(State(state): State<ServeState>, request: Request, next: Next)
| 241 | } |
| 242 | |
| 243 | async fn api_guard(State(state): State<ServeState>, request: Request, next: Next) -> Response { |
| 244 | if !host_allowed(request.headers(), &state) { |
| 245 | return json_error(StatusCode::BAD_REQUEST, "Host header is not allowed"); |
| 246 | } |
| 247 | if !origin_allowed(request.headers(), &state) { |
| 248 | return json_error(StatusCode::FORBIDDEN, "Origin header is not allowed"); |
| 249 | } |
| 250 | if !authorization_valid(request.headers(), &state.token) { |
| 251 | return json_error( |
| 252 | StatusCode::UNAUTHORIZED, |
| 253 | "Missing or invalid authorization token", |
| 254 | ); |
| 255 | } |
| 256 | if request.method() == Method::POST && !content_type_is_json(request.headers()) { |
| 257 | return json_error( |
| 258 | StatusCode::UNSUPPORTED_MEDIA_TYPE, |
| 259 | "Content-Type must be application/json", |
| 260 | ); |
| 261 | } |
| 262 | next.run(request).await |
| 263 | } |
| 264 | |
| 265 | async fn add_security_headers(request: Request, next: Next) -> Response { |
| 266 | let mut response = next.run(request).await; |
nothing calls this directly
no test coverage detected