README: Updated to v0.2.0, with UI/UX implementation, phase 0
This commit is contained in:
1 parent
7b7797cf7f
commit
ce3bff5097
3 files changed
+453
-133
No files matched your search
Generated
+1
-1
@@ -1251,7 +1251,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "nx9-auth"
|
name = "nx9-auth"
|
||||||
version = "0.1.0"
|
version = "0.2.0"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"argon2",
|
"argon2",
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "nx9-auth"
|
name = "nx9-auth"
|
||||||
version = "0.1.0"
|
version = "0.2.0"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
rust-version = "1.85"
|
rust-version = "1.85"
|
||||||
authors = ["NX9 Team","Sunil Thakare"]
|
authors = ["NX9 Team","Sunil Thakare"]
|
||||||
|
|||||||
@@ -1,183 +1,503 @@
|
|||||||
# nx9-auth
|
# nx9-auth
|
||||||
|
|
||||||
A lightweight Identity and Access Management (IAM) service.
|
<p align="center">
|
||||||
|
|
||||||
Built with Rust, Axum, SQLite, and modern security practices, `nx9-auth` provides authentication, authorization, session management, personal access tokens, audit logging, and role-based access control in a single deployable binary.
|
**Enterprise Identity & Access Management (IAM)**
|
||||||
|
|
||||||
## Features
|
*Self-Hosted • Privacy-First • Pure Rust • Single Binary • Linux Native*
|
||||||
|
|
||||||
* User management
|
[]()
|
||||||
* Role-Based Access Control (RBAC)
|
[](https://www.rust-lang.org/)
|
||||||
* Session authentication
|
[](LICENSE)
|
||||||
* Personal Access Tokens (PAT)
|
[]()
|
||||||
* Audit logging
|
[]()
|
||||||
* Transaction-safe operations
|
[]()
|
||||||
* SQLite with WAL mode
|
|
||||||
* Online backups
|
|
||||||
* Interactive initialization
|
|
||||||
* Docker and CasaOS support
|
|
||||||
* Systemd deployment support
|
|
||||||
* XDG-compliant user mode
|
|
||||||
* **Dioxus enterprise web UI** (single binary, no Node.js)
|
|
||||||
|
|
||||||
## Quick Start
|
</p>
|
||||||
|
|
||||||
Initialize a new installation:
|
---
|
||||||
|
|
||||||
```bash
|
## Overview
|
||||||
nx9-auth init
|
|
||||||
```
|
|
||||||
|
|
||||||
Start the server:
|
**nx9-auth** is a modern, enterprise-grade Identity & Access Management (IAM) platform built entirely in Rust.
|
||||||
|
|
||||||
```bash
|
It provides centralized authentication, authorization, user administration, multi-tenancy, session management, audit logging and administrative tools in a single deployable application.
|
||||||
nx9-auth serve
|
|
||||||
```
|
|
||||||
|
|
||||||
Verify health:
|
Unlike traditional IAM platforms that require multiple services, Java application servers, Redis, PostgreSQL, Kubernetes and extensive operational overhead, **nx9-auth** is intentionally designed around simplicity, security and complete ownership.
|
||||||
|
|
||||||
```bash
|
Current release **v0.2.0** delivers a production-quality Phase 0 implementation using SQLite with a modern Dioxus WebAssembly administration interface.
|
||||||
curl http://127.0.0.1:8655/health
|
|
||||||
```
|
|
||||||
|
|
||||||
Open the UI in a browser:
|
---
|
||||||
|
|
||||||
```text
|
# Why nx9-auth?
|
||||||
http://127.0.0.1:8655/
|
|
||||||
```
|
|
||||||
|
|
||||||
## Authentication
|
Modern identity platforms are often:
|
||||||
|
|
||||||
Login is **POST-only** with a JSON body (never query parameters):
|
- Complex
|
||||||
|
- Heavyweight
|
||||||
|
- Cloud dependent
|
||||||
|
- Expensive
|
||||||
|
- Difficult to self-host
|
||||||
|
|
||||||
```bash
|
nx9-auth follows a different philosophy.
