pub struct BasicAuth {
pub username: String,
pub password: String,
}Expand description
HTTP Basic credentials from Authorization: Basic ..., as an extractor (Rails’ http_basic_authenticate_with).
Rejects requests without valid Basic credentials with
BasicAuth::challenge: 401 and WWW-Authenticate: Basic, so the
browser asks for a user name and password. Check them with
matches (constant time) against Worker secrets, and
answer challenge when they are wrong. Browsers resend
the credentials on every request over HTTPS; use it for a staging site or
an internal page, not for user accounts (ocre g auth).
§Examples
use axum::{extract::State, response::{IntoResponse, Response}};
use ocre::{Ctx, Result, security::BasicAuth};
async fn admin(State(ctx): State<Ctx>, auth: BasicAuth) -> Result<Response> {
let password = ctx.secret("ADMIN_PASSWORD").await?;
if !auth.matches("admin", &password) {
return Ok(BasicAuth::challenge());
}
Ok("Welcome, admin".into_response())
}Fields§
§username: StringThe user name the client sent.
password: StringThe password the client sent.
Implementations§
Source§impl BasicAuth
impl BasicAuth
Sourcepub fn matches(&self, username: &str, password: &str) -> bool
pub fn matches(&self, username: &str, password: &str) -> bool
Whether the credentials are username and password, compared in constant time.
§Examples
use ocre::security::BasicAuth;
let auth = BasicAuth { username: "admin".into(), password: "s3cret".into() };
assert!(auth.matches("admin", "s3cret"));
assert!(!auth.matches("admin", "guess"));Sourcepub fn challenge() -> Response
pub fn challenge() -> Response
401 Unauthorized with WWW-Authenticate: Basic realm="Application": the browser asks again.
§Examples
let response = ocre::security::BasicAuth::challenge();
assert_eq!(response.status(), 401);
assert_eq!(response.headers()["www-authenticate"], r#"Basic realm="Application", charset="UTF-8""#);Trait Implementations§
impl Eq for BasicAuth
impl StructuralPartialEq for BasicAuth
Auto Trait Implementations§
impl Freeze for BasicAuth
impl RefUnwindSafe for BasicAuth
impl Send for BasicAuth
impl Sync for BasicAuth
impl Unpin for BasicAuth
impl UnsafeUnpin for BasicAuth
impl UnwindSafe for BasicAuth
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Checks if this value is equivalent to the given key. Read more
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.§impl<S, T> FromRequest<S, ViaParts> for T
impl<S, T> FromRequest<S, ViaParts> for T
§type Rejection = <T as FromRequestParts<S>>::Rejection
type Rejection = <T as FromRequestParts<S>>::Rejection
If the extractor fails it’ll use this “rejection” type. A rejection is
a kind of error that can be converted into a response.
§fn from_request(
req: Request<Body>,
state: &S,
) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
fn from_request( req: Request<Body>, state: &S, ) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
Perform the extraction.