backbone-integrations 0.6.1

Integration registry: connectors, integration accounts and an idempotent inbound event lane, with one OAuth flow (HMAC-bound state, PKCE)
Documentation
[package]
name = "backbone-integrations"
version = "0.6.1"
edition = "2021"
description = "Integration registry: connectors, integration accounts and an idempotent inbound event lane, with one OAuth flow (HMAC-bound state, PKCE)"
license = "MIT OR Apache-2.0"
repository = "https://github.com/faridlab/backbone-integrations"
exclude = [".claude/", ".github/", "graphify-out/"]

[lib]
path = "src/lib.rs"

[dependencies]
# -----------------------------------------------------------------------------
# Backbone Framework crates
#
# Pulled directly from the public framework repository so this skeleton works
# anywhere on disk without path fix-up. For reproducible builds, pin to a
# specific tag or commit by replacing `branch = "main"` with `tag = "vX.Y.Z"`
# or `rev = "<commit-sha>"`. Cargo dedupes the git fetch — the repo is only
# cloned once even though four crates reference it.
# -----------------------------------------------------------------------------
backbone-core = { version = "3.0.0", features = ["postgres"] }
backbone-orm = { version = "3.0.0" }
backbone-auth = { version = "3.0.0" }
backbone-messaging = { version = "3.0.0" }
# Transactional outbox — the integration event is staged in the same tx as the record (durable).
backbone-outbox = { version = "3.0.0", features = ["multi_tenant"] }

# Core async runtime and serialization
tokio = { version = "1.0", features = ["full"] }
async-trait = "0.1"
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0"
uuid = { version = "1.0", features = ["v4", "serde"] }
chrono = { version = "0.4", features = ["serde"] }
# Money/quantities — near-universal in domain modules. Generated code for any `decimal`
# field imports rust_decimal, so ship it (and the matching sqlx feature) by default.
rust_decimal = { version = "1.36", features = ["serde"] }

# Database (PostgreSQL primary)
sqlx = { version = "0.8", features = ["runtime-tokio-rustls", "postgres", "uuid", "chrono", "json", "migrate", "rust_decimal"] }

# HTTP framework (Axum)
axum = { version = "0.7", features = ["macros"] }
tower = "0.4"
tower-http = { version = "0.5", features = ["cors", "trace"] }

# Logging
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter"] }

# Validation
validator = { version = "0.16", features = ["derive"] }

# Error handling
anyhow = "1.0"
thiserror = "1.0"
# In-memory token buffers for the OAuth credential port — zeroized on drop, redacted in Debug.
zeroize = "1"

# OAuth state signing + PKCE material (the one OAuth generation): HMAC-SHA256
# over the state payload with constant-time comparison, SHA-256 for the PKCE
# S256 challenge, base64url encoding, and randomness for verifier/nonce minting.
hmac = "0.12"
sha2 = "0.10"
subtle = "2"
base64 = "0.22"
rand = "0.8"

# Configuration
config = "0.14"
serde_yaml = "0.9"

# Outbound OAuth transport — the token exchange and the server-side identity read are module
# code (reached only through the endpoint guard's validated URLs); the client refuses redirects
# and carries explicit timeouts.
reqwest = { version = "0.12", features = ["json", "rustls-tls"] }

# Protocol Buffers (Generated from Schema-First YAML)
tonic = "0.12"
prost = "0.13"
prost-types = "0.13"

# OpenAPI schema derive. The generator emits `use utoipa::ToSchema;` in every
# entity and DTO behind the `openapi` feature, so the crate only builds with that
# feature on when the derive's crate is present: a feature that cannot compile is
# not a feature.
utoipa = { version = "5", features = ["chrono", "uuid"] }

[features]
default = []
events = []
auth = []
grpc = []
openapi = []
validation = []

[build-dependencies]
tonic-build = "0.12"

[dev-dependencies]
tempfile = "3.0"
tokio-test = "0.4"
mockall = "0.12"
pretty_assertions = "1.0"

# Integration testing framework — the generated tests/integration_tests.rs hits a live server
# via reqwest; guarded-route probes hit the router in-process via tower's ServiceExt::oneshot.
jsonwebtoken = "9.3"
# URL parsing for probe assertions over the authorize redirect the service builds.
url = "2"
# TEST-ONLY edge: the payment-gateway seam proves a settled-payment notification drives the REAL
# backbone-payment write path (create_payment) via an in-test TargetPort. Dev-dependency ONLY — the shipped
# library reaches a module through the port, never a Cargo edge.
backbone-payment = { version = "0.12.0" }