pub struct RequestContext<'a> {
pub method: &'a str,
pub uri: &'a str,
pub body: Option<&'a [u8]>,
pub headers: &'a [(&'a str, &'a str)],
pub peer_addr: Option<SocketAddr>,
}Expand description
The request fields the Digest response hash covers (RFC 7616 §3.4.1 / RFC
2326 §14): the method, the request URI, and — for qop=auth-int — the
body. Also carries the request’s headers and transport peer address, so a
server-side crate::Verifier scheme can see beyond the Authorization
header — e.g. a reverse-proxy forwarded-auth scheme reading
X-Forwarded-User/X-Forwarded-For (issue #663 extensibility wave part
1). Client-side use (crate::respond/crate::Authenticator) needs
neither field; Self::new defaults both to empty/None.
The uri is scheme-specific: an HTTP absolute/relative URL for HTTP
clients, or the RTSP request URI (e.g. rtsp://host/stream) for RTSP —
never translate one into the other (RFC 2326 §14).
Fields§
§method: &'a strThe request method ("GET", "DESCRIBE", …).
uri: &'a strThe request URI, in the caller’s protocol’s own form.
body: Option<&'a [u8]>The request body, needed only for Digest qop=auth-int. Some(&[])
for a bodyless request still lets auth-int be computed.
headers: &'a [(&'a str, &'a str)]Every request header, as (name, value) pairs — Self::header
looks one up case-insensitively (header names are case-insensitive,
RFC 7230 §3.2). Empty for client-side use (Self::new’s default): a
client answering a challenge computes Authorization from
method/uri/body alone. Server-side (crate::Verifier::verify)
this is how every scheme — including a future one — reads whatever
header it needs, not just Authorization.
peer_addr: Option<SocketAddr>The transport-layer peer address (e.g. the accepted TCP connection’s
remote address), if the caller has one to attach. This is the actual
connection peer — which, behind a reverse proxy, is the proxy itself,
not the original client (see X-Forwarded-For in Self::headers
for that). None for client-side use and whenever the caller has no
transport peer to attach.
Implementations§
Source§impl<'a> RequestContext<'a>
impl<'a> RequestContext<'a>
Sourcepub fn new(method: &'a str, uri: &'a str) -> RequestContext<'a>
pub fn new(method: &'a str, uri: &'a str) -> RequestContext<'a>
Builds a context for a bodyless request with no headers/peer attached
(the common client-side case) — use Self::with_headers/
Self::with_peer_addr to attach either.
Sourcepub fn with_body(self, body: &'a [u8]) -> RequestContext<'a>
pub fn with_body(self, body: &'a [u8]) -> RequestContext<'a>
Attaches a request body (for qop=auth-int).
Sourcepub fn with_headers(
self,
headers: &'a [(&'a str, &'a str)],
) -> RequestContext<'a>
pub fn with_headers( self, headers: &'a [(&'a str, &'a str)], ) -> RequestContext<'a>
Attaches the request’s headers (server-side use — see
Self::headers).
Sourcepub fn with_peer_addr(self, peer_addr: SocketAddr) -> RequestContext<'a>
pub fn with_peer_addr(self, peer_addr: SocketAddr) -> RequestContext<'a>
Attaches the transport peer address (server-side use — see
Self::peer_addr).
Trait Implementations§
Source§impl<'a> Clone for RequestContext<'a>
impl<'a> Clone for RequestContext<'a>
Source§fn clone(&self) -> RequestContext<'a>
fn clone(&self) -> RequestContext<'a>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl<'a> Copy for RequestContext<'a>
Source§impl Debug for RequestContext<'_>
Manual Debug (rather than #[derive(Debug)]): Self::headers carries
whatever the caller attached, which — server-side — includes the real
Authorization/Proxy-Authorization header the request was authenticated
with. Basic’s value is a reversible base64 user:pass (RFC 7617 §2); a
bare tracing::debug!(?ctx, ...) call must not dump it to logs. Every
other header (name and value) is rendered normally — only the value of an
auth header is redacted, and only that header’s name is enough to tell
which one.
impl Debug for RequestContext<'_>
Manual Debug (rather than #[derive(Debug)]): Self::headers carries
whatever the caller attached, which — server-side — includes the real
Authorization/Proxy-Authorization header the request was authenticated
with. Basic’s value is a reversible base64 user:pass (RFC 7617 §2); a
bare tracing::debug!(?ctx, ...) call must not dump it to logs. Every
other header (name and value) is rendered normally — only the value of an
auth header is redacted, and only that header’s name is enough to tell
which one.