pub struct CspNonce(/* private fields */);Expand description
The request’s Content-Security-Policy nonce, as an extractor (Rails’ content_security_policy_nonce).
A new random value (16 bytes, base64) per request, created by the
ContentSecurityPolicy layer and sent as 'nonce-<value>' wherever the
policy lists NONCE. Pass it to the template and write
<script nonce="{{ nonce }}">; <meta name="csp-nonce" content="{{ nonce }}">
exposes it to JavaScript (Rails’ csp_meta_tag). Rejects with
Error::Internal when no policy layer wraps the route.
§Examples
use axum::response::Html;
use ocre::security::CspNonce;
async fn page(nonce: CspNonce) -> Html<String> {
Html(format!(r#"<script nonce="{nonce}">console.log("allowed")</script>"#))
}Implementations§
Trait Implementations§
impl Eq for CspNonce
impl StructuralPartialEq for CspNonce
Auto Trait Implementations§
impl Freeze for CspNonce
impl RefUnwindSafe for CspNonce
impl Send for CspNonce
impl Sync for CspNonce
impl Unpin for CspNonce
impl UnsafeUnpin for CspNonce
impl UnwindSafe for CspNonce
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Checks if this value is equivalent to the given key. Read more
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.§impl<S, T> FromRequest<S, ViaParts> for T
impl<S, T> FromRequest<S, ViaParts> for T
§type Rejection = <T as FromRequestParts<S>>::Rejection
type Rejection = <T as FromRequestParts<S>>::Rejection
If the extractor fails it’ll use this “rejection” type. A rejection is
a kind of error that can be converted into a response.
§fn from_request(
req: Request<Body>,
state: &S,
) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
fn from_request( req: Request<Body>, state: &S, ) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
Perform the extraction.