Skip to main content

acme_proxy_admin/admin/
mod.rs

1//! Administrative operations, shared by both front ends and owned by neither.
2//!
3//! `cli` and [`crate::webadmin`] are the two front ends; everything
4//! they can do lives here, so the password policy, the duplicate check and the
5//! rehash-on-login cannot drift between a terminal and a browser.
6//!
7//! - [`ops`] — the operations themselves (accounts, orders, EAB, nonces, audit).
8//! - [`render`] — one JSON renderer per shape, surfacing the admin-only fields
9//!   (an order's revocation, an account's traceability columns) the ACME wire
10//!   format deliberately does not carry. **JSON only**: both front ends parse
11//!   these, so they are a wire format. The human-readable renderings have
12//!   exactly one consumer and live in `cli::render`, which is where
13//!   colour is woven in — and therefore cannot reach a `--json` shape.
14//! - [`password`], [`users`] — the credential store and the KDF.
15//! - [`changes`] — a change to an operator (by another, or their own contact
16//!   address), with its audit rows and message, for both front ends.
17//! - [`totp`], [`recovery`], [`mfa`] — the second factor: RFC 6238 over RFC 4226,
18//!   single-use recovery codes, and where those two meet the database.
19//! - [`prompt`] — confirmation, over an injectable reader so it is testable.
20//! - [`subject`] — the one "not found" sentence per kind of row.
21//!
22//! **Destructive operations come in pairs**: a bare form, and a `confirm_*`
23//! wrapper taking `assume_yes` and a reader. Those two arguments are a
24//! terminal's concern, so the CLI calls the wrapper and the web calls the bare
25//! form — rather than an HTTP caller passing `true` and an empty reader to
26//! assert a confirmation that never happened.
27
28pub mod changes;
29pub mod mfa;
30pub mod ops;
31pub mod password;
32pub mod prompt;
33pub mod recovery;
34pub mod render;
35pub mod subject;
36pub mod totp;
37pub mod users;
38
39pub use ops::*;
40pub use prompt::*;
41pub use render::*;
42
43// `password`, `totp`, `recovery` and `users` are deliberately *not* re-exported
44// flat. The three modules above hold one vocabulary between them, but
45// `admin::password::verify` and `admin::users::create_user` read as what they
46// are only with the module name attached -- a bare `admin::authenticate` says
47// nothing about who, and a bare `admin::verify` says nothing about what.