README: Updated to v0.2.0, with UI/UX implementation, phase 0
This commit is contained in:
1 parent
7b7797cf7f
commit
ce3bff5097
3 files changed
+453
-133
No files matched your search
@@ -1,183 +1,503 @@
|
||||
# nx9-auth
|
||||
|
||||
A lightweight Identity and Access Management (IAM) service.
|
||||
<p align="center">
|
||||
|
||||
Built with Rust, Axum, SQLite, and modern security practices, `nx9-auth` provides authentication, authorization, session management, personal access tokens, audit logging, and role-based access control in a single deployable binary.
|
||||
**Enterprise Identity & Access Management (IAM)**
|
||||
|
||||
## Features
|
||||
*Self-Hosted • Privacy-First • Pure Rust • Single Binary • Linux Native*
|
||||
|
||||
* User management
|
||||
* Role-Based Access Control (RBAC)
|
||||
* Session authentication
|
||||
* Personal Access Tokens (PAT)
|
||||
* Audit logging
|
||||
* Transaction-safe operations
|
||||
* SQLite with WAL mode
|
||||
* Online backups
|
||||
* Interactive initialization
|
||||
* Docker and CasaOS support
|
||||
* Systemd deployment support
|
||||
* XDG-compliant user mode
|
||||
* **Dioxus enterprise web UI** (single binary, no Node.js)
|
||||
[]()
|
||||
[](https://www.rust-lang.org/)
|
||||
[](LICENSE)
|
||||
[]()
|
||||
[]()
|
||||
[]()
|
||||
|
||||
## Quick Start
|
||||
</p>
|
||||
|
||||
Initialize a new installation:
|
||||
---
|
||||
|
||||
```bash
|
||||
nx9-auth init
|
||||
```
|
||||
## Overview
|
||||
|
||||
Start the server:
|
||||
**nx9-auth** is a modern, enterprise-grade Identity & Access Management (IAM) platform built entirely in Rust.
|
||||
|
||||
```bash
|
||||
nx9-auth serve
|
||||
```
|
||||
It provides centralized authentication, authorization, user administration, multi-tenancy, session management, audit logging and administrative tools in a single deployable application.
|
||||
|
||||
Verify health:
|
||||
Unlike traditional IAM platforms that require multiple services, Java application servers, Redis, PostgreSQL, Kubernetes and extensive operational overhead, **nx9-auth** is intentionally designed around simplicity, security and complete ownership.
|
||||
|
||||
```bash
|
||||
curl http://127.0.0.1:8655/health
|
||||
```
|
||||
Current release **v0.2.0** delivers a production-quality Phase 0 implementation using SQLite with a modern Dioxus WebAssembly administration interface.
|
||||
|
||||
Open the UI in a browser:
|
||||
---
|
||||
|
||||
```text
|
||||
http://127.0.0.1:8655/
|
||||
```
|
||||
# Why nx9-auth?
|
||||
|
||||
## Authentication
|
||||
Modern identity platforms are often:
|
||||
|
||||
Login is **POST-only** with a JSON body (never query parameters):
|
||||
- Complex
|
||||
- Heavyweight
|
||||
- Cloud dependent
|
||||
- Expensive
|
||||
- Difficult to self-host
|
||||
|
||||
```bash
|
||||
curl -sS -X POST http://127.0.0.1:8655/api/v1/auth/login \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d '{"username":"admin","password":"your-password"}'
|
||||
```
|
||||
nx9-auth follows a different philosophy.
|
||||
|
||||
Passwords are verified with **Argon2id** and never logged or stored in plaintext.
|
||||
See [docs/AUTHENTICATION.md](docs/AUTHENTICATION.md) for the full security model.
|
||||
### Design Goals
|
||||
|
||||
## Web UI
|
||||
- Self-hosted first
|
||||
- Privacy first
|
||||
- Linux native
|
||||
- Pure Rust
|
||||
- Single executable
|
||||
- Minimal dependencies
|
||||
- Enterprise security
|
||||
- Zero vendor lock-in
|
||||
- Open source forever
|
||||
|
||||
The management UI is implemented in pure Rust with **Dioxus** (no React/Vue/Node).
|
||||
It is served from the same process as the REST API.
|
||||
---
|
||||
|
||||
### Build UI assets
|
||||
# Features
|
||||
|
||||
```bash
|
||||
./scripts/build-ui.sh
|
||||
```
|
||||
## Identity
|
||||
|
||||
This compiles `ui/` to WebAssembly and writes static files to `ui/dist/`.
|
||||
The server serves those files automatically (override path with `NX9_AUTH_UI_DIST`).
