chore: clean repository and add documentation screenshots
This commit is contained in:
1 parent
71e1e4ee6b
commit
5abbf5123e
1 file changed
+395
-340
@@ -17,156 +17,240 @@
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Overview
|
# nx9-auth
|
||||||
|
|
||||||
**nx9-auth** is a modern, enterprise-grade Identity & Access Management (IAM) platform built entirely in Rust.
|
<div align="center">
|
||||||
|
|
||||||
It provides centralized authentication, authorization, user administration, multi-tenancy, session management, audit logging and administrative tools in a single deployable application.
|
**Enterprise Identity & Access Management (IAM) written entirely in Rust.**
|
||||||
|
|
||||||
Unlike traditional IAM platforms that require multiple services, Java application servers, Redis, PostgreSQL, Kubernetes and extensive operational overhead, **nx9-auth** is intentionally designed around simplicity, security and complete ownership.
|
Self-hosted • Privacy-first • Linux-native • Single Binary • Multi-Tenant • Open Source
|
||||||
|
|
||||||
Current release **v0.2.0** delivers a production-quality Phase 0 implementation using SQLite with a modern Dioxus WebAssembly administration interface.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Why nx9-auth?
|
*Part of the **NX9** ecosystem.*
|
||||||
|
|
||||||
Modern identity platforms are often:
|
</div>
|
||||||
|
|
||||||
- Complex
|
---
|
||||||
- Heavyweight
|
|
||||||
- Cloud dependent
|
|
||||||
- Expensive
|
|
||||||
- Difficult to self-host
|
|
||||||
|
|
||||||
nx9-auth follows a different philosophy.
|
## Overview
|
||||||
|
|
||||||
### Design Goals
|
**nx9-auth** is a modern Identity & Access Management (IAM) server built entirely in **Rust**, designed for organizations that require secure, self-hosted authentication and authorization without the complexity of traditional enterprise IAM platforms.
|
||||||
|
|
||||||
- Self-hosted first
|
Unlike heavyweight Java-based IAM systems, **nx9-auth** focuses on:
|
||||||
- Privacy first
|
|
||||||
- Linux native
|
- Security first
|
||||||
- Pure Rust
|
- Operational simplicity
|
||||||
- Single executable
|
- Low resource usage
|
||||||
- Minimal dependencies
|
- Fast deployment
|
||||||
- Enterprise security
|
- Modern REST APIs
|
||||||
- Zero vendor lock-in
|
- Complete ownership of your data
|
||||||
- Open source forever
|
|
||||||
|
The project is designed as the authentication foundation for the **NX9 ecosystem**, while remaining completely independent and reusable for any application.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Dashboard
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/dashboard-overview.png" width="100%">
|
||||||
|
</p>
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Features
|
# Features
|
||||||
|
|
||||||
## Identity
|
## Identity Management
|
||||||
|
|
||||||
- User Management
|
- ✅ Multi-Tenant Architecture
|
||||||
- User Profiles
|
- ✅ User Management
|
||||||
- Password Authentication
|
- ✅ User Profiles
|
||||||
- Password Reset
|
- ✅ Groups
|
||||||
- Account Locking
|
- ✅ Role Based Access Control (RBAC)
|
||||||
- Profile Management
|
- ✅ Fine-grained Permissions
|
||||||
|
- ✅ Applications
|
||||||
|
- ✅ Service Accounts
|
||||||
|
|
||||||
---
|
## Authentication
|
||||||
|
|
||||||
## Authorization
|
- ✅ Username / Password
|
||||||
|
- ✅ Session Management
|
||||||
- Role Based Access Control (RBAC)
|
- ✅ API Tokens
|
||||||
- Permissions
|
- ✅ Personal Access Tokens
|
||||||
- Multiple Roles per User
|
- ✅ Password Reset
|
||||||
- Fine-grained Authorization
|
- ✅ Secure Cookie Authentication
|
||||||
- Authorization Middleware
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Multi-Tenancy
|
|
||||||
|
|
||||||
- Tenant Management
|
|
||||||
- Tenant Isolation
|
|
||||||
- Tenant Administration
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Organization
|
|
||||||
|
|
||||||
- Groups
|
|
||||||
- Applications
|
|
||||||
- Service Accounts
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Security
|
## Security
|
||||||
|
|
||||||
- Secure Sessions
|
- ✅ Argon2id Password Hashing
|
||||||
- API Tokens
|
- ✅ Session Revocation
|
||||||
- Secure Authentication
|
- ✅ Token Revocation
|
||||||
- Security Headers
|
- ✅ Security Headers
|
||||||
- Audit Logging
|
- ✅ Audit Logging
|
||||||
