pub struct RefererRestrictionPlugin {
whitelist: HostMatcher,
blacklist: HostMatcher,
bypass_missing: bool,
message: Template,
}Expand description
Restricts access based on the host of the Referer request header.
Exactly one of whitelist / blacklist is configured (APISIX oneOf
parity). A missing or malformed Referer is rejected unless
bypass_missing is set. Rejections produce a 403 JSON response.
Fields§
§whitelist: HostMatcherHost patterns that may pass; non-empty means whitelist mode.
blacklist: HostMatcherHost patterns that are rejected; non-empty means blacklist mode.
bypass_missing: boolPass requests whose Referer is missing or malformed (default false).
message: TemplateBody message for rejections. Supports {{namespace.path}} references
(no legacy $var interpolation — this field never supported it, so
this sweep must not start).
Implementations§
Source§impl RefererRestrictionPlugin
impl RefererRestrictionPlugin
Sourcepub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
pub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
whitelist(array of host patterns): only these Referer hosts pass.blacklist(array of host patterns): these Referer hosts are rejected. Exactly one ofwhitelist/blacklistmust be non-empty (APISIXoneOfparity). Patterns are exact hosts (example.com) or leading-*wildcards (*.example.com, which matches any subdomain but not the bare apex).bypass_missing(bool, defaultfalse): pass requests whose Referer header is missing or not a parseable http(s) URL.message(string, default"Your referer host is not allowed"): rejection message, returned as{"message": ...}. Supports{{namespace.path}}references.
type: referer-restriction
config:
whitelist: ["example.com", "*.example.org"]
bypass_missing: trueSourcefn reject(&self, ctx: Context) -> Result<PluginOutput, PluginExecutionError>
fn reject(&self, ctx: Context) -> Result<PluginOutput, PluginExecutionError>
Builds the 403 rejection routed through the denied port.
Trait Implementations§
Source§impl Plugin for RefererRestrictionPlugin
impl Plugin for RefererRestrictionPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn execute<'life0, 'async_trait>(
&'life0 self,
ctx: Context,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Executes the plugin logic against the request/response context. Read more
Source§fn reads_response_body(&self) -> bool
fn reads_response_body(&self) -> bool
Whether this configured instance reads
context.response.body. Read moreSource§fn cache_target(&self) -> Option<CacheTarget>
fn cache_target(&self) -> Option<CacheTarget>
The cache backend this node writes to, if it is a
proxy-cache half. Read moreAuto Trait Implementations§
impl Freeze for RefererRestrictionPlugin
impl RefUnwindSafe for RefererRestrictionPlugin
impl Send for RefererRestrictionPlugin
impl Sync for RefererRestrictionPlugin
impl Unpin for RefererRestrictionPlugin
impl UnsafeUnpin for RefererRestrictionPlugin
impl UnwindSafe for RefererRestrictionPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more