Compare commits

...
Author SHA1 Message Date
phoenix ae2577d90e bump: icarus_auth
Rust Build / Rustfmt (pull_request) Successful in 43s
Rust Build / Test Suite (pull_request) Failing after 2m6s
Rust Build / Check (pull_request) Successful in 3m8s
Rust Build / Clippy (pull_request) Successful in 3m18s
Rust Build / build (pull_request) Successful in 1m57s
2026-07-07 17:27:24 -04:00
phoenix c4bd39b2ca Added openssl dependency 2026-07-07 17:26:26 -04:00
phoenix 95b113f08f bump: icarus_models 2026-07-07 17:24:11 -04:00
phoenix 74fffa01f0 cargo update 2026-07-07 17:22:53 -04:00
phoenix 1b2ebd4f41 bump: icarus_envy 2026-07-07 17:21:54 -04:00
phoenix 48ae5799b7 bump: time 2026-07-07 17:16:39 -04:00
phoenix 46c2079ae5 bump
: uuid
2026-07-07 17:15:15 -04:00
phoenix 533e6db992 bump: sqlx 2026-07-07 17:14:42 -04:00
phoenix cc8074a5b1 Removing hyper, rand, once_cell dependencies 2026-07-07 17:13:29 -04:00
phoenix de873fbcf1 bump: tower-http 2026-07-07 17:11:54 -04:00
phoenix 3083fb7a0d bump: tokio 2026-07-07 17:11:13 -04:00
phoenix 17403b3038 bump: serde_json 2026-07-07 17:10:15 -04:00
phoenix 7bb62d479e bump: rust docker 2026-07-07 17:08:20 -04:00
phoenix 7c15f145dc Updated workflow 2026-07-07 17:08:01 -04:00
phoenix 54b0710298 Update rust (#1)
Rust Build / Check (push) Successful in 31s
Rust Build / Test Suite (push) Successful in 35s
Rust Build / Clippy (push) Successful in 30s
Rust Build / Rustfmt (push) Successful in 58s
Rust Build / build (push) Successful in 48s
Release Tagging / release (push) Successful in 1m34s
Rust Build / Rustfmt (pull_request) Successful in 34s
Rust Build / Test Suite (pull_request) Successful in 1m37s
Rust Build / Check (pull_request) Successful in 2m6s
Rust Build / Clippy (pull_request) Successful in 1m31s
Rust Build / build (pull_request) Successful in 1m21s
Reviewed-on: phoenix/icarus_auth#1
2026-05-22 11:24:55 -04:00
phoenix 4233876bb0 Update rust (#79)
Reviewed-on: phoenix/icarus_auth#79
Co-authored-by: phoenix <mail@kundeng.us>
Co-committed-by: phoenix <mail@kundeng.us>
2026-04-05 17:51:13 -04:00
phoenix 907a2dbfc3 tsk-64: Postgresql version bump 18 (#78)
Closes #64

Reviewed-on: phoenix/icarus_auth#78
Co-authored-by: phoenix <kundeng00@pm.me>
Co-committed-by: phoenix <kundeng00@pm.me>
2025-11-02 21:43:35 +00:00
phoenix cba3e3db79 tsk-68: Remove run_migrations.txt (#77)
Close #68

Reviewed-on: phoenix/icarus_auth#77
Co-authored-by: phoenix <kundeng00@pm.me>
Co-committed-by: phoenix <kundeng00@pm.me>
2025-10-22 15:48:39 +00:00
12 changed files with 530 additions and 951 deletions
+3 -2
View File
@@ -10,15 +10,16 @@ jobs:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
steps: steps:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v5 uses: actions/checkout@v6
with: with:
fetch-depth: 0 # Important for git describe --tags fetch-depth: 0 # Important for git describe --tags
- name: Install Rust - name: Install Rust
uses: actions-rs/toolchain@v1 uses: actions-rs/toolchain@v1
with: with:
toolchain: 1.90.0 toolchain: 1.96.1
components: cargo components: cargo
- uses: Swatinem/rust-cache@v2
- name: Extract Version from Cargo.toml - name: Extract Version from Cargo.toml
id: version id: version
+16 -11
View File
@@ -15,10 +15,11 @@ jobs:
name: Check name: Check
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
steps: steps:
- uses: actions/checkout@v5 - uses: actions/checkout@v6
- uses: actions-rust-lang/setup-rust-toolchain@v1 - uses: actions-rust-lang/setup-rust-toolchain@v1
with: with:
toolchain: 1.90.0 toolchain: 1.96.1
- uses: Swatinem/rust-cache@v2
- run: | - run: |
mkdir -p ~/.ssh mkdir -p ~/.ssh
echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key
@@ -36,7 +37,7 @@ jobs:
# --- Add database service definition --- # --- Add database service definition ---
services: services:
postgres: postgres:
image: postgres:17.5 image: postgres:18.3-alpine
env: env:
