Skip to main content

Crate cairn_mod

Crate cairn_mod 

Source
Expand description

Cairn — lightweight Rust-native ATProto labeler.

This crate is a library surface (cairn_mod) plus a binary (cairn) for running a standalone labeler. The library modules mirror the §10 architecture of the design doc: storage, writer (single-writer task pattern, §F5), signing (§6.2), auth (§5.2), HTTP routers (§F3/F4/F11/F12), and CLI.

Start points:

Re-exports§

pub use auth::AuthConfig;
pub use auth::AuthContext;
pub use auth::AuthError;
pub use auth::VerifiedCaller;
pub use config::Config;
pub use error::Error;
pub use error::Result;
pub use label::Label;
pub use server::AdminConfig;
pub use server::CreateReportConfig;
pub use server::RetentionConfig;
pub use server::SubscribeConfig;
pub use server::admin_router;
pub use server::create_report_router;
pub use server::current_retention_floor;
pub use server::did_document_router;
pub use server::health_router;
pub use server::router as subscribe_router;
pub use server::serve;
pub use server::wellknown_router;
pub use signing::canonical_bytes;
pub use signing::label_to_lex_value_with_sig;
pub use signing::sign_label;
pub use signing::verify_label;
pub use signing_key::SigningKey;
pub use writer::ApplyLabelRequest;
pub use writer::LabelEvent;
pub use writer::NegateLabelRequest;
pub use writer::SweepBatchResult;
pub use writer::SweepRequest;
pub use writer::SweepResult;
pub use writer::WriterHandle;
pub use writer::spawn as spawn_writer;

Modules§

auth
ATProto service-auth verification for moderator-authenticated endpoints (§5.2).
cli
Command-line surface for cairn (§F9 + §5.3).
config
Layered config loading.
credential_file
Shared file-permission invariants for on-disk credentials (§5.1 + §5.3).
error
Crate-wide error type.
label
Label record — in-memory shape of com.atproto.label.defs#label (§6.1).
moderators
Moderator identity + role-based authorization primitives shared between the HTTP admin surface and the cairn moderator CLI (#24).
report
Report domain type — flat projection of the reports table (§F11 intake schema in migrations/0001_init.sql).
serve
cairn serve lifecycle — the long-running-process entry point (L4).
server
HTTP server: XRPC endpoints over axum.
service_record
app.bsky.labeler.service record rendering + idempotency hash (§F1, §6.4).
signing
Label canonical encoding, signing, and verification (§6.2, §6.3, §F2).
signing_key
Signing-key newtype (§5.1).
storage
SQLite storage layer (§10 architecture).
writer
Single-writer task (§F5 / §10 architecture).