refactor: apply clippy let-chains and harden password validation
- Auto-fix 29 clippy warnings by converting nested if-lets to let-chains - Harden password strength validator to reject restricted substrings - Simplify rate_limiter state checks using is_none_or - Improves idiomatic Rust style and overall security posture
This commit is contained in:
1 parent
f2f615b456
commit
b25a015898
17 files changed
+81
-109
No files matched your search
+6
-9
@@ -68,11 +68,10 @@ pub async fn login(
|
||||
}
|
||||
|
||||
// Rate limit check (per IP)
|
||||
if let Some(ip_str) = &ctx.ip_address {
|
||||
if let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
|
||||
if let Some(ip_str) = &ctx.ip_address
|
||||
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
|
||||
state.rate_limiter.check(ip_addr)?;
|
||||
}
|
||||
}
|
||||
|
||||
// Look up user — always run comparable work on failure paths (timing).
|
||||
let user_opt = state
|
||||
@@ -103,11 +102,10 @@ pub async fn login(
|
||||
|
||||
if !is_authed {
|
||||
record_login_failure(&state, body.username.trim(), ip, ctx.user_agent.as_deref()).await;
|
||||
if let Some(ip_str) = &ctx.ip_address {
|
||||
if let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
|
||||
if let Some(ip_str) = &ctx.ip_address
|
||||
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
|
||||
state.rate_limiter.record_failure(ip_addr);
|
||||
}
|
||||
}
|
||||
// Non-enumerating error for both unknown user and bad password.
|
||||
return Err(AppError::InvalidCredentials);
|
||||
}
|
||||
@@ -118,11 +116,10 @@ pub async fn login(
|
||||
};
|
||||
|
||||
// Clear rate limit on success
|
||||
if let Some(ip_str) = &ctx.ip_address {
|
||||
if let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
|
||||
if let Some(ip_str) = &ctx.ip_address
|
||||
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() {
|
||||
state.rate_limiter.record_success(ip_addr);
|
||||
}
|
||||
}
|
||||
|
||||
// Session fixation mitigation: revoke prior sessions + refresh tokens.
|
||||
let _ = state
|
||||
|
||||
Reference in new issue
Block a user