server/lib.rs
1#![deny(clippy::await_holding_lock)]
2
3mod http;
4mod json;
5mod mcp;
6mod mcp_tasks;
7mod subscribe;
8mod ws;
9
10use core_api::{MutationEvent, SharedDb};
11
12pub use mcp::{run_mcp_stdio, run_mcp_stdio_with};
13
14/// Resolved authentication identity for a single request.
15///
16/// Injected into request extensions by `auth_middleware` before any handler
17/// runs. Handlers that need to enforce role-based access control extract it
18/// via `Extension<AuthIdentity>`.
19#[derive(Clone, Debug)]
20pub(crate) enum AuthIdentity {
21 /// Full-access token (or no auth configured).
22 Full,
23 /// Role-bound token; the inner string is the role name.
24 Role(String),
25}
26
27/// Router state: the database plus the watch broadcast fan-out.
28#[derive(Clone)]
29struct AppState {
30 db: SharedDb,
31 watch: tokio::sync::broadcast::Sender<MutationEvent>,
32 /// Full-access bearer token (`--token` / `MUSHROOMDB_TOKEN`).
33 token: Option<String>,
34 /// Role-bound tokens: bearer value → role name.
35 /// A non-empty map enables role enforcement on every request.
36 role_tokens: std::collections::HashMap<String, String>,
37 /// Bind address advertised in `GET /health`.
38 addr: std::net::SocketAddr,
39 /// True when the server is serving over TLS (via the `tls` feature).
40 /// When true, the auth cookie gains the `Secure` attribute.
41 tls_active: bool,
42 /// Instant the router was first built; used by `GET /metrics` uptime_s.
43 started_at: std::time::Instant,
44}
45
46#[cfg(feature = "tls")]
47pub use http::serve_tls;
48#[allow(deprecated)]
49pub use http::{
50 router, router_with_auth, router_with_role_tokens, router_with_ui, router_with_ui_tls, serve,
51 serve_with_role_tokens, serve_with_ui, serve_with_ui_and_role_tokens,
52};
53#[cfg(feature = "embed-ui")]
54pub use http::{router_with_embedded_ui, serve_with_embedded_ui};