+21
.github/workflows/build.yml
+21
.github/workflows/build.yml
···
1
+
name: Build
2
+
3
+
on:
4
+
push:
5
+
tags:
6
+
- "reflector-v*.*.*"
7
+
8
+
jobs:
9
+
build:
10
+
runs-on: ubuntu-latest
11
+
permissions:
12
+
contents: write
13
+
14
+
steps:
15
+
- uses: actions/checkout@v4
16
+
- name: build reflector
17
+
run: cargo build --bin reflector --release && mv target/release/reflector target/release/reflector_amd64
18
+
- name: release
19
+
uses: softprops/action-gh-release@v2
20
+
with:
21
+
files: target/release/reflector_amd64
+1
-1
.github/workflows/checks.yml
+1
-1
.github/workflows/checks.yml
···
28
28
- name: get nightly toolchain for jetstream fmt
29
29
run: rustup toolchain install nightly --allow-downgrade -c rustfmt
30
30
- name: fmt
31
-
run: cargo fmt --package links --package constellation --package ufos --package spacedust --package who-am-i -- --check
31
+
run: cargo fmt --package links --package constellation --package ufos --package spacedust --package who-am-i --package slingshot --package pocket -- --check
32
32
- name: fmt jetstream (nightly)
33
33
run: cargo +nightly fmt --package jetstream -- --check
34
34
- name: clippy
+1487
-230
Cargo.lock
+1487
-230
Cargo.lock
···
24
24
checksum = "e89da841a80418a9b391ebaea17f5c112ffaaa96f621d2c285b5174da76b9011"
25
25
dependencies = [
26
26
"cfg-if",
27
+
"getrandom 0.2.15",
27
28
"once_cell",
28
29
"version_check",
29
30
"zerocopy 0.7.35",
···
122
123
checksum = "dde20b3d026af13f561bdd0f15edf01fc734f0dafcedbaf42bba506a9517f223"
123
124
124
125
[[package]]
126
+
name = "arc-swap"
127
+
version = "1.7.1"
128
+
source = "registry+https://github.com/rust-lang/crates.io-index"
129
+
checksum = "69f7f8c3906b62b754cd5326047894316021dcfe5a194c8ea52bdd94934a3457"
130
+
131
+
[[package]]
125
132
name = "arrayvec"
126
133
version = "0.7.6"
127
134
source = "registry+https://github.com/rust-lang/crates.io-index"
···
155
162
"proc-macro2",
156
163
"quote",
157
164
"serde",
158
-
"syn",
165
+
"syn 2.0.106",
159
166
]
160
167
161
168
[[package]]
···
174
181
]
175
182
176
183
[[package]]
184
+
name = "asn1-rs"
185
+
version = "0.7.1"
186
+
source = "registry+https://github.com/rust-lang/crates.io-index"
187
+
checksum = "56624a96882bb8c26d61312ae18cb45868e5a9992ea73c58e45c3101e56a1e60"
188
+
dependencies = [
189
+
"asn1-rs-derive",
190
+
"asn1-rs-impl",
191
+
"displaydoc",
192
+
"nom",
193
+
"num-traits",
194
+
"rusticata-macros",
195
+
"thiserror 2.0.16",
196
+
"time",
197
+
]
198
+
199
+
[[package]]
200
+
name = "asn1-rs-derive"
201
+
version = "0.6.0"
202
+
source = "registry+https://github.com/rust-lang/crates.io-index"
203
+
checksum = "3109e49b1e4909e9db6515a30c633684d68cdeaa252f215214cb4fa1a5bfee2c"
204
+
dependencies = [
205
+
"proc-macro2",
206
+
"quote",
207
+
"syn 2.0.106",
208
+
"synstructure",
209
+
]
210
+
211
+
[[package]]
212
+
name = "asn1-rs-impl"
213
+
version = "0.2.0"
214
+
source = "registry+https://github.com/rust-lang/crates.io-index"
215
+
checksum = "7b18050c2cd6fe86c3a76584ef5e0baf286d038cda203eb6223df2cc413565f7"
216
+
dependencies = [
217
+
"proc-macro2",
218
+
"quote",
219
+
"syn 2.0.106",
220
+
]
221
+
222
+
[[package]]
223
+
name = "async-channel"
224
+
version = "2.5.0"
225
+
source = "registry+https://github.com/rust-lang/crates.io-index"
226
+
checksum = "924ed96dd52d1b75e9c1a3e6275715fd320f5f9439fb5a4a11fa51f4221158d2"
227
+
dependencies = [
228
+
"concurrent-queue",
229
+
"event-listener-strategy",
230
+
"futures-core",
231
+
"pin-project-lite",
232
+
]
233
+
234
+
[[package]]
177
235
name = "async-compression"
178
236
version = "0.4.25"
179
237
source = "registry+https://github.com/rust-lang/crates.io-index"
···
216
274
dependencies = [
217
275
"proc-macro2",
218
276
"quote",
219
-
"syn",
277
+
"syn 2.0.106",
220
278
]
279
+
280
+
[[package]]
281
+
name = "async-task"
282
+
version = "4.7.1"
283
+
source = "registry+https://github.com/rust-lang/crates.io-index"
284
+
checksum = "8b75356056920673b02621b35afd0f7dda9306d03c79a30f5c56c44cf256e3de"
221
285
222
286
[[package]]
223
287
name = "async-trait"
···
227
291
dependencies = [
228
292
"proc-macro2",
229
293
"quote",
230
-
"syn",
294
+
"syn 2.0.106",
231
295
]
232
296
233
297
[[package]]
···
238
302
239
303
[[package]]
240
304
name = "atrium-api"
241
-
version = "0.25.3"
242
-
source = "git+https://github.com/uniphil/atrium?branch=fix%2Fnsid-allow-nonleading-name-digits#c4364f318d337bbc3e3e3aaf97c9f971e95f5f7e"
305
+
version = "0.25.4"
306
+
source = "registry+https://github.com/rust-lang/crates.io-index"
307
+
checksum = "46355d3245edc7b3160b2a45fe55d09a6963ebd3eee0252feb6b72fb0eb71463"
243
308
dependencies = [
244
-
"atrium-common 0.1.2 (git+https://github.com/uniphil/atrium?branch=fix%2Fnsid-allow-nonleading-name-digits)",
245
-
"atrium-xrpc 0.12.3 (git+https://github.com/uniphil/atrium?branch=fix%2Fnsid-allow-nonleading-name-digits)",
309
+
"atrium-common 0.1.2 (registry+https://github.com/rust-lang/crates.io-index)",
310
+
"atrium-xrpc 0.12.3 (registry+https://github.com/rust-lang/crates.io-index)",
246
311
"chrono",
247
312
"http",
248
313
"ipld-core",
···
252
317
"serde_bytes",
253
318
"serde_json",
254
319
"thiserror 1.0.69",
320
+
"tokio",
255
321
"trait-variant",
256
322
]
257
323
258
324
[[package]]
259
325
name = "atrium-api"
260
326
version = "0.25.4"
261
-
source = "registry+https://github.com/rust-lang/crates.io-index"
262
-
checksum = "46355d3245edc7b3160b2a45fe55d09a6963ebd3eee0252feb6b72fb0eb71463"
327
+
source = "git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace#80a355991ac9b48ba3f559d12aac74f071fc638c"
263
328
dependencies = [
264
-
"atrium-common 0.1.2 (registry+https://github.com/rust-lang/crates.io-index)",
265
-
"atrium-xrpc 0.12.3 (registry+https://github.com/rust-lang/crates.io-index)",
329
+
"atrium-common 0.1.2 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
330
+
"atrium-xrpc 0.12.3 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
266
331
"chrono",
267
332
"http",
268
333
"ipld-core",
···
294
359
[[package]]
295
360
name = "atrium-common"
296
361
version = "0.1.2"
297
-
source = "git+https://github.com/uniphil/atrium?branch=fix%2Fnsid-allow-nonleading-name-digits#c4364f318d337bbc3e3e3aaf97c9f971e95f5f7e"
362
+
source = "git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace#80a355991ac9b48ba3f559d12aac74f071fc638c"
298
363
dependencies = [
299
364
"dashmap",
300
365
"lru",
···
306
371
]
307
372
308
373
[[package]]
374
+
name = "atrium-crypto"
375
+
version = "0.1.2"
376
+
source = "registry+https://github.com/rust-lang/crates.io-index"
377
+
checksum = "73a3da430c71dd9006d61072c20771f264e5c498420a49c32305ceab8bd71955"
378
+
dependencies = [
379
+
"ecdsa",
380
+
"k256",
381
+
"multibase",
382
+
"p256",
383
+
"thiserror 1.0.69",
384
+
]
385
+
386
+
[[package]]
309
387
name = "atrium-identity"
310
388
version = "0.1.5"
311
389
source = "registry+https://github.com/rust-lang/crates.io-index"
312
390
checksum = "c9e2d42bb4dbea038f4f5f45e3af2a89d61a9894a75f06aa550b74a60d2be380"
313
391
dependencies = [
314
-
"atrium-api 0.25.4",
392
+
"atrium-api 0.25.4 (registry+https://github.com/rust-lang/crates.io-index)",
315
393
"atrium-common 0.1.2 (registry+https://github.com/rust-lang/crates.io-index)",
316
394
"atrium-xrpc 0.12.3 (registry+https://github.com/rust-lang/crates.io-index)",
317
395
"serde",
···
322
400
]
323
401
324
402
[[package]]
403
+
name = "atrium-identity"
404
+
version = "0.1.5"
405
+
source = "git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace#80a355991ac9b48ba3f559d12aac74f071fc638c"
406
+
dependencies = [
407
+
"atrium-api 0.25.4 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
408
+
"atrium-common 0.1.2 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
409
+
"atrium-xrpc 0.12.3 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
410
+
"serde",
411
+
"serde_html_form",
412
+
"serde_json",
413
+
"thiserror 1.0.69",
414
+
"trait-variant",
415
+
]
416
+
417
+
[[package]]
325
418
name = "atrium-oauth"
326
419
version = "0.1.3"
327
420
source = "registry+https://github.com/rust-lang/crates.io-index"
328
421
checksum = "ca22dc4eaf77fd9bf050b21192ac58cd654a437d28e000ec114ebd93a51d36f5"
329
422
dependencies = [
330
-
"atrium-api 0.25.4",
423
+
"atrium-api 0.25.4 (registry+https://github.com/rust-lang/crates.io-index)",
331
424
"atrium-common 0.1.2 (registry+https://github.com/rust-lang/crates.io-index)",
332
-
"atrium-identity",
425
+
"atrium-identity 0.1.5 (registry+https://github.com/rust-lang/crates.io-index)",
333
426
"atrium-xrpc 0.12.3 (registry+https://github.com/rust-lang/crates.io-index)",
334
427
"base64 0.22.1",
335
428
"chrono",
···
351
444
]
352
445
353
446
[[package]]
447
+
name = "atrium-oauth"
448
+
version = "0.1.3"
449
+
source = "git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace#80a355991ac9b48ba3f559d12aac74f071fc638c"
450
+
dependencies = [
451
+
"atrium-api 0.25.4 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
452
+
"atrium-common 0.1.2 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
453
+
"atrium-identity 0.1.5 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
454
+
"atrium-xrpc 0.12.3 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
455
+
"base64 0.22.1",
456
+
"chrono",
457
+
"dashmap",
458
+
"ecdsa",
459
+
"elliptic-curve",
460
+
"jose-jwa",
461
+
"jose-jwk",
462
+
"p256",
463
+
"rand 0.8.5",
464
+
"reqwest",
465
+
"serde",
466
+
"serde_html_form",
467
+
"serde_json",
468
+
"sha2",
469
+
"thiserror 1.0.69",
470
+
"tokio",
471
+
"trait-variant",
472
+
]
473
+
474
+
[[package]]
354
475
name = "atrium-xrpc"
355
476
version = "0.12.3"
356
477
source = "registry+https://github.com/rust-lang/crates.io-index"
···
367
488
[[package]]
368
489
name = "atrium-xrpc"
369
490
version = "0.12.3"
370
-
source = "git+https://github.com/uniphil/atrium?branch=fix%2Fnsid-allow-nonleading-name-digits#c4364f318d337bbc3e3e3aaf97c9f971e95f5f7e"
491
+
source = "git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace#80a355991ac9b48ba3f559d12aac74f071fc638c"
371
492
dependencies = [
372
493
"http",
373
494
"serde",
···
378
499
]
379
500
380
501
[[package]]
502
+
name = "auto_enums"
503
+
version = "0.8.7"
504
+
source = "registry+https://github.com/rust-lang/crates.io-index"
505
+
checksum = "9c170965892137a3a9aeb000b4524aa3cc022a310e709d848b6e1cdce4ab4781"
506
+
dependencies = [
507
+
"derive_utils",
508
+
"proc-macro2",
509
+
"quote",
510
+
"syn 2.0.106",
511
+
]
512
+
513
+
[[package]]
381
514
name = "autocfg"
382
515
version = "1.4.0"
383
516
source = "registry+https://github.com/rust-lang/crates.io-index"
···
470
603
"axum-core",
471
604
"bytes",
472
605
"cookie",
606
+
"form_urlencoded",
473
607
"futures-util",
474
608
"headers",
475
609
"http",
···
479
613
"pin-project-lite",
480
614
"rustversion",
481
615
"serde",
616
+
"serde_html_form",
617
+
"serde_path_to_error",
482
618
"tower",
483
619
"tower-layer",
484
620
"tower-service",
···
508
644
"axum",
509
645
"handlebars",
510
646
"serde",
511
-
"thiserror 2.0.12",
647
+
"thiserror 2.0.16",
512
648
]
513
649
514
650
[[package]]
···
613
749
"regex",
614
750
"rustc-hash 1.1.0",
615
751
"shlex",
616
-
"syn",
752
+
"syn 2.0.106",
617
753
"which",
618
754
]
619
755
···
632
768
"regex",
633
769
"rustc-hash 1.1.0",
634
770
"shlex",
635
-
"syn",
771
+
"syn 2.0.106",
636
772
]
637
773
638
774
[[package]]
···
650
786
"regex",
651
787
"rustc-hash 2.1.1",
652
788
"shlex",
653
-
"syn",
789
+
"syn 2.0.106",
790
+
]
791
+
792
+
[[package]]
793
+
name = "bitcoin-io"
794
+
version = "0.1.3"
795
+
source = "registry+https://github.com/rust-lang/crates.io-index"
796
+
checksum = "0b47c4ab7a93edb0c7198c5535ed9b52b63095f4e9b45279c6736cec4b856baf"
797
+
798
+
[[package]]
799
+
name = "bitcoin_hashes"
800
+
version = "0.14.0"
801
+
source = "registry+https://github.com/rust-lang/crates.io-index"
802
+
checksum = "bb18c03d0db0247e147a21a6faafd5a7eb851c743db062de72018b6b7e8e4d16"
803
+
dependencies = [
804
+
"bitcoin-io",
805
+
"hex-conservative",
654
806
]
655
807
656
808
[[package]]
···
710
862
711
863
[[package]]
712
864
name = "camino"
713
-
version = "1.1.9"
865
+
version = "1.2.1"
714
866
source = "registry+https://github.com/rust-lang/crates.io-index"
715
-
checksum = "8b96ec4966b5813e2c0507c1f86115c8c5abaadc3980879c3424042a02fd1ad3"
867
+
checksum = "276a59bf2b2c967788139340c9f0c5b12d7fd6630315c15c217e559de85d2609"
716
868
dependencies = [
717
-
"serde",
869
+
"serde_core",
718
870
]
719
871
720
872
[[package]]
···
787
939
]
788
940
789
941
[[package]]
942
+
name = "ciborium"
943
+
version = "0.2.2"
944
+
source = "registry+https://github.com/rust-lang/crates.io-index"
945
+
checksum = "42e69ffd6f0917f5c029256a24d0161db17cea3997d185db0d35926308770f0e"
946
+
dependencies = [
947
+
"ciborium-io",
948
+
"ciborium-ll",
949
+
"serde",
950
+
]
951
+
952
+
[[package]]
953
+
name = "ciborium-io"
954
+
version = "0.2.2"
955
+
source = "registry+https://github.com/rust-lang/crates.io-index"
956
+
checksum = "05afea1e0a06c9be33d539b876f1ce3692f4afea2cb41f740e7743225ed1c757"
957
+
958
+
[[package]]
959
+
name = "ciborium-ll"
960
+
version = "0.2.2"
961
+
source = "registry+https://github.com/rust-lang/crates.io-index"
962
+
checksum = "57663b653d948a338bfb3eeba9bb2fd5fcfaecb9e199e87e1eda4d9e8b240fd9"
963
+
dependencies = [
964
+
"ciborium-io",
965
+
"half",
966
+
]
967
+
968
+
[[package]]
790
969
name = "cid"
791
970
version = "0.11.1"
792
971
source = "registry+https://github.com/rust-lang/crates.io-index"
···
813
992
814
993
[[package]]
815
994
name = "clap"
816
-
version = "4.5.40"
995
+
version = "4.5.48"
817
996
source = "registry+https://github.com/rust-lang/crates.io-index"
818
-
checksum = "40b6887a1d8685cebccf115538db5c0efe625ccac9696ad45c409d96566e910f"
997
+
checksum = "e2134bb3ea021b78629caa971416385309e0131b351b25e01dc16fb54e1b5fae"
819
998
dependencies = [
820
999
"clap_builder",
821
1000
"clap_derive",
···
823
1002
824
1003
[[package]]
825
1004
name = "clap_builder"
826
-
version = "4.5.40"
1005
+
version = "4.5.48"
827
1006
source = "registry+https://github.com/rust-lang/crates.io-index"
828
-
checksum = "e0c66c08ce9f0c698cbce5c0279d0bb6ac936d8674174fe48f736533b964f59e"
1007
+
checksum = "c2ba64afa3c0a6df7fa517765e31314e983f51dda798ffba27b988194fb65dc9"
829
1008
dependencies = [
830
1009
"anstream",
831
1010
"anstyle",
832
1011
"clap_lex",
833
-
"strsim",
1012
+
"strsim 0.11.1",
834
1013
]
835
1014
836
1015
[[package]]
837
1016
name = "clap_derive"
838
-
version = "4.5.40"
1017
+
version = "4.5.47"
839
1018
source = "registry+https://github.com/rust-lang/crates.io-index"
840
-
checksum = "d2c7947ae4cc3d851207c1adb5b5e260ff0cca11446b1d6d1423788e442257ce"
1019
+
checksum = "bbfd7eae0b0f1a6e63d4b13c9c478de77c2eb546fba158ad50b4203dc24b9f9c"
841
1020
dependencies = [
842
1021
"heck",
843
1022
"proc-macro2",
844
1023
"quote",
845
-
"syn",
1024
+
"syn 2.0.106",
846
1025
]
847
1026
848
1027
[[package]]
···
872
1051
]
873
1052
874
1053
[[package]]
1054
+
name = "cmsketch"
1055
+
version = "0.2.2"
1056
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1057
+
checksum = "553c840ee51da812c6cd621f9f7e07dfb00a49f91283a8e6380c78cba4f61aba"
1058
+
dependencies = [
1059
+
"paste",
1060
+
]
1061
+
1062
+
[[package]]
875
1063
name = "colorchoice"
876
1064
version = "1.0.3"
877
1065
source = "registry+https://github.com/rust-lang/crates.io-index"
···
911
1099
"clap",
912
1100
"ctrlc",
913
1101
"flume",
914
-
"fs4",
1102
+
"fs4 0.12.0",
915
1103
"headers-accept",
916
1104
"links",
917
1105
"mediatype",
···
1043
1231
checksum = "d0a5c400df2834b80a4c3327b3aad3a4c4cd4de0629063962b03235697506a28"
1044
1232
1045
1233
[[package]]
1234
+
name = "crunchy"
1235
+
version = "0.2.4"
1236
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1237
+
checksum = "460fbee9c2c2f33933d720630a6a0bac33ba7053db5344fac858d4b8952d77d5"
1238
+
1239
+
[[package]]
1046
1240
name = "crypto-bigint"
1047
1241
version = "0.5.5"
1048
1242
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1076
1270
1077
1271
[[package]]
1078
1272
name = "darling"
1273
+
version = "0.14.4"
1274
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1275
+
checksum = "7b750cb3417fd1b327431a470f388520309479ab0bf5e323505daf0290cd3850"
1276
+
dependencies = [
1277
+
"darling_core 0.14.4",
1278
+
"darling_macro 0.14.4",
1279
+
]
1280
+
1281
+
[[package]]
1282
+
name = "darling"
1079
1283
version = "0.20.11"
1080
1284
source = "registry+https://github.com/rust-lang/crates.io-index"
1081
1285
checksum = "fc7f46116c46ff9ab3eb1597a45688b6715c6e628b5c133e288e709a29bcb4ee"
1082
1286
dependencies = [
1083
-
"darling_core",
1084
-
"darling_macro",
1287
+
"darling_core 0.20.11",
1288
+
"darling_macro 0.20.11",
1289
+
]
1290
+
1291
+
[[package]]
1292
+
name = "darling_core"
1293
+
version = "0.14.4"
1294
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1295
+
checksum = "109c1ca6e6b7f82cc233a97004ea8ed7ca123a9af07a8230878fcfda9b158bf0"
1296
+
dependencies = [
1297
+
"fnv",
1298
+
"ident_case",
1299
+
"proc-macro2",
1300
+
"quote",
1301
+
"strsim 0.10.0",
1302
+
"syn 1.0.109",
1085
1303
]
1086
1304
1087
1305
[[package]]
···
1094
1312
"ident_case",
1095
1313
"proc-macro2",
1096
1314
"quote",
1097
-
"strsim",
1098
-
"syn",
1315
+
"strsim 0.11.1",
1316
+
"syn 2.0.106",
1317
+
]
1318
+
1319
+
[[package]]
1320
+
name = "darling_macro"
1321
+
version = "0.14.4"
1322
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1323
+
checksum = "a4aab4dbc9f7611d8b55048a3a16d2d010c2c8334e46304b40ac1cc14bf3b48e"
1324
+
dependencies = [
1325
+
"darling_core 0.14.4",
1326
+
"quote",
1327
+
"syn 1.0.109",
1099
1328
]
1100
1329
1101
1330
[[package]]
···
1104
1333
source = "registry+https://github.com/rust-lang/crates.io-index"
1105
1334
checksum = "fc34b93ccb385b40dc71c6fceac4b2ad23662c7eeb248cf10d529b7e055b6ead"
1106
1335
dependencies = [
1107
-
"darling_core",
1336
+
"darling_core 0.20.11",
1108
1337
"quote",
1109
-
"syn",
1338
+
"syn 2.0.106",
1110
1339
]
1111
1340
1112
1341
[[package]]
···
1146
1375
checksum = "18e4fdb82bd54a12e42fb58a800dcae6b9e13982238ce2296dc3570b92148e1f"
1147
1376
dependencies = [
1148
1377
"data-encoding",
1149
-
"syn",
1378
+
"syn 2.0.106",
1150
1379
]
1151
1380
1152
1381
[[package]]
···
1162
1391
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
1163
1392
dependencies = [
1164
1393
"const-oid",
1394
+
"pem-rfc7468",
1165
1395
"zeroize",
1166
1396
]
1167
1397
1168
1398
[[package]]
1399
+
name = "der-parser"
1400
+
version = "10.0.0"
1401
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1402
+
checksum = "07da5016415d5a3c4dd39b11ed26f915f52fc4e0dc197d87908bc916e51bc1a6"
1403
+
dependencies = [
1404
+
"asn1-rs",
1405
+
"displaydoc",
1406
+
"nom",
1407
+
"num-bigint",
1408
+
"num-traits",
1409
+
"rusticata-macros",
1410
+
]
1411
+
1412
+
[[package]]
1169
1413
name = "deranged"
1170
1414
version = "0.4.0"
1171
1415
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1190
1434
source = "registry+https://github.com/rust-lang/crates.io-index"
1191
1435
checksum = "2d5bcf7b024d6835cfb3d473887cd966994907effbe9227e8c8219824d06c4e8"
1192
1436
dependencies = [
1193
-
"darling",
1437
+
"darling 0.20.11",
1194
1438
"proc-macro2",
1195
1439
"quote",
1196
-
"syn",
1440
+
"syn 2.0.106",
1197
1441
]
1198
1442
1199
1443
[[package]]
···
1203
1447
checksum = "ab63b0e2bf4d5928aff72e83a7dace85d7bba5fe12dcc3c5a572d78caffd3f3c"
1204
1448
dependencies = [
1205
1449
"derive_builder_core",
1206
-
"syn",
1450
+
"syn 2.0.106",
1451
+
]
1452
+
1453
+
[[package]]
1454
+
name = "derive_more"
1455
+
version = "2.0.1"
1456
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1457
+
checksum = "093242cf7570c207c83073cf82f79706fe7b8317e98620a47d5be7c3d8497678"
1458
+
dependencies = [
1459
+
"derive_more-impl",
1460
+
]
1461
+
1462
+
[[package]]
1463
+
name = "derive_more-impl"
1464
+
version = "2.0.1"
1465
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1466
+
checksum = "bda628edc44c4bb645fbe0f758797143e4e07926f7ebf4e9bdfbd3d2ce621df3"
1467
+
dependencies = [
1468
+
"proc-macro2",
1469
+
"quote",
1470
+
"syn 2.0.106",
1471
+
"unicode-xid",
1472
+
]
1473
+
1474
+
[[package]]
1475
+
name = "derive_utils"
1476
+
version = "0.15.0"
1477
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1478
+
checksum = "ccfae181bab5ab6c5478b2ccb69e4c68a02f8c3ec72f6616bfec9dbc599d2ee0"
1479
+
dependencies = [
1480
+
"proc-macro2",
1481
+
"quote",
1482
+
"syn 2.0.106",
1207
1483
]
1208
1484
1209
1485
[[package]]
···
1247
1523
dependencies = [
1248
1524
"proc-macro2",
1249
1525
"quote",
1250
-
"syn",
1526
+
"syn 2.0.106",
1251
1527
]
1252
1528
1253
1529
[[package]]
···
1257
1533
checksum = "c0d05e1c0dbad51b52c38bda7adceef61b9efc2baf04acfe8726a8c4630a6f57"
1258
1534
1259
1535
[[package]]
1536
+
name = "downcast-rs"
1537
+
version = "1.2.1"
1538
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1539
+
checksum = "75b325c5dbd37f80359721ad39aca5a29fb04c89279657cffdda8736d0c0b9d2"
1540
+
1541
+
[[package]]
1260
1542
name = "dropshot"
1261
-
version = "0.16.2"
1543
+
version = "0.16.3"
1262
1544
source = "registry+https://github.com/rust-lang/crates.io-index"
1263
-
checksum = "50e8fed669e35e757646ad10f97c4d26dd22cce3da689b307954f7000d2719d0"
1545
+
checksum = "eedf902e40c1024b8ed9ca16378a54e9655cdf0e698245ba82d81a3778dcbc54"
1264
1546
dependencies = [
1265
1547
"async-stream",
1266
1548
"async-trait",
···
1277
1559
"http-body-util",
1278
1560
"hyper",
1279
1561
"hyper-util",
1280
-
"indexmap 2.9.0",
1562
+
"indexmap 2.11.4",
1281
1563
"multer",
1282
1564
"openapiv3",
1283
1565
"paste",
···
1297
1579
"slog-bunyan",
1298
1580
"slog-json",
1299
1581
"slog-term",
1300
-
"thiserror 2.0.12",
1582
+
"thiserror 2.0.16",
1301
1583
"tokio",
1302
1584
"tokio-rustls 0.25.0",
1303
-
"toml",
1585
+
"toml 0.9.7",
1304
1586
"uuid",
1305
1587
"version_check",
1306
1588
"waitgroup",
···
1308
1590
1309
1591
[[package]]
1310
1592
name = "dropshot_endpoint"
1311
-
version = "0.16.2"
1593
+
version = "0.16.4"
1312
1594
source = "registry+https://github.com/rust-lang/crates.io-index"
1313
-
checksum = "acebb687581abdeaa2c89fa448818a5f803b0e68e5d7e7a1cf585a8f3c5c57ac"
1595
+
checksum = "89d09440e73a9dcf8a0f7fbd6ab889a7751d59f0fe76e5082a0a6d5623ec6da3"
1314
1596
dependencies = [
1315
1597
"heck",
1316
1598
"proc-macro2",
···
1318
1600
"semver",
1319
1601
"serde",
1320
1602
"serde_tokenstream",
1321
-
"syn",
1603
+
"syn 2.0.106",
1322
1604
]
1323
1605
1324
1606
[[package]]
···
1344
1626
"elliptic-curve",
1345
1627
"rfc6979",
1346
1628
"signature",
1629
+
"spki",
1347
1630
]
1348
1631
1349
1632
[[package]]
···
1364
1647
"ff",
1365
1648
"generic-array",
1366
1649
"group",
1650
+
"pem-rfc7468",
1651
+
"pkcs8",
1367
1652
"rand_core 0.6.4",
1368
1653
"sec1",
1369
1654
"subtle",
···
1388
1673
"heck",
1389
1674
"proc-macro2",
1390
1675
"quote",
1391
-
"syn",
1676
+
"syn 2.0.106",
1392
1677
]
1393
1678
1394
1679
[[package]]
···
1400
1685
"once_cell",
1401
1686
"proc-macro2",
1402
1687
"quote",
1403
-
"syn",
1688
+
"syn 2.0.106",
1404
1689
]
1405
1690
1406
1691
[[package]]
···
1464
1749
]
1465
1750
1466
1751
[[package]]
1752
+
name = "fallible-iterator"
1753
+
version = "0.3.0"
1754
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1755
+
checksum = "2acce4a10f12dc2fb14a218589d4f1f62ef011b2d0cc4b3cb1bba8e94da14649"
1756
+
1757
+
[[package]]
1758
+
name = "fallible-streaming-iterator"
1759
+
version = "0.1.9"
1760
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1761
+
checksum = "7360491ce676a36bf9bb3c56c1aa791658183a54d2744120f27285738d90465a"
1762
+
1763
+
[[package]]
1467
1764
name = "fastrand"
1468
1765
version = "2.3.0"
1469
1766
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1481
1778
1482
1779
[[package]]
1483
1780
name = "fjall"
1484
-
version = "2.8.0"
1781
+
version = "2.11.2"
1485
1782
source = "registry+https://github.com/rust-lang/crates.io-index"
1486
-
checksum = "26b2ced3483989a62b3533c9f99054d73b527c6c0045cf22b00fe87956f1a46f"
1783
+
checksum = "0b25ad44cd4360a0448a9b5a0a6f1c7a621101cca4578706d43c9a821418aebc"
1784
+
dependencies = [
1785
+
"byteorder",
1786
+
"byteview",
1787
+
"dashmap",
1788
+
"log",
1789
+
"lsm-tree",
1790
+
"path-absolutize",
1791
+
"std-semaphore",
1792
+
"tempfile",
1793
+
"xxhash-rust",
1794
+
]
1795
+
1796
+
[[package]]
1797
+
name = "fjall"
1798
+
version = "2.11.2"
1799
+
source = "git+https://github.com/fjall-rs/fjall.git#42d811f7c8cc9004407d520d37d2a1d8d246c03d"
1487
1800
dependencies = [
1488
1801
"byteorder",
1489
1802
"byteview",
···
1522
1835
source = "registry+https://github.com/rust-lang/crates.io-index"
1523
1836
checksum = "da0e4dd2a88388a1f4ccc7c9ce104604dab68d9f408dc34cd45823d5a9069095"
1524
1837
dependencies = [
1838
+
"futures-core",
1839
+
"futures-sink",
1840
+
"nanorand",
1525
1841
"spin",
1526
1842
]
1527
1843
···
1562
1878
]
1563
1879
1564
1880
[[package]]
1881
+
name = "foyer"
1882
+
version = "0.18.0"
1883
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1884
+
checksum = "0b4d8e96374206ff1b4265f2e2e6e1f80bc3048957b2a1e7fdeef929d68f318f"
1885
+
dependencies = [
1886
+
"equivalent",
1887
+
"foyer-common",
1888
+
"foyer-memory",
1889
+
"foyer-storage",
1890
+
"madsim-tokio",
1891
+
"mixtrics",
1892
+
"pin-project",
1893
+
"serde",
1894
+
"thiserror 2.0.16",
1895
+
"tokio",
1896
+
"tracing",
1897
+
]
1898
+
1899
+
[[package]]
1900
+
name = "foyer-common"
1901
+
version = "0.18.0"
1902
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1903
+
checksum = "911b8e3f23d5fe55b0b240f75af1d2fa5cb7261d3f9b38ef1c57bbc9f0449317"
1904
+
dependencies = [
1905
+
"bincode 1.3.3",
1906
+
"bytes",
1907
+
"cfg-if",
1908
+
"itertools 0.14.0",
1909
+
"madsim-tokio",
1910
+
"mixtrics",
1911
+
"parking_lot",
1912
+
"pin-project",
1913
+
"serde",
1914
+
"thiserror 2.0.16",
1915
+
"tokio",
1916
+
"twox-hash",
1917
+
]
1918
+
1919
+
[[package]]
1920
+
name = "foyer-intrusive-collections"
1921
+
version = "0.10.0-dev"
1922
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1923
+
checksum = "6e4fee46bea69e0596130e3210e65d3424e0ac1e6df3bde6636304bdf1ca4a3b"
1924
+
dependencies = [
1925
+
"memoffset",
1926
+
]
1927
+
1928
+
[[package]]
1929
+
name = "foyer-memory"
1930
+
version = "0.18.0"
1931
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1932
+
checksum = "506883d5a8500dea1b1662f7180f3534bdcbfa718d3253db7179552ef83612fa"
1933
+
dependencies = [
1934
+
"arc-swap",
1935
+
"bitflags",
1936
+
"cmsketch",
1937
+
"equivalent",
1938
+
"foyer-common",
1939
+
"foyer-intrusive-collections",
1940
+
"hashbrown 0.15.2",
1941
+
"itertools 0.14.0",
1942
+
"madsim-tokio",
1943
+
"mixtrics",
1944
+
"parking_lot",
1945
+
"pin-project",
1946
+
"serde",
1947
+
"thiserror 2.0.16",
1948
+
"tokio",
1949
+
"tracing",
1950
+
]
1951
+
1952
+
[[package]]
1953
+
name = "foyer-storage"
1954
+
version = "0.18.0"
1955
+
source = "registry+https://github.com/rust-lang/crates.io-index"
1956
+
checksum = "1ba8403a54a2f2032fb647e49c442e5feeb33f3989f7024f1b178341a016f06d"
1957
+
dependencies = [
1958
+
"allocator-api2",
1959
+
"anyhow",
1960
+
"auto_enums",
1961
+
"bytes",
1962
+
"equivalent",
1963
+
"flume",
1964
+
"foyer-common",
1965
+
"foyer-memory",
1966
+
"fs4 0.13.1",
1967
+
"futures-core",
1968
+
"futures-util",
1969
+
"itertools 0.14.0",
1970
+
"libc",
1971
+
"lz4",
1972
+
"madsim-tokio",
1973
+
"ordered_hash_map",
1974
+
"parking_lot",
1975
+
"paste",
1976
+
"pin-project",
1977
+
"rand 0.9.1",
1978
+
"serde",
1979
+
"thiserror 2.0.16",
1980
+
"tokio",
1981
+
"tracing",
1982
+
"twox-hash",
1983
+
"zstd",
1984
+
]
1985
+
1986
+
[[package]]
1565
1987
name = "fs4"
1566
1988
version = "0.12.0"
1567
1989
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1572
1994
]
1573
1995
1574
1996
[[package]]
1997
+
name = "fs4"
1998
+
version = "0.13.1"
1999
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2000
+
checksum = "8640e34b88f7652208ce9e88b1a37a2ae95227d84abec377ccd3c5cfeb141ed4"
2001
+
dependencies = [
2002
+
"rustix 1.0.5",
2003
+
"windows-sys 0.59.0",
2004
+
]
2005
+
2006
+
[[package]]
1575
2007
name = "fs_extra"
1576
2008
version = "1.3.0"
1577
2009
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1633
2065
dependencies = [
1634
2066
"proc-macro2",
1635
2067
"quote",
1636
-
"syn",
2068
+
"syn 2.0.106",
1637
2069
]
1638
2070
1639
2071
[[package]]
···
1710
2142
checksum = "26145e563e54f2cadc477553f1ec5ee650b00862f0a58bcd12cbdc5f0ea2d2f4"
1711
2143
dependencies = [
1712
2144
"cfg-if",
2145
+
"js-sys",
1713
2146
"libc",
1714
2147
"r-efi",
1715
2148
"wasi 0.14.2+wasi-0.2.4",
2149
+
"wasm-bindgen",
1716
2150
]
1717
2151
1718
2152
[[package]]
···
1756
2190
"futures-core",
1757
2191
"futures-sink",
1758
2192
"http",
1759
-
"indexmap 2.9.0",
2193
+
"indexmap 2.11.4",
1760
2194
"slab",
1761
2195
"tokio",
1762
2196
"tokio-util",
···
1764
2198
]
1765
2199
1766
2200
[[package]]
2201
+
name = "half"
2202
+
version = "2.6.0"
2203
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2204
+
checksum = "459196ed295495a68f7d7fe1d84f6c4b7ff0e21fe3017b2f283c6fac3ad803c9"
2205
+
dependencies = [
2206
+
"cfg-if",
2207
+
"crunchy",
2208
+
]
2209
+
2210
+
[[package]]
1767
2211
name = "handlebars"
1768
2212
version = "6.3.2"
1769
2213
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1776
2220
"pest_derive",
1777
2221
"serde",
1778
2222
"serde_json",
1779
-
"thiserror 2.0.12",
2223
+
"thiserror 2.0.16",
1780
2224
"walkdir",
1781
2225
]
1782
2226
···
1788
2232
1789
2233
[[package]]
1790
2234
name = "hashbrown"
2235
+
version = "0.13.2"
2236
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2237
+
checksum = "43a3c133739dddd0d2990f9a4bdf8eb4b21ef50e4851ca85ab661199821d510e"
2238
+
dependencies = [
2239
+
"ahash",
2240
+
]
2241
+
2242
+
[[package]]
2243
+
name = "hashbrown"
1791
2244
version = "0.14.5"
1792
2245
source = "registry+https://github.com/rust-lang/crates.io-index"
1793
2246
checksum = "e5274423e17b7c9fc20b6e7e208532f9b19825d82dfd615708b70edd83df41f1"
···
1801
2254
"allocator-api2",
1802
2255
"equivalent",
1803
2256
"foldhash",
2257
+
]
2258
+
2259
+
[[package]]
2260
+
name = "hashlink"
2261
+
version = "0.10.0"
2262
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2263
+
checksum = "7382cf6263419f2d8df38c55d7da83da5c18aef87fc7a7fc1fb1e344edfe14c1"
2264
+
dependencies = [
2265
+
"hashbrown 0.15.2",
1804
2266
]
1805
2267
1806
2268
[[package]]
···
1857
2319
checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70"
1858
2320
1859
2321
[[package]]
2322
+
name = "hex-conservative"
2323
+
version = "0.2.1"
2324
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2325
+
checksum = "5313b072ce3c597065a808dbf612c4c8e8590bdbf8b579508bf7a762c5eae6cd"
2326
+
dependencies = [
2327
+
"arrayvec",
2328
+
]
2329
+
2330
+
[[package]]
1860
2331
name = "hickory-proto"
1861
2332
version = "0.25.2"
1862
2333
source = "registry+https://github.com/rust-lang/crates.io-index"
···
1874
2345
"once_cell",
1875
2346
"rand 0.9.1",
1876
2347
"ring",
1877
-
"thiserror 2.0.12",
2348
+
"thiserror 2.0.16",
1878
2349
"tinyvec",
1879
2350
"tokio",
1880
2351
"tracing",
···
1897
2368
"rand 0.9.1",
1898
2369
"resolv-conf",
1899
2370
"smallvec",
1900
-
"thiserror 2.0.12",
2371
+
"thiserror 2.0.16",
1901
2372
"tokio",
1902
2373
"tracing",
1903
2374
]
···
2027
2498
"http",
2028
2499
"hyper",
2029
2500
"hyper-util",
2030
-
"rustls 0.23.28",
2501
+
"rustls 0.23.31",
2031
2502
"rustls-native-certs",
2032
2503
"rustls-pki-types",
2033
2504
"tokio",
···
2053
2524
2054
2525
[[package]]
2055
2526
name = "hyper-util"
2056
-
version = "0.1.14"
2527
+
version = "0.1.16"
2057
2528
source = "registry+https://github.com/rust-lang/crates.io-index"
2058
-
checksum = "dc2fdfdbff08affe55bb779f33b053aa1fe5dd5b54c257343c17edfa55711bdb"
2529
+
checksum = "8d9b05277c7e8da2c93a568989bb6207bef0112e8d17df7a6eda4a3cf143bc5e"
2059
2530
dependencies = [
2060
2531
"base64 0.22.1",
2061
2532
"bytes",
···
2069
2540
"libc",
2070
2541
"percent-encoding",
2071
2542
"pin-project-lite",
2072
-
"socket2",
2543
+
"socket2 0.6.0",
2073
2544
"system-configuration",
2074
2545
"tokio",
2075
2546
"tower-service",
···
2089
2560
"js-sys",
2090
2561
"log",
2091
2562
"wasm-bindgen",
2092
-
"windows-core 0.61.0",
2563
+
"windows-core",
2093
2564
]
2094
2565
2095
2566
[[package]]
···
2216
2687
dependencies = [
2217
2688
"proc-macro2",
2218
2689
"quote",
2219
-
"syn",
2690
+
"syn 2.0.106",
2220
2691
]
2221
2692
2222
2693
[[package]]
···
2259
2730
2260
2731
[[package]]
2261
2732
name = "indexmap"
2262
-
version = "2.9.0"
2733
+
version = "2.11.4"
2263
2734
source = "registry+https://github.com/rust-lang/crates.io-index"
2264
-
checksum = "cea70ddb795996207ad57735b50c5982d8844f38ba9ee5f1aedcfb708a2aa11e"
2735
+
checksum = "4b0f83760fb341a774ed326568e19f5a863af4a952def8c39f9ab92fd95b88e5"
2265
2736
dependencies = [
2266
2737
"equivalent",
2267
2738
"hashbrown 0.15.2",
2268
2739
"serde",
2740
+
"serde_core",
2269
2741
]
2270
2742
2271
2743
[[package]]
···
2275
2747
checksum = "11274e5e8e89b8607cfedc2910b6626e998779b48a019151c7604d0adcb86ac6"
2276
2748
dependencies = [
2277
2749
"compare",
2750
+
]
2751
+
2752
+
[[package]]
2753
+
name = "io-uring"
2754
+
version = "0.7.9"
2755
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2756
+
checksum = "d93587f37623a1a17d94ef2bc9ada592f5465fe7732084ab7beefabe5c77c0c4"
2757
+
dependencies = [
2758
+
"bitflags",
2759
+
"cfg-if",
2760
+
"libc",
2278
2761
]
2279
2762
2280
2763
[[package]]
···
2283
2766
source = "registry+https://github.com/rust-lang/crates.io-index"
2284
2767
checksum = "b58db92f96b720de98181bbbe63c831e87005ab460c1bf306eb2622b4707997f"
2285
2768
dependencies = [
2286
-
"socket2",
2769
+
"socket2 0.5.9",
2287
2770
"widestring",
2288
2771
"windows-sys 0.48.0",
2289
2772
"winreg",
···
2352
2835
]
2353
2836
2354
2837
[[package]]
2838
+
name = "itertools"
2839
+
version = "0.14.0"
2840
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2841
+
checksum = "2b192c782037fadd9cfa75548310488aabdbf3d2da73885b31bd0abd03351285"
2842
+
dependencies = [
2843
+
"either",
2844
+
]
2845
+
2846
+
[[package]]
2355
2847
name = "itoa"
2356
2848
version = "1.0.15"
2357
2849
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2363
2855
dependencies = [
2364
2856
"anyhow",
2365
2857
"async-trait",
2366
-
"atrium-api 0.25.3",
2858
+
"atrium-api 0.25.4 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
2367
2859
"chrono",
2368
2860
"clap",
2369
2861
"futures-util",
···
2371
2863
"metrics",
2372
2864
"serde",
2373
2865
"serde_json",
2374
-
"thiserror 2.0.12",
2866
+
"thiserror 2.0.16",
2375
2867
"tokio",
2376
2868
"tokio-tungstenite 0.26.2",
2377
2869
"url",
···
2399
2891
dependencies = [
2400
2892
"proc-macro2",
2401
2893
"quote",
2402
-
"syn",
2894
+
"syn 2.0.106",
2403
2895
]
2404
2896
2405
2897
[[package]]
···
2442
2934
"jose-b64",
2443
2935
"jose-jwa",
2444
2936
"p256",
2937
+
"p384",
2938
+
"rsa",
2445
2939
"serde",
2446
2940
"zeroize",
2447
2941
]
···
2472
2966
]
2473
2967
2474
2968
[[package]]
2969
+
name = "jwt-compact"
2970
+
version = "0.9.0-beta.1"
2971
+
source = "git+https://github.com/fatfingers23/jwt-compact.git#aed088b8ff5ad44ef2785c453f6a4b7916728b1c"
2972
+
dependencies = [
2973
+
"anyhow",
2974
+
"base64ct",
2975
+
"chrono",
2976
+
"ciborium",
2977
+
"hmac",
2978
+
"lazy_static",
2979
+
"rand_core 0.6.4",
2980
+
"secp256k1",
2981
+
"serde",
2982
+
"serde_json",
2983
+
"sha2",
2984
+
"smallvec",
2985
+
"subtle",
2986
+
"zeroize",
2987
+
]
2988
+
2989
+
[[package]]
2990
+
name = "k256"
2991
+
version = "0.13.4"
2992
+
source = "registry+https://github.com/rust-lang/crates.io-index"
2993
+
checksum = "f6e3919bbaa2945715f0bb6d3934a173d1e9a59ac23767fbaaef277265a7411b"
2994
+
dependencies = [
2995
+
"cfg-if",
2996
+
"ecdsa",
2997
+
"elliptic-curve",
2998
+
"sha2",
2999
+
]
3000
+
3001
+
[[package]]
2475
3002
name = "langtag"
2476
3003
version = "0.3.4"
2477
3004
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2485
3012
version = "1.5.0"
2486
3013
source = "registry+https://github.com/rust-lang/crates.io-index"
2487
3014
checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe"
3015
+
dependencies = [
3016
+
"spin",
3017
+
]
2488
3018
2489
3019
[[package]]
2490
3020
name = "lazycell"
···
2494
3024
2495
3025
[[package]]
2496
3026
name = "libc"
2497
-
version = "0.2.171"
3027
+
version = "0.2.174"
2498
3028
source = "registry+https://github.com/rust-lang/crates.io-index"
2499
-
checksum = "c19937216e9d3aa9956d9bb8dfc0b0c8beb6058fc4f7a4dc4d850edf86a237d6"
3029
+
checksum = "1171693293099992e19cddea4e8b849964e9846f4acee11b3948bcc337be8776"
2500
3030
2501
3031
[[package]]
2502
3032
name = "libfuzzer-sys"
···
2561
3091
]
2562
3092
2563
3093
[[package]]
3094
+
name = "libsqlite3-sys"
3095
+
version = "0.35.0"
3096
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3097
+
checksum = "133c182a6a2c87864fe97778797e46c7e999672690dc9fa3ee8e241aa4a9c13f"
3098
+
dependencies = [
3099
+
"pkg-config",
3100
+
"vcpkg",
3101
+
]
3102
+
3103
+
[[package]]
2564
3104
name = "libz-sys"
2565
3105
version = "1.1.22"
2566
3106
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2578
3118
"anyhow",
2579
3119
"fluent-uri",
2580
3120
"nom",
2581
-
"thiserror 2.0.12",
3121
+
"thiserror 2.0.16",
2582
3122
"tinyjson",
2583
3123
]
2584
3124
···
2612
3152
2613
3153
[[package]]
2614
3154
name = "log"
2615
-
version = "0.4.27"
3155
+
version = "0.4.28"
2616
3156
source = "registry+https://github.com/rust-lang/crates.io-index"
2617
-
checksum = "13dc2df351e3202783a1fe0d44375f7295ffb4049267b0f3018346dc122a1d94"
3157
+
checksum = "34080505efa8e45a4b816c349525ebe327ceaa8559756f0356cba97ef3bf7432"
2618
3158
2619
3159
[[package]]
2620
3160
name = "loom"
···
2639
3179
]
2640
3180
2641
3181
[[package]]
3182
+
name = "lru-slab"
3183
+
version = "0.1.2"
3184
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3185
+
checksum = "112b39cec0b298b6c1999fee3e31427f74f676e4cb9879ed1a121b43661a4154"
3186
+
3187
+
[[package]]
2642
3188
name = "lsm-tree"
2643
-
version = "2.8.0"
3189
+
version = "2.10.2"
2644
3190
source = "registry+https://github.com/rust-lang/crates.io-index"
2645
-
checksum = "d0a63a5e98a38b51765274137d8aedfbd848da5f4d016867e186b673fcc06a8c"
3191
+
checksum = "55b6d7475a8dd22e749186968daacf8e2a77932b061b1bd263157987bbfc0c6c"
2646
3192
dependencies = [
2647
3193
"byteorder",
2648
3194
"crossbeam-skiplist",
···
2660
3206
"value-log",
2661
3207
"varint-rs",
2662
3208
"xxhash-rust",
3209
+
]
3210
+
3211
+
[[package]]
3212
+
name = "lz4"
3213
+
version = "1.28.1"
3214
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3215
+
checksum = "a20b523e860d03443e98350ceaac5e71c6ba89aea7d960769ec3ce37f4de5af4"
3216
+
dependencies = [
3217
+
"lz4-sys",
2663
3218
]
2664
3219
2665
3220
[[package]]
···
2688
3243
]
2689
3244
2690
3245
[[package]]
3246
+
name = "madsim"
3247
+
version = "0.2.32"
3248
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3249
+
checksum = "db6694555643da293dfb89e33c2880a13b62711d64b6588bc7df6ce4110b27f1"
3250
+
dependencies = [
3251
+
"ahash",
3252
+
"async-channel",
3253
+
"async-stream",
3254
+
"async-task",
3255
+
"bincode 1.3.3",
3256
+
"bytes",
3257
+
"downcast-rs",
3258
+
"futures-util",
3259
+
"lazy_static",
3260
+
"libc",
3261
+
"madsim-macros",
3262
+
"naive-timer",
3263
+
"panic-message",
3264
+
"rand 0.8.5",
3265
+
"rand_xoshiro 0.6.0",
3266
+
"rustversion",
3267
+
"serde",
3268
+
"spin",
3269
+
"tokio",
3270
+
"tokio-util",
3271
+
"toml 0.8.23",
3272
+
"tracing",
3273
+
"tracing-subscriber",
3274
+
]
3275
+
3276
+
[[package]]
3277
+
name = "madsim-macros"
3278
+
version = "0.2.12"
3279
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3280
+
checksum = "f3d248e97b1a48826a12c3828d921e8548e714394bf17274dd0a93910dc946e1"
3281
+
dependencies = [
3282
+
"darling 0.14.4",
3283
+
"proc-macro2",
3284
+
"quote",
3285
+
"syn 1.0.109",
3286
+
]
3287
+
3288
+
[[package]]
3289
+
name = "madsim-tokio"
3290
+
version = "0.2.30"
3291
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3292
+
checksum = "7d3eb2acc57c82d21d699119b859e2df70a91dbdb84734885a1e72be83bdecb5"
3293
+
dependencies = [
3294
+
"madsim",
3295
+
"spin",
3296
+
"tokio",
3297
+
]
3298
+
3299
+
[[package]]
2691
3300
name = "match_cfg"
2692
3301
version = "0.1.0"
2693
3302
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2695
3304
2696
3305
[[package]]
2697
3306
name = "matchers"
2698
-
version = "0.1.0"
3307
+
version = "0.2.0"
2699
3308
source = "registry+https://github.com/rust-lang/crates.io-index"
2700
-
checksum = "8263075bb86c5a1b1427b5ae862e8889656f126e9f77c484496e8b47cf5c5558"
3309
+
checksum = "d1525a2a28c7f4fa0fc98bb91ae755d1e2d1505079e05539e35bc876b5d65ae9"
2701
3310
dependencies = [
2702
-
"regex-automata 0.1.10",
3311
+
"regex-automata",
2703
3312
]
2704
3313
2705
3314
[[package]]
···
2721
3330
checksum = "78ca9ab1a0babb1e7d5695e3530886289c18cf2f87ec19a575a0abdce112e3a3"
2722
3331
2723
3332
[[package]]
3333
+
name = "memoffset"
3334
+
version = "0.9.1"
3335
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3336
+
checksum = "488016bfae457b036d996092f6cb448677611ce4449e970ceaf42695203f218a"
3337
+
dependencies = [
3338
+
"autocfg",
3339
+
]
3340
+
3341
+
[[package]]
2724
3342
name = "metrics"
2725
3343
version = "0.24.2"
2726
3344
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2740
3358
"http-body-util",
2741
3359
"hyper",
2742
3360
"hyper-util",
2743
-
"indexmap 2.9.0",
3361
+
"indexmap 2.11.4",
2744
3362
"ipnet",
2745
3363
"metrics",
2746
3364
"metrics-util 0.19.0",
···
2761
3379
"hyper",
2762
3380
"hyper-rustls",
2763
3381
"hyper-util",
2764
-
"indexmap 2.9.0",
3382
+
"indexmap 2.11.4",
2765
3383
"ipnet",
2766
3384
"metrics",
2767
3385
"metrics-util 0.20.0",
2768
3386
"quanta",
2769
-
"thiserror 2.0.12",
3387
+
"thiserror 2.0.16",
2770
3388
"tokio",
2771
3389
"tracing",
2772
3390
]
···
2862
3480
]
2863
3481
2864
3482
[[package]]
3483
+
name = "mixtrics"
3484
+
version = "0.2.0"
3485
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3486
+
checksum = "adbcddf5a90b959eea97ae505e0391f5c6dd411fbf546d43b9c59ad1c3bd4391"
3487
+
dependencies = [
3488
+
"itertools 0.14.0",
3489
+
"parking_lot",
3490
+
]
3491
+
3492
+
[[package]]
2865
3493
name = "moka"
2866
3494
version = "0.12.10"
2867
3495
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2897
3525
"memchr",
2898
3526
"mime",
2899
3527
"spin",
3528
+
"tokio",
2900
3529
"version_check",
2901
3530
]
2902
3531
···
2923
3552
]
2924
3553
2925
3554
[[package]]
3555
+
name = "naive-timer"
3556
+
version = "0.2.0"
3557
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3558
+
checksum = "034a0ad7deebf0c2abcf2435950a6666c3c15ea9d8fad0c0f48efa8a7f843fed"
3559
+
3560
+
[[package]]
3561
+
name = "nanorand"
3562
+
version = "0.7.0"
3563
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3564
+
checksum = "6a51313c5820b0b02bd422f4b44776fbf47961755c74ce64afc73bfad10226c3"
3565
+
dependencies = [
3566
+
"getrandom 0.2.15",
3567
+
]
3568
+
3569
+
[[package]]
2926
3570
name = "native-tls"
2927
3571
version = "0.2.14"
2928
3572
source = "registry+https://github.com/rust-lang/crates.io-index"
···
2963
3607
2964
3608
[[package]]
2965
3609
name = "nu-ansi-term"
2966
-
version = "0.46.0"
3610
+
version = "0.50.1"
2967
3611
source = "registry+https://github.com/rust-lang/crates.io-index"
2968
-
checksum = "77a8165726e8236064dbb45459242600304b42a5ea24ee2948e18e023bf7ba84"
3612
+
checksum = "d4a28e057d01f97e61255210fcff094d74ed0466038633e95017f5beb68e4399"
2969
3613
dependencies = [
2970
-
"overload",
2971
-
"winapi",
3614
+
"windows-sys 0.52.0",
2972
3615
]
2973
3616
2974
3617
[[package]]
···
2982
3625
]
2983
3626
2984
3627
[[package]]
3628
+
name = "num-bigint-dig"
3629
+
version = "0.8.4"
3630
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3631
+
checksum = "dc84195820f291c7697304f3cbdadd1cb7199c0efc917ff5eafd71225c136151"
3632
+
dependencies = [
3633
+
"byteorder",
3634
+
"lazy_static",
3635
+
"libm",
3636
+
"num-integer",
3637
+
"num-iter",
3638
+
"num-traits",
3639
+
"rand 0.8.5",
3640
+
"smallvec",
3641
+
"zeroize",
3642
+
]
3643
+
3644
+
[[package]]
2985
3645
name = "num-conv"
2986
3646
version = "0.1.0"
2987
3647
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3007
3667
]
3008
3668
3009
3669
[[package]]
3670
+
name = "num-iter"
3671
+
version = "0.1.45"
3672
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3673
+
checksum = "1429034a0490724d0075ebb2bc9e875d6503c3cf69e235a8941aa757d83ef5bf"
3674
+
dependencies = [
3675
+
"autocfg",
3676
+
"num-integer",
3677
+
"num-traits",
3678
+
]
3679
+
3680
+
[[package]]
3010
3681
name = "num-modular"
3011
3682
version = "0.6.1"
3012
3683
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3028
3699
checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841"
3029
3700
dependencies = [
3030
3701
"autocfg",
3702
+
"libm",
3031
3703
]
3032
3704
3033
3705
[[package]]
···
3046
3718
checksum = "62948e14d923ea95ea2c7c86c71013138b66525b86bdc08d2dcc262bdb497b87"
3047
3719
dependencies = [
3048
3720
"memchr",
3721
+
]
3722
+
3723
+
[[package]]
3724
+
name = "oid-registry"
3725
+
version = "0.8.1"
3726
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3727
+
checksum = "12f40cff3dde1b6087cc5d5f5d4d65712f34016a03ed60e9c08dcc392736b5b7"
3728
+
dependencies = [
3729
+
"asn1-rs",
3049
3730
]
3050
3731
3051
3732
[[package]]
···
3060
3741
3061
3742
[[package]]
3062
3743
name = "openapiv3"
3063
-
version = "2.0.0"
3744
+
version = "2.2.0"
3064
3745
source = "registry+https://github.com/rust-lang/crates.io-index"
3065
-
checksum = "cc02deea53ffe807708244e5914f6b099ad7015a207ee24317c22112e17d9c5c"
3746
+
checksum = "5c8d427828b22ae1fff2833a03d8486c2c881367f1c336349f307f321e7f4d05"
3066
3747
dependencies = [
3067
-
"indexmap 2.9.0",
3748
+
"indexmap 2.11.4",
3068
3749
"serde",
3069
3750
"serde_json",
3070
3751
]
···
3092
3773
dependencies = [
3093
3774
"proc-macro2",
3094
3775
"quote",
3095
-
"syn",
3776
+
"syn 2.0.106",
3096
3777
]
3097
3778
3098
3779
[[package]]
···
3124
3805
]
3125
3806
3126
3807
[[package]]
3127
-
name = "overload"
3128
-
version = "0.1.1"
3808
+
name = "ordered_hash_map"
3809
+
version = "0.4.0"
3129
3810
source = "registry+https://github.com/rust-lang/crates.io-index"
3130
-
checksum = "b15813163c1d831bf4a13c3610c05c0d03b39feb07f7e09fa234dac9b15aaf39"
3811
+
checksum = "ab0e5f22bf6dd04abd854a8874247813a8fa2c8c1260eba6fbb150270ce7c176"
3812
+
dependencies = [
3813
+
"hashbrown 0.13.2",
3814
+
]
3131
3815
3132
3816
[[package]]
3133
3817
name = "p256"
···
3142
3826
]
3143
3827
3144
3828
[[package]]
3829
+
name = "p384"
3830
+
version = "0.13.1"
3831
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3832
+
checksum = "fe42f1670a52a47d448f14b6a5c61dd78fce51856e68edaa38f7ae3a46b8d6b6"
3833
+
dependencies = [
3834
+
"elliptic-curve",
3835
+
"primeorder",
3836
+
]
3837
+
3838
+
[[package]]
3839
+
name = "panic-message"
3840
+
version = "0.3.0"
3841
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3842
+
checksum = "384e52fd8fbd4cbe3c317e8216260c21a0f9134de108cea8a4dd4e7e152c472d"
3843
+
3844
+
[[package]]
3145
3845
name = "parking"
3146
3846
version = "2.2.1"
3147
3847
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3205
3905
]
3206
3906
3207
3907
[[package]]
3908
+
name = "pem-rfc7468"
3909
+
version = "0.7.0"
3910
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3911
+
checksum = "88b39c9bfcfc231068454382784bb460aae594343fb030d46e9f50a645418412"
3912
+
dependencies = [
3913
+
"base64ct",
3914
+
]
3915
+
3916
+
[[package]]
3208
3917
name = "percent-encoding"
3209
3918
version = "2.3.1"
3210
3919
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3217
3926
checksum = "1db05f56d34358a8b1066f67cbb203ee3e7ed2ba674a6263a1d5ec6db2204323"
3218
3927
dependencies = [
3219
3928
"memchr",
3220
-
"thiserror 2.0.12",
3929
+
"thiserror 2.0.16",
3221
3930
"ucd-trie",
3222
3931
]
3223
3932
···
3241
3950
"pest_meta",
3242
3951
"proc-macro2",
3243
3952
"quote",
3244
-
"syn",
3953
+
"syn 2.0.106",
3245
3954
]
3246
3955
3247
3956
[[package]]
···
3255
3964
]
3256
3965
3257
3966
[[package]]
3967
+
name = "pin-project"
3968
+
version = "1.1.10"
3969
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3970
+
checksum = "677f1add503faace112b9f1373e43e9e054bfdd22ff1a63c1bc485eaec6a6a8a"
3971
+
dependencies = [
3972
+
"pin-project-internal",
3973
+
]
3974
+
3975
+
[[package]]
3976
+
name = "pin-project-internal"
3977
+
version = "1.1.10"
3978
+
source = "registry+https://github.com/rust-lang/crates.io-index"
3979
+
checksum = "6e918e4ff8c4549eb882f14b3a4bc8c8bc93de829416eacf579f1207a8fbf861"
3980
+
dependencies = [
3981
+
"proc-macro2",
3982
+
"quote",
3983
+
"syn 2.0.106",
3984
+
]
3985
+
3986
+
[[package]]
3258
3987
name = "pin-project-lite"
3259
3988
version = "0.2.16"
3260
3989
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3267
3996
checksum = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184"
3268
3997
3269
3998
[[package]]
3999
+
name = "pkcs1"
4000
+
version = "0.7.5"
4001
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4002
+
checksum = "c8ffb9f10fa047879315e6625af03c164b16962a5368d724ed16323b68ace47f"
4003
+
dependencies = [
4004
+
"der",
4005
+
"pkcs8",
4006
+
"spki",
4007
+
]
4008
+
4009
+
[[package]]
4010
+
name = "pkcs8"
4011
+
version = "0.10.2"
4012
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4013
+
checksum = "f950b2377845cebe5cf8b5165cb3cc1a5e0fa5cfa3e1f7f55707d8fd82e0a7b7"
4014
+
dependencies = [
4015
+
"der",
4016
+
"spki",
4017
+
]
4018
+
4019
+
[[package]]
3270
4020
name = "pkg-config"
3271
4021
version = "0.3.32"
3272
4022
source = "registry+https://github.com/rust-lang/crates.io-index"
3273
4023
checksum = "7edddbd0b52d732b21ad9a5fab5c704c14cd949e5e9a1ec5929a24fded1b904c"
3274
4024
3275
4025
[[package]]
4026
+
name = "pocket"
4027
+
version = "0.1.0"
4028
+
dependencies = [
4029
+
"atrium-crypto",
4030
+
"clap",
4031
+
"jwt-compact",
4032
+
"log",
4033
+
"poem",
4034
+
"poem-openapi",
4035
+
"reqwest",
4036
+
"rusqlite",
4037
+
"serde",
4038
+
"serde_json",
4039
+
"thiserror 2.0.16",
4040
+
"tokio",
4041
+
"tracing-subscriber",
4042
+
]
4043
+
4044
+
[[package]]
4045
+
name = "poem"
4046
+
version = "3.1.12"
4047
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4048
+
checksum = "9f977080932c87287147dca052951c3e2696f8759863f6b4e4c0c9ffe7a4cc8b"
4049
+
dependencies = [
4050
+
"base64 0.22.1",
4051
+
"bytes",
4052
+
"chrono",
4053
+
"futures-util",
4054
+
"headers",
4055
+
"http",
4056
+
"http-body-util",
4057
+
"httpdate",
4058
+
"hyper",
4059
+
"hyper-util",
4060
+
"mime",
4061
+
"mime_guess",
4062
+
"multer",
4063
+
"nix",
4064
+
"parking_lot",
4065
+
"percent-encoding",
4066
+
"pin-project-lite",
4067
+
"poem-derive",
4068
+
"quick-xml",
4069
+
"rcgen",
4070
+
"regex",
4071
+
"reqwest",
4072
+
"rfc7239",
4073
+
"ring",
4074
+
"rustls-pemfile",
4075
+
"serde",
4076
+
"serde_json",
4077
+
"serde_urlencoded",
4078
+
"serde_yaml",
4079
+
"smallvec",
4080
+
"sync_wrapper",
4081
+
"tempfile",
4082
+
"thiserror 2.0.16",
4083
+
"tokio",
4084
+
"tokio-rustls 0.26.2",
4085
+
"tokio-stream",
4086
+
"tokio-util",
4087
+
"tracing",
4088
+
"wildmatch",
4089
+
"x509-parser",
4090
+
]
4091
+
4092
+
[[package]]
4093
+
name = "poem-derive"
4094
+
version = "3.1.12"
4095
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4096
+
checksum = "056e2fea6de1cb240ffe23cfc4fc370b629f8be83b5f27e16b7acd5231a72de4"
4097
+
dependencies = [
4098
+
"proc-macro-crate",
4099
+
"proc-macro2",
4100
+
"quote",
4101
+
"syn 2.0.106",
4102
+
]
4103
+
4104
+
[[package]]
4105
+
name = "poem-openapi"
4106
+
version = "5.1.16"
4107
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4108
+
checksum = "1ccbcc395bf4dd03df1da32da351b6b6732e4074ce27ddec315650e52a2be44c"
4109
+
dependencies = [
4110
+
"base64 0.22.1",
4111
+
"bytes",
4112
+
"derive_more",
4113
+
"futures-util",
4114
+
"indexmap 2.11.4",
4115
+
"itertools 0.14.0",
4116
+
"mime",
4117
+
"num-traits",
4118
+
"poem",
4119
+
"poem-openapi-derive",
4120
+
"quick-xml",
4121
+
"regex",
4122
+
"serde",
