Skip to main content

Module security

Module security 

Source
Expand description

Security helpers beyond what serve always does: policies, rate limits, safe redirects, HTML cleaning.

serve already applies security headers, host authorization (ALLOWED_HOSTS), CORS, cross-site request (CSRF) protection and encrypted session cookies. This module adds what an app opts into:

ItemRails equivalent
ContentSecurityPolicy, CspNoncecontent_security_policy, content_security_policy_nonce
PermissionsPolicypermissions_policy
rate_limitrate_limit to:, within:, by:
url_fromurl_from, redirect_to ... allow_other_host: false
sanitize, sanitize_with, strip_tagssanitize, strip_tags
json_escape, escape_javascriptjson_escape, escape_javascript
filter_parameters, filter_json, FILTERED_PARAMETERSfilter_parameters
BasicAuthhttp_basic_authenticate_with
AllowBrowserallow_browser versions: :modern
use axum::{Router, routing::get};
use ocre::security::{ContentSecurityPolicy, PermissionsPolicy, SELF};

let app: Router = Router::new()
    .route("/", get(|| async { "home" }))
    .layer(ContentSecurityPolicy::new().default_src(&[SELF]))
    .layer(PermissionsPolicy::new().deny(&["camera", "microphone"]));

Structs§

AllowBrowser
Tower layer that answers 406 Not Acceptable to browsers older than the versions it allows (Rails’ allow_browser).
AllowBrowserService
The service built by the AllowBrowser layer.
BasicAuth
HTTP Basic credentials from Authorization: Basic ..., as an extractor (Rails’ http_basic_authenticate_with).
ContentSecurityPolicy
A Content-Security-Policy header, built directive by directive, and the layer that sends it.
CspNonce
The request’s Content-Security-Policy nonce, as an extractor (Rails’ content_security_policy_nonce).
PermissionsPolicy
A Permissions-Policy header, built feature by feature, and the layer that sends it.
PolicyService
The service a ContentSecurityPolicy or PermissionsPolicy layer wraps routes in.

Enums§

Browser
A browser family that AllowBrowser recognizes in the User-Agent header.

Constants§

BLOB
blob: URLs (files built in the browser).
DATA
data: URLs (inline images, fonts).
FILTERED_PARAMETERS
Parameter name fragments whose values filter_parameters and filter_json hide.
HTTPS
Any https: URL.
NONCE
Placeholder for the request’s nonce: sent as 'nonce-<value>' (Rails’ content_security_policy_nonce).
NONE
'none': nothing is allowed, in a ContentSecurityPolicy source list.
SANITIZE_ATTRIBUTES
Attributes sanitize keeps on those tags: Rails’ safe list.
SANITIZE_TAGS
Tags sanitize keeps: Rails’ safe list (Rails::HTML5::SafeListSanitizer).
SELF
'self': the app’s own origin, in a ContentSecurityPolicy or PermissionsPolicy source list.
STRICT_DYNAMIC
'strict-dynamic': scripts loaded by a nonced script are trusted too.
UNSAFE_EVAL
'unsafe-eval': allows eval and new Function (htmx’s hx-on and js: need it). Avoid it.
UNSAFE_INLINE
'unsafe-inline': allows inline <style>/<script> and style= attributes. Avoid it for scripts.

Functions§

escape_javascript
Escapes text for a JavaScript string literal in single, double or back quotes (Rails’ escape_javascript).
filter_json
A JSON value with sensitive values replaced by "[FILTERED]", at any depth.
filter_parameters
A query string or form body with sensitive values replaced by [FILTERED] (Rails’ filter_parameters).
json_escape
Escapes a JSON string for a <script> element (Rails’ json_escape).
rate_limit
Counts one request for key against the Workers Rate Limiting binding binding; 429 when over the limit.
sanitize
Cleans user-supplied HTML down to SANITIZE_TAGS and SANITIZE_ATTRIBUTES (Rails’ sanitize).
sanitize_with
Like sanitize, with your own allowed tags and attributes (Rails’ sanitize(html, tags:, attributes:)).
strip_tags
Removes every tag and comment and keeps the text, escaped (Rails’ strip_tags).
url_from
The URL to redirect to when candidate points inside this app, else None (Rails’ url_from).