pub struct Csrf { /* private fields */ }Expand description
A Handler that rejects state-changing cross-origin requests.
See the crate-level docs for the exact decision sequence. Construct with csrf or
Csrf::new and place it in the handler tuple before any handler with side effects.
Implementations§
Source§impl Csrf
impl Csrf
Sourcepub fn with_trusted_origins<I>(self, origins: I) -> Self
pub fn with_trusted_origins<I>(self, origins: I) -> Self
Allows cross-origin requests from these origins.
Each entry must be a full origin — scheme, host, and optional port, such as
"https://app.example.com" — with nothing else. Requests are compared by exact origin:
no wildcards, and subdomains of a trusted origin are not trusted.
use trillium_csrf::csrf;
let handler = csrf().with_trusted_origins(["https://app.example.com"]);§Panics
Panics if an entry is not parseable as an origin, is not http or https, or contains a
path, query, or credentials. A path would be silently ignored during comparison, so an
entry like "https://example.com/app" is rejected rather than matching more broadly
than it reads.
Trait Implementations§
Source§impl Handler for Csrf
impl Handler for Csrf
Source§async fn run(&self, conn: Conn) -> Conn
async fn run(&self, conn: Conn) -> Conn
Source§fn init(&mut self, info: &mut Info) -> impl Future<Output = ()> + Send
fn init(&mut self, info: &mut Info) -> impl Future<Output = ()> + Send
Source§fn before_send(&self, conn: Conn) -> impl Future<Output = Conn> + Send
fn before_send(&self, conn: Conn) -> impl Future<Output = Conn> + Send
Source§fn has_upgrade(&self, upgrade: &Upgrade) -> bool
fn has_upgrade(&self, upgrade: &Upgrade) -> bool
Handler::upgrade. The first handler that responds true to this will receive
ownership of the trillium::Upgrade in a subsequent call to
Handler::upgradeSource§fn upgrade(&self, upgrade: Upgrade) -> impl Future<Output = ()> + Send
fn upgrade(&self, upgrade: Upgrade) -> impl Future<Output = ()> + Send
Handler::has_upgrade and will
only be called once for this upgrade. There is no return value, and this function takes
exclusive ownership of the underlying transport once this is called. You can downcast
the transport to whatever the source transport type is and perform any non-http protocol
communication that has been negotiated. You probably don’t want this unless you’re
implementing something like websockets. Please note that for many transports such as
TcpStreams, dropping the transport (and therefore the Upgrade) will hang up /
disconnect.