1
0
mirror of https://github.com/actix/actix-extras.git synced 2024-11-24 16:02:59 +01:00

allow only GET and HEAD for NamedFile

This commit is contained in:
Nikolay Kim 2018-03-05 14:04:30 -08:00
parent c8844425ad
commit 05e49e893e

View File

@ -8,14 +8,14 @@ use std::fs::{File, DirEntry};
use std::path::{Path, PathBuf}; use std::path::{Path, PathBuf};
use std::ops::{Deref, DerefMut}; use std::ops::{Deref, DerefMut};
use http::{header, Method};
use mime_guess::get_mime_type; use mime_guess::get_mime_type;
use param::FromParam; use param::FromParam;
use handler::{Handler, Responder}; use handler::{Handler, Responder};
use headers::ContentEncoding;
use httprequest::HttpRequest; use httprequest::HttpRequest;
use httpresponse::HttpResponse; use httpresponse::HttpResponse;
use httpcodes::{HttpOk, HttpFound}; use httpcodes::{HttpOk, HttpFound, HttpMethodNotAllowed};
/// A file with an associated name; responds with the Content-Type based on the /// A file with an associated name; responds with the Content-Type based on the
/// file extension. /// file extension.
@ -83,7 +83,13 @@ impl Responder for NamedFile {
type Item = HttpResponse; type Item = HttpResponse;
type Error = io::Error; type Error = io::Error;
fn respond_to(mut self, _: HttpRequest) -> Result<HttpResponse, io::Error> { fn respond_to(mut self, req: HttpRequest) -> Result<HttpResponse, io::Error> {
if *req.method() != Method::GET && *req.method() != Method::HEAD {
Ok(HttpMethodNotAllowed.build()
.header(header::CONTENT_TYPE, "text/plain")
.header(header::ALLOW, "GET, HEAD")
.body("This resource only supports GET and HEAD.").unwrap())
} else {
let mut resp = HttpOk.build(); let mut resp = HttpOk.build();
if let Some(ext) = self.path().extension() { if let Some(ext) = self.path().extension() {
let mime = get_mime_type(&ext.to_string_lossy()); let mime = get_mime_type(&ext.to_string_lossy());
@ -93,6 +99,7 @@ impl Responder for NamedFile {
let _ = self.1.read_to_end(&mut data); let _ = self.1.read_to_end(&mut data);
Ok(resp.body(data).unwrap()) Ok(resp.body(data).unwrap())
} }
}
} }
/// A directory; responds with the generated directory listing. /// A directory; responds with the generated directory listing.