refactor: apply clippy let-chains and harden password validation

- Auto-fix 29 clippy warnings by converting nested if-lets to let-chains
- Harden password strength validator to reject restricted substrings
- Simplify rate_limiter state checks using is_none_or
- Improves idiomatic Rust style and overall security posture
This commit is contained in:
thakares committed 2026-08-07 19:48:25 +05:30
1 parent f2f615b456
commit b25a015898
17 files changed
+81 -109

No files matched your search

+6 -9
View File
@@ -68,11 +68,10 @@ pub async fn login(
}
// Rate limit check (per IP)
if let Some(ip_str) = &ctx.ip_address {
if let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
if let Some(ip_str) = &ctx.ip_address
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
state.rate_limiter.check(ip_addr)?;
}
}
// Look up user — always run comparable work on failure paths (timing).
let user_opt = state
@@ -103,11 +102,10 @@ pub async fn login(
if !is_authed {
record_login_failure(&state, body.username.trim(), ip, ctx.user_agent.as_deref()).await;
if let Some(ip_str) = &ctx.ip_address {
if let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
if let Some(ip_str) = &ctx.ip_address
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
state.rate_limiter.record_failure(ip_addr);
}
}
// Non-enumerating error for both unknown user and bad password.
return Err(AppError::InvalidCredentials);
}
@@ -118,11 +116,10 @@ pub async fn login(
};
// Clear rate limit on success
if let Some(ip_str) = &ctx.ip_address {
if let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
if let Some(ip_str) = &ctx.ip_address
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
state.rate_limiter.record_success(ip_addr);
}
}
// Session fixation mitigation: revoke prior sessions + refresh tokens.
let _ = state