stac_auth_proxy.middleware.RejectAmbiguousPathMiddleware
¶
Middleware to reject requests whose checked and routed paths may differ.
RejectAmbiguousPathMiddleware
dataclass
¶
Reject requests whose request.url.path differs from the routed path.
Auth, filter and transaction checks match on request.url.path, which
Starlette rebuilds from the scope's scheme, server and path. Any request where
its path differs from scope["path"] (e.g. "/search%23" truncated to
"/search", or a scheme copied from a client's X-Forwarded-Proto) is rejected.
Paths that are only ambiguous once forwarded upstream are rejected by
ReverseProxyHandler, so the app's own routes (non-proxy mode) accept them.
IMPORTANT: Must run before any middleware that uses the request path.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
app
|
Callable[list, Awaitable[None]]
|
|
required |
Source code in src/stac_auth_proxy/middleware/RejectAmbiguousPathMiddleware.py
11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 | |
__call__(scope: Scope, receive: Receive, send: Send) -> None
async
¶
Reject ambiguous request paths.
Source code in src/stac_auth_proxy/middleware/RejectAmbiguousPathMiddleware.py
29 30 31 32 33 34 35 36 37 38 39 40 | |
query_is_utf8(scope: Scope) -> bool
staticmethod
¶
Whether the raw query string is valid UTF-8.
Source code in src/stac_auth_proxy/middleware/RejectAmbiguousPathMiddleware.py
42 43 44 45 46 47 48 49 | |
url_matches_scope(scope: Scope) -> bool
staticmethod
¶
Whether Starlette's request URL has the scope's path.
Source code in src/stac_auth_proxy/middleware/RejectAmbiguousPathMiddleware.py
51 52 53 54 55 56 57 58 59 60 61 62 63 | |