Expand description
/ui — the HTML the operator actually looks at.
§Why this is separate from handlers/
handlers/ answers JSON at /api; this answers HTML at /ui. Both are
thin layers over the same crates/admin/src/admin/ operations, which is the whole point:
neither re-derives data, and neither is where a rule lives. Two small
handlers over one operation beat one handler content-negotiating itself into
two representations — htmx swaps markup, and a text/html branch inside a
JSON handler is where the two would start disagreeing.
A write goes one step further: a page calls the same apply_* function
its /api twin does (see handlers/mod.rs), which owns the validation, the
audit rows and the log line. A page decides only which refusals are a banner
beside the card and which replace the page.
every_shared_write_leaves_the_same_audit_rows_on_both_surfaces
(tests/admin_pages.rs) compares the two.
§Pages and fragments
Every list and detail route serves both. A normal navigation gets the full
document — the layout, the navigation, the page’s content — and an htmx
request gets the bare partial it is going to swap in. The choice is made off
the HX-Request header (auth::is_htmx), not off the route, so there is
one URL per resource and it is bookmarkable.
§What makes a write safe here
Exactly what makes it safe on the API: PageSessionWrite wraps
crate::webadmin::session::AuthenticatedWrite, so the origin gate, the
session lookup and the CSRF check all run before a mutating handler can see
a session. The token reaches the browser through hx-headers on <body> in
layout.html and comes back as X-CSRF-Token — the same header the JSON
API uses, and the reason check_csrf needed no second code path.
Re-exports§
pub use auth::PageAdminRead;pub use auth::PageAdminWrite;pub use auth::PageAuth;pub use auth::PageSelfServiceWrite;pub use auth::PageSession;pub use auth::PageSessionWrite;pub use error::PageError;
Modules§
- account
/ui/account— the operator’s own page: password, second factor, and their own live sessions.- accounts
/ui/accounts— the account list, one account, and the three things an operator can do to it.- assets
GET /ui/static/{file}— the two vendored assets, out of the binary.- audit
/ui/audit— the CA’s audit trail, and one row in full.- auth
- The page layer’s session extractors.
- eab
/ui/eab— External Account Binding credentials.- error
- The page layer’s error type.
- expiring
/ui/expiring— what lapses soon, and whether anything has replaced it.- filter
/ui/profiles/{name}/filter— the policy behind one endpoint.- jobs
/ui/jobs— the queue list, one job with its upstream cross-link, and the two things an operator can do to it.- misc
/ui/,/ui/profilesand/ui/nonces— the overview and the two small surfaces.- operators
/ui/operators— every operator this process has, and acting on one other than the caller.- orders
/ui/orders— the order list, one order with its authorizations, and the two things an operator can do to it.- session
/ui/loginand/ui/logout— the sign-in page and its counterpart.- templates
- The page templates: embedded defaults, the on-disk override, and rendering.
- upstream_
orders /ui/upstream-orders— the relay signer’s per-order upstream state.