diff --git a/.env.example b/.env.example index 2b679a4..2e5ff45 100644 --- a/.env.example +++ b/.env.example @@ -36,6 +36,14 @@ DATABASE_URL=postgres://postgres@localhost:5432/integration_proxy # openssl rand -base64 32 | tr '+/' '-_' | tr -d '=\n' ENCRYPTION_KEY= +# Where the client address of the per-network key-check limit comes from +# (0.3.0+): `none` (TCP peer), or `heroku`/`rightmost` (the right-most +# X-Forwarded-For entry). localthought.io on Heroku must set `heroku`, or every +# client shares the router's limit. +TRUST_FORWARDED_FOR=none +# Key checks per client network and platform per hour (default 20, 0 = off). +KEY_CHECK_LIMIT_PER_HOUR=20 + # Spotify Web API uses PKCE; no client secret is needed. Its authorization # server advertises only the public "none" client authentication method, so # that must be set explicitly (the proxy otherwise defaults to diff --git a/Cargo.lock b/Cargo.lock index e06a3ac..64f4be7 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -59,15 +59,16 @@ dependencies = [ [[package]] name = "atomic-integration-proxy" -version = "0.2.5" +version = "0.3.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7fc905daad0fc05e6d0c8cbdc865cc44fd531b23f770121e79ad70cb8faab27f" +checksum = "1f63effacd1a864b68b6cefd260f8a62ce59e2d4de719080f6c804b07372f472" dependencies = [ "axum", "axum-extra", "base64", "chacha20poly1305", "ed25519-dalek", + "hmac 0.12.1", "native-tls", "postgres-native-tls", "rand 0.8.8", @@ -474,6 +475,7 @@ checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292" dependencies = [ "block-buffer 0.10.4", "crypto-common 0.1.7", + "subtle", ] [[package]] @@ -696,6 +698,15 @@ version = "0.17.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "ed5909b6e89a2db4456e54cd5f673791d7eca6732202bbf2a9cc504fe2f9b84a" +[[package]] +name = "hmac" +version = "0.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6c49c37c09c17a53d937dfbb742eb3a961d65a994e6bcdcf37e7399d0cc8ab5e" +dependencies = [ + "digest 0.10.7", +] + [[package]] name = "hmac" version = "0.13.0" @@ -1332,7 +1343,7 @@ dependencies = [ "byteorder", "bytes", "fallible-iterator", - "hmac", + "hmac 0.13.0", "md-5", "memchr", "rand 0.10.2", diff --git a/Cargo.toml b/Cargo.toml index 659ef92..ba847b2 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -17,7 +17,7 @@ publish = false # Published to crates.io from ontola/atomic-plugins' integration-proxy/. # Bump this (and run `cargo update -p atomic-integration-proxy`) to deploy a # new release. -atomic-integration-proxy = "=0.2.5" +atomic-integration-proxy = "=0.3.0" tokio = { version = "1", features = ["rt-multi-thread", "macros"] } [profile.release]