Repository navigation
API Key Authentication, Token Consolidation & JWT Handling
Purpose
This merge request introduces a comprehensive API key authentication system for automated/external integration, refactors and consolidates the core token management architecture, and transitions JWT key handling to an optimized, cloud-native environment variable model to improve security, performance, and Kubernetes deployment flexibility.
Features & Architecture Enhancements
- API Key Authentication:
- Full CRUD operations with dedicated GraphQL mutations (
createApiKey,updateApiKey,deleteApiKey,rotateApiKey). - Secure management via
apiKeysandapiKeyGraphQL queries. - Native
X-API-Keyheader support integrated into the authentication middleware. - Cryptographic security featuring SHA-256 hashing, precise expiration control, activation/deactivation states, and
last_used_atusage auditing.
- Full CRUD operations with dedicated GraphQL mutations (
- Token Module Consolidation:
- Unified token-related operations by consolidating JWT and generic token modules into
src/auth/token/. - Refactored token extraction to use high-performance
strip_prefixstring operations instead of regex.
- Unified token-related operations by consolidating JWT and generic token modules into
- Environment Configuration:
- Added
ALLOWED_ORIGINSparameter for highly configurable CORS setups. - Externalized core system UUIDs via environment variables to eliminate legacy database-lookup dependencies.
- Added
Performance & Optimizations
- Zero-Allocation Key Parsing: Refactored JWT logic to accept key slices directly (
&[u8]), avoiding unnecessary memory allocations and string copying during request cycles. - Explicit Initialization: Replaced
lazy_staticwith the standard librarystd::sync::OnceLock. Key formats are validated strictly once at application startup (main()) to prevent runtime crashes. - Password Hashing Upgrades: Removed deprecated
psw_saltfields, delegating all verification to native, fastargon2::verify_encodedchecks. - Parallel S3 Verification: Optimized file upload confirmation by implementing parallel S3 checks, significantly reducing response latency for multi-file operations.
- Hashing Optimization: Configured
argon2with low-latency parameters, reducing password verification overhead without compromising security. - Language Detection Refactor: Simplified language detection logic by replacing full
LanguageTagparsing with efficientstrip_prefixoperations, reducing allocation overhead.
Security
- Fail-Fast Enforcement: Invalid JWT key formats now trigger a clean process exit at startup with structured error logs, ensuring damaged secrets never reach runtime.
- SQL Injection Prevention: Hardened custom search queries against injection vectors by strictly using parameterized type-safe queries with
bind. - Session Lifetimes: Integrated
AUTH_DURATION_IN_HOURconfiguration to govern cookie and token expiration times uniformly. - Licensing Compliance: Added standard AGPL v3 license templates along with dual-licensing informational metadata.
- Security Headers: Added comprehensive security headers (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, CSP) to protect against common web vulnerabilities.
Bug Fixes & Refactoring
- Removed the redundant
TokenExpirederror variant in favor of standardServiceError::Unauthorized. - Fixed various typos in code comments and completed translation of code documentation to English.
- Replaced all
unwrap()calls with proper error handling (?,map_err, and custom error types) to eliminate potential panics and improve system reliability. - Migrated from
Local::now()toUtc::now()for consistent UTC-based timestamps across all services, eliminating timezone-related inconsistencies. - Standardized context variable naming from
cxttoctxthroughout the codebase for improved readability and consistency with Rust conventions.