Skip to main content

Module webadmin

Module webadmin 

Source
Expand description

The web admin interface: a second HTTP listener, serving no ACME.

§Where this sits

src/cli/ and src/webadmin/ are the two front ends; src/admin/ is the operation layer both dispatch to and neither owns. A handler here is a few lines over an admin::ops call and an admin::render_*_json, the same way a src/cli/ command body is a few lines over the same call and a render_*_line.

§Why a second listener

The ACME listener is public, unauthenticated and often internet-facing. This one defaults to loopback, requires a session on every route but login, and carries no admission control or filter chain because neither fits it (see build_admin_app). Keeping them on one socket would have meant one set of defaults for two very different threat models.

Re-exports§

pub use error::AdminError;
pub use pages::PageError;
pub use session::LoginLimiter;

Modules§

error
The admin API’s error type.
handlers
One module per admin resource, re-exported flat — mirroring crate::handlers, which does the same for the ACME resources.
pages
/ui — the HTML the operator actually looks at.
session
Session tokens, the cookie they travel in, the extractors that resolve them, the CSRF check, and the login rate limiter.

Structs§

AdminState
Shared state for every admin route.

Functions§

build_admin_app
Builds the whole admin service: /health, then the JSON API under /api.
build_admin_app_with_logins
build_admin_app, carrying login counters across a configuration reload.
check_config
Rejects an [admin] section that cannot work, before anything binds.