The five modules underneath this backend that were never about AI sessions -- the pinned CA and leaf, QR enrollment and the bearer token, wg0 binding and the certificate's SANs, owner-only files, and the RON house rules -- were written twice, once here and once in dev-updater, and had drifted. They now come from the submodule, as a path dependency so both projects stay locked to one commit. What stayed is what makes this project itself: the routes, the drivers, the config schema, and the auth middleware, which is generic over this server's state. Sharing a transport is worth doing; sharing an API would mean inventing a vocabulary neither project wants. Four dependencies go with the code -- rcgen, qrcode, subtle and if-addrs are no longer named here at all -- and the three that remain are now described by what still uses them rather than by what used to. Verified by running it, not only by building: a fresh server generates its CA, prints an `aiapp://enroll` QR with the scheme now passed as a parameter, covers 127.0.0.1, 10.0.2.2 and wg0's 10.66.0.1 in the leaf, answers an enrolled token and returns 401 without one, and writes config.ron in the house rules with every file owner-only. 36 tests pass, clippy is silent, rustfmt is clean.
51 lines
2.1 KiB
TOML
51 lines
2.1 KiB
TOML
[package]
|
|
name = "ai-server"
|
|
version = "0.1.0"
|
|
edition = "2024"
|
|
|
|
[[bin]]
|
|
name = "ai-server"
|
|
path = "src/main.rs"
|
|
|
|
[dependencies]
|
|
# The link both this and dev-updater need in order to be reached from a
|
|
# phone: wg binding, the pinned CA, QR enrollment, owner-only files, and
|
|
# the RON house rules. Extracted from the two copies that had drifted --
|
|
# see that repo's README for the evidence and the bug the extraction found.
|
|
wg-app-link = { path = "../wg-app-link/server" }
|
|
axum = { version = "0.8", features = ["json", "multipart"] }
|
|
axum-server = { version = "0.8", features = ["tls-rustls"] }
|
|
tokio = { version = "1", features = ["rt-multi-thread", "macros", "net", "sync", "time", "process", "io-util", "signal"] }
|
|
tokio-stream = "0.1"
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
# The config file's format. Not JSON, because this file is written and read
|
|
# by hand and RON says a sum type as syntax. The two house rules both
|
|
# projects write it under live in wg-app-link; this is here for the error
|
|
# types the schema's own signatures name.
|
|
ron = "0.12.2"
|
|
clap = { version = "4", features = ["derive"] }
|
|
anyhow = "1"
|
|
thiserror = "2"
|
|
# Verifying a downloaded model against HuggingFace's published digest.
|
|
sha2 = "0.11"
|
|
# Naming a session directory, and an attachment inside one.
|
|
rand = "0.10"
|
|
# Decoding the images a phone attaches, and encoding them for a driver.
|
|
base64 = "0.23"
|
|
# Outbound HTTPS for the usage endpoint. A small blocking client fits an
|
|
# every-few-minutes poll better than pulling in reqwest's tower stack;
|
|
# rustls-backed like the rest of the TLS here.
|
|
ureq = { version = "3", features = ["json"] }
|
|
# Direct dependency only to pick the process-level CryptoProvider in main:
|
|
# ureq pulls rustls-with-ring, axum-server rustls-with-aws-lc-rs, and with
|
|
# both in the graph rustls refuses to auto-select one.
|
|
rustls = "0.23"
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3"
|
|
# ServiceExt::oneshot, to drive the auth middleware without a socket.
|
|
tower = { version = "0.5", features = ["util"] }
|