Files
mytheclipse/crates/corex-crypto/README.md
T
asepharyana d119821339 feat: add panic tracking and logging with PanicTracker
- Implemented PanicTracker to log panics using tracing within a dedicated span.
- Introduced PanicInfo struct to capture panic details.
- Added tests for panic catching and hook restoration.

feat: implement token-bucket rate limiter

- Created RateLimiter to manage token consumption with configurable rates and burst capacity.
- Added methods for acquiring tokens and checking available tokens.
- Included tests for rate limiting behavior and token availability.

feat: add automatic retry with exponential backoff

- Developed retry function to handle transient errors with configurable retry strategies.
- Introduced RetryConfig for customizing retry behavior and jitter.
- Added tests for various retry scenarios and error handling.

feat: implement graceful shutdown coordination

- Created ShutdownManager to manage shutdown signals and task completion.
- Introduced ShutdownSignal for tasks to observe shutdown requests.
- Added tests for shutdown request handling and task draining.

feat: add timeout functionality for async operations

- Implemented with_timeout function to enforce execution time limits on futures.
- Created Timeout struct for wrapping futures with a deadline.
- Added tests for timeout behavior and error mapping.
2026-08-28 21:46:18 +07:00

1.2 KiB

corex-crypto

Safe, one-line security helpers that are easy to get wrong when hand-rolled:

  • Argon2id password hashing & verification (PHC-encoded, RFC 9106-style).
  • AES-256-GCM authenticated encryption with a fresh random nonce per op.
  • JWT (HS256) token generation & validation.
  • Key rotation via KeyRing — reads keep working with the previous key during a rotation window.

Features

  • password (default) — Argon2id hashing.
  • encryption (default) — AES-256-GCM.
  • tokens (default) — JSON Web Tokens.

Zero features enabled by default? No — all three are on, but each is cheap and independent.

Usage

use corex_crypto::{PasswordHasher, Encryptor, TokenSigner};

let hasher = PasswordHasher::new();
let hash = hasher.hash("letmein").unwrap();
assert!(hasher.verify(&hash, "letmein"));

let enc = Encryptor::new(&[0u8; 32]);
let (nonce, ct) = enc.encrypt(b"secret");
assert_eq!(enc.decrypt(&nonce, &ct).unwrap(), b"secret");

let signer = TokenSigner::new("my-secret");
let token = signer.sign(&serde_json::json!({"sub":"u1"}), std::time::Duration::from_secs(3600)).unwrap();
assert_eq!(signer.verify(&token).unwrap()["sub"], "u1");