Skip to main content

systemprompt_users/
lib.rs

1//! # systemprompt-users
2//!
3//! User management for the systemprompt.io AI governance platform. The crate
4//! provides:
5//!
6//! - **6-tier RBAC** — typed `UserRole` and policy-aware promotion/demotion
7//!   helpers in [`UserAdminService`].
8//! - **Sessions** — lifecycle management for browser, API, and anonymous
9//!   sessions including bulk-end and recent-activity queries.
10//! - **API keys** — issuance, hashing, and verification via [`ApiKeyService`].
11//! - **Device certificates** — enrollment and rotation via
12//!   [`DeviceCertService`].
13//! - **IP bans** — typed [`BannedIpRepository`] with metadata-aware queries.
14//! - **Rate-limit buckets** — [`UserRateLimitBucketRepository`], the
15//!   replica-shared counters behind the global per-user HTTP throttle.
16//! - **Cleanup job** — purges anonymous users past the retention window.
17//!
18//! ## Feature flags
19//!
20//! | Feature | Default | Effect |
21//! |---------|---------|--------|
22//! | _none_  | n/a     | The crate exposes a single feature surface; all modules are compiled unconditionally. The `[package.metadata.docs.rs] all-features = true` setting is retained so future feature additions automatically appear in published docs. |
23//!
24//! ## Layering
25//!
26//! `systemprompt-users` is a **domain** crate. It depends downward on
27//! `systemprompt-database`, `systemprompt-extension`, `systemprompt-models`,
28//! `systemprompt-traits`, `systemprompt-provider-contracts`, and
29//! `systemprompt-identifiers`.
30//!
31//! Copyright (c) systemprompt.io — Business Source License 1.1.
32//! See <https://systemprompt.io> for licensing details.
33
34pub mod error;
35pub(crate) mod extension;
36pub mod jobs;
37pub(crate) mod models;
38pub(crate) mod repository;
39pub(crate) mod services;
40
41pub use extension::UsersExtension;
42
43pub use error::{Result, UserError, UserResult};
44pub use models::{
45    ApiKeyLimits, NewApiKey, User, UserActivity, UserApiKey, UserCountBreakdown, UserDeviceCert,
46    UserExport, UserRole, UserSession, UserStats, UserStatus, UserWithSessions, normalise_email,
47};
48pub use repository::{
49    BanDuration, BanIpParams, BanIpWithMetadataParams, BannedIp, BannedIpRepository,
50    CreateApiKeyParams, EnrollDeviceCertParams, MERGE_EXCLUDED_SECURITY_TABLES, MergeResult,
51    PurgeCount, SessionRepository, UserRateLimitBucketRepository, UserRepository,
52    UsersRoleDirectory,
53};
54pub use services::{
55    API_KEY_PREFIX, ApiKeyService, DEVICE_FINGERPRINT_FOREIGN_USER, DemoteResult,
56    DeviceCertService, EnrollDeviceCertServiceParams, IssueApiKeyParams, PromoteResult,
57    UpdateUserParams, UserAdminService, UserService,
58};
59
60pub use systemprompt_traits::auth::{RoleProvider, UserProvider};
61
62pub(crate) mod sessions;
63pub use sessions::UsersAiSessionProvider;