|
||||
- User Management
|
||||
- User Profiles
|
||||
- Password Authentication
|
||||
- Password Reset
|
||||
- Account Locking
|
||||
- Profile Management
|
||||
|
||||
### UI features
|
||||
---
|
||||
|
||||
* Login / logout with session restoration
|
||||
* Permission-aware sidebar and routing
|
||||
* User, role, permission, token, application, and service-account management
|
||||
* Audit log viewer with filters
|
||||
* Profile and settings (theme: light / dark / system)
|
||||
* Responsive enterprise shell (header, sidebar, breadcrumbs, toasts)
|
||||
## Authorization
|
||||
|
||||
Frontend RBAC is presentation-only; the backend remains authoritative.
|
||||
- Role Based Access Control (RBAC)
|
||||
- Permissions
|
||||
- Multiple Roles per User
|
||||
- Fine-grained Authorization
|
||||
- Authorization Middleware
|
||||
|
||||
## CLI Commands
|
||||
---
|
||||
|
||||
```bash
|
||||
nx9-auth init
|
||||
nx9-auth serve
|
||||
nx9-auth doctor
|
||||
## Multi-Tenancy
|
||||
|
||||
nx9-auth create-user
|
||||
nx9-auth create-admin
|
||||
- Tenant Management
|
||||
- Tenant Isolation
|
||||
- Tenant Administration
|
||||
|
||||
nx9-auth create-token
|
||||
nx9-auth revoke-token
|
||||
---
|
||||
|
||||
nx9-auth show-user
|
||||
nx9-auth show-token
|
||||
## Organization
|
||||
|
||||
nx9-auth backup
|
||||
```
|
||||
- Groups
|
||||
- Applications
|
||||
- Service Accounts
|
||||
|
||||
## Deployment Modes
|
||||
|
||||
### User Mode
|
||||
|
||||
Uses XDG directories:
|
||||
|
||||
```text
|
||||
~/.config/nx9-auth/
|
||||
~/.local/share/nx9-auth/
|
||||
~/.local/state/nx9-auth/
|
||||
```
|
||||
|
||||
### System Mode
|
||||
|
||||
```text
|
||||
/etc/nx9-auth/
|
||||
/var/lib/nx9-auth/
|
||||
/var/log/nx9-auth/
|
||||
```
|
||||
|
||||
### Docker
|
||||
|
||||
```bash
|
||||
docker compose up -d
|
||||
```
|
||||
|
||||
### CasaOS
|
||||
|
||||
```text
|
||||
/DATA/AppData/nx9-auth
|
||||
├── config
|
||||
├── db
|
||||
├── state
|
||||
└── backups
|
||||
```
|
||||
---
|
||||
|
||||
## Security
|
||||
|
||||
* Argon2id password hashing
|
||||
* BLAKE3 token hashing
|
||||
* Session revocation
|
||||
* Transactional audit logging
|
||||
* Timing attack mitigation
|
||||
* Security regression test suite
|
||||
- Secure Sessions
|
||||
- API Tokens
|
||||
- Secure Authentication
|
||||
- Security Headers
|
||||
- Audit Logging
|
||||
- Password Hashing (Argon2id)
|
||||
- Cookie Authentication
|
||||
|
||||
## Testing
|
||||
---
|
||||
|
||||
## Administration
|
||||
|
||||
- Dashboard
|
||||
- User Administration
|
||||
- Group Administration
|
||||
- Role Administration
|
||||
- Permission Administration
|
||||
- Session Administration
|
||||
- Application Administration
|
||||
- Service Account Administration
|
||||
- Tenant Administration
|
||||
- Audit Viewer
|
||||
- Profile Settings
|
||||
|
||||
---
|
||||
|
||||
## User Interface
|
||||
|
||||
- Dioxus WebAssembly UI
|
||||
- Responsive Design
|
||||
- Enterprise Dashboard
|
||||
- Modern Navigation
|
||||
- Dark Theme
|
||||
|
||||
---
|
||||
|
||||
# Screenshots
|
||||
|
||||
*(Coming with future releases)*
|
||||
|
||||
- Login
|
||||
- Dashboard
|
||||
- Users
|
||||
- Roles
|
||||
- Permissions
|
||||
- Audit Log
|
||||
- Sessions
|
||||
- Applications
|
||||
|
||||
---
|
||||
|
||||
# Architecture
|
||||
|
||||
```
|
||||
Browser
|
||||
│
|
||||
Dioxus WebAssembly
|
||||
│
|
||||
Axum HTTP Server
|
||||
│
|
||||
Authentication Layer
|
||||
│
|
||||
Authorization Layer
|
||||
│
|
||||
REST API Layer
|
||||
│
|
||||
Database Provider API
|
||||
│
|
||||
SQLite Repository Layer
|
||||
│
|
||||
SQLite Database