4123
+
"serde_json",
4124
+
"serde_urlencoded",
4125
+
"serde_yaml",
4126
+
"thiserror 2.0.16",
4127
+
"tokio",
4128
+
]
4129
+
4130
+
[[package]]
4131
+
name = "poem-openapi-derive"
4132
+
version = "5.1.16"
4133
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4134
+
checksum = "41273b691a3d467a8c44d05506afba9f7b6bd56c9cdf80123de13fe52d7ec587"
4135
+
dependencies = [
4136
+
"darling 0.20.11",
4137
+
"http",
4138
+
"indexmap 2.11.4",
4139
+
"mime",
4140
+
"proc-macro-crate",
4141
+
"proc-macro2",
4142
+
"quote",
4143
+
"regex",
4144
+
"syn 2.0.106",
4145
+
"thiserror 2.0.16",
4146
+
]
4147
+
4148
+
[[package]]
3276
4149
name = "portable-atomic"
3277
4150
version = "1.11.0"
3278
4151
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3309
4182
checksum = "6837b9e10d61f45f987d50808f83d1ee3d206c66acf650c3e4ae2e1f6ddedf55"
3310
4183
dependencies = [
3311
4184
"proc-macro2",
3312
-
"syn",
4185
+
"syn 2.0.106",
3313
4186
]
3314
4187
3315
4188
[[package]]
···
3322
4195
]
3323
4196
3324
4197
[[package]]
4198
+
name = "proc-macro-crate"
4199
+
version = "3.3.0"
4200
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4201
+
checksum = "edce586971a4dfaa28950c6f18ed55e0406c1ab88bbce2c6f6293a7aaba73d35"
4202
+
dependencies = [
4203
+
"toml_edit",
4204
+
]
4205
+
4206
+
[[package]]
3325
4207
name = "proc-macro2"
3326
4208
version = "1.0.94"
3327
4209
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3368
4250
]
3369
4251
3370
4252
[[package]]
4253
+
name = "quasar"
4254
+
version = "0.1.0"
4255
+
dependencies = [
4256
+
"clap",
4257
+
"fjall 2.11.2 (registry+https://github.com/rust-lang/crates.io-index)",
4258
+
]
4259
+
4260
+
[[package]]
4261
+
name = "quick-xml"
4262
+
version = "0.36.2"
4263
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4264
+
checksum = "f7649a7b4df05aed9ea7ec6f628c67c9953a43869b8bc50929569b2999d443fe"
4265
+
dependencies = [
4266
+
"memchr",
4267
+
"serde",
4268
+
]
4269
+
4270
+
[[package]]
3371
4271
name = "quick_cache"
3372
4272
version = "0.6.12"
3373
4273
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3378
4278
]
3379
4279
3380
4280
[[package]]
4281
+
name = "quinn"
4282
+
version = "0.11.8"
4283
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4284
+
checksum = "626214629cda6781b6dc1d316ba307189c85ba657213ce642d9c77670f8202c8"
4285
+
dependencies = [
4286
+
"bytes",
4287
+
"cfg_aliases",
4288
+
"pin-project-lite",
4289
+
"quinn-proto",
4290
+
"quinn-udp",
4291
+
"rustc-hash 2.1.1",
4292
+
"rustls 0.23.31",
4293
+
"socket2 0.5.9",
4294
+
"thiserror 2.0.16",
4295
+
"tokio",
4296
+
"tracing",
4297
+
"web-time",
4298
+
]
4299
+
4300
+
[[package]]
4301
+
name = "quinn-proto"
4302
+
version = "0.11.12"
4303
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4304
+
checksum = "49df843a9161c85bb8aae55f101bc0bac8bcafd637a620d9122fd7e0b2f7422e"
4305
+
dependencies = [
4306
+
"bytes",
4307
+
"getrandom 0.3.3",
4308
+
"lru-slab",
4309
+
"rand 0.9.1",
4310
+
"ring",
4311
+
"rustc-hash 2.1.1",
4312
+
"rustls 0.23.31",
4313
+
"rustls-pki-types",
4314
+
"slab",
4315
+
"thiserror 2.0.16",
4316
+
"tinyvec",
4317
+
"tracing",
4318
+
"web-time",
4319
+
]
4320
+
4321
+
[[package]]
4322
+
name = "quinn-udp"
4323
+
version = "0.5.13"
4324
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4325
+
checksum = "fcebb1209ee276352ef14ff8732e24cc2b02bbac986cd74a4c81bcb2f9881970"
4326
+
dependencies = [
4327
+
"cfg_aliases",
4328
+
"libc",
4329
+
"once_cell",
4330
+
"socket2 0.5.9",
4331
+
"tracing",
4332
+
"windows-sys 0.59.0",
4333
+
]
4334
+
4335
+
[[package]]
3381
4336
name = "quote"
3382
4337
version = "1.0.40"
3383
4338
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3490
4445
]
3491
4446
3492
4447
[[package]]
4448
+
name = "rcgen"
4449
+
version = "0.12.1"
4450
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4451
+
checksum = "48406db8ac1f3cbc7dcdb56ec355343817958a356ff430259bb07baf7607e1e1"
4452
+
dependencies = [
4453
+
"pem",
4454
+
"ring",
4455
+
"time",
4456
+
"yasna",
4457
+
]
4458
+
4459
+
[[package]]
3493
4460
name = "redox_syscall"
3494
4461
version = "0.5.11"
3495
4462
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3526
4493
dependencies = [
3527
4494
"proc-macro2",
3528
4495
"quote",
3529
-
"syn",
4496
+
"syn 2.0.106",
4497
+
]
4498
+
4499
+
[[package]]
4500
+
name = "reflector"
4501
+
version = "0.1.0"
4502
+
dependencies = [
4503
+
"clap",
4504
+
"log",
4505
+
"poem",
4506
+
"serde",
4507
+
"tokio",
4508
+
"tracing-subscriber",
3530
4509
]
3531
4510
3532
4511
[[package]]
···
3537
4516
dependencies = [
3538
4517
"aho-corasick",
3539
4518
"memchr",
3540
-
"regex-automata 0.4.9",
3541
-
"regex-syntax 0.8.5",
3542
-
]
3543
-
3544
-
[[package]]
3545
-
name = "regex-automata"
3546
-
version = "0.1.10"
3547
-
source = "registry+https://github.com/rust-lang/crates.io-index"
3548
-
checksum = "6c230d73fb8d8c1b9c0b3135c5142a8acee3a0558fb8db5cf1cb65f8d7862132"
3549
-
dependencies = [
3550
-
"regex-syntax 0.6.29",
4519
+
"regex-automata",
4520
+
"regex-syntax",
3551
4521
]
3552
4522
3553
4523
[[package]]
···
3558
4528
dependencies = [
3559
4529
"aho-corasick",
3560
4530
"memchr",
3561
-
"regex-syntax 0.8.5",
4531
+
"regex-syntax",
3562
4532
]
3563
4533
3564
4534
[[package]]
3565
4535
name = "regex-syntax"
3566
-
version = "0.6.29"
3567
-
source = "registry+https://github.com/rust-lang/crates.io-index"
3568
-
checksum = "f162c6dd7b008981e4d40210aca20b4bd0f9b60ca9271061b07f78537722f2e1"
3569
-
3570
-
[[package]]
3571
-
name = "regex-syntax"
3572
4536
version = "0.8.5"
3573
4537
source = "registry+https://github.com/rust-lang/crates.io-index"
3574
4538
checksum = "2b15c43186be67a4fd63bee50d0303afffcef381492ebe2c5d87f324e1b8815c"
3575
4539
3576
4540
[[package]]
3577
4541
name = "reqwest"
3578
-
version = "0.12.22"
4542
+
version = "0.12.23"
3579
4543
source = "registry+https://github.com/rust-lang/crates.io-index"
3580
-
checksum = "cbc931937e6ca3a06e3b6c0aa7841849b160a90351d6ab467a8b9b9959767531"
4544
+
checksum = "d429f34c8092b2d42c7c93cec323bb4adeb7c67698f70839adec842ec10c7ceb"
3581
4545
dependencies = [
3582
4546
"async-compression",
3583
4547
"base64 0.22.1",
···
3599
4563
"native-tls",
3600
4564
"percent-encoding",
3601
4565
"pin-project-lite",
4566
+
"quinn",
4567
+
"rustls 0.23.31",
4568
+
"rustls-native-certs",
3602
4569
"rustls-pki-types",
3603
4570
"serde",
3604
4571
"serde_json",
···
3606
4573
"sync_wrapper",
3607
4574
"tokio",
3608
4575
"tokio-native-tls",
4576
+
"tokio-rustls 0.26.2",
3609
4577
"tokio-util",
3610
4578
"tower",
3611
4579
"tower-http",
···
3633
4601
]
3634
4602
3635
4603
[[package]]
4604
+
name = "rfc7239"
4605
+
version = "0.1.3"
4606
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4607
+
checksum = "4a82f1d1e38e9a85bb58ffcfadf22ed6f2c94e8cd8581ec2b0f80a2a6858350f"
4608
+
dependencies = [
4609
+
"uncased",
4610
+
]
4611
+
4612
+
[[package]]
3636
4613
name = "ring"
3637
4614
version = "0.17.14"
3638
4615
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3666
4643
]
3667
4644
3668
4645
[[package]]
4646
+
name = "rsa"
4647
+
version = "0.9.8"
4648
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4649
+
checksum = "78928ac1ed176a5ca1d17e578a1825f3d81ca54cf41053a592584b020cfd691b"
4650
+
dependencies = [
4651
+
"const-oid",
4652
+
"digest",
4653
+
"num-bigint-dig",
4654
+
"num-integer",
4655
+
"num-traits",
4656
+
"pkcs1",
4657
+
"pkcs8",
4658
+
"rand_core 0.6.4",
4659
+
"signature",
4660
+
"spki",
4661
+
"subtle",
4662
+
"zeroize",
4663
+
]
4664
+
4665
+
[[package]]
4666
+
name = "rusqlite"
4667
+
version = "0.37.0"
4668
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4669
+
checksum = "165ca6e57b20e1351573e3729b958bc62f0e48025386970b6e4d29e7a7e71f3f"
4670
+
dependencies = [
4671
+
"bitflags",
4672
+
"fallible-iterator",
4673
+
"fallible-streaming-iterator",
4674
+
"hashlink",
4675
+
"libsqlite3-sys",
4676
+
"smallvec",
4677
+
]
4678
+
4679
+
[[package]]
3669
4680
name = "rustc-demangle"
3670
4681
version = "0.1.24"
3671
4682
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3690
4701
checksum = "cfcb3a22ef46e85b45de6ee7e79d063319ebb6594faafcf1c225ea92ab6e9b92"
3691
4702
dependencies = [
3692
4703
"semver",
4704
+
]
4705
+
4706
+
[[package]]
4707
+
name = "rusticata-macros"
4708
+
version = "4.1.0"
4709
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4710
+
checksum = "faf0c4a6ece9950b9abdb62b1cfcf2a68b3b67a10ba445b3bb85be2a293d0632"
4711
+
dependencies = [
4712
+
"nom",
3693
4713
]
3694
4714
3695
4715
[[package]]
···
3734
4754
3735
4755
[[package]]
3736
4756
name = "rustls"
3737
-
version = "0.23.28"
4757
+
version = "0.23.31"
3738
4758
source = "registry+https://github.com/rust-lang/crates.io-index"
3739
-
checksum = "7160e3e10bf4535308537f3c4e1641468cd0e485175d6163087c0393c7d46643"
4759
+
checksum = "c0ebcbd2f03de0fc1122ad9bb24b127a5a6cd51d72604a3f3c50ac459762b6cc"
3740
4760
dependencies = [
3741
4761
"aws-lc-rs",
4762
+
"log",
3742
4763
"once_cell",
4764
+
"ring",
3743
4765
"rustls-pki-types",
3744
-
"rustls-webpki 0.103.3",
4766
+
"rustls-webpki 0.103.4",
3745
4767
"subtle",
3746
4768
"zeroize",
3747
4769
]
···
3769
4791
3770
4792
[[package]]
3771
4793
name = "rustls-pki-types"
3772
-
version = "1.11.0"
4794
+
version = "1.12.0"
3773
4795
source = "registry+https://github.com/rust-lang/crates.io-index"
3774
-
checksum = "917ce264624a4b4db1c364dcc35bfca9ded014d0a958cd47ad3e960e988ea51c"
4796
+
checksum = "229a4a4c221013e7e1f1a043678c5cc39fe5171437c88fb47151a21e6f5b5c79"
4797
+
dependencies = [
4798
+
"web-time",
4799
+
"zeroize",
4800
+
]
3775
4801
3776
4802
[[package]]
3777
4803
name = "rustls-webpki"
···
3786
4812
3787
4813
[[package]]
3788
4814
name = "rustls-webpki"
3789
-
version = "0.103.3"
4815
+
version = "0.103.4"
3790
4816
source = "registry+https://github.com/rust-lang/crates.io-index"
3791
-
checksum = "e4a72fe2bcf7a6ac6fd7d0b9e5cb68aeb7d4c0a0271730218b3e92d43b4eb435"
4817
+
checksum = "0a17884ae0c1b773f1ccd2bd4a8c72f16da897310a98b0e84bf349ad5ead92fc"
3792
4818
dependencies = [
3793
4819
"aws-lc-rs",
3794
4820
"ring",
···
3849
4875
"proc-macro2",
3850
4876
"quote",
3851
4877
"serde_derive_internals",
3852
-
"syn",
4878
+
"syn 2.0.106",
3853
4879
]
3854
4880
3855
4881
[[package]]
···
3873
4899
"base16ct",
3874
4900
"der",
3875
4901
"generic-array",
4902
+
"pkcs8",
3876
4903
"subtle",
3877
4904
"zeroize",
3878
4905
]
3879
4906
3880
4907
[[package]]
4908
+
name = "secp256k1"
4909
+
version = "0.30.0"
4910
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4911
+
checksum = "b50c5943d326858130af85e049f2661ba3c78b26589b8ab98e65e80ae44a1252"
4912
+
dependencies = [
4913
+
"bitcoin_hashes",
4914
+
"rand 0.8.5",
4915
+
"secp256k1-sys",
4916
+
]
4917
+
4918
+
[[package]]
4919
+
name = "secp256k1-sys"
4920
+
version = "0.10.1"
4921
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4922
+
checksum = "d4387882333d3aa8cb20530a17c69a3752e97837832f34f6dccc760e715001d9"
4923
+
dependencies = [
4924
+
"cc",
4925
+
]
4926
+
4927
+
[[package]]
3881
4928
name = "security-framework"
3882
4929
version = "2.11.1"
3883
4930
source = "registry+https://github.com/rust-lang/crates.io-index"
···
3927
4974
3928
4975
[[package]]
3929
4976
name = "serde"
3930
-
version = "1.0.219"
4977
+
version = "1.0.228"
3931
4978
source = "registry+https://github.com/rust-lang/crates.io-index"
3932
-
checksum = "5f0e2c6ed6606019b4e29e69dbaba95b11854410e5347d525002456dbbb786b6"
4979
+
checksum = "9a8e94ea7f378bd32cbbd37198a4a91436180c5bb472411e48b5ec2e2124ae9e"
3933
4980
dependencies = [
4981
+
"serde_core",
3934
4982
"serde_derive",
3935
4983
]
3936
4984
···
3944
4992
]
3945
4993
3946
4994
[[package]]
4995
+
name = "serde_core"
4996
+
version = "1.0.228"
4997
+
source = "registry+https://github.com/rust-lang/crates.io-index"
4998
+
checksum = "41d385c7d4ca58e59fc732af25c3983b67ac852c1a25000afe1175de458b67ad"
4999
+
dependencies = [
5000
+
"serde_derive",
5001
+
]
5002
+
5003
+
[[package]]
3947
5004
name = "serde_derive"
3948
-
version = "1.0.219"
5005
+
version = "1.0.228"
3949
5006
source = "registry+https://github.com/rust-lang/crates.io-index"
3950
-
checksum = "5b0276cf7f2c73365f7157c8123c21cd9a50fbbd844757af28ca1f5925fc2a00"
5007
+
checksum = "d540f220d3187173da220f885ab66608367b6574e925011a9353e4badda91d79"
3951
5008
dependencies = [
3952
5009
"proc-macro2",
3953
5010
"quote",
3954
-
"syn",
5011
+
"syn 2.0.106",
3955
5012
]
3956
5013
3957
5014
[[package]]
···
3962
5019
dependencies = [
3963
5020
"proc-macro2",
3964
5021
"quote",
3965
-
"syn",
5022
+
"syn 2.0.106",
3966
5023
]
3967
5024
3968
5025
[[package]]
···
3972
5029
checksum = "9d2de91cf02bbc07cde38891769ccd5d4f073d22a40683aa4bc7a95781aaa2c4"
3973
5030
dependencies = [
3974
5031
"form_urlencoded",
3975
-
"indexmap 2.9.0",
5032
+
"indexmap 2.11.4",
3976
5033
"itoa",
3977
5034
"ryu",
3978
5035
"serde",
···
3980
5037
3981
5038
[[package]]
3982
5039
name = "serde_json"
3983
-
version = "1.0.140"
5040
+
version = "1.0.145"
3984
5041
source = "registry+https://github.com/rust-lang/crates.io-index"
3985
-
checksum = "20068b6e96dc6c9bd23e01df8827e6c7e1f2fddd43c21810382803c136b99373"
5042
+
checksum = "402a6f66d8c709116cf22f558eab210f5a50187f702eb4d7e5ef38d9a7f1c79c"
3986
5043
dependencies = [
3987
5044
"itoa",
3988
5045
"memchr",
3989
5046
"ryu",
3990
5047
"serde",
5048
+
"serde_core",
3991
5049
]
3992
5050
3993
5051
[[package]]
···
4010
5068
"percent-encoding",
4011
5069
"ryu",
4012
5070
"serde",
4013
-
"thiserror 2.0.12",
5071
+
"thiserror 2.0.16",
4014
5072
]
4015
5073
4016
5074
[[package]]
···
4023
5081
]
4024
5082
4025
5083
[[package]]
5084
+
name = "serde_spanned"
5085
+
version = "1.0.2"
5086
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5087
+
checksum = "5417783452c2be558477e104686f7de5dae53dba813c28435e0e70f82d9b04ee"
5088
+
dependencies = [
5089
+
"serde_core",
5090
+
]
5091
+
5092
+
[[package]]
4026
5093
name = "serde_tokenstream"
4027
5094
version = "0.2.2"
4028
5095
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4031
5098
"proc-macro2",
4032
5099
"quote",
4033
5100
"serde",
4034
-
"syn",
5101
+
"syn 2.0.106",
4035
5102
]
4036
5103
4037
5104
[[package]]
···
4056
5123
"chrono",
4057
5124
"hex",
4058
5125
"indexmap 1.9.3",
4059
-
"indexmap 2.9.0",
5126
+
"indexmap 2.11.4",
4060
5127
"serde",
4061
5128
"serde_derive",
4062
5129
"serde_json",
···
4070
5137
source = "registry+https://github.com/rust-lang/crates.io-index"
4071
5138
checksum = "8d00caa5193a3c8362ac2b73be6b9e768aa5a4b2f721d8f4b339600c3cb51f8e"
4072
5139
dependencies = [
4073
-
"darling",
5140
+
"darling 0.20.11",
4074
5141
"proc-macro2",
4075
5142
"quote",
4076
-
"syn",
5143
+
"syn 2.0.106",
5144
+
]
5145
+
5146
+
[[package]]
5147
+
name = "serde_yaml"
5148
+
version = "0.9.34+deprecated"
5149
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5150
+
checksum = "6a8b1a1a2ebf674015cc02edccce75287f1a0130d394307b36743c2f5d504b47"
5151
+
dependencies = [
5152
+
"indexmap 2.11.4",
5153
+
"itoa",
5154
+
"ryu",
5155
+
"serde",
5156
+
"unsafe-libyaml",
4077
5157
]
4078
5158
4079
5159
[[package]]
···
4140
5220
dependencies = [
4141
5221
"num-bigint",
4142
5222
"num-traits",
4143
-
"thiserror 2.0.12",
5223
+
"thiserror 2.0.16",
4144
5224
"time",
4145
5225
]
4146
5226
···
4160
5240
]
4161
5241
4162
5242
[[package]]
5243
+
name = "slingshot"
5244
+
version = "0.1.0"
5245
+
dependencies = [
5246
+
"atrium-api 0.25.4 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
5247
+
"atrium-common 0.1.2 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
5248
+
"atrium-identity 0.1.5 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
5249
+
"atrium-oauth 0.1.3 (git+https://github.com/uniphil/atrium.git?branch=fix%2Fresolve-handle-https-accept-whitespace)",
5250
+
"clap",
5251
+
"ctrlc",
5252
+
"foyer",
5253
+
"hickory-resolver",
5254
+
"jetstream",
5255
+
"links",
5256
+
"log",
5257
+
"metrics",
5258
+
"metrics-exporter-prometheus 0.17.2",
5259
+
"poem",
5260
+
"poem-openapi",
5261
+
"reqwest",
5262
+
"rustls 0.23.31",
5263
+
"serde",
5264
+
"serde_json",
5265
+
"thiserror 2.0.16",
5266
+
"time",
5267
+
"tokio",
5268
+
"tokio-util",
5269
+
"tracing-subscriber",
5270
+
"url",
5271
+
]
5272
+
5273
+
[[package]]
4163
5274
name = "slog"
4164
5275
version = "2.7.0"
4165
5276
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4231
5342
]
4232
5343
4233
5344
[[package]]
5345
+
name = "socket2"
5346
+
version = "0.6.0"
5347
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5348
+
checksum = "233504af464074f9d066d7b5416c5f9b894a5862a6506e306f7b816cdd6f1807"
5349
+
dependencies = [
5350
+
"libc",
5351
+
"windows-sys 0.59.0",
5352
+
]
5353
+
5354
+
[[package]]
4234
5355
name = "spacedust"
4235
5356
version = "0.1.0"
4236
5357
dependencies = [
···
4252
5373
"serde",
4253
5374
"serde_json",
4254
5375
"serde_qs",
4255
-
"thiserror 2.0.12",
5376
+
"thiserror 2.0.16",
4256
5377
"tinyjson",
4257
5378
"tokio",
4258
5379
"tokio-tungstenite 0.27.0",
···
4269
5390
]
4270
5391
4271
5392
[[package]]
5393
+
name = "spki"
5394
+
version = "0.7.3"
5395
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5396
+
checksum = "d91ed6c858b01f942cd56b37a94b3e0a1798290327d1236e4d9cf4eaca44d29d"
5397
+
dependencies = [
5398
+
"base64ct",
5399
+
"der",
5400
+
]
5401
+
5402
+
[[package]]
4272
5403
name = "stable_deref_trait"
4273
5404
version = "1.2.0"
4274
5405
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4282
5413
4283
5414
[[package]]
4284
5415
name = "strsim"
5416
+
version = "0.10.0"
5417
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5418
+
checksum = "73473c0e59e6d5812c5dfe2a064a6444949f089e20eec9a2e5506596494e4623"
5419
+
5420
+
[[package]]
5421
+
name = "strsim"
4285
5422
version = "0.11.1"
4286
5423
source = "registry+https://github.com/rust-lang/crates.io-index"
4287
5424
checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f"
···
4294
5431
4295
5432
[[package]]
4296
5433
name = "syn"
4297
-
version = "2.0.103"
5434
+
version = "1.0.109"
5435
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5436
+
checksum = "72b64191b275b66ffe2469e8af2c1cfe3bafa67b529ead792a6d0160888b4237"
5437
+
dependencies = [
5438
+
"proc-macro2",
5439
+
"quote",
5440
+
"unicode-ident",
5441
+
]
5442
+
5443
+
[[package]]
5444
+
name = "syn"
5445
+
version = "2.0.106"
4298
5446
source = "registry+https://github.com/rust-lang/crates.io-index"
4299
-
checksum = "e4307e30089d6fd6aff212f2da3a1f9e32f3223b1f010fb09b7c95f90f3ca1e8"
5447
+
checksum = "ede7c438028d4436d71104916910f5bb611972c5cfd7f89b8300a8186e6fada6"
4300
5448
dependencies = [
4301
5449
"proc-macro2",
4302
5450
"quote",
···
4320
5468
dependencies = [
4321
5469
"proc-macro2",
4322
5470
"quote",
4323
-
"syn",
5471
+
"syn 2.0.106",
4324
5472
]
4325
5473
4326
5474
[[package]]
···
4391
5539
4392
5540
[[package]]
4393
5541
name = "thiserror"
4394
-
version = "2.0.12"
5542
+
version = "2.0.16"
4395
5543
source = "registry+https://github.com/rust-lang/crates.io-index"
4396
-
checksum = "567b8a2dae586314f7be2a752ec7474332959c6460e02bde30d702a66d488708"
5544
+
checksum = "3467d614147380f2e4e374161426ff399c91084acd2363eaf549172b3d5e60c0"
4397
5545
dependencies = [
4398
-
"thiserror-impl 2.0.12",
5546
+
"thiserror-impl 2.0.16",
4399
5547
]
4400
5548
4401
5549
[[package]]
···
4406
5554
dependencies = [
4407
5555
"proc-macro2",
4408
5556
"quote",
4409
-
"syn",
5557
+
"syn 2.0.106",
4410
5558
]
4411
5559
4412
5560
[[package]]
4413
5561
name = "thiserror-impl"
4414
-
version = "2.0.12"
5562
+
version = "2.0.16"
4415
5563
source = "registry+https://github.com/rust-lang/crates.io-index"
4416
-
checksum = "7f7cf42b4507d8ea322120659672cf1b9dbb93f8f2d4ecfd6e51350ff5b17a1d"
5564
+
checksum = "6c5e1be1c48b9172ee610da68fd9cd2770e7a4056cb3fc98710ee6906f0c7960"
4417
5565
dependencies = [
4418
5566
"proc-macro2",
4419
5567
"quote",
4420
-
"syn",
5568
+
"syn 2.0.106",
4421
5569
]
4422
5570
4423
5571
[[package]]
···
4516
5664
4517
5665
[[package]]
4518
5666
name = "tokio"
4519
-
version = "1.45.1"
5667
+
version = "1.47.1"
4520
5668
source = "registry+https://github.com/rust-lang/crates.io-index"
4521
-
checksum = "75ef51a33ef1da925cea3e4eb122833cb377c61439ca401b770f54902b806779"
5669
+
checksum = "89e49afdadebb872d3145a5638b59eb0691ea23e46ca484037cfab3b76b95038"
4522
5670
dependencies = [
4523
5671
"backtrace",
4524
5672
"bytes",
5673
+
"io-uring",
4525
5674
"libc",
4526
5675
"mio",
4527
5676
"parking_lot",
4528
5677
"pin-project-lite",
4529
5678
"signal-hook-registry",
4530
-
"socket2",
5679
+
"slab",
5680
+
"socket2 0.6.0",
4531
5681
"tokio-macros",
4532
-
"windows-sys 0.52.0",
5682
+
"windows-sys 0.59.0",
4533
5683
]
4534
5684
4535
5685
[[package]]
···
4540
5690
dependencies = [
4541
5691
"proc-macro2",
4542
5692
"quote",
4543
-
"syn",
5693
+
"syn 2.0.106",
4544
5694
]
4545
5695
4546
5696
[[package]]
···
4570
5720
source = "registry+https://github.com/rust-lang/crates.io-index"
4571
5721
checksum = "8e727b36a1a0e8b74c376ac2211e40c2c8af09fb4013c60d910495810f008e9b"
4572
5722
dependencies = [
4573
-
"rustls 0.23.28",
5723
+
"rustls 0.23.31",
5724
+
"tokio",
5725
+
]
5726
+
5727
+
[[package]]
5728
+
name = "tokio-stream"
5729
+
version = "0.1.17"
5730
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5731
+
checksum = "eca58d7bba4a75707817a2c44174253f9236b2d5fbd055602e9d5c07c139a047"
5732
+
dependencies = [
5733
+
"futures-core",
5734
+
"pin-project-lite",
4574
5735
"tokio",
4575
5736
]
4576
5737
···
4620
5781
checksum = "dc1beb996b9d83529a9e75c17a1686767d148d70663143c7854d8b4a09ced362"
4621
5782
dependencies = [
4622
5783
"serde",
4623
-
"serde_spanned",
4624
-
"toml_datetime",
5784
+
"serde_spanned 0.6.9",
5785
+
"toml_datetime 0.6.11",
4625
5786
"toml_edit",
4626
5787
]
4627
5788
4628
5789
[[package]]
5790
+
name = "toml"
5791
+
version = "0.9.7"
5792
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5793
+
checksum = "00e5e5d9bf2475ac9d4f0d9edab68cc573dc2fd644b0dba36b0c30a92dd9eaa0"
5794
+
dependencies = [
5795
+
"indexmap 2.11.4",
5796
+
"serde_core",
5797
+
"serde_spanned 1.0.2",
5798
+
"toml_datetime 0.7.2",
5799
+
"toml_parser",
5800
+
"toml_writer",
5801
+
"winnow",
5802
+
]
5803
+
5804
+
[[package]]
4629
5805
name = "toml_datetime"
4630
5806
version = "0.6.11"
4631
5807
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4635
5811
]
4636
5812
4637
5813
[[package]]
5814
+
name = "toml_datetime"
5815
+
version = "0.7.2"
5816
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5817
+
checksum = "32f1085dec27c2b6632b04c80b3bb1b4300d6495d1e129693bdda7d91e72eec1"
5818
+
dependencies = [
5819
+
"serde_core",
5820
+
]
5821
+
5822
+
[[package]]
4638
5823
name = "toml_edit"
4639
5824
version = "0.22.27"
4640
5825
source = "registry+https://github.com/rust-lang/crates.io-index"
4641
5826
checksum = "41fe8c660ae4257887cf66394862d21dbca4a6ddd26f04a3560410406a2f819a"
4642
5827
dependencies = [
4643
-
"indexmap 2.9.0",
5828
+
"indexmap 2.11.4",
4644
5829
"serde",
4645
-
"serde_spanned",
4646
-
"toml_datetime",
5830
+
"serde_spanned 0.6.9",
5831
+
"toml_datetime 0.6.11",
4647
5832
"toml_write",
4648
5833
"winnow",
4649
5834
]
4650
5835
4651
5836
[[package]]
5837
+
name = "toml_parser"
5838
+
version = "1.0.3"
5839
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5840
+
checksum = "4cf893c33be71572e0e9aa6dd15e6677937abd686b066eac3f8cd3531688a627"
5841
+
dependencies = [
5842
+
"winnow",
5843
+
]
5844
+
5845
+
[[package]]
4652
5846
name = "toml_write"
4653
5847
version = "0.1.2"
4654
5848
source = "registry+https://github.com/rust-lang/crates.io-index"
4655
5849
checksum = "5d99f8c9a7727884afe522e9bd5edbfc91a3312b36a77b5fb8926e4c31a41801"
5850
+
5851
+
[[package]]
5852
+
name = "toml_writer"
5853
+
version = "1.0.3"
5854
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5855
+
checksum = "d163a63c116ce562a22cda521fcc4d79152e7aba014456fb5eb442f6d6a10109"
4656
5856
4657
5857
[[package]]
4658
5858
name = "tower"
···
4708
5908
dependencies = [
4709
5909
"log",
4710
5910
"pin-project-lite",
5911
+
"tracing-attributes",
4711
5912
"tracing-core",
5913
+
]
5914
+
5915
+
[[package]]
5916
+
name = "tracing-attributes"
5917
+
version = "0.1.30"
5918
+
source = "registry+https://github.com/rust-lang/crates.io-index"
5919
+
checksum = "81383ab64e72a7a8b8e13130c49e3dab29def6d0c7d76a03087b3cf71c5c6903"
5920
+
dependencies = [
5921
+
"proc-macro2",
5922
+
"quote",
5923
+
"syn 2.0.106",
4712
5924
]
4713
5925
4714
5926
[[package]]
···
4734
5946
4735
5947
[[package]]
4736
5948
name = "tracing-subscriber"
4737
-
version = "0.3.19"
5949
+
version = "0.3.20"
4738
5950
source = "registry+https://github.com/rust-lang/crates.io-index"
4739
-
checksum = "e8189decb5ac0fa7bc8b96b7cb9b2701d60d48805aca84a238004d665fcc4008"
5951
+
checksum = "2054a14f5307d601f88daf0553e1cbf472acc4f2c51afab632431cdcd72124d5"
4740
5952
dependencies = [
4741
5953
"matchers",
4742
5954
"nu-ansi-term",
4743
5955
"once_cell",
4744
-
"regex",
5956
+
"regex-automata",
4745
5957
"sharded-slab",
4746
5958
"smallvec",
4747
5959
"thread_local",
···
4758
5970
dependencies = [
4759
5971
"proc-macro2",
4760
5972
"quote",
4761
-
"syn",
5973
+
"syn 2.0.106",
4762
5974
]
4763
5975
4764
5976
[[package]]
···
4781
5993
"native-tls",
4782
5994
"rand 0.9.1",
4783
5995
"sha1",
4784
-
"thiserror 2.0.12",
5996
+
"thiserror 2.0.16",
4785
5997
"url",
4786
5998
"utf-8",
4787
5999
]
···
4799
6011
"log",
4800
6012
"rand 0.9.1",
4801
6013
"sha1",
4802
-
"thiserror 2.0.12",
6014
+
"thiserror 2.0.16",
4803
6015
"utf-8",
4804
6016
]
4805
6017
4806
6018
[[package]]
6019
+
name = "twox-hash"
6020
+
version = "2.1.1"
6021
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6022
+
checksum = "8b907da542cbced5261bd3256de1b3a1bf340a3d37f93425a07362a1d687de56"
6023
+
dependencies = [
6024
+
"rand 0.9.1",
6025
+
]
6026
+
6027
+
[[package]]
4807
6028
name = "typenum"
4808
6029
version = "1.18.0"
4809
6030
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4828
6049
"clap",
4829
6050
"dropshot",
4830
6051
"env_logger",
4831
-
"fjall",
6052
+
"fjall 2.11.2 (git+https://github.com/fjall-rs/fjall.git)",
4832
6053
"getrandom 0.3.3",
4833
6054
"http",
4834
6055
"jetstream",
···
4843
6064
"serde_qs",
4844
6065
"sha2",
4845
6066
"tempfile",
4846
-
"thiserror 2.0.12",
6067
+
"thiserror 2.0.16",
4847
6068
"tikv-jemallocator",
4848
6069
"tokio",
4849
6070
"tokio-util",
···
4862
6083
]
4863
6084
4864
6085
[[package]]
6086
+
name = "uncased"
6087
+
version = "0.9.10"
6088
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6089
+
checksum = "e1b88fcfe09e89d3866a5c11019378088af2d24c3fbd4f0543f96b479ec90697"
6090
+
dependencies = [
6091
+
"version_check",
6092
+
]
6093
+
6094
+
[[package]]
4865
6095
name = "unicase"
4866
6096
version = "2.8.1"
4867
6097
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4874
6104
checksum = "5a5f39404a5da50712a4c1eecf25e90dd62b613502b7e925fd4e4d19b5c96512"
4875
6105
4876
6106
[[package]]
6107
+
name = "unicode-xid"
6108
+
version = "0.2.6"
6109
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6110
+
checksum = "ebc1c04c71510c7f702b52b7c350734c9ff1295c464a03335b00bb84fc54f853"
6111
+
6112
+
[[package]]
6113
+
name = "unsafe-libyaml"
6114
+
version = "0.2.11"
6115
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6116
+
checksum = "673aac59facbab8a9007c7f6108d11f63b603f7cabff99fabf650fea5c32b861"
6117
+
6118
+
[[package]]
4877
6119
name = "unsigned-varint"
4878
6120
version = "0.8.0"
4879
6121
source = "registry+https://github.com/rust-lang/crates.io-index"
···
4928
6170
4929
6171
[[package]]
4930
6172
name = "uuid"
4931
-
version = "1.16.0"
6173
+
version = "1.18.1"
4932
6174
source = "registry+https://github.com/rust-lang/crates.io-index"
4933
-
checksum = "458f7a779bf54acc9f347480ac654f68407d3aab21269a6e3c9f922acd9e2da9"
6175
+
checksum = "2f87b8aa10b915a06587d0dec516c282ff295b475d94abf425d62b57710070a2"
4934
6176
dependencies = [
4935
6177
"getrandom 0.3.3",
6178
+
"js-sys",
4936
6179
"serde",
6180
+
"wasm-bindgen",
4937
6181
]
4938
6182
4939
6183
[[package]]
···
4944
6188
4945
6189
[[package]]
4946
6190
name = "value-log"
4947
-
version = "1.8.0"
6191
+
version = "1.9.0"
4948
6192
source = "registry+https://github.com/rust-lang/crates.io-index"
4949
-
checksum = "fd29b17c041f94e0885179637289815cd038f0c9fc19c4549d5a97017404fb7d"
6193
+
checksum = "62fc7c4ce161f049607ecea654dca3f2d727da5371ae85e2e4f14ce2b98ed67c"
4950
6194
dependencies = [
4951
6195
"byteorder",
4952
6196
"byteview",
···
5048
6292
"log",
5049
6293
"proc-macro2",
5050
6294
"quote",
5051
-
"syn",
6295
+
"syn 2.0.106",
5052
6296
"wasm-bindgen-shared",
5053
6297
]
5054
6298
···
5083
6327
dependencies = [
5084
6328
"proc-macro2",
5085
6329
"quote",
5086
-
"syn",
6330
+
"syn 2.0.106",
5087
6331
"wasm-bindgen-backend",
5088
6332
"wasm-bindgen-shared",
5089
6333
]
···
5133
6377
name = "who-am-i"
5134
6378
version = "0.1.0"
5135
6379
dependencies = [
5136
-
"atrium-api 0.25.4",
6380
+
"atrium-api 0.25.4 (registry+https://github.com/rust-lang/crates.io-index)",
5137
6381
"atrium-common 0.1.2 (registry+https://github.com/rust-lang/crates.io-index)",
5138
-
"atrium-identity",
5139
-
"atrium-oauth",
6382
+
"atrium-identity 0.1.5 (registry+https://github.com/rust-lang/crates.io-index)",
6383
+
"atrium-oauth 0.1.3 (registry+https://github.com/rust-lang/crates.io-index)",
5140
6384
"axum",
5141
6385
"axum-extra",
5142
6386
"axum-template",
5143
6387
"clap",
5144
6388
"ctrlc",
5145
6389
"dashmap",
6390
+
"elliptic-curve",
5146
6391
"handlebars",
5147
6392
"hickory-resolver",
6393
+
"jose-jwk",
5148
6394
"jsonwebtoken",
5149
6395
"metrics",
5150
6396
"metrics-exporter-prometheus 0.17.2",
6397
+
"p256",
6398
+
"pkcs8",
5151
6399
"rand 0.9.1",
5152
6400
"reqwest",
5153
6401
"serde",
5154
6402
"serde_json",
5155
-
"thiserror 2.0.12",
6403
+
"thiserror 2.0.16",
5156
6404
"tokio",
5157
6405
"tokio-util",
5158
6406
"url",
···
5163
6411
version = "1.2.0"
5164
6412
source = "registry+https://github.com/rust-lang/crates.io-index"
5165
6413
checksum = "dd7cf3379ca1aac9eea11fba24fd7e315d621f8dfe35c8d7d2be8b793726e07d"
6414
+
6415
+
[[package]]
6416
+
name = "wildmatch"
6417
+
version = "2.4.0"
6418
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6419
+
checksum = "68ce1ab1f8c62655ebe1350f589c61e505cf94d385bc6a12899442d9081e71fd"
5166
6420
5167
6421
[[package]]
5168
6422
name = "winapi"
···
5201
6455
source = "registry+https://github.com/rust-lang/crates.io-index"
5202
6456
checksum = "dd04d41d93c4992d421894c18c8b43496aa748dd4c081bac0dc93eb0489272b6"
5203
6457
dependencies = [
5204
-
"windows-core 0.58.0",
6458
+
"windows-core",
5205
6459
"windows-targets 0.52.6",
5206
6460
]
5207
6461
···
5211
6465
source = "registry+https://github.com/rust-lang/crates.io-index"
5212
6466
checksum = "6ba6d44ec8c2591c134257ce647b7ea6b20335bf6379a27dac5f1641fcf59f99"
5213
6467
dependencies = [
5214
-
"windows-implement 0.58.0",
5215
-
"windows-interface 0.58.0",
6468
+
"windows-implement",
6469
+
"windows-interface",
5216
6470
"windows-result 0.2.0",
5217
6471
"windows-strings 0.1.0",
5218
6472
"windows-targets 0.52.6",
5219
6473
]
5220
6474
5221
6475
[[package]]
5222
-
name = "windows-core"
5223
-
version = "0.61.0"
5224
-
source = "registry+https://github.com/rust-lang/crates.io-index"
5225
-
checksum = "4763c1de310c86d75a878046489e2e5ba02c649d185f21c67d4cf8a56d098980"
5226
-
dependencies = [
5227
-
"windows-implement 0.60.0",
5228
-
"windows-interface 0.59.1",
5229
-
"windows-link",
5230
-
"windows-result 0.3.4",
5231
-
"windows-strings 0.4.2",
5232
-
]
5233
-
5234
-
[[package]]
5235
6476
name = "windows-implement"
5236
6477
version = "0.58.0"
5237
6478
source = "registry+https://github.com/rust-lang/crates.io-index"
···
5239
6480
dependencies = [
5240
6481
"proc-macro2",
5241
6482
"quote",
5242
-
"syn",
5243
-
]
5244
-
5245
-
[[package]]
5246
-
name = "windows-implement"
5247
-
version = "0.60.0"
5248
-
source = "registry+https://github.com/rust-lang/crates.io-index"
5249
-
checksum = "a47fddd13af08290e67f4acabf4b459f647552718f683a7b415d290ac744a836"
5250
-
dependencies = [
5251
-
"proc-macro2",
5252
-
"quote",
5253
-
"syn",
6483
+
"syn 2.0.106",
5254
6484
]
5255
6485
5256
6486
[[package]]
···
5261
6491
dependencies = [
5262
6492
"proc-macro2",
5263
6493
"quote",
5264
-
"syn",
5265
-
]
5266
-
5267
-
[[package]]
5268
-
name = "windows-interface"
5269
-
version = "0.59.1"
5270
-
source = "registry+https://github.com/rust-lang/crates.io-index"
5271
-
checksum = "bd9211b69f8dcdfa817bfd14bf1c97c9188afa36f4750130fcdf3f400eca9fa8"
5272
-
dependencies = [
5273
-
"proc-macro2",
5274
-
"quote",
5275
-
"syn",
6494
+
"syn 2.0.106",
5276
6495
]
5277
6496
5278
6497
[[package]]
···
5479
6698
5480
6699
[[package]]
5481
6700
name = "winnow"
5482
-
version = "0.7.11"
6701
+
version = "0.7.13"
5483
6702
source = "registry+https://github.com/rust-lang/crates.io-index"
5484
-
checksum = "74c7b26e3480b707944fc872477815d29a8e429d2f93a1ce000f5fa84a15cbcd"
6703
+
checksum = "21a0236b59786fed61e2a80582dd500fe61f18b5dca67a4a067d0bc9039339cf"
5485
6704
dependencies = [
5486
6705
"memchr",
5487
6706
]
···
5527
6746
]
5528
6747
5529
6748
[[package]]
6749
+
name = "x509-parser"
6750
+
version = "0.17.0"
6751
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6752
+
checksum = "4569f339c0c402346d4a75a9e39cf8dad310e287eef1ff56d4c68e5067f53460"
6753
+
dependencies = [
6754
+
"asn1-rs",
6755
+
"data-encoding",
6756
+
"der-parser",
6757
+
"lazy_static",
6758
+
"nom",
6759
+
"oid-registry",
6760
+
"rusticata-macros",
6761
+
"thiserror 2.0.16",
6762
+
"time",
6763
+
]
6764
+
6765
+
[[package]]
5530
6766
name = "xxhash-rust"
5531
6767
version = "0.8.15"
5532
6768
source = "registry+https://github.com/rust-lang/crates.io-index"
5533
6769
checksum = "fdd20c5420375476fbd4394763288da7eb0cc0b8c11deed431a91562af7335d3"
5534
6770
5535
6771
[[package]]
6772
+
name = "yasna"
6773
+
version = "0.5.2"
6774
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6775
+
checksum = "e17bb3549cc1321ae1296b9cdc2698e2b6cb1992adfa19a8c72e5b7a738f44cd"
6776
+
dependencies = [
6777
+
"time",
6778
+
]
6779
+
6780
+
[[package]]
5536
6781
name = "yoke"
5537
6782
version = "0.7.5"
5538
6783
source = "registry+https://github.com/rust-lang/crates.io-index"
···
5552
6797
dependencies = [
5553
6798
"proc-macro2",
5554
6799
"quote",
5555
-
"syn",
6800
+
"syn 2.0.106",
5556
6801
"synstructure",
5557
6802
]
5558
6803
···
5582
6827
dependencies = [
5583
6828
"proc-macro2",
5584
6829
"quote",
5585
-
"syn",
6830
+
"syn 2.0.106",
5586
6831
]
5587
6832
5588
6833
[[package]]
···
5593
6838
dependencies = [
5594
6839
"proc-macro2",
5595
6840
"quote",
5596
-
"syn",
6841
+
"syn 2.0.106",
5597
6842
]
5598
6843
5599
6844
[[package]]
···
5613
6858
dependencies = [
5614
6859
"proc-macro2",
5615
6860
"quote",
5616
-
"syn",
6861
+
"syn 2.0.106",
5617
6862
"synstructure",
5618
6863
]
5619
6864
···
5624
6869
checksum = "ced3678a2879b30306d323f4542626697a464a97c0a07c9aebf7ebca65cd4dde"
5625
6870
dependencies = [
5626
6871
"serde",
6872
+
"zeroize_derive",
6873
+
]
6874
+
6875
+
[[package]]
6876
+
name = "zeroize_derive"
6877
+
version = "1.4.2"
6878
+
source = "registry+https://github.com/rust-lang/crates.io-index"
6879
+
checksum = "ce36e65b0d2999d2aafac989fb249189a141aee1f53c612c1f37d72631959f69"
6880
+
dependencies = [
6881
+
"proc-macro2",
6882
+
"quote",
6883
+
"syn 2.0.106",
5627
6884
]
5628
6885
5629
6886
[[package]]
···
5645
6902
dependencies = [
5646
6903
"proc-macro2",
5647
6904
"quote",
5648
-
"syn",
6905
+
"syn 2.0.106",
5649
6906
]
5650
6907
5651
6908
[[package]]
+4
Cargo.toml
+4
Cargo.toml
+8
-1
Makefile
+8
-1
Makefile
···
5
5
cargo test --all-features
6
6
7
7
fmt:
8
-
cargo fmt --package links --package constellation --package ufos --package spacedust --package who-am-i
8
+
cargo fmt --package links \
9
+
--package constellation \
10
+
--package ufos \
11
+
--package spacedust \
12
+
--package who-am-i \
13
+
--package slingshot \
14
+
--package pocket \
15
+
--package reflector
9
16
cargo +nightly fmt --package jetstream
10
17
11
18
clippy:
+1
-1
constellation/Cargo.toml
+1
-1
constellation/Cargo.toml
···
8
8
anyhow = "1.0.95"
9
9
askama = { version = "0.12.1", features = ["serde-json"] }
10
10
axum = "0.8.1"
11
-
axum-extra = { version = "0.10.0", features = ["typed-header"] }
11
+
axum-extra = { version = "0.10.0", features = ["query", "typed-header"] }
12
12
axum-metrics = "0.2"
13
13
bincode = "1.3.3"
14
14
clap = { version = "4.5.26", features = ["derive"] }
+661
constellation/LICENSE
+661
constellation/LICENSE
···
1
+
GNU AFFERO GENERAL PUBLIC LICENSE
2
+
Version 3, 19 November 2007
3
+
4
+
Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
5
+
Everyone is permitted to copy and distribute verbatim copies
6
+
of this license document, but changing it is not allowed.
7
+
8
+
Preamble
9
+
10
+
The GNU Affero General Public License is a free, copyleft license for
11
+
software and other kinds of works, specifically designed to ensure
12
+
cooperation with the community in the case of network server software.
13
+
14
+
The licenses for most software and other practical works are designed
15
+
to take away your freedom to share and change the works. By contrast,
16
+
our General Public Licenses are intended to guarantee your freedom to
17
+
share and change all versions of a program--to make sure it remains free
18
+
software for all its users.
19
+
20
+
When we speak of free software, we are referring to freedom, not
21
+
price. Our General Public Licenses are designed to make sure that you
22
+
have the freedom to distribute copies of free software (and charge for
23
+
them if you wish), that you receive source code or can get it if you
24
+
want it, that you can change the software or use pieces of it in new
25
+
free programs, and that you know you can do these things.
26
+
27
+
Developers that use our General Public Licenses protect your rights
28
+
with two steps: (1) assert copyright on the software, and (2) offer
29
+
you this License which gives you legal permission to copy, distribute
30
+
and/or modify the software.
31
+
32
+
A secondary benefit of defending all users' freedom is that
33
+
improvements made in alternate versions of the program, if they
34
+
receive widespread use, become available for other developers to
35
+
incorporate. Many developers of free software are heartened and
36
+
encouraged by the resulting cooperation. However, in the case of
37
+
software used on network servers, this result may fail to come about.
38
+
The GNU General Public License permits making a modified version and
39
+
letting the public access it on a server without ever releasing its
40
+
source code to the public.
41
+
42
+
The GNU Affero General Public License is designed specifically to
43
+
ensure that, in such cases, the modified source code becomes available
44
+
to the community. It requires the operator of a network server to
45
+
provide the source code of the modified version running there to the
46
+
users of that server. Therefore, public use of a modified version, on
47
+
a publicly accessible server, gives the public access to the source
48
+
code of the modified version.
49
+
50
+
An older license, called the Affero General Public License and
51
+
published by Affero, was designed to accomplish similar goals. This is
52
+
a different license, not a version of the Affero GPL, but Affero has
53
+
released a new version of the Affero GPL which permits relicensing under
54
+
this license.
55
+
56
+
The precise terms and conditions for copying, distribution and
57
+
modification follow.
58
+
59
+
TERMS AND CONDITIONS
60
+
61
+
0. Definitions.
62
+
63
+
"This License" refers to version 3 of the GNU Affero General Public License.
64
+
65
+
"Copyright" also means copyright-like laws that apply to other kinds of
66
+
works, such as semiconductor masks.
67
+
68
+
"The Program" refers to any copyrightable work licensed under this
69
+
License. Each licensee is addressed as "you". "Licensees" and
70
+
"recipients" may be individuals or organizations.
71
+
72
+
To "modify" a work means to copy from or adapt all or part of the work
73
+
in a fashion requiring copyright permission, other than the making of an
74
+
exact copy. The resulting work is called a "modified version" of the
75
+
earlier work or a work "based on" the earlier work.
76
+
77
+
A "covered work" means either the unmodified Program or a work based
78
+
on the Program.
79
+
80
+
To "propagate" a work means to do anything with it that, without
81
+
permission, would make you directly or secondarily liable for
82
+
infringement under applicable copyright law, except executing it on a
83
+
computer or modifying a private copy. Propagation includes copying,
84
+
distribution (with or without modification), making available to the
85
+
public, and in some countries other activities as well.
86
+
87
+
To "convey" a work means any kind of propagation that enables other
88
+
parties to make or receive copies. Mere interaction with a user through
89
+
a computer network, with no transfer of a copy, is not conveying.
90
+
91
+
An interactive user interface displays "Appropriate Legal Notices"
92
+
to the extent that it includes a convenient and prominently visible
93
+
feature that (1) displays an appropriate copyright notice, and (2)
94
+
tells the user that there is no warranty for the work (except to the
95
+
extent that warranties are provided), that licensees may convey the
96
+
work under this License, and how to view a copy of this License. If
97
+
the interface presents a list of user commands or options, such as a
98
+
menu, a prominent item in the list meets this criterion.
99
+
100
+
1. Source Code.
101
+
102
+
The "source code" for a work means the preferred form of the work
103
+
for making modifications to it. "Object code" means any non-source
104
+
form of a work.
105
+
106
+
A "Standard Interface" means an interface that either is an official
107
+
standard defined by a recognized standards body, or, in the case of
108
+
interfaces specified for a particular programming language, one that
109
+
is widely used among developers working in that language.
110
+
111
+
The "System Libraries" of an executable work include anything, other
112
+
than the work as a whole, that (a) is included in the normal form of
113
+
packaging a Major Component, but which is not part of that Major
114
+
Component, and (b) serves only to enable use of the work with that
115
+
Major Component, or to implement a Standard Interface for which an
116
+
implementation is available to the public in source code form. A
117
+
"Major Component", in this context, means a major essential component
118
+
(kernel, window system, and so on) of the specific operating system
119
+
(if any) on which the executable work runs, or a compiler used to
120
+
produce the work, or an object code interpreter used to run it.
121
+
122
+
The "Corresponding Source" for a work in object code form means all
123
+
the source code needed to generate, install, and (for an executable
124
+
work) run the object code and to modify the work, including scripts to
125
+
control those activities. However, it does not include the work's
126
+
System Libraries, or general-purpose tools or generally available free
127
+
programs which are used unmodified in performing those activities but
128
+
which are not part of the work. For example, Corresponding Source
129
+
includes interface definition files associated with source files for
130
+
the work, and the source code for shared libraries and dynamically
131
+
linked subprograms that the work is specifically designed to require,
132
+
such as by intimate data communication or control flow between those
133
+
subprograms and other parts of the work.
134
+
135
+
The Corresponding Source need not include anything that users
136
+
can regenerate automatically from other parts of the Corresponding
137
+
Source.
138
+
139
+
The Corresponding Source for a work in source code form is that
140
+
same work.
141
+
142
+
2. Basic Permissions.
143
+
144
+
All rights granted under this License are granted for the term of
145
+
copyright on the Program, and are irrevocable provided the stated
146
+
conditions are met. This License explicitly affirms your unlimited
147
+
permission to run the unmodified Program. The output from running a
148
+
covered work is covered by this License only if the output, given its
149
+
content, constitutes a covered work. This License acknowledges your
150
+
rights of fair use or other equivalent, as provided by copyright law.
151
+
152
+
You may make, run and propagate covered works that you do not
153
+
convey, without conditions so long as your license otherwise remains
154
+
in force. You may convey covered works to others for the sole purpose
155
+
of having them make modifications exclusively for you, or provide you
156
+
with facilities for running those works, provided that you comply with
157
+
the terms of this License in conveying all material for which you do
158
+
not control copyright. Those thus making or running the covered works
159
+
for you must do so exclusively on your behalf, under your direction
160
+
and control, on terms that prohibit them from making any copies of
161
+
your copyrighted material outside their relationship with you.
162
+
163
+
Conveying under any other circumstances is permitted solely under
164
+
the conditions stated below. Sublicensing is not allowed; section 10
165
+
makes it unnecessary.
166
+
167
+
3. Protecting Users' Legal Rights From Anti-Circumvention Law.
168
+
169
+
No covered work shall be deemed part of an effective technological
170
+
measure under any applicable law fulfilling obligations under article
171
+
11 of the WIPO copyright treaty adopted on 20 December 1996, or
172
+
similar laws prohibiting or restricting circumvention of such
173
+
measures.
174
+
175
+
When you convey a covered work, you waive any legal power to forbid
176
+
circumvention of technological measures to the extent such circumvention
177
+
is effected by exercising rights under this License with respect to
178
+
the covered work, and you disclaim any intention to limit operation or
179
+
modification of the work as a means of enforcing, against the work's
180
+
users, your or third parties' legal rights to forbid circumvention of
181
+
technological measures.
182
+
183
+
4. Conveying Verbatim Copies.
184
+
185
+
You may convey verbatim copies of the Program's source code as you
186
+
receive it, in any medium, provided that you conspicuously and
187
+
appropriately publish on each copy an appropriate copyright notice;
188
+
keep intact all notices stating that this License and any
189
+
non-permissive terms added in accord with section 7 apply to the code;
190
+
keep intact all notices of the absence of any warranty; and give all
191
+
recipients a copy of this License along with the Program.
192
+
193
+
You may charge any price or no price for each copy that you convey,
194
+
and you may offer support or warranty protection for a fee.
195
+
196
+
5. Conveying Modified Source Versions.
197
+
198
+
You may convey a work based on the Program, or the modifications to
199
+
produce it from the Program, in the form of source code under the
200
+
terms of section 4, provided that you also meet all of these conditions:
201
+
202
+
a) The work must carry prominent notices stating that you modified
203
+
it, and giving a relevant date.
204
+
205
+
b) The work must carry prominent notices stating that it is
206
+
released under this License and any conditions added under section
207
+
7. This requirement modifies the requirement in section 4 to
208
+
"keep intact all notices".
209
+
210
+
c) You must license the entire work, as a whole, under this
211
+
License to anyone who comes into possession of a copy. This
212
+
License will therefore apply, along with any applicable section 7
213
+
additional terms, to the whole of the work, and all its parts,
214
+
regardless of how they are packaged. This License gives no
215
+
permission to license the work in any other way, but it does not
216
+
invalidate such permission if you have separately received it.
217
+
218
+
d) If the work has interactive user interfaces, each must display
219
+
Appropriate Legal Notices; however, if the Program has interactive
220
+
interfaces that do not display Appropriate Legal Notices, your
221
+
work need not make them do so.
222
+
223
+
A compilation of a covered work with other separate and independent
224
+
works, which are not by their nature extensions of the covered work,
225
+
and which are not combined with it such as to form a larger program,
226
+
in or on a volume of a storage or distribution medium, is called an
227
+
"aggregate" if the compilation and its resulting copyright are not
228
+
used to limit the access or legal rights of the compilation's users
229
+
beyond what the individual works permit. Inclusion of a covered work
230
+
in an aggregate does not cause this License to apply to the other
231
+
parts of the aggregate.
232
+
233
+
6. Conveying Non-Source Forms.
234
+
235
+
You may convey a covered work in object code form under the terms
236
+
of sections 4 and 5, provided that you also convey the
237
+
machine-readable Corresponding Source under the terms of this License,
238
+
in one of these ways:
239
+
240
+
a) Convey the object code in, or embodied in, a physical product
241
+
(including a physical distribution medium), accompanied by the
242
+
Corresponding Source fixed on a durable physical medium
243
+
customarily used for software interchange.
244
+
245
+
b) Convey the object code in, or embodied in, a physical product
246
+
(including a physical distribution medium), accompanied by a
247
+
written offer, valid for at least three years and valid for as
248
+
long as you offer spare parts or customer support for that product
249
+
model, to give anyone who possesses the object code either (1) a
250
+
copy of the Corresponding Source for all the software in the
251
+
product that is covered by this License, on a durable physical
252
+
medium customarily used for software interchange, for a price no
253
+
more than your reasonable cost of physically performing this
254
+
conveying of source, or (2) access to copy the
255
+
Corresponding Source from a network server at no charge.
256
+
257
+
c) Convey individual copies of the object code with a copy of the
258
+
written offer to provide the Corresponding Source. This
259
+
alternative is allowed only occasionally and noncommercially, and
260
+
only if you received the object code with such an offer, in accord
261
+
with subsection 6b.
262
+
263
+
d) Convey the object code by offering access from a designated
264
+
place (gratis or for a charge), and offer equivalent access to the
265
+
Corresponding Source in the same way through the same place at no
266
+
further charge. You need not require recipients to copy the
267
+
Corresponding Source along with the object code. If the place to
268
+
copy the object code is a network server, the Corresponding Source
269
+
may be on a different server (operated by you or a third party)
270
+
that supports equivalent copying facilities, provided you maintain
271
+
clear directions next to the object code saying where to find the
272
+
Corresponding Source. Regardless of what server hosts the
273
+
Corresponding Source, you remain obligated to ensure that it is
274
+
available for as long as needed to satisfy these requirements.
275
+
276
+
e) Convey the object code using peer-to-peer transmission, provided
277
+
you inform other peers where the object code and Corresponding
278
+
Source of the work are being offered to the general public at no
279
+
charge under subsection 6d.
280
+
281
+
A separable portion of the object code, whose source code is excluded
282
+
from the Corresponding Source as a System Library, need not be
283
+
included in conveying the object code work.
