systemprompt_security/lib.rs
1//! Security infrastructure for systemprompt.io.
2//!
3//! Houses the request-level authentication primitives shared by the HTTP
4//! API and the runtime layer:
5//!
6//! - Asymmetric signing key plane ([`keys`]) — the in-process `TokenAuthority`
7//! holds the active RSA keypair, exposes the public set for
8//! `/.well-known/jwks.json`, and caches federated JWKS documents under a
9//! bounded LRU with an HTTPS allowlist.
10//! - JWT minting ([`jwt`]) for admin tokens and ([`session`]) for
11//! session-scoped tokens. Tokens are signed RS256 via `TokenAuthority` and
12//! carry a `kid` header; HS256 is rejected on validation.
13//! - Token extraction ([`extraction`]) from `Authorization` headers, MCP proxy
14//! headers, and cookies.
15//! - Request validation ([`auth`]) that turns those tokens into a
16//! [`systemprompt_models::execution::context::RequestContext`], resolving
17//! non-self-issued tokens against `profile.security.trusted_issuers` and
18//! propagating the RFC 8693 `act_chain` onto the per-request context.
19//! - At-rest hashing ([`at_rest`]) — `hmac_sha256` / `hmac_sha256_hex` under
20//! the deployment `oauth_at_rest_pepper`, used to store refresh-token ids and
21//! authorisation codes as digests rather than plaintext.
22//! - Google service-account credentials ([`google`]) — the RFC 7523 JWT-bearer
23//! exchange that turns a service-account key into a Google OAuth access
24//! token, with a process-wide token cache.
25//! - Bridge manifest signing ([`manifest_signing`]) with Ed25519 keys.
26//! - Lightweight scanner / bot detection ([`services`]).
27//! - Authorization decision plane ([`authz`]) — deny-overrides resolver,
28//! `access_control_rules` repository, and `AuthzDecisionHook` extension
29//! surface shared by the gateway and MCP enforcement sites.
30//! - Governed-call plane ([`policy`]) — the `GovernanceEngine` policy chain
31//! (secret scan, scope check, blocklist, rate limit + extension-registered
32//! policies) with per-entry audit tracing into `governance_decisions`.
33//!
34//! - Upstream-credential plane ([`credential`]) — a stored secret is parsed
35//! once into a `ProviderCredential`, which answers for its own scope
36//! (project, region, principal) and its own auth header; [`google`] is one
37//! implementation of that model, not a credential story of its own.
38//!
39//! All public fallible APIs return typed errors from [`error`] and
40//! [`credential::CredentialError`] — `anyhow` is not used in any public
41//! signature.
42//!
43//! # Feature flags
44//!
45//! This crate has no Cargo features; everything compiles by default.
46//!
47//! # Example
48//!
49//! ```no_run
50//! use systemprompt_models::auth::JwtAudience;
51//! use systemprompt_security::AuthValidationService;
52//!
53//! # fn demo(headers: &axum::http::HeaderMap) -> systemprompt_security::AuthResult<()> {
54//! let svc = AuthValidationService::new("systemprompt.io".to_string(), JwtAudience::standard());
55//! let _ctx = svc.validate_request(headers)?;
56//! # Ok(())
57//! # }
58//! ```
59//!
60//! Copyright (c) systemprompt.io — Business Source License 1.1.
61//! See <https://systemprompt.io> for licensing details.
62
63pub mod at_rest;
64pub mod auth;
65pub mod authz;
66pub mod credential;
67pub mod error;
68pub mod extraction;
69pub mod google;
70pub mod jwt;
71pub mod keys;
72pub mod manifest_signing;
73pub mod policy;
74pub mod services;
75pub mod session;
76
77pub use at_rest::{hmac_sha256, hmac_sha256_hex};
78
79pub use auth::{AuthValidationService, HookTokenValidator, ValidatedHookClaims};
80pub use authz::CompositeAuthzHook;
81pub use error::{
82 AuthError, AuthResult, JwtError, JwtResult, ManifestSigningError, ManifestSigningResult,
83};
84pub use extraction::{
85 CookieExtractionError, CookieExtractor, ExtractionMethod, HeaderExtractor,
86 HeaderInjectionError, HeaderInjector, TokenExtractionError, TokenExtractor,
87};
88pub use jwt::{AdminTokenParams, JwtService, JwtUserContext, extract_user_context};
89pub use services::ScannerDetector;
90pub use session::{SessionGenerator, SessionParams, ValidatedSessionClaims};