oxedyne/fe2o3/fe2o3_net/src/guard/mod.rs
1.1 KiB, 10 runs
created by r1870400018:10864, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | //! Generic guards that make per-address and per-user accept/drop decisions. |
| 2 | //! |
| 3 | //! `addr::AddressGuard` is a transport-agnostic per-IP rate-limiter and blacklist. It was |
| 4 | //! originally lifted out of `fe2o3_shield`'s SHIELD UDP protocol so that any consumer -- |
| 5 | //! HTTPS servers, SMTP, IMAP, DNS resolvers, the SHIELD wire protocol itself -- can share a |
| 6 | //! single, hardened implementation. The SHIELD-specific handshake-sequence check is built |
| 7 | //! on top of the generic core via `AddressGuard::update_log`, leaving the base guard free of |
| 8 | //! protocol details. |
| 9 | //! |
| 10 | //! `user::UserGuard` is the per-user counterpart: a sharded map of trust state (Unknown / |
| 11 | //! Blacklist / Whitelist) with a caller-supplied data payload, likewise lifted out of |
| 12 | //! `fe2o3_shield` so any protocol can classify users, not only addresses. |
| 13 | //! |
| 14 | //! `nonce::NonceTracker` refuses a nonce shown twice inside a window, for a |
| 15 | //! signed command whose signer chose the nonce; it came from `fe2o3_steel`'s |
| 16 | //! signed admin login. |
| 17 | //! |
| 18 | //! [Written with AI entirely](https://need2know.ai/entirely-ai/code)\ |
| 19 | //! Anthropic Claude |
| 20 | |
| 21 | pub mod addr; |
| 22 | pub mod nonce; |
| 23 | pub mod user; |