284
+
285
+
A "User Product" is either (1) a "consumer product", which means any
286
+
tangible personal property which is normally used for personal, family,
287
+
or household purposes, or (2) anything designed or sold for incorporation
288
+
into a dwelling. In determining whether a product is a consumer product,
289
+
doubtful cases shall be resolved in favor of coverage. For a particular
290
+
product received by a particular user, "normally used" refers to a
291
+
typical or common use of that class of product, regardless of the status
292
+
of the particular user or of the way in which the particular user
293
+
actually uses, or expects or is expected to use, the product. A product
294
+
is a consumer product regardless of whether the product has substantial
295
+
commercial, industrial or non-consumer uses, unless such uses represent
296
+
the only significant mode of use of the product.
297
+
298
+
"Installation Information" for a User Product means any methods,
299
+
procedures, authorization keys, or other information required to install
300
+
and execute modified versions of a covered work in that User Product from
301
+
a modified version of its Corresponding Source. The information must
302
+
suffice to ensure that the continued functioning of the modified object
303
+
code is in no case prevented or interfered with solely because
304
+
modification has been made.
305
+
306
+
If you convey an object code work under this section in, or with, or
307
+
specifically for use in, a User Product, and the conveying occurs as
308
+
part of a transaction in which the right of possession and use of the
309
+
User Product is transferred to the recipient in perpetuity or for a
310
+
fixed term (regardless of how the transaction is characterized), the
311
+
Corresponding Source conveyed under this section must be accompanied
312
+
by the Installation Information. But this requirement does not apply
313
+
if neither you nor any third party retains the ability to install
314
+
modified object code on the User Product (for example, the work has
315
+
been installed in ROM).
316
+
317
+
The requirement to provide Installation Information does not include a
318
+
requirement to continue to provide support service, warranty, or updates
319
+
for a work that has been modified or installed by the recipient, or for
320
+
the User Product in which it has been modified or installed. Access to a
321
+
network may be denied when the modification itself materially and
322
+
adversely affects the operation of the network or violates the rules and
323
+
protocols for communication across the network.
324
+
325
+
Corresponding Source conveyed, and Installation Information provided,
326
+
in accord with this section must be in a format that is publicly
327
+
documented (and with an implementation available to the public in
328
+
source code form), and must require no special password or key for
329
+
unpacking, reading or copying.
330
+
331
+
7. Additional Terms.
332
+
333
+
"Additional permissions" are terms that supplement the terms of this
334
+
License by making exceptions from one or more of its conditions.
335
+
Additional permissions that are applicable to the entire Program shall
336
+
be treated as though they were included in this License, to the extent
337
+
that they are valid under applicable law. If additional permissions
338
+
apply only to part of the Program, that part may be used separately
339
+
under those permissions, but the entire Program remains governed by
340
+
this License without regard to the additional permissions.
341
+
342
+
When you convey a copy of a covered work, you may at your option
343
+
remove any additional permissions from that copy, or from any part of
344
+
it. (Additional permissions may be written to require their own
345
+
removal in certain cases when you modify the work.) You may place
346
+
additional permissions on material, added by you to a covered work,
347
+
for which you have or can give appropriate copyright permission.
348
+
349
+
Notwithstanding any other provision of this License, for material you
350
+
add to a covered work, you may (if authorized by the copyright holders of
351
+
that material) supplement the terms of this License with terms:
352
+
353
+
a) Disclaiming warranty or limiting liability differently from the
354
+
terms of sections 15 and 16 of this License; or
355
+
356
+
b) Requiring preservation of specified reasonable legal notices or
357
+
author attributions in that material or in the Appropriate Legal
358
+
Notices displayed by works containing it; or
359
+
360
+
c) Prohibiting misrepresentation of the origin of that material, or
361
+
requiring that modified versions of such material be marked in
362
+
reasonable ways as different from the original version; or
363
+
364
+
d) Limiting the use for publicity purposes of names of licensors or
365
+
authors of the material; or
366
+
367
+
e) Declining to grant rights under trademark law for use of some
368
+
trade names, trademarks, or service marks; or
369
+
370
+
f) Requiring indemnification of licensors and authors of that
371
+
material by anyone who conveys the material (or modified versions of
372
+
it) with contractual assumptions of liability to the recipient, for
373
+
any liability that these contractual assumptions directly impose on
374
+
those licensors and authors.
375
+
376
+
All other non-permissive additional terms are considered "further
377
+
restrictions" within the meaning of section 10. If the Program as you
378
+
received it, or any part of it, contains a notice stating that it is
379
+
governed by this License along with a term that is a further
380
+
restriction, you may remove that term. If a license document contains
381
+
a further restriction but permits relicensing or conveying under this
382
+
License, you may add to a covered work material governed by the terms
383
+
of that license document, provided that the further restriction does
384
+
not survive such relicensing or conveying.
385
+
386
+
If you add terms to a covered work in accord with this section, you
387
+
must place, in the relevant source files, a statement of the
388
+
additional terms that apply to those files, or a notice indicating
389
+
where to find the applicable terms.
390
+
391
+
Additional terms, permissive or non-permissive, may be stated in the
392
+
form of a separately written license, or stated as exceptions;
393
+
the above requirements apply either way.
394
+
395
+
8. Termination.
396
+
397
+
You may not propagate or modify a covered work except as expressly
398
+
provided under this License. Any attempt otherwise to propagate or
399
+
modify it is void, and will automatically terminate your rights under
400
+
this License (including any patent licenses granted under the third
401
+
paragraph of section 11).
402
+
403
+
However, if you cease all violation of this License, then your
404
+
license from a particular copyright holder is reinstated (a)
405
+
provisionally, unless and until the copyright holder explicitly and
406
+
finally terminates your license, and (b) permanently, if the copyright
407
+
holder fails to notify you of the violation by some reasonable means
408
+
prior to 60 days after the cessation.
409
+
410
+
Moreover, your license from a particular copyright holder is
411
+
reinstated permanently if the copyright holder notifies you of the
412
+
violation by some reasonable means, this is the first time you have
413
+
received notice of violation of this License (for any work) from that
414
+
copyright holder, and you cure the violation prior to 30 days after
415
+
your receipt of the notice.
416
+
417
+
Termination of your rights under this section does not terminate the
418
+
licenses of parties who have received copies or rights from you under
419
+
this License. If your rights have been terminated and not permanently
420
+
reinstated, you do not qualify to receive new licenses for the same
421
+
material under section 10.
422
+
423
+
9. Acceptance Not Required for Having Copies.
424
+
425
+
You are not required to accept this License in order to receive or
426
+
run a copy of the Program. Ancillary propagation of a covered work
427
+
occurring solely as a consequence of using peer-to-peer transmission
428
+
to receive a copy likewise does not require acceptance. However,
429
+
nothing other than this License grants you permission to propagate or
430
+
modify any covered work. These actions infringe copyright if you do
431
+
not accept this License. Therefore, by modifying or propagating a
432
+
covered work, you indicate your acceptance of this License to do so.
433
+
434
+
10. Automatic Licensing of Downstream Recipients.
435
+
436
+
Each time you convey a covered work, the recipient automatically
437
+
receives a license from the original licensors, to run, modify and
438
+
propagate that work, subject to this License. You are not responsible
439
+
for enforcing compliance by third parties with this License.
440
+
441
+
An "entity transaction" is a transaction transferring control of an
442
+
organization, or substantially all assets of one, or subdividing an
443
+
organization, or merging organizations. If propagation of a covered
444
+
work results from an entity transaction, each party to that
445
+
transaction who receives a copy of the work also receives whatever
446
+
licenses to the work the party's predecessor in interest had or could
447
+
give under the previous paragraph, plus a right to possession of the
448
+
Corresponding Source of the work from the predecessor in interest, if
449
+
the predecessor has it or can get it with reasonable efforts.
450
+
451
+
You may not impose any further restrictions on the exercise of the
452
+
rights granted or affirmed under this License. For example, you may
453
+
not impose a license fee, royalty, or other charge for exercise of
454
+
rights granted under this License, and you may not initiate litigation
455
+
(including a cross-claim or counterclaim in a lawsuit) alleging that
456
+
any patent claim is infringed by making, using, selling, offering for
457
+
sale, or importing the Program or any portion of it.
458
+
459
+
11. Patents.
460
+
461
+
A "contributor" is a copyright holder who authorizes use under this
462
+
License of the Program or a work on which the Program is based. The
463
+
work thus licensed is called the contributor's "contributor version".
464
+
465
+
A contributor's "essential patent claims" are all patent claims
466
+
owned or controlled by the contributor, whether already acquired or
467
+
hereafter acquired, that would be infringed by some manner, permitted
468
+
by this License, of making, using, or selling its contributor version,
469
+
but do not include claims that would be infringed only as a
470
+
consequence of further modification of the contributor version. For
471
+
purposes of this definition, "control" includes the right to grant
472
+
patent sublicenses in a manner consistent with the requirements of
473
+
this License.
474
+
475
+
Each contributor grants you a non-exclusive, worldwide, royalty-free
476
+
patent license under the contributor's essential patent claims, to
477
+
make, use, sell, offer for sale, import and otherwise run, modify and
478
+
propagate the contents of its contributor version.
479
+
480
+
In the following three paragraphs, a "patent license" is any express
481
+
agreement or commitment, however denominated, not to enforce a patent
482
+
(such as an express permission to practice a patent or covenant not to
483
+
sue for patent infringement). To "grant" such a patent license to a
484
+
party means to make such an agreement or commitment not to enforce a
485
+
patent against the party.
486
+
487
+
If you convey a covered work, knowingly relying on a patent license,
488
+
and the Corresponding Source of the work is not available for anyone
489
+
to copy, free of charge and under the terms of this License, through a
490
+
publicly available network server or other readily accessible means,
491
+
then you must either (1) cause the Corresponding Source to be so
492
+
available, or (2) arrange to deprive yourself of the benefit of the
493
+
patent license for this particular work, or (3) arrange, in a manner
494
+
consistent with the requirements of this License, to extend the patent
495
+
license to downstream recipients. "Knowingly relying" means you have
496
+
actual knowledge that, but for the patent license, your conveying the
497
+
covered work in a country, or your recipient's use of the covered work
498
+
in a country, would infringe one or more identifiable patents in that
499
+
country that you have reason to believe are valid.
500
+
501
+
If, pursuant to or in connection with a single transaction or
502
+
arrangement, you convey, or propagate by procuring conveyance of, a
503
+
covered work, and grant a patent license to some of the parties
504
+
receiving the covered work authorizing them to use, propagate, modify
505
+
or convey a specific copy of the covered work, then the patent license
506
+
you grant is automatically extended to all recipients of the covered
507
+
work and works based on it.
508
+
509
+
A patent license is "discriminatory" if it does not include within
510
+
the scope of its coverage, prohibits the exercise of, or is
511
+
conditioned on the non-exercise of one or more of the rights that are
512
+
specifically granted under this License. You may not convey a covered
513
+
work if you are a party to an arrangement with a third party that is
514
+
in the business of distributing software, under which you make payment
515
+
to the third party based on the extent of your activity of conveying
516
+
the work, and under which the third party grants, to any of the
517
+
parties who would receive the covered work from you, a discriminatory
518
+
patent license (a) in connection with copies of the covered work
519
+
conveyed by you (or copies made from those copies), or (b) primarily
520
+
for and in connection with specific products or compilations that
521
+
contain the covered work, unless you entered into that arrangement,
522
+
or that patent license was granted, prior to 28 March 2007.
523
+
524
+
Nothing in this License shall be construed as excluding or limiting
525
+
any implied license or other defenses to infringement that may
526
+
otherwise be available to you under applicable patent law.
527
+
528
+
12. No Surrender of Others' Freedom.
529
+
530
+
If conditions are imposed on you (whether by court order, agreement or
531
+
otherwise) that contradict the conditions of this License, they do not
532
+
excuse you from the conditions of this License. If you cannot convey a
533
+
covered work so as to satisfy simultaneously your obligations under this
534
+
License and any other pertinent obligations, then as a consequence you may
535
+
not convey it at all. For example, if you agree to terms that obligate you
536
+
to collect a royalty for further conveying from those to whom you convey
537
+
the Program, the only way you could satisfy both those terms and this
538
+
License would be to refrain entirely from conveying the Program.
539
+
540
+
13. Remote Network Interaction; Use with the GNU General Public License.
541
+
542
+
Notwithstanding any other provision of this License, if you modify the
543
+
Program, your modified version must prominently offer all users
544
+
interacting with it remotely through a computer network (if your version
545
+
supports such interaction) an opportunity to receive the Corresponding
546
+
Source of your version by providing access to the Corresponding Source
547
+
from a network server at no charge, through some standard or customary
548
+
means of facilitating copying of software. This Corresponding Source
549
+
shall include the Corresponding Source for any work covered by version 3
550
+
of the GNU General Public License that is incorporated pursuant to the
551
+
following paragraph.
552
+
553
+
Notwithstanding any other provision of this License, you have
554
+
permission to link or combine any covered work with a work licensed
555
+
under version 3 of the GNU General Public License into a single
556
+
combined work, and to convey the resulting work. The terms of this
557
+
License will continue to apply to the part which is the covered work,
558
+
but the work with which it is combined will remain governed by version
559
+
3 of the GNU General Public License.
560
+
561
+
14. Revised Versions of this License.
562
+
563
+
The Free Software Foundation may publish revised and/or new versions of
564
+
the GNU Affero General Public License from time to time. Such new versions
565
+
will be similar in spirit to the present version, but may differ in detail to
566
+
address new problems or concerns.
567
+
568
+
Each version is given a distinguishing version number. If the
569
+
Program specifies that a certain numbered version of the GNU Affero General
570
+
Public License "or any later version" applies to it, you have the
571
+
option of following the terms and conditions either of that numbered
572
+
version or of any later version published by the Free Software
573
+
Foundation. If the Program does not specify a version number of the
574
+
GNU Affero General Public License, you may choose any version ever published
575
+
by the Free Software Foundation.
576
+
577
+
If the Program specifies that a proxy can decide which future
578
+
versions of the GNU Affero General Public License can be used, that proxy's
579
+
public statement of acceptance of a version permanently authorizes you
580
+
to choose that version for the Program.
581
+
582
+
Later license versions may give you additional or different
583
+
permissions. However, no additional obligations are imposed on any
584
+
author or copyright holder as a result of your choosing to follow a
585
+
later version.
586
+
587
+
15. Disclaimer of Warranty.
588
+
589
+
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
590
+
APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
591
+
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
592
+
OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
593
+
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
594
+
PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
595
+
IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
596
+
ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
597
+
598
+
16. Limitation of Liability.
599
+
600
+
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
601
+
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
602
+
THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
603
+
GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
604
+
USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
605
+
DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
606
+
PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
607
+
EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
608
+
SUCH DAMAGES.
609
+
610
+
17. Interpretation of Sections 15 and 16.
611
+
612
+
If the disclaimer of warranty and limitation of liability provided
613
+
above cannot be given local legal effect according to their terms,
614
+
reviewing courts shall apply local law that most closely approximates
615
+
an absolute waiver of all civil liability in connection with the
616
+
Program, unless a warranty or assumption of liability accompanies a
617
+
copy of the Program in return for a fee.
618
+
619
+
END OF TERMS AND CONDITIONS
620
+
621
+
How to Apply These Terms to Your New Programs
622
+
623
+
If you develop a new program, and you want it to be of the greatest
624
+
possible use to the public, the best way to achieve this is to make it
625
+
free software which everyone can redistribute and change under these terms.
626
+
627
+
To do so, attach the following notices to the program. It is safest
628
+
to attach them to the start of each source file to most effectively
629
+
state the exclusion of warranty; and each file should have at least
630
+
the "copyright" line and a pointer to where the full notice is found.
631
+
632
+
<one line to give the program's name and a brief idea of what it does.>
633
+
Copyright (C) <year> <name of author>
634
+
635
+
This program is free software: you can redistribute it and/or modify
636
+
it under the terms of the GNU Affero General Public License as published
637
+
by the Free Software Foundation, either version 3 of the License, or
638
+
(at your option) any later version.
639
+
640
+
This program is distributed in the hope that it will be useful,
641
+
but WITHOUT ANY WARRANTY; without even the implied warranty of
642
+
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
643
+
GNU Affero General Public License for more details.
644
+
645
+
You should have received a copy of the GNU Affero General Public License
646
+
along with this program. If not, see <https://www.gnu.org/licenses/>.
647
+
648
+
Also add information on how to contact you by electronic and paper mail.
649
+
650
+
If your software can interact with users remotely through a computer
651
+
network, you should also make sure that it provides a way for users to
652
+
get its source. For example, if your program is a web application, its
653
+
interface could display a "Source" link that leads users to an archive
654
+
of the code. There are many ways you could offer source, and different
655
+
solutions will be better for different programs; see section 13 for the
656
+
specific requirements.
657
+
658
+
You should also get your employer (if you work as a programmer) or school,
659
+
if any, to sign a "copyright disclaimer" for the program, if necessary.
660
+
For more information on this, and how to apply and follow the GNU AGPL, see
661
+
<https://www.gnu.org/licenses/>.
+3
constellation/LICENSE.future
+3
constellation/LICENSE.future
+9
constellation/readme.md
+9
constellation/readme.md
···
83
83
```
84
84
85
85
86
+
## Contributions
87
+
88
+
### Licensing
89
+
90
+
Constellation's source code is currently available exclusively under the AGPL license (see [LICENSE](./LICENSE)).
91
+
92
+
In the future, its code MAY become available under the MIT and/or Apache2.0 licenses, at the sole discretion of the microcosm organization. Contributing implies acceptance with this possible future licensing change. The change has not happed yet and is not guaranteed.
93
+
94
+
86
95
some todos
87
96
88
97
- [x] find links and write them to rocksdb
+57
-14
constellation/src/bin/main.rs
+57
-14
constellation/src/bin/main.rs
···
1
1
use anyhow::{bail, Result};
2
2
use clap::{Parser, ValueEnum};
3
3
use metrics_exporter_prometheus::PrometheusBuilder;
4
+
use std::net::SocketAddr;
4
5
use std::num::NonZero;
5
6
use std::path::PathBuf;
6
7
use std::sync::{atomic::AtomicU32, Arc};
···
21
22
#[derive(Parser, Debug)]
22
23
#[command(version, about, long_about = None)]
23
24
struct Args {
24
-
#[arg(short, long)]
25
+
/// constellation server's listen address
26
+
#[arg(long)]
27
+
#[clap(default_value = "0.0.0.0:6789")]
28
+
bind: SocketAddr,
29
+
/// metrics server's listen address
30
+
#[arg(long)]
31
+
#[clap(default_value = "0.0.0.0:8765")]
32
+
bind_metrics: SocketAddr,
25
33
/// Jetstream server to connect to (exclusive with --fixture). Provide either a wss:// URL, or a shorhand value:
26
34
/// 'us-east-1', 'us-east-2', 'us-west-1', or 'us-west-2'
27
35
#[arg(short, long)]
···
46
54
/// Saved jsonl from jetstream to use instead of a live subscription
47
55
#[arg(short, long)]
48
56
fixture: Option<PathBuf>,
57
+
/// run a scan across the target id table and write all key -> ids to id -> keys
58
+
#[arg(long, action)]
59
+
repair_target_ids: bool,
49
60
}
50
61
51
62
#[derive(Debug, Clone, ValueEnum)]
···
78
89
let stream = jetstream_url(&args.jetstream);
79
90
println!("using jetstream server {stream:?}...",);
80
91
92
+
let bind = args.bind;
93
+
let metrics_bind = args.bind_metrics;
94
+
81
95
let stay_alive = CancellationToken::new();
82
96
83
97
match args.backend {
84
-
StorageBackend::Memory => run(MemStorage::new(), fixture, None, stream, stay_alive),
98
+
StorageBackend::Memory => run(
99
+
MemStorage::new(),
100
+
fixture,
101
+
None,
102
+
stream,
103
+
bind,
104
+
metrics_bind,
105
+
stay_alive,
106
+
),
85
107
#[cfg(feature = "rocks")]
86
108
StorageBackend::Rocks => {
87
109
let storage_dir = args.data.clone().unwrap_or("rocks.test".into());
···
96
118
rocks.start_backup(backup_dir, auto_backup, stay_alive.clone())?;
97
119
}
98
120
println!("rocks ready.");
99
-
run(rocks, fixture, args.data, stream, stay_alive)
121
+
std::thread::scope(|s| {
122
+
if args.repair_target_ids {
123
+
let rocks = rocks.clone();
124
+
let stay_alive = stay_alive.clone();
125
+
s.spawn(move || {
126
+
let rep = rocks.run_repair(time::Duration::from_millis(0), stay_alive);
127
+
eprintln!("repair finished: {rep:?}");
128
+
rep
129
+
});
130
+
}
131
+
s.spawn(|| {
132
+
let r = run(
133
+
rocks,
134
+
fixture,
135
+
args.data,
136
+
stream,
137
+
bind,
138
+
metrics_bind,
139
+
stay_alive,
140
+
);
141
+
eprintln!("run finished: {r:?}");
142
+
r
143
+
});
144
+
});
145
+
Ok(())
100
146
}
101
147
}
102
148
}
···
106
152
fixture: Option<PathBuf>,
107
153
data_dir: Option<PathBuf>,
108
154
stream: String,
155
+
bind: SocketAddr,
156
+
metrics_bind: SocketAddr,
109
157
stay_alive: CancellationToken,
110
158
) -> Result<()> {
111
159
ctrlc::set_handler({
···
150
198
.build()
151
199
.expect("axum startup")
152
200
.block_on(async {
153
-
install_metrics_server()?;
154
-
serve(readable, "0.0.0.0:6789", staying_alive).await
201
+
install_metrics_server(metrics_bind)?;
202
+
serve(readable, bind, staying_alive).await
155
203
})
156
204
.unwrap();
157
205
stay_alive.drop_guard();
···
184
232
185
233
'monitor: loop {
186
234
match readable.get_stats() {
187
-
Ok(StorageStats { dids, targetables, linking_records }) => {
235
+
Ok(StorageStats { dids, targetables, linking_records, .. }) => {
188
236
metrics::gauge!("storage.stats.dids").set(dids as f64);
189
237
metrics::gauge!("storage.stats.targetables").set(targetables as f64);
190
238
metrics::gauge!("storage.stats.linking_records").set(linking_records as f64);
···
218
266
Ok(())
219
267
}
220
268
221
-
fn install_metrics_server() -> Result<()> {
269
+
fn install_metrics_server(metrics_bind: SocketAddr) -> Result<()> {
222
270
println!("installing metrics server...");
223
-
let host = [0, 0, 0, 0];
224
-
let port = 8765;
225
271
PrometheusBuilder::new()
226
272
.set_quantiles(&[0.5, 0.9, 0.99, 1.0])?
227
273
.set_bucket_duration(time::Duration::from_secs(30))?
228
274
.set_bucket_count(NonZero::new(10).unwrap()) // count * duration = 5 mins. stuff doesn't happen that fast here.
229
275
.set_enable_unit_suffix(true)
230
-
.with_http_listener((host, port))
276
+
.with_http_listener(metrics_bind)
231
277
.install()?;
232
-
println!(
233
-
"metrics server installed! listening on http://{}.{}.{}.{}:{port}",
234
-
host[0], host[1], host[2], host[3]
235
-
);
278
+
println!("metrics server installed! listening at {metrics_bind:?}");
236
279
Ok(())
237
280
}
238
281
+239
-238
constellation/src/bin/rocks-link-stats.rs
+239
-238
constellation/src/bin/rocks-link-stats.rs
···
1
-
use bincode::config::Options;
2
-
use clap::Parser;
3
-
use serde::Serialize;
4
-
use std::collections::HashMap;
5
-
use std::path::PathBuf;
1
+
// use bincode::config::Options;
2
+
// use clap::Parser;
3
+
// use serde::Serialize;
4
+
// use std::collections::HashMap;
5
+
// use std::path::PathBuf;
6
6
7
-
use tokio_util::sync::CancellationToken;
7
+
// use tokio_util::sync::CancellationToken;
8
8
9
-
use constellation::storage::rocks_store::{
10
-
Collection, DidId, RKey, RPath, Target, TargetKey, TargetLinkers, _bincode_opts,
11
-
};
12
-
use constellation::storage::RocksStorage;
13
-
use constellation::Did;
9
+
// use constellation::storage::rocks_store::{
10
+
// Collection, DidId, RKey, RPath, Target, TargetKey, TargetLinkers, _bincode_opts,
11
+
// };
12
+
// use constellation::storage::RocksStorage;
13
+
// use constellation::Did;
14
14
15
-
use links::parse_any_link;
16
-
use rocksdb::IteratorMode;
17
-
use std::time;
15
+
// use links::parse_any_link;
16
+
// use rocksdb::IteratorMode;
17
+
// use std::time;
18
18
19
-
/// Aggregate links in the at-mosphere
20
-
#[derive(Parser, Debug)]
21
-
#[command(version, about, long_about = None)]
22
-
struct Args {
23
-
/// where is rocksdb's data
24
-
#[arg(short, long)]
25
-
data: PathBuf,
26
-
/// slow down so we don't kill the firehose consumer, if running concurrently
27
-
#[arg(short, long)]
28
-
limit: Option<u64>,
29
-
}
19
+
// xxxx/// Aggregate links in the at-mosphere
20
+
// #[derive(Parser, Debug)]
21
+
// #[command(version, about, long_about = None)]
22
+
// struct Args {
23
+
// /// where is rocksdb's data
24
+
// #[arg(short, long)]
25
+
// data: PathBuf,
26
+
// /// slow down so we don't kill the firehose consumer, if running concurrently
27
+
// #[arg(short, long)]
28
+
// limit: Option<u64>,
29
+
// }
30
30
31
-
type LinkType = String;
31
+
// type LinkType = String;
32
32
33
-
#[derive(Debug, Eq, Hash, PartialEq, Serialize)]
34
-
struct SourceLink(Collection, RPath, LinkType, Option<Collection>); // last is target collection, if it's an at-uri link with a collection
33
+
// #[derive(Debug, Eq, Hash, PartialEq, Serialize)]
34
+
// struct SourceLink(Collection, RPath, LinkType, Option<Collection>); // last is target collection, if it's an at-uri link with a collection
35
35
36
-
#[derive(Debug, Serialize)]
37
-
struct SourceSample {
38
-
did: String,
39
-
rkey: String,
40
-
}
36
+
// #[derive(Debug, Serialize)]
37
+
// struct SourceSample {
38
+
// did: String,
39
+
// rkey: String,
40
+
// }
41
41
42
-
#[derive(Debug, Default, Serialize)]
43
-
struct Bucket {
44
-
count: u64,
45
-
sum: u64,
46
-
sample: Option<SourceSample>,
47
-
}
42
+
// #[derive(Debug, Default, Serialize)]
43
+
// struct Bucket {
44
+
// count: u64,
45
+
// sum: u64,
46
+
// sample: Option<SourceSample>,
47
+
// }
48
48
49
-
#[derive(Debug, Default, Serialize)]
50
-
struct Buckets([Bucket; 23]);
49
+
// #[derive(Debug, Default, Serialize)]
50
+
// struct Buckets([Bucket; 23]);
51
51
52
-
const BUCKETS: [u64; 23] = [
53
-
1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 12, 16, 32, 64, 128, 256, 512, 1024, 4096, 16_384, 65_535,
54
-
262_144, 1_048_576,
55
-
];
52
+
// const BUCKETS: [u64; 23] = [
53
+
// 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 12, 16, 32, 64, 128, 256, 512, 1024, 4096, 16_384, 65_535,
54
+
// 262_144, 1_048_576,
55
+
// ];
56
56
57
-
// b1, b2, b3, b4, b5, b6, b7, b8, b9, b10, b12, b16, b32, b64, b128, b256, b512, b1024, b4096, b16384, b65535, b262144, bmax
57
+
// xxx// b1, b2, b3, b4, b5, b6, b7, b8, b9, b10, b12, b16, b32, b64, b128, b256, b512, b1024, b4096, b16384, b65535, b262144, bmax
58
58
59
-
static DID_IDS_CF: &str = "did_ids";
60
-
static TARGET_IDS_CF: &str = "target_ids";
61
-
static TARGET_LINKERS_CF: &str = "target_links";
59
+
// static DID_IDS_CF: &str = "did_ids";
60
+
// static TARGET_IDS_CF: &str = "target_ids";
61
+
// static TARGET_LINKERS_CF: &str = "target_links";
62
62
63
-
const REPORT_INTERVAL: usize = 50_000;
63
+
// const REPORT_INTERVAL: usize = 50_000;
64
64
65
-
type Stats = HashMap<SourceLink, Buckets>;
65
+
// type Stats = HashMap<SourceLink, Buckets>;
66
66
67
-
#[derive(Debug, Serialize)]
68
-
struct Printable {
69
-
collection: String,
70
-
path: String,
71
-
link_type: String,
72
-
target_collection: Option<String>,
73
-
buckets: Buckets,
74
-
}
67
+
// #[derive(Debug, Serialize)]
68
+
// struct Printable {
69
+
// collection: String,
70
+
// path: String,
71
+
// link_type: String,
72
+
// target_collection: Option<String>,
73
+
// buckets: Buckets,
74
+
// }
75
75
76
-
#[derive(Debug, Default)]
77
-
struct ErrStats {
78
-
failed_to_get_sample: usize,
79
-
failed_to_read_target_id: usize,
80
-
failed_to_deserialize_target_key: usize,
81
-
failed_to_parse_target_as_link: usize,
82
-
failed_to_get_links: usize,
83
-
failed_to_deserialize_linkers: usize,
84
-
}
76
+
// #[derive(Debug, Default)]
77
+
// struct ErrStats {
78
+
// failed_to_get_sample: usize,
79
+
// failed_to_read_target_id: usize,
80
+
// failed_to_deserialize_target_key: usize,
81
+
// failed_to_parse_target_as_link: usize,
82
+
// failed_to_get_links: usize,
83
+
// failed_to_deserialize_linkers: usize,
84
+
// }
85
85
86
-
fn thousands(n: usize) -> String {
87
-
n.to_string()
88
-
.as_bytes()
89
-
.rchunks(3)
90
-
.rev()
91
-
.map(std::str::from_utf8)
92
-
.collect::<Result<Vec<&str>, _>>()
93
-
.unwrap()
94
-
.join(",")
95
-
}
86
+
// fn thousands(n: usize) -> String {
87
+
// n.to_string()
88
+
// .as_bytes()
89
+
// .rchunks(3)
90
+
// .rev()
91
+
// .map(std::str::from_utf8)
92
+
// .collect::<Result<Vec<&str>, _>>()
93
+
// .unwrap()
94
+
// .join(",")
95
+
// }
96
96
97
-
fn main() {
98
-
let args = Args::parse();
97
+
// fn main() {
98
+
// let args = Args::parse();
99
99
100
-
let limit = args.limit.map(|amount| {
101
-
ratelimit::Ratelimiter::builder(amount, time::Duration::from_secs(1))
102
-
.max_tokens(amount)
103
-
.initial_available(amount)
104
-
.build()
105
-
.unwrap()
106
-
});
100
+
// let limit = args.limit.map(|amount| {
101
+
// ratelimit::Ratelimiter::builder(amount, time::Duration::from_secs(1))
102
+
// .max_tokens(amount)
103
+
// .initial_available(amount)
104
+
// .build()
105
+
// .unwrap()
106
+
// });
107
107
108
-
eprintln!("starting rocksdb...");
109
-
let rocks = RocksStorage::open_readonly(args.data).unwrap();
110
-
eprintln!("rocks ready.");
108
+
// eprintln!("starting rocksdb...");
109
+
// let rocks = RocksStorage::open_readonly(args.data).unwrap();
110
+
// eprintln!("rocks ready.");
111
111
112
-
let RocksStorage { ref db, .. } = rocks;
112
+
// let RocksStorage { ref db, .. } = rocks;
113
113
114
-
let stay_alive = CancellationToken::new();
115
-
ctrlc::set_handler({
116
-
let mut desperation: u8 = 0;
117
-
let stay_alive = stay_alive.clone();
118
-
move || match desperation {
119
-
0 => {
120
-
eprintln!("ok, shutting down...");
121
-
stay_alive.cancel();
122
-
desperation += 1;
123
-
}
124
-
1.. => panic!("fine, panicking!"),
125
-
}
126
-
})
127
-
.unwrap();
114
+
// let stay_alive = CancellationToken::new();
115
+
// ctrlc::set_handler({
116
+
// let mut desperation: u8 = 0;
117
+
// let stay_alive = stay_alive.clone();
118
+
// move || match desperation {
119
+
// 0 => {
120
+
// eprintln!("ok, shutting down...");
121
+
// stay_alive.cancel();
122
+
// desperation += 1;
123
+
// }
124
+
// 1.. => panic!("fine, panicking!"),
125
+
// }
126
+
// })
127
+
// .unwrap();
128
128
129
-
let mut stats = Stats::new();
130
-
let mut err_stats: ErrStats = Default::default();
129
+
// let mut stats = Stats::new();
130
+
// let mut err_stats: ErrStats = Default::default();
131
131
132
-
let did_ids_cf = db.cf_handle(DID_IDS_CF).unwrap();
133
-
let target_id_cf = db.cf_handle(TARGET_IDS_CF).unwrap();
134
-
let target_links_cf = db.cf_handle(TARGET_LINKERS_CF).unwrap();
132
+
// let did_ids_cf = db.cf_handle(DID_IDS_CF).unwrap();
133
+
// let target_id_cf = db.cf_handle(TARGET_IDS_CF).unwrap();
134
+
// let target_links_cf = db.cf_handle(TARGET_LINKERS_CF).unwrap();
135
135
136
-
let t0 = time::Instant::now();
137
-
let mut t_prev = t0;
136
+
// let t0 = time::Instant::now();
137
+
// let mut t_prev = t0;
138
138
139
-
let mut i = 0;
140
-
for item in db.iterator_cf(&target_id_cf, IteratorMode::Start) {
141
-
if stay_alive.is_cancelled() {
142
-
break;
143
-
}
139
+
// let mut i = 0;
140
+
// for item in db.iterator_cf(&target_id_cf, IteratorMode::Start) {
141
+
// if stay_alive.is_cancelled() {
142
+
// break;
143
+
// }
144
144
145
-
if let Some(ref limiter) = limit {
146
-
if let Err(dur) = limiter.try_wait() {
147
-
std::thread::sleep(dur)
148
-
}
149
-
}
145
+
// if let Some(ref limiter) = limit {
146
+
// if let Err(dur) = limiter.try_wait() {
147
+
// std::thread::sleep(dur)
148
+
// }
149
+
// }
150
150
151
-
if i > 0 && i % REPORT_INTERVAL == 0 {
152
-
let now = time::Instant::now();
153
-
let rate = (REPORT_INTERVAL as f32) / (now.duration_since(t_prev).as_secs_f32());
154
-
eprintln!(
155
-
"{i}\t({}k)\t{:.2}\t{rate:.1}/s",
156
-
thousands(i / 1000),
157
-
t0.elapsed().as_secs_f32()
158
-
);
159
-
t_prev = now;
160
-
}
161
-
i += 1;
151
+
// if i > 0 && i % REPORT_INTERVAL == 0 {
152
+
// let now = time::Instant::now();
153
+
// let rate = (REPORT_INTERVAL as f32) / (now.duration_since(t_prev).as_secs_f32());
154
+
// eprintln!(
155
+
// "{i}\t({}k)\t{:.2}\t{rate:.1}/s",
156
+
// thousands(i / 1000),
157
+
// t0.elapsed().as_secs_f32()
158
+
// );
159
+
// t_prev = now;
160
+
// }
161
+
// i += 1;
162
162
163
-
let Ok((target_key, target_id)) = item else {
164
-
err_stats.failed_to_read_target_id += 1;
165
-
continue;
166
-
};
163
+
// let Ok((target_key, target_id)) = item else {
164
+
// err_stats.failed_to_read_target_id += 1;
165
+
// continue;
166
+
// };
167
167
168
-
let Ok(TargetKey(Target(target), collection, rpath)) =
169
-
_bincode_opts().deserialize(&target_key)
170
-
else {
171
-
err_stats.failed_to_deserialize_target_key += 1;
172
-
continue;
173
-
};
168
+
// let Ok(TargetKey(Target(target), collection, rpath)) =
169
+
// _bincode_opts().deserialize(&target_key)
170
+
// else {
171
+
// err_stats.failed_to_deserialize_target_key += 1;
172
+
// continue;
173
+
// };
174
174
175
-
let source = {
176
-
let Some(parsed) = parse_any_link(&target) else {
177
-
err_stats.failed_to_parse_target_as_link += 1;
178
-
continue;
179
-
};
180
-
SourceLink(
181
-
collection,
182
-
rpath,
183
-
parsed.name().into(),
184
-
parsed.at_uri_collection().map(Collection),
185
-
)
186
-
};
175
+
// let source = {
176
+
// let Some(parsed) = parse_any_link(&target) else {
177
+
// err_stats.failed_to_parse_target_as_link += 1;
178
+
// continue;
179
+
// };
180
+
// SourceLink(
181
+
// collection,
182
+
// rpath,
183
+
// parsed.name().into(),
184
+
// parsed.at_uri_collection().map(Collection),
185
+
// )
186
+
// };
187
187
188
-
let Ok(Some(links_raw)) = db.get_cf(&target_links_cf, &target_id) else {
189
-
err_stats.failed_to_get_links += 1;
190
-
continue;
191
-
};
192
-
let Ok(linkers) = _bincode_opts().deserialize::<TargetLinkers>(&links_raw) else {
193
-
err_stats.failed_to_deserialize_linkers += 1;
194
-
continue;
195
-
};
196
-
let (n, _) = linkers.count();
188
+
// let Ok(Some(links_raw)) = db.get_cf(&target_links_cf, &target_id) else {
189
+
// err_stats.failed_to_get_links += 1;
190
+
// continue;
191
+
// };
192
+
// let Ok(linkers) = _bincode_opts().deserialize::<TargetLinkers>(&links_raw) else {
193
+
// err_stats.failed_to_deserialize_linkers += 1;
194
+
// continue;
195
+
// };
196
+
// let (n, _) = linkers.count();
197
197
198
-
if n == 0 {
199
-
continue;
200
-
}
198
+
// if n == 0 {
199
+
// continue;
200
+
// }
201
201
202
-
let mut bucket = 0;
203
-
for edge in BUCKETS {
204
-
if n <= edge || bucket == 22 {
205
-
break;
206
-
}
207
-
bucket += 1;
208
-
}
202
+
// let mut bucket = 0;
203
+
// for edge in BUCKETS {
204
+
// if n <= edge || bucket == 22 {
205
+
// break;
206
+
// }
207
+
// bucket += 1;
208
+
// }
209
209
210
-
let b = &mut stats.entry(source).or_default().0[bucket];
211
-
b.count += 1;
212
-
b.sum += n;
213
-
if b.sample.is_none() {
214
-
let (DidId(did_id), RKey(k)) = &linkers.0[(n - 1) as usize];
215
-
if let Ok(Some(did_bytes)) = db.get_cf(&did_ids_cf, did_id.to_be_bytes()) {
216
-
if let Ok(Did(did)) = _bincode_opts().deserialize(&did_bytes) {
217
-
b.sample = Some(SourceSample {
218
-
did,
219
-
rkey: k.clone(),
220
-
});
221
-
} else {
222
-
err_stats.failed_to_get_sample += 1;
223
-
}
224
-
} else {
225
-
err_stats.failed_to_get_sample += 1;
226
-
}
227
-
}
210
+
// let b = &mut stats.entry(source).or_default().0[bucket];
211
+
// b.count += 1;
212
+
// b.sum += n;
213
+
// if b.sample.is_none() {
214
+
// let (DidId(did_id), RKey(k)) = &linkers.0[(n - 1) as usize];
215
+
// if let Ok(Some(did_bytes)) = db.get_cf(&did_ids_cf, did_id.to_be_bytes()) {
216
+
// if let Ok(Did(did)) = _bincode_opts().deserialize(&did_bytes) {
217
+
// b.sample = Some(SourceSample {
218
+
// did,
219
+
// rkey: k.clone(),
220
+
// });
221
+
// } else {
222
+
// err_stats.failed_to_get_sample += 1;
223
+
// }
224
+
// } else {
225
+
// err_stats.failed_to_get_sample += 1;
226
+
// }
227
+
// }
228
228
229
-
// if i >= 40_000 {
230
-
// break;
231
-
// }
232
-
}
229
+
// // if i >= 40_000 {
230
+
// // break;
231
+
// // }
232
+
// }
233
233
234
-
let dt = t0.elapsed();
234
+
// let dt = t0.elapsed();
235
235
236
-
eprintln!("gathering stats for output...");
236
+
// eprintln!("gathering stats for output...");
237
237
238
-
let itemified = stats
239
-
.into_iter()
240
-
.map(
241
-
|(
242
-
SourceLink(Collection(collection), RPath(path), link_type, target_collection),
243
-
buckets,
244
-
)| Printable {
245
-
collection,
246
-
path,
247
-
link_type,
248
-
target_collection: target_collection.map(|Collection(c)| c),
249
-
buckets,
250
-
},
251
-
)
252
-
.collect::<Vec<_>>();
238
+
// let itemified = stats
239
+
// .into_iter()
240
+
// .map(
241
+
// |(
242
+
// SourceLink(Collection(collection), RPath(path), link_type, target_collection),
243
+
// buckets,
244
+
// )| Printable {
245
+
// collection,
246
+
// path,
247
+
// link_type,
248
+
// target_collection: target_collection.map(|Collection(c)| c),
249
+
// buckets,
250
+
// },
251
+
// )
252
+
// .collect::<Vec<_>>();
253
253
254
-
match serde_json::to_string(&itemified) {
255
-
Ok(s) => println!("{s}"),
256
-
Err(e) => eprintln!("failed to serialize results: {e:?}"),
257
-
}
254
+
// match serde_json::to_string(&itemified) {
255
+
// Ok(s) => println!("{s}"),
256
+
// Err(e) => eprintln!("failed to serialize results: {e:?}"),
257
+
// }
258
258
259
-
eprintln!(
260
-
"{} summarizing {} link targets in {:.1}s",
261
-
if stay_alive.is_cancelled() {
262
-
"STOPPED"
263
-
} else {
264
-
"FINISHED"
265
-
},
266
-
thousands(i),
267
-
dt.as_secs_f32()
268
-
);
269
-
eprintln!("{err_stats:?}");
270
-
eprintln!("bye.");
271
-
}
259
+
// eprintln!(
260
+
// "{} summarizing {} link targets in {:.1}s",
261
+
// if stay_alive.is_cancelled() {
262
+
// "STOPPED"
263
+
// } else {
264
+
// "FINISHED"
265
+
// },
266
+
// thousands(i),
267
+
// dt.as_secs_f32()
268
+
// );
269
+
// eprintln!("{err_stats:?}");
270
+
// eprintln!("bye.");
271
+
// }
272
272
273
-
// scan plan
273
+
// xxx// scan plan
274
274
275
-
// buckets (backlink count)
276
-
// 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 12, 16, 32, 64, 128, 256, 512, 1024, 4096, 16384, 65535, 262144, 1048576+
277
-
// by
278
-
// - collection
279
-
// - json path
280
-
// - link type
281
-
// samples for each bucket for each variation
275
+
// xxx// buckets (backlink count)
276
+
// xxx// 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 12, 16, 32, 64, 128, 256, 512, 1024, 4096, 16384, 65535, 262144, 1048576+
277
+
// xxx// by
278
+
// xxx// - collection
279
+
// xxx// - json path
280
+
// xxx// - link type
281
+
// xxx// samples for each bucket for each variation
282
+
fn main() {}
+2
constellation/src/bin/rocks-restore-from-backup.rs
+2
constellation/src/bin/rocks-restore-from-backup.rs
···
3
3
use clap::Parser;
4
4
use std::path::PathBuf;
5
5
6
+
#[cfg(feature = "rocks")]
6
7
use rocksdb::backup::{BackupEngine, BackupEngineOptions, RestoreOptions};
7
8
8
9
use std::time;
···
19
20
to_data_dir: PathBuf,
20
21
}
21
22
23
+
#[cfg(feature = "rocks")]
22
24
fn main() -> Result<()> {
23
25
let args = Args::parse();
24
26
+13
-6
constellation/src/consumer/jetstream.rs
+13
-6
constellation/src/consumer/jetstream.rs
···
226
226
println!("jetstream closed the websocket cleanly.");
227
227
break;
228
228
}
229
-
r => eprintln!("jetstream: close result after error: {r:?}"),
229
+
Err(_) => {
230
+
counter!("jetstream_read_fail", "url" => stream.clone(), "reason" => "dirty close").increment(1);
231
+
println!("jetstream failed to close the websocket cleanly.");
232
+
break;
233
+
}
234
+
Ok(r) => {
235
+
eprintln!("jetstream: close result after error: {r:?}");
236
+
counter!("jetstream_read_fail", "url" => stream.clone(), "reason" => "read error")
237
+
.increment(1);
238
+
// if we didn't immediately get ConnectionClosed, we should keep polling read
239
+
// until we get it.
240
+
continue;
241
+
}
230
242
}
231
-
counter!("jetstream_read_fail", "url" => stream.clone(), "reason" => "read error")
232
-
.increment(1);
233
-
// if we didn't immediately get ConnectionClosed, we should keep polling read
234
-
// until we get it.
235
-
continue;
236
243
}
237
244
};
238
245
+8
-6
constellation/src/server/filters.rs
+8
-6
constellation/src/server/filters.rs
···
5
5
Ok({
6
6
if let Some(link) = parse_any_link(s) {
7
7
match link {
8
-
Link::AtUri(at_uri) => at_uri.strip_prefix("at://").map(|noproto| {
9
-
format!("https://atproto-browser-plus-links.vercel.app/at/{noproto}")
10
-
}),
11
-
Link::Did(did) => Some(format!(
12
-
"https://atproto-browser-plus-links.vercel.app/at/{did}"
13
-
)),
8
+
Link::AtUri(at_uri) => at_uri
9
+
.strip_prefix("at://")
10
+
.map(|noproto| format!("https://pdsls.dev/at://{noproto}")),
11
+
Link::Did(did) => Some(format!("https://pdsls.dev/at://{did}")),
14
12
Link::Uri(uri) => Some(uri),
15
13
}
16
14
} else {
···
22
20
pub fn human_number(n: &u64) -> askama::Result<String> {
23
21
Ok(n.to_formatted_string(&Locale::en))
24
22
}
23
+
24
+
pub fn to_u64(n: usize) -> askama::Result<u64> {
25
+
Ok(n as u64)
26
+
}
+332
-19
constellation/src/server/mod.rs
+332
-19
constellation/src/server/mod.rs
···
11
11
use bincode::Options;
12
12
use serde::{Deserialize, Serialize};
13
13
use serde_with::serde_as;
14
-
use std::collections::HashMap;
14
+
use std::collections::{HashMap, HashSet};
15
15
use std::time::{Duration, UNIX_EPOCH};
16
16
use tokio::net::{TcpListener, ToSocketAddrs};
17
-
use tokio::task::block_in_place;
17
+
use tokio::task::spawn_blocking;
18
18
use tokio_util::sync::CancellationToken;
19
19
20
20
use crate::storage::{LinkReader, StorageStats};
···
28
28
const DEFAULT_CURSOR_LIMIT: u64 = 16;
29
29
const DEFAULT_CURSOR_LIMIT_MAX: u64 = 100;
30
30
31
-
const INDEX_BEGAN_AT_TS: u64 = 1738083600; // TODO: not this
31
+
fn get_default_cursor_limit() -> u64 {
32
+
DEFAULT_CURSOR_LIMIT
33
+
}
34
+
35
+
fn to500(e: tokio::task::JoinError) -> http::StatusCode {
36
+
eprintln!("handler error: {e}");
37
+
http::StatusCode::INTERNAL_SERVER_ERROR
38
+
}
32
39
33
40
pub async fn serve<S, A>(store: S, addr: A, stay_alive: CancellationToken) -> anyhow::Result<()>
34
41
where
···
41
48
"/",
42
49
get({
43
50
let store = store.clone();
44
-
move |accept| async { block_in_place(|| hello(accept, store)) }
51
+
move |accept| async {
52
+
spawn_blocking(|| hello(accept, store))
53
+
.await
54
+
.map_err(to500)?
55
+
}
56
+
}),
57
+
)
58
+
.route(
59
+
"/xrpc/blue.microcosm.links.getManyToManyCounts",
60
+
get({
61
+
let store = store.clone();
62
+
move |accept, query| async {
63
+
spawn_blocking(|| get_many_to_many_counts(accept, query, store))
64
+
.await
65
+
.map_err(to500)?
66
+
}
45
67
}),
46
68
)
47
69
.route(
48
70
"/links/count",
49
71
get({
50
72
let store = store.clone();
51
-
move |accept, query| async { block_in_place(|| count_links(accept, query, store)) }
73
+
move |accept, query| async {
74
+
spawn_blocking(|| count_links(accept, query, store))
75
+
.await
76
+
.map_err(to500)?
77
+
}
52
78
}),
53
79
)
54
80
.route(
···
56
82
get({
57
83
let store = store.clone();
58
84
move |accept, query| async {
59
-
block_in_place(|| count_distinct_dids(accept, query, store))
85
+
spawn_blocking(|| count_distinct_dids(accept, query, store))
86
+
.await
87
+
.map_err(to500)?
88
+
}
89
+
}),
90
+
)
91
+
.route(
92
+
"/xrpc/blue.microcosm.links.getBacklinks",
93
+
get({
94
+
let store = store.clone();
95
+
move |accept, query| async {
96
+
spawn_blocking(|| get_backlinks(accept, query, store))
97
+
.await
98
+
.map_err(to500)?
60
99
}
61
100
}),
62
101
)
···
64
103
"/links",
65
104
get({
66
105
let store = store.clone();
67
-
move |accept, query| async { block_in_place(|| get_links(accept, query, store)) }
106
+
move |accept, query| async {
107
+
spawn_blocking(|| get_links(accept, query, store))
108
+
.await
109
+
.map_err(to500)?
110
+
}
68
111
}),
69
112
)
70
113
.route(
···
72
115
get({
73
116
let store = store.clone();
74
117
move |accept, query| async {
75
-
block_in_place(|| get_distinct_dids(accept, query, store))
118
+
spawn_blocking(|| get_distinct_dids(accept, query, store))
119
+
.await
120
+
.map_err(to500)?
76
121
}
77
122
}),
78
123
)
···
82
127
get({
83
128
let store = store.clone();
84
129
move |accept, query| async {
85
-
block_in_place(|| count_all_links(accept, query, store))
130
+
spawn_blocking(|| count_all_links(accept, query, store))
131
+
.await
132
+
.map_err(to500)?
86
133
}
87
134
}),
88
135
)
···
91
138
get({
92
139
let store = store.clone();
93
140
move |accept, query| async {
94
-
block_in_place(|| explore_links(accept, query, store))
141
+
spawn_blocking(|| explore_links(accept, query, store))
142
+
.await
143
+
.map_err(to500)?
95
144
}
96
145
}),
97
146
)
···
150
199
#[template(path = "hello.html.j2")]
151
200
struct HelloReponse {
152
201
help: &'static str,
153
-
days_indexed: u64,
202
+
days_indexed: Option<u64>,
154
203
stats: StorageStats,
155
204
}
156
205
fn hello(
···
160
209
let stats = store
161
210
.get_stats()
162
211
.map_err(|_| http::StatusCode::INTERNAL_SERVER_ERROR)?;
163
-
let days_indexed = (UNIX_EPOCH + Duration::from_secs(INDEX_BEGAN_AT_TS))
164
-
.elapsed()
212
+
let days_indexed = stats
213
+
.started_at
214
+
.map(|c| (UNIX_EPOCH + Duration::from_micros(c)).elapsed())
215
+
.transpose()
165
216
.map_err(|_| http::StatusCode::INTERNAL_SERVER_ERROR)?
166
-
.as_secs()
167
-
/ 86400;
217
+
.map(|d| d.as_secs() / 86_400);
168
218
Ok(acceptable(accept, HelloReponse {
169
219
help: "open this URL in a web browser (or request with Accept: text/html) for information about this API.",
170
220
days_indexed,
···
173
223
}
174
224
175
225
#[derive(Clone, Deserialize)]
226
+
#[serde(rename_all = "camelCase")]
227
+
struct GetManyToManyCountsQuery {
228
+
subject: String,
229
+
source: String,
230
+
/// path to the secondary link in the linking record
231
+
path_to_other: String,
232
+
/// filter to linking records (join of the m2m) by these DIDs
233
+
#[serde(default)]
234
+
did: Vec<String>,
235
+
/// filter to specific secondary records
236
+
#[serde(default)]
237
+
other_subject: Vec<String>,
238
+
cursor: Option<OpaqueApiCursor>,
239
+
/// Set the max number of links to return per page of results
240
+
#[serde(default = "get_default_cursor_limit")]
241
+
limit: u64,
242
+
}
243
+
#[derive(Serialize)]
244
+
struct OtherSubjectCount {
245
+
subject: String,
246
+
total: u64,
247
+
distinct: u64,
248
+
}
249
+
#[derive(Template, Serialize)]
250
+
#[template(path = "get-many-to-many-counts.html.j2")]
251
+
struct GetManyToManyCountsResponse {
252
+
counts_by_other_subject: Vec<OtherSubjectCount>,
253
+
cursor: Option<OpaqueApiCursor>,
254
+
#[serde(skip_serializing)]
255
+
query: GetManyToManyCountsQuery,
256
+
}
257
+
fn get_many_to_many_counts(
258
+
accept: ExtractAccept,
259
+
query: axum_extra::extract::Query<GetManyToManyCountsQuery>,
260
+
store: impl LinkReader,
261
+
) -> Result<impl IntoResponse, http::StatusCode> {
262
+
let cursor_key = query
263
+
.cursor
264
+
.clone()
265
+
.map(|oc| ApiKeyedCursor::try_from(oc).map_err(|_| http::StatusCode::BAD_REQUEST))
266
+
.transpose()?
267
+
.map(|c| c.next);
268
+
269
+
let limit = query.limit;
270
+
if limit > DEFAULT_CURSOR_LIMIT_MAX {
271
+
return Err(http::StatusCode::BAD_REQUEST);
272
+
}
273
+
274
+
let filter_dids: HashSet<Did> = HashSet::from_iter(
275
+
query
276
+
.did
277
+
.iter()
278
+
.map(|d| d.trim())
279
+
.filter(|d| !d.is_empty())
280
+
.map(|d| Did(d.to_string())),
281
+
);
282
+
283
+
let filter_other_subjects: HashSet<String> = HashSet::from_iter(
284
+
query
285
+
.other_subject
286
+
.iter()
287
+
.map(|s| s.trim().to_string())
288
+
.filter(|s| !s.is_empty()),
289
+
);
290
+
291
+
let Some((collection, path)) = query.source.split_once(':') else {
292
+
return Err(http::StatusCode::BAD_REQUEST);
293
+
};
294
+
let path = format!(".{path}");
295
+
296
+
let path_to_other = format!(".{}", query.path_to_other);
297
+
298
+
let paged = store
299
+
.get_many_to_many_counts(
300
+
&query.subject,
301
+
collection,
302
+
&path,
303
+
&path_to_other,
304
+
limit,
305
+
cursor_key,
306
+
&filter_dids,
307
+
&filter_other_subjects,
308
+
)
309
+
.map_err(|_| http::StatusCode::INTERNAL_SERVER_ERROR)?;
310
+
311
+
let cursor = paged.next.map(|next| ApiKeyedCursor { next }.into());
312
+
313
+
let items = paged
314
+
.items
315
+
.into_iter()
316
+
.map(|(subject, total, distinct)| OtherSubjectCount {
317
+
subject,
318
+
total,
319
+
distinct,
320
+
})
321
+
.collect();
322
+
323
+
Ok(acceptable(
324
+
accept,
325
+
GetManyToManyCountsResponse {
326
+
counts_by_other_subject: items,
327
+
cursor,
328
+
query: (*query).clone(),
329
+
},
330
+
))
331
+
}
332
+
333
+
#[derive(Clone, Deserialize)]
176
334
struct GetLinksCountQuery {
177
335
target: String,
178
336
collection: String,
···
233
391
}
234
392
235
393
#[derive(Clone, Deserialize)]
394
+
struct GetBacklinksQuery {
395
+
/// The link target
396
+
///
397
+
/// can be an AT-URI, plain DID, or regular URI
398
+
subject: String,
399
+
/// Filter links only from this link source
400
+
///
401
+
/// eg.: `app.bsky.feed.like:subject.uri`
402
+
source: String,
403
+
cursor: Option<OpaqueApiCursor>,
404
+
/// Filter links only from these DIDs
405
+
///
406
+
/// include multiple times to filter by multiple source DIDs
407
+
#[serde(default)]
408
+
did: Vec<String>,
409
+
/// Set the max number of links to return per page of results
410
+
#[serde(default = "get_default_cursor_limit")]
411
+
limit: u64,
412
+
// TODO: allow reverse (er, forward) order as well
413
+
}
414
+
#[derive(Template, Serialize)]
415
+
#[template(path = "get-backlinks.html.j2")]
416
+
struct GetBacklinksResponse {
417
+
total: u64,
418
+
records: Vec<RecordId>,
419
+
cursor: Option<OpaqueApiCursor>,
420
+
#[serde(skip_serializing)]
421
+
query: GetBacklinksQuery,
422
+
#[serde(skip_serializing)]
423
+
collection: String,
424
+
#[serde(skip_serializing)]
425
+
path: String,
426
+
}
427
+
fn get_backlinks(
428
+
accept: ExtractAccept,
429
+
query: axum_extra::extract::Query<GetBacklinksQuery>, // supports multiple param occurrences
430
+
store: impl LinkReader,
431
+
) -> Result<impl IntoResponse, http::StatusCode> {
432
+
let until = query
433
+
.cursor
434
+
.clone()
435
+
.map(|oc| ApiCursor::try_from(oc).map_err(|_| http::StatusCode::BAD_REQUEST))
436
+
.transpose()?
437
+
.map(|c| c.next);
438
+
439
+
let limit = query.limit;
440
+
if limit > DEFAULT_CURSOR_LIMIT_MAX {
441
+
return Err(http::StatusCode::BAD_REQUEST);
442
+
}
443
+
444
+
let filter_dids: HashSet<Did> = HashSet::from_iter(
445
+
query
446
+
.did
447
+
.iter()
448
+
.map(|d| d.trim())
449
+
.filter(|d| !d.is_empty())
450
+
.map(|d| Did(d.to_string())),
451
+
);
452
+
453
+
let Some((collection, path)) = query.source.split_once(':') else {
454
+
return Err(http::StatusCode::BAD_REQUEST);
455
+
};
456
+
let path = format!(".{path}");
457
+
458
+
let paged = store
459
+
.get_links(
460
+
&query.subject,
461
+
collection,
462
+
&path,
463
+
limit,
464
+
until,
465
+
&filter_dids,
466
+
)
467
+
.map_err(|_| http::StatusCode::INTERNAL_SERVER_ERROR)?;
468
+
469
+
let cursor = paged.next.map(|next| {
470
+
ApiCursor {
471
+
version: paged.version,
472
+
next,
473
+
}
474
+
.into()
475
+
});
476
+
477
+
Ok(acceptable(
478
+
accept,
479
+
GetBacklinksResponse {
480
+
total: paged.total,
481
+
records: paged.items,
482
+
cursor,
483
+
query: (*query).clone(),
484
+
collection: collection.to_string(),
485
+
path,
486
+
},
487
+
))
488
+
}
489
+
490
+
#[derive(Clone, Deserialize)]
236
491
struct GetLinkItemsQuery {
237
492
target: String,
238
493
collection: String,
239
494
path: String,
240
495
cursor: Option<OpaqueApiCursor>,
241
-
limit: Option<u64>,
496
+
/// Filter links only from these DIDs
497
+
///
498
+
/// include multiple times to filter by multiple source DIDs
499
+
#[serde(default)]
500
+
did: Vec<String>,
501
+
/// [deprecated] Filter links only from these DIDs
502
+
///
503
+
/// format: comma-separated sequence of DIDs
504
+
///
505
+
/// errors: if `did` parameter is also present
506
+
///
507
+
/// deprecated: use `did`, which can be repeated multiple times
508
+
from_dids: Option<String>, // comma separated: gross
509
+
#[serde(default = "get_default_cursor_limit")]
510
+
limit: u64,
242
511
// TODO: allow reverse (er, forward) order as well
243
512
}
244
513
#[derive(Template, Serialize)]
···
255
524
}
256
525
fn get_links(
257
526
accept: ExtractAccept,
258
-
query: Query<GetLinkItemsQuery>,
527
+
query: axum_extra::extract::Query<GetLinkItemsQuery>, // supports multiple param occurrences
259
528
store: impl LinkReader,
260
529
) -> Result<impl IntoResponse, http::StatusCode> {
261
530
let until = query
···
265
534
.transpose()?
