Introduction & Architecture
Securing enterprise applications often leads to messy, scattered middleware across various routers. Rays Web Security centralizes this logic into declarative Security Filter Chains.
Core Architectural Features
- Declarative Authorization: Define endpoint security rules using a highly expressive
HttpSecurityBuilderrather than imperativeif/elseblocks inside your handlers. - Pluggable Authentication: Easily swap out how users are authenticated by implementing the
AuthenticationProviderorUserDetailsServiceinterfaces. - ThreadLocal Context: Web Security utilizes
github.com/timandy/routineto store the currently authenticated user in a ThreadLocalSecurityContext. Your deeper service layers can retrieve the user without needing the HTTP request object passed down. - IoC Native Auto-Configuration: The framework provides default security implementations out of the box, which you can easily override by defining your own Beams.
๐ฆ Package Structure & Imports
To prevent circular dependencies and maintain clean boundaries, Rays Web Security is split into distinct packages:
github.com/BeamFoundry/rays-web-security: The root package. You underscore-import this inmain.goto trigger the internal auto-configurations..../pkg/core: Contains all interfaces (UserDetails,PasswordEncoder,SecurityContextHolder, etc.)..../pkg/config: Contains theHttpSecurityBuildertypes..../pkg/auth: Contains concreteAuthenticationProviderimplementations..../pkg/password: Contains concretePasswordEncoderimplementations..../pkg/rememberme: ContainsRememberMeServiceimplementations..../pkg/testing: Contains in-memory mock implementations for Ginkgo test suites.
๐งน Simplifying with Dot Imports
To keep your domain code clean, it is highly recommended to use Go’s dot import feature for the core and config packages:
import (
. "github.com/BeamFoundry/rays-web-security/pkg/core"
. "github.com/BeamFoundry/rays-web-security/pkg/config"
)