- Password Hashing (Argon2id)
|
- ✅ Rate Limiting
|
||||||
- Cookie Authentication
|
- ✅ No Plaintext Password Storage
|
||||||
|
- ✅ No Plaintext Token Storage
|
||||||
---
|
- ✅ Transaction Rollback Protection
|
||||||
|
|
||||||
## Administration
|
## Administration
|
||||||
|
|
||||||
- Dashboard
|
- ✅ Dashboard
|
||||||
- User Administration
|
- ✅ Audit Viewer
|
||||||
- Group Administration
|
- ✅ Settings
|
||||||
- Role Administration
|
- ✅ Tenant Management
|
||||||
- Permission Administration
|
- ✅ Profile Management
|
||||||
- Session Administration
|
|
||||||
- Application Administration
|
|
||||||
- Service Account Administration
|
|
||||||
- Tenant Administration
|
|
||||||
- Audit Viewer
|
|
||||||
- Profile Settings
|
|
||||||
|
|
||||||
---
|
## Database
|
||||||
|
|
||||||
## User Interface
|
- ✅ SQLite
|
||||||
|
- 🚧 PostgreSQL
|
||||||
- Dioxus WebAssembly UI
|
- 🚧 MySQL
|
||||||
- Responsive Design
|
|
||||||
- Enterprise Dashboard
|
|
||||||
- Modern Navigation
|
|
||||||
- Dark Theme
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Screenshots
|
# Screenshots
|
||||||
|
|
||||||
*(Coming with future releases)*
|
## Login
|
||||||
|
|
||||||
- Login
|
<p align="center">
|
||||||
- Dashboard
|
<img src="docs/images/login-page.png" width="90%">
|
||||||
- Users
|
</p>
|
||||||
- Roles
|
|
||||||
- Permissions
|
---
|
||||||
- Audit Log
|
|
||||||
- Sessions
|
## Dashboard
|
||||||
- Applications
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/dashboard-overview.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Roles & Permissions
|
||||||
|
|
||||||
|
| Roles | Permissions |
|
||||||
|
|------|------|
|
||||||
|
|  |  |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Applications
|
||||||
|
|
||||||
|
| Applications | Create Application |
|
||||||
|
|------|------|
|
||||||
|
|  |  |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Service Accounts
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/service-accounts-create-dialog.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Sessions
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/sessions-management.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## API Tokens
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/api-tokens-management.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Audit Log
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/audit-log.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Tenants
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/tenants-management.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Settings
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
<img src="docs/images/settings-page.png" width="90%">
|
||||||
|
</p>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Why nx9-auth?
|
||||||
|
|
||||||
|
| Traditional Enterprise IAM | nx9-auth |
|
||||||
|
|----------------------------|----------|
|
||||||
|
| Java based | Rust |
|
||||||
|
| Large memory footprint | Lightweight |
|
||||||
|
| Complex deployment | Single Binary |
|
||||||
|
| Multiple services | Minimal dependencies |
|
||||||
|
| Cloud-first | Self-hosted |
|
||||||
|
| Vendor lock-in | Open Source |
|
||||||
|
| Large attack surface | Minimal attack surface |
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Architecture
|
# Architecture
|
||||||
|
|
||||||
```
|
```
|
||||||
Browser
|
Browser
|
||||||
│
|
|
||||||
Dioxus WebAssembly
|
│
|
||||||
│
|
|
||||||
Axum HTTP Server
|
▼
|
||||||
│
|
|
||||||
Authentication Layer
|
Dioxus Web UI (WASM)
|
||||||
│
|
|
||||||
Authorization Layer
|
│
|
||||||
│
|
|
||||||
REST API Layer
|
▼
|
||||||
│
|
|
||||||
Database Provider API
|
REST API (Axum)
|
||||||
│
|
|
||||||
SQLite Repository Layer
|
│
|
||||||
│
|
|
||||||
SQLite Database
|
▼
|
||||||
|
|
||||||
|
Authentication Layer
|
||||||
|
|
||||||
|
│
|
||||||
|
|
||||||
|
▼
|
||||||
|
|
||||||
|
Authorization (RBAC)
|
||||||
|
|
||||||
|
│
|
||||||
|
|
||||||
|
▼
|
||||||
|
|
||||||
|
Repository Layer
|
||||||
|
|
||||||
|
│
|
||||||
|
|
||||||
|
▼
|
||||||
|
|
||||||
|
Database Provider
|
||||||
|
|
||||||
|
│
|
||||||
|
|
||||||
|
┌───────────┴───────────┐
|
||||||
|
│ │
|
||||||
|
SQLite PostgreSQL
|
||||||
|
(Current) (Planned)
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -175,65 +259,19 @@ nx9-auth follows a different philosophy.
