pub struct CsrfPlugin {
key: Key,
expires: u64,
name: Template,
phase: CsrfPhase,
}Expand description
Double-submit-cookie CSRF protection keyed by an HMAC secret.
In phase: request (default), unsafe methods must present matching
header and cookie tokens carrying a valid signature; safe methods pass
through (and get a token cookie, though a downstream upstream node will
replace it — see the module docs). In phase: response the node only
issues the token cookie, mirroring APISIX’s header_filter.
Fields§
§key: KeyHMAC-SHA256 key derived from the configured secret.
expires: u64Token lifetime in seconds; 0 disables the expiry check.
name: TemplateCookie and header name carrying the token. Supports
{{namespace.path}} references (no legacy $var interpolation —
name never supported it, so this sweep must not start); rendered
then lowercased for lookup at each use.
phase: CsrfPhaseWhich side of the exchange this node handles.
Implementations§
Source§impl CsrfPlugin
impl CsrfPlugin
Sourcepub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
pub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
key(string, required, non-empty): HMAC secret used to sign tokens.expires(integer seconds, default7200): token lifetime;0disables the expiry check and makes the cookie a session cookie.name(string, default"featherbit-csrf-token"): cookie and request-header name carrying the token; supports{{namespace.path}}references (rendered then lowercased).phase(string, defaultrequest):requestvalidates unsafe methods;responseonly issues the token cookie (place it after the upstream node).
type: csrf
config:
key: edd1c9f034335f136f87ad84b625c8f1
expires: 3600
name: featherbit-csrf-tokenSourcefn sign(&self, random: &str, expires: u64) -> String
fn sign(&self, random: &str, expires: u64) -> String
Computes the token signature: hex(HMAC-SHA256(key, random || expires)).
Sourcefn token_at(&self, ts: u64) -> String
fn token_at(&self, ts: u64) -> String
Builds a token issued at timestamp ts:
base64(json{random, expires: ts, sign}).
Sourcefn check_token(&self, token: &str) -> bool
fn check_token(&self, token: &str) -> bool
Verifies a token’s structure, expiry, and signature.
Sourcefn rendered_name(&self, ctx: &Context) -> String
fn rendered_name(&self, ctx: &Context) -> String
Renders and lowercases name for the current request (shared by the
cookie name and the request-header lookup — see the module docs on
the double-submit pattern using the same field for both).
Appends the token Set-Cookie header to the response.
Deviation: uses Max-Age instead of APISIX’s Expires date (omitted
when expires is 0, yielding a session cookie).
Sourcefn reject(
&self,
ctx: Context,
msg: &str,
) -> Result<PluginOutput, PluginExecutionError>
fn reject( &self, ctx: Context, msg: &str, ) -> Result<PluginOutput, PluginExecutionError>
Builds the 401 rejection routed through the denied port.
Trait Implementations§
Source§impl Plugin for CsrfPlugin
impl Plugin for CsrfPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Source§fn reads_response_body(&self) -> bool
fn reads_response_body(&self) -> bool
context.response.body. Read moreSource§fn cache_target(&self) -> Option<CacheTarget>
fn cache_target(&self) -> Option<CacheTarget>
proxy-cache half. Read moreAuto Trait Implementations§
impl Freeze for CsrfPlugin
impl RefUnwindSafe for CsrfPlugin
impl Send for CsrfPlugin
impl Sync for CsrfPlugin
impl Unpin for CsrfPlugin
impl UnsafeUnpin for CsrfPlugin
impl UnwindSafe for CsrfPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more