diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index 931887c..94ea733 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -1,22 +1,46 @@ -- uses: actions/checkout@v4 +name: Rust CI -- name: Install Rust - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ matrix.rust }} - components: rustfmt, clippy +on: + push: + branches: + - main + pull_request: + branches: + - main -- name: Cache Cargo - uses: Swatinem/rust-cache@v2 +permissions: + contents: read -- name: Check formatting - run: cargo fmt --check +jobs: + test: + name: Rust ${{ matrix.rust }} + runs-on: ubuntu-latest -- name: Clippy - run: cargo clippy --all-targets -- -D warnings + strategy: + matrix: + rust: + - stable -- name: Tests - run: cargo test --all + steps: + - uses: actions/checkout@v4 -- name: Release build - run: cargo build --release \ No newline at end of file + - name: Install Rust + uses: dtolnay/rust-toolchain@stable + with: + toolchain: ${{ matrix.rust }} + components: rustfmt, clippy + + - name: Cache Cargo + uses: Swatinem/rust-cache@v2 + + - name: Check formatting + run: cargo fmt --check + + - name: Run Clippy + run: cargo clippy --workspace --all-targets -- -D warnings + + - name: Run Tests + run: cargo test --workspace --all-features + + - name: Release Build + run: cargo build --release --workspace \ No newline at end of file diff --git a/docs/dashboard.html b/docs/dashboard.html new file mode 100644 index 0000000..b6bf269 --- /dev/null +++ b/docs/dashboard.html @@ -0,0 +1,912 @@ + + +
+ + ++ High-performance, zero-Node.js Rust IAM server featuring Argon2id password hashing, BLAKE3 token hashing, and strict OWASP security controls. +
+{
+ "status": "ready",
+ "message": "Click 'Send Request' to execute simulated request."
+}
+ Non-enumerating authentication failures with constant-time dummy Argon2id execution delays for unknown users.
+Hardened CSP (script-src 'self' 'wasm-unsafe-eval') with zero inline script execution and zero javascript: URIs.
Dual-mode cookie authentication featuring HttpOnly, SameSite=Lax, and automatic Cache-Control: no-store.
Lock-free exponential backoff lockout penalties managed via concurrent DashMap tracking.
| Method | +Endpoint Path | +Guard / Authentication | +Description | +
|---|---|---|---|
| GET | +/health |
+ Public | +System and database health diagnostic check. | +
| GET | +/version |
+ Public | +Returns binary version and build target information. | +
| POST | +/api/v1/auth/login |
+ Rate Limiter | +JSON login. Issues session cookies & Bearer access tokens. | +
| GET | +/api/v1/auth/me |
+ AuthUser (Cookie/Bearer) | +Resolves current identity, assigned roles, and permission scopes. | +
| POST | +/api/v1/auth/logout |
+ AuthUser | +Revokes active session and invalidates HttpOnly cookies. | +
| GET | +/api/v1/users |
+ AuthUser (Admin) | +Paginated search and listing of registered platform users. | +