Skip to main content

build_admin_app

Function build_admin_app 

Source
pub fn build_admin_app(
    database: Arc<Database>,
    config: Arc<Config>,
    profiles: &[Arc<Profile>],
    audit: Arc<Auditor>,
    notifiers: Notifiers,
    jobs: JobQueue,
) -> Router
Expand description

Builds the whole admin service: /health, then the JSON API under /api.

Takes profiles as a slice so it can be called before build_app consumes the Vec in server::generation::build_generation — the ordering is a real constraint and the signature is where it is stated.

§What this router deliberately does not have

  • No admission control. Admission exists because the ACME surface is public and unauthenticated. This one defaults to loopback and needs a session on every route but login; the real availability concern is credential brute force, which admission control would not touch and the login limiter does.
  • No profile filter. The profiles’ [filter] is an ACME concern, and inheriting it would let an edit made for the ACME listener open or shut this one. The listener’s own policy is [admin.filter] (filter), beside the bind address, TLS and the session.

§Panics

On an admin.filter that check_config would have refused. The server builds the policy itself and calls build_admin_app_with_logins; this is the convenience form tests and fixtures use.