|
||||||
curl -sS -X POST http://127.0.0.1:8655/api/v1/auth/login \
|
|
||||||
-H 'Content-Type: application/json' \
|
|
||||||
-d '{"username":"admin","password":"your-password"}'
|
|
||||||
```
|
|
||||||
|
|
||||||
Passwords are verified with **Argon2id** and never logged or stored in plaintext.
|
### Design Goals
|
||||||
See [docs/AUTHENTICATION.md](docs/AUTHENTICATION.md) for the full security model.
|
|
||||||
|
|
||||||
## Web UI
|
- Self-hosted first
|
||||||
|
- Privacy first
|
||||||
|
- Linux native
|
||||||
|
- Pure Rust
|
||||||
|
- Single executable
|
||||||
|
- Minimal dependencies
|
||||||
|
- Enterprise security
|
||||||
|
- Zero vendor lock-in
|
||||||
|
- Open source forever
|
||||||
|
|
||||||
The management UI is implemented in pure Rust with **Dioxus** (no React/Vue/Node).
|
---
|
||||||
It is served from the same process as the REST API.
|
|
||||||
|
|
||||||
### Build UI assets
|
# Features
|
||||||
|
|
||||||
```bash
|
## Identity
|
||||||
./scripts/build-ui.sh
|
|
||||||
```
|
|
||||||
|
|
||||||
This compiles `ui/` to WebAssembly and writes static files to `ui/dist/`.
|
- User Management
|
||||||
The server serves those files automatically (override path with `NX9_AUTH_UI_DIST`).
|
- User Profiles
|
||||||
|
- Password Authentication
|
||||||
|
- Password Reset
|
||||||
|
- Account Locking
|
||||||
|
- Profile Management
|
||||||
|
|
||||||
### UI features
|
---
|
||||||
|
|
||||||
* Login / logout with session restoration
|
## Authorization
|
||||||
* Permission-aware sidebar and routing
|
|
||||||
* User, role, permission, token, application, and service-account management
|
|
||||||
* Audit log viewer with filters
|
|
||||||
* Profile and settings (theme: light / dark / system)
|
|
||||||
* Responsive enterprise shell (header, sidebar, breadcrumbs, toasts)
|
|
||||||
|
|
||||||
Frontend RBAC is presentation-only; the backend remains authoritative.
|
- Role Based Access Control (RBAC)
|
||||||
|
- Permissions
|
||||||
|
- Multiple Roles per User
|
||||||
|
- Fine-grained Authorization
|
||||||
|
- Authorization Middleware
|
||||||
|
|
||||||
## CLI Commands
|
---
|
||||||
|
|
||||||
```bash
|
## Multi-Tenancy
|
||||||
nx9-auth init
|
|
||||||
nx9-auth serve
|
|
||||||
nx9-auth doctor
|
|
||||||
|
|
||||||
nx9-auth create-user
|
- Tenant Management
|
||||||
nx9-auth create-admin
|
- Tenant Isolation
|
||||||
|
- Tenant Administration
|
||||||
|
|
||||||
nx9-auth create-token
|
---
|
||||||
nx9-auth revoke-token
|
|
||||||
|
|
||||||
nx9-auth show-user
|
## Organization
|
||||||
nx9-auth show-token
|
|
||||||
|
|
||||||
nx9-auth backup
|
- Groups
|
||||||
```
|
- Applications
|
||||||
|
- Service Accounts
|
||||||
|
|
||||||
## Deployment Modes
|
---
|
||||||
|
|
||||||
### User Mode
|
|
||||||
|
|
||||||
Uses XDG directories:
|
|
||||||
|
|
||||||
```text
|
|
||||||
~/.config/nx9-auth/
|
|
||||||
~/.local/share/nx9-auth/
|
|
||||||
~/.local/state/nx9-auth/
|
|
||||||
```
|
|
||||||
|
|
||||||
### System Mode
|
|
||||||
|
|
||||||
```text
|
|
||||||
/etc/nx9-auth/
|
|
||||||
/var/lib/nx9-auth/
|
|
||||||
/var/log/nx9-auth/
|
|
||||||
```
|
|
||||||
|
|
||||||
### Docker
|
|
||||||
|
|
||||||
```bash
|
|
