|
| 1 | +--- |
| 2 | +title: Building an Authentication RESTful API |
| 3 | +slug: building-an-authentication-restful-api |
| 4 | +--- |
| 5 | + |
| 6 | +> [!Assignment] In this series, |
| 7 | +> We build a production-ready authentication RESTful API server application using Axum, Tokio, Tower, Serde, Toasty ORM, Argon2, Garde, Utoipa with Docker and PostgreSQL. |
| 8 | +> - [Hyper](https://github.com/hyperium/hyper), [Axum](https://github.com/tokio-rs/axum), [Tokio](https://tokio.rs) and [Tower](https://github.com/tower-rs): The most prominent HTTP server ecosystem at the time of writing. |
| 9 | +> - [Toasty ORM](https://github.com/tokio-rs/toasty): The most promising Object-Relational Mapper (ORM), built by the creators of Tokio and Axum. |
| 10 | +> - [Serde](https://github.com/serde-rs/serde) and [Utoipa](https://github.com/juhaku/utoipa): The most prominent serialization framework and OpenAPI 3.1 specification generator. |
| 11 | +> - [Garde](https://github.com/jprochazk/garde): The most promising and most feature-rich validation library in Rust at the time of writing. |
| 12 | +
|
| 13 | +## Database Design |
| 14 | + |
| 15 | +``` |
| 16 | +users user_devices user_passwords |
| 17 | +┌─────────────┬────────────┐ ┌──────────────────┬──────────────┐ ┌───────────────┬────────────────┐ |
| 18 | +│ id │ uuid │ │ created_at │ ... │ │ created_at │ timestamp │ |
| 19 | +│ created_at │ timestamp │ │ last_used_at │ ... │ │ updated_at │ timestamp │ |
| 20 | +│ updated_at │ timestamp │ │ user_id │ uuid │ │ password_hash │ text │ |
| 21 | +│ is_verified │ boolean │ │ signature_counter│ bigint │ │ user_id │ uuid │ |
| 22 | +│ email │ text │ │ device_hash │ text │ └───────────────┴────────────────┘ |
| 23 | +└─────────────┴────────────┘ │ credential_id │ bytea │ |
| 24 | + │ public_key │ bytea │ |
| 25 | + │ id │ uuid │ |
| 26 | + └──────────────────┴──────────────┘ |
| 27 | +
|
| 28 | +user_identities webauthn_challenges oauth_challenges |
| 29 | +┌─────────────────┬──────┐ ┌─────────────────┬────────────┐ ┌────────────────────┬──────┐ |
| 30 | +│ created_at │ ... │ │ created_at │ ... │ │ created_at │ ... │ |
| 31 | +│ user_id │ uuid │ │ expires_at │ ... │ │ expires_at │ ... │ |
| 32 | +│ provider │ text │ │ user_id │ uuid │ │ pkce_code_verifier │ text │ |
| 33 | +│ provider_sub_id │ text │ │ device_id │ uuid │ │ client_redirect_uri│ text │ |
| 34 | +│ id │ uuid │ │ challenge_type │ text │ │ provider │ text │ |
| 35 | +└─────────────────┴──────┘ │ challenge_token │ bytea │ │ flow_type │ text │ |
| 36 | + └─────────────────┴────────────┘ │ state │ uuid │ |
| 37 | + └────────────────────┴──────┘ |
| 38 | +security_audit_logs refresh_tokens |
| 39 | +┌─────────────────┬──────────────┐ ┌─────────────────┬────────┐ |
| 40 | +│ created_at │ ... │ │ created_at │ ... │ |
| 41 | +│ user_id │ uuid │ │ expires_at │ ... │ |
| 42 | +│ device_id │ uuid │ │ user_id │ uuid │ |
| 43 | +│ ip_address │ text │ │ device_id │ uuid │ |
| 44 | +│ user_agent │ text │ │ token_family_id │ uuid │ |
| 45 | +│ location │ text │ │ is_revoked │ boolean│ |
| 46 | +│ event_type │ text │ │ token_hash │ bytea │ |
| 47 | +│ context │ text │ │ id │ uuid │ |
| 48 | +│ id │ uuid │ └─────────────────┴────────┘ |
| 49 | +└─────────────────┴──────────────┘ |
| 50 | +``` |
0 commit comments