266
535
.map(|c| c.next);
267
536
268
-
let limit = query.limit.unwrap_or(DEFAULT_CURSOR_LIMIT);
537
+
let limit = query.limit;
269
538
if limit > DEFAULT_CURSOR_LIMIT_MAX {
270
539
return Err(http::StatusCode::BAD_REQUEST);
271
540
}
272
541
542
+
let mut filter_dids: HashSet<Did> = HashSet::from_iter(
543
+
query
544
+
.did
545
+
.iter()
546
+
.map(|d| d.trim())
547
+
.filter(|d| !d.is_empty())
548
+
.map(|d| Did(d.to_string())),
549
+
);
550
+
551
+
if let Some(comma_joined) = &query.from_dids {
552
+
if !filter_dids.is_empty() {
553
+
return Err(http::StatusCode::BAD_REQUEST);
554
+
}
555
+
for did in comma_joined.split(',') {
556
+
filter_dids.insert(Did(did.to_string()));
557
+
}
558
+
}
559
+
273
560
let paged = store
274
-
.get_links(&query.target, &query.collection, &query.path, limit, until)
561
+
.get_links(
562
+
&query.target,
563
+
&query.collection,
564
+
&query.path,
565
+
limit,
566
+
until,
567
+
&filter_dids,
568
+
)
275
569
.map_err(|_| http::StatusCode::INTERNAL_SERVER_ERROR)?;
276
570
277
571
let cursor = paged.next.map(|next| {
···
433
727
OpaqueApiCursor(bincode::DefaultOptions::new().serialize(&item).unwrap())
434
728
}
435
729
}
730
+
731
+
#[derive(Serialize, Deserialize)] // for bincode
732
+
struct ApiKeyedCursor {
733
+
next: String, // the key
734
+
}
735
+
736
+
impl TryFrom<OpaqueApiCursor> for ApiKeyedCursor {
737
+
type Error = bincode::Error;
738
+
739
+
fn try_from(item: OpaqueApiCursor) -> Result<Self, Self::Error> {
740
+
bincode::DefaultOptions::new().deserialize(&item.0)
741
+
}
742
+
}
743
+
744
+
impl From<ApiKeyedCursor> for OpaqueApiCursor {
745
+
fn from(item: ApiKeyedCursor) -> Self {
746
+
OpaqueApiCursor(bincode::DefaultOptions::new().serialize(&item).unwrap())
747
+
}
748
+
}
+93
-1
constellation/src/storage/mem_store.rs
+93
-1
constellation/src/storage/mem_store.rs
···
1
-
use super::{LinkReader, LinkStorage, PagedAppendingCollection, StorageStats};
1
+
use super::{
2
+
LinkReader, LinkStorage, PagedAppendingCollection, PagedOrderedCollection, StorageStats,
3
+
};
2
4
use crate::{ActionableEvent, CountsByCount, Did, RecordId};
3
5
use anyhow::Result;
4
6
use links::CollectedLink;
···
132
134
}
133
135
134
136
impl LinkReader for MemStorage {
137
+
fn get_many_to_many_counts(
138
+
&self,
139
+
target: &str,
140
+
collection: &str,
141
+
path: &str,
142
+
path_to_other: &str,
143
+
limit: u64,
144
+
after: Option<String>,
145
+
filter_dids: &HashSet<Did>,
146
+
filter_to_targets: &HashSet<String>,
147
+
) -> Result<PagedOrderedCollection<(String, u64, u64), String>> {
148
+
let data = self.0.lock().unwrap();
149
+
let Some(paths) = data.targets.get(&Target::new(target)) else {
150
+
return Ok(PagedOrderedCollection::default());
151
+
};
152
+
let Some(linkers) = paths.get(&Source::new(collection, path)) else {
153
+
return Ok(PagedOrderedCollection::default());
154
+
};
155
+
156
+
let path_to_other = RecordPath::new(path_to_other);
157
+
let filter_to_targets: HashSet<Target> =
158
+
HashSet::from_iter(filter_to_targets.iter().map(|s| Target::new(s)));
159
+
160
+
let mut grouped_counts: HashMap<Target, (u64, HashSet<Did>)> = HashMap::new();
161
+
for (did, rkey) in linkers.iter().flatten().cloned() {
162
+
if !filter_dids.is_empty() && !filter_dids.contains(&did) {
163
+
continue;
164
+
}
165
+
if let Some(fwd_target) = data
166
+
.links
167
+
.get(&did)
168
+
.unwrap_or(&HashMap::new())
169
+
.get(&RepoId {
170
+
collection: collection.to_string(),
171
+
rkey,
172
+
})
173
+
.unwrap_or(&Vec::new())
174
+
.iter()
175
+
.filter_map(|(path, target)| {
176
+
if *path == path_to_other
177
+
&& (filter_to_targets.is_empty() || filter_to_targets.contains(target))
178
+
{
179
+
Some(target)
180
+
} else {
181
+
None
182
+
}
183
+
})
184
+
.take(1)
185
+
.next()
186
+
{
187
+
let e = grouped_counts.entry(fwd_target.clone()).or_default();
188
+
e.0 += 1;
189
+
e.1.insert(did.clone());
190
+
}
191
+
}
192
+
let mut items: Vec<(String, u64, u64)> = grouped_counts
193
+
.iter()
194
+
.map(|(k, (n, u))| (k.0.clone(), *n, u.len() as u64))
195
+
.collect();
196
+
items.sort();
197
+
items = items
198
+
.into_iter()
199
+
.skip_while(|(t, _, _)| after.as_ref().map(|a| t <= a).unwrap_or(false))
200
+
.take(limit as usize)
201
+
.collect();
202
+
let next = if items.len() as u64 >= limit {
203
+
items.last().map(|(t, _, _)| t.clone())
204
+
} else {
205
+
None
206
+
};
207
+
Ok(PagedOrderedCollection { items, next })
208
+
}
209
+
135
210
fn get_count(&self, target: &str, collection: &str, path: &str) -> Result<u64> {
136
211
let data = self.0.lock().unwrap();
137
212
let Some(paths) = data.targets.get(&Target::new(target)) else {
···
166
241
path: &str,
167
242
limit: u64,
168
243
until: Option<u64>,
244
+
filter_dids: &HashSet<Did>,
169
245
) -> Result<PagedAppendingCollection<RecordId>> {
170
246
let data = self.0.lock().unwrap();
171
247
let Some(paths) = data.targets.get(&Target::new(target)) else {
···
183
259
next: None,
184
260
total: 0,
185
261
});
262
+
};
263
+
264
+
let did_rkeys: Vec<_> = if !filter_dids.is_empty() {
265
+
did_rkeys
266
+
.iter()
267
+
.filter(|m| {
268
+
Option::<(Did, RKey)>::clone(m)
269
+
.map(|(did, _)| filter_dids.contains(&did))
270
+
.unwrap_or(false)
271
+
})
272
+
.cloned()
273
+
.collect()
274
+
} else {
275
+
did_rkeys.to_vec()
186
276
};
187
277
188
278
let total = did_rkeys.len();
···
338
428
dids,
339
429
targetables,
340
430
linking_records,
431
+
started_at: None,
432
+
other_data: Default::default(),
341
433
})
342
434
}
343
435
}
+484
-14
constellation/src/storage/mod.rs
+484
-14
constellation/src/storage/mod.rs
···
1
1
use crate::{ActionableEvent, CountsByCount, Did, RecordId};
2
2
use anyhow::Result;
3
3
use serde::{Deserialize, Serialize};
4
-
use std::collections::HashMap;
4
+
use std::collections::{HashMap, HashSet};
5
5
6
6
pub mod mem_store;
7
7
pub use mem_store::MemStorage;
···
19
19
pub total: u64,
20
20
}
21
21
22
+
/// A paged collection whose keys are sorted instead of indexed
23
+
///
24
+
/// this has weaker guarantees than PagedAppendingCollection: it might
25
+
/// return a totally consistent snapshot. but it should avoid duplicates
26
+
/// and each page should at least be internally consistent.
27
+
#[derive(Debug, PartialEq, Default)]
28
+
pub struct PagedOrderedCollection<T, K: Ord> {
29
+
pub items: Vec<T>,
30
+
pub next: Option<K>,
31
+
}
32
+
22
33
#[derive(Debug, Deserialize, Serialize, PartialEq)]
23
34
pub struct StorageStats {
24
35
/// estimate of how many accounts we've seen create links. the _subjects_ of any links are not represented here.
···
33
44
/// records with multiple links are single-counted.
34
45
/// for LSM stores, deleted links don't decrement this, and updated records with any links will likely increment it.
35
46
pub linking_records: u64,
47
+
48
+
/// first jetstream cursor when this instance first started
49
+
pub started_at: Option<u64>,
50
+
51
+
/// anything else we want to throw in
52
+
pub other_data: HashMap<String, u64>,
36
53
}
37
54
38
55
pub trait LinkStorage: Send + Sync {
···
48
65
}
49
66
50
67
pub trait LinkReader: Clone + Send + Sync + 'static {
68
+
#[allow(clippy::too_many_arguments)]
69
+
fn get_many_to_many_counts(
70
+
&self,
71
+
target: &str,
72
+
collection: &str,
73
+
path: &str,
74
+
path_to_other: &str,
75
+
limit: u64,
76
+
after: Option<String>,
77
+
filter_dids: &HashSet<Did>,
78
+
filter_to_targets: &HashSet<String>,
79
+
) -> Result<PagedOrderedCollection<(String, u64, u64), String>>;
80
+
51
81
fn get_count(&self, target: &str, collection: &str, path: &str) -> Result<u64>;
52
82
53
83
fn get_distinct_did_count(&self, target: &str, collection: &str, path: &str) -> Result<u64>;
···
59
89
path: &str,
60
90
limit: u64,
61
91
until: Option<u64>,
92
+
filter_dids: &HashSet<Did>,
62
93
) -> Result<PagedAppendingCollection<RecordId>>;
63
94
64
95
fn get_distinct_dids(
···
145
176
);
146
177
assert_eq!(storage.get_distinct_did_count("", "", "")?, 0);
147
178
assert_eq!(
148
-
storage.get_links("a.com", "app.t.c", ".abc.uri", 100, None)?,
179
+
storage.get_links(
180
+
"a.com",
181
+
"app.t.c",
182
+
".abc.uri",
183
+
100,
184
+
None,
185
+
&HashSet::default()
186
+
)?,
149
187
PagedAppendingCollection {
150
188
version: (0, 0),
151
189
items: vec![],
···
641
679
0,
642
680
)?;
643
681
assert_eq!(
644
-
storage.get_links("a.com", "app.t.c", ".abc.uri", 100, None)?,
682
+
storage.get_links(
683
+
"a.com",
684
+
"app.t.c",
685
+
".abc.uri",
686
+
100,
687
+
None,
688
+
&HashSet::default()
689
+
)?,
645
690
PagedAppendingCollection {
646
691
version: (1, 0),
647
692
items: vec![RecordId {
···
682
727
0,
683
728
)?;
684
729
}
685
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None)?;
730
+
let links =
731
+
storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None, &HashSet::default())?;
686
732
let dids = storage.get_distinct_dids("a.com", "app.t.c", ".abc.uri", 2, None)?;
687
733
assert_eq!(
688
734
links,
···
713
759
total: 5,
714
760
}
715
761
);
716
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, links.next)?;
762
+
let links = storage.get_links(
763
+
"a.com",
764
+
"app.t.c",
765
+
".abc.uri",
766
+
2,
767
+
links.next,
768
+
&HashSet::default(),
769
+
)?;
717
770
let dids = storage.get_distinct_dids("a.com", "app.t.c", ".abc.uri", 2, dids.next)?;
718
771
assert_eq!(
719
772
links,
···
744
797
total: 5,
745
798
}
746
799
);
747
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, links.next)?;
800
+
let links = storage.get_links(
801
+
"a.com",
802
+
"app.t.c",
803
+
".abc.uri",
804
+
2,
805
+
links.next,
806
+
&HashSet::default(),
807
+
)?;
748
808
let dids = storage.get_distinct_dids("a.com", "app.t.c", ".abc.uri", 2, dids.next)?;
749
809
assert_eq!(
750
810
links,
···
771
831
assert_stats(storage.get_stats()?, 5..=5, 1..=1, 5..=5);
772
832
});
773
833
834
+
test_each_storage!(get_filtered_links, |storage| {
835
+
let links = storage.get_links(
836
+
"a.com",
837
+
"app.t.c",
838
+
".abc.uri",
839
+
2,
840
+
None,
841
+
&HashSet::from([Did("did:plc:linker".to_string())]),
842
+
)?;
843
+
assert_eq!(
844
+
links,
845
+
PagedAppendingCollection {
846
+
version: (0, 0),
847
+
items: vec![],
848
+
next: None,
849
+
total: 0,
850
+
}
851
+
);
852
+
853
+
storage.push(
854
+
&ActionableEvent::CreateLinks {
855
+
record_id: RecordId {
856
+
did: "did:plc:linker".into(),
857
+
collection: "app.t.c".into(),
858
+
rkey: "asdf".into(),
859
+
},
860
+
links: vec![CollectedLink {
861
+
target: Link::Uri("a.com".into()),
862
+
path: ".abc.uri".into(),
863
+
}],
864
+
},
865
+
0,
866
+
)?;
867
+
868
+
let links = storage.get_links(
869
+
"a.com",
870
+
"app.t.c",
871
+
".abc.uri",
872
+
2,
873
+
None,
874
+
&HashSet::from([Did("did:plc:linker".to_string())]),
875
+
)?;
876
+
assert_eq!(
877
+
links,
878
+
PagedAppendingCollection {
879
+
version: (1, 0),
880
+
items: vec![RecordId {
881
+
did: "did:plc:linker".into(),
882
+
collection: "app.t.c".into(),
883
+
rkey: "asdf".into(),
884
+
},],
885
+
next: None,
886
+
total: 1,
887
+
}
888
+
);
889
+
890
+
let links = storage.get_links(
891
+
"a.com",
892
+
"app.t.c",
893
+
".abc.uri",
894
+
2,
895
+
None,
896
+
&HashSet::from([Did("did:plc:someone-else".to_string())]),
897
+
)?;
898
+
assert_eq!(
899
+
links,
900
+
PagedAppendingCollection {
901
+
version: (0, 0),
902
+
items: vec![],
903
+
next: None,
904
+
total: 0,
905
+
}
906
+
);
907
+
908
+
storage.push(
909
+
&ActionableEvent::CreateLinks {
910
+
record_id: RecordId {
911
+
did: "did:plc:linker".into(),
912
+
collection: "app.t.c".into(),
913
+
rkey: "asdf-2".into(),
914
+
},
915
+
links: vec![CollectedLink {
916
+
target: Link::Uri("a.com".into()),
917
+
path: ".abc.uri".into(),
918
+
}],
919
+
},
920
+
0,
921
+
)?;
922
+
storage.push(
923
+
&ActionableEvent::CreateLinks {
924
+
record_id: RecordId {
925
+
did: "did:plc:someone-else".into(),
926
+
collection: "app.t.c".into(),
927
+
rkey: "asdf".into(),
928
+
},
929
+
links: vec![CollectedLink {
930
+
target: Link::Uri("a.com".into()),
931
+
path: ".abc.uri".into(),
932
+
}],
933
+
},
934
+
0,
935
+
)?;
936
+
937
+
let links = storage.get_links(
938
+
"a.com",
939
+
"app.t.c",
940
+
".abc.uri",
941
+
2,
942
+
None,
943
+
&HashSet::from([Did("did:plc:linker".to_string())]),
944
+
)?;
945
+
assert_eq!(
946
+
links,
947
+
PagedAppendingCollection {
948
+
version: (2, 0),
949
+
items: vec![
950
+
RecordId {
951
+
did: "did:plc:linker".into(),
952
+
collection: "app.t.c".into(),
953
+
rkey: "asdf-2".into(),
954
+
},
955
+
RecordId {
956
+
did: "did:plc:linker".into(),
957
+
collection: "app.t.c".into(),
958
+
rkey: "asdf".into(),
959
+
},
960
+
],
961
+
next: None,
962
+
total: 2,
963
+
}
964
+
);
965
+
966
+
let links = storage.get_links(
967
+
"a.com",
968
+
"app.t.c",
969
+
".abc.uri",
970
+
2,
971
+
None,
972
+
&HashSet::from([
973
+
Did("did:plc:linker".to_string()),
974
+
Did("did:plc:someone-else".to_string()),
975
+
]),
976
+
)?;
977
+
assert_eq!(
978
+
links,
979
+
PagedAppendingCollection {
980
+
version: (3, 0),
981
+
items: vec![
982
+
RecordId {
983
+
did: "did:plc:someone-else".into(),
984
+
collection: "app.t.c".into(),
985
+
rkey: "asdf".into(),
986
+
},
987
+
RecordId {
988
+
did: "did:plc:linker".into(),
989
+
collection: "app.t.c".into(),
990
+
rkey: "asdf-2".into(),
991
+
},
992
+
],
993
+
next: Some(1),
994
+
total: 3,
995
+
}
996
+
);
997
+
998
+
let links = storage.get_links(
999
+
"a.com",
1000
+
"app.t.c",
1001
+
".abc.uri",
1002
+
2,
1003
+
None,
1004
+
&HashSet::from([Did("did:plc:someone-unknown".to_string())]),
1005
+
)?;
1006
+
assert_eq!(
1007
+
links,
1008
+
PagedAppendingCollection {
1009
+
version: (0, 0),
1010
+
items: vec![],
1011
+
next: None,
1012
+
total: 0,
1013
+
}
1014
+
);
1015
+
});
1016
+
774
1017
test_each_storage!(get_links_exact_multiple, |storage| {
775
1018
for i in 1..=4 {
776
1019
storage.push(
···
788
1031
0,
789
1032
)?;
790
1033
}
791
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None)?;
1034
+
let links =
1035
+
storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None, &HashSet::default())?;
792
1036
assert_eq!(
793
1037
links,
794
1038
PagedAppendingCollection {
···
809
1053
total: 4,
810
1054
}
811
1055
);
812
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, links.next)?;
1056
+
let links = storage.get_links(
1057
+
"a.com",
1058
+
"app.t.c",
1059
+
".abc.uri",
1060
+
2,
1061
+
links.next,
1062
+
&HashSet::default(),
1063
+
)?;
813
1064
assert_eq!(
814
1065
links,
815
1066
PagedAppendingCollection {
···
850
1101
0,
851
1102
)?;
852
1103
}
853
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None)?;
1104
+
let links =
1105
+
storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None, &HashSet::default())?;
854
1106
assert_eq!(
855
1107
links,
856
1108
PagedAppendingCollection {
···
885
1137
},
886
1138
0,
887
1139
)?;
888
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, links.next)?;
1140
+
let links = storage.get_links(
1141
+
"a.com",
1142
+
"app.t.c",
1143
+
".abc.uri",
1144
+
2,
1145
+
links.next,
1146
+
&HashSet::default(),
1147
+
)?;
889
1148
assert_eq!(
890
1149
links,
891
1150
PagedAppendingCollection {
···
926
1185
0,
927
1186
)?;
928
1187
}
929
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None)?;
1188
+
let links =
1189
+
storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None, &HashSet::default())?;
930
1190
assert_eq!(
931
1191
links,
932
1192
PagedAppendingCollection {
···
955
1215
}),
956
1216
0,
957
1217
)?;
958
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, links.next)?;
1218
+
let links = storage.get_links(
1219
+
"a.com",
1220
+
"app.t.c",
1221
+
".abc.uri",
1222
+
2,
1223
+
links.next,
1224
+
&HashSet::default(),
1225
+
)?;
959
1226
assert_eq!(
960
1227
links,
961
1228
PagedAppendingCollection {
···
989
1256
0,
990
1257
)?;
991
1258
}
992
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None)?;
1259
+
let links =
1260
+
storage.get_links("a.com", "app.t.c", ".abc.uri", 2, None, &HashSet::default())?;
993
1261
assert_eq!(
994
1262
links,
995
1263
PagedAppendingCollection {
···
1014
1282
&ActionableEvent::DeactivateAccount("did:plc:asdf-1".into()),
1015
1283
0,
1016
1284
)?;
1017
-
let links = storage.get_links("a.com", "app.t.c", ".abc.uri", 2, links.next)?;
1285
+
let links = storage.get_links(
1286
+
"a.com",
1287
+
"app.t.c",
1288
+
".abc.uri",
1289
+
2,
1290
+
links.next,
1291
+
&HashSet::default(),
1292
+
)?;
1018
1293
assert_eq!(
1019
1294
links,
1020
1295
PagedAppendingCollection {
···
1081
1356
counts
1082
1357
});
1083
1358
assert_stats(storage.get_stats()?, 1..=1, 2..=2, 1..=1);
1359
+
});
1360
+
1361
+
//////// many-to-many /////////
1362
+
1363
+
test_each_storage!(get_m2m_counts_empty, |storage| {
1364
+
assert_eq!(
1365
+
storage.get_many_to_many_counts(
1366
+
"a.com",
1367
+
"a.b.c",
1368
+
".d.e",
1369
+
".f.g",
1370
+
10,
1371
+
None,
1372
+
&HashSet::new(),
1373
+
&HashSet::new(),
1374
+
)?,
1375
+
PagedOrderedCollection {
1376
+
items: vec![],
1377
+
next: None,
1378
+
}
1379
+
);
1380
+
});
1381
+
1382
+
test_each_storage!(get_m2m_counts_single, |storage| {
1383
+
storage.push(
1384
+
&ActionableEvent::CreateLinks {
1385
+
record_id: RecordId {
1386
+
did: "did:plc:asdf".into(),
1387
+
collection: "app.t.c".into(),
1388
+
rkey: "asdf".into(),
1389
+
},
1390
+
links: vec![
1391
+
CollectedLink {
1392
+
target: Link::Uri("a.com".into()),
1393
+
path: ".abc.uri".into(),
1394
+
},
1395
+
CollectedLink {
1396
+
target: Link::Uri("b.com".into()),
1397
+
path: ".def.uri".into(),
1398
+
},
1399
+
CollectedLink {
1400
+
target: Link::Uri("b.com".into()),
1401
+
path: ".ghi.uri".into(),
1402
+
},
1403
+
],
1404
+
},
1405
+
0,
1406
+
)?;
1407
+
assert_eq!(
1408
+
storage.get_many_to_many_counts(
1409
+
"a.com",
1410
+
"app.t.c",
1411
+
".abc.uri",
1412
+
".def.uri",
1413
+
10,
1414
+
None,
1415
+
&HashSet::new(),
1416
+
&HashSet::new(),
1417
+
)?,
1418
+
PagedOrderedCollection {
1419
+
items: vec![("b.com".to_string(), 1, 1)],
1420
+
next: None,
1421
+
}
1422
+
);
1423
+
});
1424
+
1425
+
test_each_storage!(get_m2m_counts_filters, |storage| {
1426
+
storage.push(
1427
+
&ActionableEvent::CreateLinks {
1428
+
record_id: RecordId {
1429
+
did: "did:plc:asdf".into(),
1430
+
collection: "app.t.c".into(),
1431
+
rkey: "asdf".into(),
1432
+
},
1433
+
links: vec![
1434
+
CollectedLink {
1435
+
target: Link::Uri("a.com".into()),
1436
+
path: ".abc.uri".into(),
1437
+
},
1438
+
CollectedLink {
1439
+
target: Link::Uri("b.com".into()),
1440
+
path: ".def.uri".into(),
1441
+
},
1442
+
],
1443
+
},
1444
+
0,
1445
+
)?;
1446
+
storage.push(
1447
+
&ActionableEvent::CreateLinks {
1448
+
record_id: RecordId {
1449
+
did: "did:plc:asdfasdf".into(),
1450
+
collection: "app.t.c".into(),
1451
+
rkey: "asdf".into(),
1452
+
},
1453
+
links: vec![
1454
+
CollectedLink {
1455
+
target: Link::Uri("a.com".into()),
1456
+
path: ".abc.uri".into(),
1457
+
},
1458
+
CollectedLink {
1459
+
target: Link::Uri("b.com".into()),
1460
+
path: ".def.uri".into(),
1461
+
},
1462
+
],
1463
+
},
1464
+
1,
1465
+
)?;
1466
+
storage.push(
1467
+
&ActionableEvent::CreateLinks {
1468
+
record_id: RecordId {
1469
+
did: "did:plc:fdsa".into(),
1470
+
collection: "app.t.c".into(),
1471
+
rkey: "asdf".into(),
1472
+
},
1473
+
links: vec![
1474
+
CollectedLink {
1475
+
target: Link::Uri("a.com".into()),
1476
+
path: ".abc.uri".into(),
1477
+
},
1478
+
CollectedLink {
1479
+
target: Link::Uri("c.com".into()),
1480
+
path: ".def.uri".into(),
1481
+
},
1482
+
],
1483
+
},
1484
+
2,
1485
+
)?;
1486
+
storage.push(
1487
+
&ActionableEvent::CreateLinks {
1488
+
record_id: RecordId {
1489
+
did: "did:plc:fdsa".into(),
1490
+
collection: "app.t.c".into(),
1491
+
rkey: "asdf2".into(),
1492
+
},
1493
+
links: vec![
1494
+
CollectedLink {
1495
+
target: Link::Uri("a.com".into()),
1496
+
path: ".abc.uri".into(),
1497
+
},
1498
+
CollectedLink {
1499
+
target: Link::Uri("c.com".into()),
1500
+
path: ".def.uri".into(),
1501
+
},
1502
+
],
1503
+
},
1504
+
3,
1505
+
)?;
1506
+
assert_eq!(
1507
+
storage.get_many_to_many_counts(
1508
+
"a.com",
1509
+
"app.t.c",
1510
+
".abc.uri",
1511
+
".def.uri",
1512
+
10,
1513
+
None,
1514
+
&HashSet::new(),
1515
+
&HashSet::new(),
1516
+
)?,
1517
+
PagedOrderedCollection {
1518
+
items: vec![("b.com".to_string(), 2, 2), ("c.com".to_string(), 2, 1),],
1519
+
next: None,
1520
+
}
1521
+
);
1522
+
assert_eq!(
1523
+
storage.get_many_to_many_counts(
1524
+
"a.com",
1525
+
"app.t.c",
1526
+
".abc.uri",
1527
+
".def.uri",
1528
+
10,
1529
+
None,
1530
+
&HashSet::from_iter([Did("did:plc:fdsa".to_string())]),
1531
+
&HashSet::new(),
1532
+
)?,
1533
+
PagedOrderedCollection {
1534
+
items: vec![("c.com".to_string(), 2, 1),],
1535
+
next: None,
1536
+
}
1537
+
);
1538
+
assert_eq!(
1539
+
storage.get_many_to_many_counts(
1540
+
"a.com",
1541
+
"app.t.c",
1542
+
".abc.uri",
1543
+
".def.uri",
1544
+
10,
1545
+
None,
1546
+
&HashSet::new(),
1547
+
&HashSet::from_iter(["b.com".to_string()]),
1548
+
)?,
1549
+
PagedOrderedCollection {
1550
+
items: vec![("b.com".to_string(), 2, 2),],
1551
+
next: None,
1552
+
}
1553
+
);
1084
1554
});
1085
1555
}
+361
-41
constellation/src/storage/rocks_store.rs
+361
-41
constellation/src/storage/rocks_store.rs
···
1
-
use super::{ActionableEvent, LinkReader, LinkStorage, PagedAppendingCollection, StorageStats};
1
+
use super::{
2
+
ActionableEvent, LinkReader, LinkStorage, PagedAppendingCollection, PagedOrderedCollection,
3
+
StorageStats,
4
+
};
2
5
use crate::{CountsByCount, Did, RecordId};
3
6
use anyhow::{bail, Result};
4
7
use bincode::Options as BincodeOptions;
···
11
14
MultiThreaded, Options, PrefixRange, ReadOptions, WriteBatch,
12
15
};
13
16
use serde::{Deserialize, Serialize};
14
-
use std::collections::{HashMap, HashSet};
17
+
use std::collections::{BTreeMap, HashMap, HashSet};
15
18
use std::io::Read;
16
19
use std::marker::PhantomData;
17
20
use std::path::{Path, PathBuf};
···
20
23
Arc,
21
24
};
22
25
use std::thread;
23
-
use std::time::{Duration, Instant};
26
+
use std::time::{Duration, Instant, SystemTime, UNIX_EPOCH};
24
27
use tokio_util::sync::CancellationToken;
25
28
26
29
static DID_IDS_CF: &str = "did_ids";
···
29
32
static LINK_TARGETS_CF: &str = "link_targets";
30
33
31
34
static JETSTREAM_CURSOR_KEY: &str = "jetstream_cursor";
35
+
static STARTED_AT_KEY: &str = "jetstream_first_cursor";
36
+
// add reverse mappings for targets if this db was running before that was a thing
37
+
static TARGET_ID_REPAIR_STATE_KEY: &str = "target_id_table_repair_state";
38
+
39
+
static COZY_FIRST_CURSOR: u64 = 1_738_083_600_000_000; // constellation.microcosm.blue started
40
+
41
+
#[derive(Debug, Clone, Serialize, Deserialize)]
42
+
struct TargetIdRepairState {
43
+
/// start time for repair, microseconds timestamp
44
+
current_us_started_at: u64,
45
+
/// id table's latest id when repair started
46
+
id_when_started: u64,
47
+
/// id table id
48
+
latest_repaired_i: u64,
49
+
}
50
+
impl AsRocksValue for TargetIdRepairState {}
51
+
impl ValueFromRocks for TargetIdRepairState {}
32
52
33
53
// todo: actually understand and set these options probably better
34
54
fn rocks_opts_base() -> Options {
···
56
76
#[derive(Debug, Clone)]
57
77
pub struct RocksStorage {
58
78
pub db: Arc<DBWithThreadMode<MultiThreaded>>, // TODO: mov seqs here (concat merge op will be fun)
59
-
did_id_table: IdTable<Did, DidIdValue, true>,
60
-
target_id_table: IdTable<TargetKey, TargetId, false>,
79
+
did_id_table: IdTable<Did, DidIdValue>,
80
+
target_id_table: IdTable<TargetKey, TargetId>,
61
81
is_writer: bool,
62
82
backup_task: Arc<Option<thread::JoinHandle<Result<()>>>>,
63
83
}
···
85
105
fn cf_descriptor(&self) -> ColumnFamilyDescriptor {
86
106
ColumnFamilyDescriptor::new(&self.name, rocks_opts_base())
87
107
}
88
-
fn init<const WITH_REVERSE: bool>(
89
-
self,
90
-
db: &DBWithThreadMode<MultiThreaded>,
91
-
) -> Result<IdTable<Orig, IdVal, WITH_REVERSE>> {
108
+
fn init(self, db: &DBWithThreadMode<MultiThreaded>) -> Result<IdTable<Orig, IdVal>> {
92
109
if db.cf_handle(&self.name).is_none() {
93
110
bail!("failed to get cf handle from db -- was the db open with our .cf_descriptor()?");
94
111
}
···
119
136
}
120
137
}
121
138
#[derive(Debug, Clone)]
122
-
struct IdTable<Orig, IdVal: IdTableValue, const WITH_REVERSE: bool>
139
+
struct IdTable<Orig, IdVal: IdTableValue>
123
140
where
124
141
Orig: KeyFromRocks,
125
142
for<'a> &'a Orig: AsRocksKey,
···
127
144
base: IdTableBase<Orig, IdVal>,
128
145
priv_id_seq: u64,
129
146
}
130
-
impl<Orig: Clone, IdVal: IdTableValue, const WITH_REVERSE: bool> IdTable<Orig, IdVal, WITH_REVERSE>
147
+
impl<Orig: Clone, IdVal: IdTableValue> IdTable<Orig, IdVal>
131
148
where
132
149
Orig: KeyFromRocks,
133
150
for<'v> &'v IdVal: AsRocksValue,
···
139
156
_key_marker: PhantomData,
140
157
_val_marker: PhantomData,
141
158
name: name.into(),
142
-
id_seq: Arc::new(AtomicU64::new(0)), // zero is "uninint", first seq num will be 1
159
+
id_seq: Arc::new(AtomicU64::new(0)), // zero is "uninit", first seq num will be 1
143
160
}
144
161
}
145
162
fn get_id_val(
···
178
195
id_value
179
196
}))
180
197
}
198
+
181
199
fn estimate_count(&self) -> u64 {
182
200
self.base.id_seq.load(Ordering::SeqCst) - 1 // -1 because seq zero is reserved
183
201
}
184
-
}
185
-
impl<Orig: Clone, IdVal: IdTableValue> IdTable<Orig, IdVal, true>
186
-
where
187
-
Orig: KeyFromRocks,
188
-
for<'v> &'v IdVal: AsRocksValue,
189
-
for<'k> &'k Orig: AsRocksKey,
190
-
{
202
+
191
203
fn get_or_create_id_val(
192
204
&mut self,
193
205
db: &DBWithThreadMode<MultiThreaded>,
···
215
227
}
216
228
}
217
229
}
218
-
impl<Orig: Clone, IdVal: IdTableValue> IdTable<Orig, IdVal, false>
219
-
where
220
-
Orig: KeyFromRocks,
221
-
for<'v> &'v IdVal: AsRocksValue,
222
-
for<'k> &'k Orig: AsRocksKey,
223
-
{
224
-
fn get_or_create_id_val(
225
-
&mut self,
226
-
db: &DBWithThreadMode<MultiThreaded>,
227
-
batch: &mut WriteBatch,
228
-
orig: &Orig,
229
-
) -> Result<IdVal> {
230
-
let cf = db.cf_handle(&self.base.name).unwrap();
231
-
self.__get_or_create_id_val(&cf, db, batch, orig)
232
-
}
233
-
}
234
230
235
231
impl IdTableValue for DidIdValue {
236
232
fn new(v: u64) -> Self {
···
249
245
}
250
246
}
251
247
248
+
fn now() -> u64 {
249
+
SystemTime::now()
250
+
.duration_since(UNIX_EPOCH)
251
+
.unwrap()
252
+
.as_micros() as u64
253
+
}
254
+
252
255
impl RocksStorage {
253
256
pub fn new(path: impl AsRef<Path>) -> Result<Self> {
254
257
Self::describe_metrics();
255
-
RocksStorage::open_readmode(path, false)
258
+
let me = RocksStorage::open_readmode(path, false)?;
259
+
me.global_init()?;
260
+
Ok(me)
256
261
}
257
262
258
263
pub fn open_readonly(path: impl AsRef<Path>) -> Result<Self> {
···
260
265
}
261
266
262
267
fn open_readmode(path: impl AsRef<Path>, readonly: bool) -> Result<Self> {
263
-
let did_id_table = IdTable::<_, _, true>::setup(DID_IDS_CF);
264
-
let target_id_table = IdTable::<_, _, false>::setup(TARGET_IDS_CF);
268
+
let did_id_table = IdTable::setup(DID_IDS_CF);
269
+
let target_id_table = IdTable::setup(TARGET_IDS_CF);
265
270
271
+
// note: global stuff like jetstream cursor goes in the default cf
272
+
// these are bonus extra cfs
266
273
let cfs = vec![
267
274
// id reference tables
268
275
did_id_table.cf_descriptor(),
···
296
303
is_writer: !readonly,
297
304
backup_task: None.into(),
298
305
})
306
+
}
307
+
308
+
fn global_init(&self) -> Result<()> {
309
+
let first_run = self.db.get(JETSTREAM_CURSOR_KEY)?.is_some();
310
+
if first_run {
311
+
self.db.put(STARTED_AT_KEY, _rv(now()))?;
312
+
313
+
// hack / temporary: if we're a new db, put in a completed repair
314
+
// state so we don't run repairs (repairs are for old-code dbs)
315
+
let completed = TargetIdRepairState {
316
+
id_when_started: 0,
317
+
current_us_started_at: 0,
318
+
latest_repaired_i: 0,
319
+
};
320
+
self.db.put(TARGET_ID_REPAIR_STATE_KEY, _rv(completed))?;
321
+
}
322
+
Ok(())
323
+
}
324
+
325
+
pub fn run_repair(&self, breather: Duration, stay_alive: CancellationToken) -> Result<bool> {
326
+
let mut state = match self
327
+
.db
328
+
.get(TARGET_ID_REPAIR_STATE_KEY)?
329
+
.map(|s| _vr(&s))
330
+
.transpose()?
331
+
{
332
+
Some(s) => s,
333
+
None => TargetIdRepairState {
334
+
id_when_started: self.did_id_table.priv_id_seq,
335
+
current_us_started_at: now(),
336
+
latest_repaired_i: 0,
337
+
},
338
+
};
339
+
340
+
eprintln!("initial repair state: {state:?}");
341
+
342
+
let cf = self.db.cf_handle(TARGET_IDS_CF).unwrap();
343
+
344
+
let mut iter = self.db.raw_iterator_cf(&cf);
345
+
iter.seek_to_first();
346
+
347
+
eprintln!("repair iterator sent to first key");
348
+
349
+
// skip ahead if we're done some, or take a single first step
350
+
for _ in 0..state.latest_repaired_i {
351
+
iter.next();
352
+
}
353
+
354
+
eprintln!(
355
+
"repair iterator skipped to {}th key",
356
+
state.latest_repaired_i
357
+
);
358
+
359
+
let mut maybe_done = false;
360
+
361
+
let mut write_fast = rocksdb::WriteOptions::default();
362
+
write_fast.set_sync(false);
363
+
write_fast.disable_wal(true);
364
+
365
+
while !stay_alive.is_cancelled() && !maybe_done {
366
+
// let mut batch = WriteBatch::default();
367
+
368
+
let mut any_written = false;
369
+
370
+
for _ in 0..1000 {
371
+
if state.latest_repaired_i % 1_000_000 == 0 {
372
+
eprintln!("target iter at {}", state.latest_repaired_i);
373
+
}
374
+
state.latest_repaired_i += 1;
375
+
376
+
if !iter.valid() {
377
+
eprintln!("invalid iter, are we done repairing?");
378
+
maybe_done = true;
379
+
break;
380
+
};
381
+
382
+
// eprintln!("iterator seems to be valid! getting the key...");
383
+
let raw_key = iter.key().unwrap();
384
+
if raw_key.len() == 8 {
385
+
// eprintln!("found an 8-byte key, skipping it since it's probably an id...");
386
+
iter.next();
387
+
continue;
388
+
}
389
+
let target: TargetKey = _kr::<TargetKey>(raw_key)?;
390
+
let target_id: TargetId = _vr(iter.value().unwrap())?;
391
+
392
+
self.db
393
+
.put_cf_opt(&cf, target_id.id().to_be_bytes(), _rv(&target), &write_fast)?;
394
+
any_written = true;
395
+
iter.next();
396
+
}
397
+
398
+
if any_written {
399
+
self.db
400
+
.put(TARGET_ID_REPAIR_STATE_KEY, _rv(state.clone()))?;
401
+
std::thread::sleep(breather);
402
+
}
403
+
}
404
+
405
+
eprintln!("repair iterator done.");
406
+
407
+
Ok(false)
299
408
}
300
409
301
410
pub fn start_backup(
···
826
935
}
827
936
828
937
impl LinkReader for RocksStorage {
938
+
fn get_many_to_many_counts(
939
+
&self,
940
+
target: &str,
941
+
collection: &str,
942
+
path: &str,
943
+
path_to_other: &str,
944
+
limit: u64,
945
+
after: Option<String>,
946
+
filter_dids: &HashSet<Did>,
947
+
filter_to_targets: &HashSet<String>,
948
+
) -> Result<PagedOrderedCollection<(String, u64, u64), String>> {
949
+
let collection = Collection(collection.to_string());
950
+
let path = RPath(path.to_string());
951
+
952
+
let target_key = TargetKey(Target(target.to_string()), collection.clone(), path.clone());
953
+
954
+
// unfortunately the cursor is a, uh, stringified number.
955
+
// this was easier for the memstore (plain target, not target id), and
956
+
// making it generic is a bit awful.
957
+
// so... parse the number out of a string here :(
958
+
// TODO: this should bubble up to a BAD_REQUEST response
959
+
let after = after.map(|s| s.parse::<u64>().map(TargetId)).transpose()?;
960
+
961
+
let Some(target_id) = self.target_id_table.get_id_val(&self.db, &target_key)? else {
962
+
eprintln!("nothin doin for this target, {target_key:?}");
963
+
return Ok(Default::default());
964
+
};
965
+
966
+
let filter_did_ids: HashMap<DidId, bool> = filter_dids
967
+
.iter()
968
+
.filter_map(|did| self.did_id_table.get_id_val(&self.db, did).transpose())
969
+
.collect::<Result<Vec<DidIdValue>>>()?
970
+
.into_iter()
971
+
.map(|DidIdValue(id, active)| (id, active))
972
+
.collect();
973
+
974
+
// stored targets are keyed by triples of (target, collection, path).
975
+
// target filtering only consideres the target itself, so we actually
976
+
// need to do a prefix iteration of all target ids for this target and
977
+
// keep them all.
978
+
// i *think* the number of keys at a target prefix should usually be
979
+
// pretty small, so this is hopefully fine. but if it turns out to be
980
+
// large, we can push this filtering back into the main links loop and
981
+
// do forward db queries per backlink to get the raw target back out.
982
+
let mut filter_to_target_ids: HashSet<TargetId> = HashSet::new();
983
+
for t in filter_to_targets {
984
+
for (_, target_id) in self.iter_targets_for_target(&Target(t.to_string())) {
985
+
filter_to_target_ids.insert(target_id);
986
+
}
987
+
}
988
+
989
+
let linkers = self.get_target_linkers(&target_id)?;
990
+
991
+
let mut grouped_counts: BTreeMap<TargetId, (u64, HashSet<DidId>)> = BTreeMap::new();
992
+
993
+
for (did_id, rkey) in linkers.0 {
994
+
if did_id.is_empty() {
995
+
continue;
996
+
}
997
+
998
+
if !filter_did_ids.is_empty() && filter_did_ids.get(&did_id) != Some(&true) {
999
+
continue;
1000
+
}
1001
+
1002
+
let record_link_key = RecordLinkKey(did_id, collection.clone(), rkey);
1003
+
let Some(targets) = self.get_record_link_targets(&record_link_key)? else {
1004
+
continue;
1005
+
};
1006
+
1007
+
let Some(fwd_target) = targets
1008
+
.0
1009
+
.into_iter()
1010
+
.filter_map(|RecordLinkTarget(rpath, target_id)| {
1011
+
if rpath.0 == path_to_other
1012
+
&& (filter_to_target_ids.is_empty()
1013
+
|| filter_to_target_ids.contains(&target_id))
1014
+
{
1015
+
Some(target_id)
1016
+
} else {
1017
+
None
1018
+
}
1019
+
})
1020
+
.take(1)
1021
+
.next()
1022
+
else {
1023
+
eprintln!("no forward match");
1024
+
continue;
1025
+
};
1026
+
1027
+
// small relief: we page over target ids, so we can already bail
1028
+
// reprocessing previous pages here
1029
+
if after.as_ref().map(|a| fwd_target <= *a).unwrap_or(false) {
1030
+
continue;
1031
+
}
1032
+
1033
+
// aand we can skip target ids that must be on future pages
1034
+
// (this check continues after the did-lookup, which we have to do)
1035
+
let page_is_full = grouped_counts.len() as u64 >= limit;
1036
+
if page_is_full {
1037
+
let current_max = grouped_counts.keys().next_back().unwrap(); // limit should be non-zero bleh
1038
+
if fwd_target > *current_max {
1039
+
continue;
1040
+
}
1041
+
}
1042
+
1043
+
// bit painful: 2-step lookup to make sure this did is active
1044
+
let Some(did) = self.did_id_table.get_val_from_id(&self.db, did_id.0)? else {
1045
+
eprintln!("failed to look up did from did_id {did_id:?}");
1046
+
continue;
1047
+
};
1048
+
let Some(DidIdValue(_, active)) = self.did_id_table.get_id_val(&self.db, &did)? else {
1049
+
eprintln!("failed to look up did_value from did_id {did_id:?}: {did:?}: data consistency bug?");
1050
+
continue;
1051
+
};
1052
+
if !active {
1053
+
continue;
1054
+
}
1055
+
1056
+
// page-management, continued
1057
+
// if we have a full page, and we're inserting a *new* key less than
1058
+
// the current max, then we can evict the current max
1059
+
let mut should_evict = false;
1060
+
let entry = grouped_counts.entry(fwd_target.clone()).or_insert_with(|| {
1061
+
// this is a *new* key, so kick the max if we're full
1062
+
should_evict = page_is_full;
1063
+
Default::default()
1064
+
});
1065
+
entry.0 += 1;
1066
+
entry.1.insert(did_id);
1067
+
1068
+
if should_evict {
1069
+
grouped_counts.pop_last();
1070
+
}
1071
+
}
1072
+
1073
+
let mut items: Vec<(String, u64, u64)> = Vec::with_capacity(grouped_counts.len());
1074
+
for (target_id, (n, dids)) in &grouped_counts {
1075
+
let Some(target) = self
1076
+
.target_id_table
1077
+
.get_val_from_id(&self.db, target_id.0)?
1078
+
else {
1079
+
eprintln!("failed to look up target from target_id {target_id:?}");
1080
+
continue;
1081
+
};
1082
+
items.push((target.0 .0, *n, dids.len() as u64));
1083
+
}
1084
+
1085
+
let next = if grouped_counts.len() as u64 >= limit {
1086
+
// yeah.... it's a number saved as a string......sorry
1087
+
grouped_counts
1088
+
.keys()
1089
+
.next_back()
1090
+
.map(|k| format!("{}", k.0))
1091
+
} else {
1092
+
None
1093
+
};
1094
+
1095
+
Ok(PagedOrderedCollection { items, next })
1096
+
}
1097
+
829
1098
fn get_count(&self, target: &str, collection: &str, path: &str) -> Result<u64> {
830
1099
let target_key = TargetKey(
831
1100
Target(target.to_string()),
···
860
1129
path: &str,
861
1130
limit: u64,
862
1131
until: Option<u64>,
1132
+
filter_dids: &HashSet<Did>,
863
1133
) -> Result<PagedAppendingCollection<RecordId>> {
864
1134
let target_key = TargetKey(
865
1135
Target(target.to_string()),
···
876
1146
});
877
1147
};
878
1148
879
-
let linkers = self.get_target_linkers(&target_id)?;
1149
+
let mut linkers = self.get_target_linkers(&target_id)?;
1150
+
if !filter_dids.is_empty() {
1151
+
let mut did_filter = HashSet::new();
1152
+
for did in filter_dids {
1153
+
let Some(DidIdValue(did_id, active)) =
1154
+
self.did_id_table.get_id_val(&self.db, did)?
1155
+
else {
1156
+
eprintln!("failed to find a did_id for {did:?}");
1157
+
continue;
1158
+
};
1159
+
if !active {
1160
+
eprintln!("excluding inactive did from filtered results");
1161
+
continue;
1162
+
}
1163
+
did_filter.insert(did_id);
1164
+
}
1165
+
linkers.0.retain(|linker| did_filter.contains(&linker.0));
1166
+
}
880
1167
881
1168
let (alive, gone) = linkers.count();
882
1169
let total = alive + gone;
···
1024
1311
.map(|s| s.parse::<u64>())
1025
1312
.transpose()?
1026
1313
.unwrap_or(0);
1314
+
let started_at = self
1315
+
.db
1316
+
.get(STARTED_AT_KEY)?
1317
+
.map(|c| _vr(&c))
1318
+
.transpose()?
1319
+
.unwrap_or(COZY_FIRST_CURSOR);
1320
+
1321
+
let other_data = self
1322
+
.db
1323
+
.get(TARGET_ID_REPAIR_STATE_KEY)?
1324
+
.map(|s| _vr(&s))
1325
+
.transpose()?
1326
+
.map(
1327
+
|TargetIdRepairState {
1328
+
current_us_started_at,
1329
+
id_when_started,
1330
+
latest_repaired_i,
1331
+
}| {
1332
+
HashMap::from([
1333
+
("current_us_started_at".to_string(), current_us_started_at),
1334
+
("id_when_started".to_string(), id_when_started),
1335
+
("latest_repaired_i".to_string(), latest_repaired_i),
1336
+
])
1337
+
},
1338
+
)
1339
+
.unwrap_or(HashMap::default());
1340
+
1027
1341
Ok(StorageStats {
1028
1342
dids,
1029
1343
targetables,
1030
1344
linking_records,
1345
+
started_at: Some(started_at),
1346
+
other_data,
1031
1347
})
1032
1348
}
1033
1349
}
···
1053
1369
impl AsRocksValue for &TargetId {}
1054
1370
impl KeyFromRocks for TargetKey {}
1055
1371
impl ValueFromRocks for TargetId {}
1372
+
1373
+
// temp?
1374
+
impl KeyFromRocks for TargetId {}
1375
+
impl AsRocksValue for &TargetKey {}
1056
1376
1057
1377
// target_links table
1058
1378
impl AsRocksKey for &TargetId {}
···
1124
1444
}
1125
1445
1126
1446
// target ids
1127
-
#[derive(Debug, Clone, Serialize, Deserialize)]
1447
+
#[derive(Debug, Clone, Serialize, Deserialize, PartialOrd, Ord, PartialEq, Eq, Hash)]
1128
1448
struct TargetId(u64); // key
1129
1449
1130
-
#[derive(Debug, Clone, Serialize, Deserialize)]
1450
+
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq, Hash)]
1131
1451
pub struct Target(pub String); // the actual target/uri
1132
1452
1133
1453
// targets (uris, dids, etc.): the reverse index
+1
-1
constellation/templates/dids.html.j2
+1
-1
constellation/templates/dids.html.j2
···
27
27
{% for did in linking_dids %}
28
28
<pre style="display: block; margin: 1em 2em" class="code"><strong>DID</strong>: {{ did.0 }}
29
29
-> see <a href="/links/all?target={{ did.0|urlencode }}">links to this DID</a>
30
-
-> browse <a href="https://atproto-browser-plus-links.vercel.app/at/{{ did.0|urlencode }}">this DID record</a></pre>
30
+
-> browse <a href="https://pdsls.dev/at://{{ did.0|urlencode }}">this DID record</a></pre>
31
31
{% endfor %}
32
32
33
33
{% if let Some(c) = cursor %}
+54
constellation/templates/get-backlinks.html.j2
+54
constellation/templates/get-backlinks.html.j2
···
1
+
{% extends "base.html.j2" %}
2
+
{% import "try-it-macros.html.j2" as try_it %}
3
+
4
+
{% block title %}Backlinks{% endblock %}
5
+
{% block description %}All {{ query.source }} records with links to {{ query.subject }}{% endblock %}
6
+
7
+
{% block content %}
8
+
9
+
{% call try_it::get_backlinks(query.subject, query.source, query.did, query.limit) %}
10
+
11
+
<h2>
12
+
Links to <code>{{ query.subject }}</code>
13
+
{% if let Some(browseable_uri) = query.subject|to_browseable %}
14
+
<small style="font-weight: normal; font-size: 1rem"><a href="{{ browseable_uri }}">browse record</a></small>
15
+
{% endif %}
16
+
</h2>
17
+
18
+
<p><strong>{{ total|human_number }} links</strong> from <code>{{ query.source }}</code>.</p>
19
+
20
+
<ul>
21
+
<li>See distinct linking DIDs at <code>/links/distinct-dids</code>: <a href="/links/distinct-dids?target={{ query.subject|urlencode }}&collection={{ collection|urlencode }}&path={{ path|urlencode }}">/links/distinct-dids?target={{ query.subject }}&collection={{ collection }}&path={{ path }}</a></li>
22
+
<li>See all links to this target at <code>/links/all</code>: <a href="/links/all?target={{ query.subject|urlencode }}">/links/all?target={{ query.subject }}</a></li>
23
+
</ul>
24
+
25
+
<h3>Links, most recent first:</h3>
26
+
27
+
{% for record in records %}
28
+
<pre style="display: block; margin: 1em 2em" class="code"><strong>DID</strong>: {{ record.did().0 }} (<a href="/links/all?target={{ record.did().0|urlencode }}">DID links</a>)
29
+
<strong>Collection</strong>: {{ record.collection }}
30
+
<strong>RKey</strong>: {{ record.rkey }}
31
+
-> <a href="https://pdsls.dev/at://{{ record.did().0 }}/{{ record.collection }}/{{ record.rkey }}">browse record</a></pre>
32
+
{% endfor %}
33
+
34
+
{% if let Some(c) = cursor %}
35
+
<form method="get" action="/xrpc/blue.microcosm.links.getBacklinks">
36
+
<input type="hidden" name="subject" value="{{ query.subject }}" />
37
+
<input type="hidden" name="source" value="{{ query.source }}" />
38
+
<input type="hidden" name="limit" value="{{ query.limit }}" />
39
+
{% for did in query.did %}
40
+
<input type="hidden" name="did" value="{{ did }}" />
41
+
{% endfor %}
42
+
<input type="hidden" name="cursor" value={{ c|json|safe }} />
43
+
<button type="submit">next page…</button>
44
+
</form>
45
+
{% else %}
46
+
<button disabled><em>end of results</em></button>
47
+
{% endif %}
48
+
49
+
<details>
50
+
<summary>Raw JSON response</summary>
51
+
<pre class="code">{{ self|tojson }}</pre>
52
+
</details>
53
+
54
+
{% endblock %}
+67
constellation/templates/get-many-to-many-counts.html.j2
+67
constellation/templates/get-many-to-many-counts.html.j2
···
1
+
{% extends "base.html.j2" %}
2
+
{% import "try-it-macros.html.j2" as try_it %}
3
+
4
+
{% block title %}Many to Many counts{% endblock %}
5
+
{% block description %}Counts of many-to-many {{ query.source }} join records with links to {{ query.subject }} and a secondary target at {{ query.path_to_other }}{% endblock %}
6
+
7
+
{% block content %}
8
+
9
+
{% call try_it::get_many_to_many_counts(
10
+
query.subject,
11
+
query.source,
12
+
query.path_to_other,
13
+
query.did,
14
+
query.other_subject,
15
+
query.limit,
16
+
) %}
17
+
18
+
<h2>
19
+
Many-to-many links to <code>{{ query.subject }}</code> joining through <code>{{ query.path_to_other }}</code>
20
+
{% if let Some(browseable_uri) = query.subject|to_browseable %}
21
+
<small style="font-weight: normal; font-size: 1rem"><a href="{{ browseable_uri }}">browse record</a></small>
22
+
{% endif %}
23
+
</h2>
24
+
25
+
<p><strong>{% if cursor.is_some() || query.cursor.is_some() %}more than {% endif %}{{ counts_by_other_subject.len()|to_u64|human_number }} joins</strong> <code>{{ query.source }}→{{ query.path_to_other }}</code></p>
26
+
27
+
<ul>
28
+
<li>See direct backlinks at <code>/xrpc/blue.microcosm.links.getBacklinks</code>: <a href="/xrpc/blue.microcosm.links.getBacklinks?subject={{ query.subject|urlencode }}&source={{ query.source|urlencode }}">/xrpc/blue.microcosm.links.getBacklinks?subject={{ query.subject }}&source={{ query.source }}</a></li>
29
+
<li>See all links to this target at <code>/links/all</code>: <a href="/links/all?target={{ query.subject|urlencode }}">/links/all?target={{ query.subject }}</a></li>
30
+
</ul>
31
+
32
+
<h3>Counts by other subject:</h3>
33
+
34
+
{% for counts in counts_by_other_subject %}
35
+
<pre style="display: block; margin: 1em 2em" class="code"><strong>Joined subject</strong>: {{ counts.subject }}
36
+
<strong>Joining records</strong>: {{ counts.total }}
37
+
<strong>Unique joiner ids</strong>: {{ counts.distinct }}
38
+
-> {% if let Some(browseable_uri) = counts.subject|to_browseable -%}
39
+
<a href="{{ browseable_uri }}">browse record</a>
40
+
{%- endif %}</pre>
41
+
{% endfor %}
42
+
43
+
{% if let Some(c) = cursor %}
44
+
<form method="get" action="/xrpc/blue.microcosm.links.getManyToManyCounts">
45
+
<input type="hidden" name="subject" value="{{ query.subject }}" />
46
+
<input type="hidden" name="source" value="{{ query.source }}" />
47
+
<input type="hidden" name="pathToOther" value="{{ query.path_to_other }}" />
48
+
{% for did in query.did %}
49
+
<input type="hidden" name="did" value="{{ did }}" />
50
+
{% endfor %}
51
+
{% for otherSubject in query.other_subject %}
52
+
<input type="hidden" name="otherSubject" value="{{ otherSubject }}" />
53
+
{% endfor %}
54
+
<input type="hidden" name="limit" value="{{ query.limit }}" />
55
+
<input type="hidden" name="cursor" value={{ c|json|safe }} />
56
+
<button type="submit">next page…</button>
57
+
</form>
58
+
{% else %}
59
+
<button disabled><em>end of results</em></button>
60
+
{% endif %}
61
+
62
+
<details>
63
+
<summary>Raw JSON response</summary>
64
+
<pre class="code">{{ self|tojson }}</pre>
65
+
</details>
66
+
67
+
{% endblock %}
+65
-7
constellation/templates/hello.html.j2
+65
-7
constellation/templates/hello.html.j2
···
19
19
<p>It works by recursively walking <em>all</em> records coming through the firehose, searching for anything that looks like a link. Links are indexed by the target they point at, the collection the record came from, and the JSON path to the link in that record.</p>
20
20
21
21
<p>
22
-
This server has indexed <span class="stat">{{ stats.linking_records|human_number }}</span> links between <span class="stat">{{ stats.targetables|human_number }}</span> targets and sources from <span class="stat">{{ stats.dids|human_number }}</span> identities over <span class="stat">{{ days_indexed|human_number }}</span> days.<br/>
23
-
<small>(indexing new records in real time, backfill still TODO)</small>
22
+
This server has indexed <span class="stat">{{ stats.linking_records|human_number }}</span> links between <span class="stat">{{ stats.targetables|human_number }}</span> targets and sources from <span class="stat">{{ stats.dids|human_number }}</span> identities over <span class="stat">
23
+
{%- if let Some(days) = days_indexed %}
24
+
{{ days|human_number }}
25
+
{% else %}
26
+
???