||||||
docker compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
### CasaOS
|
|
||||||
|
|
||||||
```text
|
|
||||||
/DATA/AppData/nx9-auth
|
|
||||||
├── config
|
|
||||||
├── db
|
|
||||||
├── state
|
|
||||||
└── backups
|
|
||||||
```
|
|
||||||
|
|
||||||
## Security
|
## Security
|
||||||
|
|
||||||
* Argon2id password hashing
|
- Secure Sessions
|
||||||
* BLAKE3 token hashing
|
- API Tokens
|
||||||
* Session revocation
|
- Secure Authentication
|
||||||
* Transactional audit logging
|
- Security Headers
|
||||||
* Timing attack mitigation
|
- Audit Logging
|
||||||
* Security regression test suite
|
- Password Hashing (Argon2id)
|
||||||
|
- Cookie Authentication
|
||||||
|
|
||||||
## Testing
|
---
|
||||||
|
|
||||||
|
## Administration
|
||||||
|
|
||||||
|
- Dashboard
|
||||||
|
- User Administration
|
||||||
|
- Group Administration
|
||||||
|
- Role Administration
|
||||||
|
- Permission Administration
|
||||||
|
- Session Administration
|
||||||
|
- Application Administration
|
||||||
|
- Service Account Administration
|
||||||
|
- Tenant Administration
|
||||||
|
- Audit Viewer
|
||||||
|
- Profile Settings
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## User Interface
|
||||||
|
|
||||||
|
- Dioxus WebAssembly UI
|
||||||
|
- Responsive Design
|
||||||
|
- Enterprise Dashboard
|
||||||
|
- Modern Navigation
|
||||||
|
- Dark Theme
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Screenshots
|
||||||
|
|
||||||
|
*(Coming with future releases)*
|
||||||
|
|
||||||
|
- Login
|
||||||
|
- Dashboard
|
||||||
|
- Users
|
||||||
|
- Roles
|
||||||
|
- Permissions
|
||||||
|
- Audit Log
|
||||||
|
- Sessions
|
||||||
|
- Applications
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Architecture
|
||||||
|
|
||||||
|
```
|
||||||
|
Browser
|
||||||
|
│
|
||||||
|
Dioxus WebAssembly
|
||||||
|
│
|
||||||
|
Axum HTTP Server
|
||||||
|
│
|
||||||
|
Authentication Layer
|
||||||
|
│
|
||||||
|
Authorization Layer
|
||||||
|
│
|
||||||
|
REST API Layer
|
||||||
|
│
|
||||||
|
Database Provider API
|
||||||
|
│
|
||||||
|
SQLite Repository Layer
|
||||||
|
│
|
||||||
|
SQLite Database
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Technology Stack
|
||||||
|
|
||||||
|
| Component | Technology |
|
||||||
|
|------------|------------|
|
||||||
|
| Language | Rust 2021 |
|
||||||
|
| Backend | Axum |
|
||||||
|
| Frontend | Dioxus |
|
||||||
|
| UI Runtime | WebAssembly |
|
||||||
|
| Async Runtime | Tokio |
|
||||||
|
| Database | SQLite |
|
||||||
|
| SQL Layer | SQLx |
|
||||||
|
| Serialization | Serde |
|
||||||
|
| Password Hashing | Argon2id |
|
||||||
|
| Configuration | TOML |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Current Capabilities
|
||||||
|
|
||||||
|
| Module | Status |
|
||||||
|
|----------|--------|
|
||||||
|
| Dashboard | ✅ |
|
||||||
|
| Authentication | ✅ |
|
||||||
|
| Users | ✅ |
|
||||||
|
| Roles | ✅ |
|
||||||
|
| Permissions | ✅ |
|
||||||
|
| Groups | ✅ |
|
||||||
|
| Tenants | ✅ |
|
||||||
|
| Applications | ✅ |
|
||||||
|
| Sessions | ✅ |
|
||||||
|
| API Tokens | ✅ |
|
||||||
|
| Service Accounts | ✅ |
|
||||||
|
| Audit Logs | ✅ |
|
||||||
|
| Profile | ✅ |
