Skip to main content

Auth Middleware

1. Overview (What does this do?)โ€‹

The Auth Middleware module is an advanced component of the Ferrox ecosystem natively implemented in Rust. Core middleware for intercepting and verifying authentication tokens. It leverages the sheer performance of the Rust memory model to perform these operations with virtually zero latency, tightly integrating with the broader Sentinel mesh and CQRS bus.

2. Philosophy (Why does it exist?)โ€‹

In modern Enterprise architectures, relying on external services or API gateways for Auth operations introduces unacceptable network I/O bounds and points of failure. By embedding Auth Middleware directly into the Ferrox binary, we adhere to the Zero-Trust and Zero-Latency philosophy, ensuring that security and performance are mathematically guaranteed at compile-time rather than bolted on as an afterthought.

3. Target Audience (Who is it for?)โ€‹

This module is designed for DevSecOps engineers, system architects, and Rust developers building hyper-scale systems, financial exchanges, or military-grade data platforms where Auth is absolutely mission-critical.

4. Architecture (How does it work?)โ€‹

Auth Middleware operates natively within the ferrox execution graph. When an inbound request hits the FerroxApp transport layer, it is processed through the 7-Layer Onion Pipeline. At the appropriate layer, this module intercepts the payload or context:

  • It runs highly optimized Rust structures (often bypassing standard allocations using Bumpalo or [Singleflight](/docs/ferrox/security/singleflight)).
  • It evaluates the state deterministically.
  • It yields a Result Ok() to continue the pipeline, or an AppError which immediately aborts the connection.

5. Installation / Setupโ€‹

Because this is part of the core Ferrox Rust crates, it is available out-of-the-box when you use the ferrox metapackage.

[dependencies]
ferrox = { version = "1.0", features = ["auth-middleware"] }

6. Quickstart (Usage)โ€‹

Integrating Auth Middleware into your Rust application is entirely declarative:

use ferrox::security::sentinel::AuthMiddleware;
use ferrox::app::FerroxApp;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
let mut app = FerroxApp::new();

// Injecting the Auth Middleware into the [Sentinel](/docs/ferrox/security/ferrox-sentinel) Pipeline
let guard = AuthMiddleware::new()
.with_strict_mode(true)
.build();

app.add_guard(guard);

app.start().await
}

7. Ecosystem Integrationโ€‹

This component is designed to work in perfect harmony with the rest of the Ferrox ecosystem. For example, if Auth Middleware blocks a request, it automatically triggers an event on the Event Bus, which can be caught by the Webhooks system to alert administrators, or by the DataGrid for dashboard monitoring.