Skip to main content

AuthFailures

Struct AuthFailures 

Source
pub struct AuthFailures { /* private fields */ }
Expand description

The authentication failures one connection has run up, in buckets.

Which bucket a failure lands in is what makes clearing them on success honest. auth.users is a list, so a peer can hold one valid credential and guess at another user’s password with it: with one counter cleared by any success, it interleaves a good request between guesses and never reaches max_auth_failures. One counter per user-id guessed at closes that, and leaves the case the clearing exists for — one client, one credential, an app that drops the header now and then — exactly as it was.

A single run charged to the first failure that named somebody was the earlier answer and was not enough: the peer opens each cycle with a deliberate failure as itself, which claims the run, and its success as itself then clears the whole thing, guesses at everybody else included.

The cap is on the total across the buckets, not on any one of them. A per-bucket cap would hand a guesser max_auth_failures - 1 free guesses for every configured user rather than that many for the whole connection.

One connection holds at most |configured users| + 2 counters, and every key is a copy of a name from the configuration file, so a peer cannot grow this by inventing user-ids however many it invents.

Trait Implementations§

Source§

impl Default for AuthFailures

Source§

fn default() -> AuthFailures

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more