Skip to main content

Crate ferrox_security

Crate ferrox_security 

Source
Expand description

§Ferrox Security (ferrox-security)

ferrox-security provides zero-trust authentication mechanisms, including PASETO (Platform-Agnostic Security Tokens) v4 local/public token generation, dual-token refresh rotation, password hashing abstractions, and authorization claim extractors.

§Why PASETO over JWT?

Traditional JSON Web Tokens (JWT) suffer from algorithm confusion attacks (e.g., none algorithm vulnerability, RSA vs HMAC confusion). PASETO eliminates algorithm negotiation entirely by hardcoding modern cryptographic primitives (Ed25519, XChaCha20-Poly1305), making security token handling foolproof.

§Key Features

  • 🛡️ PASETO v4 Support: Encrypted local tokens and signed public tokens.
  • 🔑 Token Engine: Issue, verify, and refresh access tokens securely.
  • 🔒 Password Hashing: Secure Argon2id password hashing integration.

Modules§

auth_middleware
dual_token
fingerprint
mtd
public_id
threats

Structs§

AuthPayload
PasetoAuth
A securely typed PASETO Auth Engine

Functions§

hash_password
Hashes a password securely using Argon2. The input is wrapped in Secret<String> to guarantee it doesn’t leak in logs.
setup
verify_password
Verifies a password against an Argon2 hash.