27
+
{% endif -%}
28
+
</span> days.<br/>
29
+
<small>(indexing new records in real time, backfill coming soon!)</small>
24
30
</p>
25
31
26
-
<p>The API is currently <strong>unstable</strong>. But feel free to use it! If you want to be nice, put your project name and bsky username (or email) in your user-agent header for api requests.</p>
32
+
{# {% for k, v in stats.other_data.iter() %}
33
+
<p><strong>{{ k }}</strong>: {{ v }}</p>
34
+
{% endfor %} #}
35
+
36
+
<p>You're welcome to use this public instance! Please do not build the torment nexus. If you want to be nice, put your project name and bsky username (or email) in your user-agent header for api requests.</p>
27
37
28
38
29
39
<h2>API Endpoints</h2>
30
40
41
+
<h3 class="route"><code>GET /xrpc/blue.microcosm.links.getBacklinks</code></h3>
42
+
43
+
<p>A list of records linking to any record, identity, or uri.</p>
44
+
45
+
<h4>Query parameters:</h4>
46
+
47
+
<ul>
48
+
<li><p><code>subject</code>: required, must url-encode. Example: <code>at://did:plc:vc7f4oafdgxsihk4cry2xpze/app.bsky.feed.post/3lgwdn7vd722r</code></p></li>
49
+
<li><p><code>source</code>: required. Example: <code>app.bsky.feed.like:subject.uri</code></p></li>
50
+
<li><p><code>did</code>: optional, filter links to those from specific users. Include multiple times to filter by multiple users. Example: <code>did=did:plc:vc7f4oafdgxsihk4cry2xpze&did=did:plc:vc7f4oafdgxsihk4cry2xpze</code></p></li>
51
+
<li><p><code>limit</code>: optional. Default: <code>16</code>. Maximum: <code>100</code></p></li>
52
+
</ul>
53
+
54
+
<p style="margin-bottom: 0"><strong>Try it:</strong></p>
55
+
{% call try_it::get_backlinks("at://did:plc:a4pqq234yw7fqbddawjo7y35/app.bsky.feed.post/3m237ilwc372e", "app.bsky.feed.like:subject.uri", [""], 16) %}
56
+
57
+
58
+
<h3 class="route"><code>GET /xrpc/blue.microcosm.links.getManyToManyCounts</code></h3>
59
+
60
+
<p>TODO: description</p>
61
+
62
+
<h4>Query parameters:</h4>
63
+
64
+
<ul>
65
+
<li><p><code>subject</code>: required, must url-encode. Example: <code>at://did:plc:vc7f4oafdgxsihk4cry2xpze/app.bsky.feed.post/3lgwdn7vd722r</code></p></li>
66
+
<li><p><code>source</code>: required. Example: <code>app.bsky.feed.like:subject.uri</code></p></li>
67
+
<li><p><code>pathToOther</code>: required. Path to the secondary link in the many-to-many record. Example: <code>otherThing.uri</code></p></li>
68
+
<li><p><code>did</code>: optional, filter links to those from specific users. Include multiple times to filter by multiple users. Example: <code>did=did:plc:vc7f4oafdgxsihk4cry2xpze&did=did:plc:vc7f4oafdgxsihk4cry2xpze</code></p></li>
69
+
<li><p><code>otherSubject</code>: optional, filter secondary links to specific subjects. Include multiple times to filter by multiple users. Example: <code>at://did:plc:vc7f4oafdgxsihk4cry2xpze/app.bsky.feed.post/3lgwdn7vd722r</code></p></li>
70
+
<li><p><code>limit</code>: optional. Default: <code>16</code>. Maximum: <code>100</code></p></li>
71
+
</ul>
72
+
73
+
<p style="margin-bottom: 0"><strong>Try it:</strong></p>
74
+
{% call try_it::get_many_to_many_counts(
75
+
"at://did:plc:wshs7t2adsemcrrd4snkeqli/sh.tangled.label.definition/good-first-issue",
76
+
"sh.tangled.label.op:add[].key",
77
+
"subject",
78
+
[""],
79
+
[""],
80
+
25,
81
+
) %}
82
+
83
+
31
84
<h3 class="route"><code>GET /links</code></h3>
32
85
33
86
<p>A list of records linking to a target.</p>
34
87
88
+
<p>[DEPRECATED]: use <code>GET /xrpc/blue.microcosm.links.getBacklinks</code>. New apps should avoid it, but this endpoint <strong>will</strong> remain supported for the forseeable future.</p>
89
+
35
90
<h4>Query parameters:</h4>
36
91
37
92
<ul>
38
-
<li><code>target</code>: required, must url-encode. Example: <code>at://did:plc:vc7f4oafdgxsihk4cry2xpze/app.bsky.feed.post/3lgwdn7vd722r</code></li>
39
-
<li><code>collection</code>: required. Example: <code>app.bsky.feed.like</code></li>
40
-
<li><code>path</code>: required, must url-encode. Example: <code>.subject.uri</code></li>
93
+
<li><p><code>target</code>: required, must url-encode. Example: <code>at://did:plc:vc7f4oafdgxsihk4cry2xpze/app.bsky.feed.post/3lgwdn7vd722r</code></p></li>
94
+
<li><p><code>collection</code>: required. Example: <code>app.bsky.feed.like</code></p></li>
95
+
<li><p><code>path</code>: required, must url-encode. Example: <code>.subject.uri</code></p></li>
96
+
<li><p><code>did</code>: optional, filter links to those from specific users. Include multiple times to filter by multiple users. Example: <code>did=did:plc:vc7f4oafdgxsihk4cry2xpze&did=did:plc:vc7f4oafdgxsihk4cry2xpze</code></p></li>
97
+
<li><p><code>from_dids</code> [deprecated]: optional. Use <code>did</code> instead. Example: <code>from_dids=did:plc:vc7f4oafdgxsihk4cry2xpze,did:plc:vc7f4oafdgxsihk4cry2xpze</code></p></li>
98
+
<li><p><code>limit</code>: optional. Default: <code>16</code>. Maximum: <code>100</code></p></li>
41
99
</ul>
42
100
43
101
<p style="margin-bottom: 0"><strong>Try it:</strong></p>
44
-
{% call try_it::links("at://did:plc:vc7f4oafdgxsihk4cry2xpze/app.bsky.feed.post/3lgwdn7vd722r", "app.bsky.feed.like", ".subject.uri") %}
102
+
{% call try_it::links("at://did:plc:a4pqq234yw7fqbddawjo7y35/app.bsky.feed.post/3m237ilwc372e", "app.bsky.feed.like", ".subject.uri", [""], 16) %}
45
103
46
104
47
105
<h3 class="route"><code>GET /links/distinct-dids</code></h3>
+2
-2
constellation/templates/links.html.j2
+2
-2
constellation/templates/links.html.j2
···
6
6
7
7
{% block content %}
8
8
9
-
{% call try_it::links(query.target, query.collection, query.path) %}
9
+
{% call try_it::links(query.target, query.collection, query.path, query.did, query.limit) %}
10
10
11
11
<h2>
12
12
Links to <code>{{ query.target }}</code>
···
28
28
<pre style="display: block; margin: 1em 2em" class="code"><strong>DID</strong>: {{ record.did().0 }} (<a href="/links/all?target={{ record.did().0|urlencode }}">DID links</a>)
29
29
<strong>Collection</strong>: {{ record.collection }}
30
30
<strong>RKey</strong>: {{ record.rkey }}
31
-
-> <a href="https://atproto-browser-plus-links.vercel.app/at/{{ record.did().0|urlencode }}/{{ record.collection }}/{{ record.rkey }}">browse record</a></pre>
31
+
-> <a href="https://pdsls.dev/at://{{ record.did().0 }}/{{ record.collection }}/{{ record.rkey }}">browse record</a></pre>
32
32
{% endfor %}
33
33
34
34
{% if let Some(c) = cursor %}
+88
-3
constellation/templates/try-it-macros.html.j2
+88
-3
constellation/templates/try-it-macros.html.j2
···
1
-
{% macro links(target, collection, path) %}
1
+
{% macro get_backlinks(subject, source, dids, limit) %}
2
+
<form method="get" action="/xrpc/blue.microcosm.links.getBacklinks">
3
+
<pre class="code"><strong>GET</strong> /xrpc/blue.microcosm.links.getBacklinks
4
+
?subject= <input type="text" name="subject" value="{{ subject }}" placeholder="at-uri, did, uri..." />
5
+
&source= <input type="text" name="source" value="{{ source }}" placeholder="app.bsky.feed.like:subject.uri" />
6
+
{%- for did in dids %}{% if !did.is_empty() %}
7
+
&did= <input type="text" name="did" value="{{ did }}" placeholder="did:plc:..." />{% endif %}{% endfor %}
8
+
<span id="did-placeholder"></span> <button id="add-did">+ did filter</button>
9
+
&limit= <input type="number" name="limit" value="{{ limit }}" max="100" placeholder="100" /> <button type="submit">get links</button></pre>
10
+
</form>
11
+
<script>
12
+
const addDidButton = document.getElementById('add-did');
13
+
const didPlaceholder = document.getElementById('did-placeholder');
14
+
addDidButton.addEventListener('click', e => {
15
+
e.preventDefault();
16
+
const i = document.createElement('input');
17
+
i.placeholder = 'did:plc:...';
18
+
i.name = "did"
19
+
const p = addDidButton.parentNode;
20
+
p.insertBefore(document.createTextNode('&did= '), didPlaceholder);
21
+
p.insertBefore(i, didPlaceholder);
22
+
p.insertBefore(document.createTextNode('\n '), didPlaceholder);
23
+
});
24
+
</script>
25
+
{% endmacro %}
26
+
27
+
{% macro get_many_to_many_counts(subject, source, pathToOther, dids, otherSubjects, limit) %}
28
+
<form method="get" action="/xrpc/blue.microcosm.links.getManyToManyCounts">
29
+
<pre class="code"><strong>GET</strong> /xrpc/blue.microcosm.links.getManyToManyCounts
30
+
?subject= <input type="text" name="subject" value="{{ subject }}" placeholder="at-uri, did, uri..." />
31
+
&source= <input type="text" name="source" value="{{ source }}" placeholder="app.bsky.feed.like:subject.uri" />
32
+
&pathToOther= <input type="text" name="pathToOther" value="{{ pathToOther }}" placeholder="otherThing.uri" />
33
+
{%- for did in dids %}{% if !did.is_empty() %}
34
+
&did= <input type="text" name="did" value="{{ did }}" placeholder="did:plc:..." />{% endif %}{% endfor %}
35
+
<span id="m2m-subject-placeholder"></span> <button id="m2m-add-subject">+ other subject filter</button>
36
+
{%- for otherSubject in otherSubjects %}{% if !otherSubject.is_empty() %}
37
+
&otherSubject= <input type="text" name="did" value="{{ otherSubject }}" placeholder="at-uri, did, uri..." />{% endif %}{% endfor %}
38
+
<span id="m2m-did-placeholder"></span> <button id="m2m-add-did">+ did filter</button>
39
+
&limit= <input type="number" name="limit" value="{{ limit }}" max="100" placeholder="100" /> <button type="submit">get links</button></pre>
40
+
</form>
41
+
<script>
42
+
const m2mAddDidButton = document.getElementById('m2m-add-did');
43
+
const m2mDidPlaceholder = document.getElementById('m2m-did-placeholder');
44
+
m2mAddDidButton.addEventListener('click', e => {
45
+
e.preventDefault();
46
+
const i = document.createElement('input');
47
+
i.placeholder = 'did:plc:...';
48
+
i.name = "did"
49
+
const p = m2mAddDidButton.parentNode;
50
+
p.insertBefore(document.createTextNode('&did= '), m2mDidPlaceholder);
51
+
p.insertBefore(i, m2mDidPlaceholder);
52
+
p.insertBefore(document.createTextNode('\n '), m2mDidPlaceholder);
53
+
});
54
+
const m2mAddSubjectButton = document.getElementById('m2m-add-subject');
55
+
const m2mSubjectPlaceholder = document.getElementById('m2m-subject-placeholder');
56
+
m2mAddSubjectButton.addEventListener('click', e => {
57
+
e.preventDefault();
58
+
const i = document.createElement('input');
59
+
i.placeholder = 'at-uri, did, uri...';
60
+
i.name = "otherSubject"
61
+
const p = m2mAddSubjectButton.parentNode;
62
+
p.insertBefore(document.createTextNode('&otherSubject= '), m2mSubjectPlaceholder);
63
+
p.insertBefore(i, m2mSubjectPlaceholder);
64
+
p.insertBefore(document.createTextNode('\n '), m2mSubjectPlaceholder);
65
+
});
66
+
</script>
67
+
{% endmacro %}
68
+
69
+
{% macro links(target, collection, path, dids, limit) %}
2
70
<form method="get" action="/links">
3
71
<pre class="code"><strong>GET</strong> /links
4
72
?target= <input type="text" name="target" value="{{ target }}" placeholder="target" />
5
73
&collection= <input type="text" name="collection" value="{{ collection }}" placeholder="collection" />
6
-
&path= <input type="text" name="path" value="{{ path }}" placeholder="path" /> <button type="submit">get links</button></pre>
74
+
&path= <input type="text" name="path" value="{{ path }}" placeholder="path" />
75
+
{%- for did in dids %}{% if !did.is_empty() %}
76
+
&did= <input type="text" name="did" value="{{ did }}" placeholder="did:plc:..." />{% endif %}{% endfor %}
77
+
<span id="did-placeholder"></span> <button id="add-did">+ did filter</button>
78
+
&limit= <input type="number" name="limit" value="{{ limit }}" max="100" placeholder="100" /> <button type="submit">get links</button></pre>
7
79
</form>
80
+
<script>
81
+
const addDidButton = document.getElementById('add-did');
82
+
const didPlaceholder = document.getElementById('did-placeholder');
83
+
addDidButton.addEventListener('click', e => {
84
+
e.preventDefault();
85
+
const i = document.createElement('input');
86
+
i.placeholder = 'did:plc:...';
87
+
i.name = "did"
88
+
const p = addDidButton.parentNode;
89
+
p.insertBefore(document.createTextNode('&did= '), didPlaceholder);
90
+
p.insertBefore(i, didPlaceholder);
91
+
p.insertBefore(document.createTextNode('\n '), didPlaceholder);
92
+
});
93
+
</script>
8
94
{% endmacro %}
9
-
10
95
11
96
{% macro dids(target, collection, path) %}
12
97
<form method="get" action="/links/distinct-dids">
-496
cozy-setup (move to another repo).md
-496
cozy-setup (move to another repo).md
···
1
-
cozy-ucosm
2
-
3
-
4
-
## gateway
5
-
6
-
- tailscale (exit node enabled)
7
-
-> allow ipv4 and ipv6 forwarding
8
-
- caddy
9
-
10
-
```bash
11
-
apt install golang
12
-
go install github.com/caddyserver/xcaddy/cmd/xcaddy@latest
13
-
go/bin/xcaddy build \
14
-
--with github.com/caddyserver/cache-handler \
15
-
--with github.com/darkweak/storages/badger/caddy \
16
-
--with github.com/mholt/caddy-ratelimit
17
-
# then https://caddyserver.com/docs/running#manual-installation
18
-
19
-
mkdir /var/cache/caddy-badger
20
-
chown -R caddy:caddy /var/cache/caddy-badger/
21
-
```
22
-
23
-
- `/etc/caddy/Caddyfile`
24
-
25
-
```
26
-
{
27
-
cache {
28
-
badger
29
-
api {
30
-
prometheus
31
-
}
32
-
}
33
-
}
34
-
35
-
links.bsky.bad-example.com {
36
-
reverse_proxy link-aggregator:6789
37
-
38
-
@browser `{header.Origin.startsWith("Mozilla/5.0")`
39
-
rate_limit {
40
-
zone global_burst {
41
-
key {remote_host}
42
-
events 10
43
-
window 1s
44
-
}
45
-
zone global_general {
46
-
key {remote_host}
47
-
events 100
48
-
window 60s
49
-
log_key true
50
-
}
51
-
zone website_harsh_limit {
52
-
key {header.Origin}
53
-
match {
54
-
expression {header.User-Agent}.startsWith("Mozilla/5.0")
55
-
}
56
-
events 1000
57
-
window 30s
58
-
log_key true
59
-
}
60
-
}
61
-
respond /souin-api/metrics "denied" 403 # does not work
62
-
cache {
63
-
ttl 3s
64
-
stale 1h
65
-
default_cache_control public, s-maxage=3
66
-
badger {
67
-
path /var/cache/caddy-badger/links
68
-
}
69
-
}
70
-
}
71
-
72
-
gateway:80 {
73
-
metrics
74
-
cache
75
-
}
76
-
```
77
-
well... the gateway fell over IMMEDIATELY with like 2 req/sec from deletions, with that ^^ config. for now i removed everything except the reverse proxy config + normal caddy metrics and it's running fine on vanilla caddy. i did try reducing the rate-limiting configs to a single, fixed-key global limit but it still ate all the ram and died. maybe badger w/ the cache config was still a problem. maybe it would have been ok on a machine with more than 1GB mem.
78
-
79
-
80
-
alternative proxies:
81
-
82
-
- nginx. i should probably just use this. acme-client is a piece of cake to set up, and i know how to configure it.
83
-
- haproxy. also kind of familiar, it's old and stable. no idea how it handle low-mem (our 1gb) vs nginx.
84
-
- sozu. popular rust thing, fast. doesn't have rate-limiting or cache feature?
85
-
- rpxy. like caddy (auto-tls) but in rust and actually fast? has an "experimental" cache feature. but the cache feature looks good.
86
-
- rama. build-your-own proxy. not sure that it has both cache and limiter in their standard features?
87
-
- pingora. build-your-own cloudflare, so like, probably stable. has tools for cache and limiting. low-mem...?
88
-
- cache stuff in pingora seems a little... hit and miss (byeeeee). only a test impl for Storage for the main cache feature?
89
-
- but the rate-limiter has a guide: https://github.com/cloudflare/pingora/blob/main/docs/user_guide/rate_limiter.md
90
-
91
-
what i want is low-resource reverse proxy with built-in rate-limiting and caching. but maybe cache (and/or ratelimiting) could be external to the reverse proxy
92
-
- varnish is a dedicated cache. has https://github.com/varnish/varnish-modules/blob/master/src/vmod_vsthrottle.vcc
93
-
- apache traffic control has experimental rate-limiting plugins
94
-
95
-
96
-
- victoriametrics
97
-
98
-
```bash
99
-
curl -LO https://github.com/VictoriaMetrics/VictoriaMetrics/releases/download/v1.109.1/victoria-metrics-linux-amd64-v1.109.1.tar.gz
100
-
tar xzf victoria-metrics-linux-amd64-v1.109.1.tar.gz
101
-
# and then https://docs.victoriametrics.com/quick-start/#starting-vm-single-from-a-binary
102
-
sudo mkdir /etc/victoria-metrics && sudo chown -R victoriametrics:victoriametrics /etc/victoria-metrics
103
-
104
-
```
105
-
106
-
- `/etc/victoria-metrics/prometheus.yml`
107
-
108
-
```yaml
109
-
global:
110
-
scrape_interval: '15s'
111
-
112
-
scrape_configs:
113
-
- job_name: 'link_aggregator'
114
-
static_configs:
115
-
- targets: ['link-aggregator:8765']
116
-
- job_name: 'gateway:caddy'
117
-
static_configs:
118
-
- targets: ['gateway:80/metrics']
119
-
- job_name: 'gateway:cache'
120
-
static_configs:
121
-
- targets: ['gateway:80/souin-api/metrics']
122
-
```
123
-
124
-
- `ExecStart` in `/etc/systemd/system/victoriametrics.service`:
125
-
126
-
```
127
-
ExecStart=/usr/local/bin/victoria-metrics-prod -storageDataPath=/var/lib/victoria-metrics -retentionPeriod=90d -selfScrapeInterval=1m -promscrape.config=/etc/victoria-metrics/prometheus.yml
128
-
```
129
-
130
-
- grafana
131
-
132
-
followed `https://grafana.com/docs/grafana/latest/setup-grafana/installation/debian/#install-grafana-on-debian-or-ubuntu`
133
-
134
-
something something something then
135
-
136
-
```
137
-
sudo grafana-cli --pluginUrl https://github.com/VictoriaMetrics/victoriametrics-datasource/releases/download/v0.11.1/victoriametrics-datasource-v0.11.1.zip plugins install victoriametrics
138
-
```
139
-
140
-
- raspi node_exporter
141
-
142
-
```bash
143
-
curl -LO https://github.com/prometheus/node_exporter/releases/download/v1.8.2/node_exporter-1.8.2.linux-armv7.tar.gz
144
-
tar xzf node_exporter-1.8.2.linux-armv7.tar.gz
145
-
sudo cp node_exporter-1.8.2.linux-armv7/node_exporter /usr/local/bin/
146
-
sudo useradd --no-create-home --shell /bin/false node_exporter
147
-
sudo nano /etc/systemd/system/node_exporter.service
148
-
# [Unit]
149
-
# Description=Node Exporter
150
-
# Wants=network-online.target
151
-
# After=network-online.target
152
-
153
-
# [Service]
154
-
# User=node_exporter
155
-
# Group=node_exporter
156
-
# Type=simple
157
-
# ExecStart=/usr/local/bin/node_exporter
158
-
# Restart=always
159
-
# RestartSec=3
160
-
161
-
# [Install]
162
-
# WantedBy=multi-user.target
163
-
sudo systemctl daemon-reload
164
-
sudo systemctl enable node_exporter.service
165
-
sudo systemctl start node_exporter.service
166
-
```
167
-
168
-
todo: get raspi vcgencmd outputs into metrics
169
-
170
-
- nginx on gateway
171
-
172
-
```nginx
173
-
# in http
174
-
175
-
##
176
-
# cozy cache
177
-
##
178
-
proxy_cache_path /var/cache/nginx keys_zone=cozy_zone:10m;
179
-
180
-
##
181
-
# cozy limit
182
-
##
183
-
limit_req_zone $binary_remote_addr zone=cozy_ip_limit:10m rate=50r/s;
184
-
limit_req_zone $server_name zone=cozy_global_limit:10m rate=1000r/s;
185
-
186
-
# in sites-available/constellation.microcosm.blue
187
-
188
-
upstream cozy_link_aggregator {
189
-
server link-aggregator:6789;
190
-
keepalive 16;
191
-
}
192
-
193
-
server {
194
-
listen 8080;
195
-
listen [::]:8080;
196
-
197
-
server_name constellation.microcosm.blue;
198
-
199
-
proxy_cache cozy_zone;
200
-
proxy_cache_background_update on;
201
-
proxy_cache_key "$scheme$proxy_host$uri$is_args$args$http_accept";
202
-
proxy_cache_lock on; # make simlutaneous requests for the same uri wait for it to appear in cache instead of hitting origin
203
-
proxy_cache_lock_age 1s;
204
-
proxy_cache_lock_timeout 2s;
205
-
proxy_cache_valid 10s; # default -- should be explicitly set in the response headers
206
-
proxy_cache_valid any 15s; # non-200s default
207
-
proxy_read_timeout 5s;
208
-
proxy_send_timeout 15s;
209
-
proxy_socket_keepalive on;
210
-
211
-
limit_req zone=cozy_ip_limit nodelay burst=100;
212
-
limit_req zone=cozy_global_limit;
213
-
limit_req_status 429;
214
-
215
-
location / {
216
-
proxy_pass http://cozy_link_aggregator;
217
-
include proxy_params;
218
-
proxy_http_version 1.1;
219
-
proxy_set_header Connection ""; # for keepalive
220
-
}
221
-
}
222
-
```
223
-
224
-
also `systemctl edit nginx` and paste
225
-
226
-
```
227
-
[Service]
228
-
Restart=always
229
-
```
230
-
231
-
—https://serverfault.com/a/1003373
232
-
233
-
now making browsers redirect to the microcosm.blue url:
234
-
235
-
```
236
-
[...]
237
-
server_name links.bsky.bad-example.com;
238
-
239
-
add_header Access-Control-Allow-Origin * always; # bit of hack to have it here but nginx doesn't like it in the `if`
240
-
if ($http_user_agent ~ ^Mozilla/) {
241
-
# for now send *browsers* to the new location, hopefully without impacting api requests
242
-
# (yeah we're doing UA test here and content-negotatiation in the app. whatever.)
243
-
return 301 https://constellation.microcosm.blue$request_uri;
244
-
}
245
-
[...]
246
-
```
247
-
248
-
- nginx metrics
249
-
250
-
- download nginx-prometheus-exporter
251
-
https://github.com/nginx/nginx-prometheus-exporter/releases/download/v1.4.1/nginx-prometheus-exporter_1.4.1_linux_amd64.tar.gz
252
-
253
-
- err actually going to make mistakes and try with snap
254
-
`snap install nginx-prometheus-exporter`
255
-
- so it got a binary for me but no systemd task set up. boooo.
256
-
`snap remove nginx-prometheus-exporter`
257
-
258
-
- ```bash
259
-
curl -LO https://github.com/nginx/nginx-prometheus-exporter/releases/download/v1.4.1/nginx-prometheus-exporter_1.4.1_linux_amd64.tar.gz
260
-
tar xzf nginx-prometheus-exporter_1.4.1_linux_amd64.tar.gz
261
-
mv nginx-prometheus-exporter /usr/local/bin
262
-
useradd --no-create-home --shell /bin/false nginx-prometheus-exporter
263
-
nano /etc/systemd/system/nginx-prometheus-exporter.service
264
-
# [Unit]
265
-
# Description=NGINX Exporter
266
-
# Wants=network-online.target
267
-
# After=network-online.target
268
-
269
-
# [Service]
270
-
# User=nginx-prometheus-exporter
271
-
# Group=nginx-prometheus-exporter
272
-
# Type=simple
273
-
# ExecStart=/usr/local/bin/nginx-prometheus-exporter --nginx.scrape-uri=http://gateway:8080/stub_status --web.listen-address=gateway:9113
274
-
# Restart=always
275
-
# RestartSec=3
276
-
277
-
# [Install]
278
-
# WantedBy=multi-user.target
279
-
systemctl daemon-reload
280
-
systemctl start nginx-prometheus-exporter.service
281
-
systemctl enable nginx-prometheus-exporter.service
282
-
```
283
-
284
-
- nginx `/etc/nginx/sites-available/gateway-nginx-status`
285
-
286
-
```nginx
287
-
server {
288
-
listen 8080;
289
-
listen [::]:8080;
290
-
291
-
server_name gateway;
292
-
293
-
location /stub_status {
294
-
stub_status;
295
-
}
296
-
location / {
297
-
return 404;
298
-
}
299
-
}
300
-
```
301
-
302
-
```bash
303
-
ln -s /etc/nginx/sites-available/gateway-nginx-status /etc/nginx/sites-enabled/
304
-
```
305
-
306
-
307
-
## bootes (pi5)
308
-
309
-
- mount sd card, touch `ssh` file echo `echo "pi:$(echo raspberry | openssl passwd -6 -stdin)" > userconf.txt`
310
-
- raspi-config: enable pcie 3, set hostname, enable ssh
311
-
- put ssh key into `.ssh/authorized_keys`
312
-
- put `PasswordAuthentication no` in `/etc/ssh/sshd_config`
313
-
- `sudo apt update && sudo apt upgrade`
314
-
- `sudo apt install xfsprogs`
315
-
- `sudo mkfs.xfs -L c11n-kv /dev/nvme0n1`
316
-
- `sudo mount /dev/nvme0n1 /mnt`
317
-
- set up tailscale
318
-
- `sudo tailscale up`
319
-
- `git clone https://github.com/atcosm/links.git`
320
-
- tailscale: disable bootes key expiry
321
-
- rustup `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`
322
-
- `cd links/constellation`
323
-
- `sudo apt install libssl-dev` needed
324
-
- `sudo apt install clang` needed for bindgen
325
-
- (in tmux) `cargo build --release`
326
-
- `mkdir ~/backup`
327
-
- `sudo mount.cifs "//truenas.local/folks data" /home/pi/backup -o user=phil,uid=pi`
328
-
- `sudo chown pi:pi /mnt/`
329
-
- `RUST_BACKTRACE=full cargo run --bin rocks-restore-from-backup --release -- --from-backup-dir "/home/pi/backup/constellation-index" --to-data-dir /mnt/constellation-index`
330
-
etc
331
-
- follow above `- raspi node_exporter`
332
-
- configure victoriametrics to scrape the new pi
333
-
- configure ulimit before starting! `ulimit -n 16384`
334
-
- `RUST_BACKTRACE=full cargo run --release -- --backend rocks --data /mnt/constellation-index/ --jetstream us-east-2 --backup /home/pi/backup/constellation-index --backup-interval 6 --max-old-backups 20`
335
-
- add server to nginx gateway upstream: ` server 100.123.79.12:6789; # bootes`
336
-
- stop backups from running on the older instance! `RUST_BACKTRACE=full cargo run --release -- --backend rocks --data /mnt/links-2.rocks/ --jetstream us-east-1`
337
-
- stop upstreaming requests to older instance in nginx
338
-
339
-
340
-
- systemd unit for running: `sudo nano /etc/systemd/system/constellation.service`
341
-
342
-
```ini
343
-
[Unit]
344
-
Description=Constellation backlinks index
345
-
After=network.target
346
-
347
-
[Service]
348
-
User=pi
349
-
WorkingDirectory=/home/pi/links/constellation
350
-
ExecStart=/home/pi/links/target/release/main --backend rocks --data /mnt/constellation-index/ --jetstream us-east-2 --backup /home/pi/backup/constellation-index --backup-interval 6 --max-old-backups 20
351
-
LimitNOFILE=16384
352
-
Restart=always
353
-
354
-
[Install]
355
-
WantedBy=multi-user.target
356
-
```
357
-
358
-
359
-
- todo: overlayfs? would need to figure out builds/updates still, also i guess logs are currently written to sd? (oof)
360
-
- todo: cross-compile for raspi?
361
-
362
-
---
363
-
364
-
some todos
365
-
366
-
- [x] tailscale: exit node
367
-
- [!] link_aggregator: use exit node
368
-
-> worked, but reverted for now: tailscale on raspi was consuming ~50% cpu for the jetstream traffic. this might be near its max since it would have been catching up at the time (max jetstream throughput) but it feels a bit too much. we have to trust the jetstream server and link_aggregator doesn't (yet) make any other external connections, so for now the raspi connects directly from my home again.
369
-
- [x] caddy: reverse proxy
370
-
- [x] build with cache and rate-limit plugins
371
-
- [x] configure systemd to keep it alive
372
-
- [x] configure caddy cache
373
-
- [x] configure caddy rate-limit
374
-
- [ ] configure ~caddy~ nginx to use a health check (once it's added)
375
-
- [ ] ~configure caddy to only expose cache metrics to tailnet :/~
376
-
- [x] make some grafana dashboards
377
-
- [ ] raspi: mount /dev/sda on boot
378
-
- [ ] raspi: run link_aggregator via systemd so it starts on startup (and restarts?)
379
-
380
-
- [x] use nginx instead of caddy
381
-
- [x] nginx: enable cache
382
-
- [x] nginx: rate-limit
383
-
- [ ] nginx: get metrics
384
-
385
-
386
-
387
-
388
-
---
389
-
390
-
nginx cors for constellation + small burst bump
391
-
392
-
```nginx
393
-
upstream cozy_constellation {
394
-
server <tailnet ip>:6789; # bootes; ip so that we don't race on reboot with tailscale coming up, which nginx doesn't like
395
-
keepalive 16;
396
-
}
397
-
398
-
server {
399
-
server_name constellation.microcosm.blue;
400
-
401
-
proxy_cache cozy_zone;
402
-
proxy_cache_background_update on;
403
-
proxy_cache_key "$scheme$proxy_host$uri$is_args$args$http_accept";
404
-
proxy_cache_lock on; # make simlutaneous requests for the same uri wait for it to appear in cache instead of hitting origin
405
-
proxy_cache_lock_age 1s;
406
-
proxy_cache_lock_timeout 2s;
407
-
proxy_cache_valid 10s; # default -- should be explicitly set in the response headers
408
-
proxy_cache_valid any 2s; # non-200s default
409
-
proxy_read_timeout 5s;
410
-
proxy_send_timeout 15s;
411
-
proxy_socket_keepalive on;
412
-
413
-
# take over cors responsibility from upsteram. `always` applies it to error responses.
414
-
proxy_hide_header 'Access-Control-Allow-Origin';
415
-
proxy_hide_header 'Access-Control-Allowed-Methods';
416
-
proxy_hide_header 'Access-Control-Allow-Headers';
417
-
add_header 'Access-Control-Allow-Origin' '*' always;
418
-
add_header 'Access-Control-Allow-Methods' 'GET' always;
419
-
add_header 'Access-Control-Allow-Headers' '*' always;
420
-
421
-
422
-
limit_req zone=cozy_ip_limit nodelay burst=150;
423
-
limit_req zone=cozy_global_limit burst=1800;
424
-
limit_req_status 429;
425
-
426
-
location / {
427
-
proxy_pass http://cozy_constellation;
428
-
include proxy_params;
429
-
proxy_http_version 1.1;
430
-
proxy_set_header Connection ""; # for keepalive
431
-
}
432
-
433
-
434
-
listen 443 ssl; # managed by Certbot
435
-
ssl_certificate /etc/letsencrypt/live/constellation.microcosm.blue/fullchain.pem; # managed by Certbot
436
-
ssl_certificate_key /etc/letsencrypt/live/constellation.microcosm.blue/privkey.pem; # managed by Certbot
437
-
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
438
-
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
439
-
440
-
}
441
-
442
-
server {
443
-
if ($host = constellation.microcosm.blue) {
444
-
return 301 https://$host$request_uri;
445
-
} # managed by Certbot
446
-
447
-
448
-
server_name constellation.microcosm.blue;
449
-
listen 80;
450
-
return 404; # managed by Certbot
451
-
}
452
-
```
453
-
454
-
re-reading about `nodelay`, i should probably remove it -- nginx would then queue requests to upstream, but still service them at the configured limit. it's fine for my internet since the global limit isn't nodelay, but probably less "fair" to clients if there's contention around the global limit (earlier requests would get all of theirs serviced before later ones can get in the queue)
455
-
456
-
leaving it for now though.
457
-
458
-
459
-
### nginx logs to prom
460
-
461
-
```bash
462
-
curl -LO https://github.com/martin-helmich/prometheus-nginxlog-exporter/releases/download/v1.11.0/prometheus-nginxlog-exporter_1.11.0_linux_amd64.deb
463
-
apt install ./prometheus-nginxlog-exporter_1.11.0_linux_amd64.deb
464
-
systemctl enable prometheus-nginxlog-exporter.service
465
-
466
-
```
467
-
468
-
have it run as www-data (maybe not the best idea but...)
469
-
file `/usr/lib/systemd/system/prometheus-nginxlog-exporter.service`
470
-
set User under service and remove capabilities bounding
471
-
472
-
```systemd
473
-
User=www-data
474
-
#CapabilityBoundingSet=
475
-
```
476
-
477
-
in `nginx.conf` in `http`:
478
-
479
-
```nginx
480
-
log_format constellation_format "$remote_addr - $remote_user [$time_local] \"$request\" $status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\"";
481
-
```
482
-
483
-
in `sites-available/constellation.microcosm.blue` in `server`:
484
-
485
-
```nginx
486
-
# log format must match prometheus-nginx-log-exporter
487
-
access_log /var/log/nginx/constellation-access.log constellation_format;
488
-
```
489
-
490
-
config at `/etc/prometheus-nginxlog-exporter.hcl`
491
-
492
-
493
-
494
-
```bash
495
-
systemctl start prometheus-nginxlog-exporter.service
496
-
```
+1
-1
jetstream/Cargo.toml
+1
-1
jetstream/Cargo.toml
···
10
10
11
11
[dependencies]
12
12
async-trait = "0.1.83"
13
-
atrium-api = { git = "https://github.com/uniphil/atrium", branch = "fix/nsid-allow-nonleading-name-digits", default-features = false, features = [
13
+
atrium-api = { git = "https://github.com/uniphil/atrium.git", branch = "fix/resolve-handle-https-accept-whitespace", default-features = false, features = [
14
14
"namespace-appbsky",
15
15
] }
16
16
tokio = { version = "1.44.2", features = ["full", "sync", "time"] }
+496
legacy/cozy-setup (move to another repo).md
+496
legacy/cozy-setup (move to another repo).md
···
1
+
cozy-ucosm
2
+
3
+
4
+
## gateway
5
+
6
+
- tailscale (exit node enabled)
7
+
-> allow ipv4 and ipv6 forwarding
8
+
- caddy
9
+
10
+
```bash
11
+
apt install golang
12
+
go install github.com/caddyserver/xcaddy/cmd/xcaddy@latest
13
+
go/bin/xcaddy build \
14
+
--with github.com/caddyserver/cache-handler \
15
+
--with github.com/darkweak/storages/badger/caddy \
16
+
--with github.com/mholt/caddy-ratelimit
17
+
# then https://caddyserver.com/docs/running#manual-installation
18
+
19
+
mkdir /var/cache/caddy-badger
20
+
chown -R caddy:caddy /var/cache/caddy-badger/
21
+
```
22
+
23
+
- `/etc/caddy/Caddyfile`
24
+
25
+
```
26
+
{
27
+
cache {
28
+
badger
29
+
api {
30
+
prometheus
31
+
}
32
+
}
33
+
}
34
+
35
+
links.bsky.bad-example.com {
36
+
reverse_proxy link-aggregator:6789
37
+
38
+
@browser `{header.Origin.startsWith("Mozilla/5.0")`
39
+
rate_limit {
40
+
zone global_burst {
41
+
key {remote_host}
42
+
events 10
43
+
window 1s
44
+
}
45
+
zone global_general {
46
+
key {remote_host}
47
+
events 100
48
+
window 60s
49
+
log_key true
50
+
}
51
+
zone website_harsh_limit {
52
+
key {header.Origin}
53
+
match {
54
+
expression {header.User-Agent}.startsWith("Mozilla/5.0")
55
+
}
56
+
events 1000
57
+
window 30s
58
+
log_key true
59
+
}
60
+
}
61
+
respond /souin-api/metrics "denied" 403 # does not work
62
+
cache {
63
+
ttl 3s
64
+
stale 1h
65
+
default_cache_control public, s-maxage=3
66
+
badger {
67
+
path /var/cache/caddy-badger/links
68
+
}
69
+
}
70
+
}
71
+
72
+
gateway:80 {
73
+
metrics
74
+
cache
75
+
}
76
+
```
77
+
well... the gateway fell over IMMEDIATELY with like 2 req/sec from deletions, with that ^^ config. for now i removed everything except the reverse proxy config + normal caddy metrics and it's running fine on vanilla caddy. i did try reducing the rate-limiting configs to a single, fixed-key global limit but it still ate all the ram and died. maybe badger w/ the cache config was still a problem. maybe it would have been ok on a machine with more than 1GB mem.
78
+
79
+
80
+
alternative proxies:
81
+
82
+
- nginx. i should probably just use this. acme-client is a piece of cake to set up, and i know how to configure it.
83
+
- haproxy. also kind of familiar, it's old and stable. no idea how it handle low-mem (our 1gb) vs nginx.
84
+
- sozu. popular rust thing, fast. doesn't have rate-limiting or cache feature?
85
+
- rpxy. like caddy (auto-tls) but in rust and actually fast? has an "experimental" cache feature. but the cache feature looks good.
86
+
- rama. build-your-own proxy. not sure that it has both cache and limiter in their standard features?
87
+
- pingora. build-your-own cloudflare, so like, probably stable. has tools for cache and limiting. low-mem...?
88
+
- cache stuff in pingora seems a little... hit and miss (byeeeee). only a test impl for Storage for the main cache feature?
89
+
- but the rate-limiter has a guide: https://github.com/cloudflare/pingora/blob/main/docs/user_guide/rate_limiter.md
90
+
91
+
what i want is low-resource reverse proxy with built-in rate-limiting and caching. but maybe cache (and/or ratelimiting) could be external to the reverse proxy
92
+
- varnish is a dedicated cache. has https://github.com/varnish/varnish-modules/blob/master/src/vmod_vsthrottle.vcc
93
+
- apache traffic control has experimental rate-limiting plugins
94
+
95
+
96
+
- victoriametrics
97
+
98
+
```bash
99
+
curl -LO https://github.com/VictoriaMetrics/VictoriaMetrics/releases/download/v1.109.1/victoria-metrics-linux-amd64-v1.109.1.tar.gz
100
+
tar xzf victoria-metrics-linux-amd64-v1.109.1.tar.gz
101
+
# and then https://docs.victoriametrics.com/quick-start/#starting-vm-single-from-a-binary
102
+
sudo mkdir /etc/victoria-metrics && sudo chown -R victoriametrics:victoriametrics /etc/victoria-metrics
103
+
104
+
```
105
+
106
+
- `/etc/victoria-metrics/prometheus.yml`
107
+
108
+
```yaml
109
+
global:
110
+
scrape_interval: '15s'
111
+
112
+
scrape_configs:
113
+
- job_name: 'link_aggregator'
114
+
static_configs:
115
+
- targets: ['link-aggregator:8765']
116
+
- job_name: 'gateway:caddy'
117
+
static_configs:
118
+
- targets: ['gateway:80/metrics']
119
+
- job_name: 'gateway:cache'
120
+
static_configs:
121
+
- targets: ['gateway:80/souin-api/metrics']
122
+
```
123
+
124
+
- `ExecStart` in `/etc/systemd/system/victoriametrics.service`:
125
+
126
+
```
127
+
ExecStart=/usr/local/bin/victoria-metrics-prod -storageDataPath=/var/lib/victoria-metrics -retentionPeriod=90d -selfScrapeInterval=1m -promscrape.config=/etc/victoria-metrics/prometheus.yml
128
+
```
129
+
130
+
- grafana
131
+
132
+
followed `https://grafana.com/docs/grafana/latest/setup-grafana/installation/debian/#install-grafana-on-debian-or-ubuntu`
133
+
134
+
something something something then
135
+
136
+
```
137
+
sudo grafana-cli --pluginUrl https://github.com/VictoriaMetrics/victoriametrics-datasource/releases/download/v0.11.1/victoriametrics-datasource-v0.11.1.zip plugins install victoriametrics
138
+
```
139
+
140
+
- raspi node_exporter
141
+
142
+
```bash
143
+
curl -LO https://github.com/prometheus/node_exporter/releases/download/v1.8.2/node_exporter-1.8.2.linux-armv7.tar.gz
144
+
tar xzf node_exporter-1.8.2.linux-armv7.tar.gz
145
+
sudo cp node_exporter-1.8.2.linux-armv7/node_exporter /usr/local/bin/
146
+
sudo useradd --no-create-home --shell /bin/false node_exporter
147
+
sudo nano /etc/systemd/system/node_exporter.service
148
+
# [Unit]
149
+
# Description=Node Exporter
150
+
# Wants=network-online.target
151
+
# After=network-online.target
152
+
153
+
# [Service]
154
+
# User=node_exporter
155
+
# Group=node_exporter
156
+
# Type=simple
157
+
# ExecStart=/usr/local/bin/node_exporter
158
+
# Restart=always
159
+
# RestartSec=3
160
+
161
+
# [Install]
162
+
# WantedBy=multi-user.target
163
+
sudo systemctl daemon-reload
164
+
sudo systemctl enable node_exporter.service
165
+
sudo systemctl start node_exporter.service
166
+
```
167
+
168
+
todo: get raspi vcgencmd outputs into metrics
169
+
170
+
- nginx on gateway
171
+
172
+
```nginx
173
+
# in http
174
+
175
+
##
176
+
# cozy cache
177
+
##
178
+
proxy_cache_path /var/cache/nginx keys_zone=cozy_zone:10m;
179
+
180
+
##
181
+
# cozy limit
182
+
##
183
+
limit_req_zone $binary_remote_addr zone=cozy_ip_limit:10m rate=50r/s;
184
+
limit_req_zone $server_name zone=cozy_global_limit:10m rate=1000r/s;
185
+
186
+
# in sites-available/constellation.microcosm.blue
187
+
188
+
upstream cozy_link_aggregator {
189
+
server link-aggregator:6789;
190
+
keepalive 16;
191
+
}
192
+
193
+
server {
194
+
listen 8080;
195
+
listen [::]:8080;
196
+
197
+
server_name constellation.microcosm.blue;
198
+
199
+
proxy_cache cozy_zone;
200
+
proxy_cache_background_update on;
201
+
proxy_cache_key "$scheme$proxy_host$uri$is_args$args$http_accept";
202
+
proxy_cache_lock on; # make simlutaneous requests for the same uri wait for it to appear in cache instead of hitting origin
203
+
proxy_cache_lock_age 1s;
204
+
proxy_cache_lock_timeout 2s;
205
+
proxy_cache_valid 10s; # default -- should be explicitly set in the response headers
206
+
proxy_cache_valid any 15s; # non-200s default
207
+
proxy_read_timeout 5s;
208
+
proxy_send_timeout 15s;
209
+
proxy_socket_keepalive on;
210
+
211
+
limit_req zone=cozy_ip_limit nodelay burst=100;
212
+
limit_req zone=cozy_global_limit;
213
+
limit_req_status 429;
214
+
215
+
location / {
216
+
proxy_pass http://cozy_link_aggregator;
217
+
include proxy_params;
218
+
proxy_http_version 1.1;
219
+
proxy_set_header Connection ""; # for keepalive
220
+
}
221
+
}
222
+
```
223
+
224
+
also `systemctl edit nginx` and paste
225
+
226
+
```
227
+
[Service]
228
+
Restart=always
229
+
```
230
+
231
+
—https://serverfault.com/a/1003373
232
+
233
+
now making browsers redirect to the microcosm.blue url:
234
+
235
+
```
236
+
[...]
237
+
server_name links.bsky.bad-example.com;
238
+
239
+
add_header Access-Control-Allow-Origin * always; # bit of hack to have it here but nginx doesn't like it in the `if`
240
+
if ($http_user_agent ~ ^Mozilla/) {
241
+
# for now send *browsers* to the new location, hopefully without impacting api requests
242
+
# (yeah we're doing UA test here and content-negotatiation in the app. whatever.)
243
+
return 301 https://constellation.microcosm.blue$request_uri;
244
+
}
245
+
[...]
246
+
```
247
+
248
+
- nginx metrics
249
+
250
+
- download nginx-prometheus-exporter
251
+
https://github.com/nginx/nginx-prometheus-exporter/releases/download/v1.4.1/nginx-prometheus-exporter_1.4.1_linux_amd64.tar.gz
252
+
253
+
- err actually going to make mistakes and try with snap
254
+
`snap install nginx-prometheus-exporter`
255
+
- so it got a binary for me but no systemd task set up. boooo.
256
+
`snap remove nginx-prometheus-exporter`
257
+
258
+
- ```bash
259
+
curl -LO https://github.com/nginx/nginx-prometheus-exporter/releases/download/v1.4.1/nginx-prometheus-exporter_1.4.1_linux_amd64.tar.gz
260
+
tar xzf nginx-prometheus-exporter_1.4.1_linux_amd64.tar.gz
261
+
mv nginx-prometheus-exporter /usr/local/bin
262
+
useradd --no-create-home --shell /bin/false nginx-prometheus-exporter
263
+
nano /etc/systemd/system/nginx-prometheus-exporter.service
264
+
# [Unit]
265
+
# Description=NGINX Exporter
266
+
# Wants=network-online.target
267
+
# After=network-online.target
268
+
269
+
# [Service]
270
+
# User=nginx-prometheus-exporter
271
+
# Group=nginx-prometheus-exporter
272
+
# Type=simple
273
+
# ExecStart=/usr/local/bin/nginx-prometheus-exporter --nginx.scrape-uri=http://gateway:8080/stub_status --web.listen-address=gateway:9113
274
+
# Restart=always
275
+
# RestartSec=3
276
+
277
+
# [Install]
278
+
# WantedBy=multi-user.target
279
+
systemctl daemon-reload
280
+
systemctl start nginx-prometheus-exporter.service
281
+
systemctl enable nginx-prometheus-exporter.service
282
+
```
283
+
284
+
- nginx `/etc/nginx/sites-available/gateway-nginx-status`
285
+
286
+
```nginx
287
+
server {
288
+
listen 8080;
289
+
listen [::]:8080;
290
+
291
+
server_name gateway;
292
+
293
+
location /stub_status {
294
+
stub_status;
295
+
}
296
+
location / {
297
+
return 404;
298
+
}
299
+
}
300
+
```
301
+
302
+
```bash
303
+
ln -s /etc/nginx/sites-available/gateway-nginx-status /etc/nginx/sites-enabled/
304
+
```
305
+
306
+
307
+
## bootes (pi5)
308
+
309
+
- mount sd card, touch `ssh` file echo `echo "pi:$(echo raspberry | openssl passwd -6 -stdin)" > userconf.txt`
310
+
- raspi-config: enable pcie 3, set hostname, enable ssh
311
+
- put ssh key into `.ssh/authorized_keys`
312
+
- put `PasswordAuthentication no` in `/etc/ssh/sshd_config`
313
+
- `sudo apt update && sudo apt upgrade`
314
+
- `sudo apt install xfsprogs`
315
+
- `sudo mkfs.xfs -L c11n-kv /dev/nvme0n1`
316
+
- `sudo mount /dev/nvme0n1 /mnt`
317
+
- set up tailscale
318
+
- `sudo tailscale up`
319
+
- `git clone https://github.com/atcosm/links.git`
320
+
- tailscale: disable bootes key expiry
321
+
- rustup `curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh`
322
+
- `cd links/constellation`
323
+
- `sudo apt install libssl-dev` needed
324
+
- `sudo apt install clang` needed for bindgen
325
+
- (in tmux) `cargo build --release`
326
+
- `mkdir ~/backup`
327
+
- `sudo mount.cifs "//truenas.local/folks data" /home/pi/backup -o user=phil,uid=pi`
328
+
- `sudo chown pi:pi /mnt/`
329
+
- `RUST_BACKTRACE=full cargo run --bin rocks-restore-from-backup --release -- --from-backup-dir "/home/pi/backup/constellation-index" --to-data-dir /mnt/constellation-index`
330
+
etc
331
+
- follow above `- raspi node_exporter`
332
+
- configure victoriametrics to scrape the new pi
333
+
- configure ulimit before starting! `ulimit -n 16384`
334
+
- `RUST_BACKTRACE=full cargo run --release -- --backend rocks --data /mnt/constellation-index/ --jetstream us-east-2 --backup /home/pi/backup/constellation-index --backup-interval 6 --max-old-backups 20`
335
+
- add server to nginx gateway upstream: ` server 100.123.79.12:6789; # bootes`
336
+
- stop backups from running on the older instance! `RUST_BACKTRACE=full cargo run --release -- --backend rocks --data /mnt/links-2.rocks/ --jetstream us-east-1`
337
+
- stop upstreaming requests to older instance in nginx
338
+
339
+
340
+
- systemd unit for running: `sudo nano /etc/systemd/system/constellation.service`
341
+
342
+
```ini
343
+
[Unit]
344
+
Description=Constellation backlinks index
345
+
After=network.target
346
+
347
+
[Service]
348
+
User=pi
349
+
WorkingDirectory=/home/pi/links/constellation
350
+
ExecStart=/home/pi/links/target/release/main --backend rocks --data /mnt/constellation-index/ --jetstream us-east-2 --backup /home/pi/backup/constellation-index --backup-interval 6 --max-old-backups 20
351
+
LimitNOFILE=16384
352
+
Restart=always
353
+
354
+
[Install]
355
+
WantedBy=multi-user.target
356
+
```
357
+
358
+
359
+
- todo: overlayfs? would need to figure out builds/updates still, also i guess logs are currently written to sd? (oof)
360
+
- todo: cross-compile for raspi?
361
+
362
+
---
363
+
364
+
some todos
365
+
366
+
- [x] tailscale: exit node
367
+
- [!] link_aggregator: use exit node
368
+
-> worked, but reverted for now: tailscale on raspi was consuming ~50% cpu for the jetstream traffic. this might be near its max since it would have been catching up at the time (max jetstream throughput) but it feels a bit too much. we have to trust the jetstream server and link_aggregator doesn't (yet) make any other external connections, so for now the raspi connects directly from my home again.
369
+
- [x] caddy: reverse proxy
370
+
- [x] build with cache and rate-limit plugins
371
+
- [x] configure systemd to keep it alive
372
+
- [x] configure caddy cache
373
+
- [x] configure caddy rate-limit
374
+
- [ ] configure ~caddy~ nginx to use a health check (once it's added)
375
+
- [ ] ~configure caddy to only expose cache metrics to tailnet :/~
376
+
- [x] make some grafana dashboards
377
+
- [ ] raspi: mount /dev/sda on boot
378
+
- [ ] raspi: run link_aggregator via systemd so it starts on startup (and restarts?)
379
+
380
+
- [x] use nginx instead of caddy
381
+
- [x] nginx: enable cache
382
+
- [x] nginx: rate-limit
383
+
- [ ] nginx: get metrics
384
+
385
+
386
+
387
+
388
+
---
389
+
390
+
nginx cors for constellation + small burst bump
391
+
392
+
```nginx
393
+
upstream cozy_constellation {
394
+
server <tailnet ip>:6789; # bootes; ip so that we don't race on reboot with tailscale coming up, which nginx doesn't like
395
+
keepalive 16;
396
+
}
397
+
398
+
server {
399
+
server_name constellation.microcosm.blue;
400
+
401
+
proxy_cache cozy_zone;
402
+
proxy_cache_background_update on;
403
+
proxy_cache_key "$scheme$proxy_host$uri$is_args$args$http_accept";
404
+
proxy_cache_lock on; # make simlutaneous requests for the same uri wait for it to appear in cache instead of hitting origin
405
+
proxy_cache_lock_age 1s;
406
+
proxy_cache_lock_timeout 2s;
407
+
proxy_cache_valid 10s; # default -- should be explicitly set in the response headers
408
+
proxy_cache_valid any 2s; # non-200s default
409
+
proxy_read_timeout 5s;
410
+
proxy_send_timeout 15s;
411
+
proxy_socket_keepalive on;
412
+
413
+
# take over cors responsibility from upsteram. `always` applies it to error responses.
414
+
proxy_hide_header 'Access-Control-Allow-Origin';
415
+
proxy_hide_header 'Access-Control-Allowed-Methods';
416
+
proxy_hide_header 'Access-Control-Allow-Headers';
417
+
add_header 'Access-Control-Allow-Origin' '*' always;
418
+
add_header 'Access-Control-Allow-Methods' 'GET' always;
419
+
add_header 'Access-Control-Allow-Headers' '*' always;
420
+
421
+
422
+
limit_req zone=cozy_ip_limit nodelay burst=150;
423
+
limit_req zone=cozy_global_limit burst=1800;
424
+
limit_req_status 429;
425
+
426
+
location / {
427
+
proxy_pass http://cozy_constellation;
428
+
include proxy_params;
429
+
proxy_http_version 1.1;
430
+
proxy_set_header Connection ""; # for keepalive
431
+
}
432
+
433
+
434
+
listen 443 ssl; # managed by Certbot
435
+
ssl_certificate /etc/letsencrypt/live/constellation.microcosm.blue/fullchain.pem; # managed by Certbot
436
+
ssl_certificate_key /etc/letsencrypt/live/constellation.microcosm.blue/privkey.pem; # managed by Certbot
437
+
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
438
+
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
439
+
440
+
}
441
+
442
+
server {
443
+
if ($host = constellation.microcosm.blue) {
444
+
return 301 https://$host$request_uri;
445
+
} # managed by Certbot
446
+
447
+
448
+
server_name constellation.microcosm.blue;
449
+
listen 80;
450
+
return 404; # managed by Certbot
451
+
}
452
+
```
453
+
454
+
re-reading about `nodelay`, i should probably remove it -- nginx would then queue requests to upstream, but still service them at the configured limit. it's fine for my internet since the global limit isn't nodelay, but probably less "fair" to clients if there's contention around the global limit (earlier requests would get all of theirs serviced before later ones can get in the queue)
455
+
456
+
leaving it for now though.
457
+
458
+
459
+
### nginx logs to prom
460
+
461
+
```bash
462
+
curl -LO https://github.com/martin-helmich/prometheus-nginxlog-exporter/releases/download/v1.11.0/prometheus-nginxlog-exporter_1.11.0_linux_amd64.deb
463
+
apt install ./prometheus-nginxlog-exporter_1.11.0_linux_amd64.deb
464
+
systemctl enable prometheus-nginxlog-exporter.service
465
+
466
+
```
467
+
468
+
have it run as www-data (maybe not the best idea but...)
469
+
file `/usr/lib/systemd/system/prometheus-nginxlog-exporter.service`
470
+
set User under service and remove capabilities bounding
471
+
472
+
```systemd
473
+
User=www-data
474
+
#CapabilityBoundingSet=
475
+
```
476
+
477
+
in `nginx.conf` in `http`:
478
+
479
+
```nginx
480
+
log_format constellation_format "$remote_addr - $remote_user [$time_local] \"$request\" $status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\"";
481
+
```
482
+
483
+
in `sites-available/constellation.microcosm.blue` in `server`:
484
+
485
+
```nginx
486
+
# log format must match prometheus-nginx-log-exporter
487
+
access_log /var/log/nginx/constellation-access.log constellation_format;
488
+
```
489
+
490
+
config at `/etc/prometheus-nginxlog-exporter.hcl`
491
+
492
+
493
+
494
+
```bash
495
+
systemctl start prometheus-nginxlog-exporter.service
496
+
```
+35
legacy/old-readme-details.md
+35
legacy/old-readme-details.md
···
1
+
[Constellation](./constellation/)
2
+
--------------------------------------------
3
+
4
+
A global atproto backlink index ✨
5
+
6
+
- Self hostable: handles the full write throughput of the global atproto firehose on a raspberry pi 4b + single SSD
7
+
- Storage efficient: less than 2GB/day disk consumption indexing all references in all lexicons and all non-atproto URLs
8
+
- Handles record deletion, account de/re-activation, and account deletion, ensuring accurate link counts and respecting users data choices
9
+
- Simple JSON API
10
+
11
+
All social interactions in atproto tend to be represented by links (or references) between PDS records. This index can answer questions like "how many likes does a bsky post have", "who follows an account", "what are all the comments on a [frontpage](https://frontpage.fyi/) post", and more.
12
+
13
+
- **status**: works! api is unstable and likely to change, and no known instances have a full network backfill yet.
14
+
- source: [./constellation/](./constellation/)
15
+
- public instance: [constellation.microcosm.blue](https://constellation.microcosm.blue/)
16
+
17
+
_note: the public instance currently runs on a little raspberry pi in my house, feel free to use it! it comes with only with best-effort uptime, no commitment to not breaking the api for now, and possible rate-limiting. if you want to be nice you can put your project name and bsky username (or email) in your user-agent header for api requests._
18
+
19
+
20
+
App: Spacedust
21
+
--------------
22
+
23
+
A notification subscription service 💫
24
+
25
+
using the same "link source" concept as [constellation](./constellation/), offer webhook notifications for new references created to records
26
+
27
+
- **status**: in design
28
+
29
+
30
+
Library: [links](./links/)
31
+
------------------------------------
32
+
33
+
A rust crate (not published on crates.io yet) for optimistically parsing links out of arbitrary atproto PDS records, and potentially canonicalizing them
34
+
35
+
- **status**: unstable, might remain an internal lib for constellation (and spacedust, soon)
+123
legacy/original-notes.md
+123
legacy/original-notes.md
···
1
+
---
2
+
3
+
4
+
old notes follow, ignore
5
+
------------------------
6
+
7
+
8
+
as far as i can tell, atproto lexicons today don't follow much of a convention for referencing across documents: sometimes it's a StrongRef, sometimes it's a DID, sometimes it's a bare at-uri. lexicon authors choose any old link-sounding key name for the key in their document.
9
+
10
+
it's pretty messy so embrace the mess: atproto wants to be part of the web, so this library will also extract URLs and other URIs if you want it to. all the links.
11
+
12
+
13
+
why
14
+
---
15
+
16
+
the atproto firehose that bluesky sprays at you will contain raw _contents_ from peoples' pdses. these are isolated, decontextualized updates. it's very easy to build some kinds of interesting downstream apps off of this feed.
17
+
18
+
- bluesky posts (firesky, deletions, )
19
+
- blueksy post stats (emojis, )
20
+
- trending keywords ()
21
+
22
+
but bringing almost kind of _context_ into your project requires a big step up in complexity and potentially cost: you're entering "appview" territory. _how many likes does a post have? who follows this account?_
23
+
24
+
you own your atproto data: it's kept in your personal data repository (PDS) and noone else can write to it. when someone likes your post, they create a "like" record in their _own_ pds, and that like belongs to _them_, not to you/your post.
25
+
26
+
in the firehose you'll see a `app.bsky.feed.post` record created, with no details about who has liked it. then you'll see separate `app.bsky.feed.like` records show up for each like that comes in on that post, with no context about the post except a random-looking reference to it. storing these in order to do so is up to you!
27
+
28
+
**so, why**
29
+
30
+
everything is links, and they're a mess, but they all kinda work the same, so maybe some tooling can bring down that big step in complexity from firehose raw-content apps -> apps requiring any social context.
31
+
32
+
everything is links:
33
+
34
+
- likes
35
+
- follows
36
+
- blocks
37
+
- reposts
38
+
- quotes
39
+
40
+
some low-level things you could make from links:
41
+
42
+
- notification streams (part of ucosm)
43
+
- a global reverse index (part of ucosm)
44
+
45
+
i think that making these low-level services as easy to use as jetstream could open up pathways for building more atproto apps that operate at full scale with interesting features for reasonable effort at low cost to operate.
46
+
47
+
48
+
extracting links
49
+
---------------
50
+
51
+
52
+
- low-level: pass a &str of a field value and get a parsed link back
53
+
54
+
- med-level: pass a &str of record in json form and get a list of parsed links + json paths back. (todo: should also handle dag-cbor prob?)
55
+
56
+
- high-ish level: pass the json record and maybe apply some pre-loaded rules based on known lexicons to get the best result.
57
+
58
+
for now, a link is only considered if it matches for the entire value of the record's field -- links embedded in text content are not included. note that urls in bluesky posts _will_ still be extracted, since they are broken out into facets.
59
+
60
+
61
+
resolving / canonicalizing links
62
+
--------------------------------
63
+
64
+
65
+
### at-uris
66
+
67
+
every at-uri has at least two equivalent forms, one with a `DID`, and one with an account handle. the at-uri spec [illustrates this by example](https://atproto.com/specs/at-uri-scheme):
68
+
69
+
- `at://did:plc:44ybard66vv44zksje25o7dz/app.bsky.feed.post/3jwdwj2ctlk26`
70
+
- `at://bnewbold.bsky.team/app.bsky.feed.post/3jwdwj2ctlk26`
71
+
72
+
some applications, like a reverse link index, may wish to canonicalize at-uris to a single form. the `DID`-form is stable as an account changes its handle and probably the right choice to canonicalize to, but maybe some apps would actually perfer to canonicalise to handles?
73
+
74
+
hopefully atrium will make it easy to resolve at-uris.
75
+
76
+
77
+
### urls
78
+
79
+
canonicalizing URLs is more annoying but also a bit more established. lots of details.
80
+
81
+
- do we have to deal with punycode?
82
+
- follow redirects (todo: only permanent ones, or all?)
83
+
- check for rel=canonical http header and possibly follow it
84
+
- check link rel=canonical meta tag and possibly follow it
85
+
- do we need to check site maps??
86
+
- do we have to care at all about AMP?
87
+
- do we want anything to do with url shorteners??
88
+
- how do multilingual sites affect this?
89
+
- do we have to care about `script type="application/ld+json"` ???
90
+
91
+
ugh. is there a crate for this.
92
+
93
+
94
+
### relative uris?
95
+
96
+
links might be relative, in which case they might need to be made absolute before being useful. is that a concern for this library, or up to the user? (seems like we might not have context here to determine its absolute)
97
+
98
+
99
+
### canonicalizing
100
+
101
+
there should be a few async functions available to canonicalize already-parsed links.
102
+
103
+
- what happens if a link can't be resolved?
104
+
105
+
106
+
---
107
+
108
+
- using `tinyjson` because it's nice -- maybe should switch to serde_json to share deps with atrium?
109
+
110
+
- would use atrium for parsing at-uris, but it's not in there. there's a did-only version in the non-lib commands.rs. its identifier parser is strict to did + handle, which makes sense, but for our purposes we might want to allow unknown methods too?
111
+
112
+
- rsky-syntax has an aturi
113
+
- adenosyne also
114
+
- might come back to these
115
+
116
+
117
+
-------
118
+
119
+
rocks
120
+
121
+
```bash
122
+
ROCKSDB_LIB_DIR=/nix/store/z2chn0hsik0clridr8mlprx1cngh1g3c-rocksdb-9.7.3/lib/ cargo build
123
+
```
+196
legacy/ufos ops (move to micro-ops).md
+196
legacy/ufos ops (move to micro-ops).md
···
1
+
ufos ops
2
+
3
+
btrfs snapshots: snapper
4
+
5
+
```bash
6
+
sudo apt install snapper
7
+
sudo snapper -c ufos-db create-config /mnt/ufos-db
8
+
9
+
# edit /etc/snapper/configs/ufos-db
10
+
# change
11
+
TIMELINE_MIN_AGE="1800"
12
+
TIMELINE_LIMIT_HOURLY="10"
13
+
TIMELINE_LIMIT_DAILY="10"
14
+
TIMELINE_LIMIT_WEEKLY="0"
15
+
TIMELINE_LIMIT_MONTHLY="10"
16
+
TIMELINE_LIMIT_YEARLY="10"
17
+
# to
18
+
TIMELINE_MIN_AGE="1800"
19
+
TIMELINE_LIMIT_HOURLY="22"
20
+
TIMELINE_LIMIT_DAILY="4"
21
+
TIMELINE_LIMIT_WEEKLY="0"
22
+
TIMELINE_LIMIT_MONTHLY="0"
23
+
TIMELINE_LIMIT_YEARLY="0"
24
+
```
25
+
26
+
this should be enough?
27
+
28
+
list snapshots:
29
+
30
+
```bash
31
+
sudo snapper -c ufos-db list
32
+
```
33
+
34
+
systemd
35
+
36
+
create file: `/etc/systemd/system/ufos.service`
37
+
38
+
```ini
39
+
[Unit]
40
+
Description=UFOs-API
41
+
After=network.target
42
+
43
+
[Service]
44
+
User=pi
45
+
WorkingDirectory=/home/pi/
46
+
ExecStart=/home/pi/ufos --jetstream us-west-2 --data /mnt/ufos-db/
47
+
Environment="RUST_LOG=info"
48
+
LimitNOFILE=16384
49
+
Restart=always
50
+
51
+
[Install]
52
+
WantedBy=multi-user.target
53
+
```
54
+
55
+
then
56
+
57
+
```bash
58
+
sudo systemctl daemon-reload
59
+
sudo systemctl enable ufos
60
+
sudo systemctl start ufos
61
+
```
62
+
63
+
monitor with
64
+
65
+
```bash
66
+
journalctl -u ufos -f
67
+
```
68
+
69
+
make sure a backup dir exists
70
+
71
+
```bash
72
+
mkdir /home/pi/backup
73
+
```
74
+
75
+
mount the NAS
76
+
77
+
```bash
78
+
sudo mount.cifs "//truenas.local/folks data" /home/pi/backup -o user=phil,uid=pi
79
+
```
80
+
81
+
manual rsync
82
+
83
+
```bash
84
+
sudo rsync -ahP --delete /mnt/ufos-db/.snapshots/1/snapshot/ backup/ufos/
85
+
```
86
+
87
+
backup script sketch
88
+
89
+
```bash
90
+
NUM=$(sudo snapper --csvout -c ufos-db list --type single --columns number | tail -n1)
91
+
sudo rsync -ahP --delete "/mnt/ufos-db/.snapshots/${NUM}/snapshot/" backup/ufos/
92
+
```
93
+
94
+
just crontab it?
95
+
96
+
`sudo crontab -e`
97
+
```bash
98
+
0 1/6 * * * rsync -ahP --delete "/mnt/ufos-db/.snapshots/$(sudo snapper --csvout -c ufos-db list --columns number | tail -n1)/snapshot/" backup/ufos/
99
+
```
100
+
101
+
^^ try once initial backup is done
102
+
103
+
104
+
--columns subvolume,number
105
+
106
+
subvolume
107
+
number
108
+
109
+
110
+
111
+
112
+
gateway: follow constellation for nginx->prom thing
113
+
114
+
config at `/etc/prometheus-nginxlog-exporter.hcl`
115
+
116
+
before: `/etc/prometheus-nginxlog-exporter.hcl`
117
+
118
+
```hcl
119
+
listen {
120
+
port = 4044
121
+
}
122
+
123
+
namespace "nginx" {
124
+
source = {
125
+
files = [
126
+
"/var/log/nginx/constellation-access.log"
127
+
]
128
+
}
129
+
130
+
format = "$remote_addr - $remote_user [$time_local] \"$request\" $status $upstream_cache_status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\""
131
+
132
+
labels {
133
+
app = "constellation"
134
+
}
135
+
136
+
relabel "cache_status" {
137
+
from = "upstream_cache_status"
138
+
}
139
+
}
140
+
```
141
+
142
+
after:
143
+
144
+
```hcl
145
+
listen {
146
+
port = 4044
147
+
}
148
+
149
+
namespace "constellation" {
150
+
source = {
151
+
files = [
152
+
"/var/log/nginx/constellation-access.log"
153
+
]
154
+
}
155
+
156
+
format = "$remote_addr - $remote_user [$time_local] \"$request\" $status $upstream_cache_status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\""
157
+
158
+
labels {
159
+
app = "constellation"
160
+
}
161
+
162
+
relabel "cache_status" {
163
+
from = "upstream_cache_status"
164
+
}
165
+
166
+
namespace_label = "vhost"
167
+
metrics_override = { prefix = "nginx" }
168
+
}
169
+
170
+
namespace "ufos" {
171
+
source = {
172
+
files = [
173
+
"/var/log/nginx/ufos-access.log"
174
+
]
175
+
}
176
+
177
+
format = "$remote_addr - $remote_user [$time_local] \"$request\" $status $upstream_cache_status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\""
178
+
179
+
labels {
180
+
app = "ufos"
181
+
}
182
+
183
+
relabel "cache_status" {
184
+
from = "upstream_cache_status"
185
+
}
186
+
187
+
namespace_label = "vhost"
188
+
metrics_override = { prefix = "nginx" }
189
+
}
190
+
```
191
+
192
+
193
+
```bash
194
+
systemctl start prometheus-nginxlog-exporter.service
195
+
```
196
+
+1
pocket/.gitignore
+1
pocket/.gitignore
···
1
+
prefs.sqlite3*
+19
pocket/Cargo.toml
+19
pocket/Cargo.toml
···
1
+
[package]
2
+
name = "pocket"
3
+
version = "0.1.0"
4
+
edition = "2024"
5
+
6
+
[dependencies]
7
+
atrium-crypto = "0.1.2"
8
+
clap = { version = "4.5.41", features = ["derive"] }
9
+
jwt-compact = { git = "https://github.com/fatfingers23/jwt-compact.git", features = ["es256k"] }
10
+
log = "0.4.27"
11
+
poem = { version = "3.1.12", features = ["acme", "static-files"] }
12
+
poem-openapi = { version = "5.1.16", features = ["scalar"] }
13
+
reqwest = { version = "0.12.22", features = ["json"] }
14
+
rusqlite = "0.37.0"
15
+
serde = { version = "1.0.219", features = ["derive"] }
16
+
serde_json = { version = "1.0.141" }
17
+
thiserror = "2.0.16"
18
+
tokio = { version = "1.47.0", features = ["full"] }
19
+
tracing-subscriber = { version = "0.3.19", features = ["env-filter"] }
+17
pocket/api-description.md
+17
pocket/api-description.md
···
1
+
_A pocket dimension to stash a bit of non-public user data._
2
+
3
+
4
+
# Pocket: user preference storage
5
+
6
+
This API leverages atproto service proxying to offer a bit of per-user per-app non-public data storage.
