1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
[]
= "backbone-integrations"
= "0.6.1"
= "2021"
= "Integration registry: connectors, integration accounts and an idempotent inbound event lane, with one OAuth flow (HMAC-bound state, PKCE)"
= "MIT OR Apache-2.0"
= "https://github.com/faridlab/backbone-integrations"
= [".claude/", ".github/", "graphify-out/"]
[]
= "src/lib.rs"
[]
# -----------------------------------------------------------------------------
# Backbone Framework crates
#
# Pulled directly from the public framework repository so this skeleton works
# anywhere on disk without path fix-up. For reproducible builds, pin to a
# specific tag or commit by replacing `branch = "main"` with `tag = "vX.Y.Z"`
# or `rev = "<commit-sha>"`. Cargo dedupes the git fetch — the repo is only
# cloned once even though four crates reference it.
# -----------------------------------------------------------------------------
= { = "3.0.0", = ["postgres"] }
= { = "3.0.0" }
= { = "3.0.0" }
= { = "3.0.0" }
# Transactional outbox — the integration event is staged in the same tx as the record (durable).
= { = "3.0.0", = ["multi_tenant"] }
# Core async runtime and serialization
= { = "1.0", = ["full"] }
= "0.1"
= { = "1.0", = ["derive"] }
= "1.0"
= { = "1.0", = ["v4", "serde"] }
= { = "0.4", = ["serde"] }
# Money/quantities — near-universal in domain modules. Generated code for any `decimal`
# field imports rust_decimal, so ship it (and the matching sqlx feature) by default.
= { = "1.36", = ["serde"] }
# Database (PostgreSQL primary)
= { = "0.8", = ["runtime-tokio-rustls", "postgres", "uuid", "chrono", "json", "migrate", "rust_decimal"] }
# HTTP framework (Axum)
= { = "0.7", = ["macros"] }
= "0.4"
= { = "0.5", = ["cors", "trace"] }
# Logging
= "0.1"
= { = "0.3", = ["env-filter"] }
# Validation
= { = "0.16", = ["derive"] }
# Error handling
= "1.0"
= "1.0"
# In-memory token buffers for the OAuth credential port — zeroized on drop, redacted in Debug.
= "1"
# OAuth state signing + PKCE material (the one OAuth generation): HMAC-SHA256
# over the state payload with constant-time comparison, SHA-256 for the PKCE
# S256 challenge, base64url encoding, and randomness for verifier/nonce minting.
= "0.12"
= "0.10"
= "2"
= "0.22"
= "0.8"
# Configuration
= "0.14"
= "0.9"
# Outbound OAuth transport — the token exchange and the server-side identity read are module
# code (reached only through the endpoint guard's validated URLs); the client refuses redirects
# and carries explicit timeouts.
= { = "0.12", = ["json", "rustls-tls"] }
# Protocol Buffers (Generated from Schema-First YAML)
= "0.12"
= "0.13"
= "0.13"
# OpenAPI schema derive. The generator emits `use utoipa::ToSchema;` in every
# entity and DTO behind the `openapi` feature, so the crate only builds with that
# feature on when the derive's crate is present: a feature that cannot compile is
# not a feature.
= { = "5", = ["chrono", "uuid"] }
[]
= []
= []
= []
= []
= []
= []
[]
= "0.12"
[]
= "3.0"
= "0.4"
= "0.12"
= "1.0"
# Integration testing framework — the generated tests/integration_tests.rs hits a live server
# via reqwest; guarded-route probes hit the router in-process via tower's ServiceExt::oneshot.
= "9.3"
# URL parsing for probe assertions over the authorize redirect the service builds.
= "2"
# TEST-ONLY edge: the payment-gateway seam proves a settled-payment notification drives the REAL
# backbone-payment write path (create_payment) via an in-test TargetPort. Dev-dependency ONLY — the shipped
# library reaches a module through the port, never a Cargo edge.
= { = "0.12.0" }