# Auth

Magic-link auth has protected paths since version 0.9.0. `[[auth.rules]]` is access control. It is not a [redirect](/features/redirects/) and it is not a form success redirect. A redirect is answered before auth, so an anonymous visitor follows the redirect and any login happens on the destination.

```toml
[auth]
db = "/data/benson_data.db"
token_ttl_minutes = 15
session_ttl_days = 30
default_role = "member"

[auth.email]
from = "noreply@example.com"
host = "mail.example.com"
port = 2525
username = "noreply@example.com"

[[auth.rules]]
path = "/private/**"
roles = ["member"]

[auth.role_redirects]
member = "/private/"
```

The SMTP password is `BENSON_SMTP_PASSWORD`. It is read when mail is sent. It is not a `config.toml` field.

Users live in `users.toml` with an email, a role, and an optional name. `[user.session_data]` is exposed to templates as `profile`. `[auth.role_redirects]` sends a user to a path after login, by role. `open_registration` allows a visitor to create an account. `default_role` is the role that account receives.

`benson serve --development --no-auth` skips the auth subsystem. That flag is only valid with `--development`.