|
|||||||
|
|
||||||
| Component | Technology |
|
| Component | Technology |
|
||||||
|------------|------------|
|
|------------|------------|
|
||||||
| Language | Rust 2021 |
|
| Language | Rust |
|
||||||
| Backend | Axum |
|
| Backend | Axum |
|
||||||
| Frontend | Dioxus |
|
| Frontend | Dioxus |
|
||||||
| UI Runtime | WebAssembly |
|
|
||||||
| Async Runtime | Tokio |
|
|
||||||
| Database | SQLite |
|
| Database | SQLite |
|
||||||
| SQL Layer | SQLx |
|
| Async Runtime | Tokio |
|
||||||
| Serialization | Serde |
|
| Authentication | JWT + Cookies |
|
||||||
| Password Hashing | Argon2id |
|
| Password Hashing | Argon2id |
|
||||||
| Configuration | TOML |
|
| ORM | SQLx |
|
||||||
|
| Serialization | Serde |
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Current Capabilities
|
# Quick Start
|
||||||
|
|
||||||
| Module | Status |
|
|
||||||
|----------|--------|
|
|
||||||
| Dashboard | ✅ |
|
|
||||||
| Authentication | ✅ |
|
|
||||||
| Users | ✅ |
|
|
||||||
| Roles | ✅ |
|
|
||||||
| Permissions | ✅ |
|
|
||||||
| Groups | ✅ |
|
|
||||||
| Tenants | ✅ |
|
|
||||||
| Applications | ✅ |
|
|
||||||
| Sessions | ✅ |
|
|
||||||
| API Tokens | ✅ |
|
|
||||||
| Service Accounts | ✅ |
|
|
||||||
| Audit Logs | ✅ |
|
|
||||||
| Profile | ✅ |
|
|
||||||
| SQLite | ✅ |
|
|
||||||
| PostgreSQL | 🚧 |
|
|
||||||
| OAuth2 | 🚧 |
|
|
||||||
| OIDC | 🚧 |
|
|
||||||
| SAML | 🚧 |
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
# REST API
|
|
||||||
|
|
||||||
```
|
|
||||||
/api/v1/auth
|
|
||||||
/api/v1/dashboard
|
|
||||||
/api/v1/users
|
|
||||||
/api/v1/groups
|
|
||||||
/api/v1/roles
|
|
||||||
/api/v1/permissions
|
|
||||||
/api/v1/tenants
|
|
||||||
/api/v1/applications
|
|
||||||
/api/v1/service-accounts
|
|
||||||
/api/v1/tokens
|
|
||||||
/api/v1/sessions
|
|
||||||
/api/v1/audit
|
|
||||||
/api/v1/profile
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
# Installation
|
|
||||||
|
|
||||||
Clone the repository
|
Clone the repository
|
||||||
|
|
||||||
@@ -254,187 +292,135 @@ Initialize
|
|||||||
./target/release/nx9-auth init
|
./target/release/nx9-auth init
|
||||||
```
|
```
|
||||||
|
|
||||||
Configure
|
Run Setup Wizard
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cp config.example.toml config.toml
|
./target/release/nx9-auth setup
|
||||||
```
|
```
|
||||||
|
|
||||||
Run
|
Start Server
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
./target/release/nx9-auth serve
|
./target/release/nx9-auth serve
|
||||||
```
|
```
|
||||||
|
|
||||||
The administration interface will be available after startup.
