Compare commits
	
		
			38 Commits
		
	
	
		
			v0.3.0-dev
			...
			v0.6.1
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 7e44d523f2 | |||
| 59d0ca0c0b | |||
| a02b15c65c | |||
| ebe29df991 | |||
| 473b4ec762 | |||
| a66ab7826c | |||
| 9da068252d | |||
| 2ba037c393 | |||
| a4c943189c | |||
| eb1e2990f9 | |||
| 99390ce8b7 | |||
| 5967ed5b13 | |||
| be4d1109a7 | |||
| 4353414c69 | |||
| c176d0fcf3 | |||
| c8b8d470dc | |||
| bcd0e607ef | |||
| 70de6b862f | |||
| 8c902b9d61 | |||
| 480a428e8b | |||
| 02697b2fd9 | |||
| d4faa7976e | |||
| ed77cab700 | |||
| 2c30abb5c6 | |||
| 1817ab01d6 | |||
| 31be156be3 | |||
| fc6b66f2e6 | |||
| eb7e394cf0 | |||
| 6dec9942cc | |||
| a855db9ecc | |||
| 17af1a00c0 | |||
| 50e735e1a9 | |||
| f6cf968f86 | |||
| 70a547ca94 | |||
| 89c89a5524 | |||
| f601442f0e | |||
| 2229d98ab6 | |||
| 88f45645b3 | 
							
								
								
									
										21
									
								
								.dockerignore.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										21
									
								
								.dockerignore.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,21 @@ | |||||||
|  | # Ignore build artifacts | ||||||
|  | target/ | ||||||
|  | pkg/ | ||||||
|  |  | ||||||
|  | # Ignore git directory | ||||||
|  | .git/ | ||||||
|  |  | ||||||
|  | .gitea/ | ||||||
|  |  | ||||||
|  | # Ignore environment files (configure via docker-compose instead) | ||||||
|  | .env* | ||||||
|  |  | ||||||
|  | # Ignore IDE/editor specific files | ||||||
|  | .idea/ | ||||||
|  | .vscode/ | ||||||
|  |  | ||||||
|  | # Ignore OS specific files | ||||||
|  | *.DS_Store | ||||||
|  |  | ||||||
|  | # Add any other files/directories you don't need in the image | ||||||
|  | # e.g., logs/, tmp/ | ||||||
							
								
								
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								.env.docker.sample
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,12 @@ | |||||||
|  | APP_ENV=development | ||||||
|  | BACKEND_PORT=8001 | ||||||
|  | FRONTEND_URL=http://localhost:4200 | ||||||
|  | RUST_LOG=debug | ||||||
|  | ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||||
|  | SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||||
|  | SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||||
|  | POSTGRES_AUTH_USER=icarus_op | ||||||
|  | POSTGRES_AUTH_PASSWORD=password | ||||||
|  | POSTGRES_AUTH_DB=icarus_auth_db | ||||||
|  | POSTGRES_AUTH_HOST=auth_db | ||||||
|  | DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||||
							
								
								
									
										12
									
								
								.env.sample
									
									
									
									
									
								
							
							
						
						
									
										12
									
								
								.env.sample
									
									
									
									
									
								
							| @@ -1,2 +1,12 @@ | |||||||
| DATABASE_URL=postgres://username:password@localhost/database_name | APP_ENV=development | ||||||
|  | BACKEND_PORT=8001 | ||||||
|  | FRONTEND_URL=http://localhost:4200 | ||||||
|  | RUST_LOG=debug | ||||||
|  | ALLOWED_ORIGINS=https://soaricarus.com,https://www.soaricarus.com | ||||||
| SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | SECRET_KEY=refero34o8rfhfjn983thf39fhc943rf923n3h | ||||||
|  | SERVICE_PASSPHRASE=iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH | ||||||
|  | POSTGRES_AUTH_USER=icarus_op_test | ||||||
|  | POSTGRES_AUTH_PASSWORD=password | ||||||
|  | POSTGRES_AUTH_DB=icarus_auth_test_db | ||||||
|  | POSTGRES_AUTH_HOST=localhost | ||||||
|  | DATABASE_URL=postgresql://${POSTGRES_AUTH_USER}:${POSTGRES_AUTH_PASSWORD}@${POSTGRES_AUTH_HOST}:5432/${POSTGRES_AUTH_DB} | ||||||
|   | |||||||
| @@ -3,23 +3,21 @@ name: Release Tagging | |||||||
| on: | on: | ||||||
|   push: |   push: | ||||||
|     branches: |     branches: | ||||||
|       - devel |       - main | ||||||
|     tags: |  | ||||||
|       - 'v*' # Trigger on tags matching v* |  | ||||||
|  |  | ||||||
| jobs: | jobs: | ||||||
|   release: |   release: | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - name: Checkout code |       - name: Checkout code | ||||||
|         uses: actions/checkout@v3 |         uses: actions/checkout@v5 | ||||||
|         with: |         with: | ||||||
|           fetch-depth: 0 # Important for git describe --tags |           fetch-depth: 0 # Important for git describe --tags | ||||||
|  |  | ||||||
|       - name: Install Rust |       - name: Install Rust | ||||||
|         uses: actions-rs/toolchain@v1 |         uses: actions-rs/toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|           components: cargo |           components: cargo | ||||||
|  |  | ||||||
|       - name: Extract Version from Cargo.toml |       - name: Extract Version from Cargo.toml | ||||||
| @@ -29,8 +27,10 @@ jobs: | |||||||
|           PROJECT_COMMIT_HASH=$(git rev-parse HEAD | cut -c 1-10) |           PROJECT_COMMIT_HASH=$(git rev-parse HEAD | cut -c 1-10) | ||||||
|           BRANCH_REF="${GITHUB_REF}" |           BRANCH_REF="${GITHUB_REF}" | ||||||
|           BRANCH_NAME=$(echo "$BRANCH_REF" | cut -d '/' -f 3) |           BRANCH_NAME=$(echo "$BRANCH_REF" | cut -d '/' -f 3) | ||||||
|           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH" |           PROJECT_TAG_RELEASE="v$VERSION-$BRANCH_NAME-$PROJECT_COMMIT_HASH-950" | ||||||
|           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE-950" |  | ||||||
|  |           echo "::set-output name=project_tag_release::$PROJECT_TAG_RELEASE" | ||||||
|  |  | ||||||
|           echo "Version: $VERSION" |           echo "Version: $VERSION" | ||||||
|           echo "Hash: $PROJECT_COMMIT_HASH" |           echo "Hash: $PROJECT_COMMIT_HASH" | ||||||
|           echo "Branch: $BRANCH_NAME" |           echo "Branch: $BRANCH_NAME" | ||||||
| @@ -51,7 +51,3 @@ jobs: | |||||||
|           release_name: Release ${{ steps.version.outputs.project_tag_release }} |           release_name: Release ${{ steps.version.outputs.project_tag_release }} | ||||||
|           body: | |           body: | | ||||||
|            Release of version ${{ steps.version.outputs.project_tag_release }} |            Release of version ${{ steps.version.outputs.project_tag_release }} | ||||||
|           # draft: false |  | ||||||
|           # prerelease: ${{ startsWith(github.ref, 'v') == false }} # prerelease if not a valid release tag |  | ||||||
|  |  | ||||||
|  |  | ||||||
|   | |||||||
| @@ -15,10 +15,10 @@ jobs: | |||||||
|     name: Check |     name: Check | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key |           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||||
| @@ -36,7 +36,7 @@ jobs: | |||||||
|     # --- Add database service definition --- |     # --- Add database service definition --- | ||||||
|     services: |     services: | ||||||
|       postgres: |       postgres: | ||||||
|         image: postgres:17.4 # Or pin to a more specific version like 14.9 |         image: postgres:17.5 | ||||||
|         env: |         env: | ||||||
|           # Use secrets for DB init, with fallbacks for flexibility |           # Use secrets for DB init, with fallbacks for flexibility | ||||||
|           POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} |           POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} | ||||||
| @@ -50,10 +50,10 @@ jobs: | |||||||
|           --health-retries 5 |           --health-retries 5 | ||||||
|  |  | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       # --- Add this step for explicit verification --- |       # --- Add this step for explicit verification --- | ||||||
|       - name: Verify Docker Environment |       - name: Verify Docker Environment | ||||||
|         run: | |         run: | | ||||||
| @@ -91,10 +91,10 @@ jobs: | |||||||
|     name: Rustfmt |     name: Rustfmt | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: rustup component add rustfmt |       - run: rustup component add rustfmt | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
| @@ -110,10 +110,10 @@ jobs: | |||||||
|     name: Clippy |     name: Clippy | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: rustup component add clippy |       - run: rustup component add clippy | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
| @@ -129,10 +129,10 @@ jobs: | |||||||
|     name: build |     name: build | ||||||
|     runs-on: ubuntu-24.04 |     runs-on: ubuntu-24.04 | ||||||
|     steps: |     steps: | ||||||
|       - uses: actions/checkout@v4 |       - uses: actions/checkout@v5 | ||||||
|       - uses: actions-rust-lang/setup-rust-toolchain@v1 |       - uses: actions-rust-lang/setup-rust-toolchain@v1 | ||||||
|         with: |         with: | ||||||
|           toolchain: 1.86.0 |           toolchain: 1.90.0 | ||||||
|       - run: | |       - run: | | ||||||
|           mkdir -p ~/.ssh |           mkdir -p ~/.ssh | ||||||
|           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key |           echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key | ||||||
|   | |||||||
							
								
								
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,3 +1,4 @@ | |||||||
| /target | /target | ||||||
| Cargo.lock |  | ||||||
| .env | .env | ||||||
|  | .env.local | ||||||
|  | .env.docker | ||||||
|   | |||||||
							
								
								
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
							
						
						
									
										2865
									
								
								Cargo.lock
									
									
									
										generated
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										37
									
								
								Cargo.toml
									
									
									
									
									
								
							
							
						
						
									
										37
									
								
								Cargo.toml
									
									
									
									
									
								
							| @@ -1,27 +1,30 @@ | |||||||
| [package] | [package] | ||||||
| name = "icarus_auth" | name = "icarus_auth" | ||||||
| version = "0.3.0" | version = "0.6.1" | ||||||
| edition = "2024" | edition = "2024" | ||||||
| rust-version = "1.86" | rust-version = "1.90" | ||||||
|  |  | ||||||
| [dependencies] | [dependencies] | ||||||
| axum = { version = "0.8.3" } | axum = { version = "0.8.6" } | ||||||
| serde = { version = "1.0.218", features = ["derive"] } | serde = { version = "1.0.228", features = ["derive"] } | ||||||
| serde_json = { version = "1.0.139" } | serde_json = { version = "1.0.145" } | ||||||
| tokio = { version = "1.44.1", features = ["rt-multi-thread"] } | tokio = { version = "1.47.1", features = ["rt-multi-thread"] } | ||||||
| tracing-subscriber = { version = "0.3.19" } | tracing-subscriber = { version = "0.3.20" } | ||||||
| tower = { version = "0.5.2" } | tower = { version = "0.5.2", features = ["full"] } | ||||||
| hyper = { version = "1.6.0" } | tower-http = { version = "0.6.6", features = ["cors"] } | ||||||
| sqlx = { version = "0.8.3", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | hyper = { version = "1.7.0" } | ||||||
| dotenvy = { version = "0.15.7" } | sqlx = { version = "0.8.6", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } | ||||||
| uuid = { version = "1.16.0", features = ["v4", "serde"] } | uuid = { version = "1.18.1", features = ["v4", "serde"] } | ||||||
| argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version | argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version | ||||||
| rand = { version = "0.9" } | rand = { version = "0.9.2" } | ||||||
| time = { version = "0.3.41", features = ["macros", "serde"] } | time = { version = "0.3.41", features = ["macros", "serde"] } | ||||||
| josekit = { version = "0.10.1" } | josekit = { version = "0.10.3" } | ||||||
| icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.4.1" } | utoipa = { version = "5.4.0", features = ["axum_extras"] } | ||||||
|  | utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] } | ||||||
|  | icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.8.0" } | ||||||
|  | icarus_envy = { git = "ssh://git@git.kundeng.us/phoenix/icarus_envy.git", tag = "v0.5.0" } | ||||||
|  |  | ||||||
| [dev-dependencies] | [dev-dependencies] | ||||||
| http-body-util = { version = "0.1.3" } | http-body-util = { version = "0.1.3" } | ||||||
| url = { version = "2.5" } | url = { version = "2.5.7" } | ||||||
| once_cell = { version = "1.19" } # Useful for lazy initialization in tests/app setup | once_cell = { version = "1.21.3" } # Useful for lazy initialization in tests/app setup | ||||||
|   | |||||||
							
								
								
									
										71
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										71
									
								
								Dockerfile
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,71 @@ | |||||||
|  | # Stage 1: Build the application | ||||||
|  | # Use a specific Rust version for reproducibility. Choose one that matches your development environment. | ||||||
|  | # Using slim variant for smaller base image | ||||||
|  | FROM rust:1.90 as builder | ||||||
|  |  | ||||||
|  | # Set the working directory inside the container | ||||||
|  | WORKDIR /usr/src/app | ||||||
|  |  | ||||||
|  | # Install build dependencies if needed (e.g., for certain crates like sqlx with native TLS) | ||||||
|  | # RUN apt-get update && apt-get install -y pkg-config libssl-dev | ||||||
|  |  | ||||||
|  | # Install build dependencies if needed (e.g., git for cloning) | ||||||
|  | RUN apt-get update && apt-get install -y --no-install-recommends \ | ||||||
|  |     pkg-config libssl3 \ | ||||||
|  |     ca-certificates \ | ||||||
|  |     openssh-client git \ | ||||||
|  |     && rm -rf /var/lib/apt/lists/* | ||||||
|  |  | ||||||
|  | # << --- ADD HOST KEY HERE --- >> | ||||||
|  | # Replace 'yourgithost.com' with the actual hostname (e.g., github.com) | ||||||
|  | RUN mkdir -p -m 0700 ~/.ssh && \ | ||||||
|  |     ssh-keyscan git.kundeng.us >> ~/.ssh/known_hosts | ||||||
|  |  | ||||||
|  | # Copy Cargo manifests | ||||||
|  | COPY Cargo.toml Cargo.lock ./ | ||||||
|  |  | ||||||
|  | # Build *only* dependencies to leverage Docker cache | ||||||
|  | # This dummy build caches dependencies as a separate layer | ||||||
|  | RUN --mount=type=ssh mkdir src && \ | ||||||
|  |     echo "fn main() {println!(\"if you see this, the build broke\")}" > src/main.rs && \ | ||||||
|  |     cargo build --release --quiet && \ | ||||||
|  |     rm -rf src target/release/deps/icarus_auth* # Clean up dummy build artifacts (replace icarus_auth) | ||||||
|  |  | ||||||
|  | # Copy the actual source code | ||||||
|  | COPY src ./src | ||||||
|  | # If you have other directories like `templates` or `static`, copy them too | ||||||
|  | COPY .env ./.env | ||||||
|  | COPY migrations ./migrations | ||||||
|  |  | ||||||
|  | # << --- SSH MOUNT ADDED HERE --- >> | ||||||
|  | # Build *only* dependencies to leverage Docker cache | ||||||
|  | # This dummy build caches dependencies as a separate layer | ||||||
|  | # Mount the SSH agent socket for this command | ||||||
|  | RUN --mount=type=ssh \ | ||||||
|  |     cargo build --release --quiet | ||||||
|  |  | ||||||
|  | # Stage 2: Create the final, smaller runtime image | ||||||
|  | # Use a minimal base image like debian-slim or even distroless for security/size | ||||||
|  | FROM ubuntu:24.04 | ||||||
|  |  | ||||||
|  | # Install runtime dependencies if needed (e.g., SSL certificates) | ||||||
|  | RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/* | ||||||
|  |  | ||||||
|  | # Set the working directory | ||||||
|  | WORKDIR /usr/local/bin | ||||||
|  |  | ||||||
|  | # Copy the compiled binary from the builder stage | ||||||
|  | # Replace 'icarus_auth' with the actual name of your binary (usually the crate name) | ||||||
|  | COPY --from=builder /usr/src/app/target/release/icarus_auth . | ||||||
|  |  | ||||||
|  | # Copy other necessary files like .env (if used for runtime config) or static assets | ||||||
|  | # It's generally better to configure via environment variables in Docker though | ||||||
|  | COPY --from=builder /usr/src/app/.env . | ||||||
|  | COPY --from=builder /usr/src/app/migrations ./migrations | ||||||
|  |  | ||||||
|  | # Expose the port your Axum app listens on (e.g., 3000 or 8000) | ||||||
|  | EXPOSE 3000 | ||||||
|  |  | ||||||
|  | # Set the command to run your application | ||||||
|  | # Ensure this matches the binary name copied above | ||||||
|  | CMD ["./icarus_auth"] | ||||||
							
								
								
									
										32
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										32
									
								
								README.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,32 @@ | |||||||
|  | A auth web API services for the Icarus project. | ||||||
|  |  | ||||||
|  |  | ||||||
|  | # Getting Started | ||||||
|  | The easiest way to get started is through docker. This assumes that docker is already installed | ||||||
|  | on your system. Copy the `.env.docker.sample` as `.env`. Most of the data in the env file doesn't  | ||||||
|  | need to be modified. The `SECRET_KEY` variable should be changed since it will be used for token | ||||||
|  | generation. The `SECRET_PASSPHASE` should also be changed when in production mode, but make sure | ||||||
|  | the respective `passphrase` database table record exists. | ||||||
|  |  | ||||||
|  | Build image | ||||||
|  | ``` | ||||||
|  | docker compose build | ||||||
|  | ``` | ||||||
|  |  | ||||||
|  | Start images | ||||||
|  | ``` | ||||||
|  | docker compose up -d --force-recreate | ||||||
|  | ``` | ||||||
|  |  | ||||||
|  | Bring it down | ||||||
|  | ``` | ||||||
|  | docker compose down -v | ||||||
|  | ``` | ||||||
|  |  | ||||||
|  | Pruning | ||||||
|  | ``` | ||||||
|  | docker system prune -a | ||||||
|  | ``` | ||||||
|  |  | ||||||
|  | To view the OpenAPI spec, run the project and access `/swagger-ui`. If running through docker, | ||||||
|  | the url would be something like `http://localhost:8000/swagger-ui`. | ||||||
							
								
								
									
										45
									
								
								docker-compose.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								docker-compose.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,45 @@ | |||||||
|  | version: '3.8' # Use a recent version | ||||||
|  |  | ||||||
|  | services: | ||||||
|  |   # Your Rust Application Service | ||||||
|  |   auth_api: | ||||||
|  |     build: # Tells docker-compose to build the Dockerfile in the current directory | ||||||
|  |       context: . | ||||||
|  |       ssh: ["default"]  # Uses host's SSH agent | ||||||
|  |     container_name: icarus_auth # Optional: Give the container a specific name | ||||||
|  |     ports: | ||||||
|  |       # Map host port 8000 to container port 3000 (adjust as needed) | ||||||
|  |       - "8001:8001" | ||||||
|  |     env_file: | ||||||
|  |       - .env | ||||||
|  |     depends_on: | ||||||
|  |       auth_db: | ||||||
|  |         condition: service_healthy # Wait for the DB to be healthy before starting the app | ||||||
|  |     restart: unless-stopped # Optional: Restart policy | ||||||
|  |  | ||||||
|  |   # PostgreSQL Database Service | ||||||
|  |   auth_db: | ||||||
|  |     image: postgres:17.5-alpine # Use an official Postgres image (Alpine variant is smaller) | ||||||
|  |     container_name: icarus_auth_db # Optional: Give the container a specific name | ||||||
|  |     environment: | ||||||
|  |       # These MUST match the user, password, and database name in the DATABASE_URL above | ||||||
|  |       POSTGRES_USER: ${POSTGRES_AUTH_USER:-icarus_op} | ||||||
|  |       POSTGRES_PASSWORD: ${POSTGRES_AUTH_PASSWORD:-password} | ||||||
|  |       POSTGRES_DB: ${POSTGRES_AUTH_DB:-icarus_auth_db} | ||||||
|  |     volumes: | ||||||
|  |       # Persist database data using a named volume | ||||||
|  |       - postgres_data:/var/lib/postgresql/data | ||||||
|  |     ports: [] | ||||||
|  |     healthcheck: | ||||||
|  |         # Checks if Postgres is ready to accept connections | ||||||
|  |         test: ["CMD-SHELL", "pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB"] | ||||||
|  |         interval: 10s | ||||||
|  |         timeout: 5s | ||||||
|  |         retries: 5 | ||||||
|  |         start_period: 10s | ||||||
|  |     restart: always # Optional: Restart policy | ||||||
|  |  | ||||||
|  | # Define the named volume for data persistence | ||||||
|  | volumes: | ||||||
|  |   postgres_data: | ||||||
|  |     driver: local # Use the default local driver | ||||||
| @@ -20,3 +20,9 @@ CREATE TABLE IF NOT EXISTS "salt" ( | |||||||
|     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), |     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||||
|     salt TEXT NOT NULL |     salt TEXT NOT NULL | ||||||
| ); | ); | ||||||
|  |  | ||||||
|  | CREATE TABLE IF NOT EXISTS "passphrase" ( | ||||||
|  |     id UUID PRIMARY KEY DEFAULT gen_random_uuid(), | ||||||
|  |     passphrase TEXT NOT NULL, | ||||||
|  |     date_created TIMESTAMPTZ NOT NULL DEFAULT NOW() | ||||||
|  | ); | ||||||
|   | |||||||
							
