Ferrox Guards (ferrox-guards)
ferrox-guards provides declarative role-based access control (RBAC) route extractors, zero-width evasion sanitizers, and session hijacking replay guards for Axum web applications.
🔑 Key Features
- 🛡️
FeatureSqueezer: Strips zero-width Unicode characters (\u{200B},\u{FEFF}), canonicalizes percent-encoded strings, and normalizes whitespace to prevent WAF evasion. - 🔒
SessionReplayDetector: Binds PASETO/JWT session tokens to client User-Agent and HTTP header structure fingerprints (ClientFingerprint), invalidating stolen token replay attempts. - 🔐 Declarative Guard Extractors: Axum extractors (
RequireRole) protecting handlers with compile-safe role constraints.
🚀 Quickstart Usage
Add ferrox-guards to your Cargo.toml:
[]
= "0.1.2"
= "0.7"
1. Zero-Width Unicode Evasion Sanitization (FeatureSqueezer)
use FeatureSqueezer;
2. Session Replay & Fingerprint Guard (SessionReplayDetector)
use ;
📜 License
Licensed under either of:
- Apache License, Version 2.0 (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0)
- MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT)
at your option.