feat: harden runtime lifecycle and application credentials

- enforce deterministic runtime lifecycle state transitions
- add live graceful-to-forced shutdown escalation
- align HTTP draining and worker shutdown with global deadline
- guarantee deterministic shutdown hook ordering
- add secure application client IDs and one-time client secrets
- hash application secrets with BLAKE3 and constant-time verification
- make credential creation and rotation transactionally auditable
- enforce strict client_id authentication and redirect URI validation
- add SQLite and PostgreSQL credential migrations
- add application credential and runtime lifecycle acceptance tests
- update Dioxus application management workflows
- update security and architecture documentation
This commit is contained in:
thakares committed 2026-07-23 15:17:30 +05:30
1 parent 4c697e9adf
commit dc5417334b
26 files changed
+2477 -183

No files matched your search

+47 -7
View File
@@ -2,36 +2,76 @@
use tokio_util::sync::CancellationToken;
/// Dual-token shutdown coordinator that supports graceful termination
/// (1st signal) and live forced escalation (2nd signal).
#[derive(Clone)]
pub struct ShutdownCoordinator {
root: CancellationToken,
graceful: CancellationToken,
forced: CancellationToken,
}
impl ShutdownCoordinator {
pub fn new() -> Self {
Self {
root: CancellationToken::new(),
graceful: CancellationToken::new(),
forced: CancellationToken::new(),
}
}
/// Access the primary graceful cancellation token.
pub fn token(&self) -> &CancellationToken {
&self.root
&self.graceful
}
/// Access the forced cancellation token.
pub fn forced_token(&self) -> &CancellationToken {
&self.forced
}
/// Create a child token linked to graceful cancellation.
pub fn child_token(&self) -> CancellationToken {
self.root.child_token()
self.graceful.child_token()
}
/// Trigger graceful shutdown.
pub fn cancel(&self) {
self.root.cancel();
self.graceful.cancel();
}
/// Trigger graceful shutdown explicitly.
pub fn cancel_graceful(&self) {
self.graceful.cancel();
}
/// Trigger forced shutdown escalation live.
pub fn cancel_forced(&self) {
self.graceful.cancel();
self.forced.cancel();
}
/// Check if graceful shutdown has been initiated.
pub fn is_cancelled(&self) -> bool {
self.root.is_cancelled()
self.graceful.is_cancelled()
}
/// Check if forced escalation has been triggered.
pub fn is_forced(&self) -> bool {
self.forced.is_cancelled()
}
/// Await graceful cancellation.
pub async fn cancelled(&self) {
self.root.cancelled().await;
self.graceful.cancelled().await;
}
/// Await graceful cancellation explicitly.
pub async fn graceful_cancelled(&self) {
self.graceful.cancelled().await;
}
/// Await forced escalation live.
pub async fn forced_cancelled(&self) {
self.forced.cancelled().await;
}
}