								
								
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										2
									
								
								migrations/20250802185652_passphrase_data.sql
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,2 @@ | |||||||
|  | -- Add migration script here | ||||||
|  | INSERT INTO "passphrase" (id, passphrase) VALUES('22f9c775-cce9-457a-a147-9dafbb801f61', 'iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH'); | ||||||
| @@ -1,3 +1,5 @@ | |||||||
|  | TODO: At some point, move this somewhere that is appropriate | ||||||
|  |  | ||||||
| # Make sure role has CREATEDB | # Make sure role has CREATEDB | ||||||
| ALTER ROLE username_that_needs_permission CREATEDB; | ALTER ROLE username_that_needs_permission CREATEDB; | ||||||
|  |  | ||||||
|   | |||||||
| @@ -1,30 +1,54 @@ | |||||||
| use axum::{Extension, Json, http::StatusCode}; | pub mod response { | ||||||
|  |  | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
| #[derive(Deserialize, Serialize)] |     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct TestResult { |     pub struct TestResult { | ||||||
|     message: String, |         pub message: String, | ||||||
|  |     } | ||||||
| } | } | ||||||
|  |  | ||||||
| // basic handler that responds with a static string | pub mod endpoint { | ||||||
|  |     use super::*; | ||||||
|  |     use axum::{Extension, Json, http::StatusCode}; | ||||||
|  |  | ||||||
|  |     /// Endpoint to hit the root | ||||||
|  |     /// basic handler that responds with a static string | ||||||
|  |     #[utoipa::path( | ||||||
|  |         get, | ||||||
|  |         path = super::super::endpoints::ROOT, | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Test", body = &str), | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|     pub async fn root() -> &'static str { |     pub async fn root() -> &'static str { | ||||||
|         "Hello, World!" |         "Hello, World!" | ||||||
|     } |     } | ||||||
|  |  | ||||||
| pub async fn db_ping(Extension(pool): Extension<sqlx::PgPool>) -> (StatusCode, Json<TestResult>) { |     /// Endpoint to do a database ping | ||||||
|  |     #[utoipa::path( | ||||||
|  |         get, | ||||||
|  |         path = super::super::endpoints::DBTEST, | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Successful ping of the db", body = super::response::TestResult), | ||||||
|  |             (status = 400, description = "Failure in pinging the db", body = super::response::TestResult) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|  |     pub async fn db_ping( | ||||||
|  |         Extension(pool): Extension<sqlx::PgPool>, | ||||||
|  |     ) -> (StatusCode, Json<response::TestResult>) { | ||||||
|         match sqlx::query("SELECT 1").execute(&pool).await { |         match sqlx::query("SELECT 1").execute(&pool).await { | ||||||
|             Ok(_) => { |             Ok(_) => { | ||||||
|             let tr = TestResult { |                 let tr = response::TestResult { | ||||||
|                     message: String::from("This works"), |                     message: String::from("This works"), | ||||||
|                 }; |                 }; | ||||||
|                 (StatusCode::OK, Json(tr)) |                 (StatusCode::OK, Json(tr)) | ||||||
|             } |             } | ||||||
|             Err(e) => ( |             Err(e) => ( | ||||||
|                 StatusCode::BAD_REQUEST, |                 StatusCode::BAD_REQUEST, | ||||||
|             Json(TestResult { |                 Json(response::TestResult { | ||||||
|                     message: e.to_string(), |                     message: e.to_string(), | ||||||
|                 }), |                 }), | ||||||
|             ), |             ), | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  | } | ||||||
|   | |||||||
| @@ -1,23 +1,54 @@ | |||||||
| pub mod request { | pub mod request { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Default, Deserialize, Serialize)] |     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Request { |     pub struct Request { | ||||||
|         pub username: String, |         pub username: String, | ||||||
|         pub password: String, |         pub password: String, | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub mod service_login { | ||||||
|  |         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Request { | ||||||
|  |             pub passphrase: String, | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     pub mod refresh_token { | ||||||
|  |         #[derive(Debug, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Request { | ||||||
|  |             pub access_token: String, | ||||||
|  |         } | ||||||
|  |     } | ||||||
| } | } | ||||||
|  |  | ||||||
| pub mod response { | pub mod response { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Default, Deserialize, Serialize)] |     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|  |     pub struct Response { | ||||||
|  |         pub message: String, | ||||||
|  |         pub data: Vec<icarus_models::login_result::LoginResult>, | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     pub mod service_login { | ||||||
|  |         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|         pub struct Response { |         pub struct Response { | ||||||
|             pub message: String, |             pub message: String, | ||||||
|             pub data: Vec<icarus_models::login_result::LoginResult>, |             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub mod refresh_token { | ||||||
|  |         #[derive(Debug, Default, serde::Deserialize, serde::Serialize, utoipa::ToSchema)] | ||||||
|  |         pub struct Response { | ||||||
|  |             pub message: String, | ||||||
|  |             pub data: Vec<icarus_models::login_result::LoginResult>, | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | /// Module for login endpoints | ||||||
| pub mod endpoint { | pub mod endpoint { | ||||||
|     use axum::{Json, http::StatusCode}; |     use axum::{Json, http::StatusCode}; | ||||||
|  |  | ||||||
| @@ -28,6 +59,10 @@ pub mod endpoint { | |||||||
|     use super::request; |     use super::request; | ||||||
|     use super::response; |     use super::response; | ||||||
|  |  | ||||||
|  |     // TODO: At some point, get the username from the DB | ||||||
|  |     // Name of service username when returning a login result | ||||||
|  |     pub const SERVICE_USERNAME: &str = "service"; | ||||||
|  |  | ||||||
|     async fn not_found(message: &str) -> (StatusCode, Json<response::Response>) { |     async fn not_found(message: &str) -> (StatusCode, Json<response::Response>) { | ||||||
|         ( |         ( | ||||||
|             StatusCode::NOT_FOUND, |             StatusCode::NOT_FOUND, | ||||||
| @@ -38,6 +73,20 @@ pub mod endpoint { | |||||||
|         ) |         ) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to login | ||||||
|  |     #[utoipa::path( | ||||||
|  |         post, | ||||||
|  |         path = super::super::endpoints::LOGIN, | ||||||
|  |         request_body( | ||||||
|  |             content = request::Request, | ||||||
|  |             description = "Data required to login", | ||||||
|  |             content_type = "application/json" | ||||||
|  |         ), | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Successfully logged in", body = response::Response), | ||||||
|  |             (status = 404, description = "Could not login with credentials", body = response::Response) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|     pub async fn login( |     pub async fn login( | ||||||
|         axum::Extension(pool): axum::Extension<sqlx::PgPool>, |         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|         Json(payload): Json<request::Request>, |         Json(payload): Json<request::Request>, | ||||||
| @@ -45,31 +94,25 @@ pub mod endpoint { | |||||||
|         // Check if user exists |         // Check if user exists | ||||||
|         match repo::user::get(&pool, &payload.username).await { |         match repo::user::get(&pool, &payload.username).await { | ||||||
|             Ok(user) => { |             Ok(user) => { | ||||||
|                 let salt = repo::salt::get(&pool, &user.salt_id).await.unwrap(); |                 if hashing::verify_password(&payload.password, user.password.clone()).unwrap() { | ||||||
|                 let salt_str = hashing::get_salt(&salt.salt).unwrap(); |  | ||||||
|                 let unhashed_password = payload.password; |  | ||||||
|  |  | ||||||
|                 // Check if password is correct |  | ||||||
|                 match hashing::hash_password(&unhashed_password, &salt_str) { |  | ||||||
|                     Ok(hash_password) => { |  | ||||||
|                         if hashing::verify_password(&unhashed_password, hash_password.clone()) |  | ||||||
|                             .unwrap() |  | ||||||
|                         { |  | ||||||
|                     // Create token |                     // Create token | ||||||
|                             let key = token_stuff::get_key().unwrap(); |                     let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|                     let (token_literal, duration) = |                     let (token_literal, duration) = | ||||||
|                                 token_stuff::create_token(&key).unwrap(); |                         token_stuff::create_token(&key, &user.id).unwrap(); | ||||||
|  |  | ||||||
|                     if token_stuff::verify_token(&key, &token_literal) { |                     if token_stuff::verify_token(&key, &token_literal) { | ||||||
|  |                         let current_time = time::OffsetDateTime::now_utc(); | ||||||
|  |                         let _ = repo::user::update_last_login(&pool, &user, ¤t_time).await; | ||||||
|  |  | ||||||
|                         ( |                         ( | ||||||
|                             StatusCode::OK, |                             StatusCode::OK, | ||||||
|                             Json(response::Response { |                             Json(response::Response { | ||||||
|                                 message: String::from("Successful"), |                                 message: String::from("Successful"), | ||||||
|                                 data: vec![icarus_models::login_result::LoginResult { |                                 data: vec![icarus_models::login_result::LoginResult { | ||||||
|                                     id: user.id, |                                     id: user.id, | ||||||
|                                             username: user.username, |                                     username: user.username.clone(), | ||||||
|                                     token: token_literal, |                                     token: token_literal, | ||||||
|                                             token_type: String::from(token_stuff::TOKENTYPE), |                                     token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||||
|                                     expiration: duration, |                                     expiration: duration, | ||||||
|                                 }], |                                 }], | ||||||
|                             }), |                             }), | ||||||
| @@ -86,9 +129,140 @@ pub mod endpoint { | |||||||
|             } |             } | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to login as a service user | ||||||
|  |     #[utoipa::path( | ||||||
|  |         post, | ||||||
|  |         path = super::super::endpoints::SERVICE_LOGIN, | ||||||
|  |         request_body( | ||||||
|  |             content = request::service_login::Request, | ||||||
|  |             description = "Data required to login as a service user", | ||||||
|  |             content_type = "application/json" | ||||||
|  |         ), | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Login successful", body = response::Response), | ||||||
|  |             (status = 400, description = "Error logging in with credentials", body = response::Response) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|  |     pub async fn service_login( | ||||||
|  |         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|  |         axum::Json(payload): axum::Json<request::service_login::Request>, | ||||||
|  |     ) -> ( | ||||||
|  |         axum::http::StatusCode, | ||||||
|  |         axum::Json<response::service_login::Response>, | ||||||
|  |     ) { | ||||||
|  |         let mut response = response::service_login::Response::default(); | ||||||
|  |  | ||||||
|  |         match repo::service::valid_passphrase(&pool, &payload.passphrase).await { | ||||||
|  |             Ok((id, _passphrase, _date_created)) => { | ||||||
|  |                 let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|  |                 let (token_literal, duration) = | ||||||
|  |                     token_stuff::create_service_token(&key, &id).unwrap(); | ||||||
|  |  | ||||||
|  |                 if token_stuff::verify_token(&key, &token_literal) { | ||||||
|  |                     let login_result = icarus_models::login_result::LoginResult { | ||||||
|  |                         id, | ||||||
|  |                         username: String::from(SERVICE_USERNAME), | ||||||
|  |                         token: token_literal, | ||||||
|  |                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||||
|  |                         expiration: duration, | ||||||
|  |                     }; | ||||||
|  |  | ||||||
|  |                     response.data.push(login_result); | ||||||
|  |                     response.message = String::from("Successful"); | ||||||
|  |  | ||||||
