Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bad65135aa | ||
|
|
8106f8943e | ||
|
|
2596b357ec | ||
|
|
2c9367a83c | ||
|
|
8ff33817a8 | ||
|
|
b6f138b90d | ||
|
|
4027d3eb17 | ||
|
|
5f1e3ace5c | ||
|
|
0f2b776bb8 | ||
|
|
5717f8aaaa | ||
|
|
52d9e1e93e | ||
|
|
19941156b4 | ||
|
|
b2d3f32d83 | ||
|
|
4d851c5a58 | ||
|
|
db4f277336 | ||
|
|
6a4b2b8f54 | ||
|
|
d119821339 | ||
|
|
ca39dea5db | ||
|
|
8dec413005 | ||
|
|
4043a681db | ||
|
|
7cdf52544c | ||
|
|
fa14529aa2 | ||
|
|
4b6e9f35ef | ||
|
|
5684938b4c | ||
|
|
c830d2b949 | ||
|
|
d3c35eccd0 | ||
|
|
e7a932f716 | ||
|
|
3c04aa44b6 | ||
|
|
5a2bb634a1 | ||
|
|
6c8c98e86c | ||
|
|
c995b2b937 | ||
|
|
90322b5f97 | ||
|
|
8a3869773c | ||
|
|
12a1ab10d0 |
+60
-18
@@ -28,10 +28,10 @@ jobs:
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
with:
|
||||
components: clippy
|
||||
- name: Clippy (all features)
|
||||
run: cargo clippy --all-features -- -D warnings
|
||||
- name: Clippy (no default features)
|
||||
run: cargo clippy --no-default-features -- -D warnings
|
||||
- name: Clippy (workspace, all features)
|
||||
run: cargo clippy --workspace --all-features -- -D warnings
|
||||
- name: Clippy (workspace, no default features)
|
||||
run: cargo clippy --workspace --no-default-features -- -D warnings
|
||||
|
||||
test-matrix:
|
||||
name: Test (${{ matrix.name }})
|
||||
@@ -40,16 +40,53 @@ jobs:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- name: default features
|
||||
flags: ""
|
||||
- name: all features
|
||||
flags: "--all-features"
|
||||
- name: io only
|
||||
flags: "--no-default-features --features io"
|
||||
- name: compute only
|
||||
flags: "--no-default-features --features compute"
|
||||
- name: bg only
|
||||
flags: "--no-default-features --features bg"
|
||||
# Whole-workspace sanity passes.
|
||||
- name: workspace default features
|
||||
flags: "--workspace"
|
||||
- name: workspace all features
|
||||
flags: "--workspace --all-features"
|
||||
# mytheclipse: execution primitives + resiliency/traffic/lifecycle/observability
|
||||
- name: mytheclipse / io only
|
||||
flags: "-p mytheclipse --no-default-features --features io"
|
||||
- name: mytheclipse / compute only
|
||||
flags: "-p mytheclipse --no-default-features --features compute"
|
||||
- name: mytheclipse / bg only
|
||||
flags: "-p mytheclipse --no-default-features --features bg"
|
||||
- name: mytheclipse / resiliency only
|
||||
flags: "-p mytheclipse --no-default-features --features resiliency"
|
||||
- name: mytheclipse / traffic only
|
||||
flags: "-p mytheclipse --no-default-features --features traffic"
|
||||
- name: mytheclipse / lifecycle only
|
||||
flags: "-p mytheclipse --no-default-features --features lifecycle"
|
||||
- name: mytheclipse / observability only
|
||||
flags: "-p mytheclipse --no-default-features --features observability"
|
||||
# mytheclipse-cache
|
||||
- name: mytheclipse-cache / default
|
||||
flags: "-p mytheclipse-cache"
|
||||
- name: mytheclipse-cache / l1-moka
|
||||
flags: "-p mytheclipse-cache --no-default-features --features l1-moka"
|
||||
- name: mytheclipse-cache / l2-redis
|
||||
flags: "-p mytheclipse-cache --no-default-features --features l1-memory,l2-redis"
|
||||
# mytheclipse-storage
|
||||
- name: mytheclipse-storage / default (local)
|
||||
flags: "-p mytheclipse-storage"
|
||||
- name: mytheclipse-storage / s3
|
||||
flags: "-p mytheclipse-storage --no-default-features --features s3"
|
||||
- name: mytheclipse-storage / gcs
|
||||
flags: "-p mytheclipse-storage --no-default-features --features gcs"
|
||||
# mytheclipse-event
|
||||
- name: mytheclipse-event / default (mem)
|
||||
flags: "-p mytheclipse-event"
|
||||
- name: mytheclipse-event / amqp
|
||||
flags: "-p mytheclipse-event --no-default-features --features amqp"
|
||||
- name: mytheclipse-event / nats
|
||||
flags: "-p mytheclipse-event --no-default-features --features nats"
|
||||
# mytheclipse-config
|