|
Open
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
# CLI
|
|
||||||
|
|
||||||
```
|
```
|
||||||
nx9-auth init
|
http://localhost:8655
|
||||||
nx9-auth setup
|
|
||||||
nx9-auth migrate
|
|
||||||
nx9-auth serve
|
|
||||||
nx9-auth doctor
|
|
||||||
nx9-auth version
|
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Configuration
|
# Configuration
|
||||||
|
|
||||||
Configuration is stored in
|
Create your local configuration from the example:
|
||||||
|
|
||||||
```
|
```bash
|
||||||
config.toml
|
cp config.example.toml config.toml
|
||||||
```
|
```
|
||||||
|
|
||||||
An example configuration is available in
|
Then edit:
|
||||||
|
|
||||||
```
|
- Database
|
||||||
config.example.toml
|
- Server
|
||||||
|
- Session
|
||||||
|
- Security
|
||||||
|
- SMTP
|
||||||
|
- Logging
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# CLI
|
||||||
|
|
||||||
|
| Command | Description |
|
||||||
|
|----------|-------------|
|
||||||
|
| init | Initialize project |
|
||||||
|
| setup | Interactive setup wizard |
|
||||||
|
| serve | Start server |
|
||||||
|
| migrate | Run migrations |
|
||||||
|
| backup | Backup database |
|
||||||
|
| restore | Restore database |
|
||||||
|
| user | User management |
|
||||||
|
| token | API token management |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# REST API
|
||||||
|
|
||||||
|
| Endpoint | Description |
|
||||||
|
|-----------|-------------|
|
||||||
|
| /api/v1/auth | Authentication |
|
||||||
|
| /api/v1/users | Users |
|
||||||
|
| /api/v1/groups | Groups |
|
||||||
|
| /api/v1/roles | Roles |
|
||||||
|
| /api/v1/permissions | Permissions |
|
||||||
|
| /api/v1/applications | Applications |
|
||||||
|
| /api/v1/service-accounts | Service Accounts |
|
||||||
|
| /api/v1/sessions | Sessions |
|
||||||
|
| /api/v1/tokens | API Tokens |
|
||||||
|
| /api/v1/audit | Audit Logs |
|
||||||
|
| /api/v1/profile | Current User |
|
||||||
|
| /api/v1/dashboard | Dashboard |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Docker
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Project Layout
|
# CasaOS
|
||||||
|
|
||||||
```
|
```bash
|
||||||
src/
|
docker compose -f compose.casaos.yml up -d
|
||||||
├── api/
|
|
||||||
├── audit/
|
|
||||||
├── cli/
|
|
||||||
├── config/
|
|
||||||
├── db/
|
|
||||||
│ ├── migrations/
|
|
||||||
│ ├── models/
|
|
||||||
│ ├── repository/
|
|
||||||
│ │ ├── sqlite/
|
|
||||||
│ │ ├── postgres/
|
|
||||||
│ │ └── traits.rs
|
|
||||||
│ └── provider.rs
|
|
||||||
├── identity/
|
|
||||||
├── middleware/
|
|
||||||
├── security/
|
|
||||||
├── state.rs
|
|
||||||
└── main.rs
|
|
||||||
|
|
||||||
ui/
|
|
||||||
├── assets/
|
|
||||||
├── components/
|
|
||||||
├── layouts/
|
|
||||||
├── pages/
|
|
||||||
└── services/
|
|
||||||
|
|
||||||
tests/
|
|
||||||
|
|
||||||
docs/
|
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Security
|
# Security
|
||||||
|
|
||||||
Security is a fundamental design goal.
|
Security is a primary design goal.