7
+
Perfect for things like application preferences that might be better left out of the public PDS data.
8
+
9
+
The intent is to use oauth scopes to isolate storage on a per-application basis, and to allow easy data migration from a community hosted instance to your own if you end up needing that.
10
+
11
+
12
+
### Current status
13
+
14
+
> [!important]
15
+
> Pocket is currently in a **v0, pre-release state**. There is one production instance and you can use it! Expect short downtimes for restarts as development progresses and occaisional data loss until it's stable.
16
+
17
+
ATProto might end up adding a similar feature to [PDSs](https://atproto.com/guides/glossary#pds-personal-data-server). If/when that happens, you should use it instead of this!
+7
pocket/src/lib.rs
+7
pocket/src/lib.rs
+34
pocket/src/main.rs
+34
pocket/src/main.rs
···
1
+
use clap::Parser;
2
+
use pocket::{Storage, serve};
3
+
use std::path::PathBuf;
4
+
5
+
/// Slingshot record edge cache
6
+
#[derive(Parser, Debug, Clone)]
7
+
#[command(version, about, long_about = None)]
8
+
struct Args {
9
+
/// path to the sqlite db file
10
+
#[arg(long)]
11
+
db: Option<PathBuf>,
12
+
/// just initialize the db and exit
13
+
#[arg(long, action)]
14
+
init_db: bool,
15
+
/// the domain for serving a did doc (unused if running behind reflector)
16
+
#[arg(long)]
17
+
domain: Option<String>,
18
+
}
19
+
20
+
#[tokio::main]
21
+
async fn main() {
22
+
tracing_subscriber::fmt::init();
23
+
log::info!("👖 hi");
24
+
let args = Args::parse();
25
+
let domain = args.domain.unwrap_or("bad-example.com".into());
26
+
let db_path = args.db.unwrap_or("prefs.sqlite3".into());
27
+
if args.init_db {
28
+
Storage::init(&db_path).unwrap();
29
+
log::info!("👖 initialized db at {db_path:?}. bye")
30
+
} else {
31
+
let storage = Storage::connect(db_path).unwrap();
32
+
serve(&domain, storage).await
33
+
}
34
+
}
+265
pocket/src/server.rs
+265
pocket/src/server.rs
···
1
+
use crate::{Storage, TokenVerifier};
2
+
use poem::{
3
+
Endpoint, EndpointExt, Route, Server,
4
+
endpoint::{StaticFileEndpoint, make_sync},
5
+
http::Method,
6
+
listener::TcpListener,
7
+
middleware::{CatchPanic, Cors, Tracing},
8
+
};
9
+
use poem_openapi::{
10
+
ApiResponse, ContactObject, ExternalDocumentObject, Object, OpenApi, OpenApiService,
11
+
SecurityScheme, Tags,
12
+
auth::Bearer,
13
+
payload::{Json, PlainText},
14
+
types::Example,
15
+
};
16
+
use serde::Serialize;
17
+
use serde_json::{Value, json};
18
+
use std::sync::{Arc, Mutex};
19
+
20
+
#[derive(Debug, SecurityScheme)]
21
+
#[oai(ty = "bearer")]
22
+
struct XrpcAuth(Bearer);
23
+
24
+
#[derive(Tags)]
25
+
enum ApiTags {
26
+
/// Custom pocket APIs
27
+
#[oai(rename = "Pocket APIs")]
28
+
Pocket,
29
+
}
30
+
31
+
#[derive(Object)]
32
+
#[oai(example = true)]
33
+
struct XrpcErrorResponseObject {
34
+
/// Should correspond an error `name` in the lexicon errors array
35
+
error: String,
36
+
/// Human-readable description and possibly additonal context
37
+
message: String,
38
+
}
39
+
impl Example for XrpcErrorResponseObject {
40
+
fn example() -> Self {
41
+
Self {
42
+
error: "PreferencesNotFound".to_string(),
43
+
message: "No preferences were found for this user".to_string(),
44
+
}
45
+
}
46
+
}
47
+
type XrpcError = Json<XrpcErrorResponseObject>;
48
+
fn xrpc_error(error: impl AsRef<str>, message: impl AsRef<str>) -> XrpcError {
49
+
Json(XrpcErrorResponseObject {
50
+
error: error.as_ref().to_string(),
51
+
message: message.as_ref().to_string(),
52
+
})
53
+
}
54
+
55
+
#[derive(Debug, Object)]
56
+
#[oai(example = true)]
57
+
struct BskyPrefsObject {
58
+
/// at-uri for this record
59
+
preferences: Value,
60
+
}
61
+
impl Example for BskyPrefsObject {
62
+
fn example() -> Self {
63
+
Self {
64
+
preferences: json!({
65
+
"hello": "world",
66
+
}),
67
+
}
68
+
}
69
+
}
70
+
71
+
#[derive(ApiResponse)]
72
+
enum GetBskyPrefsResponse {
73
+
/// Record found
74
+
#[oai(status = 200)]
75
+
Ok(Json<BskyPrefsObject>),
76
+
/// Bad request or no preferences to return
77
+
#[oai(status = 400)]
78
+
BadRequest(XrpcError),
79
+
}
80
+
81
+
#[derive(ApiResponse)]
82
+
enum PutBskyPrefsResponse {
83
+
/// Record found
84
+
#[oai(status = 200)]
85
+
Ok(PlainText<String>),
86
+
/// Bad request or no preferences to return
87
+
#[oai(status = 400)]
88
+
BadRequest(XrpcError),
89
+
// /// Server errors
90
+
// #[oai(status = 500)]
91
+
// ServerError(XrpcError),
92
+
}
93
+
94
+
struct Xrpc {
95
+
verifier: TokenVerifier,
96
+
storage: Arc<Mutex<Storage>>,
97
+
}
98
+
99
+
#[OpenApi]
100
+
impl Xrpc {
101
+
/// com.bad-example.pocket.getPreferences
102
+
///
103
+
/// get stored preferencess
104
+
#[oai(
105
+
path = "/com.bad-example.pocket.getPreferences",
106
+
method = "get",
107
+
tag = "ApiTags::Pocket"
108
+
)]
109
+
async fn pocket_get_prefs(&self, XrpcAuth(auth): XrpcAuth) -> GetBskyPrefsResponse {
110
+
let (did, aud) = match self
111
+
.verifier
112
+
.verify("com.bad-example.pocket.getPreferences", &auth.token)
113
+
.await
114
+
{
115
+
Ok(d) => d,
116
+
Err(e) => return GetBskyPrefsResponse::BadRequest(xrpc_error("boooo", e.to_string())),
117
+
};
118
+
log::info!("verified did: {did}/{aud}");
119
+
120
+
let storage = self.storage.clone();
121
+
122
+
let Ok(Ok(res)) = tokio::task::spawn_blocking(move || {
123
+
storage
124
+
.lock()
125
+
.unwrap()
126
+
.get(&did, &aud)
127
+
.inspect_err(|e| log::error!("failed to get prefs: {e}"))
128
+
})
129
+
.await
130
+
else {
131
+
return GetBskyPrefsResponse::BadRequest(xrpc_error("boooo", "failed to get from db"));
132
+
};
133
+
134
+
let Some(serialized) = res else {
135
+
return GetBskyPrefsResponse::BadRequest(xrpc_error(
136
+
"NotFound",
137
+
"could not find prefs for u",
138
+
));
139
+
};
140
+
141
+
let preferences = match serde_json::from_str(&serialized) {
142
+
Ok(v) => v,
143
+
Err(e) => {
144
+
log::error!("failed to deserialize prefs: {e}");
145
+
return GetBskyPrefsResponse::BadRequest(xrpc_error(
146
+
"boooo",
147
+
"failed to deserialize prefs",
148
+
));
149
+
}
150
+
};
151
+
152
+
GetBskyPrefsResponse::Ok(Json(BskyPrefsObject { preferences }))
153
+
}
154
+
155
+
/// com.bad-example.pocket.putPreferences
156
+
///
157
+
/// store bluesky prefs
158
+
#[oai(
159
+
path = "/com.bad-example.pocket.putPreferences",
160
+
method = "post",
161
+
tag = "ApiTags::Pocket"
162
+
)]
163
+
async fn pocket_put_prefs(
164
+
&self,
165
+
XrpcAuth(auth): XrpcAuth,
166
+
Json(prefs): Json<BskyPrefsObject>,
167
+
) -> PutBskyPrefsResponse {
168
+
let (did, aud) = match self
169
+
.verifier
170
+
.verify("com.bad-example.pocket.putPreferences", &auth.token)
171
+
.await
172
+
{
173
+
Ok(d) => d,
174
+
Err(e) => return PutBskyPrefsResponse::BadRequest(xrpc_error("boooo", e.to_string())),
175
+
};
176
+
log::info!("verified did: {did}/{aud}");
177
+
log::warn!("received prefs: {prefs:?}");
178
+
179
+
let storage = self.storage.clone();
180
+
let serialized = prefs.preferences.to_string();
181
+
182
+
let Ok(Ok(())) = tokio::task::spawn_blocking(move || {
183
+
storage
184
+
.lock()
185
+
.unwrap()
186
+
.put(&did, &aud, &serialized)
187
+
.inspect_err(|e| log::error!("failed to insert prefs: {e}"))
188
+
})
189
+
.await
190
+
else {
191
+
return PutBskyPrefsResponse::BadRequest(xrpc_error("boooo", "failed to put to db"));
192
+
};
193
+
194
+
PutBskyPrefsResponse::Ok(PlainText("saved.".to_string()))
195
+
}
196
+
}
197
+
198
+
#[derive(Debug, Clone, Serialize)]
199
+
#[serde(rename_all = "camelCase")]
200
+
struct AppViewService {
201
+
id: String,
202
+
r#type: String,
203
+
service_endpoint: String,
204
+
}
205
+
#[derive(Debug, Clone, Serialize)]
206
+
struct AppViewDoc {
207
+
id: String,
208
+
service: [AppViewService; 2],
209
+
}
210
+
/// Serve a did document for did:web for this to be an xrpc appview
211
+
fn get_did_doc(domain: &str) -> impl Endpoint + use<> {
212
+
let doc = poem::web::Json(AppViewDoc {
213
+
id: format!("did:web:{domain}"),
214
+
service: [
215
+
AppViewService {
216
+
id: "#pocket_prefs".to_string(),
217
+
r#type: "PocketPreferences".to_string(),
218
+
service_endpoint: format!("https://{domain}"),
219
+
},
220
+
AppViewService {
221
+
id: "#bsky_appview".to_string(),
222
+
r#type: "BlueskyAppview".to_string(),
223
+
service_endpoint: format!("https://{domain}"),
224
+
},
225
+
],
226
+
});
227
+
make_sync(move |_| doc.clone())
228
+
}
229
+
230
+
pub async fn serve(domain: &str, storage: Storage) -> () {
231
+
let verifier = TokenVerifier::default();
232
+
let api_service = OpenApiService::new(
233
+
Xrpc {
234
+
verifier,
235
+
storage: Arc::new(Mutex::new(storage)),
236
+
},
237
+
"Pocket",
238
+
env!("CARGO_PKG_VERSION"),
239
+
)
240
+
.server(domain)
241
+
.url_prefix("/xrpc")
242
+
.contact(
243
+
ContactObject::new()
244
+
.name("@microcosm.blue")
245
+
.url("https://bsky.app/profile/microcosm.blue"),
246
+
)
247
+
.description(include_str!("../api-description.md"))
248
+
.external_document(ExternalDocumentObject::new("https://microcosm.blue/pocket"));
249
+
250
+
let app = Route::new()
251
+
.nest("/openapi", api_service.spec_endpoint())
252
+
.nest("/xrpc/", api_service)
253
+
.at("/.well-known/did.json", get_did_doc(domain))
254
+
.at("/", StaticFileEndpoint::new("./static/index.html"))
255
+
.with(
256
+
Cors::new()
257
+
.allow_method(Method::GET)
258
+
.allow_method(Method::POST),
259
+
)
260
+
.with(CatchPanic::new())
261
+
.with(Tracing);
262
+
263
+
let listener = TcpListener::bind("127.0.0.1:3000");
264
+
Server::new(listener).name("pocket").run(app).await.unwrap();
265
+
}
+50
pocket/src/storage.rs
+50
pocket/src/storage.rs
···
1
+
use rusqlite::{Connection, OptionalExtension, Result};
2
+
use std::path::Path;
3
+
4
+
pub struct Storage {
5
+
con: Connection,
6
+
}
7
+
8
+
impl Storage {
9
+
pub fn connect(path: impl AsRef<Path>) -> Result<Self> {
10
+
let con = Connection::open(path)?;
11
+
con.pragma_update(None, "journal_mode", "WAL")?;
12
+
con.pragma_update(None, "synchronous", "NORMAL")?;
13
+
con.pragma_update(None, "busy_timeout", "100")?;
14
+
con.pragma_update(None, "foreign_keys", "ON")?;
15
+
Ok(Self { con })
16
+
}
17
+
pub fn init(path: impl AsRef<Path>) -> Result<Self> {
18
+
let me = Self::connect(path)?;
19
+
me.con.execute(
20
+
r#"
21
+
create table prefs (
22
+
actor text not null,
23
+
aud text not null,
24
+
pref text not null,
25
+
primary key (actor, aud)
26
+
) strict"#,
27
+
(),
28
+
)?;
29
+
Ok(me)
30
+
}
31
+
pub fn put(&self, actor: &str, aud: &str, pref: &str) -> Result<()> {
32
+
self.con.execute(
33
+
r#"insert into prefs (actor, aud, pref)
34
+
values (?1, ?2, ?3)
35
+
on conflict do update set pref = excluded.pref"#,
36
+
[actor, aud, pref],
37
+
)?;
38
+
Ok(())
39
+
}
40
+
pub fn get(&self, actor: &str, aud: &str) -> Result<Option<String>> {
41
+
self.con
42
+
.query_one(
43
+
r#"select pref from prefs
44
+
where actor = ?1 and aud = ?2"#,
45
+
[actor, aud],
46
+
|row| row.get(0),
47
+
)
48
+
.optional()
49
+
}
50
+
}
+143
pocket/src/token.rs
+143
pocket/src/token.rs
···
1
+
use atrium_crypto::did::parse_multikey;
2
+
use atrium_crypto::verify::Verifier;
3
+
use jwt_compact::UntrustedToken;
4
+
use serde::Deserialize;
5
+
use std::collections::HashMap;
6
+
use std::time::Duration;
7
+
use thiserror::Error;
8
+
9
+
#[derive(Debug, Deserialize)]
10
+
struct MiniDoc {
11
+
signing_key: String,
12
+
did: String,
13
+
}
14
+
15
+
#[derive(Error, Debug)]
16
+
pub enum VerifyError {
17
+
#[error("The cross-service authorization token failed verification: {0}")]
18
+
VerificationFailed(&'static str),
19
+
#[error("Error trying to resolve the DID to a signing key, retry in a moment: {0}")]
20
+
ResolutionFailed(&'static str),
21
+
}
22
+
23
+
pub struct TokenVerifier {
24
+
client: reqwest::Client,
25
+
}
26
+
27
+
impl TokenVerifier {
28
+
pub fn new() -> Self {
29
+
let client = reqwest::Client::builder()
30
+
.user_agent(format!(
31
+
"microcosm pocket v{} (dev: @bad-example.com)",
32
+
env!("CARGO_PKG_VERSION")
33
+
))
34
+
.no_proxy()
35
+
.timeout(Duration::from_secs(12)) // slingshot timeout is 10s
36
+
.build()
37
+
.unwrap();
38
+
Self { client }
39
+
}
40
+
41
+
pub async fn verify(
42
+
&self,
43
+
expected_lxm: &str,
44
+
token: &str,
45
+
) -> Result<(String, String), VerifyError> {
46
+
let untrusted = UntrustedToken::new(token).unwrap();
47
+
48
+
// danger! unfortunately we need to decode the DID from the jwt body before we have a public key to verify the jwt with
49
+
let Ok(untrusted_claims) =
50
+
untrusted.deserialize_claims_unchecked::<HashMap<String, String>>()
51
+
else {
52
+
return Err(VerifyError::VerificationFailed(
53
+
"could not deserialize jtw claims",
54
+
));
55
+
};
56
+
57
+
// get the (untrusted!) claimed DID
58
+
let Some(untrusted_did) = untrusted_claims.custom.get("iss") else {
59
+
return Err(VerifyError::VerificationFailed(
60
+
"jwt must include the user's did in `iss`",
61
+
));
62
+
};
63
+
64
+
// bail if it's not even a user-ish did
65
+
if !untrusted_did.starts_with("did:") {
66
+
return Err(VerifyError::VerificationFailed("iss should be a did"));
67
+
}
68
+
if untrusted_did.contains("#") {
69
+
return Err(VerifyError::VerificationFailed(
70
+
"iss should be a user did without a service identifier",
71
+
));
72
+
}
73
+
74
+
let endpoint =
75
+
"https://slingshot.microcosm.blue/xrpc/com.bad-example.identity.resolveMiniDoc";
76
+
let doc: MiniDoc = self
77
+
.client
78
+
.get(format!("{endpoint}?identifier={untrusted_did}"))
79
+
.send()
80
+
.await
81
+
.map_err(|_| VerifyError::ResolutionFailed("failed to fetch minidoc"))?
82
+
.error_for_status()
83
+
.map_err(|_| VerifyError::ResolutionFailed("non-ok response for minidoc"))?
84
+
.json()
85
+
.await
86
+
.map_err(|_| VerifyError::ResolutionFailed("failed to parse json to minidoc"))?;
87
+
88
+
// sanity check before we go ahead with this signing key
89
+
if doc.did != *untrusted_did {
90
+
return Err(VerifyError::VerificationFailed(
91
+
"wtf, resolveMiniDoc returned a doc for a different DID, slingshot bug",
92
+
));
93
+
}
94
+
95
+
let Ok((alg, public_key)) = parse_multikey(&doc.signing_key) else {
96
+
return Err(VerifyError::VerificationFailed(
97
+
"could not parse signing key form minidoc",
98
+
));
99
+
};
100
+
101
+
// i _guess_ we've successfully bootstrapped the verification of the jwt unless this fails
102
+
if let Err(e) = Verifier::default().verify(
103
+
alg,
104
+
&public_key,
105
+
&untrusted.signed_data,
106
+
untrusted.signature_bytes(),
107
+
) {
108
+
log::warn!("jwt verification failed: {e}");
109
+
return Err(VerifyError::VerificationFailed(
110
+
"jwt signature verification failed",
111
+
));
112
+
}
113
+
114
+
// past this point we're should have established trust. crossing ts and dotting is.
115
+
let did = &untrusted_did;
116
+
let claims = &untrusted_claims;
117
+
118
+
let Some(aud) = claims.custom.get("aud") else {
119
+
return Err(VerifyError::VerificationFailed("missing aud"));
120
+
};
121
+
let Some(mut aud) = aud.strip_prefix("did:web:") else {
122
+
return Err(VerifyError::VerificationFailed("expected a did:web aud"));
123
+
};
124
+
if let Some((aud_without_hash, _)) = aud.split_once("#") {
125
+
log::warn!("aud claim is missing service id fragment: {aud:?}");
126
+
aud = aud_without_hash;
127
+
}
128
+
let Some(lxm) = claims.custom.get("lxm") else {
129
+
return Err(VerifyError::VerificationFailed("missing lxm"));
130
+
};
131
+
if lxm != expected_lxm {
132
+
return Err(VerifyError::VerificationFailed("wrong lxm"));
133
+
}
134
+
135
+
Ok((did.to_string(), aud.to_string()))
136
+
}
137
+
}
138
+
139
+
impl Default for TokenVerifier {
140
+
fn default() -> Self {
141
+
Self::new()
142
+
}
143
+
}
+67
pocket/static/index.html
+67
pocket/static/index.html
···
1
+
<!doctype html>
2
+
<html lang="en">
3
+
<head>
4
+
<meta charset="utf-8" />
5
+
<title>Pocket: atproto user preference storage</title>
6
+
<meta name="viewport" content="width=device-width, initial-scale=1" />
7
+
<meta name="description" content="API Documentation for Pocket, a simple user-preference storage system for atproto" />
8
+
<style>
9
+
:root {
10
+
--scalar-small: 13px;
11
+
}
12
+
.scalar-app .markdown .markdown-alert {
13
+
font-size: var(--scalar-small);
14
+
}
15
+
.sidebar-heading-link-title {
16
+
line-height: 1.2;
17
+
}
18
+
.custom-header {
19
+
height: 42px;
20
+
background-color: #221828;
21
+
box-shadow: inset 0 -1px 0 var(--scalar-border-color);
22
+
color: var(--scalar-color-1);
23
+
font-size: var(--scalar-font-size-3);
24
+
font-family: 'Iowan Old Style', 'Palatino Linotype', 'URW Palladio L', P052, serif;
25
+
padding: 0 18px;
26
+
justify-content: space-between;
27
+
}
28
+
.custom-header,
29
+
.custom-header nav {
30
+
display: flex;
31
+
align-items: center;
32
+
gap: 18px;
33
+
}
34
+
.custom-header a:hover {
35
+
color: var(--scalar-color-2);
36
+
}
37
+
38
+
.light-mode .custom-header {
39
+
background-color: thistle;
40
+
}
41
+
</style>
42
+
</head>
43
+
<body>
44
+
<header class="custom-header scalar-app">
45
+
<p>
46
+
TODO: thing
47
+
</p>
48
+
<nav>
49
+
<b>a <a href="https://microcosm.blue">microcosm</a> project</b>
50
+
<a href="https://bsky.app/profile/microcosm.blue">@microcosm.blue</a>
51
+
<a href="https://github.com/at-microcosm">github</a>
52
+
</nav>
53
+
</header>
54
+
55
+
<script id="api-reference" type="application/json" data-url="/openapi"></script>
56
+
57
+
<script>
58
+
var configuration = {
59
+
theme: 'purple',
60
+
hideModels: true,
61
+
}
62
+
document.getElementById('api-reference').dataset.configuration = JSON.stringify(configuration)
63
+
</script>
64
+
65
+
<script src="https://cdn.jsdelivr.net/npm/@scalar/api-reference"></script>
66
+
</body>
67
+
</html>
+8
quasar/Cargo.toml
+8
quasar/Cargo.toml
+3
quasar/readme.md
+3
quasar/readme.md
+57
-129
readme.md
+57
-129
readme.md
···
1
-
microcosm: links
2
-
================
3
-
4
-
this repo contains libraries and apps for working with cross-record references in at-protocol.
5
-
1
+
microcosm HTTP APIs + rust crates
2
+
=================================
3
+
[](https://bsky.app/profile/microcosm.blue)
4
+
[](https://discord.gg/tcDfe4PGVB)
5
+
[](https://github.com/sponsors/uniphil/)
6
+
[](https://ko-fi.com/bad_example)
6
7
7
-
App: [Constellation](./constellation/)
8
-
--------------------------------------------
8
+
Welcome! Documentation is under active development. If you like reading API docs, you'll probably hit the ground running!
9
9
10
-
A global atproto backlink index ✨
10
+
Tutorials, how-to guides, and client SDK libraries are all in the works for gentler on-ramps, but are not quite ready yet. But don't let that stop you! Hop in the [microcosm discord](https://discord.gg/tcDfe4PGVB), or post questions and tag [@bad-example.com](https://bsky.app/profile/bad-example.com) on Bluesky if you get stuck anywhere.
11
11
12
-
- Self hostable: handles the full write throughput of the global atproto firehose on a raspberry pi 4b + single SSD
13
-
- Storage efficient: less than 2GB/day disk consumption indexing all references in all lexicons and all non-atproto URLs
14
-
- Handles record deletion, account de/re-activation, and account deletion, ensuring accurate link counts and respecting users data choices
15
-
- Simple JSON API
12
+
> [!tip]
13
+
> This repository's primary home is moving to tangled: [@microcosm.blue/microcosm-rs](https://tangled.sh/@microcosm.blue/microcosm-rs). It will continue to be mirrored on [github](https://github.com/at-microcosm/microcosm-rs) for the forseeable future, and it's fine to open issues or pulls in either place!
16
14
17
-
All social interactions in atproto tend to be represented by links (or references) between PDS records. This index can answer questions like "how many likes does a bsky post have", "who follows an account", "what are all the comments on a [frontpage](https://frontpage.fyi/) post", and more.
18
15
19
-
- **status**: works! api is unstable and likely to change, and no known instances have a full network backfill yet.
20
-
- source: [./constellation/](./constellation/)
21
-
- public instance: [constellation.microcosm.blue](https://constellation.microcosm.blue/)
22
-
23
-
_note: the public instance currently runs on a little raspberry pi in my house, feel free to use it! it comes with only with best-effort uptime, no commitment to not breaking the api for now, and possible rate-limiting. if you want to be nice you can put your project name and bsky username (or email) in your user-agent header for api requests._
24
-
25
-
26
-
App: Spacedust
27
-
--------------
28
-
29
-
A notification subscription service 💫
30
-
31
-
using the same "link source" concept as [constellation](./constellation/), offer webhook notifications for new references created to records
32
-
33
-
- **status**: in design
34
-
35
-
36
-
Library: [links](./links/)
16
+
🌌 [Constellation](./constellation/)
37
17
------------------------------------
38
18
39
-
A rust crate (not published on crates.io yet) for optimistically parsing links out of arbitrary atproto PDS records, and potentially canonicalizing them
40
-
41
-
- **status**: unstable, might remain an internal lib for constellation (and spacedust, soon)
42
-
43
-
44
-
45
-
---
46
-
47
-
48
-
old notes follow, ignore
49
-
------------------------
50
-
51
-
52
-
as far as i can tell, atproto lexicons today don't follow much of a convention for referencing across documents: sometimes it's a StrongRef, sometimes it's a DID, sometimes it's a bare at-uri. lexicon authors choose any old link-sounding key name for the key in their document.
53
-
54
-
it's pretty messy so embrace the mess: atproto wants to be part of the web, so this library will also extract URLs and other URIs if you want it to. all the links.
55
-
56
-
57
-
why
58
-
---
59
-
60
-
the atproto firehose that bluesky sprays at you will contain raw _contents_ from peoples' pdses. these are isolated, decontextualized updates. it's very easy to build some kinds of interesting downstream apps off of this feed.
61
-
62
-
- bluesky posts (firesky, deletions, )
63
-
- blueksy post stats (emojis, )
64
-
- trending keywords ()
65
-
66
-
but bringing almost kind of _context_ into your project requires a big step up in complexity and potentially cost: you're entering "appview" territory. _how many likes does a post have? who follows this account?_
67
-
68
-
you own your atproto data: it's kept in your personal data repository (PDS) and noone else can write to it. when someone likes your post, they create a "like" record in their _own_ pds, and that like belongs to _them_, not to you/your post.
69
-
70
-
in the firehose you'll see a `app.bsky.feed.post` record created, with no details about who has liked it. then you'll see separate `app.bsky.feed.like` records show up for each like that comes in on that post, with no context about the post except a random-looking reference to it. storing these in order to do so is up to you!
71
-
72
-
**so, why**
73
-
74
-
everything is links, and they're a mess, but they all kinda work the same, so maybe some tooling can bring down that big step in complexity from firehose raw-content apps -> apps requiring any social context.
75
-
76
-
everything is links:
77
-
78
-
- likes
79
-
- follows
80
-
- blocks
81
-
- reposts
82
-
- quotes
83
-
84
-
some low-level things you could make from links:
85
-
86
-
- notification streams (part of ucosm)
87
-
- a global reverse index (part of ucosm)
88
-
89
-
i think that making these low-level services as easy to use as jetstream could open up pathways for building more atproto apps that operate at full scale with interesting features for reasonable effort at low cost to operate.
19
+
A global atproto interactions backlink index as a simple JSON API. Works with every lexicon, runs on a raspberry pi, consumes less than 2GiB of disk per day. Handles record deletion, account de/re-activation, and account deletion, ensuring accurate link counts while respecting users' data choices.
90
20
21
+
- Source: [./constellation/](./constellation/)
22
+
- [Public instance/API docs](https://constellation.microcosm.blue/)
23
+
- Status: used in production. APIs will change but backwards compatibility will be maintained as long as needed.
91
24
92
-
extracting links
93
-
---------------
94
25
26
+
🎇 [Spacedust](./spacedust/)
27
+
----------------------------
95
28
96
-
- low-level: pass a &str of a field value and get a parsed link back
29
+
A global atproto interactions firehose. Extracts all at-uris, DIDs, and URLs from every lexicon in the firehose, and exposes them over a websocket modelled after [jetstream](github.com/bluesky-social/jetstream).
97
30
98
-
- med-level: pass a &str of record in json form and get a list of parsed links + json paths back. (todo: should also handle dag-cbor prob?)
31
+
- Source: [./spacedust/](./spacedust/)
32
+
- [Public instance/API docs](https://spacedust.microcosm.blue/)
33
+
- Status: v0: the basics work and the APIs are in place! missing cursor replay, forward link storage, and delete event link hydration.
99
34
100
-
- high-ish level: pass the json record and maybe apply some pre-loaded rules based on known lexicons to get the best result.
35
+
### Demos:
101
36
102
-
for now, a link is only considered if it matches for the entire value of the record's field -- links embedded in text content are not included. note that urls in bluesky posts _will_ still be extracted, since they are broken out into facets.
37
+
- [Spacedust notifications](https://notifications.microcosm.blue/): web push notifications for _every_ atproto app
38
+
- [Zero-Bluesky real-time interaction-updating post embed](https://bsky.bad-example.com/zero-bluesky-realtime-embed/)
103
39
104
40
105
-
resolving / canonicalizing links
106
-
--------------------------------
41
+
🛰️ [Slingshot](./slingshot)
42
+
---------------------------
107
43
44
+
A fast, eager, production-grade edge cache for atproto records and identities. Pre-caches all records from the firehose and maintains a longer-term cache of requested records on disk.
108
45
109
-
### at-uris
46
+
- Source: [./slingshot/](./slingshot/)
47
+
- [Public instance/API docs](https://slingshot.microcosm.blue/)
48
+
- Status: v0: most XRPC APIs are working. cache storage is being reworked.
110
49
111
-
every at-uri has at least two equivalent forms, one with a `DID`, and one with an account handle. the at-uri spec [illustrates this by example](https://atproto.com/specs/at-uri-scheme):
112
50
113
-
- `at://did:plc:44ybard66vv44zksje25o7dz/app.bsky.feed.post/3jwdwj2ctlk26`
114
-
- `at://bnewbold.bsky.team/app.bsky.feed.post/3jwdwj2ctlk26`
51
+
🛸 [UFOs API](./ufos)
52
+
---------------------
115
53
116
-
some applications, like a reverse link index, may wish to canonicalize at-uris to a single form. the `DID`-form is stable as an account changes its handle and probably the right choice to canonicalize to, but maybe some apps would actually perfer to canonicalise to handles?
54
+
Timeseries stats and sample records for every [collection](https://atproto.com/guides/glossary#collection) ever seen in the atproto firehose. Unique users are counted in hyperloglog sketches enabling arbitrary cardinality aggregation across time buckets and/or NSIDs.
117
55
118
-
hopefully atrium will make it easy to resolve at-uris.
56
+
- Source: [./ufos/](./ufos/)
57
+
- [Public instance/API docs](https://ufos-api.microcosm.blue/)
58
+
- Status: Used in production. It has APIs and they work! Needs improvement on indexing; needs more indexes and some more APIs to the data exposed.
119
59
60
+
> [!tip]
61
+
> See also: [UFOs atproto explorer](https://ufos.microcosm.blue/) built on UFOs API. ([source](github.com/at-microcosm/spacedust-utils))
120
62
121
-
### urls
122
63
123
-
canonicalizing URLs is more annoying but also a bit more established. lots of details.
64
+
💫 [Links](./links)
65
+
-------------------
124
66
125
-
- do we have to deal with punycode?
126
-
- follow redirects (todo: only permanent ones, or all?)
127
-
- check for rel=canonical http header and possibly follow it
128
-
- check link rel=canonical meta tag and possibly follow it
129
-
- do we need to check site maps??
130
-
- do we have to care at all about AMP?
131
-
- do we want anything to do with url shorteners??
132
-
- how do multilingual sites affect this?
133
-
- do we have to care about `script type="application/ld+json"` ???
67
+
Rust library for parsing and extracting links (at-uris, DIDs, and URLs) from atproto records.
134
68
135
-
ugh. is there a crate for this.
69
+
- Source: [./links/](./links/)
70
+
- Status: not yet published to crates.io; needs some rework
136
71
137
72
138
-
### relative uris?
139
-
140
-
links might be relative, in which case they might need to be made absolute before being useful. is that a concern for this library, or up to the user? (seems like we might not have context here to determine its absolute)
141
-
142
-
143
-
### canonicalizing
144
-
145
-
there should be a few async functions available to canonicalize already-parsed links.
146
-
147
-
- what happens if a link can't be resolved?
73
+
🛩️ [Jetstream](./jetstream)
74
+
---------------------------
148
75
76
+
A low-overhead jetstream client with cursor handling and automatic reconnect.
149
77
150
-
---
78
+
- Source: [./links/](./links/)
79
+
- Status: used in multiple apps in production, but not yet published to crates.io; some rework planned
151
80
152
-
- using `tinyjson` because it's nice -- maybe should switch to serde_json to share deps with atrium?
81
+
> [!tip]
82
+
> See also: [Rocketman](https://github.com/teal-fm/cadet/tree/main/rocketman), another excellent rust jetstream client which shares some lineage and _is_ published on crates.io.
153
83
154
-
- would use atrium for parsing at-uris, but it's not in there. there's a did-only version in the non-lib commands.rs. its identifier parser is strict to did + handle, which makes sense, but for our purposes we might want to allow unknown methods too?
155
84
156
-
- rsky-syntax has an aturi
157
-
- adenosyne also
158
-
- might come back to these
159
85
86
+
🔭 Deprecated: [Who am I](./who-am-i)
87
+
-------------------------------------
160
88
161
-
-------
89
+
An identity bridge for microcosm demos, that kinda worked. Fixing its problems is about equivalent to reinventing a lot of OIDC, so it's being retired.
162
90
163
-
rocks
91
+
- Source: [./who-am-i/](./who-am-i/)
92
+
- Status: ready for retirement.
164
93
165
-
```bash
166
-
ROCKSDB_LIB_DIR=/nix/store/z2chn0hsik0clridr8mlprx1cngh1g3c-rocksdb-9.7.3/lib/ cargo build
167
-
```
94
+
> [!warning]
95
+
> `who-am-i` is still in use for the Spacedust Notifications demo, but that will hopefully be migrated to use atproto oauth directly instead.
+12
reflector/Cargo.toml
+12
reflector/Cargo.toml
···
1
+
[package]
2
+
name = "reflector"
3
+
version = "0.1.0"
4
+
edition = "2024"
5
+
6
+
[dependencies]
7
+
clap = { version = "4.5.47", features = ["derive"] }
8
+
log = "0.4.28"
9
+
poem = "3.1.12"
10
+
serde = { version = "1.0.219", features = ["derive"] }
11
+
tokio = "1.47.1"
12
+
tracing-subscriber = { version = "0.3.20", features = ["env-filter"] }
+9
reflector/readme.md
+9
reflector/readme.md
···
1
+
# reflector
2
+
3
+
a tiny did:web service server that maps subdomains to a single service endpoint
4
+
5
+
receiving requests from multiple subdomains is left as a problem for the reverse proxy to solve, since acme wildcard certificates (ie. letsencrypt) require the most complicated and involved challenge type (DNS).
6
+
7
+
caddy [has good support for](https://caddyserver.com/docs/caddyfile/patterns#wildcard-certificates) configuring the wildcard DNS challenge with various DNS providers, and also supports [on-demand](https://caddyserver.com/docs/automatic-https#using-on-demand-tls) provisioning via the simpler methods.
8
+
9
+
if you only need a small fixed number of subdomains, you can also use certbot or otherwise individually configure them in your reverse proxy.
+112
reflector/src/main.rs
+112
reflector/src/main.rs
···
1
+
use clap::Parser;
2
+
use poem::{
3
+
EndpointExt, Response, Route, Server, get, handler,
4
+
http::StatusCode,
5
+
listener::TcpListener,
6
+
middleware::{AddData, Tracing},
7
+
web::{Data, Json, Query, TypedHeader, headers::Host},
8
+
};
9
+
use serde::{Deserialize, Serialize};
10
+
11
+
#[handler]
12
+
fn hello() -> String {
13
+
"ɹoʇɔǝʅⅎǝɹ".to_string()
14
+
}
15
+
16
+
#[derive(Debug, Serialize)]
17
+
struct DidDoc {
18
+
id: String,
19
+
service: [DidService; 1],
20
+
}
21
+
22
+
#[derive(Debug, Clone, Serialize)]
23
+
#[serde(rename_all = "camelCase")]
24
+
struct DidService {
25
+
id: String,
26
+
r#type: String,
27
+
service_endpoint: String,
28
+
}
29
+
30
+
#[handler]
31
+
fn did_doc(TypedHeader(host): TypedHeader<Host>, service: Data<&DidService>) -> Json<DidDoc> {
32
+
Json(DidDoc {
33
+
id: format!("did:web:{}", host.hostname()),
34
+
service: [service.clone()],
35
+
})
36
+
}
37
+
38
+
#[derive(Deserialize)]
39
+
struct AskQuery {
40
+
domain: String,
41
+
}
42
+
#[handler]
43
+
fn ask_caddy(
44
+
Data(parent): Data<&Option<String>>,
45
+
Query(AskQuery { domain }): Query<AskQuery>,
46
+
) -> Response {
47
+
if let Some(parent) = parent
48
+
&& let Some(prefix) = domain.strip_suffix(&format!(".{parent}"))
49
+
&& !prefix.contains('.')
50
+
{
51
+
// no sub-sub-domains allowed
52
+
return Response::builder().body("ok");
53
+
};
54
+
Response::builder()
55
+
.status(StatusCode::FORBIDDEN)
56
+
.body("nope")
57
+
}
58
+
59
+
/// Slingshot record edge cache
60
+
#[derive(Parser, Debug, Clone)]
61
+
#[command(version, about, long_about = None)]
62
+
struct Args {
63
+
/// The DID document service ID to serve
64
+
///
65
+
/// must start with a '#', like `#bsky_appview'
66
+
#[arg(long)]
67
+
id: String,
68
+
/// Service type
69
+
///
70
+
/// Not sure exactly what its requirements are. 'BlueskyAppview' for example
71
+
#[arg(long)]
72
+
r#type: String,
73
+
/// The HTTPS endpoint for the service
74
+
#[arg(long)]
75
+
service_endpoint: String,
76
+
/// The parent domain; requests should come from subdomains of this
77
+
#[arg(long)]
78
+
domain: Option<String>,
79
+
}
80
+
81
+
impl From<Args> for DidService {
82
+
fn from(a: Args) -> Self {
83
+
Self {
84
+
id: a.id,
85
+
r#type: a.r#type,
86
+
service_endpoint: a.service_endpoint,
87
+
}
88
+
}
89
+
}
90
+
91
+
#[tokio::main(flavor = "current_thread")]
92
+
async fn main() {
93
+
tracing_subscriber::fmt::init();
94
+
log::info!("ɹoʇɔǝʅⅎǝɹ");
95
+
96
+
let args = Args::parse();
97
+
let domain = args.domain.clone();
98
+
let service: DidService = args.into();
99
+
100
+
Server::new(TcpListener::bind("0.0.0.0:3001"))
101
+
.run(
102
+
Route::new()
103
+
.at("/", get(hello))
104
+
.at("/.well-known/did.json", get(did_doc))
105
+
.at("/ask", get(ask_caddy))
106
+
.with(AddData::new(service))
107
+
.with(AddData::new(domain))
108
+
.with(Tracing),
109
+
)
110
+
.await
111
+
.unwrap()
112
+
}
+1
slingshot/.gitignore
+1
slingshot/.gitignore
···
1
+
foyer
+31
slingshot/Cargo.toml
+31
slingshot/Cargo.toml
···
1
+
[package]
2
+
name = "slingshot"
3
+
version = "0.1.0"
4
+
edition = "2024"
5
+
6
+
[dependencies]
7
+
atrium-api = { git = "https://github.com/uniphil/atrium.git", branch = "fix/resolve-handle-https-accept-whitespace", default-features = false }
8
+
atrium-common = { git = "https://github.com/uniphil/atrium.git", branch = "fix/resolve-handle-https-accept-whitespace" }
9
+
atrium-identity = { git = "https://github.com/uniphil/atrium.git", branch = "fix/resolve-handle-https-accept-whitespace" }
10
+
atrium-oauth = { git = "https://github.com/uniphil/atrium.git", branch = "fix/resolve-handle-https-accept-whitespace" }
11
+
clap = { version = "4.5.41", features = ["derive"] }
12
+
ctrlc = "3.4.7"
13
+
foyer = { version = "0.18.0", features = ["serde"] }
14
+
hickory-resolver = "0.25.2"
15
+
jetstream = { path = "../jetstream", features = ["metrics"] }
16
+
links = { path = "../links" }
17
+
log = "0.4.27"
18
+
metrics = "0.24.2"
19
+
metrics-exporter-prometheus = { version = "0.17.1", features = ["http-listener"] }
20
+
poem = { version = "3.1.12", features = ["acme", "static-files"] }
21
+
poem-openapi = { version = "5.1.16", features = ["scalar"] }
22
+
reqwest = { version = "0.12.22", features = ["json"] }
23
+
rustls = "0.23.31"
24
+
serde = { version = "1.0.219", features = ["derive"] }
25
+
serde_json = { version = "1.0.141", features = ["raw_value"] }
26
+
thiserror = "2.0.12"
27
+
time = { version = "0.3.41", features = ["serde"] }
28
+
tokio = { version = "1.47.0", features = ["full"] }
29
+
tokio-util = "0.7.15"
30
+
tracing-subscriber = { version = "0.3.19", features = ["env-filter"] }
31
+
url = "2.5.4"
+93
slingshot/api-description.md
+93
slingshot/api-description.md
···
1
+
_A [gravitational slingshot](https://en.wikipedia.org/wiki/Gravity_assist) makes use of the gravity and relative movements of celestial bodies to accelerate a spacecraft and change its trajectory._
2
+
3
+
4
+
# Slingshot: edge record cache
5
+
6
+
Applications in [ATProtocol](https://atproto.com/) store data in users' own [PDS](https://atproto.com/guides/self-hosting) (Personal Data Server), which are distributed across thousands of independently-run servers all over the world. Trying to access this data poses challenges for client applications:
7
+
8
+
- A PDS might be far away with long network latency
9
+
- or may be on an unreliable connection
10
+
- or overloaded when you need it, or offline, or…
11
+
12
+
Large projects like [Bluesky](https://bsky.app/) control their performance and reliability by syncing all app-relevant data from PDSs into first-party databases. But for new apps, building out this additional data infrastructure adds significant effort and complexity up front.
13
+
14
+
**Slingshot is a fast, eager, production-grade cache of data in the [ATmosphere](https://atproto.com/)**, offering performance and reliability without custom infrastructure.
15
+
16
+
17
+
### Current status
18
+
19
+
> [!important]
20
+
> Slingshot is currently in a **v0, pre-release state**. There is one production instance and you can use it! Expect short downtimes for restarts as development progresses and lower cache hit-rates as the internal storage caches are adjusted and reset.
21
+
22
+
The core APIs will not change, since they are standard third-party `com.atproto` query APIs from ATProtocol.
23
+
24
+
25
+
## Eager caching
26
+
27
+
In many cases, Slingshot can cache the data you need *before* first request!
28
+
29
+
Slingshot subscribes to the global [Firehose](https://atproto.com/specs/sync#firehose) of data updates. It keeps a short-term rolling indexed window of *all* data, and automatically promotes content likely to be requested to its longer-term main cache. _(automatic promotion is still a work in progress)_
30
+
31
+
When there is a cache miss, Slingshot can often still accelerate record fetching, since it keeps a large cache of resolved identities: it can usually request from the correct PDS without extra lookups.
32
+
33
+
34
+
## Precise invalidation
35
+
36
+
The fireshose includes **update** and **delete** events, which Slingshot uses to ensure stale and deleted data is removed within a very short window. Additonally, identity and account-level events can trigger rapid cleanup of data for deactivated and deleted accounts. _(some of this is still a work in progress)_
37
+
38
+
39
+
## Low-trust
40
+
41
+
The "AT" in ATProtocol [stands for _Authenticated Transfer_](https://atproto.com/guides/glossary#at-protocol): all data is cryptographically signed, which makes it possible to broadcast data through third parties and trust that it's real _without_ having to directly contact the originating server.
42
+
43
+
Two core standard query APIs are supported to balance convenience and trust. They both fetch [records](https://atproto.com/guides/glossary#record):
44
+
45
+
### [`com.atproto.repo.getRecord`](#tag/comatproto-queries/get/xrpc/com.atproto.repo.getRecord)
46
+
47
+
- convenient `JSON` response format
48
+
- cannot be proven authentic
49
+
50
+
### [`com.atproto.sync.getRecord`](#tag/comatproto-queries/get/xrpc/com.atproto.sync.getRecord)
51
+
52
+
- [`DAG-CBOR`](https://atproto.com/specs/data-model)-encoded response requires extra libraries to decode, but
53
+
- includes a cryptographic proof of authenticity!
54
+
55
+
_(work on this endpoint is in progress)_
56
+
57
+
58
+
## Service proxying
59
+
60
+
Clients can proxy atproto queries through their own PDS with [Service Proxying](https://atproto.com/specs/xrpc#service-proxying), and this is supported by Slingshot. The Slingshot instance must be started the `--domain` argument specified.
61
+
62
+
Service-proxied requests can specify a Slingshot instance via the `atproto-proxy` header:
63
+
64
+
```http
65
+
GET /xrpc/com.bad-example.identity.resolveMiniDoc?identifier=bad-example.com
66
+
Host: <your pds>
67
+
atproto-proxy: did:web:<slingshot domain>#slingshot
68
+
```
69
+
70
+
Where `<your pds>` is the user's own PDS host, and `<slingshot domain>` is the domain that the slingshot instance is deployed at (eg. `slingshot.microcosm.blue`). See the [Service Proxying](https://atproto.com/specs/xrpc#service-proxying) docs for more.
71
+
72
+
> [!tip]
73
+
> Service proxying is supported but completely optional. All APIs are directly accessible over the public internet, and GeoDNS helps route users to the closest instance to them for the lowest possible latency. (_note: deploying multiple slingshot instances with GeoDNS is still TODO_)
74
+
75
+
76
+
## Ergonomic APIs
77
+
78
+
- Slingshot also offers variants of the `getRecord` endpoints that accept a full `at-uri` as a parameter, to save clients from needing to parse and validate all parts of a record location.
79
+
80
+
- Bi-directionally verifying identity endpoints, so you can directly exchange atproto [`handle`](https://atproto.com/guides/glossary#handle)s for [`DID`](https://atproto.com/guides/glossary#did-decentralized-id)s without extra steps, plus a convenient [Mini-Doc](#tag/slingshot-specific-queries/get/xrpc/com.bad-example.identity.resolveMiniDoc) verified identity summary.
81
+
82
+
83
+
## Part of microcosm
84
+
85
+
[Microcosm](https://www.microcosm.blue/) is a collection of services and independent community-run infrastructure for ATProtocol.
86
+
87
+
Slingshot excels when combined with _shallow indexing_ services, which offer fast queries of global data relationships but with only references to the data records. Microcosm has a few!
88
+
89
+
- [🌌 Constellation](https://constellation.microcosm.blue/), a global backlink index (all social interactions in atproto are links!)
90
+
- [🎇 Spacedust](https://spacedust.microcosm.blue/), a firehose of all social interactions
91
+
92
+
> [!success]
93
+
> All microcosm projects are [open source](https://tangled.sh/@bad-example.com/microcosm-links). **You can help sustain Slingshot** and all of microcosm by becoming a [Github sponsor](https://github.com/sponsors/uniphil/) or a [Ko-fi supporter](https://ko-fi.com/bad_example)!
+7
slingshot/readme.md
+7
slingshot/readme.md
+80
slingshot/src/consumer.rs
+80
slingshot/src/consumer.rs
···
1
+
use crate::CachedRecord;
2
+
use crate::error::ConsumerError;
3
+
use foyer::HybridCache;
4
+
use jetstream::{
5
+
DefaultJetstreamEndpoints, JetstreamCompression, JetstreamConfig, JetstreamConnector,
6
+
events::{CommitOp, Cursor, EventKind},
7
+
};
8
+
use tokio_util::sync::CancellationToken;
9
+
10
+
pub async fn consume(
11
+
jetstream_endpoint: String,
12
+
cursor: Option<Cursor>,
13
+
no_zstd: bool,
14
+
shutdown: CancellationToken,
15
+
cache: HybridCache<String, CachedRecord>,
16
+
) -> Result<(), ConsumerError> {
17
+
let endpoint = DefaultJetstreamEndpoints::endpoint_or_shortcut(&jetstream_endpoint);
18
+
if endpoint == jetstream_endpoint {
19
+
log::info!("consumer: connecting jetstream at {endpoint}");
20
+
} else {
21
+
log::info!("consumer: connecting jetstream at {jetstream_endpoint} => {endpoint}");
22
+
}
23
+
let config: JetstreamConfig = JetstreamConfig {
24
+
endpoint,
25
+
compression: if no_zstd {
26
+
JetstreamCompression::None
27
+
} else {
28
+
JetstreamCompression::Zstd
29
+
},
30
+
replay_on_reconnect: true,
31
+
channel_size: 1024, // buffer up to ~1s of jetstream events
32
+
..Default::default()
33
+
};
34
+
let mut receiver = JetstreamConnector::new(config)?
35
+
.connect_cursor(cursor)
36
+
.await?;
37
+
38
+
log::info!("consumer: receiving messages..");
39
+
loop {
40
+
if shutdown.is_cancelled() {
41
+
log::info!("consumer: exiting for shutdown");
42
+
return Ok(());
43
+
}
44
+
let Some(mut event) = receiver.recv().await else {
45
+
log::error!("consumer: could not receive event, bailing");
46
+
break;
47
+
};
48
+
49
+
if event.kind != EventKind::Commit {
50
+
continue;
51
+
}
52
+
let Some(ref mut commit) = event.commit else {
53
+
log::warn!("consumer: commit event missing commit data, ignoring");
54
+
continue;
55
+
};
56
+
57
+
// TODO: something a bit more robust
58
+
let at_uri = format!(
59
+
"at://{}/{}/{}",
60
+
&*event.did, &*commit.collection, &*commit.rkey
61
+
);
62
+
63
+
if commit.operation == CommitOp::Delete {
64
+
cache.insert(at_uri, CachedRecord::Deleted);
65
+
} else {
66
+
let Some(record) = commit.record.take() else {
67
+
log::warn!("consumer: commit insert or update missing record, ignoring");
68
+
continue;
69
+
};
70
+
let Some(cid) = commit.cid.take() else {
71
+
log::warn!("consumer: commit insert or update missing CID, ignoring");
72
+
continue;
73
+
};
74
+
75
+
cache.insert(at_uri, CachedRecord::Found((cid, record).into()));
76
+
}
77
+
}
78
+
79
+
Err(ConsumerError::JetstreamEnded)
80
+
}
+93
slingshot/src/error.rs
+93
slingshot/src/error.rs
···
1
+
use crate::ErrorResponseObject;
2
+
use thiserror::Error;
3
+
4
+
#[derive(Debug, Error)]
5
+
pub enum ConsumerError {
6
+
#[error(transparent)]
7
+
JetstreamConnectionError(#[from] jetstream::error::ConnectionError),
8
+
#[error(transparent)]
9
+
JetstreamConfigValidationError(#[from] jetstream::error::ConfigValidationError),
10
+
#[error("jetstream ended")]
11
+
JetstreamEnded,
12
+
#[error("delay queue output dropped")]
13
+
DelayQueueOutputDropped,
14
+
}
15
+
16
+
#[derive(Debug, Error)]
17
+
pub enum ServerError {
18
+
#[error("server build error: {0}")]
19
+
AcmeBuildError(std::io::Error),
20
+
#[error("server exited: {0}")]
21
+
ServerExited(std::io::Error),
22
+
}
23
+
24
+
#[derive(Debug, Error)]
25
+
pub enum IdentityError {
26
+
#[error("whatever: {0}")]
27
+
WhateverError(String),
28
+
#[error("bad DID: {0}")]
29
+
BadDid(&'static str),
30
+
#[error("identity types got mixed up: {0}")]
31
+
IdentityValTypeMixup(String),
32
+
#[error("foyer error: {0}")]
33
+
FoyerError(#[from] foyer::Error),
34
+
35
+
#[error("failed to resolve: {0}")]
36
+
ResolutionFailed(#[from] atrium_identity::Error),
37
+
// #[error("identity resolved but no handle found for user")]
38
+
// NoHandle,
39
+
#[error("found handle {0:?} but it appears invalid: {1}")]
40
+
InvalidHandle(String, &'static str),
41
+
42
+
#[error("could not convert atrium did doc to partial mini doc: {0}")]
43
+
BadDidDoc(String),
44
+
45
+
#[error("wrong key for clearing refresh queue: {0}")]
46
+
RefreshQueueKeyError(&'static str),
47
+
}
48
+
49
+
#[derive(Debug, Error)]
50
+
pub enum HealthCheckError {
51
+
#[error("failed to send checkin: {0}")]
52
+
HealthCheckError(#[from] reqwest::Error),
53
+
}
54
+
55
+
#[derive(Debug, Error)]
56
+
pub enum MainTaskError {
57
+
#[error(transparent)]
58
+
ConsumerTaskError(#[from] ConsumerError),
59
+
#[error(transparent)]
60
+
ServerTaskError(#[from] ServerError),
61
+
#[error(transparent)]
62
+
IdentityTaskError(#[from] IdentityError),
63
+
#[error(transparent)]
64
+
HealthCheckError(#[from] HealthCheckError),
65
+
#[error("firehose cache failed to close: {0}")]
66
+
FirehoseCacheCloseError(foyer::Error),
67
+
}
68
+
69
+
#[derive(Debug, Error)]
70
+
pub enum RecordError {
71
+
#[error("identity error: {0}")]
72
+
IdentityError(#[from] IdentityError),
73
+
#[error("repo could not be validated as either a DID or an atproto handle")]
74
+
BadRepo,
75
+
#[error("could not get record: {0}")]
76
+
NotFound(&'static str),
77
+
#[error("could nto parse pds url: {0}")]
78
+
UrlParseError(#[from] url::ParseError),
79
+
#[error("reqwest send failed: {0}")]
80
+
SendError(reqwest::Error),
81
+
#[error("reqwest raised for status: {0}")]
82
+
StatusError(reqwest::Error),
83
+
#[error("reqwest failed to parse json: {0}")]
84
+
ParseJsonError(reqwest::Error),
85
+
#[error("upstream getRecord did not include a CID")]
86
+
MissingUpstreamCid,
87
+
#[error("upstream CID was not valid: {0}")]
88
+
BadUpstreamCid(String),
89
+
#[error("upstream atproto-looking bad request")]
90
+
UpstreamBadRequest(ErrorResponseObject),
91
+
#[error("upstream non-atproto bad request")]
92
+
UpstreamBadBadNotGoodRequest(reqwest::Error),
93
+
}
+24
slingshot/src/firehose_cache.rs
+24
slingshot/src/firehose_cache.rs
···
1
+
use crate::CachedRecord;
2
+
use foyer::{DirectFsDeviceOptions, Engine, HybridCache, HybridCacheBuilder};
3
+
use std::path::Path;
4
+
5
+
pub async fn firehose_cache(
6
+
cache_dir: impl AsRef<Path>,
7
+
memory_mb: usize,
8
+
disk_gb: usize,
9
+
) -> Result<HybridCache<String, CachedRecord>, String> {
10
+
let cache = HybridCacheBuilder::new()
11
+
.with_name("firehose")
12
+
.memory(memory_mb * 2_usize.pow(20))
13
+
.with_weighter(|k: &String, v| k.len() + std::mem::size_of_val(v))
14
+
.storage(Engine::large())
15
+
.with_device_options(
16
+
DirectFsDeviceOptions::new(cache_dir)
17
+
.with_capacity(disk_gb * 2_usize.pow(30))
18
+
.with_file_size(16 * 2_usize.pow(20)), // note: this does limit the max cached item size, warning jumbo records
19
+
)
20
+
.build()
21
+
.await
22
+
.map_err(|e| format!("foyer setup error: {e:?}"))?;
23
+
Ok(cache)
24
+
}
+32
slingshot/src/healthcheck.rs
+32
slingshot/src/healthcheck.rs
···
1
+
use crate::error::HealthCheckError;
2
+
use reqwest::Client;
3
+
use std::time::Duration;
4
+
use tokio::time::sleep;
5
+
use tokio_util::sync::CancellationToken;
6
+
7
+
pub async fn healthcheck(
8
+
endpoint: String,
9
+
shutdown: CancellationToken,
10
+
) -> Result<(), HealthCheckError> {
11
+
let client = Client::builder()
12
+
.user_agent(format!(
13
+
"microcosm slingshot v{} (dev: @bad-example.com)",
14
+
env!("CARGO_PKG_VERSION")
15
+
))
16
+
.no_proxy()
17
+
.timeout(Duration::from_secs(10))
18
+
.build()?;
19
+
20
+
loop {
21
+
tokio::select! {
22
+
res = client.get(&endpoint).send() => {
23
+
let _ = res
24
+
.and_then(|r| r.error_for_status())
25
+
.inspect_err(|e| log::error!("failed to send healthcheck: {e}"));
26
+
},
27
+
_ = shutdown.cancelled() => break,
28
+
}
29
+
sleep(Duration::from_secs(51)).await;
30
+
}
31
+
Ok(())
32
+
}
+525
slingshot/src/identity.rs
+525
slingshot/src/identity.rs
···
1
+
use hickory_resolver::{ResolveError, TokioResolver};
2
+
use std::collections::{HashSet, VecDeque};
3
+
use std::path::Path;
4
+
use std::sync::Arc;
5
+
/// for now we're gonna just keep doing more cache
6
+
///
7
+
/// plc.director x foyer, ttl kept with data, refresh deferred to background on fetch
8
+
///
9
+
/// things we need:
10
+
///
11
+
/// 1. handle -> DID resolution: getRecord must accept a handle for `repo` param
12
+
/// 2. DID -> PDS resolution: so we know where to getRecord
13
+
/// 3. DID -> handle resolution: for bidirectional handle validation and in case we want to offer this
14
+
use std::time::Duration;
15
+
use tokio::sync::Mutex;
16
+
use tokio_util::sync::CancellationToken;
17
+
18
+
use crate::error::IdentityError;
19
+
use atrium_api::{
20
+
did_doc::DidDocument,
21
+
types::string::{Did, Handle},
22
+
};
23
+
use atrium_common::resolver::Resolver;
24
+
use atrium_identity::{
25
+
did::{CommonDidResolver, CommonDidResolverConfig, DEFAULT_PLC_DIRECTORY_URL},
26
+
handle::{AtprotoHandleResolver, AtprotoHandleResolverConfig, DnsTxtResolver},
27
+
};
28
+
use atrium_oauth::DefaultHttpClient; // it's probably not worth bringing all of atrium_oauth for this but
29
+
use foyer::{DirectFsDeviceOptions, Engine, HybridCache, HybridCacheBuilder};
30
+
use serde::{Deserialize, Serialize};
31
+
use time::UtcDateTime;
32
+
33
+
/// once we have something resolved, don't re-resolve until after this period
34
+
const MIN_TTL: Duration = Duration::from_secs(4 * 3600); // probably shoudl have a max ttl
35
+
const MIN_NOT_FOUND_TTL: Duration = Duration::from_secs(60);
36
+
37
+
#[derive(Debug, Clone, Hash, PartialEq, Eq, Serialize, Deserialize)]
38
+
enum IdentityKey {
39
+
Handle(Handle),
40
+
Did(Did),
41
+
}
42
+
43
+
#[derive(Debug, Serialize, Deserialize)]
44
+
struct IdentityVal(UtcDateTime, IdentityData);
45
+
46
+
#[derive(Debug, Serialize, Deserialize)]
47
+
enum IdentityData {
48
+
NotFound,
49
+
Did(Did),
50
+
Doc(PartialMiniDoc),
51
+
}
52
+
53
+
/// partial representation of a com.bad-example.identity mini atproto doc
54
+
///
55
+
/// partial because the handle is not verified
56
+
#[derive(Debug, Clone, Serialize, Deserialize)]
57
+
pub struct PartialMiniDoc {
58
+
/// an atproto handle (**unverified**)
59
+
///
60
+
/// the first valid atproto handle from the did doc's aka
61
+
pub unverified_handle: Handle,
62
+
/// the did's atproto pds url (TODO: type this?)
63
+
///
64
+
/// note: atrium *does* actually parse it into a URI, it just doesn't return
65
+
/// that for some reason
66
+
pub pds: String,
67
+
/// for now we're just pulling this straight from the did doc
68
+
///
69
+
/// would be nice to type and validate it
70
+
///
71
+
/// this is the publicKeyMultibase from the did doc.
72
+
/// legacy key encoding not supported.
73
+
/// `id`, `type`, and `controller` must be checked, but aren't stored.
74
+
pub signing_key: String,
75
+
}
76
+
77
+
impl TryFrom<DidDocument> for PartialMiniDoc {
78
+
type Error = String;
79
+
fn try_from(did_doc: DidDocument) -> Result<Self, Self::Error> {
80
+
// must use the first valid handle
81
+
let mut unverified_handle = None;
82
+
let Some(ref doc_akas) = did_doc.also_known_as else {
83
+
return Err("did doc missing `also_known_as`".to_string());
84
+
};
85
+
for aka in doc_akas {
86
+
let Some(maybe_handle) = aka.strip_prefix("at://") else {
87
+
continue;
88
+
};
89
+
let Ok(valid_handle) = Handle::new(maybe_handle.to_string()) else {
90
+
continue;
91
+
};
92
+
unverified_handle = Some(valid_handle);
93
+
break;
94
+
}
95
+
let Some(unverified_handle) = unverified_handle else {
96
+
return Err("no valid atproto handles in `also_known_as`".to_string());
97
+
};
98
+
99
+
// atrium seems to get service endpoint getters
100
+
let Some(pds) = did_doc.get_pds_endpoint() else {
101
+
return Err("no valid pds service found".to_string());
102
+
};
103
+
104
+
// TODO can't use atrium's get_signing_key() becuase it fails to check type and controller
105
+
// so if we check those and reject it, we might miss a later valid key in the array
106
+
// (todo is to fix atrium)
107
+
// actually: atrium might be flexible for legacy reps. for now we're rejecting legacy rep.
108
+
109
+
// must use the first valid signing key
110
+
let mut signing_key = None;
111
+
let Some(verification_methods) = did_doc.verification_method else {
112
+
return Err("no verification methods found".to_string());
113
+
};
114
+
for method in verification_methods {
115
+
if method.id != format!("{}#atproto", did_doc.id) {
116
+
continue;
117
+
}
118
+
if method.r#type != "Multikey" {
119
+
continue;
120
+
}
121
+
if method.controller != did_doc.id {
122
+
continue;
123
+
}
124
+
let Some(key) = method.public_key_multibase else {
125
+
continue;
126
+
};
127
+
signing_key = Some(key);
128
+
break;
129
+
}
130
+
let Some(signing_key) = signing_key else {
131
+
return Err("no valid atproto signing key found in verification methods".to_string());
132
+
};
133
+
134
+
Ok(PartialMiniDoc {
135
+
unverified_handle,
136
+
pds,
137
+
signing_key,
138
+
})
139
+
}
140
+
}
141
+
142
+
/// multi-producer *single-consumer* queue structures (wrap in arc-mutex plz)
143
+
///
144
+
/// the hashset allows testing for presense of items in the queue.