||||
- name: mytheclipse-config / default
|
||||
flags: "-p mytheclipse-config"
|
||||
# mytheclipse-crypto
|
||||
- name: mytheclipse-crypto / default
|
||||
flags: "-p mytheclipse-crypto"
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
@@ -59,12 +96,12 @@ jobs:
|
||||
run: cargo test ${{ matrix.flags }}
|
||||
|
||||
example:
|
||||
name: Run example
|
||||
name: Run mytheclipse example
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
- run: cargo run --example main --features full
|
||||
- run: cargo run -p mytheclipse --example main --features full
|
||||
|
||||
docs:
|
||||
name: Docs check
|
||||
@@ -72,13 +109,18 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
- run: RUSTDOCFLAGS="-D warnings" cargo doc --all-features --no-deps
|
||||
- run: RUSTDOCFLAGS="-D warnings" cargo doc --workspace --all-features --no-deps
|
||||
|
||||
package:
|
||||
name: Cargo package dry-run
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
crate:
|
||||
[mytheclipse, mytheclipse-cache, mytheclipse-storage, mytheclipse-event, mytheclipse-config, mytheclipse-crypto]
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
- name: Package
|
||||
run: cargo package --no-verify
|
||||
run: cargo package -p ${{ matrix.crate }} --no-verify
|
||||
|
||||
@@ -3,6 +3,15 @@ name: Publish to crates.io
|
||||
on:
|
||||
push:
|
||||
tags: ["v*.*.*"]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
tag:
|
||||
description: "Git tag to publish (e.g. v0.2.0). Defaults to latest tag."
|
||||
required: false
|
||||
type: string
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
@@ -10,8 +19,21 @@ jobs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ inputs.tag || github.event.ref || github.ref }}
|
||||
fetch-depth: 0
|
||||
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
- name: Publish mytheclipse
|
||||
run: cargo publish --allow-dirty --no-verify
|
||||
|
||||
# The workspace crates have no interdependencies, so publish order
|
||||
# doesn't matter for crates.io dependency resolution. A brief sleep
|
||||
# between publishes avoids hitting crates.io's rate limit.
|
||||
- name: Publish workspace crates
|
||||
run: |
|
||||
for crate in mytheclipse mytheclipse-cache mytheclipse-storage mytheclipse-event mytheclipse-config mytheclipse-crypto; do
|
||||
echo "Publishing $crate..."
|
||||
cargo publish -p "$crate" --allow-dirty --no-verify
|
||||
sleep 15
|
||||
done
|
||||
env:
|
||||
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
||||
@@ -0,0 +1,46 @@
|
||||
name: Release
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
issues: write
|
||||
pull-requests: write
|
||||
actions: write
|
||||
|
||||
jobs:
|
||||
release:
|
||||
name: Semantic Release
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Setup Rust toolchain
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Setup Node.js
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: "lts/*"
|
||||
|
||||
- name: Install semantic-release
|
||||
run: |
|
||||
npm install -D \
|
||||
semantic-release \
|
||||
@semantic-release/exec \
|
||||
@semantic-release/git \
|
||||
@semantic-release/changelog \
|
||||
@semantic-release/github
|
||||
|
||||
- name: Run semantic-release
|
||||
id: semantic-release
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
run: npx semantic-release
|
||||
+2
-1
@@ -1,5 +1,6 @@
|
||||
# Cargo build artifacts
|
||||
# Cargo build artifacts (workspace root and any nested crate target dirs)
|
||||
/target
|
||||
target/
|
||||
|
||||
# Editor / OS noise
|
||||
.DS_Store
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
# Implementation Spec: New Features for mytheclipse
|
||||
|
||||
## Status: COMPLETE
|
||||
|
||||
## Summary
|
||||
|
||||
Added 4 new crates and enhancements to existing crates to expand mytheclipse's
|
||||
abstraction layer coverage. All code compiles with `cargo build --workspace --all-features`,
|
||||
all tests pass, and clippy is clean.