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Technology Stack
|
||||
|
||||
| Component | Technology |
|
||||
|------------|------------|
|
||||
| Language | Rust 2021 |
|
||||
| Backend | Axum |
|
||||
| Frontend | Dioxus |
|
||||
| UI Runtime | WebAssembly |
|
||||
| Async Runtime | Tokio |
|
||||
| Database | SQLite |
|
||||
| SQL Layer | SQLx |
|
||||
| Serialization | Serde |
|
||||
| Password Hashing | Argon2id |
|
||||
| Configuration | TOML |
|
||||
|
||||
---
|
||||
|
||||
# Current Capabilities
|
||||
|
||||
| Module | Status |
|
||||
|----------|--------|
|
||||
| Dashboard | ✅ |
|
||||
| Authentication | ✅ |
|
||||
| Users | ✅ |
|
||||
| Roles | ✅ |
|
||||
| Permissions | ✅ |
|
||||
| Groups | ✅ |
|
||||
| Tenants | ✅ |
|
||||
| Applications | ✅ |
|
||||
| Sessions | ✅ |
|
||||
| API Tokens | ✅ |
|
||||
| Service Accounts | ✅ |
|
||||
| Audit Logs | ✅ |
|
||||
| Profile | ✅ |
|
||||
| SQLite | ✅ |
|
||||
| PostgreSQL | 🚧 |
|
||||
| OAuth2 | 🚧 |
|
||||
| OIDC | 🚧 |
|
||||
| SAML | 🚧 |
|
||||
|
||||
---
|
||||
|
||||
# REST API
|
||||
|
||||
```
|
||||
/api/v1/auth
|
||||
/api/v1/dashboard
|
||||
/api/v1/users
|
||||
/api/v1/groups
|
||||
/api/v1/roles
|
||||
/api/v1/permissions
|
||||
/api/v1/tenants
|
||||
/api/v1/applications
|
||||
/api/v1/service-accounts
|
||||
/api/v1/tokens
|
||||
/api/v1/sessions
|
||||
/api/v1/audit
|
||||
/api/v1/profile
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Installation
|
||||
|
||||
Clone the repository
|
||||
|
||||
```bash
|
||||
cargo test --all
|
||||
git clone https://github.com/thakares/nx9-auth.git
|
||||
cd nx9-auth
|
||||
```
|
||||
|
||||
Current test coverage includes:
|
||||
Build
|
||||
|
||||
* Unit tests
|
||||
* Integration tests
|
||||
* Security tests
|
||||
* Migration compatibility tests
|
||||
* CLI tests
|
||||
```bash
|
||||
cargo build --release
|
||||
```
|
||||
|
||||
## Roadmap
|
||||
Initialize
|
||||
|
||||
### v0.1.x
|
||||
```bash
|
||||
./target/release/nx9-auth init
|
||||
```
|
||||
|
||||
* Stable IAM core
|
||||
* BZOD integration
|
||||
Configure
|
||||
|
||||
### v0.2.x
|
||||
```bash
|
||||
cp config.example.toml config.toml
|
||||
```
|
||||
|
||||
* OAuth2 Authorization Server
|
||||
* OpenID Connect (OIDC)
|
||||
* PKCE support
|
||||
Run
|
||||
|
||||
## License
|
||||
```bash
|
||||
./target/release/nx9-auth serve
|
||||
```
|
||||
|
||||
Apache 2.0 or MIT -- Dual License
|
||||
The administration interface will be available after startup.
|
||||
|
||||
---
|
||||
|
||||
# CLI
|
||||
|
||||
```
|
||||
nx9-auth init
|
||||
nx9-auth setup
|
||||
nx9-auth migrate
|
||||
nx9-auth serve
|
||||
nx9-auth doctor
|
||||
nx9-auth version
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Configuration
|
||||
|
||||
Configuration is stored in
|
||||
|
||||
```
|
||||
config.toml
|
||||
```
|
||||
|
||||
An example configuration is available in
|
||||
|
||||
```
|
||||
config.example.toml
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Project Layout
|
||||
|
||||
```
|
||||
src/
|
||||
├── api/
|
||||
├── audit/
|
||||
├── cli/
|
||||
├── config/
|
||||
├── db/
|
||||
│ ├── migrations/
|
||||
│ ├── models/
|
||||
│ ├── repository/
|
||||
│ │ ├── sqlite/
|
||||
│ │ ├── postgres/
|
||||
│ │ └── traits.rs
|
||||
│ └── provider.rs
|
||||
├── identity/
|
||||
├── middleware/
|
||||
├── security/
|
||||
├── state.rs
|
||||
└── main.rs
|
||||
|
||||
ui/
|
||||
├── assets/
|
||||
├── components/
|
||||
├── layouts/
|
||||
├── pages/
|
||||
└── services/
|
||||
|
||||
tests/
|
||||
|
||||
docs/
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Security
|
||||
|
||||
Security is a fundamental design goal.
