-
Notifications
You must be signed in to change notification settings - Fork 27
cargo: make vss-server/impls easier to consume as a library #116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
0cf41d9
f4ae56b
019b348
50ced5c
7a3e207
f18aec2
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,61 @@ | ||
| name: Continuous Integration Checks | ||
|
|
||
| on: [push, pull_request] | ||
|
|
||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| defaults: | ||
| run: | ||
| shell: bash | ||
|
|
||
| jobs: | ||
| rustfmt: | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 15 | ||
| env: | ||
| TOOLCHAIN: 1.85.0 | ||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v7 | ||
| - name: Install Rust ${{ env.TOOLCHAIN }} toolchain | ||
| run: | | ||
| rustup toolchain install ${{ env.TOOLCHAIN }} --profile minimal | ||
| rustup default ${{ env.TOOLCHAIN }} | ||
| rustup component add rustfmt | ||
| - name: Run rustfmt checks | ||
| run: cargo fmt --check | ||
|
|
||
| minimal-versions: | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 15 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| toolchain: [ stable, 1.85.0 ] # 1.85.0 is the MSRV | ||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v7 | ||
| - name: Install Rust ${{ matrix.toolchain }} toolchain | ||
| run: | | ||
| rustup toolchain install ${{ matrix.toolchain }} --profile minimal | ||
| rustup default ${{ matrix.toolchain }} | ||
| - name: Install cargo-hack | ||
| uses: taiki-e/install-action@cargo-hack | ||
| - uses: Swatinem/rust-cache@v2 | ||
| - name: "check -Z direct-minimal-versions" | ||
| run: | | ||
| # Remove dev-deps from all Cargo.toml's to prevent `cargo update` from | ||
| # determining minimal versions based on dev-deps. | ||
| cargo hack --remove-dev-deps --workspace | ||
|
|
||
| # Resolve direct dependencies using the min. version specified in our | ||
| # Cargo.toml's. | ||
| RUSTC_BOOTSTRAP=1 cargo update -Z direct-minimal-versions | ||
|
|
||
| cargo check --workspace | ||
| cargo check --workspace --no-default-features | ||
|
Comment on lines
+60
to
+61
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Sounds like we can do a single here to test all feature combinations ? |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -7,7 +7,8 @@ the threat model and auth overview, see the root [README](../README.md). | |
|
|
||
| - Rust and Cargo, using at least the repository MSRV of 1.85.0. | ||
| - PostgreSQL 15 or newer. | ||
| - OpenSSL development/runtime libraries for PostgreSQL TLS support. | ||
| - **(Optional)** OpenSSL development/runtime libraries for JWT authentication and PostgreSQL TLS | ||
| support. These features are enabled by default. | ||
|
|
||
| ## Quick Start with Docker PostgreSQL | ||
|
|
||
|
|
@@ -99,6 +100,20 @@ or set `VSS_JWT_RSA_PEM`. Clients must send `Authorization: Bearer <jwt>`. Token | |
| include `sub` and `exp` claims, and omit `aud`; `sub` becomes the VSS storage user token. VSS only | ||
| verifies tokens, you must run the service that issues them. | ||
|
|
||
| ### Optional Features | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Let's put this section right after prerequisites above, with a H2 header instead of H3 |
||
|
|
||
| The following optional cargo features are available, all enabled by default: | ||
|
|
||
| - `jwt`: Enables JWT authentication | ||
| - `sigs`: Enables Signature authentication | ||
| - `postgres-native-tls`: Enables connecting to PostgreSQL via TLS | ||
|
|
||
| For example, to build without OpenSSL enable only the `sigs` feature: | ||
|
|
||
| ```bash | ||
| cargo build --release --no-default-features --features sigs | ||
| ``` | ||
|
|
||
| ### Local No-Auth Mode | ||
|
|
||
| For local development only, build with the cfg-gated no-op authorizer: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,17 +9,21 @@ license.workspace = true | |
| homepage.workspace = true | ||
| repository.workspace = true | ||
|
|
||
| [features] | ||
| default = ["postgres-native-tls"] | ||
| postgres-native-tls = ["dep:native-tls", "dep:postgres-native-tls"] | ||
|
|
||
| [dependencies] | ||
| async-trait = "0.1.77" | ||
| async-trait = "0.1.13" | ||
| api = { workspace = true } | ||
| chrono = "0.4.38" | ||
| tokio-postgres = { version = "0.7.12", features = ["with-chrono-0_4"] } | ||
| bytes = "1.4.0" | ||
| tokio = { version = "1.38.0", default-features = false, features = ["rt", "macros"] } | ||
| native-tls = { version = "0.2.14", default-features = false } | ||
| postgres-native-tls = { version = "0.5.2", default-features = false, features = ["runtime"] } | ||
| log = { version = "0.4.29", default-features = false } | ||
| chrono = "0.4.16" | ||
| tokio-postgres = { version = "0.7.15", features = ["with-chrono-0_4"] } | ||
| bytes = "1" | ||
| tokio = { version = "1.30", default-features = false, features = ["rt", "macros"] } | ||
| native-tls = { version = "0.2.4", optional = true, default-features = false } | ||
| postgres-native-tls = { version = "0.5", optional = true, default-features = false, features = ["runtime"] } | ||
|
phlip9 marked this conversation as resolved.
|
||
| log = { version = "0.4.8", default-features = false } | ||
|
phlip9 marked this conversation as resolved.
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. nit: looks like we can still pull this down to 0.4.6 ? Same for server/Cargo.toml. |
||
|
|
||
| [dev-dependencies] | ||
| tokio = { version = "1.38.0", default-features = false, features = ["rt-multi-thread", "macros"] } | ||
| tokio = { version = "1.30", default-features = false, features = ["rt-multi-thread", "macros"] } | ||
| api = { workspace = true, features = ["_test_utils"] } | ||
|
tankyleo marked this conversation as resolved.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
we've got this check already in ping-tests.yml I know it's hidden away in there.
Let's drop the fmt command in ping-tests.yml, and use
fmt --all --checkhere