style: apply rustfmt after clippy let-chain fixes

This commit is contained in:
thakares committed 2026-08-07 19:53:33 +05:30
1 parent b25a015898
commit 312c78dbbb
16 files changed
+73 -35

No files matched your search

+6 -3
View File
@@ -69,7 +69,8 @@ pub async fn login(
// Rate limit check (per IP) // Rate limit check (per IP)
if let Some(ip_str) = &ctx.ip_address if let Some(ip_str) = &ctx.ip_address
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() { && let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>()
{
state.rate_limiter.check(ip_addr)?; state.rate_limiter.check(ip_addr)?;
} }
@@ -103,7 +104,8 @@ pub async fn login(
if !is_authed { if !is_authed {
record_login_failure(&state, body.username.trim(), ip, ctx.user_agent.as_deref()).await; record_login_failure(&state, body.username.trim(), ip, ctx.user_agent.as_deref()).await;
if let Some(ip_str) = &ctx.ip_address if let Some(ip_str) = &ctx.ip_address
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() { && let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>()
{
state.rate_limiter.record_failure(ip_addr); state.rate_limiter.record_failure(ip_addr);
} }
// Non-enumerating error for both unknown user and bad password. // Non-enumerating error for both unknown user and bad password.
@@ -117,7 +119,8 @@ pub async fn login(
// Clear rate limit on success // Clear rate limit on success
if let Some(ip_str) = &ctx.ip_address if let Some(ip_str) = &ctx.ip_address
&& let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>() { && let Ok(ip_addr) = ip_str.parse::<std::net::IpAddr>()
{
state.rate_limiter.record_success(ip_addr); state.rate_limiter.record_success(ip_addr);
} }
+2 -1
View File
@@ -104,7 +104,8 @@ pub async fn terminate_session(
) -> Result<Json<Value>> { ) -> Result<Json<Value>> {
// If the user is trying to terminate the current session, disallow it // If the user is trying to terminate the current session, disallow it
if let Some(current_id) = auth.session_id.as_deref() if let Some(current_id) = auth.session_id.as_deref()
&& id == current_id { && id == current_id
{
return Err(AppError::InvalidInput( return Err(AppError::InvalidInput(
"Cannot terminate current session".into(), "Cannot terminate current session".into(),
)); ));
+4 -2
View File
@@ -54,7 +54,8 @@ pub async fn create_tenant(
require(&state.provider, &auth.user.id, "roles:manage").await?; require(&state.provider, &auth.user.id, "roles:manage").await?;
if let Some(ref s) = body.slug if let Some(ref s) = body.slug
&& !s.trim().is_empty() { && !s.trim().is_empty()
{
crate::identity::slug::validate_slug(s)?; crate::identity::slug::validate_slug(s)?;
} }
@@ -124,7 +125,8 @@ pub async fn update_tenant(
require(&state.provider, &auth.user.id, "roles:manage").await?; require(&state.provider, &auth.user.id, "roles:manage").await?;
if let Some(ref s) = body.slug if let Some(ref s) = body.slug
&& !s.trim().is_empty() { && !s.trim().is_empty()
{
crate::identity::slug::validate_slug(s)?; crate::identity::slug::validate_slug(s)?;
} }
+2 -1
View File
@@ -27,7 +27,8 @@ pub fn ui_dist_dir() -> PathBuf {
} }
} }
if let Ok(exe) = std::env::current_exe() if let Ok(exe) = std::env::current_exe()
&& let Some(dir) = exe.parent() { && let Some(dir) = exe.parent()
{
for rel in ["ui/dist", "../ui/dist", "../../ui/dist"] { for rel in ["ui/dist", "../ui/dist", "../../ui/dist"] {
let candidate = dir.join(rel); let candidate = dir.join(rel);
if candidate.exists() { if candidate.exists() {
+9 -4
View File
