Skip to content

feat: Remove cookie extraction for Jwt, but allow it in JwtCsrf - #332

Merged
spencewenski merged 1 commit into
mainfrom
jwt-provide-extraction-source
Aug 16, 2024
Merged

feat: Remove cookie extraction for Jwt, but allow it in JwtCsrf#332
spencewenski merged 1 commit into
mainfrom
jwt-provide-extraction-source

Conversation

@spencewenski

Copy link
Copy Markdown
Member

Add a new axum extractor called JwtCsrf that allows extracting the JWT from a cookie (if the auth.jwt.cookie-name config is set). This extractor provides some metadata about whether it's safe to use the JWT or if a CSRF protection mechanism needs to be applied first.

With this, we also remove cookie extraction from the normal Jwt, so it can safely be used without any CSRF protection mechanisms.

@codecov

codecov Bot commented Aug 16, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 0% with 56 lines in your changes missing coverage. Please review.

Project coverage is 48.28%. Comparing base (64c51f6) to head (67ec1ff).

Files Patch % Lines
src/middleware/http/auth/jwt/mod.rs 0.00% 56 Missing ⚠️
Files Coverage Δ
src/middleware/http/auth/jwt/mod.rs 52.44% <0.00%> (-11.66%) ⬇️

Continue to review full report in Codecov by Sentry.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 64c51f6...67ec1ff. Read the comment docs.

Add a new axum extractor called `JwtCsrf` that allows extracting the JWT
from a cookie (if the `auth.jwt.cookie-name` config is set). This
extractor provides some metadata about whether it's safe to use the JWT
or if a CSRF protection mechanism needs to be applied first.

With this, we also remove cookie extraction from the normal `Jwt`, so it
can safely be used without any CSRF protection mechanisms.
@spencewenski
spencewenski force-pushed the jwt-provide-extraction-source branch from 44f2c73 to 67ec1ff Compare August 16, 2024 09:47
@spencewenski
spencewenski merged commit c49eeb4 into main Aug 16, 2024
@spencewenski
spencewenski deleted the jwt-provide-extraction-source branch August 16, 2024 10:05
@github-actions github-actions Bot mentioned this pull request Aug 25, 2024
spencewenski added a commit that referenced this pull request Aug 26, 2024
## 🤖 New release
* `roadster`: 0.5.19 -> 0.6.0

<details><summary><i><b>Changelog</b></i></summary><p>

<blockquote>

##
[0.6.0](roadster-v0.5.19...roadster-v0.6.0)
- 2024-08-25

### Added
- Add a public method to decode a JWT from a string
([#348](#348))
- Mark refresh token headers as sensitive
([#347](#347))
- Make the `User` sea-orm migration enum public
([#346](#346))
- Allow splitting config files into many files in env directories
([#344](#344))
- [**breaking**] App methods take `self`
([#337](#337))
- Remove cookie extraction for `Jwt`, but allow it in `JwtCsrf`
([#332](#332))
- Allow custom sub-claims in provided `Claims` types
([#331](#331))
- Allow jwt from cookie, but only if it's explicitly requested
([#329](#329))

### Fixed
- [**breaking**] Don't expect a "Bearer" token in the auth token cookie
([#340](#340))

### Other
- Remove a `todo` comment
([#345](#345))
- Remove a todo comment from the tracing mod
([#343](#343))
- Update leptos example to use site-addr and env from roadster config
([#341](#341))
- sea-orm workspace dep and upgrade to `1.0.0`
([#336](#336))
- [**breaking**] Update tower to `0.5.0`
([#334](#334))
</blockquote>


</p></details>

---
This PR was generated with
[release-plz](https://github.com/MarcoIeni/release-plz/).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Spencer Ferris <3319370+spencewenski@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant