Expand description
The HTTP surface.
Routes and their auth posture are frozen:
| route | auth |
|---|---|
GET /health | none — uptime tooling holds no secret |
GET /admin | none — static markup, no data |
GET /.well-known/recall | none — a client asks before it can authenticate |
POST /sync, GET /sync, GET /v1/devices/me | bearer token, or the signature of any device but a worker |
GET /v1/audit/checkpoint, GET /v1/audit/consistency | bearer token, or any device’s signature |
POST /v1/devices/enroll, POST /v1/devices/enroll/poll | none, but rate limited, and small bodies only |
GET /admin/stats, the rest of /v1/devices, /v1/authkeys, and GET /v1/audit/entries | bearer token, an admin device’s signature, or the admin page’s passkey session (with its CSRF header on a POST); small bodies only |
GET /v1/jobs, POST /v1/jobs/{id}/retry | bearer token, or an admin device’s signature |
POST /v1/evaluations, GET /v1/evaluations, GET /v1/evaluations/{id} | bearer token, an admin device’s signature, or the admin page’s passkey session (with its CSRF header on a POST), which is never served details; small bodies only |
POST /v1/jobs/claim, POST /v1/jobs/{id}/result | a worker device’s signature, and nothing else |
GET /admin/session, POST /admin/login/start, POST /admin/login/finish | none, but rate limited |
POST /admin/bootstrap/register and …/finish | bearer token only, with the one-time bootstrap code, and only while no passkey exists |
GET /admin/passkeys, POST /admin/passkeys/…, POST /admin/logout, POST /admin/logout/others | the passkey session only, with its CSRF header on a POST; adding or removing a passkey and signing out the others also need a sign-in in the last five minutes |
| anything else | 404 JSON |
This module owns the shared state, the router, and the background jobs.
What it wires together are private submodules, each living next to its
own tests: middleware.rs (rate limiting, then the protocol check, then
auth), auth.rs (device signatures and the replay cache),
handlers.rs (one function per route), devices.rs (the device
routes), jobs.rs (the merge queue’s routes and its drain),
evaluations.rs (asking for and reading evaluation reports), admin.rs
(the admin page and its session), passkeys.rs (the WebAuthn ceremonies
that start a session), respond.rs (the JSON shape of every reply,
errors included), limit.rs (the per-IP window the middleware consults)
and tls.rs (the direct-TLS accept loop, used only when Config::tls
is on; plain HTTP, the default, never touches it). Both transports serve
the one router Server::router builds, every route group and layer
included.
Structs§
- Server
- The HTTP API, its background jobs, and the state they share.