@@ -567,7 +567,8 @@ async fn cmd_init(
let db_path = std::path::Path::new(&sqlite_path); let db_path = std::path::Path::new(&sqlite_path);
println!("Creating database directory..."); println!("Creating database directory...");
if let Some(parent) = db_path.parent() if let Some(parent) = db_path.parent()
&& !parent.as_os_str().is_empty() { && !parent.as_os_str().is_empty()
{
std::fs::create_dir_all(parent)?; std::fs::create_dir_all(parent)?;
} }
@@ -664,7 +665,9 @@ async fn run_init_validation(config: &Config, admin_skipped: bool) -> anyhow::Re
let db_path = std::path::Path::new(&sqlite_path); let db_path = std::path::Path::new(&sqlite_path);
let mut dirs_ok = true; let mut dirs_ok = true;
if let Some(parent) = db_path.parent() if let Some(parent) = db_path.parent()
&& !parent.as_os_str().is_empty() && std::fs::create_dir_all(parent).is_err() { && !parent.as_os_str().is_empty()
&& std::fs::create_dir_all(parent).is_err()
{
dirs_ok = false; dirs_ok = false;
} }
if let Ok(home) = std::env::var("HOME") { if let Ok(home) = std::env::var("HOME") {
@@ -891,7 +894,8 @@ async fn cmd_backup(config: &Config, path: &std::path::Path) -> anyhow::Result<(
} }
if let Some(parent) = path.parent() if let Some(parent) = path.parent()
&& !parent.as_os_str().is_empty() { && !parent.as_os_str().is_empty()
{
std::fs::create_dir_all(parent)?; std::fs::create_dir_all(parent)?;
} }
@@ -956,7 +960,8 @@ async fn cmd_restore(config: &Config, path: &std::path::Path) -> anyhow::Result<
let sqlite_path = config.database.sqlite_path(); let sqlite_path = config.database.sqlite_path();
let target_path = std::path::Path::new(&sqlite_path); let target_path = std::path::Path::new(&sqlite_path);
if let Some(parent) = target_path.parent() if let Some(parent) = target_path.parent()
&& !parent.as_os_str().is_empty() { && !parent.as_os_str().is_empty()
{
std::fs::create_dir_all(parent)?; std::fs::create_dir_all(parent)?;
} }
std::fs::copy(path, target_path).with_context(|| { std::fs::copy(path, target_path).with_context(|| {
+6 -3
View File
@@ -294,7 +294,8 @@ impl Default for ShutdownConfig {
fn resolve_home_path(path: &str) -> String { fn resolve_home_path(path: &str) -> String {
if let Some(stripped) = path.strip_prefix("~/") if let Some(stripped) = path.strip_prefix("~/")
&& let Ok(home) = std::env::var("HOME") { && let Ok(home) = std::env::var("HOME")
{
return Path::new(&home) return Path::new(&home)
.join(stripped) .join(stripped)
.to_string_lossy() .to_string_lossy()
@@ -312,7 +313,8 @@ impl Config {
*path = resolve_home_path(path); *path = resolve_home_path(path);
} }
if let Some(ref mut url) = self.database.url if let Some(ref mut url) = self.database.url
&& let Some(stripped) = url.strip_prefix("sqlite://") { && let Some(stripped) = url.strip_prefix("sqlite://")
{
let clean = resolve_home_path(stripped); let clean = resolve_home_path(stripped);
*url = format!("sqlite://{clean}"); *url = format!("sqlite://{clean}");
} }
@@ -371,7 +373,8 @@ impl Config {
/// Default user configuration path (~/.config/nx9-auth/config.toml) /// Default user configuration path (~/.config/nx9-auth/config.toml)
pub fn default_user_config_path() -> Option<PathBuf> { pub fn default_user_config_path() -> Option<PathBuf> {
if let Ok(xdg) = std::env::var("XDG_CONFIG_HOME") if let Ok(xdg) = std::env::var("XDG_CONFIG_HOME")
&& !xdg.is_empty() { && !xdg.is_empty()
{
return Some(PathBuf::from(xdg).join("nx9-auth/config.toml")); return Some(PathBuf::from(xdg).join("nx9-auth/config.toml"));
} }
