// the find
maxcountryman/axum-login
🪪 User identification, authentication, and authorization for Axum.
axum-login is a tower middleware crate that handles user identification, login sessions, and route-level authorization for Axum apps. It is for Rust web developers who want to bring their own user store and permission model instead of adopting a full auth framework. At 0.18 the API is still moving, so pin the version.
- `#![forbid(unsafe_code)]` is set at the crate root, so the auth path is safe Rust throughout. Session storage is delegated to tower-sessions rather than reimplemented here.
- The `AuthnBackend` and `AuthzBackend` traits keep the user store and permission model in your code. The crate doesn't assume Postgres, SQLite, LDAP, or an OAuth provider, and the examples show SQLite, OAuth2, multi-auth, and permission-gated routes.
- `session_auth_hash` ties a session to a value derived from the user, so changing a password can invalidate existing sessions. The trait forces that decision to be made explicitly rather than leaving it to chance.
- There are two overlapping middleware surfaces, the `require` builder and the `login_required!`/`permission_required!` macros. The README already calls the builder the long-term surface and the macros wrappers, so you are choosing between them now, and the macros may be the part that changes.
- The README says nothing about password hashing, credential verification, rate limiting, or CSRF on login forms. The quick start stubs the backend with `Ok(Some(User))` and a constant id of 0, which shows the trait shape and none of the parts that actually bite.
- The README calls the sessions 'rock-solid' and says 'no deadlocks' but gives no load or concurrency numbers. There is a benches directory, but the results aren't linked, so that claim rests on tower-sessions rather than on anything measured here.