|
||||
|
||||
Implemented protections include:
|
||||
|
||||
- Argon2id password hashing
|
||||
- Secure session management
|
||||
- Secure API tokens
|
||||
- Audit logging
|
||||
- RBAC
|
||||
- Tenant isolation
|
||||
- Security headers
|
||||
- Authorization middleware
|
||||
- Authentication middleware
|
||||
|
||||
Passwords are never stored in plaintext.
|
||||
|
||||
---
|
||||
|
||||
# Development
|
||||
|
||||
Format
|
||||
|
||||
```bash
|
||||
cargo fmt
|
||||
```
|
||||
|
||||
Check
|
||||
|
||||
```bash
|
||||
cargo check
|
||||
```
|
||||
|
||||
Lint
|
||||
|
||||
```bash
|
||||
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
||||
```
|
||||
|
||||
Tests
|
||||
|
||||
```bash
|
||||
cargo test
|
||||
```
|
||||
|
||||
Build UI
|
||||
|
||||
```bash
|
||||
scripts/build-ui.sh
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
# Roadmap
|
||||
|
||||
## Phase 0 ✅
|
||||
|
||||
- Enterprise IAM
|
||||
- SQLite
|
||||
- Web Administration
|
||||
- REST API
|
||||
- RBAC
|
||||
- Multi-tenancy
|
||||
|
||||
---
|
||||
|
||||
## Phase 1
|
||||
|
||||
- PostgreSQL
|
||||
- Database abstraction improvements
|
||||
- Performance tuning
|
||||
|
||||
---
|
||||
|
||||
## Phase 2
|
||||
|
||||
- OAuth2
|
||||
- OpenID Connect
|
||||
- SAML
|
||||
- Multi-factor Authentication
|
||||
- WebAuthn / Passkeys
|
||||
|
||||
---
|
||||
|
||||
## Phase 3
|
||||
|
||||
- Redis
|
||||
- High Availability
|
||||
- Clustering
|
||||
- Distributed Sessions
|
||||
|
||||
---
|
||||
|
||||
## Phase 4
|
||||
|
||||
- LDAP
|
||||
- Active Directory
|
||||
- SCIM
|
||||
- Enterprise Federation
|
||||
|
||||
---
|
||||
|
||||
# Documentation
|
||||
|
||||
Additional documentation is available in the `docs/` directory.
|
||||
|
||||
- Authentication
|
||||
- Deployment
|
||||
- Architecture
|
||||
- API Reference
|
||||
- Development Guide
|
||||
|
||||
---
|
||||
|
||||
# Contributing
|
||||
|
||||
Contributions are welcome.
|
||||
|
||||
Please ensure every contribution:
|
||||
|
||||
```bash
|
||||
cargo fmt
|
||||
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
||||
cargo test
|
||||
```
|
||||
|
||||
passes before opening a pull request.
|
||||
|
||||
---
|
||||
|
||||
# License
|
||||
|
||||
Released under the MIT License.
|
||||
|
||||
See the LICENSE file for details.
|
||||
|
||||
---
|
||||
|
||||
# About NX9
|
||||
|
||||
**nx9-auth** is part of the **NX9** ecosystem.
|
||||
|
||||
NX9 is a collection of self-hosted, privacy-first, Linux-native infrastructure software written entirely in Rust.
|
||||
|
||||
## NX9 Principles
|
||||
|
||||
- Self-hosted First
|
||||
- Privacy First
|
||||
- Linux Native
|
||||
- Pure Rust
|
||||
- Single Binary
|
||||
- Minimal Dependencies
|
||||
- Open Standards
|
||||
- Enterprise Security
|
||||
- FOSS Forever
|
||||
|
||||
---
|
||||
|
||||
<p align="center">
|
||||
|
||||
**Own your infrastructure. Own your identity. Own your data.**
|
||||
|
||||
**No subscriptions. No vendor lock-in. No compromises.**
|
||||
|
||||
</p>
|
||||
Reference in new issue
Block a user