if let Ok(home) = std::env::var("HOME") { if let Ok(home) = std::env::var("HOME") {
+4 -2
View File
@@ -58,7 +58,8 @@ pub async fn init_provider(
DatabaseBackend::Sqlite => { DatabaseBackend::Sqlite => {
let path = config.database.sqlite_path(); let path = config.database.sqlite_path();
if let Some(parent) = std::path::Path::new(&path).parent() if let Some(parent) = std::path::Path::new(&path).parent()
&& !parent.as_os_str().is_empty() { && !parent.as_os_str().is_empty()
{
std::fs::create_dir_all(parent).with_context(|| { std::fs::create_dir_all(parent).with_context(|| {
format!("failed to create database directory: {}", parent.display()) format!("failed to create database directory: {}", parent.display())
})?; })?;
@@ -177,7 +178,8 @@ pub async fn init_provider(
#[cfg(feature = "sqlite")] #[cfg(feature = "sqlite")]
pub async fn create_pool(path: &str) -> Result<SqlitePool> { pub async fn create_pool(path: &str) -> Result<SqlitePool> {
if let Some(parent) = std::path::Path::new(path).parent() if let Some(parent) = std::path::Path::new(path).parent()
&& !parent.as_os_str().is_empty() { && !parent.as_os_str().is_empty()
{
std::fs::create_dir_all(parent).with_context(|| { std::fs::create_dir_all(parent).with_context(|| {
format!("failed to create database directory: {}", parent.display()) format!("failed to create database directory: {}", parent.display())
})?; })?;
+2 -1
View File
@@ -222,7 +222,8 @@ pub async fn update(
} }
if let Some(new_enabled) = enabled if let Some(new_enabled) = enabled
&& new_enabled != existing.enabled { && new_enabled != existing.enabled
{
let action = if new_enabled { let action = if new_enabled {
"application.member_enabled" "application.member_enabled"
} else { } else {
+2 -1
View File
@@ -324,7 +324,8 @@ pub async fn update(
.find_by_slug(slug) .find_by_slug(slug)
.await .await
.map_err(AppError::Database)? .map_err(AppError::Database)?
&& (other.entity_id != id || other.entity_type != "application") { && (other.entity_id != id || other.entity_type != "application")
{
return Err(AppError::Conflict(format!("slug '{slug}' already exists"))); return Err(AppError::Conflict(format!("slug '{slug}' already exists")));
} }
+2 -1
View File
@@ -191,7 +191,8 @@ pub async fn update_role(
.find_by_name(name) .find_by_name(name)
.await .await
.map_err(AppError::Database)? .map_err(AppError::Database)?
&& other.id != id { && other.id != id
{
return Err(AppError::Conflict(format!("role '{name}' already exists"))); return Err(AppError::Conflict(format!("role '{name}' already exists")));
} }
+4 -6
View File
@@ -74,7 +74,8 @@ where
// cannot rely solely on the HttpOnly cookie. // cannot rely solely on the HttpOnly cookie.
if let Some(auth_header) = parts.headers.get(axum::http::header::AUTHORIZATION) if let Some(auth_header) = parts.headers.get(axum::http::header::AUTHORIZATION)
&& let Ok(value) = auth_header.to_str() && let Ok(value) = auth_header.to_str()
&& let Some(raw) = value.strip_prefix("Bearer ") { && let Some(raw) = value.strip_prefix("Bearer ")
{
let raw = raw.trim(); let raw = raw.trim();
// 2a. Personal access token // 2a. Personal access token
@@ -99,11 +100,8 @@ where
} }
// 2b. Session token (same value as nx9_session cookie) // 2b. Session token (same value as nx9_session cookie)
if let Some(session) = sessions::validate_session( if let Some(session) =
&app_state.provider, sessions::validate_session(&app_state.provider, raw, &app_state.config.security)
raw,
&app_state.config.security,
)
.await? .await?
