Skip to main content

redirect_back

Function redirect_back 

Source
pub fn redirect_back(headers: &HeaderMap, fallback: &str) -> Redirect
Expand description

Redirects to the page the request came from, or to fallback (Rails’ redirect_back_or_to).

Uses the Referer header only when it points to this app (same host as the request’s Host header), so a link from another site cannot turn the app into an open redirect; the redirect keeps the referring path and query string. Answers 303 See Other, like [Redirect::to]. Browsers send Referer for same-origin requests under Ocre’s default Referrer-Policy.

§Examples

use axum::{http::HeaderMap, response::IntoResponse};

let mut headers = HeaderMap::new();
headers.insert("host", "blog.example".parse().unwrap());
headers.insert("referer", "https://blog.example/posts?page=2".parse().unwrap());
let response = ocre::redirect_back(&headers, "/").into_response();
assert_eq!(response.headers()["location"], "/posts?page=2");

headers.insert("referer", "https://evil.example/".parse().unwrap());
let response = ocre::redirect_back(&headers, "/").into_response();
assert_eq!(response.headers()["location"], "/");