Security in Rust applications
# How the recurring security concerns map onto Rust's crates — identity, the web attack surface, and cryptography.
❯ cat documents/
-
Security in Rust applications — the map
Concept
2026-08-09
How the recurring security concerns map onto Rust's crates — composed as tower middleware and typed APIs, with memory safety covering some fronts and none of the others.
-
Cryptography in Rust — rustls, ring & RustCrypto
Concept
2026-08-09
The crate-first crypto landscape — rustls for TLS with its pluggable providers, ring versus the RustCrypto families, the dalek curves, age for file encryption, and zeroize/secrecy hygiene.
-
OAuth2 & OIDC in Rust
Concept
2026-08-09
The oauth2 crate's typed flows, openidconnect for discovery and ID-token validation, jsonwebtoken for resource servers, session auth with axum-login, and the missing authorization-server story.
-
Web security in Rust apps
Concept
2026-08-09
The OWASP concerns in Rust idiom — what memory safety does and doesn't buy, injection and XSS by construction, CSRF/CORS/headers via tower-http, sessions, panics as DoS, and serde-boundary hardening.