|
||||||
|
| SQLite | ✅ |
|
||||||
|
| PostgreSQL | 🚧 |
|
||||||
|
| OAuth2 | 🚧 |
|
||||||
|
| OIDC | 🚧 |
|
||||||
|
| SAML | 🚧 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# REST API
|
||||||
|
|
||||||
|
```
|
||||||
|
/api/v1/auth
|
||||||
|
/api/v1/dashboard
|
||||||
|
/api/v1/users
|
||||||
|
/api/v1/groups
|
||||||
|
/api/v1/roles
|
||||||
|
/api/v1/permissions
|
||||||
|
/api/v1/tenants
|
||||||
|
/api/v1/applications
|
||||||
|
/api/v1/service-accounts
|
||||||
|
/api/v1/tokens
|
||||||
|
/api/v1/sessions
|
||||||
|
/api/v1/audit
|
||||||
|
/api/v1/profile
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Installation
|
||||||
|
|
||||||
|
Clone the repository
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cargo test --all
|
git clone https://github.com/thakares/nx9-auth.git
|
||||||
|
cd nx9-auth
|
||||||
```
|
```
|
||||||
|
|
||||||
Current test coverage includes:
|
Build
|
||||||
|
|
||||||
* Unit tests
|
```bash
|
||||||
* Integration tests
|
cargo build --release
|
||||||
* Security tests
|
```
|
||||||
* Migration compatibility tests
|
|
||||||
* CLI tests
|
|
||||||
|
|
||||||
## Roadmap
|
Initialize
|
||||||
|
|
||||||
### v0.1.x
|
```bash
|
||||||
|
./target/release/nx9-auth init
|
||||||
|
```
|
||||||
|
|
||||||
* Stable IAM core
|
Configure
|
||||||
* BZOD integration
|
|
||||||
|
|
||||||
### v0.2.x
|
```bash
|
||||||
|
cp config.example.toml config.toml
|
||||||
|
```
|
||||||
|
|
||||||
* OAuth2 Authorization Server
|
Run
|
||||||
* OpenID Connect (OIDC)
|
|
||||||
* PKCE support
|
|
||||||
|
|
||||||
## License
|
```bash
|
||||||
|
./target/release/nx9-auth serve
|
||||||
|
```
|
||||||
|
|
||||||
Apache 2.0 or MIT -- Dual License
|
The administration interface will be available after startup.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# CLI
|
||||||
|
|
||||||
```
|
```
|
||||||
|
nx9-auth init
|
||||||
|
nx9-auth setup
|
||||||
|
nx9-auth migrate
|
||||||
|
nx9-auth serve
|
||||||
|
nx9-auth doctor
|
||||||
|
nx9-auth version
|
||||||
```
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Configuration
|
||||||
|
|
||||||
|
Configuration is stored in
|
||||||
|
|
||||||
|
```
|
||||||
|
config.toml
|
||||||
|
```
|
||||||
|
|
||||||
|
An example configuration is available in
|
||||||
|
|
||||||
|
```
|
||||||
|
config.example.toml
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Project Layout
|
||||||
|
|
||||||
|
```
|
||||||
|
src/
|
||||||
|
├── api/
|
||||||
|
├── audit/
|
||||||
|
├── cli/
|
||||||
|
├── config/
|
||||||
|
├── db/
|
||||||
|
│ ├── migrations/
|
||||||
|
│ ├── models/
|
||||||
|
│ ├── repository/
|
||||||
|
│ │ ├── sqlite/
|
||||||
|
│ │ ├── postgres/
|
||||||
|
│ │ └── traits.rs
|
||||||
|
│ └── provider.rs
|
||||||
|
├── identity/
|
||||||
|
├── middleware/
|
||||||
|
├── security/
|
||||||
|
├── state.rs
|
||||||
|
└── main.rs
|
||||||
|
|
||||||
|
ui/
|
||||||
|
├── assets/
|
||||||
|
├── components/
|
||||||
|
├── layouts/
|
||||||
|
├── pages/
|
||||||
|
└── services/
|
||||||
|
|
||||||
|
tests/
|
||||||
|
|
||||||
|
docs/
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Security
|
||||||
|
|
||||||
|
Security is a fundamental design goal.