|  |                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||||
|  |                 } else { | ||||||
|  |                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|             Err(err) => { |             Err(err) => { | ||||||
|                 return not_found(&err.to_string()).await; |                 response.message = err.to_string(); | ||||||
|  |                 (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||||
|             } |             } | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     /// Endpoint to retrieve a refresh token | ||||||
|  |     #[utoipa::path( | ||||||
|  |         post, | ||||||
|  |         path = super::super::endpoints::REFRESH_TOKEN, | ||||||
|  |         request_body( | ||||||
|  |             content = request::refresh_token::Request, | ||||||
|  |             description = "Data required to retrieve a refresh token", | ||||||
|  |             content_type = "application/json" | ||||||
|  |         ), | ||||||
|  |         responses( | ||||||
|  |             (status = 200, description = "Refresh token generated", body = response::Response), | ||||||
|  |             (status = 400, description = "Error verifying token", body = response::Response), | ||||||
|  |             (status = 404, description = "Could not validate token", body = response::Response), | ||||||
|  |             (status = 500, description = "Error extracting token", body = response::Response) | ||||||
|  |         ) | ||||||
|  |     )] | ||||||
|  |     pub async fn refresh_token( | ||||||
|  |         axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|  |         axum::Json(payload): axum::Json<request::refresh_token::Request>, | ||||||
|  |     ) -> ( | ||||||
|  |         axum::http::StatusCode, | ||||||
|  |         axum::Json<response::refresh_token::Response>, | ||||||
|  |     ) { | ||||||
|  |         let mut response = response::refresh_token::Response::default(); | ||||||
|  |         let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|  |  | ||||||
|  |         if token_stuff::verify_token(&key, &payload.access_token) { | ||||||
|  |             let token_type = token_stuff::get_token_type(&key, &payload.access_token).unwrap(); | ||||||
|  |  | ||||||
|  |             if token_stuff::is_token_type_valid(&token_type) { | ||||||
|  |                 // Get passphrase record with id | ||||||
|  |                 match token_stuff::extract_id_from_token(&key, &payload.access_token) { | ||||||
|  |                     Ok(id) => match repo::service::get_passphrase(&pool, &id).await { | ||||||
|  |                         Ok((returned_id, _, _)) => { | ||||||
|  |                             match token_stuff::create_service_refresh_token(&key, &returned_id) { | ||||||
|  |                                 Ok((access_token, exp_dur)) => { | ||||||
|  |                                     let login_result = icarus_models::login_result::LoginResult { | ||||||
|  |                                         id: returned_id, | ||||||
|  |                                         token: access_token, | ||||||
|  |                                         expiration: exp_dur, | ||||||
|  |                                         token_type: String::from(icarus_models::token::TOKEN_TYPE), | ||||||
|  |                                         username: String::from(SERVICE_USERNAME), | ||||||
|  |                                     }; | ||||||
|  |                                     response.message = String::from("Successful"); | ||||||
|  |                                     response.data.push(login_result); | ||||||
|  |  | ||||||
|  |                                     (axum::http::StatusCode::OK, axum::Json(response)) | ||||||
|  |                                 } | ||||||
|  |                                 Err(err) => { | ||||||
|  |                                     response.message = err.to_string(); | ||||||
|  |                                     ( | ||||||
|  |                                         axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||||
|  |                                         axum::Json(response), | ||||||
|  |                                     ) | ||||||
|  |                                 } | ||||||
|  |                             } | ||||||
|  |                         } | ||||||
|  |                         Err(err) => { | ||||||
|  |                             response.message = err.to_string(); | ||||||
|  |                             ( | ||||||
|  |                                 axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||||
|  |                                 axum::Json(response), | ||||||
|  |                             ) | ||||||
|  |                         } | ||||||
|  |                     }, | ||||||
|  |                     Err(err) => { | ||||||
|  |                         response.message = err.to_string(); | ||||||
|  |                         ( | ||||||
|  |                             axum::http::StatusCode::INTERNAL_SERVER_ERROR, | ||||||
|  |                             axum::Json(response), | ||||||
|  |                         ) | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |             } else { | ||||||
|  |                 response.message = String::from("Invalid token type"); | ||||||
|  |                 (axum::http::StatusCode::NOT_FOUND, axum::Json(response)) | ||||||
|  |             } | ||||||
|  |         } else { | ||||||
|  |             response.message = String::from("Could not verify token"); | ||||||
|  |             (axum::http::StatusCode::BAD_REQUEST, axum::Json(response)) | ||||||
|  |         } | ||||||
|  |     } | ||||||
| } | } | ||||||
|   | |||||||
| @@ -7,4 +7,6 @@ pub mod endpoints { | |||||||
|     pub const REGISTER: &str = "/api/v2/register"; |     pub const REGISTER: &str = "/api/v2/register"; | ||||||
|     pub const DBTEST: &str = "/api/v2/test/db"; |     pub const DBTEST: &str = "/api/v2/test/db"; | ||||||
|     pub const LOGIN: &str = "/api/v2/login"; |     pub const LOGIN: &str = "/api/v2/login"; | ||||||
|  |     pub const SERVICE_LOGIN: &str = "/api/v2/service/login"; | ||||||
|  |     pub const REFRESH_TOKEN: &str = "/api/v2/token/refresh"; | ||||||
| } | } | ||||||
|   | |||||||
| @@ -6,7 +6,7 @@ use crate::repo; | |||||||
| pub mod request { | pub mod request { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Default, Deserialize, Serialize)] |     #[derive(Default, Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Request { |     pub struct Request { | ||||||
|         #[serde(skip_serializing_if = "String::is_empty")] |         #[serde(skip_serializing_if = "String::is_empty")] | ||||||
|         pub username: String, |         pub username: String, | ||||||
| @@ -26,13 +26,28 @@ pub mod request { | |||||||
| pub mod response { | pub mod response { | ||||||
|     use serde::{Deserialize, Serialize}; |     use serde::{Deserialize, Serialize}; | ||||||
|  |  | ||||||
|     #[derive(Deserialize, Serialize)] |     #[derive(Deserialize, Serialize, utoipa::ToSchema)] | ||||||
|     pub struct Response { |     pub struct Response { | ||||||
|         pub message: String, |         pub message: String, | ||||||
|         pub data: Vec<icarus_models::user::User>, |         pub data: Vec<icarus_models::user::User>, | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | /// Endpoint to register a user | ||||||
|  | #[utoipa::path( | ||||||
|  |     post, | ||||||
|  |     path = super::endpoints::REGISTER, | ||||||
|  |     request_body( | ||||||
|  |         content = request::Request, | ||||||
|  |         description = "Data required to register", | ||||||
|  |         content_type = "application/json" | ||||||
|  |     ), | ||||||
|  |     responses( | ||||||
|  |         (status = 201, description = "User created", body = response::Response), | ||||||
|  |         (status = 404, description = "User already exists", body = response::Response), | ||||||
|  |         (status = 400, description = "Issue creating user", body = response::Response) | ||||||
|  |     ) | ||||||
|  | )] | ||||||
| pub async fn register_user( | pub async fn register_user( | ||||||
|     axum::Extension(pool): axum::Extension<sqlx::PgPool>, |     axum::Extension(pool): axum::Extension<sqlx::PgPool>, | ||||||
|     Json(payload): Json<request::Request>, |     Json(payload): Json<request::Request>, | ||||||
|   | |||||||
| @@ -6,5 +6,5 @@ fn get_address() -> String { | |||||||
| } | } | ||||||
|  |  | ||||||
| fn get_port() -> String { | fn get_port() -> String { | ||||||
|     String::from("3000") |     String::from("8001") | ||||||
| } | } | ||||||
|   | |||||||
| @@ -11,8 +11,7 @@ use argon2::{ | |||||||
| pub fn generate_salt() -> Result<SaltString, argon2::Error> { | pub fn generate_salt() -> Result<SaltString, argon2::Error> { | ||||||
|     // Generate a random salt |     // Generate a random salt | ||||||
|     // SaltString::generate uses OsRng internally for cryptographic security |     // SaltString::generate uses OsRng internally for cryptographic security | ||||||
|     let salt = SaltString::generate(&mut OsRng); |     Ok(SaltString::generate(&mut OsRng)) | ||||||
|     Ok(salt) |  | ||||||
| } | } | ||||||
|  |  | ||||||
| pub fn get_salt(s: &str) -> Result<SaltString, argon2::password_hash::Error> { | pub fn get_salt(s: &str) -> Result<SaltString, argon2::password_hash::Error> { | ||||||
| @@ -32,9 +31,7 @@ pub fn hash_password( | |||||||
|     // Hash the password with the salt |     // Hash the password with the salt | ||||||
|     // The output is a PasswordHash string format that includes algorithm, version, |     // The output is a PasswordHash string format that includes algorithm, version, | ||||||
|     // parameters, salt, and the hash itself. |     // parameters, salt, and the hash itself. | ||||||
|     let password_hash = argon2.hash_password(password_bytes, salt)?.to_string(); |     Ok(argon2.hash_password(password_bytes, salt)?.to_string()) | ||||||
|  |  | ||||||
|     Ok(password_hash) |  | ||||||
| } | } | ||||||
|  |  | ||||||
| pub fn verify_password( | pub fn verify_password( | ||||||
| @@ -48,11 +45,9 @@ pub fn verify_password( | |||||||
|     let parsed_hash = argon2::PasswordHash::new(stored_hash.as_str())?; |     let parsed_hash = argon2::PasswordHash::new(stored_hash.as_str())?; | ||||||
|  |  | ||||||
|     // Create an Argon2 instance (it will use the parameters from the parsed hash) |     // Create an Argon2 instance (it will use the parameters from the parsed hash) | ||||||
|     let argon2 = Argon2::default(); |  | ||||||
|  |  | ||||||
|     // Verify the password against the parsed hash |     // Verify the password against the parsed hash | ||||||
|     // This automatically uses the correct salt and parameters embedded in `parsed_hash` |     // This automatically uses the correct salt and parameters embedded in `parsed_hash` | ||||||
|     match argon2.verify_password(password_bytes, &parsed_hash) { |     match Argon2::default().verify_password(password_bytes, &parsed_hash) { | ||||||
|         Ok(()) => Ok(true),                                       // Passwords match |         Ok(()) => Ok(true),                                       // Passwords match | ||||||
|         Err(argon2::password_hash::Error::Password) => Ok(false), // Passwords don't match |         Err(argon2::password_hash::Error::Password) => Ok(false), // Passwords don't match | ||||||
|         Err(e) => Err(e), // Some other error occurred (e.g., invalid hash format) |         Err(e) => Err(e), // Some other error occurred (e.g., invalid hash format) | ||||||
| @@ -66,8 +61,7 @@ mod tests { | |||||||
|     #[test] |     #[test] | ||||||
|     fn test_hash_password() { |     fn test_hash_password() { | ||||||
|         let some_password = String::from("somethingrandom"); |         let some_password = String::from("somethingrandom"); | ||||||
|         let salt = generate_salt().unwrap(); |         match hash_password(&some_password, &generate_salt().unwrap()) { | ||||||
|         match hash_password(&some_password, &salt) { |  | ||||||
|             Ok(p) => match verify_password(&some_password, p.clone()) { |             Ok(p) => match verify_password(&some_password, p.clone()) { | ||||||
|                 Ok(res) => { |                 Ok(res) => { | ||||||
|                     assert_eq!(res, true); |                     assert_eq!(res, true); | ||||||
| @@ -81,4 +75,27 @@ mod tests { | |||||||
|             } |             } | ||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     #[test] | ||||||
|  |     fn test_wrong_password() { | ||||||
|  |         let some_password = String::from("somethingrandom"); | ||||||
|  |         match hash_password(&some_password, &generate_salt().unwrap()) { | ||||||
|  |             Ok(p) => { | ||||||
|  |                 match verify_password(&some_password, p.clone()) { | ||||||
|  |                     Ok(res) => { | ||||||
|  |                         assert_eq!(res, true, "Passwords are not verified"); | ||||||
|  |                     } | ||||||
|  |                     Err(err) => { | ||||||
|  |                         assert!(false, "Error: {:?}", err.to_string()); | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |                 let wrong_password = String::from("Differentanotherlevel"); | ||||||
|  |                 let result = verify_password(&wrong_password, p.clone()).unwrap(); | ||||||
|  |                 assert_eq!(false, result, "Passwords should not match"); | ||||||
|  |             } | ||||||
|  |             Err(err) => { | ||||||
|  |                 assert!(false, "Error: {:?}", err.to_string()); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |     } | ||||||
| } | } | ||||||
|   | |||||||
							