# Use secrets for DB init, with fallbacks for flexibility # Use secrets for DB init, with fallbacks for flexibility
POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }} POSTGRES_USER: ${{ secrets.DB_TEST_USER || 'testuser' }}
@@ -50,10 +51,11 @@ jobs:
--health-retries 5 --health-retries 5
steps: steps:
- uses: actions/checkout@v5 - uses: actions/checkout@v6
- uses: actions-rust-lang/setup-rust-toolchain@v1 - uses: actions-rust-lang/setup-rust-toolchain@v1
with: with:
toolchain: 1.90.0 toolchain: 1.96.1
- uses: Swatinem/rust-cache@v2
# --- Add this step for explicit verification --- # --- Add this step for explicit verification ---
- name: Verify Docker Environment - name: Verify Docker Environment
run: | run: |
@@ -92,10 +94,11 @@ jobs:
name: Rustfmt name: Rustfmt
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
steps: steps:
- uses: actions/checkout@v5 - uses: actions/checkout@v6
- uses: actions-rust-lang/setup-rust-toolchain@v1 - uses: actions-rust-lang/setup-rust-toolchain@v1
with: with:
toolchain: 1.90.0 toolchain: 1.96.1
- uses: Swatinem/rust-cache@v2
- run: rustup component add rustfmt - run: rustup component add rustfmt
- run: | - run: |
mkdir -p ~/.ssh mkdir -p ~/.ssh
@@ -111,10 +114,11 @@ jobs:
name: Clippy name: Clippy
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
steps: steps:
- uses: actions/checkout@v5 - uses: actions/checkout@v6
- uses: actions-rust-lang/setup-rust-toolchain@v1 - uses: actions-rust-lang/setup-rust-toolchain@v1
with: with:
toolchain: 1.90.0 toolchain: 1.96.1
- uses: Swatinem/rust-cache@v2
- run: rustup component add clippy - run: rustup component add clippy
- run: | - run: |
mkdir -p ~/.ssh mkdir -p ~/.ssh
@@ -130,10 +134,11 @@ jobs:
name: build name: build
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
steps: steps:
- uses: actions/checkout@v5 - uses: actions/checkout@v6
- uses: actions-rust-lang/setup-rust-toolchain@v1 - uses: actions-rust-lang/setup-rust-toolchain@v1
with: with:
toolchain: 1.90.0 toolchain: 1.96.1
- uses: Swatinem/rust-cache@v2
- run: | - run: |
mkdir -p ~/.ssh mkdir -p ~/.ssh
echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key echo "${{ secrets.MYREPO_TOKEN }}" > ~/.ssh/icarus_models_deploy_key
Generated
+464 -874
View File
File diff suppressed because it is too large Load Diff
+17 -19
View File
@@ -1,30 +1,28 @@
[package] [package]
name = "icarus_auth" name = "icarus_auth"
version = "0.6.5" version = "0.8.1"
edition = "2024" edition = "2024"
rust-version = "1.90" rust-version = "1.95"
[dependencies] [dependencies]
axum = { version = "0.8.6" } axum = { version = "0.8.9" }
openssl = { version = "0.10.81", features = ["vendored"] }
serde = { version = "1.0.228", features = ["derive"] } serde = { version = "1.0.228", features = ["derive"] }
serde_json = { version = "1.0.145" } serde_json = { version = "1.0.150" }
tokio = { version = "1.47.1", features = ["rt-multi-thread"] } tokio = { version = "1.52.3", features = ["rt-multi-thread"] }
tracing-subscriber = { version = "0.3.20" } tracing-subscriber = { version = "0.3.23" }
tower = { version = "0.5.2", features = ["full"] } tower = { version = "0.5.3", features = ["full"] }
tower-http = { version = "0.6.6", features = ["cors"] } tower-http = { version = "0.7.0", features = ["cors"] }
hyper = { version = "1.7.0" } sqlx = { version = "0.9.0", features = ["postgres", "runtime-tokio", "tls-native-tls", "time", "uuid"] }
sqlx = { version = "0.8.6", features = ["postgres", "runtime-tokio-native-tls", "time", "uuid"] } uuid = { version = "1.23.4", features = ["v4", "serde"] }
uuid = { version = "1.18.1", features = ["v4", "serde"] } argon2 = { version = "0.5.3", features = ["std"] }
argon2 = { version = "0.5.3", features = ["std"] } # Use the latest 0.5.x version time = { version = "0.3.53", features = ["macros", "serde"] }
rand = { version = "0.9.2" }
