diff --git a/backend/Cargo.lock b/backend/Cargo.lock
index 411f592..58bf0d5 100644
--- a/backend/Cargo.lock
+++ b/backend/Cargo.lock
@@ -280,12 +280,6 @@ dependencies = [
"libc",
]
-[[package]]
-name = "crossbeam-utils"
-version = "0.8.21"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "d0a5c400df2834b80a4c3327b3aad3a4c4cd4de0629063962b03235697506a28"
-
[[package]]
name = "crypto-common"
version = "0.1.7"
@@ -331,19 +325,6 @@ dependencies = [
"syn 1.0.109",
]
-[[package]]
-name = "dashmap"
-version = "5.5.3"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "978747c1d849a7d2ee5e8adc0159961c48fb7e5db2f06af6723b80123bb53856"
-dependencies = [
- "cfg-if",
- "hashbrown 0.14.5",
- "lock_api",
- "once_cell",
- "parking_lot_core",
-]
-
[[package]]
name = "data-encoding"
version = "2.10.0"
@@ -438,15 +419,6 @@ version = "1.0.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f"
-[[package]]
-name = "erased-serde"
-version = "0.3.31"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "6c138974f9d5e7fe373eb04df7cae98833802ae4b11c24ac7039a21d5af4b26c"
-dependencies = [
- "serde",
-]
-
[[package]]
name = "errno"
version = "0.3.14"
@@ -505,16 +477,6 @@ dependencies = [
"percent-encoding",
]
-[[package]]
-name = "forwarded-header-value"
-version = "0.1.1"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "8835f84f38484cc86f110a805655697908257fb9a7af005234060891557198e9"
-dependencies = [
- "nonempty",
- "thiserror 1.0.69",
-]
-
[[package]]
name = "funty"
version = "2.0.0"
@@ -592,12 +554,6 @@ version = "0.3.32"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "037711b3d59c33004d3856fbdc83b99d4ff37a24768fa1be9ce3538a1cde4393"
-[[package]]
-name = "futures-timer"
-version = "3.0.3"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "f288b0a4f20f9a56b5d1da57e2227c661b7b16168e2f72365f57b63326e29b24"
-
[[package]]
name = "futures-util"
version = "0.3.32"
@@ -665,26 +621,6 @@ dependencies = [
"wasip3",
]
-[[package]]
-name = "governor"
-version = "0.6.3"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "68a7f542ee6b35af73b06abc0dad1c1bae89964e4e253bc4b587b91c9637867b"
-dependencies = [
- "cfg-if",
- "dashmap",
- "futures",
- "futures-timer",
- "no-std-compat",
- "nonzero_ext",
- "parking_lot",
- "portable-atomic",
- "quanta",
- "rand 0.8.5",
- "smallvec",
- "spinning_top",
-]
-
[[package]]
name = "h2"
version = "0.4.13"
@@ -704,12 +640,6 @@ dependencies = [
"tracing",
]
-[[package]]
-name = "hashbrown"
-version = "0.14.5"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "e5274423e17b7c9fc20b6e7e208532f9b19825d82dfd615708b70edd83df41f1"
-
[[package]]
name = "hashbrown"
version = "0.15.5"
@@ -1291,24 +1221,6 @@ dependencies = [
"tempfile",
]
-[[package]]
-name = "no-std-compat"
-version = "0.4.1"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "b93853da6d84c2e3c7d730d6473e8817692dd89be387eb01b94d7f108ecb5b8c"
-
-[[package]]
-name = "nonempty"
-version = "0.7.0"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "e9e591e719385e6ebaeb5ce5d3887f7d5676fceca6411d1925ccc95745f3d6f7"
-
-[[package]]
-name = "nonzero_ext"
-version = "0.3.0"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "38bf9645c8b145698bb0b18a4637dcacbc421ea49bef2317e4fd8065a387cf21"
-
[[package]]
name = "normogen-backend"
version = "0.1.0"
@@ -1328,14 +1240,11 @@ dependencies = [
"serde",
"serde_json",
"sha2",
- "slog",
"strum",
"strum_macros",
- "thiserror 1.0.69",
"tokio",
"tower 0.4.13",
"tower-http 0.5.2",
- "tower_governor",
"tracing",
"tracing-subscriber",
"uuid",
@@ -1544,12 +1453,6 @@ version = "0.3.32"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7edddbd0b52d732b21ad9a5fab5c704c14cd949e5e9a1ec5929a24fded1b904c"
-[[package]]
-name = "portable-atomic"
-version = "1.13.1"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "c33a9471896f1c69cecef8d20cbe2f7accd12527ce60845ff44c153bb2a21b49"
-
[[package]]
name = "potential_utf"
version = "0.1.4"
@@ -1617,21 +1520,6 @@ dependencies = [
"unicode-ident",
]
-[[package]]
-name = "quanta"
-version = "0.12.6"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "f3ab5a9d756f0d97bdc89019bd2e4ea098cf9cde50ee7564dde6b81ccc8f06c7"
-dependencies = [
- "crossbeam-utils",
- "libc",
- "once_cell",
