use actix_governor::{Governor, GovernorConfigBuilder}; use actix_web::web; use actix_web::web::ServiceConfig; use super::path::Path; mod login; mod logout; pub fn auth_factory(app: &mut ServiceConfig) { let base_path: Path = Path { prefix: String::from("/auth"), backend: true, }; // Login is the only unauthenticated endpoint that checks a password, so // it's the only one worth rate-limiting against brute-force/credential // stuffing. One request every 2s with a burst of 5 per IP. let login_rate_limit = GovernorConfigBuilder::default() .seconds_per_request(2) .burst_size(5) .finish() .expect("valid governor rate-limit config"); app.service( web::resource(base_path.define(String::from("/login"))) .wrap(Governor::new(&login_rate_limit)) .route(web::post().to(login::login)), ); app.route( &base_path.define(String::from("/logout")), web::post().to(logout::logout), ); }