ferrox-security 0.8.0

PASETO v4 token translation engine, JWT claim extractors, and role-based authentication primitives.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
# Ferrox Security (`ferrox-security`)


`ferrox-security` provides zero-trust authentication mechanisms, including PASETO (Platform-Agnostic Security Tokens) v4 local/public token generation,
dual-token refresh rotation, password hashing abstractions, and authorization claim extractors.

## Why PASETO over JWT?

Traditional JSON Web Tokens (JWT) suffer from algorithm confusion attacks (e.g., `none` algorithm vulnerability, RSA vs HMAC confusion).
PASETO eliminates algorithm negotiation entirely by hardcoding modern cryptographic primitives (Ed25519, XChaCha20-Poly1305), making security token handling foolproof.

## Key Features

- 🛡️ **PASETO v4 Support**: Encrypted local tokens and signed public tokens.
- 🔑 **Token Engine**: Issue, verify, and refresh access tokens securely.
- 🔒 **Password Hashing**: Secure Argon2id password hashing integration.