- "raw-cpuid",
- "wasi",
- "web-sys",
- "winapi",
-]
-
[[package]]
name = "quote"
version = "1.0.45"
@@ -1718,15 +1606,6 @@ dependencies = [
"getrandom 0.3.4",
]
-[[package]]
-name = "raw-cpuid"
-version = "11.6.0"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "498cd0dc59d73224351ee52a95fee0f1a617a2eae0e7d9d720cc622c73a54186"
-dependencies = [
- "bitflags 2.11.0",
-]
-
[[package]]
name = "redox_syscall"
version = "0.5.18"
@@ -2175,18 +2054,6 @@ version = "0.4.12"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0c790de23124f9ab44544d7ac05d60440adc586479ce501c1d6d7da3cd8c9cf5"
-[[package]]
-name = "slog"
-version = "2.8.2"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "9b3b8565691b22d2bdfc066426ed48f837fc0c5f2c8cad8d9718f7f99d6995c1"
-dependencies = [
- "anyhow",
- "erased-serde",
- "rustversion",
- "serde_core",
-]
-
[[package]]
name = "smallvec"
version = "1.15.1"
@@ -2223,15 +2090,6 @@ dependencies = [
"windows-sys 0.61.2",
]
-[[package]]
-name = "spinning_top"
-version = "0.3.0"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "d96d2d1d716fb500937168cc09353ffdc7a012be8475ac7308e1bdf0e3923300"
-dependencies = [
- "lock_api",
-]
-
[[package]]
name = "stable_deref_trait"
version = "1.2.1"
@@ -2626,22 +2484,6 @@ version = "0.3.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8df9b6e13f2d32c91b9bd719c00d1958837bc7dec474d94952798cc8e69eeec3"
-[[package]]
-name = "tower_governor"
-version = "0.4.3"
-source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "aea939ea6cfa7c4880f3e7422616624f97a567c16df67b53b11f0d03917a8e46"
-dependencies = [
- "axum",
- "forwarded-header-value",
- "governor",
- "http",
- "pin-project",
- "thiserror 1.0.69",
- "tower 0.5.3",
- "tracing",
-]
-
[[package]]
name = "tracing"
version = "0.1.44"
diff --git a/backend/Cargo.toml b/backend/Cargo.toml
index f77cddc..62a529e 100644
--- a/backend/Cargo.toml
+++ b/backend/Cargo.toml
@@ -8,7 +8,6 @@ axum = "0.7.9"
tokio = { version = "1.41.1", features = ["full"] }
tower = { version = "0.4.13", features = ["util"] }
tower-http = { version = "0.5.2", features = ["cors", "trace"] }
-tower_governor = "0.4.3"
serde = { version = "1.0.215", features = ["derive"] }
serde_json = "1.0.133"
mongodb = "2.8.2"
@@ -23,11 +22,9 @@ password-hash = "0.5.0"
rand = "0.8.5"
base64 = "0.22.1"
sha2 = "0.10"
-thiserror = "1.0.69"
anyhow = "1.0.94"
tracing = "0.1.41"
tracing-subscriber = { version = "0.3.19", features = ["env-filter"] }
-slog = "2.7.0"
strum = { version = "0.26", features = ["derive"] }
strum_macros = "0.26"
futures = "0.3"
diff --git a/backend/src/auth/jwt.rs b/backend/src/auth/jwt.rs
index 6ec6e37..7bd05cc 100644
--- a/backend/src/auth/jwt.rs
+++ b/backend/src/auth/jwt.rs
@@ -1,4 +1,3 @@
-#![allow(dead_code)]
use anyhow::Result;
use chrono::{Duration, Utc};
use jsonwebtoken::{decode, encode, DecodingKey, EncodingKey, Header, Validation};
@@ -41,12 +40,17 @@ pub struct RefreshClaims {
pub sub: String,
pub exp: usize,
pub iat: usize,
+ /// Unique per-token id. Without this, two refresh tokens for the same user
+ /// issued in the same second (e.g. on rotation) would be byte-identical,
+ /// breaking rotation/reuse-detection. The jti makes every token unique.
+ pub jti: String,
pub user_id: String,
pub token_version: i32,
}
impl RefreshClaims {
/// Build refresh-token claims. `expiry` is taken from `JwtConfig` by callers.
+ /// A fresh random `jti` is generated so each token is unique.
pub fn new(user_id: String, token_version: i32, expiry: Duration) -> Self {
let now = Utc::now();
let exp = now + expiry;
@@ -55,6 +59,7 @@ impl RefreshClaims {
sub: user_id.clone(),
exp: exp.timestamp() as usize,
iat: now.timestamp() as usize,
+ jti: uuid::Uuid::new_v4().to_string(),
user_id,
token_version,
}
@@ -175,4 +180,30 @@ mod tests {
let refresh_claims = svc.validate_refresh_token(&refresh).unwrap();
assert_eq!(refresh_claims.token_version, 3);
}
+
+ /// Two refresh tokens issued back-to-back for the same user must be distinct,
+ /// even though everything else (sub, user_id, token_version, iat, exp) is
+ /// identical. The jti claim guarantees this — without it, rotation would
+ /// mint a byte-identical token and break reuse detection.