145
+
/// this has absolutely no support for multiple queue consumers.
146
+
#[derive(Debug, Default)]
147
+
struct RefreshQueue {
148
+
queue: VecDeque<IdentityKey>,
149
+
items: HashSet<IdentityKey>,
150
+
}
151
+
152
+
#[derive(Clone)]
153
+
pub struct Identity {
154
+
handle_resolver: Arc<AtprotoHandleResolver<HickoryDnsTxtResolver, DefaultHttpClient>>,
155
+
did_resolver: Arc<CommonDidResolver<DefaultHttpClient>>,
156
+
cache: HybridCache<IdentityKey, IdentityVal>,
157
+
/// multi-producer *single consumer* queue
158
+
refresh_queue: Arc<Mutex<RefreshQueue>>,
159
+
/// just a lock to ensure only one refresher (queue consumer) is running (to be improved with a better refresher)
160
+
refresher: Arc<Mutex<()>>,
161
+
}
162
+
163
+
impl Identity {
164
+
pub async fn new(cache_dir: impl AsRef<Path>) -> Result<Self, IdentityError> {
165
+
let http_client = Arc::new(DefaultHttpClient::default());
166
+
let handle_resolver = AtprotoHandleResolver::new(AtprotoHandleResolverConfig {
167
+
dns_txt_resolver: HickoryDnsTxtResolver::new().unwrap(),
168
+
http_client: http_client.clone(),
169
+
});
170
+
let did_resolver = CommonDidResolver::new(CommonDidResolverConfig {
171
+
plc_directory_url: DEFAULT_PLC_DIRECTORY_URL.to_string(),
172
+
http_client: http_client.clone(),
173
+
});
174
+
175
+
let cache = HybridCacheBuilder::new()
176
+
.with_name("identity")
177
+
.memory(16 * 2_usize.pow(20))
178
+
.with_weighter(|k, v| std::mem::size_of_val(k) + std::mem::size_of_val(v))
179
+
.storage(Engine::small())
180
+
.with_device_options(
181
+
DirectFsDeviceOptions::new(cache_dir)
182
+
.with_capacity(2_usize.pow(30)) // TODO: configurable (1GB to have something)
183
+
.with_file_size(2_usize.pow(20)), // note: this does limit the max cached item size, warning jumbo records
184
+
)
185
+
.build()
186
+
.await?;
187
+
188
+
Ok(Self {
189
+
handle_resolver: Arc::new(handle_resolver),
190
+
did_resolver: Arc::new(did_resolver),
191
+
cache,
192
+
refresh_queue: Default::default(),
193
+
refresher: Default::default(),
194
+
})
195
+
}
196
+
197
+
/// Resolve (and verify!) an atproto handle to a DID
198
+
///
199
+
/// The result can be stale
200
+
///
201
+
/// `None` if the handle can't be found or verification fails
202
+
pub async fn handle_to_did(&self, handle: Handle) -> Result<Option<Did>, IdentityError> {
203
+
let Some(did) = self.handle_to_unverified_did(&handle).await? else {
204
+
return Ok(None);
205
+
};
206
+
let Some(doc) = self.did_to_partial_mini_doc(&did).await? else {
207
+
return Ok(None);
208
+
};
209
+
if doc.unverified_handle != handle {
210
+
return Ok(None);
211
+
}
212
+
Ok(Some(did))
213
+
}
214
+
215
+
/// Resolve a DID to a pds url
216
+
///
217
+
/// This *also* incidentally resolves and verifies the handle, which might
218
+
/// make it slower than expected
219
+
pub async fn did_to_pds(&self, did: Did) -> Result<Option<String>, IdentityError> {
220
+
let Some(mini_doc) = self.did_to_partial_mini_doc(&did).await? else {
221
+
return Ok(None);
222
+
};
223
+
Ok(Some(mini_doc.pds))
224
+
}
225
+
226
+
/// Resolve (and cache but **not verify**) a handle to a DID
227
+
async fn handle_to_unverified_did(
228
+
&self,
229
+
handle: &Handle,
230
+
) -> Result<Option<Did>, IdentityError> {
231
+
let key = IdentityKey::Handle(handle.clone());
232
+
let entry = self
233
+
.cache
234
+
.fetch(key.clone(), {
235
+
let handle = handle.clone();
236
+
let resolver = self.handle_resolver.clone();
237
+
|| async move {
238
+
match resolver.resolve(&handle).await {
239
+
Ok(did) => Ok(IdentityVal(UtcDateTime::now(), IdentityData::Did(did))),
240
+
Err(atrium_identity::Error::NotFound) => {
241
+
Ok(IdentityVal(UtcDateTime::now(), IdentityData::NotFound))
242
+
}
243
+
Err(other) => Err(foyer::Error::Other(Box::new({
244
+
log::debug!("other error resolving handle: {other:?}");
245
+
IdentityError::ResolutionFailed(other)
246
+
}))),
247
+
}
248
+
}
249
+
})
250
+
.await?;
251
+
252
+
let now = UtcDateTime::now();
253
+
let IdentityVal(last_fetch, data) = entry.value();
254
+
match data {
255
+
IdentityData::Doc(_) => {
256
+
log::error!("identity value mixup: got a doc from a handle key (should be a did)");
257
+
Err(IdentityError::IdentityValTypeMixup(handle.to_string()))
258
+
}
259
+
IdentityData::NotFound => {
260
+
if (now - *last_fetch) >= MIN_NOT_FOUND_TTL {
261
+
self.queue_refresh(key).await;
262
+
}
263
+
Ok(None)
264
+
}
265
+
IdentityData::Did(did) => {
266
+
if (now - *last_fetch) >= MIN_TTL {
267
+
self.queue_refresh(key).await;
268
+
}
269
+
Ok(Some(did.clone()))
270
+
}
271
+
}
272
+
}
273
+
274
+
/// Fetch (and cache) a partial mini doc from a did
275
+
pub async fn did_to_partial_mini_doc(
276
+
&self,
277
+
did: &Did,
278
+
) -> Result<Option<PartialMiniDoc>, IdentityError> {
279
+
let key = IdentityKey::Did(did.clone());
280
+
let entry = self
281
+
.cache
282
+
.fetch(key.clone(), {
283
+
let did = did.clone();
284
+
let resolver = self.did_resolver.clone();
285
+
|| async move {
286
+
match resolver.resolve(&did).await {
287
+
Ok(did_doc) => {
288
+
// TODO: fix in atrium: should verify id is did
289
+
if did_doc.id != did.to_string() {
290
+
return Err(foyer::Error::other(Box::new(
291
+
IdentityError::BadDidDoc(
292
+
"did doc's id did not match did".to_string(),
293
+
),
294
+
)));
295
+
}
296
+
let mini_doc = did_doc.try_into().map_err(|e| {
297
+
foyer::Error::Other(Box::new(IdentityError::BadDidDoc(e)))
298
+
})?;
299
+
Ok(IdentityVal(UtcDateTime::now(), IdentityData::Doc(mini_doc)))
300
+
}
301
+
Err(atrium_identity::Error::NotFound) => {
302
+
Ok(IdentityVal(UtcDateTime::now(), IdentityData::NotFound))
303
+
}
304
+
Err(other) => Err(foyer::Error::Other(Box::new(
305
+
IdentityError::ResolutionFailed(other),
306
+
))),
307
+
}
308
+
}
309
+
})
310
+
.await?;
311
+
312
+
let now = UtcDateTime::now();
313
+
let IdentityVal(last_fetch, data) = entry.value();
314
+
match data {
315
+
IdentityData::Did(_) => {
316
+
log::error!("identity value mixup: got a did from a did key (should be a doc)");
317
+
Err(IdentityError::IdentityValTypeMixup(did.to_string()))
318
+
}
319
+
IdentityData::NotFound => {
320
+
if (now - *last_fetch) >= MIN_NOT_FOUND_TTL {
321
+
self.queue_refresh(key).await;
322
+
}
323
+
Ok(None)
324
+
}
325
+
IdentityData::Doc(mini_did) => {
326
+
if (now - *last_fetch) >= MIN_TTL {
327
+
self.queue_refresh(key).await;
328
+
}
329
+
Ok(Some(mini_did.clone()))
330
+
}
331
+
}
332
+
}
333
+
334
+
/// put a refresh task on the queue
335
+
///
336
+
/// this can be safely called from multiple concurrent tasks
337
+
async fn queue_refresh(&self, key: IdentityKey) {
338
+
// todo: max queue size
339
+
let mut q = self.refresh_queue.lock().await;
340
+
if !q.items.contains(&key) {
341
+
q.items.insert(key.clone());
342
+
q.queue.push_back(key);
343
+
}
344
+
}
345
+
346
+
/// find out what's next in the queue. concurrent consumers are not allowed.
347
+
///
348
+
/// intent is to leave the item in the queue while refreshing, so that a
349
+
/// producer will not re-add it if it's in progress. there's definitely
350
+
/// better ways to do this, but this is ~simple for as far as a single
351
+
/// consumer can take us.
352
+
///
353
+
/// we could take it from the queue but leave it in the set and remove from
354
+
/// set later, but splitting them apart feels more bug-prone.
355
+
async fn peek_refresh(&self) -> Option<IdentityKey> {
356
+
let q = self.refresh_queue.lock().await;
357
+
q.queue.front().cloned()
358
+
}
359
+
360
+
/// call to clear the latest key from the refresh queue. concurrent consumers not allowed.
361
+
///
362
+
/// must provide the last peeked refresh queue item as a small safety check
363
+
async fn complete_refresh(&self, key: &IdentityKey) -> Result<(), IdentityError> {
364
+
let mut q = self.refresh_queue.lock().await;
365
+
366
+
let Some(queue_key) = q.queue.pop_front() else {
367
+
// gone from queue + since we're in an error condition, make sure it's not stuck in items
368
+
// (not toctou because we have the lock)
369
+
// bolder here than below and removing from items because if the queue is *empty*, then we
370
+
// know it hasn't been re-added since losing sync.
371
+
if q.items.remove(key) {
372
+
log::error!("identity refresh: queue de-sync: not in ");
373
+
} else {
374
+
log::warn!(
375
+
"identity refresh: tried to complete with wrong key. are multiple queue consumers running?"
376
+
);
377
+
}
378
+
return Err(IdentityError::RefreshQueueKeyError("no key in queue"));
379
+
};
380
+
381
+
if queue_key != *key {
382
+
// extra weird case here, what's the most defensive behaviour?
383
+
// we have two keys: ours should have been first but isn't. this shouldn't happen, so let's
384
+
// just leave items alone for it. risks unbounded growth but we're in a bad place already.
385
+
// the other key is the one we just popped. we didn't want it, so maybe we should put it
386
+
// back, BUT if we somehow ended up with concurrent consumers, we have bigger problems. take
387
+
// responsibility for taking it instead: remove it from items as well, and just drop it.
388
+
//
389
+
// hope that whoever calls us takes this error seriously.
390
+
if q.items.remove(&queue_key) {
391
+
log::warn!(
392
+
"identity refresh: queue de-sync + dropping a bystander key without refreshing it!"
393
+
);
394
+
} else {
395
+
// you thought things couldn't get weirder? (i mean hopefully they can't)
396
+
log::error!("identity refresh: queue de-sync + bystander key also de-sync!?");
397
+
}
398
+
return Err(IdentityError::RefreshQueueKeyError(
399
+
"wrong key at front of queue",
400
+
));
401
+
}
402
+
403
+
if q.items.remove(key) {
404
+
Ok(())
405
+
} else {
406
+
log::error!("identity refresh: queue de-sync: key not in items");
407
+
Err(IdentityError::RefreshQueueKeyError("key not in items"))
408
+
}
409
+
}
410
+
411
+
/// run the refresh queue consumer
412
+
pub async fn run_refresher(&self, shutdown: CancellationToken) -> Result<(), IdentityError> {
413
+
let _guard = self
414
+
.refresher
415
+
.try_lock()
416
+
.expect("there to only be one refresher running");
417
+
loop {
418
+
if shutdown.is_cancelled() {
419
+
log::info!("identity refresher: exiting for shutdown: closing cache...");
420
+
if let Err(e) = self.cache.close().await {
421
+
log::error!("cache close errored: {e}");
422
+
} else {
423
+
log::info!("identity cache closed.")
424
+
}
425
+
return Ok(());
426
+
}
427
+
let Some(task_key) = self.peek_refresh().await else {
428
+
tokio::time::sleep(tokio::time::Duration::from_millis(100)).await;
429
+
continue;
430
+
};
431
+
match task_key {
432
+
IdentityKey::Handle(ref handle) => {
433
+
log::trace!("refreshing handle {handle:?}");
434
+
match self.handle_resolver.resolve(handle).await {
435
+
Ok(did) => {
436
+
self.cache.insert(
437
+
task_key.clone(),
438
+
IdentityVal(UtcDateTime::now(), IdentityData::Did(did)),
439
+
);
440
+
}
441
+
Err(atrium_identity::Error::NotFound) => {
442
+
self.cache.insert(
443
+
task_key.clone(),
444
+
IdentityVal(UtcDateTime::now(), IdentityData::NotFound),
445
+
);
446
+
}
447
+
Err(err) => {
448
+
log::warn!(
449
+
"failed to refresh handle: {err:?}. leaving stale (should we eventually do something?)"
450
+
);
451
+
}
452
+
}
453
+
self.complete_refresh(&task_key).await?; // failures are bugs, so break loop
454
+
}
455
+
IdentityKey::Did(ref did) => {
456
+
log::trace!("refreshing did doc: {did:?}");
457
+
458
+
match self.did_resolver.resolve(did).await {
459
+
Ok(did_doc) => {
460
+
// TODO: fix in atrium: should verify id is did
461
+
if did_doc.id != did.to_string() {
462
+
log::warn!(
463
+
"refreshed did doc failed: wrong did doc id. dropping refresh."
464
+
);
465
+
continue;
466
+
}
467
+
let mini_doc = match did_doc.try_into() {
468
+
Ok(md) => md,
469
+
Err(e) => {
470
+
log::warn!(
471
+
"converting mini doc failed: {e:?}. dropping refresh."
472
+
);
473
+
continue;
474
+
}
475
+
};
476
+
self.cache.insert(
477
+
task_key.clone(),
478
+
IdentityVal(UtcDateTime::now(), IdentityData::Doc(mini_doc)),
479
+
);
480
+
}
481
+
Err(atrium_identity::Error::NotFound) => {
482
+
self.cache.insert(
483
+
task_key.clone(),
484
+
IdentityVal(UtcDateTime::now(), IdentityData::NotFound),
485
+
);
486
+
}
487
+
Err(err) => {
488
+
log::warn!(
489
+
"failed to refresh did doc: {err:?}. leaving stale (should we eventually do something?)"
490
+
);
491
+
}
492
+
}
493
+
494
+
self.complete_refresh(&task_key).await?; // failures are bugs, so break loop
495
+
}
496
+
}
497
+
}
498
+
}
499
+
}
500
+
501
+
pub struct HickoryDnsTxtResolver(TokioResolver);
502
+
503
+
impl HickoryDnsTxtResolver {
504
+
fn new() -> Result<Self, ResolveError> {
505
+
Ok(Self(TokioResolver::builder_tokio()?.build()))
506
+
}
507
+
}
508
+
509
+
impl DnsTxtResolver for HickoryDnsTxtResolver {
510
+
async fn resolve(
511
+
&self,
512
+
query: &str,
513
+
) -> core::result::Result<Vec<String>, Box<dyn std::error::Error + Send + Sync>> {
514
+
match self.0.txt_lookup(query).await {
515
+
Ok(r) => {
516
+
metrics::counter!("whoami_resolve_dns_txt", "success" => "true").increment(1);
517
+
Ok(r.iter().map(|r| r.to_string()).collect())
518
+
}
519
+
Err(e) => {
520
+
metrics::counter!("whoami_resolve_dns_txt", "success" => "false").increment(1);
521
+
Err(e.into())
522
+
}
523
+
}
524
+
}
525
+
}
+14
slingshot/src/lib.rs
+14
slingshot/src/lib.rs
···
1
+
mod consumer;
2
+
pub mod error;
3
+
mod firehose_cache;
4
+
mod healthcheck;
5
+
mod identity;
6
+
mod record;
7
+
mod server;
8
+
9
+
pub use consumer::consume;
10
+
pub use firehose_cache::firehose_cache;
11
+
pub use healthcheck::healthcheck;
12
+
pub use identity::Identity;
13
+
pub use record::{CachedRecord, ErrorResponseObject, Repo};
14
+
pub use server::serve;
+215
slingshot/src/main.rs
+215
slingshot/src/main.rs
···
1
+
// use foyer::HybridCache;
2
+
// use foyer::{Engine, DirectFsDeviceOptions, HybridCacheBuilder};
3
+
use metrics_exporter_prometheus::PrometheusBuilder;
4
+
use slingshot::{
5
+
Identity, Repo, consume, error::MainTaskError, firehose_cache, healthcheck, serve,
6
+
};
7
+
use std::path::PathBuf;
8
+
9
+
use clap::Parser;
10
+
use tokio_util::sync::CancellationToken;
11
+
12
+
/// Slingshot record edge cache
13
+
#[derive(Parser, Debug, Clone)]
14
+
#[command(version, about, long_about = None)]
15
+
struct Args {
16
+
/// Jetstream server to connect to (exclusive with --fixture). Provide either a wss:// URL, or a shorhand value:
17
+
/// 'us-east-1', 'us-east-2', 'us-west-1', or 'us-west-2'
18
+
#[arg(long)]
19
+
jetstream: String,
20
+
/// don't request zstd-compressed jetstream events
21
+
///
22
+
/// reduces CPU at the expense of more ingress bandwidth
23
+
#[arg(long, action)]
24
+
jetstream_no_zstd: bool,
25
+
/// where to keep disk caches
26
+
#[arg(long)]
27
+
cache_dir: PathBuf,
28
+
/// memory cache size in MB
29
+
#[arg(long, default_value_t = 64)]
30
+
cache_memory_mb: usize,
31
+
/// disk cache size in GB
32
+
#[arg(long, default_value_t = 1)]
33
+
cache_disk_gb: usize,
34
+
/// host for HTTP server (when not using --domain)
35
+
#[arg(long, default_value = "127.0.0.1")]
36
+
host: String,
37
+
/// port for HTTP server (when not using --domain)
38
+
#[arg(long, default_value_t = 3000)]
39
+
port: u16,
40
+
/// port for metrics/prometheus server
41
+
#[arg(long, default_value_t = 8765)]
42
+
metrics_port: u16,
43
+
/// the domain pointing to this server
44
+
///
45
+
/// if present:
46
+
/// - a did:web document will be served at /.well-known/did.json
47
+
/// - an HTTPS certs will be automatically configured with Acme/letsencrypt
48
+
/// - TODO: a rate-limiter will be installed
49
+
#[arg(long)]
50
+
domain: Option<String>,
51
+
/// email address for letsencrypt contact
52
+
///
53
+
/// recommended in production, i guess?
54
+
#[arg(long)]
55
+
acme_contact: Option<String>,
56
+
/// a location to cache acme https certs
57
+
///
58
+
/// only used if --host is specified. omitting requires re-requesting certs
59
+
/// on every restart, and letsencrypt has rate limits that are easy to hit.
60
+
///
61
+
/// recommended in production, but mind the file permissions.
62
+
#[arg(long)]
63
+
certs: Option<PathBuf>,
64
+
/// an web address to send healtcheck pings to every ~51s or so
65
+
#[arg(long)]
66
+
healthcheck: Option<String>,
67
+
}
68
+
69
+
#[tokio::main]
70
+
async fn main() -> Result<(), String> {
71
+
tracing_subscriber::fmt::init();
72
+
73
+
let shutdown = CancellationToken::new();
74
+
75
+
let ctrlc_shutdown = shutdown.clone();
76
+
ctrlc::set_handler(move || ctrlc_shutdown.cancel()).expect("failed to set ctrl-c handler");
77
+
78
+
let args = Args::parse();
79
+
80
+
if let Err(e) = install_metrics_server(args.metrics_port) {
81
+
log::error!("failed to install metrics server: {e:?}");
82
+
} else {
83
+
log::info!("metrics listening at http://0.0.0.0:{}", args.metrics_port);
84
+
}
85
+
86
+
std::fs::create_dir_all(&args.cache_dir).map_err(|e| {
87
+
format!(
88
+
"failed to ensure cache parent dir: {e:?} (dir: {:?})",
89
+
args.cache_dir
90
+
)
91
+
})?;
92
+
let cache_dir = args.cache_dir.canonicalize().map_err(|e| {
93
+
format!(
94
+
"failed to canonicalize cache_dir: {e:?} (dir: {:?})",
95
+
args.cache_dir
96
+
)
97
+
})?;
98
+
log::info!("cache dir ready at at {cache_dir:?}.");
99
+
100
+
log::info!("setting up firehose cache...");
101
+
let cache = firehose_cache(
102
+
cache_dir.join("./firehose"),
103
+
args.cache_memory_mb,
104
+
args.cache_disk_gb,
105
+
)
106
+
.await?;
107
+
log::info!("firehose cache ready.");
108
+
109
+
let mut tasks: tokio::task::JoinSet<Result<(), MainTaskError>> = tokio::task::JoinSet::new();
110
+
111
+
log::info!("starting identity service...");
112
+
let identity = Identity::new(cache_dir.join("./identity"))
113
+
.await
114
+
.map_err(|e| format!("identity setup failed: {e:?}"))?;
115
+
log::info!("identity service ready.");
116
+
let identity_refresher = identity.clone();
117
+
let identity_shutdown = shutdown.clone();
118
+
tasks.spawn(async move {
119
+
identity_refresher.run_refresher(identity_shutdown).await?;
120
+
Ok(())
121
+
});
122
+
123
+
let repo = Repo::new(identity.clone());
124
+
125
+
let server_shutdown = shutdown.clone();
126
+
let server_cache_handle = cache.clone();
127
+
tasks.spawn(async move {
128
+
serve(
129
+
server_cache_handle,
130
+
identity,
131
+
repo,
132
+
args.domain,
133
+
args.acme_contact,
134
+
args.certs,
135
+
args.host,
136
+
args.port,
137
+
server_shutdown,
138
+
)
139
+
.await?;
140
+
Ok(())
141
+
});
142
+
143
+
let consumer_shutdown = shutdown.clone();
144
+
let consumer_cache = cache.clone();
145
+
tasks.spawn(async move {
146
+
consume(
147
+
args.jetstream,
148
+
None,
149
+
args.jetstream_no_zstd,
150
+
consumer_shutdown,
151
+
consumer_cache,
152
+
)
153
+
.await?;
154
+
Ok(())
155
+
});
156
+
157
+
if let Some(hc) = args.healthcheck {
158
+
let healthcheck_shutdown = shutdown.clone();
159
+
tasks.spawn(async move {
160
+
healthcheck(hc, healthcheck_shutdown).await?;
161
+
Ok(())
162
+
});
163
+
}
164
+
165
+
tokio::select! {
166
+
_ = shutdown.cancelled() => log::warn!("shutdown requested"),
167
+
Some(r) = tasks.join_next() => {
168
+
log::warn!("a task exited, shutting down: {r:?}");
169
+
shutdown.cancel();
170
+
}
171
+
}
172
+
173
+
tasks.spawn(async move {
174
+
cache
175
+
.close()
176
+
.await
177
+
.map_err(MainTaskError::FirehoseCacheCloseError)
178
+
});
179
+
180
+
tokio::select! {
181
+
_ = async {
182
+
while let Some(completed) = tasks.join_next().await {
183
+
log::info!("shutdown: task completed: {completed:?}");
184
+
}
185
+
} => {},
186
+
_ = tokio::time::sleep(std::time::Duration::from_secs(30)) => {
187
+
log::info!("shutdown: not all tasks completed on time. aborting...");
188
+
tasks.shutdown().await;
189
+
},
190
+
}
191
+
192
+
log::info!("bye!");
193
+
194
+
Ok(())
195
+
}
196
+
197
+
fn install_metrics_server(port: u16) -> Result<(), metrics_exporter_prometheus::BuildError> {
198
+
log::info!("installing metrics server...");
199
+
let host = [0, 0, 0, 0];
200
+
PrometheusBuilder::new()
201
+
.set_quantiles(&[0.5, 0.9, 0.99, 1.0])?
202
+
.set_bucket_duration(std::time::Duration::from_secs(300))?
203
+
.set_bucket_count(std::num::NonZero::new(12).unwrap()) // count * duration = 60 mins. stuff doesn't happen that fast here.
204
+
.set_enable_unit_suffix(false) // this seemed buggy for constellation (sometimes wouldn't engage)
205
+
.with_http_listener((host, port))
206
+
.install()?;
207
+
log::info!(
208
+
"metrics server installed! listening on http://{}.{}.{}.{}:{port}",
209
+
host[0],
210
+
host[1],
211
+
host[2],
212
+
host[3]
213
+
);
214
+
Ok(())
215
+
}
+155
slingshot/src/record.rs
+155
slingshot/src/record.rs
···
1
+
//! cached record storage
2
+
3
+
use crate::{Identity, error::RecordError};
4
+
use atrium_api::types::string::{Cid, Did, Nsid, RecordKey};
5
+
use reqwest::{Client, StatusCode};
6
+
use serde::{Deserialize, Serialize};
7
+
use serde_json::value::RawValue;
8
+
use std::str::FromStr;
9
+
use std::time::Duration;
10
+
use url::Url;
11
+
12
+
#[derive(Debug, Serialize, Deserialize)]
13
+
pub struct RawRecord {
14
+
cid: Cid,
15
+
record: String,
16
+
}
17
+
18
+
// TODO: should be able to do typed CID
19
+
impl From<(Cid, Box<RawValue>)> for RawRecord {
20
+
fn from((cid, rv): (Cid, Box<RawValue>)) -> Self {
21
+
Self {
22
+
cid,
23
+
record: rv.get().to_string(),
24
+
}
25
+
}
26
+
}
27
+
28
+
/// only for use with stored (validated) values, not general strings
29
+
impl From<&RawRecord> for (Cid, Box<RawValue>) {
30
+
fn from(RawRecord { cid, record }: &RawRecord) -> Self {
31
+
(
32
+
cid.clone(),
33
+
RawValue::from_string(record.to_string())
34
+
.expect("stored string from RawValue to be valid"),
35
+
)
36
+
}
37
+
}
38
+
39
+
#[derive(Debug, Serialize, Deserialize)]
40
+
pub enum CachedRecord {
41
+
Found(RawRecord),
42
+
Deleted,
43
+
}
44
+
45
+
//////// upstream record fetching
46
+
47
+
#[derive(Deserialize)]
48
+
struct RecordResponseObject {
49
+
#[allow(dead_code)] // expect it to be there but we ignore it
50
+
uri: String,
51
+
/// CID for this exact version of the record
52
+
///
53
+
/// this is optional in the spec and that's potentially TODO for slingshot
54
+
cid: Option<String>,
55
+
/// the record itself as JSON
56
+
value: Box<RawValue>,
57
+
}
58
+
59
+
#[derive(Debug, Deserialize)]
60
+
pub struct ErrorResponseObject {
61
+
pub error: String,
62
+
pub message: String,
63
+
}
64
+
65
+
#[derive(Clone)]
66
+
pub struct Repo {
67
+
identity: Identity,
68
+
client: Client,
69
+
}
70
+
71
+
impl Repo {
72
+
pub fn new(identity: Identity) -> Self {
73
+
let client = Client::builder()
74
+
.user_agent(format!(
75
+
"microcosm slingshot v{} (dev: @bad-example.com)",
76
+
env!("CARGO_PKG_VERSION")
77
+
))
78
+
.no_proxy()
79
+
.timeout(Duration::from_secs(10))
80
+
.build()
81
+
.unwrap();
82
+
Repo { identity, client }
83
+
}
84
+
85
+
pub async fn get_record(
86
+
&self,
87
+
did: &Did,
88
+
collection: &Nsid,
89
+
rkey: &RecordKey,
90
+
cid: &Option<Cid>,
91
+
) -> Result<CachedRecord, RecordError> {
92
+
let Some(pds) = self.identity.did_to_pds(did.clone()).await? else {
93
+
return Err(RecordError::NotFound("could not get pds for DID"));
94
+
};
95
+
96
+
// cid gets set to None for a retry, if it's Some and we got NotFound
97
+
let mut cid = cid;
98
+
99
+
let res = loop {
100
+
// TODO: throttle outgoing requests by host probably, generally guard against outgoing requests
101
+
let mut params = vec![
102
+
("repo", did.to_string()),
103
+
("collection", collection.to_string()),
104
+
("rkey", rkey.to_string()),
105
+
];
106
+
if let Some(cid) = cid {
107
+
params.push(("cid", cid.as_ref().to_string()));
108
+
}
109
+
let mut url = Url::parse_with_params(&pds, ¶ms)?;
110
+
url.set_path("/xrpc/com.atproto.repo.getRecord");
111
+
112
+
let res = self
113
+
.client
114
+
.get(url.clone())
115
+
.send()
116
+
.await
117
+
.map_err(RecordError::SendError)?;
118
+
119
+
if res.status() == StatusCode::BAD_REQUEST {
120
+
// 1. if we're not able to parse json, it's not something we can handle
121
+
let err = res
122
+
.json::<ErrorResponseObject>()
123
+
.await
124
+
.map_err(RecordError::UpstreamBadBadNotGoodRequest)?;
125
+
// 2. if we are, is it a NotFound? and if so, did we try with a CID?
126
+
// if so, retry with no CID (api handler will reject for mismatch but
127
+
// with a nice error + warm cache)
128
+
if err.error == "NotFound" && cid.is_some() {
129
+
cid = &None;
130
+
continue;
131
+
} else {
132
+
return Err(RecordError::UpstreamBadRequest(err));
133
+
}
134
+
}
135
+
break res;
136
+
};
137
+
138
+
let data = res
139
+
.error_for_status()
140
+
.map_err(RecordError::StatusError)? // TODO atproto error handling (think about handling not found)
141
+
.json::<RecordResponseObject>()
142
+
.await
143
+
.map_err(RecordError::ParseJsonError)?; // todo...
144
+
145
+
let Some(cid) = data.cid else {
146
+
return Err(RecordError::MissingUpstreamCid);
147
+
};
148
+
let cid = Cid::from_str(&cid).map_err(|e| RecordError::BadUpstreamCid(e.to_string()))?;
149
+
150
+
Ok(CachedRecord::Found(RawRecord {
151
+
cid,
152
+
record: data.value.to_string(),
153
+
}))
154
+
}
155
+
}
+785
slingshot/src/server.rs
+785
slingshot/src/server.rs
···
1
+
use crate::{
2
+
CachedRecord, ErrorResponseObject, Identity, Repo,
3
+
error::{RecordError, ServerError},
4
+
};
5
+
use atrium_api::types::string::{Cid, Did, Handle, Nsid, RecordKey};
6
+
use foyer::HybridCache;
7
+
use links::at_uri::parse_at_uri as normalize_at_uri;
8
+
use serde::Serialize;
9
+
use std::path::PathBuf;
10
+
use std::str::FromStr;
11
+
use std::sync::Arc;
12
+
use tokio_util::sync::CancellationToken;
13
+
14
+
use poem::{
15
+
Endpoint, EndpointExt, Route, Server,
16
+
endpoint::{StaticFileEndpoint, make_sync},
17
+
http::Method,
18
+
listener::{
19
+
Listener, TcpListener,
20
+
acme::{AutoCert, LETS_ENCRYPT_PRODUCTION},
21
+
},
22
+
middleware::{CatchPanic, Cors, Tracing},
23
+
};
24
+
use poem_openapi::{
25
+
ApiResponse, ContactObject, ExternalDocumentObject, Object, OpenApi, OpenApiService, Tags,
26
+
param::Query, payload::Json, types::Example,
27
+
};
28
+
29
+
fn example_handle() -> String {
30
+
"bad-example.com".to_string()
31
+
}
32
+
fn example_did() -> String {
33
+
"did:plc:hdhoaan3xa3jiuq4fg4mefid".to_string()
34
+
}
35
+
fn example_collection() -> String {
36
+
"app.bsky.feed.like".to_string()
37
+
}
38
+
fn example_rkey() -> String {
39
+
"3lv4ouczo2b2a".to_string()
40
+
}
41
+
fn example_uri() -> String {
42
+
format!(
43
+
"at://{}/{}/{}",
44
+
example_did(),
45
+
example_collection(),
46
+
example_rkey()
47
+
)
48
+
}
49
+
fn example_pds() -> String {
50
+
"https://porcini.us-east.host.bsky.network".to_string()
51
+
}
52
+
fn example_signing_key() -> String {
53
+
"zQ3shpq1g134o7HGDb86CtQFxnHqzx5pZWknrVX2Waum3fF6j".to_string()
54
+
}
55
+
56
+
#[derive(Object)]
57
+
#[oai(example = true)]
58
+
struct XrpcErrorResponseObject {
59
+
/// Should correspond an error `name` in the lexicon errors array
60
+
error: String,
61
+
/// Human-readable description and possibly additonal context
62
+
message: String,
63
+
}
64
+
impl Example for XrpcErrorResponseObject {
65
+
fn example() -> Self {
66
+
Self {
67
+
error: "RecordNotFound".to_string(),
68
+
message: "This record was deleted".to_string(),
69
+
}
70
+
}
71
+
}
72
+
type XrpcError = Json<XrpcErrorResponseObject>;
73
+
fn xrpc_error(error: impl AsRef<str>, message: impl AsRef<str>) -> XrpcError {
74
+
Json(XrpcErrorResponseObject {
75
+
error: error.as_ref().to_string(),
76
+
message: message.as_ref().to_string(),
77
+
})
78
+
}
79
+
80
+
fn bad_request_handler_get_record(err: poem::Error) -> GetRecordResponse {
81
+
GetRecordResponse::BadRequest(Json(XrpcErrorResponseObject {
82
+
error: "InvalidRequest".to_string(),
83
+
message: format!("Bad request, here's some info that maybe should not be exposed: {err}"),
84
+
}))
85
+
}
86
+
87
+
fn bad_request_handler_resolve_mini(err: poem::Error) -> ResolveMiniIDResponse {
88
+
ResolveMiniIDResponse::BadRequest(Json(XrpcErrorResponseObject {
89
+
error: "InvalidRequest".to_string(),
90
+
message: format!("Bad request, here's some info that maybe should not be exposed: {err}"),
91
+
}))
92
+
}
93
+
94
+
fn bad_request_handler_resolve_handle(err: poem::Error) -> JustDidResponse {
95
+
JustDidResponse::BadRequest(Json(XrpcErrorResponseObject {
96
+
error: "InvalidRequest".to_string(),
97
+
message: format!("Bad request, here's some info that maybe should not be exposed: {err}"),
98
+
}))
99
+
}
100
+
101
+
#[derive(Object)]
102
+
#[oai(example = true)]
103
+
struct FoundRecordResponseObject {
104
+
/// at-uri for this record
105
+
uri: String,
106
+
/// CID for this exact version of the record
107
+
///
108
+
/// Slingshot will always return the CID, despite it not being a required
109
+
/// response property in the official lexicon.
110
+
///
111
+
/// TODO: probably actually let it be optional, idk are some pds's weirdly
112
+
/// not returning it?
113
+
cid: Option<String>,
114
+
/// the record itself as JSON
115
+
value: serde_json::Value,
116
+
}
117
+
impl Example for FoundRecordResponseObject {
118
+
fn example() -> Self {
119
+
Self {
120
+
uri: example_uri(),
121
+
cid: Some("bafyreialv3mzvvxaoyrfrwoer3xmabbmdchvrbyhayd7bga47qjbycy74e".to_string()),
122
+
value: serde_json::json!({
123
+
"$type": "app.bsky.feed.like",
124
+
"createdAt": "2025-07-29T18:02:02.327Z",
125
+
"subject": {
126
+
"cid": "bafyreia2gy6eyk5qfetgahvshpq35vtbwy6negpy3gnuulcdi723mi7vxy",
127
+
"uri": "at://did:plc:vwzwgnygau7ed7b7wt5ux7y2/app.bsky.feed.post/3lv4lkb4vgs2k"
128
+
}
129
+
}),
130
+
}
131
+
}
132
+
}
133
+
134
+
#[derive(ApiResponse)]
135
+
#[oai(bad_request_handler = "bad_request_handler_get_record")]
136
+
enum GetRecordResponse {
137
+
/// Record found
138
+
#[oai(status = 200)]
139
+
Ok(Json<FoundRecordResponseObject>),
140
+
/// Bad request or no record to return
141
+
///
142
+
/// The only error name in the repo.getRecord lexicon is `RecordNotFound`,
143
+
/// but the [canonical api docs](https://docs.bsky.app/docs/api/com-atproto-repo-get-record)
144
+
/// also list `InvalidRequest`, `ExpiredToken`, and `InvalidToken`. Of
145
+
/// these, slingshot will only generate `RecordNotFound` or `InvalidRequest`,
146
+
/// but may return any proxied error code from the upstream repo.
147
+
#[oai(status = 400)]
148
+
BadRequest(XrpcError),
149
+
/// Server errors
150
+
#[oai(status = 500)]
151
+
ServerError(XrpcError),
152
+
}
153
+
154
+
#[derive(Object)]
155
+
#[oai(example = true)]
156
+
struct MiniDocResponseObject {
157
+
/// DID, bi-directionally verified if a handle was provided in the query.
158
+
did: String,
159
+
/// The validated handle of the account or `handle.invalid` if the handle
160
+
/// did not bi-directionally match the DID document.
161
+
handle: String,
162
+
/// The identity's PDS URL
163
+
pds: String,
164
+
/// The atproto signing key publicKeyMultibase
165
+
///
166
+
/// Legacy key encoding not supported. the key is returned directly; `id`,
167
+
/// `type`, and `controller` are omitted.
168
+
signing_key: String,
169
+
}
170
+
impl Example for MiniDocResponseObject {
171
+
fn example() -> Self {
172
+
Self {
173
+
did: example_did(),
174
+
handle: example_handle(),
175
+
pds: example_pds(),
176
+
signing_key: example_signing_key(),
177
+
}
178
+
}
179
+
}
180
+
181
+
#[derive(ApiResponse)]
182
+
#[oai(bad_request_handler = "bad_request_handler_resolve_mini")]
183
+
enum ResolveMiniIDResponse {
184
+
/// Identity resolved
185
+
#[oai(status = 200)]
186
+
Ok(Json<MiniDocResponseObject>),
187
+
/// Bad request or identity not resolved
188
+
#[oai(status = 400)]
189
+
BadRequest(XrpcError),
190
+
}
191
+
192
+
#[derive(Object)]
193
+
#[oai(example = true)]
194
+
struct FoundDidResponseObject {
195
+
/// the DID, bi-directionally verified if using Slingshot
196
+
did: String,
197
+
}
198
+
impl Example for FoundDidResponseObject {
199
+
fn example() -> Self {
200
+
Self { did: example_did() }
201
+
}
202
+
}
203
+
204
+
#[derive(ApiResponse)]
205
+
#[oai(bad_request_handler = "bad_request_handler_resolve_handle")]
206
+
enum JustDidResponse {
207
+
/// Resolution succeeded
208
+
#[oai(status = 200)]
209
+
Ok(Json<FoundDidResponseObject>),
210
+
/// Bad request, failed to resolve, or failed to verify
211
+
///
212
+
/// `error` will be one of `InvalidRequest`, `HandleNotFound`.
213
+
#[oai(status = 400)]
214
+
BadRequest(XrpcError),
215
+
/// Something went wrong trying to complete the request
216
+
#[oai(status = 500)]
217
+
ServerError(XrpcError),
218
+
}
219
+
220
+
struct Xrpc {
221
+
cache: HybridCache<String, CachedRecord>,
222
+
identity: Identity,
223
+
repo: Arc<Repo>,
224
+
}
225
+
226
+
#[derive(Tags)]
227
+
enum ApiTags {
228
+
/// Core ATProtocol-compatible APIs.
229
+
///
230
+
/// > [!tip]
231
+
/// > Upstream documentation is available at
232
+
/// > https://docs.bsky.app/docs/category/http-reference
233
+
///
234
+
/// These queries are usually executed directly against the PDS containing
235
+
/// the data being requested. Slingshot offers a caching view of the same
236
+
/// contents with better expected performance and reliability.
237
+
#[oai(rename = "com.atproto.* queries")]
238
+
ComAtproto,
239
+
/// Additional and improved APIs.
240
+
///
241
+
/// These APIs offer small tweaks to the core ATProtocol APIs, with more
242
+
/// more convenient [request parameters](#tag/slingshot-specific-queries/GET/xrpc/com.bad-example.repo.getUriRecord)
243
+
/// or [response formats](#tag/slingshot-specific-queries/GET/xrpc/com.bad-example.identity.resolveMiniDoc).
244
+
///
245
+
/// > [!important]
246
+
/// > At the moment, these are namespaced under the `com.bad-example.*` NSID
247
+
/// > prefix, but as they stabilize they may be migrated to an org namespace
248
+
/// > like `blue.microcosm.*`. Support for asliasing to `com.bad-example.*`
249
+
/// > will be maintained as long as it's in use.
250
+
#[oai(rename = "slingshot-specific queries")]
251
+
Custom,
252
+
}
253
+
254
+
#[OpenApi]
255
+
impl Xrpc {
256
+
/// com.atproto.repo.getRecord
257
+
///
258
+
/// Get a single record from a repository. Does not require auth.
259
+
///
260
+
/// > [!tip]
261
+
/// > See also the [canonical `com.atproto` XRPC documentation](https://docs.bsky.app/docs/api/com-atproto-repo-get-record)
262
+
/// > that this endpoint aims to be compatible with.
263
+
#[oai(
264
+
path = "/com.atproto.repo.getRecord",
265
+
method = "get",
266
+
tag = "ApiTags::ComAtproto"
267
+
)]
268
+
async fn get_record(
269
+
&self,
270
+
/// The DID or handle of the repo
271
+
#[oai(example = "example_did")]
272
+
Query(repo): Query<String>,
273
+
/// The NSID of the record collection
274
+
#[oai(example = "example_collection")]
275
+
Query(collection): Query<String>,
276
+
/// The Record key
277
+
#[oai(example = "example_rkey")]
278
+
Query(rkey): Query<String>,
279
+
/// Optional: the CID of the version of the record.
280
+
///
281
+
/// If not specified, then return the most recent version.
282
+
///
283
+
/// If a stale `CID` is specified and a newer version of the record
284
+
/// exists, Slingshot returns a `NotFound` error. That is: Slingshot
285
+
/// only retains the most recent version of a record.
286
+
Query(cid): Query<Option<String>>,
287
+
) -> GetRecordResponse {
288
+
self.get_record_impl(repo, collection, rkey, cid).await
289
+
}
290
+
291
+
/// com.bad-example.repo.getUriRecord
292
+
///
293
+
/// Ergonomic complement to [`com.atproto.repo.getRecord`](https://docs.bsky.app/docs/api/com-atproto-repo-get-record)
294
+
/// which accepts an `at-uri` instead of individual repo/collection/rkey params
295
+
#[oai(
296
+
path = "/com.bad-example.repo.getUriRecord",
297
+
method = "get",
298
+
tag = "ApiTags::Custom"
299
+
)]
300
+
async fn get_uri_record(
301
+
&self,
302
+
/// The at-uri of the record
303
+
///
304
+
/// The identifier can be a DID or an atproto handle, and the collection
305
+
/// and rkey segments must be present.
306
+
#[oai(example = "example_uri")]
307
+
Query(at_uri): Query<String>,
308
+
/// Optional: the CID of the version of the record.
309
+
///
310
+
/// If not specified, then return the most recent version.
311
+
///
312
+
/// > [!tip]
313
+
/// > If specified and a newer version of the record exists, returns 404 not
314
+
/// > found. That is: slingshot only retains the most recent version of a
315
+
/// > record.
316
+
Query(cid): Query<Option<String>>,
317
+
) -> GetRecordResponse {
318
+
let bad_at_uri = || {
319
+
GetRecordResponse::BadRequest(xrpc_error(
320
+
"InvalidRequest",
321
+
"at-uri does not appear to be valid",
322
+
))
323
+
};
324
+
325
+
let Some(normalized) = normalize_at_uri(&at_uri) else {
326
+
return bad_at_uri();
327
+
};
328
+
329
+
// TODO: move this to links
330
+
let Some(rest) = normalized.strip_prefix("at://") else {
331
+
return bad_at_uri();
332
+
};
333
+
let Some((repo, rest)) = rest.split_once('/') else {
334
+
return bad_at_uri();
335
+
};
336
+
let Some((collection, rest)) = rest.split_once('/') else {
337
+
return bad_at_uri();
338
+
};
339
+
let rkey = if let Some((rkey, _rest)) = rest.split_once('?') {
340
+
rkey
341
+
} else {
342
+
rest
343
+
};
344
+
345
+
self.get_record_impl(
346
+
repo.to_string(),
347
+
collection.to_string(),
348
+
rkey.to_string(),
349
+
cid,
350
+
)
351
+
.await
352
+
}
353
+
354
+
/// com.atproto.identity.resolveHandle
355
+
///
356
+
/// Resolves an atproto [`handle`](https://atproto.com/guides/glossary#handle)
357
+
/// (hostname) to a [`DID`](https://atproto.com/guides/glossary#did-decentralized-id).
358
+
///
359
+
/// > [!tip]
360
+
/// > Compatibility note: Slingshot will **always bi-directionally verify
361
+
/// > against the DID document**, which is optional according to the
362
+
/// > authoritative lexicon.
363
+
///
364
+
/// > [!tip]
365
+
/// > See the [canonical `com.atproto` XRPC documentation](https://docs.bsky.app/docs/api/com-atproto-identity-resolve-handle)
366
+
/// > that this endpoint aims to be compatible with.
367
+
#[oai(
368
+
path = "/com.atproto.identity.resolveHandle",
369
+
method = "get",
370
+
tag = "ApiTags::ComAtproto"
371
+
)]
372
+
async fn resolve_handle(
373
+
&self,
374
+
/// The handle to resolve.
375
+
#[oai(example = "example_handle")]
376
+
Query(handle): Query<String>,
377
+
) -> JustDidResponse {
378
+
let Ok(handle) = Handle::new(handle) else {
379
+
return JustDidResponse::BadRequest(xrpc_error("InvalidRequest", "not a valid handle"));
380
+
};
381
+
382
+
let Ok(alleged_did) = self.identity.handle_to_did(handle.clone()).await else {
383
+
return JustDidResponse::ServerError(xrpc_error("Failed", "Could not resolve handle"));
384
+
};
385
+
386
+
let Some(alleged_did) = alleged_did else {
387
+
return JustDidResponse::BadRequest(xrpc_error(
388
+
"HandleNotFound",
389
+
"Could not resolve handle to a DID",
390
+
));
391
+
};
392
+
393
+
let Ok(partial_doc) = self.identity.did_to_partial_mini_doc(&alleged_did).await else {
394
+
return JustDidResponse::ServerError(xrpc_error("Failed", "Could not fetch DID doc"));
395
+
};
396
+
397
+
let Some(partial_doc) = partial_doc else {
398
+
return JustDidResponse::BadRequest(xrpc_error(
399
+
"HandleNotFound",
400
+
"Resolved handle but could not find DID doc for the DID",
401
+
));
402
+
};
403
+
404
+
if partial_doc.unverified_handle != handle {
405
+
return JustDidResponse::BadRequest(xrpc_error(
406
+
"HandleNotFound",
407
+
"Resolved handle failed bi-directional validation",
408
+
));
409
+
}
410
+
411
+
JustDidResponse::Ok(Json(FoundDidResponseObject {
412
+
did: alleged_did.to_string(),
413
+
}))
414
+
}
415
+
416
+
/// com.bad-example.identity.resolveMiniDoc
417
+
///
418
+
/// Like [com.atproto.identity.resolveIdentity](https://docs.bsky.app/docs/api/com-atproto-identity-resolve-identity)
419
+
/// but instead of the full `didDoc` it returns an atproto-relevant subset.
420
+
#[oai(
421
+
path = "/com.bad-example.identity.resolveMiniDoc",
422
+
method = "get",
423
+
tag = "ApiTags::Custom"
424
+
)]
425
+
async fn resolve_mini_id(
426
+
&self,
427
+
/// Handle or DID to resolve
428
+
#[oai(example = "example_handle")]
429
+
Query(identifier): Query<String>,
430
+
) -> ResolveMiniIDResponse {
431
+
let invalid = |reason: &'static str| {
432
+
ResolveMiniIDResponse::BadRequest(xrpc_error("InvalidRequest", reason))
433
+
};
434
+
435
+
let mut unverified_handle = None;
436
+
let did = match Did::new(identifier.clone()) {
437
+
Ok(did) => did,
438
+
Err(_) => {
439
+
let Ok(alleged_handle) = Handle::new(identifier) else {
440
+
return invalid("Identifier was not a valid DID or handle");
441
+
};
442
+
443
+
match self.identity.handle_to_did(alleged_handle.clone()).await {
444
+
Ok(res) => {
445
+
if let Some(did) = res {
446
+
// we did it joe
447
+
unverified_handle = Some(alleged_handle);
448
+
did
449
+
} else {
450
+
return invalid("Could not resolve handle identifier to a DID");
451
+
}
452
+
}
453
+
Err(e) => {
454
+
log::debug!("failed to resolve handle: {e}");
455
+
// TODO: ServerError not BadRequest
456
+
return invalid("Errored while trying to resolve handle to DID");
457
+
}
458
+
}
459
+
}
460
+
};
461
+
let Ok(partial_doc) = self.identity.did_to_partial_mini_doc(&did).await else {
462
+
return invalid("Failed to get DID doc");
463
+
};
464
+
let Some(partial_doc) = partial_doc else {
465
+
return invalid("Failed to find DID doc");
466
+
};
467
+
468
+
// ok so here's where we're at:
469
+
// ✅ we have a DID
470
+
// ✅ we have a partial doc
471
+
// 🔶 if we have a handle, it's from the `identifier` (user-input)
472
+
// -> then we just need to compare to the partial doc to confirm
473
+
// -> else we need to resolve the DID doc's to a handle and check
474
+
let handle = if let Some(h) = unverified_handle {
475
+
if h == partial_doc.unverified_handle {
476
+
h.to_string()
477
+
} else {
478
+
"handle.invalid".to_string()
479
+
}
480
+
} else {
481
+
let Ok(handle_did) = self
482
+
.identity
483
+
.handle_to_did(partial_doc.unverified_handle.clone())
484
+
.await
485
+
else {
486
+
return invalid("Failed to get DID doc's handle");
487
+
};
488
+
let Some(handle_did) = handle_did else {
489
+
return invalid("Failed to resolve DID doc's handle");
490
+
};
491
+
if handle_did == did {
492
+
partial_doc.unverified_handle.to_string()
493
+
} else {
494
+
"handle.invalid".to_string()
495
+
}
496
+
};
497
+
498
+
ResolveMiniIDResponse::Ok(Json(MiniDocResponseObject {
499
+
did: did.to_string(),
500
+
handle,
501
+
pds: partial_doc.pds,
502
+
signing_key: partial_doc.signing_key,
503
+
}))
504
+
}
505
+
506
+
async fn get_record_impl(
507
+
&self,
508
+
repo: String,
509
+
collection: String,
510
+
rkey: String,
511
+
cid: Option<String>,
512
+
) -> GetRecordResponse {
513
+
let did = match Did::new(repo.clone()) {
514
+
Ok(did) => did,
515
+
Err(_) => {
516
+
let Ok(handle) = Handle::new(repo) else {
517
+
return GetRecordResponse::BadRequest(xrpc_error(
518
+
"InvalidRequest",
519
+
"Repo was not a valid DID or handle",
520
+
));
521
+
};
522
+
match self.identity.handle_to_did(handle).await {
523
+
Ok(res) => {
524
+
if let Some(did) = res {
525
+
did
526
+
} else {
527
+
return GetRecordResponse::BadRequest(xrpc_error(
528
+
"InvalidRequest",
529
+
"Could not resolve handle repo to a DID",
530
+
));
531
+
}
532
+
}
533
+
Err(e) => {
534
+
log::debug!("handle resolution failed: {e}");
535
+
return GetRecordResponse::ServerError(xrpc_error(
536
+
"ResolutionFailed",
537
+
"Errored while trying to resolve handle to DID",
538
+
));
539
+
}
540
+
}
541
+
}
542
+
};
543
+
544
+
let Ok(collection) = Nsid::new(collection) else {
545
+
return GetRecordResponse::BadRequest(xrpc_error(
546
+
"InvalidRequest",
547
+
"Invalid NSID for collection",
548
+
));
549
+
};
550
+
551
+
let Ok(rkey) = RecordKey::new(rkey) else {
552
+
return GetRecordResponse::BadRequest(xrpc_error("InvalidRequest", "Invalid rkey"));
553
+
};
554
+
555
+
let cid: Option<Cid> = if let Some(cid) = cid {
556
+
let Ok(cid) = Cid::from_str(&cid) else {
557
+
return GetRecordResponse::BadRequest(xrpc_error("InvalidRequest", "Invalid CID"));
558
+
};
559
+
Some(cid)
560
+
} else {
561
+
None
562
+
};
563
+
564
+
let at_uri = format!("at://{}/{}/{}", &*did, &*collection, &*rkey);
565
+
566
+
let fr = self
567
+
.cache
568
+
.fetch(at_uri.clone(), {
569
+
let cid = cid.clone();
570
+
let repo_api = self.repo.clone();
571
+
|| async move {
572
+
repo_api
573
+
.get_record(&did, &collection, &rkey, &cid)
574
+
.await
575
+
.map_err(|e| foyer::Error::Other(Box::new(e)))
576
+
}
577
+
})
578
+
.await;
579
+
580
+
let entry = match fr {
581
+
Ok(e) => e,
582
+
Err(foyer::Error::Other(e)) => {
583
+
let record_error = match e.downcast::<RecordError>() {
584
+
Ok(e) => e,
585
+
Err(e) => {
586
+
log::error!("error (foyer other) getting cache entry, {e:?}");
587
+
return GetRecordResponse::ServerError(xrpc_error(
588
+
"ServerError",
589
+
"sorry, something went wrong",
590
+
));
591
+
}
592
+
};
593
+
let RecordError::UpstreamBadRequest(ErrorResponseObject { error, message }) =
594
+
*record_error
595
+
else {
596
+
log::error!("RecordError getting cache entry, {record_error:?}");
597
+
return GetRecordResponse::ServerError(xrpc_error(
598
+
"ServerError",
599
+
"sorry, something went wrong",
600
+
));
601
+
};
602
+
603
+
// all of the noise around here is so that we can ultimately reach this:
604
+
// upstream BadRequest extracted from the foyer result which we can proxy back
605
+
return GetRecordResponse::BadRequest(xrpc_error(
606
+
error,
607
+
format!("Upstream bad request: {message}"),
608
+
));
609
+
}
610
+
Err(e) => {
611
+
log::error!("error (foyer) getting cache entry, {e:?}");
612
+
return GetRecordResponse::ServerError(xrpc_error(
613
+
"ServerError",
614
+
"sorry, something went wrong",
615
+
));
616
+
}
617
+
};
618
+
619
+
match *entry {
620
+
CachedRecord::Found(ref raw) => {
621
+
let (found_cid, raw_value) = raw.into();
622
+
if cid.clone().map(|c| c != found_cid).unwrap_or(false) {
623
+
return GetRecordResponse::BadRequest(Json(XrpcErrorResponseObject {
624
+
error: "RecordNotFound".to_string(),
625
+
message: "A record was found but its CID did not match that requested"
626
+
.to_string(),
627
+
}));
628
+
}
629
+
// TODO: thank u stellz: https://gist.github.com/stella3d/51e679e55b264adff89d00a1e58d0272
630
+
let value =
631
+
serde_json::from_str(raw_value.get()).expect("RawValue to be valid json");
632
+
GetRecordResponse::Ok(Json(FoundRecordResponseObject {
633
+
uri: at_uri,
634
+
cid: Some(found_cid.as_ref().to_string()),
635
+
value,
636
+
}))
637
+
}
638
+
CachedRecord::Deleted => GetRecordResponse::BadRequest(Json(XrpcErrorResponseObject {
639
+
error: "RecordNotFound".to_string(),
640
+
message: "This record was deleted".to_string(),
641
+
})),
642
+
}
643
+
}
644
+
645
+
// TODO
646
+
// #[oai(path = "/com.atproto.identity.resolveHandle", method = "get")]
647
+
// #[oai(path = "/com.atproto.identity.resolveDid", method = "get")]
648
+
// but these are both not specified to do bidirectional validation, which is what we want to offer
649
+
// com.atproto.identity.resolveIdentity seems right, but requires returning the full did-doc
650
+
// would be nice if there were two queries:
651
+
// did -> verified handle + pds url
652
+
// handle -> verified did + pds url
653
+
//
654
+
// we could do horrible things and implement resolveIdentity with only a stripped-down fake did doc
655
+
// but this will *definitely* cause problems because eg. we're not currently storing pubkeys and
656
+
// those are a little bit important
657
+
}
658
+
659
+
#[derive(Debug, Clone, Serialize)]
660
+
#[serde(rename_all = "camelCase")]
661
+
struct AppViewService {
662
+
id: String,
663
+
r#type: String,
664
+
service_endpoint: String,
665
+
}
666
+
#[derive(Debug, Clone, Serialize)]
667
+
struct AppViewDoc {
668
+
id: String,
669
+
service: [AppViewService; 1],
670
+
}
671
+
/// Serve a did document for did:web for this to be an xrpc appview
672
+
///
673
+
/// No slingshot endpoints currently require auth, so it's not necessary to do
674
+
/// service proxying, however clients may wish to:
675
+
///
676
+
/// - PDS proxying offers a level of client IP anonymity from slingshot
677
+
/// - slingshot *may* implement more generous per-user rate-limits for proxied requests in the future
678
+
fn get_did_doc(domain: &str) -> impl Endpoint + use<> {
679
+
let doc = poem::web::Json(AppViewDoc {
680
+
id: format!("did:web:{domain}"),
681
+
service: [AppViewService {
682
+
id: "#slingshot".to_string(),
683
+
r#type: "SlingshotRecordProxy".to_string(),
684
+
service_endpoint: format!("https://{domain}"),
685
+
}],
686
+
});
687
+
make_sync(move |_| doc.clone())
688
+
}
689
+
690
+
pub async fn serve(
691
+
cache: HybridCache<String, CachedRecord>,
692
+
identity: Identity,
693
+
repo: Repo,
694
+
domain: Option<String>,
695
+
acme_contact: Option<String>,
696
+
certs: Option<PathBuf>,
697
+
host: String,
698
+
port: u16,
699
+
shutdown: CancellationToken,
700
+
) -> Result<(), ServerError> {
701
+
let repo = Arc::new(repo);
702
+
let api_service = OpenApiService::new(
703
+
Xrpc {
704
+
cache,
705
+
identity,
706
+
repo,
707
+
},
708
+
"Slingshot",
709
+
env!("CARGO_PKG_VERSION"),
710
+
)
711
+
.server(if let Some(ref h) = domain {
712
+
format!("https://{h}")
713
+
} else {
714
+
"http://localhost:3000".to_string()
715
+
})
716
+
.url_prefix("/xrpc")
717
+
.contact(
718
+
ContactObject::new()
719
+
.name("@microcosm.blue")
720
+
.url("https://bsky.app/profile/microcosm.blue"),
721
+
)
722
+
.description(include_str!("../api-description.md"))
723
+
.external_document(ExternalDocumentObject::new(
724
+
"https://microcosm.blue/slingshot",
725
+
));
726
+
727
+
let mut app = Route::new()
728
+
.at("/", StaticFileEndpoint::new("./static/index.html"))
729
+
.nest("/openapi", api_service.spec_endpoint())
730
+
.nest("/xrpc/", api_service);
731
+
732
+
if let Some(domain) = domain {
733
+
rustls::crypto::aws_lc_rs::default_provider()
734
+
.install_default()
735
+
.expect("alskfjalksdjf");
736
+
737
+
app = app.at("/.well-known/did.json", get_did_doc(&domain));
738
+
739
+
let mut auto_cert = AutoCert::builder()
740
+
.directory_url(LETS_ENCRYPT_PRODUCTION)
741
+
.domain(&domain);
742
+
if let Some(contact) = acme_contact {
743
+
auto_cert = auto_cert.contact(contact);
744
+
}
745
+
if let Some(certs) = certs {
746
+
auto_cert = auto_cert.cache_path(certs);
747
+
}
748
+
let auto_cert = auto_cert.build().map_err(ServerError::AcmeBuildError)?;
749
+
750
+
run(
751
+
TcpListener::bind("0.0.0.0:443").acme(auto_cert),
752
+
app,
753
+
shutdown,
754
+
)
755
+
.await
756
+
} else {
757
+
run(
758
+
TcpListener::bind(format!("{host}:{port}")),
759
+
app,
760
+
shutdown,
761
+
)
762
+
.await
763
+
}
764
+
}
765
+
766
+
async fn run<L>(listener: L, app: Route, shutdown: CancellationToken) -> Result<(), ServerError>
767
+
where
768
+
L: Listener + 'static,
769
+
{
770
+
let app = app
771
+
.with(
772
+
Cors::new()
773
+
.allow_origin_regex("*")
774
+
.allow_methods([Method::GET])
775
+
.allow_credentials(false),
776
+
)
777
+
.with(CatchPanic::new())
778
+
.with(Tracing);
779
+
Server::new(listener)
780
+
.name("slingshot")
781
+
.run_with_graceful_shutdown(app, shutdown.cancelled(), None)
782
+
.await
783
+
.map_err(ServerError::ServerExited)
784
+
.inspect(|()| log::info!("server ended. goodbye."))
785
+
}
slingshot/static/favicon.ico
slingshot/static/favicon.ico
This is a binary file and will not be displayed.
