chore: clean repository and add documentation screenshots

This commit is contained in:
thakares committed 2026-07-21 16:32:56 +05:30
1 parent 71e1e4ee6b
commit 5abbf5123e
1 file changed
+395 -340
+395 -340
View File
@@ -17,156 +17,240 @@
--- ---
## Overview # nx9-auth
**nx9-auth** is a modern, enterprise-grade Identity & Access Management (IAM) platform built entirely in Rust. <div align="center">
It provides centralized authentication, authorization, user administration, multi-tenancy, session management, audit logging and administrative tools in a single deployable application. **Enterprise Identity & Access Management (IAM) written entirely in Rust.**
Unlike traditional IAM platforms that require multiple services, Java application servers, Redis, PostgreSQL, Kubernetes and extensive operational overhead, **nx9-auth** is intentionally designed around simplicity, security and complete ownership. Self-hosted • Privacy-first • Linux-native • Single Binary • Multi-Tenant • Open Source
Current release **v0.2.0** delivers a production-quality Phase 0 implementation using SQLite with a modern Dioxus WebAssembly administration interface.
--- ---
# Why nx9-auth? *Part of the **NX9** ecosystem.*
Modern identity platforms are often: </div>
- Complex ---
- Heavyweight
- Cloud dependent
- Expensive
- Difficult to self-host
nx9-auth follows a different philosophy. ## Overview
### Design Goals **nx9-auth** is a modern Identity & Access Management (IAM) server built entirely in **Rust**, designed for organizations that require secure, self-hosted authentication and authorization without the complexity of traditional enterprise IAM platforms.
- Self-hosted first Unlike heavyweight Java-based IAM systems, **nx9-auth** focuses on:
- Privacy first
- Linux native - Security first
- Pure Rust - Operational simplicity
- Single executable - Low resource usage
- Minimal dependencies - Fast deployment
- Enterprise security - Modern REST APIs
- Zero vendor lock-in - Complete ownership of your data
- Open source forever
The project is designed as the authentication foundation for the **NX9 ecosystem**, while remaining completely independent and reusable for any application.
---
# Dashboard
<p align="center">
<img src="docs/images/dashboard-overview.png" width="100%">
</p>
--- ---
# Features # Features
## Identity ## Identity Management
- User Management - ✅ Multi-Tenant Architecture
- User Profiles - ✅ User Management
- Password Authentication - ✅ User Profiles
- Password Reset - ✅ Groups
- Account Locking - ✅ Role Based Access Control (RBAC)
- Profile Management - ✅ Fine-grained Permissions
- ✅ Applications
- ✅ Service Accounts
--- ## Authentication
## Authorization - ✅ Username / Password
- ✅ Session Management
- Role Based Access Control (RBAC) - ✅ API Tokens
- Permissions - ✅ Personal Access Tokens
- Multiple Roles per User - ✅ Password Reset
- Fine-grained Authorization - ✅ Secure Cookie Authentication
- Authorization Middleware
---
## Multi-Tenancy
- Tenant Management
- Tenant Isolation
- Tenant Administration
---
## Organization
- Groups
- Applications
- Service Accounts
---
## Security ## Security
- Secure Sessions - ✅ Argon2id Password Hashing
- API Tokens - ✅ Session Revocation
- Secure Authentication - ✅ Token Revocation
- Security Headers - ✅ Security Headers
- Audit Logging - ✅ Audit Logging
- Password Hashing (Argon2id) - ✅ Rate Limiting
