fune!(auth.validate-registration@^1); // then call validate_registration(…)
Suites · auth
User accounts and authentication
Sign-up and login forms, password policy and hashing, login lockout, and signed access tokens (JWT) read from the Authorization header.
34 capabilities (12 core, 22 optional) and 12 gaps, in build order. Put each line in the file that calls it, then fune build.
1. Sign-up and login forms
Check what people type into the account forms, the same way in the browser and the API.
fune!(auth.validate-login@^1); // then call validate_login(…)
fune!(auth.normalise-email@^1); // then call normalise_email(…)
fune!(auth.validate-password-change@^1); // then call validate_password_change(…)
2. Passwords
Decide what passwords are acceptable and store them safely.
fune!(auth.password-policy@^1); // then call password_policy, check_password
fune!(auth.password-hash@^1); // then call hash_password, verify_password, password_needs_rehash
fune!(crypto.pbkdf2-sha256@^1); // then call pbkdf2_sha256(…)
fune!(crypto.constant-time-equal@^1); // then call constant_time_equal(…)
- breached-passwords Checking passwords against a breach corpus (Have I Been Pwned's range API) is network work; the policy's common-password list is built in.
3. Login protection
Slow down password guessing.
fune!(auth.login-throttle@^1); // then call login_throttle(…)
fune!(http.retry-after@^1); // then call retry_after_seconds(…)
- ip-rate-limiting Rate limiting by IP address across accounts, with its shared counter store (Redis, a database).
4. Tokens
Issue and check signed tokens for an API or a single-page app.
fune!(auth.access-token@^1); // then call issue_access_token, read_access_token, confirm_access_token
fune!(auth.bearer-token@^1); // then call parse_bearer_token(…)
fune!(auth.jwt@^1); // then call sign_jwt, verify_jwt, decode_jwt
fune!(crypto.hmac-sha256@^1); // then call hmac_sha256(…)
fune!(crypto.sha256@^1); // then call sha256(…)
fune!(encoding.base64@^1); // then call base64_encode, base64_decode, base64_url_encode, base64_url_decode
fune!(time.countdown@^1); // then call countdown(…)
- sessions Server-side sessions and cookies: storing them, Secure/HttpOnly/SameSite flags, CSRF tokens and expiry are yours.
- asymmetric-jwt RS256/ES256 tokens and JWKS key sets (for third-party identity providers): auth.jwt is HS256 only.
5. Forms in React
Accessible account pages in a React front end (TypeScript only).
6. Contact details from validation-basics
Check and normalise a person's contact details before storing them.
fune!(validation.email@^1); // then call is_email(…)
fune!(validation.phone-e164@^2); // then call validate_phone_e164(…)
fune!(validation.uk-postcode@^2); // then call validate_uk_postcode(…)
fune!(text.normalise-name@^1); // then call normalise_name(…)
7. Bank details from validation-basics
Check payee and customer bank details before money moves.
fune!(validation.iban@^1); // then call is_iban(…)
fune!(validation.bic@^1); // then call validate_bic(…)
fune!(validation.uk-sort-code-account@^3); // then call validate_uk_sort_code_account(…)
fune!(validation.uk-modulus-table@^1); // then call parse_uk_modulus_table(…)
8. Identifiers and check digits from validation-basics
Catch mistyped reference numbers by their check digits.
fune!(validation.luhn@^1); // then call is_luhn(…)
fune!(validation.uk-company-number@^2); // then call validate_uk_company_number(…)
fune!(validation.lei@^1); // then call validate_lei(…)
fune!(validation.gtin@^1); // then call validate_gtin(…)
9. Displaying sensitive values from validation-basics
Show stored identifiers without exposing them.
fune!(text.mask@^1); // then call mask(…)
Gaps
What this kind of app usually needs that Functional Weave does not have yet: write these yourself, or use a service.
- email-verification Sending verification and password-reset emails, and storing their one-time tokens with expiry.
- oauth-social-login OAuth 2.0 / OpenID Connect sign-in with Google, Microsoft, GitHub and the like.
- mfa Second factors: TOTP authenticator codes, SMS codes, passkeys/WebAuthn and recovery codes.
- roles-permissions Roles, permissions and organisation membership: who may do what is yours to model.
- user-storage The users table, unique email index, migrations and account deletion.
- address-lookup Turning a postcode into a list of addresses (Royal Mail PAF or a lookup API) is network work and not in caps.
- email-deliverability Whether a mailbox exists (MX lookups, a confirmation email): validation.email checks the syntax only.
- vocalink-data The Vocalink modulus tables themselves: download them from Pay.UK under its terms; caps parses them but does not ship them.