time = { version = "0.3.41", features = ["macros", "serde"] }
josekit = { version = "0.10.3" } josekit = { version = "0.10.3" }
utoipa = { version = "5.4.0", features = ["axum_extras"] } utoipa = { version = "5.5.0", features = ["axum_extras"] }
utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] } utoipa-swagger-ui = { version = "9.0.2", features = ["axum"] }
icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.8.0" } icarus_models = { git = "ssh://git@git.kundeng.us/phoenix/icarus_models.git", tag = "v0.11.3" }
icarus_envy = { git = "ssh://git@git.kundeng.us/phoenix/icarus_envy.git", tag = "v0.5.0" } icarus_envy = { git = "ssh://git@git.kundeng.us/phoenix/icarus_envy.git", tag = "v0.8.0" }
[dev-dependencies] [dev-dependencies]
http-body-util = { version = "0.1.3" } http-body-util = { version = "0.1.3" }
url = { version = "2.5.7" } url = { version = "2.5.8" }
once_cell = { version = "1.21.3" } # Useful for lazy initialization in tests/app setup
+3 -3
View File
@@ -1,7 +1,7 @@
# Stage 1: Build the application # Stage 1: Build the application
# Use a specific Rust version for reproducibility. Choose one that matches your development environment. # Use a specific Rust version for reproducibility. Choose one that matches your development environment.
# Using slim variant for smaller base image # Using slim variant for smaller base image
FROM rust:1.90 as builder FROM rust:1.96.1 as builder
# Set the working directory inside the container # Set the working directory inside the container
WORKDIR /usr/src/app WORKDIR /usr/src/app
@@ -46,7 +46,7 @@ RUN --mount=type=ssh \
# Stage 2: Create the final, smaller runtime image # Stage 2: Create the final, smaller runtime image
# Use a minimal base image like debian-slim or even distroless for security/size # Use a minimal base image like debian-slim or even distroless for security/size
FROM ubuntu:24.04 FROM debian:trixie-slim
# Install runtime dependencies if needed (e.g., SSL certificates) # Install runtime dependencies if needed (e.g., SSL certificates)
RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/* RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/*
@@ -64,7 +64,7 @@ COPY --from=builder /usr/src/app/.env .
COPY --from=builder /usr/src/app/migrations ./migrations COPY --from=builder /usr/src/app/migrations ./migrations
# Expose the port your Axum app listens on (e.g., 3000 or 8000) # Expose the port your Axum app listens on (e.g., 3000 or 8000)
EXPOSE 3000 EXPOSE 8001
# Set the command to run your application # Set the command to run your application
# Ensure this matches the binary name copied above # Ensure this matches the binary name copied above
+8 -1
View File
@@ -2,6 +2,13 @@ A auth web API services for the Icarus project.
# Getting Started # Getting Started
Install the `sqlx` tool to use migrations.
```
cargo install sqlx-cli
```
This will be used to scaffold development for local environments.
The easiest way to get started is through docker. This assumes that docker is already installed The easiest way to get started is through docker. This assumes that docker is already installed
on your system. Copy the `.env.docker.sample` as `.env`. Most of the data in the env file doesn't on your system. Copy the `.env.docker.sample` as `.env`. Most of the data in the env file doesn't
need to be modified. The `SECRET_KEY` variable should be changed since it will be used for token need to be modified. The `SECRET_KEY` variable should be changed since it will be used for token
@@ -33,4 +40,4 @@ docker system prune -a
``` ```
To view the OpenAPI spec, run the project and access `/swagger-ui`. If running through docker, To view the OpenAPI spec, run the project and access `/swagger-ui`. If running through docker,
the url would be something like `http://localhost:8000/swagger-ui`. the url would be something like `http://localhost:8001/swagger-ui`.
