Skip to main content

rustio_admin/
lib.rs

1//! rustio-admin — Django Admin, but for Rust.
2//!
3//! This crate is the public face of the framework. Phase 2 ships the
4//! HTTP / router / server / ORM / migrations / templates core; later
5//! phases populate `auth` and `admin`.
6
7#![forbid(unsafe_code)]
8
9pub mod admin;
10pub mod auth;
11pub mod background;
12pub mod email;
13pub mod error;
14pub mod http;
15pub mod middleware;
16pub mod migrations;
17pub mod orm;
18pub mod router;
19pub mod server;
20pub mod templates;
21
22pub use crate::admin::{
23    register_admin_routes, Admin, AdminField, AdminModel, FieldType, Fieldset, ModelAdmin,
24};
25pub use crate::auth::{Identity, Role};
26pub use crate::error::{Error, Result};
27pub use crate::http::{FormData, Request, Response};
28pub use crate::orm::{Db, DbOptions, Model, Row, Value};
29pub use crate::router::{Next, Router};
30pub use crate::server::Server;
31
32pub use rustio_admin_macros::RustioAdmin;
33
34// `RustioAdmin` emits `::rustio_admin::*` paths in its expansion. That
35// resolves cleanly for downstream consumers, but inside this crate's
36// own compilation unit `rustio_admin` isn't a known extern. Aliasing
37// the crate to itself under `cfg(test)` lets the macro be exercised
38// from this crate's own tests without changing any non-test build.
39#[cfg(test)]
40extern crate self as rustio_admin;
41
42/// Test-only re-exports for the integration-test suite under
43/// `tests/integration_*.rs`. NOT part of the public API — the
44/// module is `#[doc(hidden)]` and gated behind the
45/// `integration-test` Cargo feature, so a regular
46/// `cargo build` / `cargo test --workspace` cannot reach it.
47///
48/// Re-exports the otherwise-`pub(crate)` runtime surface of
49/// `auth::recovery_admin` so the integration tests can exercise
50/// `record_failed_login`, `admin_set_temp_password`, etc. without
51/// promoting the internal API to permanent `pub` visibility.
52///
53/// Plus a `fake_request()` builder for runtime fns that take
54/// `&Request` (currently `lock_user_account`,
55/// `unlock_user_account`, `admin_revoke_sessions`,
56/// `issue_admin_reset_token`, `admin_set_temp_password`). The
57/// fake request has no headers — `client_ip` and
58/// `correlation_id_from` both return `None`, which is the
59/// neutral state for the audit + logging layers.
60///
61/// See `DESIGN_R2_ORGANISATIONAL.md` §10.3 for the integration-
62/// test plan.
63#[doc(hidden)]
64#[cfg(feature = "integration-test")]
65pub mod __integration {
66    pub use crate::auth::recovery_admin::{
67        admin_revoke_sessions, admin_set_temp_password, check_account_lockout,
68        check_session_elevated, issue_admin_reset_token, lock_user_account,
69        promote_session_elevated, record_failed_login, record_successful_login,
70        unlock_user_account, AdminActor, AdminIssueOutcome, AdminRevokeOutcome, AdminTempPwOutcome,
71        LockDuration, LockOutcome, LockState, ThrottleOutcome, UnlockOutcome,
72    };
73    // R3 MFA — runtime fns + outcomes + key type + pure helpers the
74    // integration suite needs to drive enrolment / verify /
75    // consume / disable / regenerate flows. The `auth::mfa` module
76    // is `pub(crate)`, so this is the only door under the
77    // `integration-test` feature. See `DESIGN_R3_MFA.md` §13.3.
78    pub use crate::auth::mfa::{
79        confirm_enrolment, consume_backup_code, current_step, disable_mfa, generate_totp,
80        promote_session_to_mfa_verified, provision_secret, regenerate_backup_codes,
81        verify_totp_for_user, BackupConsumeOutcome, DisableOutcome, EnrolOutcome, MfaKey,
82        ProvisionedSecret, RegenOutcome, VerifyOutcome, BACKUP_CODE_COUNT,
83    };
84    /// R4 emergency-recovery test-only helper — forwards to the
85    /// `pub(crate)` `auth::sessions::hash_token_for_storage` so
86    /// the integration suite can verify that an
87    /// `emergency_access`-issued URL stores its token in the
88    /// exact same format R1's consume path will look up later.
89    /// Catches the hex-vs-base64 drift surfaced during commit #8
90    /// (which the unit-test gate could not have seen — only a
91    /// live-DB or testcontainers run can). Wrapped rather than
92    /// `pub use`'d because the inner helper is `pub(crate)` and
93    /// cannot be re-exported under a stricter visibility.
94    /// See `DESIGN_R4_EMERGENCY.md` §9.2.
95    pub fn hash_token_for_storage(token: &str) -> String {
96        crate::auth::sessions::hash_token_for_storage(token)
97    }
98
99    /// Construct a minimal [`crate::http::Request`] for integration
100    /// tests. POST to `/test`, no headers, no body, no params.
101    /// Adequate for runtime fns that read only `client_ip` (None)
102    /// and `correlation_id_from` (None) from the request.
103    pub fn fake_request() -> crate::http::Request {
104        use std::collections::HashMap;
105        crate::http::Request::__integration_test_fake("/test".to_string(), HashMap::new())
106    }
107}