+67
slingshot/static/index.html
+67
slingshot/static/index.html
···
1
+
<!doctype html>
2
+
<html lang="en">
3
+
<head>
4
+
<meta charset="utf-8" />
5
+
<title>Slingshot: atproto edge record cache</title>
6
+
<meta name="viewport" content="width=device-width, initial-scale=1" />
7
+
<meta name="description" content="API Documentation for Slingshot, a firehose-listening atproto edge record and identity cache." />
8
+
<style>
9
+
:root {
10
+
--scalar-small: 13px;
11
+
}
12
+
.scalar-app .markdown .markdown-alert {
13
+
font-size: var(--scalar-small);
14
+
}
15
+
.sidebar-heading-link-title {
16
+
line-height: 1.2;
17
+
}
18
+
.custom-header {
19
+
height: 42px;
20
+
background-color: #221828;
21
+
box-shadow: inset 0 -1px 0 var(--scalar-border-color);
22
+
color: var(--scalar-color-1);
23
+
font-size: var(--scalar-font-size-3);
24
+
font-family: 'Iowan Old Style', 'Palatino Linotype', 'URW Palladio L', P052, serif;
25
+
padding: 0 18px;
26
+
justify-content: space-between;
27
+
}
28
+
.custom-header,
29
+
.custom-header nav {
30
+
display: flex;
31
+
align-items: center;
32
+
gap: 18px;
33
+
}
34
+
.custom-header a:hover {
35
+
color: var(--scalar-color-2);
36
+
}
37
+
38
+
.light-mode .custom-header {
39
+
background-color: thistle;
40
+
}
41
+
</style>
42
+
</head>
43
+
<body>
44
+
<header class="custom-header scalar-app">
45
+
<p>
46
+
TODO: thing
47
+
</p>
48
+
<nav>
49
+
<b>a <a href="https://microcosm.blue">microcosm</a> project</b>
50
+
<a href="https://bsky.app/profile/microcosm.blue">@microcosm.blue</a>
51
+
<a href="https://github.com/at-microcosm">github</a>
52
+
</nav>
53
+
</header>
54
+
55
+
<script id="api-reference" type="application/json" data-url="/openapi"></script>
56
+
57
+
<script>
58
+
var configuration = {
59
+
theme: 'purple',
60
+
hideModels: true,
61
+
}
62
+
document.getElementById('api-reference').dataset.configuration = JSON.stringify(configuration)
63
+
</script>
64
+
65
+
<script src="https://cdn.jsdelivr.net/npm/@scalar/api-reference"></script>
66
+
</body>
67
+
</html>
+5
-5
spacedust/src/subscriber.rs
+5
-5
spacedust/src/subscriber.rs
···
42
42
loop {
43
43
tokio::select! {
44
44
l = receiver.recv() => match l {
45
-
Ok(link) => if self.filter(&link.properties) {
46
-
if let Err(e) = ws_sender.send(link.message.clone()).await {
47
-
log::warn!("failed to send link, dropping subscriber: {e:?}");
48
-
break;
49
-
}
45
+
Ok(link) => if self.filter(&link.properties)
46
+
&& let Err(e) = ws_sender.send(link.message.clone()).await
47
+
{
48
+
log::warn!("failed to send link, dropping subscriber: {e:?}");
49
+
break;
50
50
},
51
51
Err(RecvError::Closed) => self.shutdown.cancel(),
52
52
Err(RecvError::Lagged(n)) => {
+1
-1
ufos/Cargo.toml
+1
-1
ufos/Cargo.toml
···
13
13
clap = { version = "4.5.31", features = ["derive"] }
14
14
dropshot = "0.16.0"
15
15
env_logger = "0.11.7"
16
-
fjall = { version = "2.8.0", features = ["lz4"] }
16
+
fjall = { git = "https://github.com/fjall-rs/fjall.git", features = ["lz4"] }
17
17
getrandom = "0.3.3"
18
18
http = "1.3.1"
19
19
jetstream = { path = "../jetstream", features = ["metrics"] }
+42
-10
ufos/src/main.rs
+42
-10
ufos/src/main.rs
···
4
4
use metrics_exporter_prometheus::PrometheusBuilder;
5
5
use std::path::PathBuf;
6
6
use std::time::{Duration, SystemTime};
7
+
use tokio::task::JoinSet;
7
8
use ufos::consumer;
8
9
use ufos::file_consumer;
9
10
use ufos::server;
···
72
73
Ok(())
73
74
}
74
75
75
-
async fn go<B: StoreBackground>(
76
+
async fn go<B: StoreBackground + 'static>(
76
77
args: Args,
77
78
read_store: impl StoreReader + 'static + Clone,
78
79
mut write_store: impl StoreWriter<B> + 'static,
79
80
cursor: Option<Cursor>,
80
81
sketch_secret: SketchSecretPrefix,
81
82
) -> anyhow::Result<()> {
83
+
let mut whatever_tasks: JoinSet<anyhow::Result<()>> = JoinSet::new();
84
+
let mut consumer_tasks: JoinSet<anyhow::Result<()>> = JoinSet::new();
85
+
82
86
println!("starting server with storage...");
83
87
let serving = server::serve(read_store.clone());
88
+
whatever_tasks.spawn(async move {
89
+
serving.await.map_err(|e| {
90
+
log::warn!("server ended: {e}");
91
+
anyhow::anyhow!(e)
92
+
})
93
+
});
84
94
85
95
if args.pause_writer {
86
96
log::info!("not starting jetstream or the write loop.");
87
-
serving.await.map_err(|e| anyhow::anyhow!(e))?;
97
+
for t in whatever_tasks.join_all().await {
98
+
if let Err(e) = t {
99
+
return Err(anyhow::anyhow!(e));
100
+
}
101
+
}
88
102
return Ok(());
89
103
}
90
104
···
102
116
let rolling = write_store
103
117
.background_tasks(args.reroll)?
104
118
.run(args.backfill);
105
-
let consuming = write_store.receive_batches(batches);
119
+
whatever_tasks.spawn(async move {
120
+
rolling
121
+
.await
122
+
.inspect_err(|e| log::warn!("rollup ended: {e}"))?;
123
+
Ok(())
124
+
});
106
125
107
-
let stating = do_update_stuff(read_store);
126
+
consumer_tasks.spawn(async move {
127
+
write_store
128
+
.receive_batches(batches)
129
+
.await
130
+
.inspect_err(|e| log::warn!("consumer ended: {e}"))?;
131
+
Ok(())
132
+
});
133
+
134
+
whatever_tasks.spawn(async move {
135
+
do_update_stuff(read_store).await;
136
+
log::warn!("status task ended");
137
+
Ok(())
138
+
});
108
139
109
140
install_metrics_server()?;
110
141
111
-
tokio::select! {
112
-
z = serving => log::warn!("serve task ended: {z:?}"),
113
-
z = rolling => log::warn!("rollup task ended: {z:?}"),
114
-
z = consuming => log::warn!("consuming task ended: {z:?}"),
115
-
z = stating => log::warn!("status task ended: {z:?}"),
116
-
};
142
+
for (i, t) in consumer_tasks.join_all().await.iter().enumerate() {
143
+
log::warn!("task {i} done: {t:?}");
144
+
}
145
+
146
+
println!("consumer tasks all completed, killing the others");
147
+
whatever_tasks.shutdown().await;
117
148
118
149
println!("bye!");
119
150
···
162
193
interval.set_missed_tick_behavior(tokio::time::MissedTickBehavior::Delay);
163
194
loop {
164
195
interval.tick().await;
196
+
read_store.update_metrics();
165
197
match read_store.get_consumer_info().await {
166
198
Err(e) => log::warn!("failed to get jetstream consumer info: {e:?}"),
167
199
Ok(ConsumerInfo::Jetstream {
+11
-1
ufos/src/storage.rs
+11
-1
ufos/src/storage.rs
···
41
41
Unit::Microseconds,
42
42
"batches that took more than 3s to insert"
43
43
);
44
+
describe_histogram!(
45
+
"storage_batch_insert_time",
46
+
Unit::Microseconds,
47
+
"total time to insert one commit batch"
48
+
);
44
49
while let Some(event_batch) = batches.recv().await {
45
50
let token = CancellationToken::new();
46
51
let cancelled = token.clone();
···
69
74
let mut me = self.clone();
70
75
move || {
71
76
let _guard = token.drop_guard();
72
-
me.insert_batch(event_batch)
77
+
let t0 = Instant::now();
78
+
let r = me.insert_batch(event_batch);
79
+
histogram!("storage_batch_insert_time").record(t0.elapsed().as_micros() as f64);
80
+
r
73
81
}
74
82
})
75
83
.await??;
···
103
111
#[async_trait]
104
112
pub trait StoreReader: Send + Sync {
105
113
fn name(&self) -> String;
114
+
115
+
fn update_metrics(&self) {}
106
116
107
117
async fn get_storage_stats(&self) -> StorageResult<serde_json::Value>;
108
118
+104
-20
ufos/src/storage_fjall.rs
+104
-20
ufos/src/storage_fjall.rs
···
23
23
Batch as FjallBatch, Config, Keyspace, PartitionCreateOptions, PartitionHandle, Snapshot,
24
24
};
25
25
use jetstream::events::Cursor;
26
-
use metrics::{counter, describe_counter, describe_histogram, histogram, Unit};
26
+
use lsm_tree::AbstractTree;
27
+
use metrics::{
28
+
counter, describe_counter, describe_gauge, describe_histogram, gauge, histogram, Unit,
29
+
};
27
30
use std::collections::{HashMap, HashSet};
28
31
use std::iter::Peekable;
29
32
use std::ops::Bound;
···
227
230
feeds: feeds.clone(),
228
231
records: records.clone(),
229
232
rollups: rollups.clone(),
233
+
queues: queues.clone(),
230
234
};
235
+
reader.describe_metrics();
231
236
let writer = FjallWriter {
232
237
bg_taken: Arc::new(AtomicBool::new(false)),
233
238
keyspace,
···
237
242
rollups,
238
243
queues,
239
244
};
245
+
writer.describe_metrics();
240
246
Ok((reader, writer, js_cursor, sketch_secret))
241
247
}
242
248
}
···
250
256
feeds: PartitionHandle,
251
257
records: PartitionHandle,
252
258
rollups: PartitionHandle,
259
+
queues: PartitionHandle,
253
260
}
254
261
255
262
/// An iterator that knows how to skip over deleted/invalidated records
···
381
388
type CollectionSerieses = HashMap<Nsid, Vec<CountsValue>>;
382
389
383
390
impl FjallReader {
391
+
fn describe_metrics(&self) {
392
+
describe_gauge!(
393
+
"storage_fjall_l0_run_count",
394
+
Unit::Count,
395
+
"number of L0 runs in a partition"
396
+
);
397
+
describe_gauge!(
398
+
"storage_fjall_keyspace_disk_space",
399
+
Unit::Bytes,
400
+
"total storage used according to fjall"
401
+
);
402
+
describe_gauge!(
403
+
"storage_fjall_journal_count",
404
+
Unit::Count,
405
+
"total keyspace journals according to fjall"
406
+
);
407
+
describe_gauge!(
408
+
"storage_fjall_keyspace_sequence",
409
+
Unit::Count,
410
+
"fjall keyspace sequence"
411
+
);
412
+
}
413
+
384
414
fn get_storage_stats(&self) -> StorageResult<serde_json::Value> {
385
415
let rollup_cursor =
386
416
get_static_neu::<NewRollupCursorKey, NewRollupCursorValue>(&self.global)?
···
1000
1030
fn name(&self) -> String {
1001
1031
"fjall storage v2".into()
1002
1032
}
1033
+
fn update_metrics(&self) {
1034
+
gauge!("storage_fjall_l0_run_count", "partition" => "global")
1035
+
.set(self.global.tree.l0_run_count() as f64);
1036
+
gauge!("storage_fjall_l0_run_count", "partition" => "feeds")
1037
+
.set(self.feeds.tree.l0_run_count() as f64);
1038
+
gauge!("storage_fjall_l0_run_count", "partition" => "records")
1039
+
.set(self.records.tree.l0_run_count() as f64);
1040
+
gauge!("storage_fjall_l0_run_count", "partition" => "rollups")
1041
+
.set(self.rollups.tree.l0_run_count() as f64);
1042
+
gauge!("storage_fjall_l0_run_count", "partition" => "queues")
1043
+
.set(self.queues.tree.l0_run_count() as f64);
1044
+
gauge!("storage_fjall_keyspace_disk_space").set(self.keyspace.disk_space() as f64);
1045
+
gauge!("storage_fjall_journal_count").set(self.keyspace.journal_count() as f64);
1046
+
gauge!("storage_fjall_keyspace_sequence").set(self.keyspace.instant() as f64);
1047
+
}
1003
1048
async fn get_storage_stats(&self) -> StorageResult<serde_json::Value> {
1004
1049
let s = self.clone();
1005
1050
tokio::task::spawn_blocking(move || FjallReader::get_storage_stats(&s)).await?
···
1091
1136
}
1092
1137
1093
1138
impl FjallWriter {
1139
+
fn describe_metrics(&self) {
1140
+
describe_histogram!(
1141
+
"storage_insert_batch_db_batch_items",
1142
+
Unit::Count,
1143
+
"how many items are in the fjall batch for batched inserts"
1144
+
);
1145
+
describe_histogram!(
1146
+
"storage_rollup_counts_db_batch_items",
1147
+
Unit::Count,
1148
+
"how many items are in the fjall batch for a timlies rollup"
1149
+
);
1150
+
describe_counter!(
1151
+
"storage_delete_account_partial_commits",
1152
+
Unit::Count,
1153
+
"fjall checkpoint commits for cleaning up accounts with too many records"
1154
+
);
1155
+
describe_counter!(
1156
+
"storage_delete_account_completions",
1157
+
Unit::Count,
1158
+
"total count of account deletes handled"
1159
+
);
1160
+
describe_counter!(
1161
+
"storage_delete_account_records_deleted",
1162
+
Unit::Count,
1163
+
"total records deleted when handling account deletes"
1164
+
);
1165
+
describe_histogram!(
1166
+
"storage_trim_dirty_nsids",
1167
+
Unit::Count,
1168
+
"number of NSIDs trimmed"
1169
+
);
1170
+
describe_histogram!(
1171
+
"storage_trim_duration",
1172
+
Unit::Microseconds,
1173
+
"how long it took to trim the dirty NSIDs"
1174
+
);
1175
+
describe_counter!(
1176
+
"storage_trim_removed",
1177
+
Unit::Count,
1178
+
"how many records were removed during trim"
1179
+
);
1180
+
}
1094
1181
fn rollup_delete_account(
1095
1182
&mut self,
1096
1183
cursor: Cursor,
···
1222
1309
AllTimeRecordsKey::new(new_creates_count.into(), &nsid).to_db_bytes()?,
1223
1310
),
1224
1311
};
1225
-
batch.remove(&self.rollups, &old_k); // TODO: when fjall gets weak delete, this will hopefully work way better
1312
+
// remove_weak is allowed here because the secondary ranking index only ever inserts once at a key
1313
+
batch.remove_weak(&self.rollups, &old_k);
1226
1314
batch.insert(&self.rollups, &new_k, "");
1227
1315
}
1228
1316
···
1246
1334
AllTimeDidsKey::new(new_dids_estimate.into(), &nsid).to_db_bytes()?,
1247
1335
),
1248
1336
};
1249
-
batch.remove(&self.rollups, &old_k); // TODO: when fjall gets weak delete, this will hopefully work way better
1337
+
// remove_weak is allowed here because the secondary ranking index only ever inserts once at a key
1338
+
batch.remove_weak(&self.rollups, &old_k);
1250
1339
batch.insert(&self.rollups, &new_k, "");
1251
1340
}
1252
1341
···
1256
1345
1257
1346
insert_batch_static_neu::<NewRollupCursorKey>(&mut batch, &self.global, last_cursor)?;
1258
1347
1348
+
histogram!("storage_rollup_counts_db_batch_items").record(batch.len() as f64);
1259
1349
batch.commit()?;
1260
1350
Ok((cursors_advanced, dirty_nsids))
1261
1351
}
···
1266
1356
if self.bg_taken.swap(true, Ordering::SeqCst) {
1267
1357
return Err(StorageError::BackgroundAlreadyStarted);
1268
1358
}
1269
-
describe_histogram!(
1270
-
"storage_trim_dirty_nsids",
1271
-
Unit::Count,
1272
-
"number of NSIDs trimmed"
1273
-
);
1274
-
describe_histogram!(
1275
-
"storage_trim_duration",
1276
-
Unit::Microseconds,
1277
-
"how long it took to trim the dirty NSIDs"
1278
-
);
1279
-
describe_counter!(
1280
-
"storage_trim_removed",
1281
-
Unit::Count,
1282
-
"how many records were removed during trim"
1283
-
);
1284
1359
if reroll {
1285
1360
log::info!("reroll: resetting rollup cursor...");
1286
1361
insert_static_neu::<NewRollupCursorKey>(&self.global, Cursor::from_start())?;
···
1375
1450
latest.to_db_bytes()?,
1376
1451
);
1377
1452
1453
+
histogram!("storage_insert_batch_db_batch_items").record(batch.len() as f64);
1378
1454
batch.commit()?;
1379
1455
Ok(())
1380
1456
}
···
1529
1605
candidate_new_feed_lower_cursor = Some(feed_key.cursor());
1530
1606
}
1531
1607
1532
-
self.feeds.remove(&location_key_bytes)?;
1608
+
self.records.remove(&location_key_bytes)?;
1533
1609
self.feeds.remove(key_bytes)?;
1534
1610
records_deleted += 1;
1535
1611
}
···
1556
1632
batch.remove(&self.records, key_bytes);
1557
1633
records_deleted += 1;
1558
1634
if batch.len() >= MAX_BATCHED_ACCOUNT_DELETE_RECORDS {
1635
+
counter!("storage_delete_account_partial_commits").increment(1);
1559
1636
batch.commit()?;
1560
1637
batch = self.keyspace.batch();
1561
1638
}
1562
1639
}
1640
+
counter!("storage_delete_account_completions").increment(1);
1641
+
counter!("storage_delete_account_records_deleted").increment(records_deleted as u64);
1563
1642
batch.commit()?;
1564
1643
Ok(records_deleted)
1565
1644
}
···
1619
1698
histogram!("storage_trim_dirty_nsids").record(completed.len() as f64);
1620
1699
histogram!("storage_trim_duration").record(dt.as_micros() as f64);
1621
1700
counter!("storage_trim_removed", "dangling" => "true").increment(total_danglers as u64);
1622
-
counter!("storage_trim_removed", "dangling" => "false").increment((total_deleted - total_danglers) as u64);
1701
+
if total_deleted >= total_danglers {
1702
+
counter!("storage_trim_removed", "dangling" => "false").increment((total_deleted - total_danglers) as u64);
1703
+
} else {
1704
+
// TODO: probably think through what's happening here
1705
+
log::warn!("weird trim case: more danglers than deleted? metric will be missing for dangling=false. deleted={total_deleted} danglers={total_danglers}");
1706
+
}
1623
1707
for c in completed {
1624
1708
dirty_nsids.remove(&c);
1625
1709
}
-196
ufos ops (move to micro-ops).md
-196
ufos ops (move to micro-ops).md
···
1
-
ufos ops
2
-
3
-
btrfs snapshots: snapper
4
-
5
-
```bash
6
-
sudo apt install snapper
7
-
sudo snapper -c ufos-db create-config /mnt/ufos-db
8
-
9
-
# edit /etc/snapper/configs/ufos-db
10
-
# change
11
-
TIMELINE_MIN_AGE="1800"
12
-
TIMELINE_LIMIT_HOURLY="10"
13
-
TIMELINE_LIMIT_DAILY="10"
14
-
TIMELINE_LIMIT_WEEKLY="0"
15
-
TIMELINE_LIMIT_MONTHLY="10"
16
-
TIMELINE_LIMIT_YEARLY="10"
17
-
# to
18
-
TIMELINE_MIN_AGE="1800"
19
-
TIMELINE_LIMIT_HOURLY="22"
20
-
TIMELINE_LIMIT_DAILY="4"
21
-
TIMELINE_LIMIT_WEEKLY="0"
22
-
TIMELINE_LIMIT_MONTHLY="0"
23
-
TIMELINE_LIMIT_YEARLY="0"
24
-
```
25
-
26
-
this should be enough?
27
-
28
-
list snapshots:
29
-
30
-
```bash
31
-
sudo snapper -c ufos-db list
32
-
```
33
-
34
-
systemd
35
-
36
-
create file: `/etc/systemd/system/ufos.service`
37
-
38
-
```ini
39
-
[Unit]
40
-
Description=UFOs-API
41
-
After=network.target
42
-
43
-
[Service]
44
-
User=pi
45
-
WorkingDirectory=/home/pi/
46
-
ExecStart=/home/pi/ufos --jetstream us-west-2 --data /mnt/ufos-db/
47
-
Environment="RUST_LOG=info"
48
-
LimitNOFILE=16384
49
-
Restart=always
50
-
51
-
[Install]
52
-
WantedBy=multi-user.target
53
-
```
54
-
55
-
then
56
-
57
-
```bash
58
-
sudo systemctl daemon-reload
59
-
sudo systemctl enable ufos
60
-
sudo systemctl start ufos
61
-
```
62
-
63
-
monitor with
64
-
65
-
```bash
66
-
journalctl -u ufos -f
67
-
```
68
-
69
-
make sure a backup dir exists
70
-
71
-
```bash
72
-
mkdir /home/pi/backup
73
-
```
74
-
75
-
mount the NAS
76
-
77
-
```bash
78
-
sudo mount.cifs "//truenas.local/folks data" /home/pi/backup -o user=phil,uid=pi
79
-
```
80
-
81
-
manual rsync
82
-
83
-
```bash
84
-
sudo rsync -ahP --delete /mnt/ufos-db/.snapshots/1/snapshot/ backup/ufos/
85
-
```
86
-
87
-
backup script sketch
88
-
89
-
```bash
90
-
NUM=$(sudo snapper --csvout -c ufos-db list --type single --columns number | tail -n1)
91
-
sudo rsync -ahP --delete "/mnt/ufos-db/.snapshots/${NUM}/snapshot/" backup/ufos/
92
-
```
93
-
94
-
just crontab it?
95
-
96
-
`sudo crontab -e`
97
-
```bash
98
-
0 1/6 * * * rsync -ahP --delete "/mnt/ufos-db/.snapshots/$(sudo snapper --csvout -c ufos-db list --columns number | tail -n1)/snapshot/" backup/ufos/
99
-
```
100
-
101
-
^^ try once initial backup is done
102
-
103
-
104
-
--columns subvolume,number
105
-
106
-
subvolume
107
-
number
108
-
109
-
110
-
111
-
112
-
gateway: follow constellation for nginx->prom thing
113
-
114
-
config at `/etc/prometheus-nginxlog-exporter.hcl`
115
-
116
-
before: `/etc/prometheus-nginxlog-exporter.hcl`
117
-
118
-
```hcl
119
-
listen {
120
-
port = 4044
121
-
}
122
-
123
-
namespace "nginx" {
124
-
source = {
125
-
files = [
126
-
"/var/log/nginx/constellation-access.log"
127
-
]
128
-
}
129
-
130
-
format = "$remote_addr - $remote_user [$time_local] \"$request\" $status $upstream_cache_status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\""
131
-
132
-
labels {
133
-
app = "constellation"
134
-
}
135
-
136
-
relabel "cache_status" {
137
-
from = "upstream_cache_status"
138
-
}
139
-
}
140
-
```
141
-
142
-
after:
143
-
144
-
```hcl
145
-
listen {
146
-
port = 4044
147
-
}
148
-
149
-
namespace "constellation" {
150
-
source = {
151
-
files = [
152
-
"/var/log/nginx/constellation-access.log"
153
-
]
154
-
}
155
-
156
-
format = "$remote_addr - $remote_user [$time_local] \"$request\" $status $upstream_cache_status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\""
157
-
158
-
labels {
159
-
app = "constellation"
160
-
}
161
-
162
-
relabel "cache_status" {
163
-
from = "upstream_cache_status"
164
-
}
165
-
166
-
namespace_label = "vhost"
167
-
metrics_override = { prefix = "nginx" }
168
-
}
169
-
170
-
namespace "ufos" {
171
-
source = {
172
-
files = [
173
-
"/var/log/nginx/ufos-access.log"
174
-
]
175
-
}
176
-
177
-
format = "$remote_addr - $remote_user [$time_local] \"$request\" $status $upstream_cache_status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" \"$http_x_forwarded_for\""
178
-
179
-
labels {
180
-
app = "ufos"
181
-
}
182
-
183
-
relabel "cache_status" {
184
-
from = "upstream_cache_status"
185
-
}
186
-
187
-
namespace_label = "vhost"
188
-
metrics_override = { prefix = "nginx" }
189
-
}
190
-
```
191
-
192
-
193
-
```bash
194
-
systemctl start prometheus-nginxlog-exporter.service
195
-
```
196
-
+4
who-am-i/Cargo.toml
+4
who-am-i/Cargo.toml
···
14
14
clap = { version = "4.5.40", features = ["derive", "env"] }
15
15
ctrlc = "3.4.7"
16
16
dashmap = "6.1.0"
17
+
elliptic-curve = "0.13.8"
17
18
handlebars = { version = "6.3.2", features = ["dir_source"] }
18
19
hickory-resolver = "0.25.2"
20
+
jose-jwk = "0.1.2"
19
21
jsonwebtoken = "9.3.1"
20
22
metrics = "0.24.2"
23
+
p256 = "0.13.2"
24
+
pkcs8 = "0.10.2"
21
25
rand = "0.9.1"
22
26
reqwest = { version = "0.12.22", features = ["native-tls-vendored"] }
23
27
serde = { version = "1.0.219", features = ["derive"] }
+9
-4
who-am-i/src/expiring_task_map.rs
+9
-4
who-am-i/src/expiring_task_map.rs
···
49
49
.run_until_cancelled(sleep(expiration))
50
50
.await
51
51
.is_some()
52
+
// the (sleep) task completed first
52
53
{
53
-
// is Some if the (sleep) task completed first
54
54
map.remove(&k);
55
55
cancel.cancel();
56
56
metrics::counter!("whoami_task_map_completions", "result" => "expired")
···
62
62
}
63
63
64
64
pub fn take(&self, key: &str) -> Option<JoinHandle<T>> {
65
-
metrics::counter!("whoami_task_map_completions", "result" => "retrieved").increment(1);
66
-
// when the _guard drops, the token gets cancelled for us
67
-
self.0.map.remove(key).map(|(_, (_guard, handle))| handle)
65
+
if let Some((_key, (_guard, handle))) = self.0.map.remove(key) {
66
+
// when the _guard drops, it cancels the token for us
67
+
metrics::counter!("whoami_task_map_completions", "result" => "retrieved").increment(1);
68
+
Some(handle)
69
+
} else {
70
+
metrics::counter!("whoami_task_map_gones").increment(1);
71
+
None
72
+
}
68
73
}
69
74
}
70
75
+34
-15
who-am-i/src/jwt.rs
+34
-15
who-am-i/src/jwt.rs
···
1
+
use elliptic_curve::SecretKey;
2
+
use jose_jwk::{Class, Jwk, Key, Parameters};
1
3
use jsonwebtoken::{Algorithm, EncodingKey, Header, encode, errors::Error as JWTError};
4
+
use pkcs8::DecodePrivateKey;
2
5
use serde::Serialize;
3
6
use std::fs;
4
7
use std::io::Error as IOError;
···
27
30
28
31
pub struct Tokens {
29
32
encoding_key: EncodingKey,
30
-
jwks: String,
33
+
jwk: Jwk,
31
34
}
32
35
33
36
impl Tokens {
34
-
pub fn from_files(
35
-
priv_f: impl AsRef<Path>,
36
-
jwks_f: impl AsRef<Path>,
37
-
) -> Result<Self, TokensSetupError> {
37
+
pub fn from_files(priv_f: impl AsRef<Path>) -> Result<Self, TokensSetupError> {
38
38
let private_key_data: Vec<u8> =
39
39
fs::read(priv_f).map_err(TokensSetupError::ReadPrivateKey)?;
40
40
let encoding_key =
41
41
EncodingKey::from_ec_pem(&private_key_data).map_err(TokensSetupError::PrivateKey)?;
42
42
43
-
let jwks_data: Vec<u8> = fs::read(jwks_f).map_err(TokensSetupError::ReadJwks)?;
44
-
let jwks = String::from_utf8(jwks_data).map_err(TokensSetupError::DecodeJwks)?;
43
+
let jwk_key_string = String::from_utf8(private_key_data).unwrap();
44
+
let mut jwk = SecretKey::<p256::NistP256>::from_pkcs8_pem(&jwk_key_string)
45
+
.map(|secret_key| Jwk {
46
+
key: Key::from(&secret_key.into()),
47
+
prm: Parameters {
48
+
kid: Some("who-am-i-00".to_string()),
49
+
cls: Some(Class::Signing),
50
+
..Default::default()
51
+
},
52
+
})
53
+
.expect("to get private key");
54
+
55
+
// CRITICAL: this is what turns the private jwk into a public one: the
56
+
// `d` parameter is the secret for an EC key; a pubkey just has no `d`.
57
+
//
58
+
// this feels baaaadd but hey we're just copying atrium
59
+
// https://github.com/atrium-rs/atrium/blob/b48810f84d83d037ee89b79b8566df9e0f2a6dae/atrium-oauth/src/keyset.rs#L41
60
+
let Key::Ec(ref mut ec) = jwk.key else {
61
+
unimplemented!()
62
+
};
63
+
ec.d = None; // CRITICAL
45
64
46
-
Ok(Self { encoding_key, jwks })
65
+
Ok(Self { encoding_key, jwk })
47
66
}
48
67
49
68
pub fn mint(&self, t: impl ToString) -> Result<String, TokenMintingError> {
···
55
74
let dt_exp = dt_now + Duration::from_secs(30 * 86_400);
56
75
let exp = dt_exp.as_secs();
57
76
58
-
Ok(encode(
59
-
&Header::new(Algorithm::ES256),
60
-
&Claims { sub, exp },
61
-
&self.encoding_key,
62
-
)?)
77
+
let mut header = Header::new(Algorithm::ES256);
78
+
header.kid = Some("who-am-i-00".to_string());
79
+
// todo: consider setting jku?
80
+
81
+
Ok(encode(&header, &Claims { sub, exp }, &self.encoding_key)?)
63
82
}
64
83
65
-
pub fn jwks(&self) -> String {
66
-
self.jwks.clone()
84
+
pub fn jwk(&self) -> Jwk {
85
+
self.jwk.clone()
67
86
}
68
87
}
69
88
+36
-14
who-am-i/src/main.rs
+36
-14
who-am-i/src/main.rs
···
15
15
/// eg: `cat /dev/urandom | head -c 64 | base64`
16
16
#[arg(long, env)]
17
17
app_secret: String,
18
+
/// path to at-oauth private key (PEM pk8 format)
19
+
///
20
+
/// generate with:
21
+
///
22
+
/// openssl ecparam -genkey -noout -name prime256v1 \
23
+
/// | openssl pkcs8 -topk8 -nocrypt -out <PATH-TO-PRIV-KEY>.pem
24
+
#[arg(long, env)]
25
+
oauth_private_key: Option<PathBuf>,
18
26
/// path to jwt private key (PEM pk8 format)
19
27
///
20
28
/// generate with:
···
23
31
/// | openssl pkcs8 -topk8 -nocrypt -out <PATH-TO-PRIV-KEY>.pem
24
32
#[arg(long)]
25
33
jwt_private_key: PathBuf,
26
-
/// path to pubkeys file (jwks format)
34
+
/// this server's client-reachable base url, for oauth redirect + jwt check
27
35
///
28
-
/// get pem of pubkey from private key with:
29
-
///
30
-
/// openssl ec -in <PATH-TO-PRIV-KEY>.pem -pubout
31
-
///
32
-
/// then convert to a jwk, probably with something less sketchy than an [online tool](https://jwkset.com/generate)
33
-
///
34
-
/// wrap the jwk in an array, then in an object under "keys":
35
-
///
36
-
/// { "keys": [<JWK obj>] }
37
-
#[arg(long)]
38
-
jwks: PathBuf,
36
+
/// required unless running in localhost mode with --dev
37
+
#[arg(long, env)]
38
+
base_url: Option<String>,
39
+
/// host:port to bind to on startup
40
+
#[arg(long, env, default_value = "127.0.0.1:9997")]
41
+
bind: String,
39
42
/// Enable dev mode
40
43
///
41
-
/// enables automatic template reloading
44
+
/// enables automatic template reloading, uses localhost oauth config, etc
42
45
#[arg(long, action)]
43
46
dev: bool,
44
47
/// Hosts who are allowed to one-click auth
···
57
60
58
61
let args = Args::parse();
59
62
63
+
// let bind = args.bind.to_socket_addrs().expect("--bind must be ToSocketAddrs");
64
+
65
+
let base = args.base_url.unwrap_or_else(|| {
66
+
if args.dev {
67
+
format!("http://{}", args.bind)
68
+
} else {
69
+
panic!("not in --dev mode so --base-url is required")
70
+
}
71
+
});
72
+
73
+
if !args.dev && args.oauth_private_key.is_none() {
74
+
panic!("--at-oauth-key is required except in --dev");
75
+
} else if args.dev && args.oauth_private_key.is_some() {
76
+
eprintln!("warn: --at-oauth-key is ignored in dev (localhost config)");
77
+
}
78
+
60
79
if args.allowed_hosts.is_empty() {
61
80
panic!("at least one --allowed-host host must be set");
62
81
}
···
66
85
println!(" - {host}");
67
86
}
68
87
69
-
let tokens = Tokens::from_files(args.jwt_private_key, args.jwks).unwrap();
88
+
let tokens = Tokens::from_files(args.jwt_private_key).unwrap();
70
89
71
90
if let Err(e) = install_metrics_server() {
72
91
eprintln!("failed to install metrics server: {e:?}");
···
75
94
serve(
76
95
shutdown,
77
96
args.app_secret,
97
+
args.oauth_private_key,
78
98
tokens,
99
+
base,
100
+
args.bind,
79
101
args.allowed_hosts,
80
102
args.dev,
81
103
)
+77
-21
who-am-i/src/oauth.rs
+77
-21
who-am-i/src/oauth.rs
···
1
+
use jose_jwk::Class;
2
+
use jose_jwk::Jwk;
3
+
use jose_jwk::Key;
4
+
use jose_jwk::Parameters;
5
+
use std::fs;
6
+
use std::path::PathBuf;
7
+
// use p256::SecretKey;
1
8
use atrium_api::{agent::SessionManager, types::string::Did};
2
9
use atrium_common::resolver::Resolver;
3
10
use atrium_identity::{
···
5
12
handle::{AtprotoHandleResolver, AtprotoHandleResolverConfig, DnsTxtResolver},
6
13
};
7
14
use atrium_oauth::{
8
-
AtprotoLocalhostClientMetadata, AuthorizeOptions, CallbackParams, DefaultHttpClient,
9
-
KnownScope, OAuthClient, OAuthClientConfig, OAuthResolverConfig, Scope,
15
+
AtprotoClientMetadata, AtprotoLocalhostClientMetadata, AuthMethod, AuthorizeOptions,
16
+
CallbackParams, DefaultHttpClient, GrantType, KnownScope, OAuthClient, OAuthClientConfig,
17
+
OAuthClientMetadata, OAuthResolverConfig, Scope,
10
18
store::{session::MemorySessionStore, state::MemoryStateStore},
11
19
};
20
+
use elliptic_curve::SecretKey;
12
21
use hickory_resolver::{ResolveError, TokioResolver};
22
+
use jose_jwk::JwkSet;
23
+
use pkcs8::DecodePrivateKey;
13
24
use serde::Deserialize;
14
25
use std::sync::Arc;
15
26
use thiserror::Error;
···
83
94
}
84
95
85
96
impl OAuth {
86
-
pub fn new() -> Result<Self, AuthSetupError> {
97
+
pub fn new(oauth_private_key: Option<PathBuf>, base: String) -> Result<Self, AuthSetupError> {
87
98
let http_client = Arc::new(DefaultHttpClient::default());
88
99
let did_resolver = || {
89
100
CommonDidResolver::new(CommonDidResolverConfig {
···
93
104
};
94
105
let dns_txt_resolver =
95
106
HickoryDnsTxtResolver::new().map_err(AuthSetupError::HickoryResolverError)?;
96
-
let client_config = OAuthClientConfig {
97
-
client_metadata: AtprotoLocalhostClientMetadata {
98
-
redirect_uris: Some(vec![String::from("http://127.0.0.1:9997/authorized")]),
99
-
scopes: Some(READONLY_SCOPE.to_vec()),
100
-
},
101
-
keys: None,
102
-
resolver: OAuthResolverConfig {
103
-
did_resolver: did_resolver(),
104
-
handle_resolver: AtprotoHandleResolver::new(AtprotoHandleResolverConfig {
105
-
dns_txt_resolver,
106
-
http_client: Arc::clone(&http_client),
107
-
}),
108
-
authorization_server_metadata: Default::default(),
109
-
protected_resource_metadata: Default::default(),
110
-
},
111
-
state_store: MemoryStateStore::default(),
112
-
session_store: MemorySessionStore::default(),
107
+
108
+
let resolver = OAuthResolverConfig {
109
+
did_resolver: did_resolver(),
110
+
handle_resolver: AtprotoHandleResolver::new(AtprotoHandleResolverConfig {
111
+
dns_txt_resolver,
112
+
http_client: Arc::clone(&http_client),
113
+
}),
114
+
authorization_server_metadata: Default::default(),
115
+
protected_resource_metadata: Default::default(),
113
116
};
114
117
115
-
let client = OAuthClient::new(client_config).map_err(AuthSetupError::AtriumClientError)?;
118
+
let state_store = MemoryStateStore::default();
119
+
let session_store = MemorySessionStore::default();
120
+
121
+
let client = if let Some(path) = oauth_private_key {
122
+
let key_contents: Vec<u8> = fs::read(path).unwrap();
123
+
let key_string = String::from_utf8(key_contents).unwrap();
124
+
let key = SecretKey::<p256::NistP256>::from_pkcs8_pem(&key_string)
125
+
.map(|secret_key| Jwk {
126
+
key: Key::from(&secret_key.into()),
127
+
prm: Parameters {
128
+
kid: Some("at-oauth-00".to_string()),
129
+
cls: Some(Class::Signing),
130
+
..Default::default()
131
+
},
132
+
})
133
+
.expect("to get private key");
134
+
OAuthClient::new(OAuthClientConfig {
135
+
client_metadata: AtprotoClientMetadata {
136
+
client_id: format!("{base}/client-metadata.json"),
137
+
client_uri: Some(base.clone()),
138
+
redirect_uris: vec![format!("{base}/authorized")],
139
+
token_endpoint_auth_method: AuthMethod::PrivateKeyJwt,
140
+
grant_types: vec![GrantType::AuthorizationCode, GrantType::RefreshToken],
141
+
scopes: READONLY_SCOPE.to_vec(),
142
+
jwks_uri: Some(format!("{base}/.well-known/jwks.json")),
143
+
token_endpoint_auth_signing_alg: Some(String::from("ES256")),
144
+
},
145
+
keys: Some(vec![key]),
146
+
resolver,
147
+
state_store,
148
+
session_store,
149
+
})
150
+
.map_err(AuthSetupError::AtriumClientError)?
151
+
} else {
152
+
OAuthClient::new(OAuthClientConfig {
153
+
client_metadata: AtprotoLocalhostClientMetadata {
154
+
redirect_uris: Some(vec![String::from("http://127.0.0.1:9997/authorized")]),
155
+
scopes: Some(READONLY_SCOPE.to_vec()),
156
+
},
157
+
keys: None,
158
+
resolver,
159
+
state_store,
160
+
session_store,
161
+
})
162
+
.map_err(AuthSetupError::AtriumClientError)?
163
+
};
116
164
117
165
Ok(Self {
118
166
client: Arc::new(client),
119
167
did_resolver: Arc::new(did_resolver()),
120
168
})
169
+
}
170
+
171
+
pub fn client_metadata(&self) -> OAuthClientMetadata {
172
+
self.client.client_metadata.clone()
173
+
}
174
+
175
+
pub fn jwks(&self) -> JwkSet {
176
+
self.client.jwks()
121
177
}
122
178
123
179
pub async fn begin(&self, handle: &str) -> Result<String, atrium_oauth::Error> {
+118
-41
who-am-i/src/server.rs
+118
-41
who-am-i/src/server.rs
···
1
1
use atrium_api::types::string::Did;
2
+
use atrium_oauth::OAuthClientMetadata;
2
3
use axum::{
3
4
Router,
4
-
extract::{FromRef, Query, State},
5
+
extract::{FromRef, Json as ExtractJson, Query, State},
5
6
http::{
6
7
StatusCode,
7
-
header::{CONTENT_SECURITY_POLICY, CONTENT_TYPE, HeaderMap, REFERER, X_FRAME_OPTIONS},
8
+
header::{CONTENT_SECURITY_POLICY, CONTENT_TYPE, HeaderMap, ORIGIN, REFERER},
8
9
},
9
10
response::{IntoResponse, Json, Redirect, Response},
10
11
routing::{get, post},
11
12
};
12
-
use axum_extra::extract::cookie::{Cookie, Key, SameSite, SignedCookieJar};
13
+
use axum_extra::extract::cookie::{Cookie, Expiration, Key, SameSite, SignedCookieJar};
13
14
use axum_template::{RenderHtml, engine::Engine};
14
15
use handlebars::{Handlebars, handlebars_helper};
16
+
use jose_jwk::JwkSet;
17
+
use std::path::PathBuf;
15
18
16
19
use serde::Deserialize;
17
20
use serde_json::{Value, json};
18
21
use std::collections::HashSet;
19
22
use std::sync::Arc;
20
-
use std::time::Duration;
23
+
use std::time::{Duration, SystemTime};
21
24
use tokio::net::TcpListener;
22
25
use tokio_util::sync::CancellationToken;
23
26
use url::Url;
···
29
32
const FAVICON: &[u8] = include_bytes!("../static/favicon.ico");
30
33
const STYLE_CSS: &str = include_str!("../static/style.css");
31
34
35
+
const HELLO_COOKIE_KEY: &str = "hello-who-am-i";
32
36
const DID_COOKIE_KEY: &str = "did";
33
37
34
38
const COOKIE_EXPIRATION: Duration = Duration::from_secs(30 * 86_400);
···
52
56
}
53
57
}
54
58
59
+
#[allow(clippy::too_many_arguments)]
55
60
pub async fn serve(
56
61
shutdown: CancellationToken,
57
62
app_secret: String,
63
+
oauth_private_key: Option<PathBuf>,
58
64
tokens: Tokens,
65
+
base: String,
66
+
bind: String,
59
67
allowed_hosts: Vec<String>,
60
68
dev: bool,
61
69
) {
···
70
78
// clients have to pick up their identity-resolving tasks within this period
71
79
let task_pickup_expiration = Duration::from_secs(15);
72
80
73
-
let oauth = OAuth::new().unwrap();
81
+
let oauth = OAuth::new(oauth_private_key, base).unwrap();
74
82
75
83
let state = AppState {
76
84
engine: Engine::new(hbs),
···
87
95
.route("/favicon.ico", get(favicon)) // todo MIME
88
96
.route("/style.css", get(css))
89
97
.route("/prompt", get(prompt))
90
-
.route("/user-info", get(user_info))
98
+
.route("/user-info", post(user_info))
99
+
.route("/client-metadata.json", get(client_metadata))
91
100
.route("/auth", get(start_oauth))
92
101
.route("/authorized", get(complete_oauth))
93
102
.route("/disconnect", post(disconnect))
94
103
.route("/.well-known/jwks.json", get(jwks))
95
104
.with_state(state);
96
105
97
-
let listener = TcpListener::bind("0.0.0.0:9997")
106
+
eprintln!("starting server at http://{bind}");
107
+
let listener = TcpListener::bind(bind)
98
108
.await
99
109
.expect("listener binding to work");
100
110
···
104
114
.unwrap();
105
115
}
106
116
117
+
#[derive(Debug, Deserialize)]
118
+
struct HelloQuery {
119
+
auth_reload: Option<String>,
120
+
auth_failed: Option<String>,
121
+
}
107
122
async fn hello(
108
123
State(AppState {
109
124
engine,
···
112
127
oauth,
113
128
..
114
129
}): State<AppState>,
130
+
Query(params): Query<HelloQuery>,
115
131
mut jar: SignedCookieJar,
116
132
) -> Response {
133
+
let is_auth_reload = params.auth_reload.is_some();
134
+
let auth_failed = params.auth_failed.is_some();
135
+
let no_cookie = jar.get(HELLO_COOKIE_KEY).is_none();
136
+
jar = jar.add(hello_cookie());
137
+
117
138
let info = if let Some(did) = jar.get(DID_COOKIE_KEY) {
118
139
if let Ok(did) = Did::new(did.value_trimmed().to_string()) {
119
140
// push cookie expiry
···
129
150
json!({
130
151
"did": did,
131
152
"fetch_key": fetch_key,
153
+
"is_auth_reload": is_auth_reload,
154
+
"auth_failed": auth_failed,
155
+
"no_cookie": no_cookie,
132
156
})
133
157
} else {
134
158
jar = jar.remove(DID_COOKIE_KEY);
135
-
json!({})
159
+
json!({
160
+
"is_auth_reload": is_auth_reload,
161
+
"auth_failed": auth_failed,
162
+
"no_cookie": no_cookie,
163
+
})
136
164
}
137
165
} else {
138
-
json!({})
166
+
json!({
167
+
"is_auth_reload": is_auth_reload,
168
+
"auth_failed": auth_failed,
169
+
"no_cookie": no_cookie,
170
+
})
139
171
};
140
-
let frame_headers = [
141
-
(X_FRAME_OPTIONS, "deny"),
142
-
(CONTENT_SECURITY_POLICY, "frame-ancestors 'none'"),
143
-
];
172
+
let frame_headers = [(CONTENT_SECURITY_POLICY, "frame-ancestors 'none'")];
144
173
(frame_headers, jar, RenderHtml("hello", engine, info)).into_response()
145
174
}
146
175
···
156
185
([(CONTENT_TYPE, "image/x-icon")], FAVICON)
157
186
}
158
187
188
+
fn hello_cookie() -> Cookie<'static> {
189
+
Cookie::build((HELLO_COOKIE_KEY, "hiiii"))
190
+
.http_only(true)
191
+
.secure(true)
192
+
.same_site(SameSite::None)
193
+
.expires(Expiration::DateTime(
194
+
(SystemTime::now() + COOKIE_EXPIRATION).into(),
195
+
)) // wtf safari needs this to not be a session cookie??
196
+
.max_age(COOKIE_EXPIRATION.try_into().unwrap())
197
+
.path("/")
198
+
.into()
199
+
}
200
+
159
201
fn cookie(did: &Did) -> Cookie<'static> {
160
202
Cookie::build((DID_COOKIE_KEY, did.to_string()))
161
203
.http_only(true)
162
204
.secure(true)
163
205
.same_site(SameSite::None)
206
+
.expires(Expiration::DateTime(
207
+
(SystemTime::now() + COOKIE_EXPIRATION).into(),
208
+
)) // wtf safari needs this to not be a session cookie??
164
209
.max_age(COOKIE_EXPIRATION.try_into().unwrap())
210
+
.path("/")
165
211
.into()
166
212
}
167
213
214
+
#[derive(Debug, Deserialize)]
215
+
struct PromptQuery {
216
+
// this must *ONLY* be used for the postmessage target origin
217
+
app: Option<String>,
218
+
}
168
219
async fn prompt(
169
220
State(AppState {
170
221
allowed_hosts,
···
175
226
tokens,
176
227
..
177
228
}): State<AppState>,
229
+
Query(params): Query<PromptQuery>,
178
230
jar: SignedCookieJar,
179
231
headers: HeaderMap,
180
232
) -> impl IntoResponse {
181
-
let err = |reason, check_frame| {
233
+
let err = |reason, check_frame, detail| {
182
234
metrics::counter!("whoami_auth_prompt", "ok" => "false", "reason" => reason).increment(1);
183
-
let info = json!({ "reason": reason, "check_frame": check_frame });
235
+
let info = json!({
236
+
"reason": reason,
237
+
"check_frame": check_frame,
238
+
"detail": detail,
239
+
});
184
240
let html = RenderHtml("prompt-error", engine.clone(), info);
185
241
(StatusCode::BAD_REQUEST, html).into_response()
186
242
};
187
243
188
-
let Some(referrer) = headers.get(REFERER) else {
189
-
return err("Missing referer", true);
244
+
let Some(parent) = headers.get(ORIGIN).or_else(|| {
245
+
eprintln!("referrer fallback");
246
+
// TODO: referer should only be used for localhost??
247
+
headers.get(REFERER)
248
+
}) else {
249
+
return err("Missing origin and no referrer for fallback", true, None);
190
250
};
191
-
let Ok(referrer) = referrer.to_str() else {
192
-
return err("Unreadable referer", true);
251
+
let Ok(parent) = parent.to_str() else {
252
+
return err("Unreadable origin or referrer", true, None);
193
253
};
194
-
let Ok(url) = Url::parse(referrer) else {
195
-
return err("Bad referer", true);
254
+
eprintln!(
255
+
"rolling with parent: {parent:?} (from origin? {})",
256
+
headers.get(ORIGIN).is_some()
257
+
);
258
+
let Ok(url) = Url::parse(parent) else {
259
+
return err("Bad origin or referrer", true, None);
196
260
};
197
261
let Some(parent_host) = url.host_str() else {
198
-
return err("Referer missing host", true);
262
+
return err("Origin or referrer missing host", true, None);
199
263
};
200
264
if !allowed_hosts.contains(parent_host) {
201
-
return err("Login is not allowed on this page", false);
265
+
return err(
266
+
"Login is not allowed on this page",
267
+
false,
268
+
Some(parent_host),
269
+
);
270
+
}
271
+
if let Some(ref app) = params.app
272
+
&& !allowed_hosts.contains(app)
273
+
{
274
+
return err("Login is not allowed for this app", false, Some(app));
202
275
}
203
276
let parent_origin = url.origin().ascii_serialization();
204
277
if parent_origin == "null" {
205
-
return err("Referer origin is opaque", true);
278
+
return err("Origin or referrer header value is opaque", true, None);
206
279
}
207
280
208
-
let frame_headers = [
209
-
(X_FRAME_OPTIONS, format!("allow-from {parent_origin}")),
210
-
(
211
-
CONTENT_SECURITY_POLICY,
212
-
format!("frame-ancestors {parent_origin}"),
213
-
),
214
-
];
281
+
let all_allowed = allowed_hosts
282
+
.iter()
283
+
.map(|h| format!("https://{h}"))
284
+
.collect::<Vec<_>>()
285
+
.join(" ");
286
+
let csp = format!("frame-ancestors 'self' {parent_origin} {all_allowed}");
287
+
let frame_headers = [(CONTENT_SECURITY_POLICY, &csp)];
215
288
216
289
if let Some(did) = jar.get(DID_COOKIE_KEY) {
217
290
let Ok(did) = Did::new(did.value_trimmed().to_string()) else {
218
-
return err("Bad cookie", false);
291
+
return err("Bad cookie", false, None);
219
292
};
220
293
221
294
// push cookie expiry
···
225
298
Ok(t) => t,
226
299
Err(e) => {
227
300
eprintln!("failed to create JWT: {e:?}");
228
-
return err("failed to create JWT", false);
301
+
return err("failed to create JWT", false, None);
229
302
}
230
303
};
231
304
···
245
318
"fetch_key": fetch_key,
246
319
"parent_host": parent_host,
247
320
"parent_origin": parent_origin,
321
+
"parent_target": params.app.map(|h| format!("https://{h}")),
248
322
});
249
323
(frame_headers, jar, RenderHtml("prompt", engine, info)).into_response()
250
324
} else {
···
258
332
}
259
333
260
334
#[derive(Debug, Deserialize)]
261
-
#[serde(rename_all = "kebab-case")]
262
335
struct UserInfoParams {
263
336
fetch_key: String,
264
337
}
···
266
339
State(AppState {
267
340
resolve_handles, ..
268
341
}): State<AppState>,
269
-
Query(params): Query<UserInfoParams>,
342
+
ExtractJson(params): ExtractJson<UserInfoParams>,
270
343
) -> impl IntoResponse {
271
344
let err = |status, reason: &str| {
272
345
metrics::counter!("whoami_user_info", "found" => "false", "reason" => reason.to_string())
···
306
379
Json(json!({ "handle": handle })).into_response()
307
380
}
308
381
}
382
+
}
383
+
384
+
async fn client_metadata(
385
+
State(AppState { oauth, .. }): State<AppState>,
386
+
) -> Json<OAuthClientMetadata> {
387
+
Json(oauth.client_metadata())
309
388
}
310
389
311
390
#[derive(Debug, Deserialize)]
···
439
518
(jar, Json(json!({ "ok": true })))
440
519
}
441
520
442
-
async fn jwks(State(AppState { tokens, .. }): State<AppState>) -> impl IntoResponse {
443
-
let headers = [
444
-
(CONTENT_TYPE, "application/json"),
445
-
// (CACHE_CONTROL, "") // TODO
446
-
];
447
-
(headers, tokens.jwks())
521
+
async fn jwks(State(AppState { oauth, tokens, .. }): State<AppState>) -> Json<JwkSet> {
522
+
let mut jwks = oauth.jwks();
523
+
jwks.keys.push(tokens.jwk());
524
+
Json(jwks)
448
525
}
+24
-1
who-am-i/static/style.css
+24
-1
who-am-i/static/style.css
···
12
12
overflow: hidden;
13
13
display: flex;
14
14
flex-direction: column;
15
-
height: 100vh;
15
+
min-height: 100vh;
16
16
}
17
17
.wrap.unframed {
18
18
border-radius: 0;
···
60
60
max-width: 21rem;
61
61
}
62
62
63
+
.explain {
64
+
border-bottom: 1px dashed #888;
65
+
margin-bottom: 1rem;
66
+
padding-bottom: 2rem;
67
+
}
68
+
.explain p {
69
+
text-align: left;
70
+
}
71
+
63
72
#error-message {
64
73
font-size: 0.8rem;
65
74
color: #a31;
···
77
86
p.detail {
78
87
font-size: 0.8rem;
79
88
}
89
+
p.detail.no {
90
+
font-style: italic;
91
+
}
80
92
.parent-host {
81
93
font-weight: bold;
82
94
color: #48c;
···
153
165
color: #285;
154
166
}
155
167
168
+
#need-storage {
169
+
font-size: 0.8rem;
170
+
}
171
+
.problem {
172
+
color: #a31;
173
+
}
174
+
156
175
#or {
157
176
font-size: 0.8rem;
158
177
text-align: center;
···
170
189
.hidden {
171
190
display: none !important;
172
191
}
192
+
193
+
.hello-connect-plz {
194
+
margin: 1.667rem 0 0.667rem;
195
+
}
+54
-6
who-am-i/templates/hello.hbs
+54
-6
who-am-i/templates/hello.hbs
···
2
2
3
3
{{#*inline "main"}}
4
4
<div class="mini-content">
5
-
This is a little identity-verifying service for microcosm demos.
5
+
<div class="explain">
6
+
<p>This is a little identity-verifying service for microcosm demos.</p>
7
+
<p>Only <strong>read access to your public data</strong> is required to connect: connecting does not grant any ability to modify your account or data.</p>
8
+
</div>
6
9
7
10
{{#if did}}
8
11
<p id="error-message" class="hidden"></p>
···
38
41
({{{json did}}}) && (async () => {
39
42
40
43
const handle = await lookUp({{{json fetch_key}}});
41
-
console.log('got handle', handle);
42
44
43
45
loaderEl.classList.add('hidden');
44
46
handleViewEl.textContent = `@${handle}`;
···
49
51
} catch (e) {
50
52
err(e, 'failed to clear session, sorry');
51
53
}
52
-
window.location.reload();
54
+
window.location.replace(location.pathname);
55
+
window.location.reload(); // backup, in case there is no query?
53
56
});
54
57
})();
55
58
56
59
async function lookUp(fetch_key) {
57
-
const user_info = new URL('/user-info', window.location);
58
-
user_info.searchParams.set('fetch-key', fetch_key);
59
60
let info;
60
61
try {
61
-
const resp = await fetch(user_info);
62
+
const resp = await fetch('/user-info', {
63
+
method: 'POST',
64
+
headers: {'Content-Type': 'application/json'},
65
+
body: JSON.stringify({ fetch_key }),
66
+
});
62
67
if (!resp.ok) throw resp;
63
68
info = await resp.json();
64
69
} catch (e) {
···
67
72
return info.handle;
68
73
}
69
74
</script>
75
+
{{else}}
76
+
77
+
<p class="hello-connect-plz">Connect your handle</p>
78
+
79
+
{{#if is_auth_reload}}
80
+
{{#if no_cookie}}
81
+
<p id="prompt" class="detail no">
82
+
No identity connected. Your browser may be blocking access for connecting.
83
+
</p>
84
+
{{else}}
85
+
{{#if auth_failed}}
86
+
<p id="prompt" class="detail no">
87
+
No identity connected. Connecting failed or was denied.
88
+
</p>
89
+
{{else}}
90
+
<p id="prompt" class="detail no">
91
+
No identity connected.
92
+
</p>
93
+
{{/if}}
94
+
{{/if}}
95
+
{{/if}}
96
+
97
+
<div id="user-info">
98
+
<form id="form-action" action="/auth" target="_blank" method="GET" class="action {{#if did}}hidden{{/if}}">
99
+
<label>
100
+
@<input id="handle-input" class="handle" name="handle" placeholder="example.bsky.social" />
101
+
</label>
102
+
<button id="connect" type="submit">connect</button>
103
+
</form>
104
+
</div>
70
105
{{/if}}
106
+
71
107
</div>
108
+
<script>
109
+
window.addEventListener('storage', e => {
110
+
console.log('eyyy got storage', e);
111
+
if (e.key !== 'who-am-i') return;
112
+
if (!e.newValue) return;
113
+
if (e.newValue.result === 'success') {
114
+
window.location = '/?auth_reload=1';
115
+
} else {
116
+
window.location = '/?auth_reload=1&auth_failed=1';
117
+
}
118
+
});
119
+
</script>
72
120
{{/inline}}
73
121
74
122
{{#> base-full}}{{/base-full}}
+1
who-am-i/templates/prompt-error.hbs
+1
who-am-i/templates/prompt-error.hbs
···
2
2
<div class="prompt-error">
3
3
<p class="went-wrong">Something went wrong :(</p>
4
4
<p class="reason">{{ reason }}</p>
5
+
<p class="reason detail">{{ detail }}</p>
5
6
<p id="maybe-not-in-iframe" class="hidden">
6
7
Possibly related: this prompt is meant to be shown in an iframe, but it seems like it's not.
7
8
</p>
+67
-25
who-am-i/templates/prompt.hbs
+67
-25
who-am-i/templates/prompt.hbs
···
6
6
<p id="error-message" class="hidden"></p>
7
7
8
8
<p id="prompt" class="detail">
9
-
<span class="parent-host">{{ parent_host }}</span> would like to confirm your handle
9
+
<span class="parent-host">{{ parent_host }}</span> wants to confirm your handle
10
10
</p>
11
11
12
12
<div id="loader" {{#unless did}}class="hidden"{{/unless}}>
···
27
27
</div>
28
28
</div>
29
29
30
+
<div id="need-storage" class="hidden">
31
+
<p class="problem">Sorry, your browser is blocking access.</p>
32
+
<p>
33
+
Try <a href="/" target="_blank">connecting directly</a> first (but no promises).
34
+
Clicking <button id="desperation">this button</button> might also help.
35
+
</p>
36
+
</div>
37
+
30
38
31
39
32
40
<script>
···
39
47
const formEl = document.getElementById('form-action'); // for anon
40
48
const allowEl = document.getElementById('handle-action'); // for known-did
41
49
const connectEl = document.getElementById('connect'); // for anon
50
+
const needStorageEl = document.getElementById('need-storage'); // for safari/frame isolation
51
+
const desperationEl = document.getElementById('desperation');
42
52
43
53
function err(e, msg) {
44
54
loaderEl.classList.add('hidden');
···
49
59
50
60
// already-known user
51
61
({{{json did}}}) && (async () => {
52
-
53
62
const handle = await lookUp({{{json fetch_key}}});
54
-
console.log('got handle', handle);
55
-
56
63
loaderEl.classList.add('hidden');
57
64
handleViewEl.textContent = `@${handle}`;
58
65
allowEl.addEventListener('click', () => shareAllow(handle, {{{json token}}}));
···
69
76
window.open(url, '_blank');
70
77
};
71
78
79
+
// check if we may be partitioned, preventing access after auth completion
80
+
// this should only happen if on a browser that implements storage access api
81
+
if ('hasStorageAccess' in document) {
82
+
document.hasStorageAccess().then((hasAccess) => {
83
+
if (!hasAccess) {
84
+
promptEl.classList.add('hidden');
85
+
infoEl.classList.add('hidden');
86
+
needStorageEl.classList.remove('hidden');
87
+
desperation.addEventListener('click', () => {
88
+
document.requestStorageAccess({
89
+
cookies: true,
90
+
localStorage: true,
91
+
}).then(
92
+
() => {
93
+
desperation.textContent = "(maybe helped?)";
94
+
setTimeout(() => location.reload(), 350);
95
+
},
96
+
() => desperation.textContent = "(doubtful)",
97
+
);
98
+
})
99
+
}
100
+
});
101
+
}
102
+
72
103
window.addEventListener('storage', async e => {
73
104
// here's a fun minor vuln: we can't tell which flow triggers the storage event.
74
105
// so if you have two flows going, it grants for both (or the first responder?) if you grant for either.
75
106
// (letting this slide while parent pages are allowlisted to microcosm only)
76
107
77
-
const fail = (e, msg) => {
78
-
loaderEl.classList.add('hidden');
79
-
formEl.classList.remove('hidden');
80
-
handleInputEl.focus();
81
-
handleInputEl.select();
82
-
err(e, msg);
83
-
}
108
+
if (e.key !== 'who-am-i') return;
109
+
if (e.newValue === null) return;
84
110
85
-
const details = localStorage.getItem("who-am-i");
111
+
const details = e.newValue;
86
112
if (!details) {
87
-
console.error("hmm, heard from localstorage but did not get DID");
88
-
return;
113
+
console.error("hmm, heard from localstorage but did not get DID", details, e);
114
+
err('sorry, something went wrong getting your details');
89
115
}
90
-
localStorage.removeItem("who-am-i");
91
116
92
117
let parsed;
93
118
try {
···
96
121
err(e, "something went wrong getting the details back");
97
122
}
98
123
124
+
const fail = (e, msg) => {
125
+
loaderEl.classList.add('hidden');
126
+
formEl.classList.remove('hidden');
127
+
handleInputEl.focus();
128
+
handleInputEl.select();
129
+
err(e, msg);
130
+
}
131
+
99
132
if (parsed.result === "fail") {
100
133
fail(`uh oh: ${parsed.reason}`);
101
134
}
···
108
141
109
142
const handle = await lookUp(parsed.fetch_key);
110
143
111
-
shareAllow(handle, token);
144
+
shareAllow(handle, parsed.token);
112
145
});
113
146
114
147
async function lookUp(fetch_key) {
115
-
const user_info = new URL('/user-info', window.location);
116
-
user_info.searchParams.set('fetch-key', fetch_key);
117
148
let info;
118
149
try {
119
-
const resp = await fetch(user_info);
150
+
const resp = await fetch('/user-info', {
151
+
method: 'POST',
152
+
headers: { 'Content-Type': 'application/json' },
153
+
body: JSON.stringify({ fetch_key }),
154
+
});
120
155
if (!resp.ok) throw resp;
121
156
info = await resp.json();
122
157
} catch (e) {
123
-
err(e, 'failed to resolve handle from DID')
158
+
err(e, `failed to resolve handle from DID with ${fetch_key}`);
124
159
}
125
160
return info.handle;
126
161
}
127
162
163
+
const parentTarget = {{{json parent_target}}} ?? {{{json parent_origin}}};
164
+
128
165
const shareAllow = (handle, token) => {
129
-
top.postMessage(
130
-
{ action: "allow", handle, token },
131
-
{{{json parent_origin}}},
132
-
);
166
+
try {
167
+
top.postMessage(
168
+
{ action: "allow", handle, token },
169
+
parentTarget,
170
+
);
171
+
} catch (e) {
172
+
err(e, 'Identity verified but failed to connect with app');
173
+
};
174
+
promptEl.textContent = '✔️ shared';
133
175
}
134
176
135
177
const shareDeny = reason => {
136
178
top.postMessage(
137
179
{ action: "deny", reason },
138
-
{{{json parent_origin}}},
180
+
parentTarget,
139
181
);
140
182
}
141
183
</script>