pub struct PermissionsPolicy { /* private fields */ }Expand description
A Permissions-Policy header, built feature by feature, and the layer that sends it.
Rails’ permissions_policy initializer: it turns browser features
(camera, microphone, geolocation, …) off for the app and for the frames
it embeds. Add it with .layer(policy); like ContentSecurityPolicy,
a handler’s own header wins, so routes can override it.
In allowlists, SELF (or "self") and "*" are keywords; other
entries are origins, quoted in the header.
§Free plan
One header per response; no binding call.
§Examples
use axum::{Router, routing::get};
use ocre::security::{PermissionsPolicy, SELF};
let policy = PermissionsPolicy::new()
.deny(&["camera", "microphone", "geolocation"])
.allow("fullscreen", &[SELF, "https://player.example"]);
assert_eq!(
policy.header_value(),
r#"camera=(), microphone=(), geolocation=(), fullscreen=(self "https://player.example")"#
);
let app: Router = Router::new().route("/", get(|| async { "home" })).layer(policy);Implementations§
Source§impl PermissionsPolicy
impl PermissionsPolicy
Sourcepub fn allow(self, feature: &str, allowlist: &[&str]) -> Self
pub fn allow(self, feature: &str, allowlist: &[&str]) -> Self
Allows feature for the listed origins only; replaces a previous rule for it.
§Examples
use ocre::security::{PermissionsPolicy, SELF};
assert_eq!(PermissionsPolicy::new().allow("geolocation", &[SELF]).header_value(), "geolocation=(self)");
assert_eq!(PermissionsPolicy::new().allow("autoplay", &["*"]).header_value(), "autoplay=*");Sourcepub fn deny(self, features: &[&str]) -> Self
pub fn deny(self, features: &[&str]) -> Self
Turns features off everywhere: camera=().
§Examples
use ocre::security::PermissionsPolicy;
assert_eq!(PermissionsPolicy::new().deny(&["camera", "usb"]).header_value(), "camera=(), usb=()");Sourcepub fn header_value(&self) -> String
pub fn header_value(&self) -> String
The header value.
§Examples
let policy = ocre::security::PermissionsPolicy::new().deny(&["payment"]);
assert_eq!(policy.header_value(), "payment=()");Trait Implementations§
Source§impl Clone for PermissionsPolicy
impl Clone for PermissionsPolicy
Source§fn clone(&self) -> PermissionsPolicy
fn clone(&self) -> PermissionsPolicy
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for PermissionsPolicy
impl Debug for PermissionsPolicy
Source§impl Default for PermissionsPolicy
impl Default for PermissionsPolicy
Source§fn default() -> PermissionsPolicy
fn default() -> PermissionsPolicy
Returns the “default value” for a type. Read more
impl Eq for PermissionsPolicy
Source§impl<S> Layer<S> for PermissionsPolicy
impl<S> Layer<S> for PermissionsPolicy
Source§type Service = PolicyService<S, PermissionsPolicy>
type Service = PolicyService<S, PermissionsPolicy>
The wrapped service
Source§impl PartialEq for PermissionsPolicy
impl PartialEq for PermissionsPolicy
Source§fn eq(&self, other: &PermissionsPolicy) -> bool
fn eq(&self, other: &PermissionsPolicy) -> bool
Tests for
self and other values to be equal, and is used by ==.impl StructuralPartialEq for PermissionsPolicy
Auto Trait Implementations§
impl Freeze for PermissionsPolicy
impl RefUnwindSafe for PermissionsPolicy
impl Send for PermissionsPolicy
impl Sync for PermissionsPolicy
impl Unpin for PermissionsPolicy
impl UnsafeUnpin for PermissionsPolicy
impl UnwindSafe for PermissionsPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Checks if this value is equivalent to the given key. Read more
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.