finds.dev← search

// the find

maxcountryman/axum-login

★ 1,022 · Rust · MIT · updated Jun 2026

🪪 User identification, authentication, and authorization for Axum.

axum-login is a tower middleware crate that handles user identification, login sessions, and route-level authorization for Axum apps. It is for Rust web developers who want to bring their own user store and permission model instead of adopting a full auth framework. At 0.18 the API is still moving, so pin the version.

- `#![forbid(unsafe_code)]` is set at the crate root, so the auth path is safe Rust throughout. Session storage is delegated to tower-sessions rather than reimplemented here.

- The `AuthnBackend` and `AuthzBackend` traits keep the user store and permission model in your code. The crate doesn't assume Postgres, SQLite, LDAP, or an OAuth provider, and the examples show SQLite, OAuth2, multi-auth, and permission-gated routes.

- `session_auth_hash` ties a session to a value derived from the user, so changing a password can invalidate existing sessions. The trait forces that decision to be made explicitly rather than leaving it to chance.

- There are two overlapping middleware surfaces, the `require` builder and the `login_required!`/`permission_required!` macros. The README already calls the builder the long-term surface and the macros wrappers, so you are choosing between them now, and the macros may be the part that changes.

- The README says nothing about password hashing, credential verification, rate limiting, or CSRF on login forms. The quick start stubs the backend with `Ok(Some(User))` and a constant id of 0, which shows the trait shape and none of the parts that actually bite.

- The README calls the sessions 'rock-solid' and says 'no deadlocks' but gives no load or concurrency numbers. There is a benches directory, but the results aren't linked, so that claim rests on tower-sessions rather than on anything measured here.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →