mod admin;
#[cfg(feature = "auth")]
mod auth;
mod extensions;
mod graphql;
#[cfg(test)]
mod http_query_method_tests;
mod middleware;
#[cfg(test)]
mod mount_authz_tests;
#[cfg(feature = "observers")]
pub(in crate::server) mod observers;
#[cfg(test)]
mod persisted_only_transport_tests;
#[cfg(test)]
mod realtime_removal_survival_tests;
mod state;
#[cfg(test)]
mod storage_policy_admin_tests;
use std::sync::Arc;
use axum::{Router, middleware::from_fn_with_state};
use fraiseql_core::security::OidcValidator;
use tracing::info;
use super::{OidcAuthState, Server, oidc_auth_middleware};
use crate::{
middleware::{Hs256AuthState, hs256_auth_middleware},
routes::graphql::AppState,
};
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub(super) enum AuthPosture {
Authenticated,
}
impl Server {
pub(super) fn attach_auth<S>(
&self,
router: Router<S>,
posture: AuthPosture,
transport: &str,
) -> Router<S>
where
S: Clone + Send + Sync + 'static,
{
let AuthPosture::Authenticated = posture;
if let Some(ref validator) = self.oidc_validator {
info!(transport, "transport protected by OIDC authentication");
let auth_state = self.oidc_auth_state(Arc::clone(validator));
return router.route_layer(from_fn_with_state(auth_state, oidc_auth_middleware));
}
if let Some(ref validator) = self.hs256_auth {
info!(transport, "transport protected by HS256 authentication");
let realm = self
.config
.auth_hs256
.as_ref()
.and_then(|h| h.issuer.clone())
.unwrap_or_else(|| "fraiseql".to_string());
let auth_state = self
.hs256_auth_state(Arc::clone(validator), realm)
.with_service_accounts(self.service_account_authenticator.clone());
return router.route_layer(from_fn_with_state(auth_state, hs256_auth_middleware));
}
info!(
transport,
"no authentication configured — transport serves anonymous callers; row-scoping \
guards must fail closed on an absent security context"
);
router
}
}
impl Server {
pub(super) fn oidc_auth_state(&self, validator: Arc<OidcValidator>) -> OidcAuthState {
OidcAuthState::new(validator).with_revocation(self.revocation_manager.clone())
}
pub(super) fn hs256_auth_state(
&self,
validator: Arc<fraiseql_core::security::AuthMiddleware>,
realm: String,
) -> Hs256AuthState {
Hs256AuthState::new(validator, realm).with_revocation(self.revocation_manager.clone())
}
pub(super) fn build_router(&self) -> (Router, AppState) {
let state = self.build_app_state();
let graphql_router = self.build_graphql_router(&state);
let mut app = Router::new();
app = self.mount_base_and_admin_routes(app.merge(graphql_router), &state);
#[cfg(feature = "auth")]
{
app = self.mount_auth_routes(app);
}
app = self.mount_extensions(app, &state);
app = self.apply_middleware(app, &state);
(app, state)
}
}