<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>4. Security Chains on BeamFoundry Rays Web Security</title><link>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/</link><description>Recent content in 4. Security Chains on BeamFoundry Rays Web Security</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/index.xml" rel="self" type="application/rss+xml"/><item><title>Basic Authentication</title><link>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/1-basic-auth/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/1-basic-auth/</guid><description>&lt;h1 id="basic-authentication"&gt;Basic Authentication&lt;a class="anchor" href="#basic-authentication"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;For APIs and simple services without a frontend interface, you will typically use &lt;strong&gt;Basic Authentication&lt;/strong&gt; (passing credentials via the HTTP &lt;code&gt;Authorization&lt;/code&gt; header).&lt;/p&gt;&#10;&lt;p&gt;You can enable this by calling the &lt;code&gt;Basic()&lt;/code&gt; method on the &lt;code&gt;HttpSecurityBuilder&lt;/code&gt; before building the final security configuration.&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-go" data-lang="go"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;package&lt;/span&gt; &lt;span style="color:#a6e22e"&gt;configurations&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#f92672"&gt;import&lt;/span&gt; (&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; . &lt;span style="color:#e6db74"&gt;&amp;#34;github.com/BeamFoundry/rays-web-security/pkg/config&amp;#34;&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; . &lt;span style="color:#e6db74"&gt;&amp;#34;github.com/BeamFoundry/rays/pkg/core&amp;#34;&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;)&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;type&lt;/span&gt; &lt;span style="color:#a6e22e"&gt;BasicSecurityConfig&lt;/span&gt; &lt;span style="color:#66d9ef"&gt;struct&lt;/span&gt; {&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;Configuration&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;}&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;// The HttpSecurity Beam provider. &lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;func&lt;/span&gt; (&lt;span style="color:#a6e22e"&gt;this&lt;/span&gt; &lt;span style="color:#f92672"&gt;*&lt;/span&gt;&lt;span style="color:#a6e22e"&gt;BasicSecurityConfig&lt;/span&gt;) &lt;span style="color:#a6e22e"&gt;HttpSecurity&lt;/span&gt;() &lt;span style="color:#f92672"&gt;*&lt;/span&gt;&lt;span style="color:#a6e22e"&gt;HttpSecurity&lt;/span&gt; {&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#66d9ef"&gt;return&lt;/span&gt; (&lt;span style="color:#f92672"&gt;&amp;amp;&lt;/span&gt;&lt;span style="color:#a6e22e"&gt;HttpSecurityBuilder&lt;/span&gt;{}).&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;AuthorizedHTTPRequests&lt;/span&gt;().&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;Paths&lt;/span&gt;(&lt;span style="color:#e6db74"&gt;&amp;#34;/api/public/**&amp;#34;&lt;/span&gt;).&lt;span style="color:#a6e22e"&gt;PermitAll&lt;/span&gt;().&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;AnyRequest&lt;/span&gt;().&lt;span style="color:#a6e22e"&gt;Authenticated&lt;/span&gt;().&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;And&lt;/span&gt;().&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;Basic&lt;/span&gt;(). &lt;span style="color:#75715e"&gt;// Secure all authenticated endpoints via BasicAuth&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt; &lt;span style="color:#a6e22e"&gt;Build&lt;/span&gt;()&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;}&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;var&lt;/span&gt; &lt;span style="color:#a6e22e"&gt;_&lt;/span&gt;, &lt;span style="color:#a6e22e"&gt;_&lt;/span&gt; = &lt;span style="color:#66d9ef"&gt;any&lt;/span&gt;(&lt;span style="color:#f92672"&gt;&amp;amp;&lt;/span&gt;&lt;span style="color:#a6e22e"&gt;BasicSecurityConfig&lt;/span&gt;{}).(&lt;span style="color:#a6e22e"&gt;Stereotype&lt;/span&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>Form Login</title><link>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/2-form-login/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/2-form-login/</guid><description>&lt;h1 id="form-login--remember-me"&gt;Form Login &amp;amp; Remember Me&lt;a class="anchor" href="#form-login--remember-me"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;If you are building a traditional web application with server-rendered HTML views (instead of a stateless API), you will likely want to use &lt;strong&gt;Form Login&lt;/strong&gt; instead of Basic Authentication.&lt;/p&gt;&#10;&lt;p&gt;The &lt;code&gt;FormLogin()&lt;/code&gt; builder exposes several methods to fully customize the authentication flow.