Expand description
Security helpers beyond what serve always does: policies, rate limits, safe redirects, HTML cleaning.
serve already applies security headers, host authorization
(ALLOWED_HOSTS), CORS, cross-site request
(CSRF) protection and encrypted session cookies. This module adds what an
app opts into:
| Item | Rails equivalent |
|---|---|
ContentSecurityPolicy, CspNonce | content_security_policy, content_security_policy_nonce |
PermissionsPolicy | permissions_policy |
rate_limit | rate_limit to:, within:, by: |
url_from | url_from, redirect_to ... allow_other_host: false |
sanitize, sanitize_with, strip_tags | sanitize, strip_tags |
json_escape, escape_javascript | json_escape, escape_javascript |
filter_parameters, filter_json, FILTERED_PARAMETERS | filter_parameters |
BasicAuth | http_basic_authenticate_with |
AllowBrowser | allow_browser versions: :modern |
use axum::{Router, routing::get};
use ocre::security::{ContentSecurityPolicy, PermissionsPolicy, SELF};
let app: Router = Router::new()
.route("/", get(|| async { "home" }))
.layer(ContentSecurityPolicy::new().default_src(&[SELF]))
.layer(PermissionsPolicy::new().deny(&["camera", "microphone"]));Structs§
- Allow
Browser - Tower layer that answers
406 Not Acceptableto browsers older than the versions it allows (Rails’allow_browser). - Allow
Browser Service - The service built by the
AllowBrowserlayer. - Basic
Auth - HTTP Basic credentials from
Authorization: Basic ..., as an extractor (Rails’http_basic_authenticate_with). - Content
Security Policy - A
Content-Security-Policyheader, built directive by directive, and the layer that sends it. - CspNonce
- The request’s Content-Security-Policy nonce, as an extractor (Rails’
content_security_policy_nonce). - Permissions
Policy - A
Permissions-Policyheader, built feature by feature, and the layer that sends it. - Policy
Service - The service a
ContentSecurityPolicyorPermissionsPolicylayer wraps routes in.
Enums§
- Browser
- A browser family that
AllowBrowserrecognizes in theUser-Agentheader.
Constants§
- BLOB
blob:URLs (files built in the browser).- DATA
data:URLs (inline images, fonts).- FILTERED_
PARAMETERS - Parameter name fragments whose values
filter_parametersandfilter_jsonhide. - HTTPS
- Any
https:URL. - NONCE
- Placeholder for the request’s nonce: sent as
'nonce-<value>'(Rails’content_security_policy_nonce). - NONE
'none': nothing is allowed, in aContentSecurityPolicysource list.- SANITIZE_
ATTRIBUTES - Attributes
sanitizekeeps on those tags: Rails’ safe list. - SANITIZE_
TAGS - Tags
sanitizekeeps: Rails’ safe list (Rails::HTML5::SafeListSanitizer). - SELF
'self': the app’s own origin, in aContentSecurityPolicyorPermissionsPolicysource list.- STRICT_
DYNAMIC 'strict-dynamic': scripts loaded by a nonced script are trusted too.- UNSAFE_
EVAL 'unsafe-eval': allowsevalandnew Function(htmx’shx-onandjs:need it). Avoid it.- UNSAFE_
INLINE 'unsafe-inline': allows inline<style>/<script>andstyle=attributes. Avoid it for scripts.
Functions§
- escape_
javascript - Escapes text for a JavaScript string literal in single, double or back quotes (Rails’
escape_javascript). - filter_
json - A JSON value with sensitive values replaced by
"[FILTERED]", at any depth. - filter_
parameters - A query string or form body with sensitive values replaced by
[FILTERED](Rails’filter_parameters). - json_
escape - Escapes a JSON string for a
<script>element (Rails’json_escape). - rate_
limit - Counts one request for
keyagainst the Workers Rate Limiting bindingbinding; 429 when over the limit. - sanitize
- Cleans user-supplied HTML down to
SANITIZE_TAGSandSANITIZE_ATTRIBUTES(Rails’sanitize). - sanitize_
with - Like
sanitize, with your own allowed tags and attributes (Rails’sanitize(html, tags:, attributes:)). - strip_
tags - Removes every tag and comment and keeps the text, escaped (Rails’
strip_tags). - url_
from - The URL to redirect to when
candidatepoints inside this app, elseNone(Rails’url_from).