Skip to content

v0.3.2

Latest

Choose a tag to compare

@mnnxp mnnxp released this 06 Sep 21:26
· 3 commits to master since this release

API Key Authentication, Token Consolidation & JWT Handling

Purpose

This merge request introduces a comprehensive API key authentication system for automated/external integration, refactors and consolidates the core token management architecture, and transitions JWT key handling to an optimized, cloud-native environment variable model to improve security, performance, and Kubernetes deployment flexibility.

Features & Architecture Enhancements

  • API Key Authentication:
    • Full CRUD operations with dedicated GraphQL mutations (createApiKey, updateApiKey, deleteApiKey, rotateApiKey).
    • Secure management via apiKeys and apiKey GraphQL queries.
    • Native X-API-Key header support integrated into the authentication middleware.
    • Cryptographic security featuring SHA-256 hashing, precise expiration control, activation/deactivation states, and last_used_at usage auditing.
  • Token Module Consolidation:
    • Unified token-related operations by consolidating JWT and generic token modules into src/auth/token/.
    • Refactored token extraction to use high-performance strip_prefix string operations instead of regex.
  • Environment Configuration:
    • Added ALLOWED_ORIGINS parameter for highly configurable CORS setups.
    • Externalized core system UUIDs via environment variables to eliminate legacy database-lookup dependencies.

Performance & Optimizations

  • Zero-Allocation Key Parsing: Refactored JWT logic to accept key slices directly (&[u8]), avoiding unnecessary memory allocations and string copying during request cycles.
  • Explicit Initialization: Replaced lazy_static with the standard library std::sync::OnceLock. Key formats are validated strictly once at application startup (main()) to prevent runtime crashes.
  • Password Hashing Upgrades: Removed deprecated psw_salt fields, delegating all verification to native, fast argon2::verify_encoded checks.
  • Parallel S3 Verification: Optimized file upload confirmation by implementing parallel S3 checks, significantly reducing response latency for multi-file operations.
  • Hashing Optimization: Configured argon2 with low-latency parameters, reducing password verification overhead without compromising security.
  • Language Detection Refactor: Simplified language detection logic by replacing full LanguageTag parsing with efficient strip_prefix operations, reducing allocation overhead.

Security

  • Fail-Fast Enforcement: Invalid JWT key formats now trigger a clean process exit at startup with structured error logs, ensuring damaged secrets never reach runtime.
  • SQL Injection Prevention: Hardened custom search queries against injection vectors by strictly using parameterized type-safe queries with bind.
  • Session Lifetimes: Integrated AUTH_DURATION_IN_HOUR configuration to govern cookie and token expiration times uniformly.
  • Licensing Compliance: Added standard AGPL v3 license templates along with dual-licensing informational metadata.
  • Security Headers: Added comprehensive security headers (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, CSP) to protect against common web vulnerabilities.

Bug Fixes & Refactoring

  • Removed the redundant TokenExpired error variant in favor of standard ServiceError::Unauthorized.
  • Fixed various typos in code comments and completed translation of code documentation to English.
  • Replaced all unwrap() calls with proper error handling (?, map_err, and custom error types) to eliminate potential panics and improve system reliability.
  • Migrated from Local::now() to Utc::now() for consistent UTC-based timestamps across all services, eliminating timezone-related inconsistencies.
  • Standardized context variable naming from cxt to ctx throughout the codebase for improved readability and consistency with Rust conventions.