Skip to main content

Csrf

Struct Csrf 

Source
pub struct Csrf { /* private fields */ }
Expand description

A Handler that rejects state-changing cross-origin requests.

See the crate-level docs for the exact decision sequence. Construct with csrf or Csrf::new and place it in the handler tuple before any handler with side effects.

Implementations§

Source§

impl Csrf

Source

pub const fn new() -> Self

Constructs a new Csrf handler with no trusted origins.

Source

pub fn with_trusted_origins<I>(self, origins: I) -> Self
where I: IntoIterator, I::Item: AsRef<str>,

Allows cross-origin requests from these origins.

Each entry must be a full origin — scheme, host, and optional port, such as "https://app.example.com" — with nothing else. Requests are compared by exact origin: no wildcards, and subdomains of a trusted origin are not trusted.

use trillium_csrf::csrf;
let handler = csrf().with_trusted_origins(["https://app.example.com"]);
§Panics

Panics if an entry is not parseable as an origin, is not http or https, or contains a path, query, or credentials. A path would be silently ignored during comparison, so an entry like "https://example.com/app" is rejected rather than matching more broadly than it reads.

Trait Implementations§

Source§

impl Debug for Csrf

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Csrf

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Handler for Csrf

Source§

async fn run(&self, conn: Conn) -> Conn

Executes this handler, performing any modifications to the Conn that are desired.
Source§

fn init(&mut self, info: &mut Info) -> impl Future<Output = ()> + Send

Performs one-time async set up on a mutable borrow of the Handler before the server starts accepting requests. This allows a Handler to be defined in synchronous code but perform async setup such as establishing a database connection or fetching some state from an external source. This is optional, and chances are high that you do not need this. Read more
Source§

fn before_send(&self, conn: Conn) -> impl Future<Output = Conn> + Send

Performs any final modifications to this conn after all handlers have been run. Although this is a slight deviation from the simple conn->conn->conn chain represented by most Handlers, it provides an easy way for libraries to effectively inject a second handler into a response chain. This is useful for loggers that need to record information both before and after other handlers have run, as well as database transaction handlers and similar library code. Read more
Source§

fn has_upgrade(&self, upgrade: &Upgrade) -> bool

predicate function answering the question of whether this Handler would like to take ownership of the negotiated Upgrade. If this returns true, you must implement Handler::upgrade. The first handler that responds true to this will receive ownership of the trillium::Upgrade in a subsequent call to Handler::upgrade
Source§

fn upgrade(&self, upgrade: Upgrade) -> impl Future<Output = ()> + Send

This will only be called if the handler reponds true to Handler::has_upgrade and will only be called once for this upgrade. There is no return value, and this function takes exclusive ownership of the underlying transport once this is called. You can downcast the transport to whatever the source transport type is and perform any non-http protocol communication that has been negotiated. You probably don’t want this unless you’re implementing something like websockets. Please note that for many transports such as TcpStreams, dropping the transport (and therefore the Upgrade) will hang up / disconnect.
Source§

fn name(&self) -> Cow<'static, str>

Customize the name of your handler. This is used in Debug implementations. The default is the type name of this handler.

Auto Trait Implementations§

§

impl Freeze for Csrf

§

impl RefUnwindSafe for Csrf

§

impl Send for Csrf

§

impl Sync for Csrf

§

impl Unpin for Csrf

§

impl UnsafeUnpin for Csrf

§

impl UnwindSafe for Csrf

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.