|
||||
|
||||
## New Crates
|
||||
|
||||
1. **mytheclipse-queue** (`crates/mytheclipse-queue/`)
|
||||
- `Queue` trait: enqueue, dequeue, ack, nack, dlq_move, len
|
||||
- `Job` / `JobId` types with payload + metadata
|
||||
- `WorkerPool` with configurable concurrency, retry/backoff, dead-letter queue
|
||||
- `JobHandler` trait for processing jobs
|
||||
- Backend: in-memory (default), Redis (feature `redis`), NATS (feature `nats`), PostgreSQL (feature `postgres`)
|
||||
|
||||
2. **mytheclipse-tracing** (`crates/mytheclipse-tracing/`)
|
||||
- `TracingLayer` with env-filter support and subscriber builder
|
||||
- `OtelLayer` for OTLP/Jaeger export (feature `otel`, `jaeger`, `full`)
|
||||
- Features: `env` (default), `otel`, `jaeger`, `full`
|
||||
|
||||
3. **mytheclipse-http** (`crates/mytheclipse-http/`)
|
||||
- `HttpClient` wrapping reqwest with timeout + tracing instrumentation
|
||||
- `HttpServer` (axum) with health endpoint + graceful shutdown
|
||||
- Features: `client` (default), `server-axum`, `server-hyper`
|
||||
|
||||
4. **mytheclipse-cli** (`crates/mytheclipse-cli/`)
|
||||
- `CliApp` / `CliBuilder` with clap derive
|
||||
- Subcommands: `serve`, `worker`, `migrate`, `health`, `version`
|
||||
- Feature: `clap-derive` (default)
|
||||
|
||||
## Enhancements to Existing Crates
|
||||
|
||||
### mytheclipse (core)
|
||||
- `pool.rs`: `SemaphorePool<T>` with `Pool` trait, `Pooled<T>` RAII permit
|
||||
- `health.rs`: `HealthRegistry`, `HealthCheck` trait, `HealthStatus` enum
|
||||
- `leader.rs`: `LeaderElection` trait, `InProcLeaderElection` impl
|
||||
- Features: gated under `traffic` (pool) and `lifecycle` (health, leader)
|
||||
|
||||
### mytheclipse-cache
|
||||
- `auto_refresh.rs`: `AutoRefreshCache` — background refresh on cache miss
|
||||
- `metrics.rs`: `CacheMetrics` + `CacheSnapshot` with hit/miss/eviction tracking
|
||||
- Added `tokio` optional dep (used by cache-aside + auto-refresh)
|
||||
|
||||
### mytheclipse-config
|
||||
- `schema.rs`: `ConfigSchema` + `PropertySchema` for JSON Schema generation
|
||||
- Feature `schema` gated
|
||||
|
||||
### mytheclipse-storage
|
||||
- `multipart.rs`: `MultipartUploadDriver` trait + `MultipartUpload` handler
|
||||
- Feature `multipart` (default) gated
|
||||
|
||||
### mytheclipse-crypto
|
||||
- `paseto.rs`: `PasetoSigner` + `PasetoClaims` for PASETO v4.local tokens
|
||||
- Features `paseto` and `rate-limit` added
|
||||
|
||||
## Verification
|
||||
- `cargo build --workspace --all-features` ✓
|
||||
- `cargo test --workspace --all-features` ✓ (all pass, 1 ignored doctest)
|
||||
- `cargo clippy --workspace --all-features` ✓ (no warnings)
|
||||
@@ -0,0 +1,34 @@
|
||||
{
|
||||
"branches": [
|
||||
"main"
|
||||
],
|
||||
"plugins": [
|
||||
"@semantic-release/commit-analyzer",
|
||||
"@semantic-release/release-notes-generator",
|
||||
"@semantic-release/changelog",
|
||||
[
|
||||
"@semantic-release/exec",
|
||||
{
|
||||
"prepareCmd": "for f in crates/*/Cargo.toml; do sed -i 's/^version = \\\"[^\\\"]*\\\"/version = \\\"${nextRelease.version}\\\"/' \"$f\"; done && cargo check --workspace",
|
||||
"successCmd": "gh api -X POST repos/asepharyana/mytheclipse/actions/workflows/publish.yml/dispatches -f ref=main -f 'inputs[tag]=v${nextRelease.version}'"
|
||||
}
|
||||
],
|
||||
[
|
||||
"@semantic-release/git",
|
||||
{
|
||||
"assets": [
|
||||
"crates/*/Cargo.toml",
|
||||
"Cargo.lock",
|
||||
