ferrox-guards 0.8.0

Declarative role-based access control (RBAC) route extractors, zero-width evasion sanitizers, and session replay guards for Axum.
Documentation

Ferrox Guards (ferrox-guards)

Crates.io Documentation License

ferrox-guards provides declarative role-based access control (RBAC) route extractors, zero-width evasion sanitizers, and session hijacking replay guards for Axum web applications.


🔑 Key Features

  • 🛡️ FeatureSqueezer: Strips zero-width Unicode characters (\u{200B}, \u{FEFF}), canonicalizes percent-encoded strings, and normalizes whitespace to prevent WAF evasion.
  • 🔒 SessionReplayDetector: Binds PASETO/JWT session tokens to client User-Agent and HTTP header structure fingerprints (ClientFingerprint), invalidating stolen token replay attempts.
  • 🔐 Declarative Guard Extractors: Axum extractors (RequireRole) protecting handlers with compile-safe role constraints.

🚀 Quickstart Usage

Add ferrox-guards to your Cargo.toml:

[dependencies]
ferrox-guards = "0.1.2"
axum = "0.7"

1. Zero-Width Unicode Evasion Sanitization (FeatureSqueezer)

use ferrox_guards::FeatureSqueezer;

fn main() {
    let raw_payload = "admin\u{200B}user%20login";
    let sanitized = FeatureSqueezer::squeeze(raw_payload);
    
    assert_eq!(sanitized.clean_text, "adminuser login");
    assert!(sanitized.zero_width_detected);
}

2. Session Replay & Fingerprint Guard (SessionReplayDetector)

use ferrox_guards::{ClientFingerprint, SessionReplayDetector, SessionStatus};

fn verify_session(user_agent: &str, accept_lang: &str, accept_enc: &str, bound_hash: &str) {
    let current_fp = ClientFingerprint::new(user_agent, accept_lang, accept_enc);
    
    match SessionReplayDetector::evaluate_session(bound_hash, &current_fp) {
        SessionStatus::Valid => println!("Session authenticated successfully"),
        SessionStatus::HijackDetected { .. } => println!("Session hijacking attempt detected!"),
    }
}

📜 License

Licensed under either of:

at your option.