Skip to main content

Module auth

Module auth 

Source
Expand description

Authentication middleware for the web dashboard.

This module provides HTTP Basic authentication against a bcrypt password hash, a lockout after repeated failures, and a short-lived cache of successful verifications.

  • Password hashes: the configured password_hash is always a bcrypt hash and is only ever verified with bcrypt, never compared as text. Verifying bcrypt needs the auth feature (on by default); a build without it rejects every password, and DashboardConfig::validate refuses to start such a build with authentication enabled.
  • Timing: the username is compared in constant time through a keyed hash, and bcrypt runs whether or not the username matched, so response times do not reveal the username.
  • Blocking: bcrypt runs on Tokio’s blocking thread pool (at most one verification per CPU at a time), never on the async worker threads. A successful verification is remembered for VERIFIED_CREDENTIALS_TTL (or session_timeout, if shorter), so a dashboard polling several endpoints does not pay for bcrypt on every request.
  • Lockout: failures are counted per client IP address (the connection’s address, never a header) and username, so an attacker cannot lock the administrator out from other addresses. After max_failed_attempts failures the client is refused for lockout_duration; afterwards the count starts over, and a successful login resets it. At most MAX_TRACKED_CLIENTS clients are tracked.

§Examples

§Basic Authentication Setup

use hammerwork_web::auth::AuthState;
use hammerwork_web::config::AuthConfig;

let auth_config = AuthConfig {
    enabled: true,
    username: "admin".to_string(),
    // A bcrypt hash, for example from `bcrypt::hash(password, bcrypt::DEFAULT_COST)`.
    password_hash: "$2b$12$abcdefghijklmnopqrstuuJ0Y7gZ8z5d0FQqfJb8yX3QZpGQ0lW6e".to_string(),
    ..Default::default()
};

let auth_state = AuthState::new(auth_config);
assert!(auth_state.is_enabled());

§Extracting Basic Auth Credentials

use hammerwork_web::auth::extract_basic_auth;

// "admin:password" in base64 is "YWRtaW46cGFzc3dvcmQ="
let auth_header = "Basic YWRtaW46cGFzc3dvcmQ=";
let (username, password) = extract_basic_auth(auth_header).unwrap();

assert_eq!(username, "admin");
assert_eq!(password, "password");

// Invalid format returns None
let result = extract_basic_auth("Bearer token123");
assert!(result.is_none());

Structs§

AuthState
Authentication middleware state. Cloning it shares the state.

Enums§

AuthError
Custom authentication errors
Verdict
The outcome of checking a set of credentials.

Constants§

MAX_TRACKED_CLIENTS
The most clients (IP address and username) whose failed attempts are tracked at once.
VERIFIED_CREDENTIALS_TTL
How long a successful verification is remembered, unless session_timeout is shorter.

Functions§

auth_filter
Authentication filter for Warp.
extract_basic_auth
Extract basic auth credentials from request.
handle_auth_rejection
Handle authentication rejections