"CHANGELOG.md"
|
||||
],
|
||||
"message": "chore(release): ${nextRelease.version} [skip ci]\n\n${nextRelease.notes}"
|
||||
}
|
||||
],
|
||||
[
|
||||
"@semantic-release/github",
|
||||
{
|
||||
"assets": []
|
||||
}
|
||||
]
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,55 @@
|
||||
# [1.4.0](https://github.com/asepharyana/mytheclipse/compare/v1.3.5...v1.4.0) (2026-08-29)
|
||||
|
||||
|
||||
### Features
|
||||
|
||||
* add 4 new crates (queue, tracing, http, cli) + enhancements to existing crates ([8106f89](https://github.com/asepharyana/mytheclipse/commit/8106f8943ebe83f7348b9fde3fbd2e347018604e))
|
||||
|
||||
## [1.3.5](https://github.com/asepharyana/mytheclipse/compare/v1.3.4...v1.3.5) (2026-08-28)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* **cache:** honor sub-second Redis TTL via PSETEX + document clear() safety ([2c9367a](https://github.com/asepharyana/mytheclipse/commit/2c9367a83c2dd01b1e197ec33215a6c7d3755fa2))
|
||||
|
||||
## [1.3.4](https://github.com/asepharyana/mytheclipse/compare/v1.3.3...v1.3.4) (2026-08-28)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* **cache,storage:** harden cache bounds + atomic disk writes ([b6f138b](https://github.com/asepharyana/mytheclipse/commit/b6f138b90d67c9531b5a58993e8ec750e5eec57f))
|
||||
|
||||
## [1.3.3](https://github.com/asepharyana/mytheclipse/compare/v1.3.2...v1.3.3) (2026-08-28)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* **publish:** trim mytheclipse keywords to 5 to satisfy crates.io limit ([5f1e3ac](https://github.com/asepharyana/mytheclipse/commit/5f1e3ace5c8cb10881e30f550f51b7d845b24edd))
|
||||
|
||||
## [1.3.2](https://github.com/asepharyana/mytheclipse/compare/v1.3.1...v1.3.2) (2026-08-28)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* **ci:** gate cache & storage crate doctests behind their features ([5717f8a](https://github.com/asepharyana/mytheclipse/commit/5717f8aaaae34cb66cdbfc31f4982c93816ee5a3))
|
||||
|
||||
## [1.3.1](https://github.com/asepharyana/mytheclipse/compare/v1.3.0...v1.3.1) (2026-08-28)
|
||||
|
||||
|
||||
### Bug Fixes
|
||||
|
||||
* **ci:** gate event crate doctest behind mem feature and apply rustfmt ([1994115](https://github.com/asepharyana/mytheclipse/commit/19941156b43ec58370d0d1369174ec84400e9bc9))
|
||||
|
||||
# [1.3.0](https://github.com/asepharyana/mytheclipse/compare/v1.2.0...v1.3.0) (2026-08-28)
|
||||
|
||||
|
||||
### Features
|
||||
|
||||
* add corex-storage crate for unified storage abstraction ([db4f277](https://github.com/asepharyana/mytheclipse/commit/db4f277336d1e32cb6a2ddd86ac37ae9789fa4f8))
|
||||
|
||||
# [1.2.0](https://github.com/asepharyana/mytheclipse/compare/v1.1.0...v1.2.0) (2026-08-28)
|
||||
|
||||
|
||||
### Features
|
||||
|
||||
* add panic tracking and logging with PanicTracker ([d119821](https://github.com/asepharyana/mytheclipse/commit/d1198213391710ccc6f2c108b15aa4526380423d))
|
||||
Generated
+5302
-19
File diff suppressed because it is too large
Load Diff
+14
-40
@@ -1,40 +1,14 @@
|
||||
[package]
|
||||
name = "mytheclipse"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
repository = "https://github.com/asepharyana/corex"
|
||||
homepage = "https://github.com/asepharyana/corex"
|
||||
documentation = "https://docs.rs/mytheclipse"
|
||||
authors = ["asepharyana <superaseph@gmail.com>"]
|
||||
description = "Resource-aware abstractions for async I/O, heavy compute, and background queue management."