|
||||||
|
|
||||||
Implemented protections include:
|
Implemented features include:
|
||||||
|
|
||||||
- Argon2id password hashing
|
- Argon2id password hashing
|
||||||
- Secure session management
|
- Password strength validation
|
||||||
- Secure API tokens
|
- Secure session cookies
|
||||||
|
- Session revocation
|
||||||
|
- API token hashing
|
||||||
- Audit logging
|
- Audit logging
|
||||||
- RBAC
|
- Rate limiting
|
||||||
- Tenant isolation
|
- Transaction rollback protection
|
||||||
- Security headers
|
- Security headers
|
||||||
- Authorization middleware
|
- Authorization middleware
|
||||||
- Authentication middleware
|
|
||||||
|
|
||||||
Passwords are never stored in plaintext.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
# Development
|
|
||||||
|
|
||||||
Format
|
|
||||||
|
|
||||||
```bash
|
|
||||||
cargo fmt
|
|
||||||
```
|
|
||||||
|
|
||||||
Check
|
|
||||||
|
|
||||||
```bash
|
|
||||||
cargo check
|
|
||||||
```
|
|
||||||
|
|
||||||
Lint
|
|
||||||
|
|
||||||
```bash
|
|
||||||
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
|
||||||
```
|
|
||||||
|
|
||||||
Tests
|
|
||||||
|
|
||||||
```bash
|
|
||||||
cargo test
|
|
||||||
```
|
|
||||||
|
|
||||||
Build UI
|
|
||||||
|
|
||||||
```bash
|
|
||||||
scripts/build-ui.sh
|
|
||||||
```
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
# Roadmap
|
|
||||||
|
|
||||||
## Phase 0 ✅
|
|
||||||
|
|
||||||
- Enterprise IAM
|
|
||||||
- SQLite
|
|
||||||
- Web Administration
|
|
||||||
- REST API
|
|
||||||
- RBAC
|
- RBAC
|
||||||
- Multi-tenancy
|
- Permission middleware
|
||||||
|
- No plaintext passwords
|
||||||
|
- No plaintext session tokens
|
||||||
|
- No plaintext API tokens
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Phase 1
|
# Project Structure
|
||||||
|
|
||||||
- PostgreSQL
|
```
|
||||||
- Database abstraction improvements
|
docs/ Documentation
|
||||||
- Performance tuning
|
scripts/ Build & release scripts
|
||||||
|
src/ Backend
|
||||||
|
tests/ Integration tests
|
||||||
|
ui/ Dioxus frontend
|
||||||
|
|
||||||
---
|
src/api REST API
|
||||||
|
src/db Database
|
||||||
## Phase 2
|
src/security Security
|
||||||
|
src/middleware Middleware
|
||||||
- OAuth2
|
src/identity Identity services
|
||||||
- OpenID Connect
|
src/config Configuration
|
||||||
- SAML
|
```
|
||||||
- Multi-factor Authentication
|
|
||||||
- WebAuthn / Passkeys
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Phase 3
|
|
||||||
|
|
||||||
- Redis
|
|
||||||
- High Availability
|
|
||||||
- Clustering
|
|
||||||
- Distributed Sessions
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Phase 4
|
|
||||||
|
|
||||||
- LDAP
|
|
||||||
- Active Directory
|
|
||||||
- SCIM
|
|
||||||
- Enterprise Federation
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -442,11 +428,104 @@ scripts/build-ui.sh
|
|||||||
|
|
||||||
Additional documentation is available in the `docs/` directory.
|
Additional documentation is available in the `docs/` directory.