- Cookie Authentication - ✅ No Plaintext Password Storage
- ✅ No Plaintext Token Storage
--- - ✅ Transaction Rollback Protection
## Administration ## Administration
- Dashboard - ✅ Dashboard
- User Administration - ✅ Audit Viewer
- Group Administration - ✅ Settings
- Role Administration - ✅ Tenant Management
- Permission Administration - ✅ Profile Management
- Session Administration
- Application Administration
- Service Account Administration
- Tenant Administration
- Audit Viewer
- Profile Settings
--- ## Database
## User Interface - ✅ SQLite
- 🚧 PostgreSQL
- Dioxus WebAssembly UI - 🚧 MySQL
- Responsive Design
- Enterprise Dashboard
- Modern Navigation
- Dark Theme
--- ---
# Screenshots # Screenshots
*(Coming with future releases)* ## Login
- Login <p align="center">
- Dashboard <img src="docs/images/login-page.png" width="90%">
- Users </p>
- Roles
- Permissions ---
- Audit Log
- Sessions ## Dashboard
- Applications
<p align="center">
<img src="docs/images/dashboard-overview.png" width="90%">
</p>
---
## Roles & Permissions
| Roles | Permissions |
|------|------|
| ![](docs/images/roles-management.png) | ![](docs/images/permissions-management.png) |
---
## Applications
| Applications | Create Application |
|------|------|
| ![](docs/images/applications-management.png) | ![](docs/images/applications-create-dialog.png) |
---
## Service Accounts
<p align="center">
<img src="docs/images/service-accounts-create-dialog.png" width="90%">
</p>
---
## Sessions
<p align="center">
<img src="docs/images/sessions-management.png" width="90%">
</p>
---
## API Tokens
<p align="center">
<img src="docs/images/api-tokens-management.png" width="90%">
</p>
---
## Audit Log
<p align="center">
<img src="docs/images/audit-log.png" width="90%">
</p>
---
## Tenants
<p align="center">
<img src="docs/images/tenants-management.png" width="90%">
</p>
---
## Settings
<p align="center">
<img src="docs/images/settings-page.png" width="90%">
</p>
---
# Why nx9-auth?
| Traditional Enterprise IAM | nx9-auth |
|----------------------------|----------|
| Java based | Rust |
| Large memory footprint | Lightweight |
| Complex deployment | Single Binary |
| Multiple services | Minimal dependencies |
| Cloud-first | Self-hosted |
| Vendor lock-in | Open Source |
| Large attack surface | Minimal attack surface |
--- ---
# Architecture # Architecture
``` ```
Browser Browser
│
Dioxus WebAssembly │
│
Axum HTTP Server ▼
│
Authentication Layer Dioxus Web UI (WASM)
│
Authorization Layer │
│
REST API Layer ▼
│
Database Provider API REST API (Axum)
│
SQLite Repository Layer │
│
SQLite Database ▼
Authentication Layer
│
▼
Authorization (RBAC)
│
▼
Repository Layer
│
▼
Database Provider
│
┌───────────┴───────────┐
│ │
SQLite PostgreSQL
(Current) (Planned)
``` ```
--- ---
@@ -175,65 +259,19 @@ nx9-auth follows a different philosophy.
| Component | Technology | | Component | Technology |
|------------|------------| |------------|------------|
| Language | Rust 2021 | | Language | Rust |
| Backend | Axum | | Backend | Axum |
| Frontend | Dioxus | | Frontend | Dioxus |
| UI Runtime | WebAssembly |
| Async Runtime | Tokio |
| Database | SQLite | | Database | SQLite |
| SQL Layer | SQLx | | Async Runtime | Tokio |
| Serialization | Serde | | Authentication | JWT + Cookies |
| Password Hashing | Argon2id | | Password Hashing | Argon2id |
| Configuration | TOML | | ORM | SQLx |
| Serialization | Serde |
--- ---