&lt;/p&gt;&#10;&lt;h3 id="configuration-defaults"&gt;Configuration Defaults&lt;a class="anchor" href="#configuration-defaults"&gt;&lt;/a&gt;&lt;/h3&gt;&#10;&lt;p&gt;If you call &lt;code&gt;.FormLogin()&lt;/code&gt; without any additional chained configuration, the framework applies the following defaults automatically:&lt;/p&gt;&#10;&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th style="text-align: left"&gt;Method&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th style="text-align: left"&gt;Default Value&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th style="text-align: left"&gt;Description&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&lt;code&gt;Username()&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&amp;ldquo;username&amp;rdquo;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;The HTML form field name for the user&amp;rsquo;s username.&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&lt;code&gt;Password()&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&amp;ldquo;password&amp;rdquo;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;The HTML form field name for the user&amp;rsquo;s password.&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&lt;code&gt;LoginPath()&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&amp;ldquo;/login&amp;rdquo;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;The path where the login hook is registered.&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&lt;code&gt;LogoutPath()&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&amp;ldquo;/logout&amp;rdquo;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;The path where the logout hook is registered.&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&lt;code&gt;ViewName()&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&amp;ldquo;login&amp;rdquo;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;The template view name rendered for the login form.&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&lt;code&gt;DefaultSuccessURL()&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;&amp;ldquo;/&amp;rdquo;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td style="text-align: left"&gt;The default URL to redirect to upon successful login.&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;p&gt;You can selectively override any of these defaults, serve a specific login view, and optionally integrate a &lt;code&gt;RememberMeService&lt;/code&gt;:&lt;/p&gt;</description></item><item><title>Stateless APIs</title><link>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/3-stateless/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/3-stateless/</guid><description>&lt;h1 id="stateless-vs-stateful-sessions"&gt;Stateless vs. Stateful Sessions&lt;a class="anchor" href="#stateless-vs-stateful-sessions"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;By default, Rays Web Security assumes you are building a stateful web application (using session cookies). If you are building a modern API (e.g., React, Vue, Mobile App) that uses stateless tokens, you must tell the framework to operate in a stateless manner.&lt;/p&gt;&#10;&lt;p&gt;You can do this by using the &lt;code&gt;Csrf().Disable()&lt;/code&gt; and &lt;code&gt;SessionCreationPolicy()&lt;/code&gt; builder methods.&lt;/p&gt;&#10;&lt;h2 id="session-creation-policies"&gt;Session Creation Policies&lt;a class="anchor" href="#session-creation-policies"&gt;&lt;/a&gt;&lt;/h2&gt;&#10;&lt;p&gt;The &lt;code&gt;SessionCreationPolicy()&lt;/code&gt; builder provides several options to control when the framework provisions a session:&lt;/p&gt;</description></item><item><title>Custom Filters</title><link>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/4-custom-filters/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://rays.bfdy.dev/rays-web-security/docs/4-security-chains/4-custom-filters/</guid><description>&lt;h1 id="custom-filters"&gt;Custom Filters&lt;a class="anchor" href="#custom-filters"&gt;&lt;/a&gt;&lt;/h1&gt;&#10;&lt;p&gt;While Rays Web Security provides robust out-of-the-box mechanisms like Form Login and Basic Authentication, you may occasionally need to implement proprietary authentication flows (e.g., verifying a specific API key header, an internal SSO token, or an OAuth JWT).&lt;/p&gt;&#10;&lt;p&gt;You can inject your own security logic directly into the request lifecycle using the &lt;code&gt;AddCustomFilter()&lt;/code&gt; method on the builder.&lt;/p&gt;&#10;&lt;blockquote class='book-hint '&gt;&#10;&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt; Custom filters are always evaluated &lt;strong&gt;before&lt;/strong&gt; global filters (like BasicAuth or FormLogin).&lt;/p&gt;</description></item></channel></rss>