|
||||||
|
|
||||||
- Authentication
|
- AUTHENTICATION.md
|
||||||
- Deployment
|
- BACKUPS.md
|
||||||
- Architecture
|
- BENCHMARKS.md
|
||||||
- API Reference
|
- DEPLOYMENT.md
|
||||||
- Development Guide
|
- DOCKER.md
|
||||||
|
- INTEGRATION_BZOD.md
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Testing
|
||||||
|
|
||||||
|
Run all tests
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo test
|
||||||
|
```
|
||||||
|
|
||||||
|
Run Clippy
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
||||||
|
```
|
||||||
|
|
||||||
|
Run formatter
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo fmt --all
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Current Status
|
||||||
|
|
||||||
|
| Feature | Status |
|
||||||
|
|-----------|--------|
|
||||||
|
| Authentication | ✅ |
|
||||||
|
| RBAC | ✅ |
|
||||||
|
| Sessions | ✅ |
|
||||||
|
| Audit Logs | ✅ |
|
||||||
|
| Applications | ✅ |
|
||||||
|
| Service Accounts | ✅ |
|
||||||
|
| API Tokens | ✅ |
|
||||||
|
| Dashboard | ✅ |
|
||||||
|
| SQLite | ✅ |
|
||||||
|
| PostgreSQL | 🚧 |
|
||||||
|
| OAuth2 | 🚧 |
|
||||||
|
| OpenID Connect | 🚧 |
|
||||||
|
| WebAuthn | 🚧 |
|
||||||
|
| MFA | 🚧 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Roadmap
|
||||||
|
|
||||||
|
## Version 0.2
|
||||||
|
|
||||||
|
- SQLite
|
||||||
|
- REST API
|
||||||
|
- Dashboard
|
||||||
|
- Multi-Tenant
|
||||||
|
- RBAC
|
||||||
|
- Sessions
|
||||||
|
- Audit Logging
|
||||||
|
|
||||||
|
## Version 0.3
|
||||||
|
|
||||||
|
- PostgreSQL
|
||||||
|
- Repository Improvements
|
||||||
|
|
||||||
|
## Version 0.4
|
||||||
|
|
||||||
|
- OAuth2
|
||||||
|
- OpenID Connect
|
||||||
|
- LDAP
|
||||||
|
|
||||||
|
## Version 0.5
|
||||||
|
|
||||||
|
- WebAuthn
|
||||||
|
- Multi-Factor Authentication
|
||||||
|
|
||||||
|
## Version 1.0
|
||||||
|
|
||||||
|
- Stable Enterprise Release
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Philosophy
|
||||||
|
|
||||||
|
The **NX9** ecosystem follows a simple philosophy:
|
||||||
|
|
||||||
|
- Self-hostable first
|
||||||
|
- Linux-native
|
||||||
|
- Privacy-first
|
||||||
|
- Open Source
|
||||||
|
- Minimal dependencies
|
||||||
|
- Operational simplicity
|
||||||
|
- Single binary where practical
|
||||||
|
- No vendor lock-in
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -454,50 +533,26 @@ Additional documentation is available in the `docs/` directory.
|
|||||||
|
|
||||||
Contributions are welcome.
|
Contributions are welcome.
|
||||||
|
|
||||||
Please ensure every contribution:
|
Please:
|
||||||
|
|
||||||
```bash
|
1. Open an issue before major changes.
|
||||||
cargo fmt
|
2. Follow Rust formatting (`cargo fmt`).
|
||||||
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
3. Ensure Clippy passes without warnings.
|
||||||
cargo test
|
4. Add tests for new functionality.
|
||||||
```
|
5. Keep documentation up to date.
|
||||||
|
|
||||||
passes before opening a pull request.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# License
|
# License
|
||||||
|
|
||||||
Released under the MIT License.
|
Licensed under the MIT License.
|
||||||
|
|
||||||
See the LICENSE file for details.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# About NX9
|
<div align="center">
|
||||||
|
|
||||||
**nx9-auth** is part of the **NX9** ecosystem.
|
**nx9-auth** — Secure, self-hosted Identity & Access Management built with Rust.
|
||||||
|
|
||||||
NX9 is a collection of self-hosted, privacy-first, Linux-native infrastructure software written entirely in Rust.
|
Part of the **NX9** ecosystem.
|
||||||
|
|
||||||
## NX9 Principles
|
</div>
|
||||||
|
|
||||||
- Self-hosted First
|
|
||||||
- Privacy First
|
|
||||||
- Linux Native
|
|
||||||
- Pure Rust
|
|
||||||
- Single Binary
|
|
||||||
- Minimal Dependencies
|
|
||||||
- Open Standards
|
|
||||||
- Enterprise Security
|
|
||||||
- FOSS Forever
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
<p align="center">
|
|
||||||
|
|
||||||
**Own your infrastructure. Own your identity. Own your data.**
|
|
||||||
|
|
||||||
**No subscriptions. No vendor lock-in. No compromises.**
|
|
||||||
|
|
||||||
</p>
|
|
||||||
Reference in new issue
Block a user