+ #[test]
+ fn refresh_tokens_are_unique_even_in_same_second() {
+ let svc = JwtService::new(test_config());
+ let claims = Claims::new(
+ "user-3".to_string(),
+ "u3@example.com".to_string(),
+ 0,
+ Duration::minutes(15),
+ );
+ let (_, refresh_a) = svc.generate_tokens(claims.clone()).unwrap();
+ let (_, refresh_b) = svc.generate_tokens(claims).unwrap();
+ assert_ne!(
+ refresh_a, refresh_b,
+ "consecutive refresh tokens must differ (jti)"
+ );
+
+ // And the jti values themselves differ.
+ let jti_a = svc.validate_refresh_token(&refresh_a).unwrap().jti;
+ let jti_b = svc.validate_refresh_token(&refresh_b).unwrap().jti;
+ assert_ne!(jti_a, jti_b);
+ }
}
diff --git a/backend/src/auth/mod.rs b/backend/src/auth/mod.rs
index 8a1993f..956b164 100644
--- a/backend/src/auth/mod.rs
+++ b/backend/src/auth/mod.rs
@@ -1,4 +1,3 @@
-#![allow(dead_code)]
pub mod jwt;
pub mod password;
pub mod token_version_cache;
diff --git a/backend/src/config/mod.rs b/backend/src/config/mod.rs
index 30fdc63..edb6869 100644
--- a/backend/src/config/mod.rs
+++ b/backend/src/config/mod.rs
@@ -1,5 +1,3 @@
-#![allow(dead_code)]
-#![allow(unused_imports)]
use anyhow::Result;
use std::sync::Arc;
diff --git a/backend/src/db/appointment.rs b/backend/src/db/appointment.rs
deleted file mode 100644
index 77cf576..0000000
--- a/backend/src/db/appointment.rs
+++ /dev/null
@@ -1 +0,0 @@
-// Stub for future appointment operations
diff --git a/backend/src/db/family.rs b/backend/src/db/family.rs
deleted file mode 100644
index 9d0d242..0000000
--- a/backend/src/db/family.rs
+++ /dev/null
@@ -1 +0,0 @@
-// Stub for future family operations
diff --git a/backend/src/db/health_data.rs b/backend/src/db/health_data.rs
deleted file mode 100644
index 088ad7c..0000000
--- a/backend/src/db/health_data.rs
+++ /dev/null
@@ -1 +0,0 @@
-// Stub for future health_data operations
diff --git a/backend/src/db/init.rs b/backend/src/db/init.rs
index 0e0ffc1..8193095 100644
--- a/backend/src/db/init.rs
+++ b/backend/src/db/init.rs
@@ -1,4 +1,3 @@
-#![allow(dead_code)]
use mongodb::{bson::doc, options::IndexOptions, Collection, IndexModel};
use anyhow::Result;
diff --git a/backend/src/db/lab_result.rs b/backend/src/db/lab_result.rs
deleted file mode 100644
index 4ffed49..0000000
--- a/backend/src/db/lab_result.rs
+++ /dev/null
@@ -1 +0,0 @@
-// Stub for future lab_result operations
diff --git a/backend/src/db/medication.rs b/backend/src/db/medication.rs
deleted file mode 100644
index 3bdbf68..0000000
--- a/backend/src/db/medication.rs
+++ /dev/null
@@ -1 +0,0 @@
-// Stub for future medication operations
diff --git a/backend/src/db/mod.rs b/backend/src/db/mod.rs
index bb4df1a..7b3c125 100644
--- a/backend/src/db/mod.rs
+++ b/backend/src/db/mod.rs
@@ -1,19 +1,7 @@
-#![allow(dead_code)]
-#![allow(clippy::useless_conversion)]
use anyhow::Result;
use mongodb::{Client, Database};
use std::env;
-pub mod appointment;
-pub mod family;
-pub mod health_data;
-pub mod lab_result;
-pub mod medication;
-pub mod permission;
-pub mod profile;
-pub mod share;
-pub mod user;
-
pub mod init; // Database initialization module
mod mongodb_impl;
diff --git a/backend/src/db/mongodb_impl.rs b/backend/src/db/mongodb_impl.rs
index 4107fc5..861b34e 100644
--- a/backend/src/db/mongodb_impl.rs
+++ b/backend/src/db/mongodb_impl.rs
@@ -1,4 +1,3 @@
-#![allow(clippy::needless_question_mark)]
use anyhow::Result;
use mongodb::bson::oid::ObjectId;
use mongodb::{bson::doc, options::ClientOptions, Client, Collection, Database};
@@ -286,10 +285,9 @@ impl MongoDb {
pub async fn get_medication(&self, id: &str) -> Result