oxedyne/fe2o3/fe2o3_steel/src/main.rs
2.3 KiB, 13 runs
created by r1870400018:967, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | // TODO: |
| 2 | // |
| 3 | // 1. HTTPS/TLS Configuration: |
| 4 | // - Currently only has basic cert file paths |
| 5 | // - Could add: |
| 6 | // - Custom cipher suite selection |
| 7 | // - TLS version requirements (min/max) |
| 8 | // - HSTS settings |
| 9 | // - Certificate reload/rotation settings |
| 10 | // - Client certificate validation options |
| 11 | // |
| 12 | // 2. CORS (Cross-Origin Resource Sharing): |
| 13 | // - Currently no CORS controls |
| 14 | // - Should configure: |
| 15 | // - Allowed origins (domains that can access) |
| 16 | // - Allowed methods (GET, POST etc) |
| 17 | // - Allowed headers |
| 18 | // - Whether to allow credentials |
| 19 | // - Max age of preflight responses |
| 20 | // |
| 21 | // 3. Rate Limiting: |
| 22 | // - No protection against abuse |
| 23 | // - Could add: |
| 24 | // - Requests per second/minute per IP |
| 25 | // - Burst allowances |
| 26 | // - Custom rate limits per route |
| 27 | // - Rate limit response headers |
| 28 | // - Different strategies (token bucket, fixed window) |
| 29 | // |
| 30 | // 4. Request Size Limits: |
| 31 | // - Currently unlimited |
| 32 | // - Should have: |
| 33 | // - Max body size |
| 34 | // - Max header size |
| 35 | // - Max URI length |
| 36 | // - Max number of headers |
| 37 | // - Different limits for different routes/content types |
| 38 | // |
| 39 | // 5. Compression: done. `fe2o3_net::http::encoding` negotiates on |
| 40 | // `Accept-Encoding` and gzips every eligible response; `compression_enabled` |
| 41 | // and `compression_min_bytes` in `server_cfg` tune it. Still open: brotli, |
| 42 | // which needs a dependency, and a store of encoded bodies so a hot static |
| 43 | // file is not encoded once per request. |
| 44 | // |
| 45 | #![forbid(unsafe_code)] |
| 46 | pub mod app; |
| 47 | pub mod srv; |
| 48 | |
| 49 | use crate::{ |
| 50 | app::tui, |
| 51 | }; |
| 52 | |
| 53 | use oxedyne_fe2o3_core::{ |
| 54 | prelude::*, |
| 55 | //log::{ |
| 56 | // console::StdoutLoggerConsole, |
| 57 | //}, |
| 58 | }; |
| 59 | |
| 60 | |
| 61 | fn main() -> Outcome<()> { |
| 62 | |
| 63 | // Install the process-wide rustls default crypto provider. Rustls 0.23 |
| 64 | // requires one of `ring` or `aws-lc-rs` to be installed before any |
| 65 | // `ServerConfig::builder()` call; Steel uses `ring` throughout, matching |
| 66 | // the `rustls = { features = ["ring"] }` declaration in Cargo.toml. |
| 67 | // We ignore the error because a second install attempt is benign. |
| 68 | let _ = rustls::crypto::ring::default_provider().install_default(); |
| 69 | |
| 70 | let mut log_cfg = log_get_config!(); |
| 71 | log_cfg.file = None; |
| 72 | log_set_config!(log_cfg); |
| 73 | log_set_level!("debug"); |
| 74 | |
| 75 | let outcome = tui::run(); |
| 76 | |
| 77 | std::thread::sleep(std::time::Duration::from_secs(1)); |
| 78 | |
| 79 | log_finish_wait!(); |
| 80 | |
| 81 | outcome |
| 82 | } |