# Current Capabilities # Quick Start
| Module | Status |
|----------|--------|
| Dashboard | ✅ |
| Authentication | ✅ |
| Users | ✅ |
| Roles | ✅ |
| Permissions | ✅ |
| Groups | ✅ |
| Tenants | ✅ |
| Applications | ✅ |
| Sessions | ✅ |
| API Tokens | ✅ |
| Service Accounts | ✅ |
| Audit Logs | ✅ |
| Profile | ✅ |
| SQLite | ✅ |
| PostgreSQL | 🚧 |
| OAuth2 | 🚧 |
| OIDC | 🚧 |
| SAML | 🚧 |
---
# REST API
```
/api/v1/auth
/api/v1/dashboard
/api/v1/users
/api/v1/groups
/api/v1/roles
/api/v1/permissions
/api/v1/tenants
/api/v1/applications
/api/v1/service-accounts
/api/v1/tokens
/api/v1/sessions
/api/v1/audit
/api/v1/profile
```
---
# Installation
Clone the repository Clone the repository
@@ -254,187 +292,135 @@ Initialize
./target/release/nx9-auth init ./target/release/nx9-auth init
``` ```
Configure Run Setup Wizard
```bash ```bash
cp config.example.toml config.toml ./target/release/nx9-auth setup
``` ```
Run Start Server
```bash ```bash
./target/release/nx9-auth serve ./target/release/nx9-auth serve
``` ```
The administration interface will be available after startup. Open
---
# CLI
``` ```
nx9-auth init http://localhost:8655
nx9-auth setup
nx9-auth migrate
nx9-auth serve
nx9-auth doctor
nx9-auth version
``` ```
--- ---
# Configuration # Configuration
Configuration is stored in Create your local configuration from the example:
``` ```bash
config.toml cp config.example.toml config.toml
``` ```
An example configuration is available in Then edit:
``` - Database
config.example.toml - Server
- Session
- Security
- SMTP
- Logging
---
# CLI
| Command | Description |
|----------|-------------|
| init | Initialize project |
| setup | Interactive setup wizard |
| serve | Start server |
| migrate | Run migrations |
| backup | Backup database |
| restore | Restore database |
| user | User management |
| token | API token management |
---
# REST API
| Endpoint | Description |
|-----------|-------------|
| /api/v1/auth | Authentication |
| /api/v1/users | Users |
| /api/v1/groups | Groups |
| /api/v1/roles | Roles |
| /api/v1/permissions | Permissions |
| /api/v1/applications | Applications |
| /api/v1/service-accounts | Service Accounts |
| /api/v1/sessions | Sessions |
| /api/v1/tokens | API Tokens |
| /api/v1/audit | Audit Logs |
| /api/v1/profile | Current User |
| /api/v1/dashboard | Dashboard |
---
# Docker
```bash
docker compose up -d
``` ```
--- ---
# Project Layout # CasaOS
``` ```bash
src/ docker compose -f compose.casaos.yml up -d
├── api/
├── audit/
├── cli/
├── config/
├── db/
│ ├── migrations/
│ ├── models/
│ ├── repository/
│ │ ├── sqlite/
│ │ ├── postgres/
│ │ └── traits.rs
│ └── provider.rs
├── identity/
├── middleware/
├── security/
├── state.rs
└── main.rs
ui/
├── assets/
├── components/
├── layouts/
├── pages/
└── services/
tests/
docs/
``` ```
--- ---
# Security # Security
Security is a fundamental design goal. Security is a primary design goal.
Implemented protections include: Implemented features include:
- Argon2id password hashing - Argon2id password hashing
- Secure session management - Password strength validation
- Secure API tokens - Secure session cookies
- Session revocation
- API token hashing
- Audit logging - Audit logging
- RBAC - Rate limiting
- Tenant isolation - Transaction rollback protection
- Security headers - Security headers
- Authorization middleware - Authorization middleware
- Authentication middleware
Passwords are never stored in plaintext.
