Auth for axum
High-level http auth extractors for axum
🚨 This crate provides an alternative to TypedHeader<Authorization<..>>
which you may use instead. Take a look at the fantastic axum-login crate if your looking for more robust session management. I will continue to maintain this crate.
Usage
Bearer Authentication:
use AuthBearer;
/// Handler for a typical axum route, takes a `token` and returns it
async
Basic Authentication:
use AuthBasic;
/// Takes basic auth details and shows a message
async : AuthBasic)
You can also define custom extractors, letting you return custom extractors, status codes, and messages to users if the auth fails. Check out the crate documentation for more in-depth information into how everything works!
Installation
Simply place the following inside of your Cargo.toml
file for axum:
[]
= "0.7"
Our version follows axum since 0.7. You can also enable just basic/bearer auth via features. To enable just basic auth, you can add this to the Cargo.toml
file instead:
[]
= { = "0.7", = false, = ["auth-basic"] }
If you're still using axum 0.5, use version 0.3. If you're still using axum 0.6, use version 0.4.
Security
Some essential security considerations to take into account are the following:
- This crate has not been audited by any security professionals. If you are willing to do or have already done an audit on this crate, please create an issue as it would help out enormously! 😊
- This crate purposefully does not limit the maximum length of headers arriving so please ensure your webserver configurations are set properly.
Licensing
This project is dual-licensed under both the MIT and Apache, so feel free to use either at your discretion.