Expand description
Authentication middleware for the web dashboard.
This module provides HTTP Basic authentication against a bcrypt password hash, a lockout after repeated failures, and a short-lived cache of successful verifications.
- Password hashes: the configured
password_hashis always a bcrypt hash and is only ever verified with bcrypt, never compared as text. Verifying bcrypt needs theauthfeature (on by default); a build without it rejects every password, andDashboardConfig::validaterefuses to start such a build with authentication enabled. - Timing: the username is compared in constant time through a keyed hash, and bcrypt runs whether or not the username matched, so response times do not reveal the username.
- Blocking: bcrypt runs on Tokio’s blocking thread pool (at most one verification per
CPU at a time), never on the async worker threads. A successful verification is
remembered for
VERIFIED_CREDENTIALS_TTL(orsession_timeout, if shorter), so a dashboard polling several endpoints does not pay for bcrypt on every request. - Lockout: failures are counted per client IP address (the connection’s address, never
a header) and username, so an attacker cannot lock the administrator out from other
addresses. After
max_failed_attemptsfailures the client is refused forlockout_duration; afterwards the count starts over, and a successful login resets it. At mostMAX_TRACKED_CLIENTSclients are tracked.
§Examples
§Basic Authentication Setup
use hammerwork_web::auth::AuthState;
use hammerwork_web::config::AuthConfig;
let auth_config = AuthConfig {
enabled: true,
username: "admin".to_string(),
// A bcrypt hash, for example from `bcrypt::hash(password, bcrypt::DEFAULT_COST)`.
password_hash: "$2b$12$abcdefghijklmnopqrstuuJ0Y7gZ8z5d0FQqfJb8yX3QZpGQ0lW6e".to_string(),
..Default::default()
};
let auth_state = AuthState::new(auth_config);
assert!(auth_state.is_enabled());§Extracting Basic Auth Credentials
use hammerwork_web::auth::extract_basic_auth;
// "admin:password" in base64 is "YWRtaW46cGFzc3dvcmQ="
let auth_header = "Basic YWRtaW46cGFzc3dvcmQ=";
let (username, password) = extract_basic_auth(auth_header).unwrap();
assert_eq!(username, "admin");
assert_eq!(password, "password");
// Invalid format returns None
let result = extract_basic_auth("Bearer token123");
assert!(result.is_none());Structs§
- Auth
State - Authentication middleware state. Cloning it shares the state.
Enums§
Constants§
- MAX_
TRACKED_ CLIENTS - The most clients (IP address and username) whose failed attempts are tracked at once.
- VERIFIED_
CREDENTIALS_ TTL - How long a successful verification is remembered, unless
session_timeoutis shorter.
Functions§
- auth_
filter - Authentication filter for Warp.
- extract_
basic_ auth - Extract basic auth credentials from request.
- handle_
auth_ rejection - Handle authentication rejections