{ {
let user = app_state let user = app_state
+2 -1
View File
@@ -163,7 +163,8 @@ impl Lifecycle for Application {
} }
if self.router.is_none() if self.router.is_none()
&& let Some(provider) = &self.provider { && let Some(provider) = &self.provider
{
let app_state = crate::state::AppState::new(provider.clone(), config); let app_state = crate::state::AppState::new(provider.clone(), config);
let router = crate::api::router::build(app_state); let router = crate::api::router::build(app_state);
self.router = Some(router); self.router = Some(router);
+20 -5
View File
@@ -75,10 +75,22 @@ pub fn validate_password_strength(password: &str, is_admin: bool) -> Result<(),
// 1. Exact matches for highly common passwords // 1. Exact matches for highly common passwords
let exact_weak: HashSet<&str> = [ let exact_weak: HashSet<&str> = [
"password", "admin123", "qwerty", "12345678", "123456789", "password",
"administrator", "nx9-auth", "nx9auth", "password123", "admin", "admin123",
"letmein", "welcome", "password12345" "qwerty",
].into_iter().collect(); "12345678",
"123456789",
"administrator",
"nx9-auth",
"nx9auth",
"password123",
"admin",
"letmein",
"welcome",
"password12345",
]
.into_iter()
.collect();
if exact_weak.contains(normalized.as_str()) { if exact_weak.contains(normalized.as_str()) {
return Err(AppError::InvalidInput( return Err(AppError::InvalidInput(
@@ -98,7 +110,10 @@ pub fn validate_password_strength(password: &str, is_admin: bool) -> Result<(),
} }
// 3. Reject single repeated characters // 3. Reject single repeated characters
if password.chars().all(|c| c == password.chars().next().unwrap()) { if password
.chars()
.all(|c| c == password.chars().next().unwrap())
{
return Err(AppError::InvalidInput( return Err(AppError::InvalidInput(
"password cannot be a single repeated character".to_string(), "password cannot be a single repeated character".to_string(),
)); ));
+4 -2
View File
@@ -73,7 +73,8 @@ impl RateLimiter {
pub fn check(&self, ip: IpAddr) -> Result<(), AppError> { pub fn check(&self, ip: IpAddr) -> Result<(), AppError> {
if let Some(s) = self.state.get(&ip) if let Some(s) = self.state.get(&ip)
&& let Some(until) = s.locked_until && let Some(until) = s.locked_until
&& Instant::now() < until { && Instant::now() < until
{
return Err(AppError::RateLimited); return Err(AppError::RateLimited);
} }
Ok(()) Ok(())
@@ -86,7 +87,8 @@ impl RateLimiter {
// Clear the lockout if it has expired // Clear the lockout if it has expired
if let Some(until) = s.locked_until if let Some(until) = s.locked_until
&& now >= until { && now >= until
{
s.locked_until = None; s.locked_until = None;
} }
+2 -1
View File
@@ -78,7 +78,8 @@ pub async fn validate_session(
// Check absolute expiry // Check absolute expiry
if let Ok(expires) = chrono::DateTime::parse_from_rfc3339(&session.expires_at) if let Ok(expires) = chrono::DateTime::parse_from_rfc3339(&session.expires_at)
&& now > expires { && now > expires
{
provider provider
.sessions() .sessions()
.revoke(&session.id) .revoke(&session.id)
+2 -1
View File
@@ -132,7 +132,8 @@ pub async fn validate_token(
// Check expiry if set // Check expiry if set
if let Some(ref exp) = token.expires_at if let Some(ref exp) = token.expires_at
&& let Ok(expires) = chrono::DateTime::parse_from_rfc3339(exp) && let Ok(expires) = chrono::DateTime::parse_from_rfc3339(exp)
&& chrono::Utc::now() > expires { && chrono::Utc::now() > expires
{
return Ok(None); return Ok(None);
} }