---
# Development
Format
```bash
cargo fmt
```
Check
```bash
cargo check
```
Lint
```bash
cargo clippy --workspace --all-targets --all-features -- -D warnings
```
Tests
```bash
cargo test
```
Build UI
```bash
scripts/build-ui.sh
```
---
# Roadmap
## Phase 0 ✅
- Enterprise IAM
- SQLite
- Web Administration
- REST API
- RBAC - RBAC
- Multi-tenancy - Permission middleware
- No plaintext passwords
- No plaintext session tokens
- No plaintext API tokens
--- ---
## Phase 1 # Project Structure
- PostgreSQL ```
- Database abstraction improvements docs/ Documentation
- Performance tuning scripts/ Build & release scripts
src/ Backend
tests/ Integration tests
ui/ Dioxus frontend
--- src/api REST API
src/db Database
## Phase 2 src/security Security
src/middleware Middleware
- OAuth2 src/identity Identity services
- OpenID Connect src/config Configuration
- SAML ```
- Multi-factor Authentication
- WebAuthn / Passkeys
---
## Phase 3
- Redis
- High Availability
- Clustering
- Distributed Sessions
---
## Phase 4
- LDAP
- Active Directory
- SCIM
- Enterprise Federation
--- ---
@@ -442,11 +428,104 @@ scripts/build-ui.sh
Additional documentation is available in the `docs/` directory. Additional documentation is available in the `docs/` directory.
- Authentication - AUTHENTICATION.md
- Deployment - BACKUPS.md
- Architecture - BENCHMARKS.md
- API Reference - DEPLOYMENT.md
- Development Guide - DOCKER.md
- INTEGRATION_BZOD.md
---
# Testing
Run all tests
```bash
cargo test
```
Run Clippy
```bash
cargo clippy --workspace --all-targets --all-features -- -D warnings
```
Run formatter
```bash
cargo fmt --all
```
---
# Current Status
| Feature | Status |
|-----------|--------|
| Authentication | ✅ |
| RBAC | ✅ |
| Sessions | ✅ |
| Audit Logs | ✅ |
| Applications | ✅ |
| Service Accounts | ✅ |
| API Tokens | ✅ |
| Dashboard | ✅ |
| SQLite | ✅ |
| PostgreSQL | 🚧 |
| OAuth2 | 🚧 |
| OpenID Connect | 🚧 |
| WebAuthn | 🚧 |
| MFA | 🚧 |
---
# Roadmap
## Version 0.2
- SQLite
- REST API
- Dashboard
- Multi-Tenant
- RBAC
- Sessions
- Audit Logging
## Version 0.3
- PostgreSQL
- Repository Improvements
## Version 0.4
- OAuth2
- OpenID Connect
- LDAP
## Version 0.5
- WebAuthn
- Multi-Factor Authentication
## Version 1.0
- Stable Enterprise Release
---
# Philosophy
The **NX9** ecosystem follows a simple philosophy:
- Self-hostable first
- Linux-native
- Privacy-first
- Open Source
- Minimal dependencies
- Operational simplicity
- Single binary where practical
- No vendor lock-in
--- ---
@@ -454,50 +533,26 @@ Additional documentation is available in the `docs/` directory.
Contributions are welcome. Contributions are welcome.
Please ensure every contribution: Please:
```bash 1. Open an issue before major changes.
cargo fmt 2. Follow Rust formatting (`cargo fmt`).
cargo clippy --workspace --all-targets --all-features -- -D warnings 3. Ensure Clippy passes without warnings.
cargo test 4. Add tests for new functionality.
``` 5. Keep documentation up to date.
passes before opening a pull request.
--- ---
# License # License
Released under the MIT License. Licensed under the MIT License.
See the LICENSE file for details.
--- ---
# About NX9 <div align="center">
**nx9-auth** is part of the **NX9** ecosystem. **nx9-auth** — Secure, self-hosted Identity & Access Management built with Rust.
NX9 is a collection of self-hosted, privacy-first, Linux-native infrastructure software written entirely in Rust. Part of the **NX9** ecosystem.
## NX9 Principles </div>
- Self-hosted First
- Privacy First
- Linux Native
- Pure Rust
- Single Binary
- Minimal Dependencies
- Open Standards
- Enterprise Security
- FOSS Forever
---
<p align="center">
**Own your infrastructure. Own your identity. Own your data.**
**No subscriptions. No vendor lock-in. No compromises.**
</p>