+2 -2
View File
@@ -19,7 +19,7 @@ services:
# PostgreSQL Database Service # PostgreSQL Database Service
auth_db: auth_db:
image: postgres:17.5-alpine # Use an official Postgres image (Alpine variant is smaller) image: postgres:18.3-alpine # Use an official Postgres image (Alpine variant is smaller)
container_name: icarus_auth_db # Optional: Give the container a specific name container_name: icarus_auth_db # Optional: Give the container a specific name
environment: environment:
# These MUST match the user, password, and database name in the DATABASE_URL above # These MUST match the user, password, and database name in the DATABASE_URL above
@@ -28,7 +28,7 @@ services:
POSTGRES_DB: ${POSTGRES_AUTH_DB:-icarus_auth_db} POSTGRES_DB: ${POSTGRES_AUTH_DB:-icarus_auth_db}
volumes: volumes:
# Persist database data using a named volume # Persist database data using a named volume
- postgres_data:/var/lib/postgresql/data - postgres_data:/var/lib/postgresql
ports: [] ports: []
healthcheck: healthcheck:
# Checks if Postgres is ready to accept connections # Checks if Postgres is ready to accept connections
-27
View File
@@ -1,27 +0,0 @@
TODO: At some point, move this somewhere that is appropriate
# Make sure role has CREATEDB
ALTER ROLE username_that_needs_permission CREATEDB;
# Install migrations
cargo install sqlx-cli
# Make sure to populate DATABASE_URL with correct value.
# By default, the DATABASE_URL found in .env file will be used
export DATABASE_URL="postgres://icarus_op_test:password@localhost/icarus_auth_test"
# init
sqlx migrate add init_migration
sqlx migrate run
# Create
sqlx database create
# Drop
sqlx database drop
# setup
sqlx database setup
# Reset
sqlx database reset
+3 -3
View File
@@ -92,7 +92,7 @@ pub mod endpoint {
Ok(user) => { Ok(user) => {
if hashing::verify_password(&payload.password, user.password.clone()).unwrap() { if hashing::verify_password(&payload.password, user.password.clone()).unwrap() {
// Create token // Create token
let key = icarus_envy::environment::get_secret_key().await.value; let key = icarus_envy::environment::get_secret_key().value;
let (token_literal, duration) = let (token_literal, duration) =
token_stuff::create_token(&key, &user.id).unwrap(); token_stuff::create_token(&key, &user.id).unwrap();
@@ -151,7 +151,7 @@ pub mod endpoint {
match repo::service::valid_passphrase(&pool, &payload.passphrase).await { match repo::service::valid_passphrase(&pool, &payload.passphrase).await {
Ok((id, username, _date_created)) => { Ok((id, username, _date_created)) => {
let key = icarus_envy::environment::get_secret_key().await.value; let key = icarus_envy::environment::get_secret_key().value;
let (token_literal, duration) = let (token_literal, duration) =
token_stuff::create_service_token(&key, &id).unwrap(); token_stuff::create_service_token(&key, &id).unwrap();
@@ -203,7 +203,7 @@ pub mod endpoint {
axum::Json<response::refresh_token::Response>, axum::Json<response::refresh_token::Response>,
) { ) {
let mut response = response::refresh_token::Response::default(); let mut response = response::refresh_token::Response::default();
let key = icarus_envy::environment::get_secret_key().await.value; let key = icarus_envy::environment::get_secret_key().value;
if token_stuff::verify_token(&key, &payload.access_token) { if token_stuff::verify_token(&key, &payload.access_token) {
let token_type = token_stuff::get_token_type(&key, &payload.access_token).unwrap(); let token_type = token_stuff::get_token_type(&key, &payload.access_token).unwrap();
+1 -1
View File
@@ -144,7 +144,7 @@ pub async fn register_user(
/// Checks to see if registration is enabled /// Checks to see if registration is enabled
async fn is_registration_enabled() -> Result<bool, std::io::Error> { async fn is_registration_enabled() -> Result<bool, std::io::Error> {
let key = String::from("ENABLE_REGISTRATION"); let key = String::from("ENABLE_REGISTRATION");
let var = icarus_envy::environment::get_env(&key).await; let var = icarus_envy::environment::get_env(&key);
let parsed_value = var.value.to_uppercase(); let parsed_value = var.value.to_uppercase();
if parsed_value == "TRUE" { if parsed_value == "TRUE" {
+1 -1
View File
@@ -1,7 +1,7 @@
use sqlx::postgres::PgPoolOptions; use sqlx::postgres::PgPoolOptions;
pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> { pub async fn create_pool() -> Result<sqlx::PgPool, sqlx::Error> {
let database_url = icarus_envy::environment::get_db_url().await.value; let database_url = icarus_envy::environment::get_db_url().value;
println!("Database url: {database_url}"); println!("Database url: {database_url}");
PgPoolOptions::new() PgPoolOptions::new()
+12 -7
View File
@@ -69,7 +69,7 @@ mod init {
// Dynamically set the allowed origin based on the environment // Dynamically set the allowed origin based on the environment
match std::env::var(icarus_envy::keys::APP_ENV).as_deref() { match std::env::var(icarus_envy::keys::APP_ENV).as_deref() {
Ok("production") => { Ok("production") => {
let allowed_origins_env = icarus_envy::environment::get_allowed_origins().await; let allowed_origins_env = icarus_envy::environment::get_allowed_origins();
match icarus_envy::utility::delimitize(&allowed_origins_env) { match icarus_envy::utility::delimitize(&allowed_origins_env) {
Ok(alwd) => { Ok(alwd) => {
let allowed_origins: Vec<axum::http::HeaderValue> = alwd let allowed_origins: Vec<axum::http::HeaderValue> = alwd
@@ -162,7 +162,7 @@ mod tests {
pub const LIMIT: usize = 6; pub const LIMIT: usize = 6;
pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> { pub async fn get_pool() -> Result<sqlx::PgPool, sqlx::Error> {
let tm_db_url = icarus_envy::environment::get_db_url().await.value; let tm_db_url = icarus_envy::environment::get_db_url().value;
let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap(); let tm_options = sqlx::postgres::PgConnectOptions::from_str(&tm_db_url).unwrap();
sqlx::PgPool::connect_with(tm_options).await sqlx::PgPool::connect_with(tm_options).await
} }
@@ -175,7 +175,7 @@ mod tests {
} }
pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> { pub async fn connect_to_db(db_name: &str) -> Result<sqlx::PgPool, sqlx::Error> {
let db_url = icarus_envy::environment::get_db_url().await.value; let db_url = icarus_envy::environment::get_db_url().value;
let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name); let options = sqlx::postgres::PgConnectOptions::from_str(&db_url)?.database(db_name);
sqlx::PgPool::connect_with(options).await sqlx::PgPool::connect_with(options).await
} }
@@ -185,7 +185,10 @@ mod tests {
db_name: &str, db_name: &str,
) -> Result<(), sqlx::Error> { ) -> Result<(), sqlx::Error> {
let create_query = format!("CREATE DATABASE {}", db_name); let create_query = format!("CREATE DATABASE {}", db_name);
match sqlx::query(&create_query).execute(template_pool).await { match sqlx::query(sqlx::AssertSqlSafe(create_query))
.execute(template_pool)
.await
{
Ok(_) => Ok(()), Ok(_) => Ok(()),
Err(e) => Err(e), Err(e) => Err(e),
} }
@@ -197,12 +200,14 @@ mod tests {
db_name: &str, db_name: &str,
) -> Result<(), sqlx::Error> { ) -> Result<(), sqlx::Error> {
let drop_query = format!("DROP DATABASE IF EXISTS {} WITH (FORCE)", db_name); let drop_query = format!("DROP DATABASE IF EXISTS {} WITH (FORCE)", db_name);
sqlx::query(&drop_query).execute(template_pool).await?; sqlx::query(sqlx::AssertSqlSafe(drop_query))
.execute(template_pool)
.await?;
Ok(()) Ok(())
} }
pub async fn get_database_name() -> Result<String, Box<dyn std::error::Error>> { pub async fn get_database_name() -> Result<String, Box<dyn std::error::Error>> {
let database_url = icarus_envy::environment::get_db_url().await.value; let database_url = icarus_envy::environment::get_db_url().value;
let parsed_url = url::Url::parse(&database_url)?; let parsed_url = url::Url::parse(&database_url)?;
if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" { if parsed_url.scheme() == "postgres" || parsed_url.scheme() == "postgresql" {
@@ -503,7 +508,7 @@ mod tests {
let app = init::routes().await.layer(axum::Extension(pool)); let app = init::routes().await.layer(axum::Extension(pool));
let id = uuid::Uuid::parse_str("22f9c775-cce9-457a-a147-9dafbb801f61").unwrap(); let id = uuid::Uuid::parse_str("22f9c775-cce9-457a-a147-9dafbb801f61").unwrap();
let key = icarus_envy::environment::get_secret_key().await.value; let key = icarus_envy::environment::get_secret_key().value;
match token_stuff::create_service_token(&key, &id) { match token_stuff::create_service_token(&key, &id) {
Ok((token, _expire)) => { Ok((token, _expire)) => {