server/lib.rs
1#![deny(clippy::await_holding_lock)]
2
3mod http;
4mod json;
5mod mcp;
6mod subscribe;
7mod ws;
8
9use core_api::{MutationEvent, SharedDb};
10
11pub use mcp::run_mcp_stdio;
12
13/// Resolved authentication identity for a single request.
14///
15/// Injected into request extensions by `auth_middleware` before any handler
16/// runs. Handlers that need to enforce role-based access control extract it
17/// via `Extension<AuthIdentity>`.
18#[derive(Clone, Debug)]
19pub(crate) enum AuthIdentity {
20 /// Full-access token (or no auth configured).
21 Full,
22 /// Role-bound token; the inner string is the role name.
23 Role(String),
24}
25
26/// Router state: the database plus the watch broadcast fan-out.
27#[derive(Clone)]
28struct AppState {
29 db: SharedDb,
30 watch: tokio::sync::broadcast::Sender<MutationEvent>,
31 /// Full-access bearer token (`--token` / `MUSHROOMDB_TOKEN`).
32 token: Option<String>,
33 /// Role-bound tokens: bearer value → role name.
34 /// A non-empty map enables role enforcement on every request.
35 role_tokens: std::collections::HashMap<String, String>,
36 /// Bind address advertised in `GET /health`.
37 addr: std::net::SocketAddr,
38 /// True when the server is serving over TLS (via the `tls` feature).
39 /// When true, the auth cookie gains the `Secure` attribute.
40 tls_active: bool,
41 /// Instant the router was first built; used by `GET /metrics` uptime_s.
42 started_at: std::time::Instant,
43}
44
45#[cfg(feature = "tls")]
46pub use http::serve_tls;
47#[allow(deprecated)]
48pub use http::{
49 router, router_with_auth, router_with_role_tokens, router_with_ui, router_with_ui_tls, serve,
50 serve_with_role_tokens, serve_with_ui, serve_with_ui_and_role_tokens,
51};
52#[cfg(feature = "embed-ui")]
53pub use http::{router_with_embedded_ui, serve_with_embedded_ui};