package middleware
- Alphabetic
- Public
- All
Type Members
-
final
case class
CORSConfig(anyOrigin: Boolean, allowCredentials: Boolean, maxAge: Long, anyMethod: Boolean = true, allowedOrigins: (String) ⇒ Boolean = _ => false, allowedMethods: Option[Set[String]] = None, allowedHeaders: Option[Set[String]] = Set("Content-Type", "*").some, exposedHeaders: Option[Set[String]] = Set("*").some) extends Product with Serializable
CORS middleware config options.
CORS middleware config options. You can give an instance of this class to the CORS middleware, to specify its behavoir
-
final
class
CSRF[F[_], G[_]] extends AnyRef
Middleware to avoid Cross-site request forgery attacks.
Middleware to avoid Cross-site request forgery attacks. More info on CSRF at: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)
This middleware is modeled after the double submit cookie pattern: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet#Double_Submit_Cookie
When a user authenticates,
embedNew
is used to send a random CSRF value as a cookie. (Alternatively, an authenticating service can be wrapped inwithNewToken
).By default, for requests that are unsafe (PUT, POST, DELETE, PATCH), services protected by the
validated
method in the middleware will check that the csrf token is present in both the headerheaderName
and the cookiecookieName
. Due to the Same-Origin policy, an attacker will be unable to reproduce this value in a custom header, resulting in a403 Forbidden
response.By default, requests with safe methods (such as GET, OPTIONS, HEAD) will have a new token embedded in them if there isn't one, or will receive a refreshed token based off of the previous token to mitigate the BREACH vulnerability. If a request contains an invalid token, regardless of whether it is a safe method, this middleware will fail it with
403 Forbidden
. In this situation, your user(s) should clear their cookies for your page, to receive a new token.The default can be overridden by modifying the
predicate
invalidate
. It will, by default, check if the method is safe. Thus, you can provide some whitelisting capability for certain kinds of requests.We'd like to emphasize that you please follow proper design principles in creating endpoints, as to not mutate in what should otherwise be idempotent methods (i.e no dropping your DB in a GET method, or altering user data). Please do not use the CSRF protection from this middleware as a safety net for bad design.
Value Members
-
object
AutoSlash
Removes a trailing slash from Request path
- object CORS
- object CSRF
- object ChunkAggregator
-
object
DefaultHead
Handles HEAD requests as a GET without a body.
Handles HEAD requests as a GET without a body.
If the service returns the fallthrough response, the request is resubmitted as a GET. The resulting response's body is killed, but all headers are preserved. This is a naive, but correct, implementation of HEAD. Routes requiring more optimization should implement their own HEAD handler.
- object EntityLimiter
- object GZip
-
object
HSTS
Middleware to add HTTP Strict Transport Security (HSTS) support adding the Strict Transport Security headers
- object HeaderEcho
-
object
Jsonp
Middleware to support wrapping json responses in jsonp.
Middleware to support wrapping json responses in jsonp.
Jsonp wrapping occurs when the request contains a parameter with the given name and the request Content-Type is
application/json
.If the wrapping is done, the response Content-Type is changed into
application/javascript
and the appropriate jsonp callback is applied. -
object
Logger
Simple Middleware for Logging All Requests and Responses
-
object
Metrics
Server middleware to record metrics for the http4s server.
Server middleware to record metrics for the http4s server.
This middleware will record: - Number of active requests - Time duration to send the response headers - Time duration to send the whole response body - Time duration of errors and other abnormal terminations
This middleware can be extended to support any metrics ecosystem by implementing the MetricsOps type
- object PushSupport
-
object
RequestLogger
Simple Middleware for Logging Requests As They Are Processed
-
object
ResponseLogger
Simple middleware for logging responses as they are processed
-
object
StaticHeaders
Simple middleware for adding a static set of headers to responses returned by a kleisli.
-
object
Throttle
Transform a service to reject any calls the go over a given rate.
- object Timeout
-
object
TranslateUri
Removes the given prefix from the beginning of the path of the Request.
-
object
UrlFormLifter
Middleware for lifting application/x-www-form-urlencoded bodies into the request query params.
Middleware for lifting application/x-www-form-urlencoded bodies into the request query params.
The params are merged into the existing paras _after_ the existing query params. This means that if the query already contains the pair "foo" -> Some("bar"), parameters on the body must be acessed through
multiParams
. -
object
VirtualHost
Middleware for virtual host mapping
Middleware for virtual host mapping
The
VirtualHost
middleware allows multiple services to be mapped based on the org.http4s.headers.Host header of the org.http4s.Request.
Deprecated Value Members
-
object
URITranslation
- Annotations
- @deprecated
- Deprecated
(Since version 0.18.16) Use org.http4s.server.middleware.TranslateUri instead