								
								
									
										23
									
								
								src/lib.rs
									
									
									
									
									
								
							
							
						
						
									
										23
									
								
								src/lib.rs
									
									
									
									
									
								
							| @@ -1,17 +1,10 @@ | |||||||
|  | // TODO: Get rid of this file and place the code in more appropriate places | ||||||
| pub mod callers; | pub mod callers; | ||||||
| pub mod config; | pub mod config; | ||||||
| pub mod hashing; | pub mod hashing; | ||||||
| pub mod repo; | pub mod repo; | ||||||
| pub mod token_stuff; | pub mod token_stuff; | ||||||
|  |  | ||||||
| pub mod keys { |  | ||||||
|     pub const DBURL: &str = "DATABASE_URL"; |  | ||||||
|  |  | ||||||
|     pub mod error { |  | ||||||
|         pub const ERROR: &str = "DATABASE_URL must be set in .env"; |  | ||||||
|     } |  | ||||||
| } |  | ||||||
|  |  | ||||||
| mod connection_settings { | mod connection_settings { | ||||||
|     pub const MAXCONN: u32 = 5; |     pub const MAXCONN: u32 = 5; | ||||||
| } | } | ||||||
| @@ -19,13 +12,12 @@ mod connection_settings { | |||||||
| pub mod db { | pub mod db { | ||||||
|  |  | ||||||
|     use sqlx::postgres::PgPoolOptions; |     use sqlx::postgres::PgPoolOptions; | ||||||
|     use std::env; |  | ||||||
|  |  | ||||||
|     use crate::{connection_settings, keys}; |     use crate::connection_settings; | ||||||
|  |  | ||||||
|     pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { |     pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||||
|         let database_url = get_db_url().await; |         let database_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|         println!("Database url: {:?}", database_url); |         println!("Database url: {database_url}"); | ||||||
|  |  | ||||||
|         PgPoolOptions::new() |         PgPoolOptions::new() | ||||||
|             .max_connections(connection_settings::MAXCONN) |             .max_connections(connection_settings::MAXCONN) | ||||||
| @@ -33,13 +25,6 @@ pub mod db { | |||||||
|             .await |             .await | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     async fn get_db_url() -> String { |  | ||||||
|         #[cfg(debug_assertions)] // Example: Only load .env in debug builds |  | ||||||
|         dotenvy::dotenv().ok(); |  | ||||||
|  |  | ||||||
|         env::var(keys::DBURL).expect(keys::error::ERROR) |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     pub async fn migrations(pool: &sqlx::PgPool) { |     pub async fn migrations(pool: &sqlx::PgPool) { | ||||||
|         // Run migrations using the sqlx::migrate! macro |         // Run migrations using the sqlx::migrate! macro | ||||||
|         // Assumes your migrations are in a ./migrations folder relative to Cargo.toml |         // Assumes your migrations are in a ./migrations folder relative to Cargo.toml | ||||||
|   | |||||||
							
								
								
									
										288
									
								
								src/main.rs
									
									
									
									
									
								
							
							
						
						
									
										288
									
								
								src/main.rs
									
									
									
									
									
