Skip to content

v0.9.0

Choose a tag to compare

@davlgd davlgd released this 17 Jan 01:33
· 63 commits to main since this release

Added

  • HTTP Basic Authentication (RFC 7617): Protect your endpoints with username/password
    • Support for multiple password formats: plain text, bcrypt, APR1 MD5, SHA1
    • Constant-time comparison to prevent timing attacks
    • Multiple users via CC_HTTP_BASIC_AUTH_N environment variables
    • Configurable realm via CC_HTTP_BASIC_AUTH_REALM
  • Bearer Token Authentication (RFC 6750): API key authentication
    • Simple token-based authentication via CC_BEARER_TOKEN
    • Constant-time comparison to prevent timing attacks
    • Can be used alone or combined with Basic Auth (either method accepted)
  • auth module: New wisegate-core/src/auth/ module with:
    • Credentials struct for credential storage
    • hash::verify() for multi-format password verification
    • hash::constant_time_eq() for secure comparison
    • check_basic_auth() for request authentication
    • check_bearer_token() for bearer token verification
  • AuthenticationProvider trait: Configuration trait for authentication settings
    • bearer_token() method for bearer token access
    • is_basic_auth_enabled() and is_bearer_auth_enabled() helpers
  • New environment variables: CC_HTTP_BASIC_AUTH, CC_HTTP_BASIC_AUTH_N, CC_HTTP_BASIC_AUTH_REALM, CC_BEARER_TOKEN
  • New error types: AuthenticationRequired, InvalidCredentials
  • New headers: AUTHORIZATION, WWW_AUTHENTICATE constants
  • 51 new tests: Comprehensive coverage for auth module

Changed

  • Request pipeline now includes authentication check after method blocking, before rate limiting
  • ConfigProvider trait now requires AuthenticationProvider implementation
  • Startup info displays authentication status (Basic Auth and Bearer Token)

Full Changelog: v0.8.0...v0.9.0