Skip to main content

Module security

Module security 

Source
Expand description

Security module for bssh-server.

This module provides security features including:

§Authentication Rate Limiting

The AuthRateLimiter tracks failed authentication attempts per IP address and automatically bans IPs that exceed the configured threshold.

§Example

use bssh::server::security::{AuthRateLimiter, AuthRateLimitConfig};
use std::net::IpAddr;

#[tokio::main]
async fn main() {
    let config = AuthRateLimitConfig::default();
    let limiter = AuthRateLimiter::new(config);

    let ip: IpAddr = "192.168.1.100".parse().unwrap();

    // Check if banned before auth
    if limiter.is_banned(&ip).await {
        println!("IP is banned");
        return;
    }

    // On auth failure
    if limiter.record_failure(ip).await {
        println!("IP has been banned after too many failures");
    }

    // On auth success
    limiter.record_success(&ip).await;
}

§IP-based Access Control

The IpAccessControl provides whitelist and blacklist functionality for controlling which IP addresses can connect to the server.

§Example

use bssh::server::security::{IpAccessControl, AccessPolicy};

let mut access = IpAccessControl::new();

// Allow only private networks
access.allow_cidr("10.0.0.0/8").unwrap();
access.allow_cidr("192.168.0.0/16").unwrap();

// Block a specific subnet
access.block_cidr("192.168.100.0/24").unwrap();

let ip: std::net::IpAddr = "192.168.1.100".parse().unwrap();
assert_eq!(access.check(&ip), AccessPolicy::Allow);

Structs§

AuthRateLimitConfig
Configuration for authentication rate limiting.
AuthRateLimiter
Authentication rate limiter with ban support.
IpAccessControl
IP-based access control.
SharedIpAccessControl
Thread-safe wrapper for IP access control.

Enums§

AccessPolicy
Access policy decision.