Auth & Validation
Guards, sessions, authorization attributes, CSRF protection, and validation rules.
Guards
Auth ships JWT (via jsonwebtoken) and session guards, with argon2 for password hashing and tower-sessions for the session store.
Guard mismatches return a typed Error::GuardMismatch rather than an opaque failure.
Authorization
The #[authorize] attribute resolves through the router's AuthorizeRegistry and is applied during dispatch, alongside #[middleware].
CSRF protection
Request forgery protection is origin-aware: PreventRequestForgery inspects Sec-Fetch-Site and rejects cross-site POSTs that do not carry a valid origin signal.
Validation
Validation combines validator derive macros with the custom rustasea-validation crate, which adds ErrorBag and FormRequest semantics.
Sessions and hardening
- The session store serializes to JSON by default (not a PHP-style format).
- Deserialization uses a security allow-list.
- The cache prefix is hyphenated, and the throttle layer is configured per route.
Last updated Sep 22, 2026