								
							| @@ -8,7 +8,7 @@ async fn main() { | |||||||
|  |  | ||||||
|     let app = init::app().await; |     let app = init::app().await; | ||||||
|  |  | ||||||
|     // run our app with hyper, listening globally on port 3000 |     // run our app with hyper, listening globally on port 8001 | ||||||
|     let url = config::get_full(); |     let url = config::get_full(); | ||||||
|     let listener = tokio::net::TcpListener::bind(url).await.unwrap(); |     let listener = tokio::net::TcpListener::bind(url).await.unwrap(); | ||||||
|     axum::serve(listener, app).await.unwrap(); |     axum::serve(listener, app).await.unwrap(); | ||||||
| @@ -19,14 +19,91 @@ mod init { | |||||||
|         Router, |         Router, | ||||||
|         routing::{get, post}, |         routing::{get, post}, | ||||||
|     }; |     }; | ||||||
|  |     use utoipa::OpenApi; | ||||||
|  |  | ||||||
|     use crate::callers; |     use crate::callers; | ||||||
|  |     use callers::common as common_callers; | ||||||
|  |     use callers::login as login_caller; | ||||||
|  |     use callers::register as register_caller; | ||||||
|  |     use login_caller::endpoint as login_endpoints; | ||||||
|  |     use login_caller::response as login_responses; | ||||||
|  |     use register_caller::response as register_responses; | ||||||
|  |  | ||||||
|  |     #[derive(utoipa::OpenApi)] | ||||||
|  |     #[openapi( | ||||||
|  |         paths( | ||||||
|  |             common_callers::endpoint::db_ping, common_callers::endpoint::root, | ||||||
|  |             register_caller::register_user, | ||||||
|  |             login_endpoints::login, login_endpoints::service_login, login_endpoints::refresh_token | ||||||
|  |             ), | ||||||
|  |         components(schemas(common_callers::response::TestResult, | ||||||
|  |                 register_responses::Response, | ||||||
|  |             login_responses::Response, login_responses::service_login::Response, login_responses::refresh_token::Response)), | ||||||
|  |         tags( | ||||||
|  |             (name = "Icarus Auth API", description = "Auth API for Icarus API") | ||||||
|  |             ) | ||||||
|  |     )] | ||||||
|  |     struct ApiDoc; | ||||||
|  |  | ||||||
|  |     mod cors { | ||||||
|  |         pub async fn configure_cors() -> tower_http::cors::CorsLayer { | ||||||
|  |             // Start building the CORS layer with common settings | ||||||
|  |             let cors = tower_http::cors::CorsLayer::new() | ||||||
|  |                 .allow_methods([ | ||||||
|  |                     axum::http::Method::GET, | ||||||
|  |                     axum::http::Method::POST, | ||||||
|  |                     axum::http::Method::PUT, | ||||||
|  |                     axum::http::Method::DELETE, | ||||||
|  |                 ]) // Specify allowed methods:cite[2] | ||||||
|  |                 .allow_headers([ | ||||||
|  |                     axum::http::header::CONTENT_TYPE, | ||||||
|  |                     axum::http::header::AUTHORIZATION, | ||||||
|  |                 ]) // Specify allowed headers:cite[2] | ||||||
|  |                 .allow_credentials(true) // If you need to send cookies or authentication headers:cite[2] | ||||||
|  |                 .max_age(std::time::Duration::from_secs(3600)); // Cache the preflight response for 1 hour:cite[2] | ||||||
|  |  | ||||||
|  |             // Dynamically set the allowed origin based on the environment | ||||||
|  |             match std::env::var(icarus_envy::keys::APP_ENV).as_deref() { | ||||||
|  |                 Ok("production") => { | ||||||
|  |                     let allowed_origins_env = icarus_envy::environment::get_allowed_origins().await; | ||||||
|  |                     match icarus_envy::utility::delimitize(&allowed_origins_env) { | ||||||
|  |                         Ok(alwd) => { | ||||||
|  |                             let allowed_origins: Vec<axum::http::HeaderValue> = alwd | ||||||
|  |                                 .into_iter() | ||||||
|  |                                 .map(|s| s.parse::<axum::http::HeaderValue>().unwrap()) | ||||||
|  |                                 .collect(); | ||||||
|  |                             cors.allow_origin(allowed_origins) | ||||||
|  |                         } | ||||||
|  |                         Err(err) => { | ||||||
|  |                             eprintln!( | ||||||
|  |                                 "Could not parse out allowed origins from env: Error: {err:?}" | ||||||
|  |                             ); | ||||||
|  |                             std::process::exit(-1); | ||||||
|  |                         } | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |                 _ => { | ||||||
|  |                     // Development (default): Allow localhost origins | ||||||
|  |                     cors.allow_origin(vec![ | ||||||
|  |                         "http://localhost:4200".parse().unwrap(), | ||||||
|  |                         "http://127.0.0.1:4200".parse().unwrap(), | ||||||
|  |                     ]) | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|     pub async fn routes() -> Router { |     pub async fn routes() -> Router { | ||||||
|         // build our application with a route |         // build our application with a route | ||||||
|         Router::new() |         Router::new() | ||||||
|             .route(callers::endpoints::DBTEST, get(callers::common::db_ping)) |             .route( | ||||||
|             .route(callers::endpoints::ROOT, get(callers::common::root)) |                 callers::endpoints::DBTEST, | ||||||
|  |                 get(callers::common::endpoint::db_ping), | ||||||
|  |             ) | ||||||
|  |             .route( | ||||||
|  |                 callers::endpoints::ROOT, | ||||||
|  |                 get(callers::common::endpoint::root), | ||||||
|  |             ) | ||||||
|             .route( |             .route( | ||||||
|                 callers::endpoints::REGISTER, |                 callers::endpoints::REGISTER, | ||||||
|                 post(callers::register::register_user), |                 post(callers::register::register_user), | ||||||
| @@ -35,6 +112,15 @@ mod init { | |||||||
|                 callers::endpoints::LOGIN, |                 callers::endpoints::LOGIN, | ||||||
|                 post(callers::login::endpoint::login), |                 post(callers::login::endpoint::login), | ||||||
|             ) |             ) | ||||||
|  |             .route( | ||||||
|  |                 callers::endpoints::SERVICE_LOGIN, | ||||||
|  |                 post(callers::login::endpoint::service_login), | ||||||
|  |             ) | ||||||
|  |             .route( | ||||||
|  |                 callers::endpoints::REFRESH_TOKEN, | ||||||
|  |                 post(callers::login::endpoint::refresh_token), | ||||||
|  |             ) | ||||||
|  |             .layer(cors::configure_cors().await) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     pub async fn app() -> Router { |     pub async fn app() -> Router { | ||||||
| @@ -44,7 +130,13 @@ mod init { | |||||||
|  |  | ||||||
|         icarus_auth::db::migrations(&pool).await; |         icarus_auth::db::migrations(&pool).await; | ||||||
|  |  | ||||||
|         routes().await.layer(axum::Extension(pool)) |         routes() | ||||||
|  |             .await | ||||||
|  |             .merge( | ||||||
|  |                 utoipa_swagger_ui::SwaggerUi::new("/swagger-ui") | ||||||
|  |                     .url("/api-docs/openapi.json", ApiDoc::openapi()), | ||||||
|  |             ) | ||||||
|  |             .layer(axum::Extension(pool)) | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
| @@ -63,24 +155,23 @@ mod tests { | |||||||
|     mod db_mgr { |     mod db_mgr { | ||||||
|         use std::str::FromStr; |         use std::str::FromStr; | ||||||
|  |  | ||||||
|         use icarus_auth::keys; |  | ||||||
|  |  | ||||||
|         pub const LIMIT: usize = 6; |         pub const LIMIT: usize = 6; | ||||||
|  |  | ||||||
|         pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { |         pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { | ||||||
|             let tm_db_url = std::env::var(keys::DBURL).expect("DATABASE_URL must be present"); |             let tm_db_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|             let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); |             let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); | ||||||
|             sqlx::PgPool::connect_with(tm_options).await |             sqlx::PgPool::connect_with(tm_options).await | ||||||
|         } |         } | ||||||
|  |  | ||||||
|         pub async fn generate_db_name() -> String { |         pub async fn generate_db_name() -> String { | ||||||
|             let db_name = |             let db_name = get_database_name().await.unwrap() | ||||||
|                 get_database_name().unwrap() + &"_" + &uuid::Uuid::new_v4().to_string()[..LIMIT]; |                 + &"_" | ||||||
|  |                 + &uuid::Uuid::new_v4().to_string()[..LIMIT]; | ||||||
|             db_name |             db_name | ||||||
|         } |         } | ||||||
|  |  | ||||||
|         pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { |         pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { | ||||||
|             let db_url = std::env::var(keys::DBURL).expect("DATABASE_URL must be set for tests"); |             let db_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|             let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); |             let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); | ||||||
|             sqlx::PgPool::connect_with(options).await |             sqlx::PgPool::connect_with(options).await | ||||||
|         } |         } | ||||||
| @@ -106,11 +197,9 @@ mod tests { | |||||||
|             Ok(()) |             Ok(()) | ||||||
|         } |         } | ||||||
|  |  | ||||||
|         pub fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { |         pub async fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { | ||||||
|             dotenvy::dotenv().ok(); // Load .env file if it exists |             let database_url = icarus_envy::environment::get_db_url().await.value; | ||||||
|  |  | ||||||
|             match std::env::var(keys::DBURL) { |  | ||||||
|                 Ok(database_url) => { |  | ||||||
|             let parsed_url = url::Url::parse(&database_url)?; |             let parsed_url = url::Url::parse(&database_url)?; | ||||||
|             if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { |             if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { | ||||||
|                 match parsed_url |                 match parsed_url | ||||||
| @@ -125,12 +214,6 @@ mod tests { | |||||||
|                 Err("Error parsing".into()) |                 Err("Error parsing".into()) | ||||||
|             } |             } | ||||||
|         } |         } | ||||||
|                 Err(_) => { |  | ||||||
|                     // DATABASE_URL environment variable not found |  | ||||||
|                     Err("Error parsing".into()) |  | ||||||
|                 } |  | ||||||
|             } |  | ||||||
|         } |  | ||||||
|     } |     } | ||||||
|  |  | ||||||
|     fn get_test_register_request() -> icarus_auth::callers::register::request::Request { |     fn get_test_register_request() -> icarus_auth::callers::register::request::Request { | ||||||
| @@ -157,6 +240,25 @@ mod tests { | |||||||
|         }) |         }) | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub mod requests { | ||||||
|  |         use tower::ServiceExt; // for `call`, `oneshot`, and `ready` | ||||||
|  |  | ||||||
