str

Source§

impl<T> AnySync for T
where T: Any + Send + Sync,

Source§

fn into_any_arc(self: Arc<T>) -> Arc<dyn Any + Send + Sync>

Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Conv for T

Source§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
Source§

impl<T> FmtForward for T

Source§

fn fmt_binary(self) -> FmtBinary<Self>
where Self: Binary,

Causes self to use its Binary implementation when Debug-formatted.
Source§

fn fmt_display(self) -> FmtDisplay<Self>
where Self: Display,

Causes self to use its Display implementation when Debug-formatted.
Source§

fn fmt_lower_exp(self) -> FmtLowerExp<Self>
where Self: LowerExp,

Causes self to use its LowerExp implementation when Debug-formatted.
Source§

fn fmt_lower_hex(self) -> FmtLowerHex<Self>
where Self: LowerHex,

Causes self to use its LowerHex implementation when Debug-formatted.
Source§

fn fmt_octal(self) -> FmtOctal<Self>
where Self: Octal,

Causes self to use its Octal implementation when Debug-formatted.
Source§

fn fmt_pointer(self) -> FmtPointer<Self>
where Self: Pointer,

Causes self to use its Pointer implementation when Debug-formatted.
Source§

fn fmt_upper_exp(self) -> FmtUpperExp<Self>
where Self: UpperExp,

Causes self to use its UpperExp implementation when Debug-formatted.
Source§

fn fmt_upper_hex(self) -> FmtUpperHex<Self>
where Self: UpperHex,

Causes self to use its UpperHex implementation when Debug-formatted.
Source§

fn fmt_list(self) -> FmtList<Self>
where &'a Self: for<'a> IntoIterator,

Formats each item in a sequence. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<T> IntoResult<T> for T

Source§

type Err = !

Source§

fn into_result(self) -> Result<T, <T as IntoResult<T>>::Err>

Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pipe for T
where T: ?Sized,

Source§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
Source§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
Source§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
Source§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
Source§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
Source§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
Source§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<R, P> ReadPrimitive<R> for P
where R: Read + ReadEndian<P>, P: Default,

Source§

fn read_from_little_endian(read: &mut R) -> Result<Self, Error>

Read this value from the supplied reader. Same as ReadEndian::read_from_little_endian().
Source§

fn read_from_big_endian(read: &mut R) -> Result<Self, Error>

Read this value from the supplied reader. Same as ReadEndian::read_from_big_endian().
Source§

fn read_from_native_endian(read: &mut R) -> Result<Self, Error>

Read this value from the supplied reader. Same as ReadEndian::read_from_native_endian().
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<E> ServerFnErrorAssertions<E> for E
where E: Debug,

Source§

fn should_contain_message(&self, expected: &str)
where E: Display,

Assert that the error message contains the specified text.
Source§

fn should_have_message(&self, expected: &str)
where E: Display,

Assert that the error message matches exactly.
Source§

impl<T> Tap for T

Source§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
Source§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
Source§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
Source§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
Source§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
Source§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
Source§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
Source§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
Source§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
Source§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> TryConv for T

Source§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<S, T> Upcast<T> for S
where T: UpcastFrom<S> + ?Sized, S: ?Sized,

Source§

fn upcast(&self) -> &T
where Self: ErasableGeneric, T: Sized + ErasableGeneric<Repr = Self::Repr>,

Perform a zero-cost type-safe upcast to a wider ref type within the Wasm bindgen generics type system. Read more
Source§

fn upcast_into(self) -> T
where Self: Sized + ErasableGeneric, T: Sized + ErasableGeneric<Repr = Self::Repr>,

Perform a zero-cost type-safe upcast to a wider type within the Wasm bindgen generics type system. Read more
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more