pub struct RefererRestrictionPlugin {
whitelist: HostMatcher,
blacklist: HostMatcher,
bypass_missing: bool,
message: String,
}Expand description
Restricts access based on the host of the Referer request header.
Exactly one of whitelist / blacklist is configured (APISIX oneOf
parity). A missing or malformed Referer is rejected unless
bypass_missing is set. Rejections produce a 403 JSON response.
Fields§
§whitelist: HostMatcherHost patterns that may pass; non-empty means whitelist mode.
blacklist: HostMatcherHost patterns that are rejected; non-empty means blacklist mode.
bypass_missing: boolPass requests whose Referer is missing or malformed (default false).
message: StringBody message for rejections.
Implementations§
Source§impl RefererRestrictionPlugin
impl RefererRestrictionPlugin
Sourcepub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
pub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
whitelist(array of host patterns): only these Referer hosts pass.blacklist(array of host patterns): these Referer hosts are rejected. Exactly one ofwhitelist/blacklistmust be non-empty (APISIXoneOfparity). Patterns are exact hosts (example.com) or leading-*wildcards (*.example.com, which matches any subdomain but not the bare apex).bypass_missing(bool, defaultfalse): pass requests whose Referer header is missing or not a parseable http(s) URL.message(string, default"Your referer host is not allowed"): rejection message, returned as{"message": ...}.
type: referer-restriction
config:
whitelist: ["example.com", "*.example.org"]
bypass_missing: trueSourcefn reject(&self, ctx: Context) -> Result<PluginOutput, PluginExecutionError>
fn reject(&self, ctx: Context) -> Result<PluginOutput, PluginExecutionError>
Builds the 403 rejection routed through the error port with code
REFERER_RESTRICTED.
Trait Implementations§
Source§impl Plugin for RefererRestrictionPlugin
impl Plugin for RefererRestrictionPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Unique identifier for the plugin type (e.g., “proxy-rewrite”, “upstream”).
Source§fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Executes the plugin logic against the request/response context. Read more
Auto Trait Implementations§
impl Freeze for RefererRestrictionPlugin
impl RefUnwindSafe for RefererRestrictionPlugin
impl Send for RefererRestrictionPlugin
impl Sync for RefererRestrictionPlugin
impl Unpin for RefererRestrictionPlugin
impl UnsafeUnpin for RefererRestrictionPlugin
impl UnwindSafe for RefererRestrictionPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more