|  |         pub async fn register( | ||||||
|  |             app: &axum::Router, | ||||||
|  |             usr: &icarus_auth::callers::register::request::Request, | ||||||
|  |         ) -> Result<axum::response::Response, std::convert::Infallible> { | ||||||
|  |             let payload = super::get_test_register_payload(&usr); | ||||||
|  |             let req = axum::http::Request::builder() | ||||||
|  |                 .method(axum::http::Method::POST) | ||||||
|  |                 .uri(crate::callers::endpoints::REGISTER) | ||||||
|  |                 .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||||
|  |                 .body(axum::body::Body::from(payload.to_string())) | ||||||
|  |                 .unwrap(); | ||||||
|  |  | ||||||
|  |             app.clone().oneshot(req).await | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|     #[tokio::test] |     #[tokio::test] | ||||||
|     async fn test_hello_world() { |     async fn test_hello_world() { | ||||||
|         let app = init::app().await; |         let app = init::app().await; | ||||||
| @@ -201,18 +303,8 @@ mod tests { | |||||||
|         let app = init::routes().await.layer(axum::Extension(pool)); |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |  | ||||||
|         let usr = get_test_register_request(); |         let usr = get_test_register_request(); | ||||||
|         let payload = get_test_register_payload(&usr); |  | ||||||
|  |  | ||||||
|         let response = app |         let response = requests::register(&app, &usr).await; | ||||||
|             .oneshot( |  | ||||||
|                 Request::builder() |  | ||||||
|                     .method(axum::http::Method::POST) |  | ||||||
|                     .uri(callers::endpoints::REGISTER) |  | ||||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") |  | ||||||
|                     .body(Body::from(payload.to_string())) |  | ||||||
|                     .unwrap(), |  | ||||||
|             ) |  | ||||||
|             .await; |  | ||||||
|  |  | ||||||
|         match response { |         match response { | ||||||
|             Ok(resp) => { |             Ok(resp) => { | ||||||
| @@ -268,19 +360,8 @@ mod tests { | |||||||
|         let app = init::routes().await.layer(axum::Extension(pool)); |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |  | ||||||
|         let usr = get_test_register_request(); |         let usr = get_test_register_request(); | ||||||
|         let payload = get_test_register_payload(&usr); |  | ||||||
|  |  | ||||||
|         let response = app |         let response = requests::register(&app, &usr).await; | ||||||
|             .clone() |  | ||||||
|             .oneshot( |  | ||||||
|                 Request::builder() |  | ||||||
|                     .method(axum::http::Method::POST) |  | ||||||
|                     .uri(callers::endpoints::REGISTER) |  | ||||||
|                     .header(axum::http::header::CONTENT_TYPE, "application/json") |  | ||||||
|                     .body(Body::from(payload.to_string())) |  | ||||||
|                     .unwrap(), |  | ||||||
|             ) |  | ||||||
|             .await; |  | ||||||
|  |  | ||||||
|         match response { |         match response { | ||||||
|             Ok(resp) => { |             Ok(resp) => { | ||||||
| @@ -344,4 +425,125 @@ mod tests { | |||||||
|  |  | ||||||
|         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; |         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     #[tokio::test] | ||||||
|  |     async fn test_service_login_user() { | ||||||
|  |         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||||
|  |  | ||||||
|  |         let db_name = db_mgr::generate_db_name().await; | ||||||
|  |  | ||||||
|  |         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||||
|  |             Ok(_) => { | ||||||
|  |                 println!("Success"); | ||||||
|  |             } | ||||||
|  |             Err(e) => { | ||||||
|  |                 assert!(false, "Error: {:?}", e.to_string()); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||||
|  |  | ||||||
|  |         icarus_auth::db::migrations(&pool).await; | ||||||
|  |  | ||||||
|  |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |         let passphrase = | ||||||
|  |             String::from("iUOo1fxshf3y1tUGn1yU8l9raPApHCdinW0VdCHdRFEjqhR3Bf02aZzsKbLtaDFH"); | ||||||
|  |         let payload = serde_json::json!({ | ||||||
|  |             "passphrase": passphrase | ||||||
|  |         }); | ||||||
|  |  | ||||||
|  |         match app | ||||||
|  |             .oneshot( | ||||||
|  |                 Request::builder() | ||||||
|  |                     .method(axum::http::Method::POST) | ||||||
|  |                     .uri(callers::endpoints::SERVICE_LOGIN) | ||||||
|  |                     .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||||
|  |                     .body(Body::from(payload.to_string())) | ||||||
|  |                     .unwrap(), | ||||||
|  |             ) | ||||||
|  |             .await | ||||||
|  |         { | ||||||
|  |             Ok(response) => { | ||||||
|  |                 assert_eq!(StatusCode::OK, response.status(), "Status is not right"); | ||||||
|  |                 let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||||
|  |                     .await | ||||||
|  |                     .unwrap(); | ||||||
|  |                 let parsed_body: callers::login::response::service_login::Response = | ||||||
|  |                     serde_json::from_slice(&body).unwrap(); | ||||||
|  |                 let _login_result = &parsed_body.data[0]; | ||||||
|  |             } | ||||||
|  |             Err(err) => { | ||||||
|  |                 assert!(false, "Error: {err:?}"); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     #[tokio::test] | ||||||
|  |     async fn test_refresh_token() { | ||||||
|  |         let tm_pool = db_mgr::get_pool().await.unwrap(); | ||||||
|  |  | ||||||
|  |         let db_name = db_mgr::generate_db_name().await; | ||||||
|  |  | ||||||
|  |         match db_mgr::create_database(&tm_pool, &db_name).await { | ||||||
|  |             Ok(_) => { | ||||||
|  |                 println!("Success"); | ||||||
|  |             } | ||||||
|  |             Err(e) => { | ||||||
|  |                 assert!(false, "Error: {:?}", e.to_string()); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let pool = db_mgr::connect_to_db(&db_name).await.unwrap(); | ||||||
|  |  | ||||||
|  |         icarus_auth::db::migrations(&pool).await; | ||||||
|  |  | ||||||
|  |         let app = init::routes().await.layer(axum::Extension(pool)); | ||||||
|  |         let id = uuid::Uuid::parse_str("22f9c775-cce9-457a-a147-9dafbb801f61").unwrap(); | ||||||
|  |         let key = icarus_envy::environment::get_secret_key().await.value; | ||||||
|  |  | ||||||
|  |         match icarus_auth::token_stuff::create_service_token(&key, &id) { | ||||||
|  |             Ok((token, _expire)) => { | ||||||
|  |                 let payload = serde_json::json!({ | ||||||
|  |                     "access_token": token | ||||||
|  |                 }); | ||||||
|  |  | ||||||
|  |                 match app | ||||||
|  |                     .oneshot( | ||||||
|  |                         Request::builder() | ||||||
|  |                             .method(axum::http::Method::POST) | ||||||
|  |                             .uri(callers::endpoints::REFRESH_TOKEN) | ||||||
|  |                             .header(axum::http::header::CONTENT_TYPE, "application/json") | ||||||
|  |                             .body(Body::from(payload.to_string())) | ||||||
|  |                             .unwrap(), | ||||||
|  |                     ) | ||||||
|  |                     .await | ||||||
|  |                 { | ||||||
|  |                     Ok(response) => { | ||||||
|  |                         let body = axum::body::to_bytes(response.into_body(), usize::MAX) | ||||||
|  |                             .await | ||||||
|  |                             .unwrap(); | ||||||
|  |                         let parsed_body: callers::login::response::service_login::Response = | ||||||
|  |                             serde_json::from_slice(&body).unwrap(); | ||||||
|  |                         let login_result = &parsed_body.data[0]; | ||||||
|  |  | ||||||
|  |                         assert_eq!( | ||||||
|  |                             id, login_result.id, | ||||||
|  |                             "The Id from the response does not match {id:?} {:?}", | ||||||
|  |                             login_result.id | ||||||
|  |                         ); | ||||||
|  |                     } | ||||||
|  |                     Err(err) => { | ||||||
|  |                         assert!(false, "Error: {err:?}"); | ||||||
|  |                     } | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             Err(err) => { | ||||||
|  |                 assert!(false, "Error: {err:?}"); | ||||||
|  |             } | ||||||
|  |         } | ||||||
|  |  | ||||||
|  |         let _ = db_mgr::drop_database(&tm_pool, &db_name).await; | ||||||
|  |     } | ||||||
| } | } | ||||||
|   | |||||||
| @@ -42,6 +42,39 @@ pub mod user { | |||||||
|         } |         } | ||||||
|     } |     } | ||||||
|  |  | ||||||
|  |     pub async fn update_last_login( | ||||||
|  |         pool: &sqlx::PgPool, | ||||||
|  |         user: &icarus_models::user::User, | ||||||
|  |         time: &time::OffsetDateTime, | ||||||
|  |     ) -> Result<time::OffsetDateTime, sqlx::Error> { | ||||||
|  |         let result = sqlx::query( | ||||||
|  |             r#" | ||||||
|  |             UPDATE "user" SET last_login = $1 WHERE id = $2 RETURNING last_login | ||||||
|  |             "#, | ||||||
|  |         ) | ||||||
|  |         .bind(time) | ||||||
|  |         .bind(user.id) | ||||||
|  |         .fetch_optional(pool) | ||||||
|  |         .await | ||||||
|  |         .map_err(|e| { | ||||||
|  |             eprintln!("Error updating time: {e}"); | ||||||
|  |             e | ||||||
|  |         }); | ||||||
|  |  | ||||||
|  |         match result { | ||||||
|  |             Ok(row) => match row { | ||||||
|  |                 Some(r) => { | ||||||
|  |                     let last_login: time::OffsetDateTime = r | ||||||
|  |                         .try_get("last_login") | ||||||
|  |                         .map_err(|_e| sqlx::Error::RowNotFound)?; | ||||||
|  |                     Ok(last_login) | ||||||
|  |                 } | ||||||
|  |                 None => Err(sqlx::Error::RowNotFound), | ||||||
|  |             }, | ||||||
|  |             Err(err) => Err(err), | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|     pub async fn exists(pool: &sqlx::PgPool, username: &String) -> Result<bool, sqlx::Error> { |     pub async fn exists(pool: &sqlx::PgPool, username: &String) -> Result<bool, sqlx::Error> { | ||||||
|         let result = sqlx::query( |         let result = sqlx::query( | ||||||
|             r#" |             r#" | ||||||
| @@ -80,7 +113,7 @@ pub mod user { | |||||||
|         .fetch_one(pool) |         .fetch_one(pool) | ||||||
|         .await |         .await | ||||||
|         .map_err(|e| { |         .map_err(|e| { | ||||||
|             eprintln!("Error inserting item: {}", e); |             eprintln!("Error inserting item: {e}"); | ||||||
|             e |             e | ||||||
|         })?; |         })?; | ||||||
|  |  | ||||||
| @@ -147,7 +180,7 @@ pub mod salt { | |||||||
|         .fetch_one(pool) |         .fetch_one(pool) | ||||||
|         .await |         .await | ||||||
|         .map_err(|e| { |         .map_err(|e| { | ||||||
|             eprintln!("Error inserting item: {}", e); |             eprintln!("Error inserting item: {e}"); | ||||||
