Skip to main content

server/
lib.rs

1#![deny(clippy::await_holding_lock)]
2
3mod http;
4mod json;
5mod mcp;
6mod mcp_tasks;
7mod subscribe;
8mod ws;
9
10use core_api::{MutationEvent, SharedDb};
11
12pub use mcp::{run_mcp_stdio, run_mcp_stdio_with, ASSOCIATION_TOOLS, CODE_GRAPH_TOOLS};
13
14/// Resolved authentication identity for a single request.
15///
16/// Injected into request extensions by `auth_middleware` before any handler
17/// runs.  Handlers that need to enforce role-based access control extract it
18/// via `Extension<AuthIdentity>`.
19#[derive(Clone, Debug)]
20pub(crate) enum AuthIdentity {
21    /// Full-access token (or no auth configured).
22    Full,
23    /// Role-bound token; the inner string is the role name.
24    Role(String),
25}
26
27/// Router state: the database plus the watch broadcast fan-out.
28#[derive(Clone)]
29struct AppState {
30    db: SharedDb,
31    watch: tokio::sync::broadcast::Sender<MutationEvent>,
32    /// Full-access bearer token (`--token` / `MUSHROOMDB_TOKEN`).
33    token: Option<String>,
34    /// Role-bound tokens: bearer value → role name.
35    /// A non-empty map enables role enforcement on every request.
36    role_tokens: std::collections::HashMap<String, String>,
37    /// Bind address advertised in `GET /health`.
38    addr: std::net::SocketAddr,
39    /// True when the server is serving over TLS (via the `tls` feature).
40    /// When true, the auth cookie gains the `Secure` attribute.
41    tls_active: bool,
42    /// Instant the router was first built; used by `GET /metrics` uptime_s.
43    started_at: std::time::Instant,
44}
45
46#[cfg(feature = "tls")]
47pub use http::serve_tls;
48#[allow(deprecated)]
49pub use http::{
50    router, router_with_auth, router_with_role_tokens, router_with_ui, router_with_ui_tls, serve,
51    serve_with_role_tokens, serve_with_ui, serve_with_ui_and_role_tokens,
52};
53#[cfg(feature = "embed-ui")]
54pub use http::{router_with_embedded_ui, serve_with_embedded_ui};