diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index 931887c..94ea733 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -1,22 +1,46 @@ -- uses: actions/checkout@v4 +name: Rust CI -- name: Install Rust - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ matrix.rust }} - components: rustfmt, clippy +on: + push: + branches: + - main + pull_request: + branches: + - main -- name: Cache Cargo - uses: Swatinem/rust-cache@v2 +permissions: + contents: read -- name: Check formatting - run: cargo fmt --check +jobs: + test: + name: Rust ${{ matrix.rust }} + runs-on: ubuntu-latest -- name: Clippy - run: cargo clippy --all-targets -- -D warnings + strategy: + matrix: + rust: + - stable -- name: Tests - run: cargo test --all + steps: + - uses: actions/checkout@v4 -- name: Release build - run: cargo build --release \ No newline at end of file + - name: Install Rust + uses: dtolnay/rust-toolchain@stable + with: + toolchain: ${{ matrix.rust }} + components: rustfmt, clippy + + - name: Cache Cargo + uses: Swatinem/rust-cache@v2 + + - name: Check formatting + run: cargo fmt --check + + - name: Run Clippy + run: cargo clippy --workspace --all-targets -- -D warnings + + - name: Run Tests + run: cargo test --workspace --all-features + + - name: Release Build + run: cargo build --release --workspace \ No newline at end of file diff --git a/docs/dashboard.html b/docs/dashboard.html new file mode 100644 index 0000000..b6bf269 --- /dev/null +++ b/docs/dashboard.html @@ -0,0 +1,912 @@ + + + + + + NX9-Auth โ€” Identity & Access Management Dashboard + + + + + + + + + + + +
+ +
+ +
+ + +
+
+
+
+ System Health: Operational +
+

Identity & Access Control Center

+

+ High-performance, zero-Node.js Rust IAM server featuring Argon2id password hashing, BLAKE3 token hashing, and strict OWASP security controls. +

+
+
+ +
+
+ + +
+
+
Active Engine
+
Axum / Tokio
+ +
+
+
Password Protection
+
Argon2id
+ +
+
+
Token Hashing
+
BLAKE3
+ +
+
+
UI Architecture
+
Dioxus WASM
+ +
+
+ + +
+

+ ๐Ÿงช Authentication Simulator & Protocol Inspector +

+ +
+ +
+

Simulate API Request

+ +
+ + +
+ +
+ + +
+ +
+ + +
+ +
+ + +
+
+ + +
+
+ RESPONSE INSPECTOR + HTTP 200 OK +
+
+ Content-Type: application/json | Cache-Control: no-store +
+
{
+  "status": "ready",
+  "message": "Click 'Send Request' to execute simulated request."
+}
+
+
+
+ + +
+

+ ๐Ÿ›ก๏ธ Security & Compliance Architecture +

+ +
+
+
๐Ÿ”‘
+
+

Timing-Attack Mitigation

+

Non-enumerating authentication failures with constant-time dummy Argon2id execution delays for unknown users.

+
+
+
+
๐ŸŒ
+
+

Strict Content Security Policy

+

Hardened CSP (script-src 'self' 'wasm-unsafe-eval') with zero inline script execution and zero javascript: URIs.

+
+
+
+
๐Ÿช
+
+

HttpOnly Cookie Protection

+

Dual-mode cookie authentication featuring HttpOnly, SameSite=Lax, and automatic Cache-Control: no-store.

+
+
+
+
โšก
+
+

In-Memory IP Rate Limiter

+

Lock-free exponential backoff lockout penalties managed via concurrent DashMap tracking.

+
+
+
+
+ + +
+

+ ๐Ÿ“š Core REST API Surface Reference +

+ +
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
MethodEndpoint PathGuard / AuthenticationDescription
GET/healthPublicSystem and database health diagnostic check.
GET/versionPublicReturns binary version and build target information.
POST/api/v1/auth/loginRate LimiterJSON login. Issues session cookies & Bearer access tokens.
GET/api/v1/auth/meAuthUser (Cookie/Bearer)Resolves current identity, assigned roles, and permission scopes.
POST/api/v1/auth/logoutAuthUserRevokes active session and invalidates HttpOnly cookies.
GET/api/v1/usersAuthUser (Admin)Paginated search and listing of registered platform users.
+
+
+ + + + +
+ + + + +