Closes the regression risk of the admin API and dashboard being open
to anyone reaching the bound port. Required foundation before v1.1
data-plane services land.
Per-user accounts (admin_users), Argon2id passwords, env-var bootstrap
of the first admin that becomes inert once any admin exists, opaque
32-byte session token doubling as bearer credential, 24h sliding TTL
configurable via PICLOUD_SESSION_TTL_HOURS. is_active column lets
admins be deactivated without losing audit history; last-active-admin
guard on DELETE and on PATCH that flips is_active to false (sessions
also wiped on deactivation).
require_admin middleware fronts every /api/v1/admin/* route. The data
plane (/api/v1/execute/{id}), /healthz, /version, and user routes
stay open. picloud admin reset-password <username> subcommand handles
recovery without going through HTTP.
Dashboard gains /admin/login and /admin/admins surfaces, a top-bar
user menu, and a token store with a localStorage echo so refreshes
don't sign you out. Cookie-based auth works in parallel for non-SPA
clients.
Forward compatibility: future RBAC tables (admin_roles,
admin_user_roles) join on admin_users.id; the auth middleware is the
seam where role checks slot in. Email, 2FA, passkeys, and personal
API tokens are all additive without touching admin_users.
Blueprint §11.4 updated to reflect what actually shipped.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
97 lines
2.4 KiB
TOML
97 lines
2.4 KiB
TOML
[workspace]
|
|
resolver = "2"
|
|
members = [
|
|
"crates/shared",
|
|
"crates/executor-core",
|
|
"crates/orchestrator-core",
|
|
"crates/manager-core",
|
|
"crates/picloud",
|
|
"crates/picloud-manager",
|
|
"crates/picloud-orchestrator",
|
|
"crates/picloud-executor",
|
|
]
|
|
|
|
[workspace.package]
|
|
version = "0.5.1"
|
|
edition = "2021"
|
|
rust-version = "1.92"
|
|
license = "MIT OR Apache-2.0"
|
|
authors = ["PiCloud contributors"]
|
|
repository = "https://github.com/fhamm/picloud"
|
|
|
|
[workspace.dependencies]
|
|
# Internal crates
|
|
picloud-shared = { path = "crates/shared" }
|
|
picloud-executor-core = { path = "crates/executor-core" }
|
|
picloud-orchestrator-core = { path = "crates/orchestrator-core" }
|
|
picloud-manager-core = { path = "crates/manager-core" }
|
|
|
|
# Async + HTTP
|
|
tokio = { version = "1.40", features = ["full"] }
|
|
axum = "0.8"
|
|
tower = "0.5"
|
|
tower-http = { version = "0.6", features = ["trace", "cors"] }
|
|
hyper = "1"
|
|
|
|
# Serialization
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
|
|
# Errors + logging
|
|
thiserror = "1"
|
|
anyhow = "1"
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
|
|
# IDs + time
|
|
uuid = { version = "1", features = ["v4", "serde"] }
|
|
chrono = { version = "0.4", features = ["serde"] }
|
|
|
|
# Async traits
|
|
async-trait = "0.1"
|
|
|
|
# Rhai scripting
|
|
rhai = { version = "1.19", features = ["sync", "serde"] }
|
|
|
|
# Postgres (manager-core only — others stay DB-free)
|
|
sqlx = { version = "0.8", features = ["runtime-tokio-rustls", "postgres", "uuid", "chrono", "json", "macros", "migrate"] }
|
|
|
|
# Config
|
|
figment = { version = "0.10", features = ["toml", "env"] }
|
|
|
|
# HTTP client (for RemoteExecutorClient later)
|
|
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"] }
|
|
|
|
# URL parsing (for match-preview admin endpoint)
|
|
url = "2"
|
|
urlencoding = "2"
|
|
|
|
# Auth (admin users + sessions)
|
|
argon2 = "0.5"
|
|
rand = { version = "0.8", features = ["getrandom"] }
|
|
sha2 = "0.10"
|
|
base64 = "0.22"
|
|
|
|
[workspace.lints.rust]
|
|
unsafe_code = "forbid"
|
|
|
|
[workspace.lints.clippy]
|
|
all = { level = "warn", priority = -1 }
|
|
pedantic = { level = "warn", priority = -1 }
|
|
module_name_repetitions = "allow"
|
|
missing_errors_doc = "allow"
|
|
missing_panics_doc = "allow"
|
|
doc_markdown = "allow"
|
|
# API ergonomics: we deliberately take values by ownership for owned
|
|
# inputs (e.g. ExecRequest) and accept Rhai's Box<EvalAltResult> as-is.
|
|
needless_pass_by_value = "allow"
|
|
boxed_local = "allow"
|
|
|
|
[profile.release]
|
|
lto = "thin"
|
|
codegen-units = 1
|
|
strip = "symbols"
|
|
|
|
[profile.dev]
|
|
debug = 1
|