pub struct AllowBrowser { /* private fields */ }Expand description
Tower layer that answers 406 Not Acceptable to browsers older than the versions it allows (Rails’ allow_browser).
modern is Rails’ versions: :modern: browsers with
WebP images, web push, badges, import maps, CSS nesting and CSS :has
(Safari 17.2, Chrome and Edge 120, Firefox 121, Opera 106; no Internet
Explorer). Requests whose User-Agent is missing or names no known
browser (bots, curl, API clients, uptime checks) always pass, as in
Rails. Outdated browsers get a short HTML page asking to upgrade
(replace it with page). Pure CPU, no binding call.
Apply it to the routes of pages (.layer(...) on a Router), not to
JSON APIs or webhooks, whose clients are not browsers anyway.
§Examples
use axum::{Router, routing::get};
use ocre::security::{AllowBrowser, Browser};
let app: Router = Router::new().route("/", get(|| async { "home" })).layer(AllowBrowser::modern());
let policy = AllowBrowser::new().minimum(Browser::Firefox, 115, 0).deny(Browser::InternetExplorer);
assert!(policy.allows(Some("Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0")));
assert!(!policy.allows(Some("Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0")));
assert!(policy.allows(None));Implementations§
Source§impl AllowBrowser
impl AllowBrowser
Sourcepub fn modern() -> Self
pub fn modern() -> Self
Rails’ allow_browser versions: :modern: Safari 17.2, Chrome and Edge 120, Firefox 121, Opera 106, no Internet Explorer.
§Examples
use ocre::security::AllowBrowser;
let old_chrome = "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36";
assert!(!AllowBrowser::modern().allows(Some(old_chrome)));Sourcepub fn minimum(self, browser: Browser, major: u32, minor: u32) -> Self
pub fn minimum(self, browser: Browser, major: u32, minor: u32) -> Self
Allows browser from version major.minor on; replaces an earlier rule for the same browser.
§Examples
use ocre::security::{AllowBrowser, Browser};
let policy = AllowBrowser::modern().minimum(Browser::Safari, 16, 0);
let safari_16 = "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6 like Mac OS X) AppleWebKit/605.1.15 \
(KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1";
assert!(policy.allows(Some(safari_16)));Sourcepub fn deny(self, browser: Browser) -> Self
pub fn deny(self, browser: Browser) -> Self
Refuses every version of browser (Rails’ ie: false).
§Examples
use ocre::security::{AllowBrowser, Browser};
let policy = AllowBrowser::new().deny(Browser::InternetExplorer);
assert!(!policy.allows(Some("Mozilla/5.0 (Windows NT 10.0; Trident/7.0; rv:11.0) like Gecko")));Sourcepub fn page(self, html: impl Into<String>) -> Self
pub fn page(self, html: impl Into<String>) -> Self
Replaces the HTML page sent with the 406 (by default a short “please upgrade your browser” page).
§Examples
let policy = ocre::security::AllowBrowser::modern().page("<h1>Please use a recent browser.</h1>");Sourcepub fn allows(&self, user_agent: Option<&str>) -> bool
pub fn allows(&self, user_agent: Option<&str>) -> bool
Whether a request with this User-Agent passes: a missing header or an unknown client always does.
§Examples
use ocre::security::AllowBrowser;
let policy = AllowBrowser::modern();
assert!(policy.allows(Some("Googlebot/2.1 (+http://www.google.com/bot.html)")));
assert!(policy.allows(None));Trait Implementations§
Source§impl Clone for AllowBrowser
impl Clone for AllowBrowser
Source§fn clone(&self) -> AllowBrowser
fn clone(&self) -> AllowBrowser
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more