pub fn redirect_back(headers: &HeaderMap, fallback: &str) -> RedirectExpand description
Redirects to the page the request came from, or to fallback (Rails’ redirect_back_or_to).
Uses the Referer header only when it points to this app (same host as
the request’s Host header), so a link from another site cannot turn
the app into an open redirect; the redirect keeps the referring path and
query string. Answers 303 See Other, like [Redirect::to]. Browsers
send Referer for same-origin requests under Ocre’s default
Referrer-Policy.
§Examples
use axum::{http::HeaderMap, response::IntoResponse};
let mut headers = HeaderMap::new();
headers.insert("host", "blog.example".parse().unwrap());
headers.insert("referer", "https://blog.example/posts?page=2".parse().unwrap());
let response = ocre::redirect_back(&headers, "/").into_response();
assert_eq!(response.headers()["location"], "/posts?page=2");
headers.insert("referer", "https://evil.example/".parse().unwrap());
let response = ocre::redirect_back(&headers, "/").into_response();
assert_eq!(response.headers()["location"], "/");