|
||||||
|
|
||||||
|
Implemented protections include:
|
||||||
|
|
||||||
|
- Argon2id password hashing
|
||||||
|
- Secure session management
|
||||||
|
- Secure API tokens
|
||||||
|
- Audit logging
|
||||||
|
- RBAC
|
||||||
|
- Tenant isolation
|
||||||
|
- Security headers
|
||||||
|
- Authorization middleware
|
||||||
|
- Authentication middleware
|
||||||
|
|
||||||
|
Passwords are never stored in plaintext.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Development
|
||||||
|
|
||||||
|
Format
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo fmt
|
||||||
|
```
|
||||||
|
|
||||||
|
Check
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo check
|
||||||
|
```
|
||||||
|
|
||||||
|
Lint
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
||||||
|
```
|
||||||
|
|
||||||
|
Tests
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo test
|
||||||
|
```
|
||||||
|
|
||||||
|
Build UI
|
||||||
|
|
||||||
|
```bash
|
||||||
|
scripts/build-ui.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Roadmap
|
||||||
|
|
||||||
|
## Phase 0 ✅
|
||||||
|
|
||||||
|
- Enterprise IAM
|
||||||
|
- SQLite
|
||||||
|
- Web Administration
|
||||||
|
- REST API
|
||||||
|
- RBAC
|
||||||
|
- Multi-tenancy
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 1
|
||||||
|
|
||||||
|
- PostgreSQL
|
||||||
|
- Database abstraction improvements
|
||||||
|
- Performance tuning
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 2
|
||||||
|
|
||||||
|
- OAuth2
|
||||||
|
- OpenID Connect
|
||||||
|
- SAML
|
||||||
|
- Multi-factor Authentication
|
||||||
|
- WebAuthn / Passkeys
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 3
|
||||||
|
|
||||||
|
- Redis
|
||||||
|
- High Availability
|
||||||
|
- Clustering
|
||||||
|
- Distributed Sessions
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 4
|
||||||
|
|
||||||
|
- LDAP
|
||||||
|
- Active Directory
|
||||||
|
- SCIM
|
||||||
|
- Enterprise Federation
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Documentation
|
||||||
|
|
||||||
|
Additional documentation is available in the `docs/` directory.
|
||||||
|
|
||||||
|
- Authentication
|
||||||
|
- Deployment
|
||||||
|
- Architecture
|
||||||
|
- API Reference
|
||||||
|
- Development Guide
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Contributing
|
||||||
|
|
||||||
|
Contributions are welcome.
|
||||||
|
|
||||||
|
Please ensure every contribution:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cargo fmt
|
||||||
|
cargo clippy --workspace --all-targets --all-features -- -D warnings
|
||||||
|
cargo test
|
||||||
|
```
|
||||||
|
|
||||||
|
passes before opening a pull request.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# License
|
||||||
|
|
||||||
|
Released under the MIT License.
|
||||||
|
|
||||||
|
See the LICENSE file for details.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# About NX9
|
||||||
|
|
||||||
|
**nx9-auth** is part of the **NX9** ecosystem.
|
||||||
|
|
||||||
|
NX9 is a collection of self-hosted, privacy-first, Linux-native infrastructure software written entirely in Rust.
|
||||||
|
|
||||||
|
## NX9 Principles
|
||||||
|
|
||||||
|
- Self-hosted First
|
||||||
|
- Privacy First
|
||||||
|
- Linux Native
|
||||||
|
- Pure Rust
|
||||||
|
- Single Binary
|
||||||
|
- Minimal Dependencies
|
||||||
|
- Open Standards
|
||||||
|
- Enterprise Security
|
||||||
|
- FOSS Forever
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<p align="center">
|
||||||
|
|
||||||
|
**Own your infrastructure. Own your identity. Own your data.**
|
||||||
|
|
||||||
|
**No subscriptions. No vendor lock-in. No compromises.**
|
||||||
|
|
||||||
|
</p>
|
||||||
Reference in new issue
Block a user