|             e |             e | ||||||
|         })?; |         })?; | ||||||
|  |  | ||||||
| @@ -162,3 +195,56 @@ pub mod salt { | |||||||
|         } |         } | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | pub mod service { | ||||||
|  |     use sqlx::Row; | ||||||
|  |  | ||||||
|  |     pub async fn valid_passphrase( | ||||||
|  |         pool: &sqlx::PgPool, | ||||||
|  |         passphrase: &String, | ||||||
|  |     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||||
|  |         let result = sqlx::query( | ||||||
|  |             r#" | ||||||
|  |             SELECT * FROM "passphrase" WHERE passphrase = $1 | ||||||
|  |             "#, | ||||||
|  |         ) | ||||||
|  |         .bind(passphrase) | ||||||
|  |         .fetch_one(pool) | ||||||
|  |         .await; | ||||||
|  |  | ||||||
|  |         match result { | ||||||
|  |             Ok(row) => { | ||||||
|  |                 let id: uuid::Uuid = row.try_get("id")?; | ||||||
|  |                 let passphrase: String = row.try_get("passphrase")?; | ||||||
|  |                 let date_created: Option<time::OffsetDateTime> = row.try_get("date_created")?; | ||||||
|  |  | ||||||
|  |                 Ok((id, passphrase, date_created.unwrap())) | ||||||
|  |             } | ||||||
|  |             Err(err) => Err(err), | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  |  | ||||||
|  |     pub async fn get_passphrase( | ||||||
|  |         pool: &sqlx::PgPool, | ||||||
|  |         id: &uuid::Uuid, | ||||||
|  |     ) -> Result<(uuid::Uuid, String, time::OffsetDateTime), sqlx::Error> { | ||||||
|  |         let result = sqlx::query( | ||||||
|  |             r#" | ||||||
|  |             SELECT * FROM "passphrase" WHERE id = $1; | ||||||
|  |             "#, | ||||||
|  |         ) | ||||||
|  |         .bind(id) | ||||||
|  |         .fetch_one(pool) | ||||||
|  |         .await; | ||||||
|  |  | ||||||
|  |         match result { | ||||||
|  |             Ok(row) => { | ||||||
|  |                 let returned_id: uuid::Uuid = row.try_get("id")?; | ||||||
|  |                 let passphrase: String = row.try_get("passphrase")?; | ||||||
|  |                 let date_created: time::OffsetDateTime = row.try_get("date_created")?; | ||||||
|  |                 Ok((returned_id, passphrase, date_created)) | ||||||
|  |             } | ||||||
|  |             Err(err) => Err(err), | ||||||
|  |         } | ||||||
|  |     } | ||||||
|  | } | ||||||
|   | |||||||
| @@ -1,23 +1,16 @@ | |||||||
| use josekit::{ | use josekit::{ | ||||||
|     self, |     self, | ||||||
|     jws::{JwsHeader, alg::hmac::HmacJwsAlgorithm::Hs256}, |     jws::alg::hmac::HmacJwsAlgorithm::Hs256, | ||||||
|     jwt::{self, JwtPayload}, |     jwt::{self}, | ||||||
| }; | }; | ||||||
|  |  | ||||||
| use time; | use time; | ||||||
|  |  | ||||||
| pub const TOKENTYPE: &str = "JWT"; |  | ||||||
| pub const KEY_ENV: &str = "SECRET_KEY"; | pub const KEY_ENV: &str = "SECRET_KEY"; | ||||||
| pub const MESSAGE: &str = "Something random"; | pub const MESSAGE: &str = "Something random"; | ||||||
| pub const ISSUER: &str = "icarus_auth"; | pub const ISSUER: &str = "icarus_auth"; | ||||||
| pub const AUDIENCE: &str = "icarus"; | pub const AUDIENCE: &str = "icarus"; | ||||||
|  |  | ||||||
| pub fn get_key() -> Result<String, dotenvy::Error> { |  | ||||||
|     dotenvy::dotenv().ok(); |  | ||||||
|     let key = std::env::var(KEY_ENV).expect("SECRET_KEY_NOT_FOUND"); |  | ||||||
|     Ok(key) |  | ||||||
| } |  | ||||||
|  |  | ||||||
| pub fn get_issued() -> time::Result<time::OffsetDateTime> { | pub fn get_issued() -> time::Result<time::OffsetDateTime> { | ||||||
|     Ok(time::OffsetDateTime::now_utc()) |     Ok(time::OffsetDateTime::now_utc()) | ||||||
| } | } | ||||||
| @@ -27,63 +20,115 @@ pub fn get_expiration(issued: &time::OffsetDateTime) -> Result<time::OffsetDateT | |||||||
|     Ok(*issued + duration_expire) |     Ok(*issued + duration_expire) | ||||||
| } | } | ||||||
|  |  | ||||||
| mod util { | pub fn create_token( | ||||||
|     pub fn time_to_std_time( |     provided_key: &String, | ||||||
|         provided_time: &time::OffsetDateTime, |     id: &uuid::Uuid, | ||||||
|     ) -> Result<std::time::SystemTime, std::time::SystemTimeError> { | ) -> Result<(String, i64), josekit::JoseError> { | ||||||
|         let converted = std::time::SystemTime::from(*provided_time); |     let resource = icarus_models::token::TokenResource { | ||||||
|         Ok(converted) |         message: String::from(MESSAGE), | ||||||
|     } |         issuer: String::from(ISSUER), | ||||||
| } |         audiences: vec![String::from(AUDIENCE)], | ||||||
|  |         id: *id, | ||||||
| pub fn create_token(provided_key: &String) -> Result<(String, i64), josekit::JoseError> { |  | ||||||
|     let mut header = JwsHeader::new(); |  | ||||||
|     header.set_token_type(TOKENTYPE); |  | ||||||
|  |  | ||||||
|     let mut payload = JwtPayload::new(); |  | ||||||
|     payload.set_subject(MESSAGE); |  | ||||||
|     payload.set_issuer(ISSUER); |  | ||||||
|     payload.set_audience(vec![AUDIENCE]); |  | ||||||
|     match get_issued() { |  | ||||||
|         Ok(issued) => { |  | ||||||
|             let expire = get_expiration(&issued).unwrap(); |  | ||||||
|             payload.set_issued_at(&util::time_to_std_time(&issued).unwrap()); |  | ||||||
|             payload.set_expires_at(&util::time_to_std_time(&expire).unwrap()); |  | ||||||
|  |  | ||||||
|             let key: String = if provided_key.is_empty() { |  | ||||||
|                 get_key().unwrap() |  | ||||||
|             } else { |  | ||||||
|                 provided_key.to_owned() |  | ||||||
|     }; |     }; | ||||||
|  |     icarus_models::token::create_token(provided_key, &resource, time::Duration::hours(4)) | ||||||
|  | } | ||||||
|  |  | ||||||
|             let signer = Hs256.signer_from_bytes(key.as_bytes()).unwrap(); | pub fn create_service_token( | ||||||
|             Ok(( |     provided: &String, | ||||||
|                 josekit::jwt::encode_with_signer(&payload, &header, &signer).unwrap(), |     id: &uuid::Uuid, | ||||||
|                 (expire - time::OffsetDateTime::UNIX_EPOCH).whole_seconds(), | ) -> Result<(String, i64), josekit::JoseError> { | ||||||
|             )) |     let resource = icarus_models::token::TokenResource { | ||||||
|         } |         message: String::from(SERVICE_SUBJECT), | ||||||
|         Err(e) => Err(josekit::JoseError::InvalidClaim(e.into())), |         issuer: String::from(ISSUER), | ||||||
|  |         audiences: vec![String::from(AUDIENCE)], | ||||||
|  |         id: *id, | ||||||
|  |     }; | ||||||
|  |     icarus_models::token::create_token(provided, &resource, time::Duration::hours(1)) | ||||||
| } | } | ||||||
|  |  | ||||||
|  | pub fn create_service_refresh_token( | ||||||
|  |     key: &String, | ||||||
|  |     id: &uuid::Uuid, | ||||||
|  | ) -> Result<(String, i64), josekit::JoseError> { | ||||||
|  |     let resource = icarus_models::token::TokenResource { | ||||||
|  |         message: String::from(SERVICE_SUBJECT), | ||||||
|  |         issuer: String::from(ISSUER), | ||||||
|  |         audiences: vec![String::from(AUDIENCE)], | ||||||
|  |         id: *id, | ||||||
|  |     }; | ||||||
|  |     icarus_models::token::create_token(key, &resource, time::Duration::hours(4)) | ||||||
| } | } | ||||||
|  |  | ||||||
| pub fn verify_token(key: &String, token: &String) -> bool { | pub fn verify_token(key: &String, token: &String) -> bool { | ||||||
|     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); |     match get_payload(key, token) { | ||||||
|     let (payload, _header) = jwt::decode_with_verifier(token, &ver).unwrap(); |         Ok((payload, _header)) => match payload.subject() { | ||||||
|     match payload.subject() { |  | ||||||
|             Some(_sub) => true, |             Some(_sub) => true, | ||||||
|             None => false, |             None => false, | ||||||
|  |         }, | ||||||
|  |         Err(_err) => false, | ||||||
|     } |     } | ||||||
| } | } | ||||||
|  |  | ||||||
|  | pub fn extract_id_from_token(key: &String, token: &String) -> Result<uuid::Uuid, std::io::Error> { | ||||||
|  |     match get_payload(key, token) { | ||||||
|  |         Ok((payload, _header)) => match payload.claim("id") { | ||||||
|  |             Some(id) => match uuid::Uuid::parse_str(id.as_str().unwrap()) { | ||||||
|  |                 Ok(extracted) => Ok(extracted), | ||||||
|  |                 Err(err) => Err(std::io::Error::other(err.to_string())), | ||||||
|  |             }, | ||||||
|  |             None => Err(std::io::Error::other("No claim found")), | ||||||
|  |         }, | ||||||
|  |         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||||
|  |     } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | pub const APP_TOKEN_TYPE: &str = "Icarus_App"; | ||||||
|  | pub const APP_SUBJECT: &str = "Something random"; | ||||||
|  | pub const SERVICE_TOKEN_TYPE: &str = "Icarus_Service"; | ||||||
|  | pub const SERVICE_SUBJECT: &str = "Service random"; | ||||||
|  |  | ||||||
|  | pub fn get_token_type(key: &String, token: &String) -> Result<String, std::io::Error> { | ||||||
|  |     match get_payload(key, token) { | ||||||
|  |         Ok((payload, _header)) => match payload.subject() { | ||||||
|  |             Some(subject) => { | ||||||
|  |                 if subject == APP_SUBJECT { | ||||||
|  |                     Ok(String::from(APP_TOKEN_TYPE)) | ||||||
|  |                 } else if subject == SERVICE_SUBJECT { | ||||||
|  |                     Ok(String::from(SERVICE_TOKEN_TYPE)) | ||||||
|  |                 } else { | ||||||
|  |                     Err(std::io::Error::other(String::from("Invalid subject"))) | ||||||
|  |                 } | ||||||
|  |             } | ||||||
|  |             None => Err(std::io::Error::other(String::from("Invalid payload"))), | ||||||
|  |         }, | ||||||
|  |         Err(err) => Err(std::io::Error::other(err.to_string())), | ||||||
|  |     } | ||||||
|  | } | ||||||
|  |  | ||||||
|  | pub fn is_token_type_valid(token_type: &String) -> bool { | ||||||
|  |     token_type == SERVICE_TOKEN_TYPE | ||||||
|  | } | ||||||
|  |  | ||||||
|  | fn get_payload( | ||||||
|  |     key: &String, | ||||||
|  |     token: &String, | ||||||
|  | ) -> Result<(josekit::jwt::JwtPayload, josekit::jws::JwsHeader), josekit::JoseError> { | ||||||
|  |     let ver = Hs256.verifier_from_bytes(key.as_bytes()).unwrap(); | ||||||
|  |     jwt::decode_with_verifier(token, &ver) | ||||||
|  | } | ||||||
|  |  | ||||||
| #[cfg(test)] | #[cfg(test)] | ||||||
| mod tests { | mod tests { | ||||||
|  |  | ||||||
|     use super::*; |     use super::*; | ||||||
|  |  | ||||||
|     #[test] |     #[test] | ||||||
|     fn test_tokenize() { |     fn test_tokenize() { | ||||||
|         let special_key = get_key().unwrap(); |         let rt = tokio::runtime::Runtime::new().unwrap(); | ||||||
|         match create_token(&special_key) { |         let special_key = rt | ||||||
|  |             .block_on(icarus_envy::environment::get_secret_key()) | ||||||
|  |             .value; | ||||||
|  |         let id = uuid::Uuid::new_v4(); | ||||||
|  |         match create_token(&special_key, &id) { | ||||||
|             Ok((token, _duration)) => { |             Ok((token, _duration)) => { | ||||||
|                 let result = verify_token(&special_key, &token); |                 let result = verify_token(&special_key, &token); | ||||||
|                 assert!(result, "Token not verified"); |                 assert!(result, "Token not verified"); | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user