From aba8046921b15e407f9f7e78bd3b2ae36a657c2b Mon Sep 17 00:00:00 2001 From: Jonas Platte Date: Fri, 26 Dec 2025 14:24:42 +0100 Subject: [PATCH] Deprecate Host and Scheme extractors --- axum-extra/src/extract/host.rs | 3 +++ axum-extra/src/extract/mod.rs | 2 ++ axum-extra/src/extract/scheme.rs | 2 ++ examples/tls-graceful-shutdown/src/main.rs | 23 +++++----------------- examples/tls-rustls/src/main.rs | 21 ++++---------------- 5 files changed, 16 insertions(+), 35 deletions(-) diff --git a/axum-extra/src/extract/host.rs b/axum-extra/src/extract/host.rs index f42018d2..edac555c 100644 --- a/axum-extra/src/extract/host.rs +++ b/axum-extra/src/extract/host.rs @@ -1,3 +1,5 @@ +#![allow(deprecated)] + use super::rejection::{FailedToResolveHost, HostRejection}; use axum_core::{ extract::{FromRequestParts, OptionalFromRequestParts}, @@ -25,6 +27,7 @@ const X_FORWARDED_HOST_HEADER_KEY: &str = "X-Forwarded-Host"; /// /// Note that user agents can set `X-Forwarded-Host` and `Host` headers to arbitrary values so make /// sure to validate them to avoid security issues. +#[deprecated = "will be removed in the next version; see https://github.com/tokio-rs/axum/issues/3442"] #[derive(Debug, Clone)] pub struct Host(pub String); diff --git a/axum-extra/src/extract/mod.rs b/axum-extra/src/extract/mod.rs index cd55ecf2..389c5f48 100644 --- a/axum-extra/src/extract/mod.rs +++ b/axum-extra/src/extract/mod.rs @@ -34,6 +34,7 @@ mod scheme; #[cfg(feature = "optional-path")] pub use self::optional_path::OptionalPath; +#[allow(deprecated)] pub use self::host::Host; #[cfg(feature = "cached")] @@ -62,6 +63,7 @@ pub use self::query::{OptionalQueryRejection, Query, QueryRejection}; #[cfg(feature = "multipart")] pub use self::multipart::Multipart; +#[allow(deprecated)] #[cfg(feature = "scheme")] #[doc(no_inline)] pub use self::scheme::{Scheme, SchemeMissing}; diff --git a/axum-extra/src/extract/scheme.rs b/axum-extra/src/extract/scheme.rs index 9d3bc0c3..267f81fd 100644 --- a/axum-extra/src/extract/scheme.rs +++ b/axum-extra/src/extract/scheme.rs @@ -1,5 +1,6 @@ //! Extractor that parses the scheme of a request. //! See [`Scheme`] for more details. +#![allow(deprecated)] use axum_core::{__define_rejection as define_rejection, extract::FromRequestParts}; use http::{ @@ -17,6 +18,7 @@ const X_FORWARDED_PROTO_HEADER_KEY: &str = "X-Forwarded-Proto"; /// /// Note that user agents can set the `X-Forwarded-Proto` header to arbitrary values so make /// sure to validate them to avoid security issues. +#[deprecated = "will be removed in the next version; see https://github.com/tokio-rs/axum/issues/3442"] #[derive(Debug, Clone)] pub struct Scheme(pub String); diff --git a/examples/tls-graceful-shutdown/src/main.rs b/examples/tls-graceful-shutdown/src/main.rs index 50256e28..9a17520b 100644 --- a/examples/tls-graceful-shutdown/src/main.rs +++ b/examples/tls-graceful-shutdown/src/main.rs @@ -6,12 +6,11 @@ use axum::{ handler::HandlerWithoutStateExt, - http::{uri::Authority, StatusCode, Uri}, + http::{StatusCode, Uri}, response::Redirect, routing::get, BoxError, Router, }; -use axum_extra::extract::Host; use axum_server::tls_rustls::RustlsConfig; use std::{future::Future, net::SocketAddr, path::PathBuf, time::Duration}; use tokio::signal; @@ -106,33 +105,21 @@ async fn redirect_http_to_https(ports: Ports, signal: F) where F: Future + Send + 'static, { - fn make_https(host: &str, uri: Uri, https_port: u16) -> Result { + fn make_https(uri: Uri, https_port: u16) -> Result { let mut parts = uri.into_parts(); parts.scheme = Some(axum::http::uri::Scheme::HTTPS); + parts.authority = Some(format!("localhost:{https_port}").parse()?); if parts.path_and_query.is_none() { parts.path_and_query = Some("/".parse().unwrap()); } - let authority: Authority = host.parse()?; - let bare_host = match authority.port() { - Some(port_struct) => authority - .as_str() - .strip_suffix(port_struct.as_str()) - .unwrap() - .strip_suffix(':') - .unwrap(), // if authority.port() is Some(port) then we can be sure authority ends with :{port} - None => authority.as_str(), - }; - - parts.authority = Some(format!("{bare_host}:{https_port}").parse()?); - Ok(Uri::from_parts(parts)?) } - let redirect = move |Host(host): Host, uri: Uri| async move { - match make_https(&host, uri, ports.https) { + let redirect = move |uri: Uri| async move { + match make_https(uri, ports.https) { Ok(uri) => Ok(Redirect::permanent(&uri.to_string())), Err(error) => { tracing::warn!(%error, "failed to convert URI to HTTPS"); diff --git a/examples/tls-rustls/src/main.rs b/examples/tls-rustls/src/main.rs index 53620eff..739de241 100644 --- a/examples/tls-rustls/src/main.rs +++ b/examples/tls-rustls/src/main.rs @@ -13,7 +13,6 @@ use axum::{ routing::get, BoxError, Router, }; -use axum_extra::extract::Host; use axum_server::tls_rustls::RustlsConfig; use std::{net::SocketAddr, path::PathBuf}; use tracing_subscriber::{layer::SubscriberExt, util::SubscriberInitExt}; @@ -72,33 +71,21 @@ async fn handler() -> &'static str { #[allow(dead_code)] async fn redirect_http_to_https(ports: Ports) { - fn make_https(host: &str, uri: Uri, https_port: u16) -> Result { + fn make_https(uri: Uri, https_port: u16) -> Result { let mut parts = uri.into_parts(); parts.scheme = Some(axum::http::uri::Scheme::HTTPS); + parts.authority = Some(format!("localhost:{https_port}").parse()?); if parts.path_and_query.is_none() { parts.path_and_query = Some("/".parse().unwrap()); } - let authority: Authority = host.parse()?; - let bare_host = match authority.port() { - Some(port_struct) => authority - .as_str() - .strip_suffix(port_struct.as_str()) - .unwrap() - .strip_suffix(':') - .unwrap(), // if authority.port() is Some(port) then we can be sure authority ends with :{port} - None => authority.as_str(), - }; - - parts.authority = Some(format!("{bare_host}:{https_port}").parse()?); - Ok(Uri::from_parts(parts)?) } - let redirect = move |Host(host): Host, uri: Uri| async move { - match make_https(&host, uri, ports.https) { + let redirect = move |uri: Uri| async move { + match make_https(uri, ports.https) { Ok(uri) => Ok(Redirect::permanent(&uri.to_string())), Err(error) => { tracing::warn!(%error, "failed to convert URI to HTTPS");