auth ModuleThe Auth Module handles user authentication, session management, and account security. It includes support for:
src/
├── auth/
│ ├── api/
│ │ ├── auth.rs # Login, registration, 2FA, Google auth
│ │ ├── jwt.rs # JWT create/verify
│ │ ├── password.rs # Password hash & verify
│ │ └── two\_fa.rs # 2FA token logic
│ ├── shared/
| | ├── db.rs # Database connection
│ │ ├── email.rs # Email dispatch for verification / 2FA
│ │ └── two\_fa.rs # Email/SMS delivery methods
│ ├── constants.rs # Auth route constants
│ ├── entity/
│ │ ├── password\_reset.rs # Password reset
│ │ ├── email\_verification.rs # Email verification codes
│ │ └── two\_fa\_token.rs # 2FA token storage
│ └── auth\_middleware.rs # Role-based guard with user context
| Method | Path | Description |
|---|---|---|
| POST | /api/auth/login |
Login with email/password |
| POST | /api/auth/register |
Register new user |
| POST | /api/auth/logout |
Invalidate current session (JWT blacklist) |
| GET | /api/auth/refresh |
Refresh JWT using current token |
| POST | /api/auth/verify-2fa |
Submit 2FA code to finalize login |
| POST | /api/auth/resend-verification |
Resend email verification link |
| GET | /api/auth/verify-email |
Email verification using token |
| POST | /api/auth/login-google |
Login via Google OAuth |
/entity/users.rspub struct Model {
pub id: Uuid,
pub email: String,
pub password_hash: Option<String>,
pub email_verified: bool,
pub email_token: Option<String>,
pub requires_2fa: Option<bool>,
pub created_at: DateTime<Utc>,
pub role: String,
}
requires_2fa: enables 2FA for the useremail_token: used for email verification/entity/email_verification.rspub struct Model {
pub id: Uuid,
pub user_id: Uuid,
pub code: String,
pub expires_at: DateTime<Utc>,
}
/entity/two_fa_token.rspub struct Model {
pub id: Uuid,
pub user_id: Uuid,
pub code: String,
pub temp_token: String,
pub created_at: DateTime<Utc>,
pub expires_at: DateTime<Utc>,
pub attempts: i32,
pub sent_via: String,
}
LoginRequestpub struct LoginRequest {
pub email: String,
pub password: String,
}
RegisterRequestpub struct RegisterRequest {
pub name: String,
pub email: String,
pub password: String,
}
ResendVerificationRequestpub struct ResendVerificationRequest {
pub email: String,
}
GoogleTokenRequestpub struct GoogleTokenRequest {
pub token: String,
}
TwoFATokenpub struct TwoFAToken {
pub user_id: Uuid,
pub code: String,
pub temp_token: String,
pub created_at: DateTime<Utc>,
pub expires_at: DateTime<Utc>,
pub retries: i32,
pub delivery_method: String,
}
LoginResponsepub struct LoginResponse {
pub success: bool,
pub user_id: Option<Uuid>,
pub token: Option<String>,
pub temp_token: Option<String>,
pub error: Option<String>,
}
temp_token is returned when 2FA is requiredAuthResponsepub struct AuthResponse {
pub token: String,
}
/api/auth.rslogin_handler
register_handler
verify_email_handler
resend_verification_handler
logout_handler
refresh_handler
verify_2fa_handler
login_google_handler
/api/jwt.rscreate_jwt(user_id: Uuid) -> Result<String>
SECRET_KEYverify_jwt(token: &str) -> Result<Uuid>
/api/password.rshash_password
verify_password
/api/two_fa.rsgenerate_and_dispatch_2fa
verify_2fa
/auth_middleware.rsAuthenticatedUser
ensure_role method to restrict by rolepub async fn ensure_role(&self, required_role: &str) -> Result<(), StatusCode>