oxedyne/fe2o3/fe2o3_steel/src/srv/admin/mod.rs
5.0 KiB, 47 runs
created by r1870400018:10326, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | //! Admin dashboard for Steel. |
| 2 | //! |
| 3 | //! A self-contained web dashboard embedded inside the Steel server |
| 4 | //! binary. Operators reach it locally on a plaintext loopback listener |
| 5 | //! or remotely under `/admin` on the main vhost. The dashboard reuses |
| 6 | //! the wallet admin identities -- logging in is equivalent to handing |
| 7 | //! a passphrase to `steel admin` at the CLI -- so there is no second |
| 8 | //! user database to administer. |
| 9 | //! |
| 10 | //! # Capabilities |
| 11 | //! |
| 12 | //! - Browse and filter the ozone database associated with each vhost. |
| 13 | //! - Watch live traffic: recent requests, per-path and per-status |
| 14 | //! counters, rate information. |
| 15 | //! - Manage wallet admin entries (add, remove, list) from the browser, |
| 16 | //! mirroring the CLI's `admin` verbs. |
| 17 | //! |
| 18 | //! # Scopes |
| 19 | //! |
| 20 | //! Dashboard access is gated by the same scope strings used by the |
| 21 | //! CLI's `admin` verbs. The dashboard recognises: |
| 22 | //! |
| 23 | //! - [`SCOPE_DASHBOARD_VIEW`] -- read-only access; traffic and ozone |
| 24 | //! browsing only. |
| 25 | //! - [`SCOPE_DASHBOARD_ADMIN`] -- full dashboard access; required to |
| 26 | //! mutate the address guard's whitelist and blacklist, which is the |
| 27 | //! only mutation the dashboard performs, and to see the Fleet view, |
| 28 | //! which shows what every watched peer reports about itself. |
| 29 | //! - [`SCOPE_ADMIN`] -- the existing CLI scope; required *in addition* |
| 30 | //! to one of the dashboard scopes to see the admin-management UI. |
| 31 | //! |
| 32 | //! An admin holding only the wildcard `"*"` scope sees everything. |
| 33 | //! |
| 34 | //! # Submodules |
| 35 | //! |
| 36 | //! - [`auth`] -- login flow; verifies a passphrase against the loaded |
| 37 | //! wallet and produces an [`AdminPrincipal`]. |
| 38 | //! - [`session`] -- signed cookie format, encode/decode, principal |
| 39 | //! extraction from an incoming request. |
| 40 | //! - [`traffic`] -- in-memory ring buffer of recent requests and the |
| 41 | //! counters that feed the live dashboard views. |
| 42 | //! - [`ozone_view`] -- read-only ozone browsing, prefix scans, key |
| 43 | //! detail lookup. |
| 44 | //! - [`fleet_view`] -- the Fleet page: this host and every peer its |
| 45 | //! watcher reads, judged against the alarm's own thresholds. |
| 46 | //! - [`assets`] -- embedded HTML, CSS, JavaScript and image assets |
| 47 | //! served as the dashboard front end. |
| 48 | //! - [`handler`] -- HTTP dispatcher that maps `/admin/*` request paths |
| 49 | //! to the appropriate view or action. |
| 50 | //! |
| 51 | //! [Written with AI entirely](https://need2know.ai/entirely-ai/code)\ |
| 52 | //! Anthropic Claude |
| 53 | |
| 54 | pub mod assets; |
| 55 | pub mod audit; |
| 56 | pub mod auth; |
| 57 | pub mod fleet_view; |
| 58 | pub mod guard; |
| 59 | pub mod handler; |
| 60 | pub mod host_sampler; |
| 61 | pub mod local_listener; |
| 62 | pub mod ozone_view; |
| 63 | pub mod persist; |
| 64 | pub mod session; |
| 65 | pub mod signed_login; |
| 66 | pub mod state; |
| 67 | pub mod traffic; |
| 68 | |
| 69 | // ┌───────────────────────────────────────────────────────────────────────────┐ |
| 70 | // │ SCOPE CONSTANTS │ |
| 71 | // └───────────────────────────────────────────────────────────────────────────┘ |
| 72 | |
| 73 | pub const SCOPE_WILDCARD: &str = "*"; |
| 74 | pub const SCOPE_ADMIN: &str = "admin"; |
| 75 | pub const SCOPE_DASHBOARD_VIEW: &str = "dashboard.view"; |
| 76 | pub const SCOPE_DASHBOARD_ADMIN: &str = "dashboard.admin"; |
| 77 | |
| 78 | // ┌───────────────────────────────────────────────────────────────────────────┐ |
| 79 | // │ ADMIN PRINCIPAL │ |
| 80 | // └───────────────────────────────────────────────────────────────────────────┘ |
| 81 | |
| 82 | /// Identity and authorisation carried with every authenticated |
| 83 | /// dashboard request. |
| 84 | #[derive(Clone, Debug)] |
| 85 | pub struct AdminPrincipal { |
| 86 | pub name: String, // wallet admin that unlocked the session |
| 87 | // Snapshot taken at login and never refreshed, so rotating an admin's scopes |
| 88 | // takes effect only on their next login. |
| 89 | pub scopes: Vec<String>, |
| 90 | pub expires_at: u64, // unix seconds |
| 91 | } |
| 92 | |
| 93 | impl AdminPrincipal { |
| 94 | pub fn has_scope(&self, verb: &str) -> bool { |
| 95 | self.scopes.iter().any(|s| s == SCOPE_WILDCARD || s == verb) |
| 96 | } |
| 97 | |
| 98 | pub fn can_view_dashboard(&self) -> bool { |
| 99 | self.has_scope(SCOPE_DASHBOARD_VIEW) |
| 100 | || self.has_scope(SCOPE_DASHBOARD_ADMIN) |
| 101 | } |
| 102 | |
| 103 | /// Gates dashboard mutations, such as the address-guard whitelist and |
| 104 | /// blacklist actions. |
| 105 | pub fn can_admin_dashboard(&self) -> bool { |
| 106 | self.has_scope(SCOPE_DASHBOARD_ADMIN) |
| 107 | } |
| 108 | |
| 109 | /// Requires the CLI `admin` scope on top of a dashboard scope, so granting |
| 110 | /// dashboard login does not also grant the power to enrol more admins. |
| 111 | pub fn can_manage_admins(&self) -> bool { |
| 112 | self.has_scope(SCOPE_ADMIN) && self.can_view_dashboard() |
| 113 | } |
| 114 | } |