|
||||
readme = "README.md"
|
||||
keywords = ["async", "concurrency", "rayon", "tokio", "resource-management"]
|
||||
categories = ["asynchronous", "concurrency", "rust-patterns"]
|
||||
|
||||
[dependencies]
|
||||
tokio = { version = "1.53", features = ["full"], optional = true }
|
||||
rayon = { version = "1.12", optional = true }
|
||||
num_cpus = "1.17"
|
||||
tracing = "0.1"
|
||||
|
||||
[dev-dependencies]
|
||||
tokio = { version = "1.53", features = ["full"] }
|
||||
tracing-subscriber = "0.3"
|
||||
|
||||
[features]
|
||||
default = []
|
||||
io = ["dep:tokio"]
|
||||
compute = ["dep:rayon"]
|
||||
bg = ["dep:tokio"]
|
||||
full = ["io", "compute", "bg"]
|
||||
|
||||
[[example]]
|
||||
name = "main"
|
||||
path = "examples/main.rs"
|
||||
required-features = ["full"]
|
||||
|
||||
[package.metadata.docs.rs]
|
||||
all-features = true
|
||||
rustdoc-args = ["--cfg", "docsrs"]
|
||||
[workspace]
|
||||
members = [
|
||||
"crates/mytheclipse",
|
||||
"crates/mytheclipse-cache",
|
||||
"crates/mytheclipse-storage",
|
||||
"crates/mytheclipse-event",
|
||||
"crates/mytheclipse-config",
|
||||
"crates/mytheclipse-crypto",
|
||||
"crates/mytheclipse-queue",
|
||||
"crates/mytheclipse-tracing",
|
||||
"crates/mytheclipse-http",
|
||||
"crates/mytheclipse-cli",
|
||||
]
|
||||
resolver = "2"
|
||||
@@ -1,81 +1,68 @@
|
||||
# mytheclipse
|
||||
|
||||
[](https://crates.io/crates/mytheclipse)
|
||||
[](https://docs.rs/mytheclipse)
|
||||
[](LICENSE-MIT)
|
||||
A personal collection of Rust abstractions for building resource-aware,
|
||||
resilient, and well-instrumented applications without hand-rolling the same
|
||||
plumbing every time — organized as a Cargo workspace, one focused crate per
|
||||
concern.
|
||||
|
||||
Resource-aware execution primitives for Rust: async I/O, heavy compute, and background queue management, sized automatically from the host's logical core count and exposed through a single, lazily-initialized engine context.
|
||||
[](crates/mytheclipse/LICENSE-MIT)
|
||||
|
||||
## Resource Sizing
|
||||
## Crates
|
||||
|
||||
Given $N$ logical cores (via `num_cpus::get()`):
|
||||
| Crate | Description | Docs |
|
||||
| :--- | :--- | :--- |
|
||||
| [`mytheclipse`](crates/mytheclipse) | Resource-aware execution primitives (async I/O, compute, background queues), resiliency (retry, circuit breaker, timeout), traffic control (rate limiter, backpressure, concurrency limiter), lifecycle (graceful shutdown, cron), and observability (metrics, panic tracking). | [README](crates/mytheclipse/README.md) |
|
||||
| [`mytheclipse-cache`](crates/mytheclipse-cache) | Unified multi-layer (L1/L2) cache abstraction: in-memory or Moka L1, Redis/Valkey L2, cache-aside read-through. | [README](crates/mytheclipse-cache/README.md) |
|
||||
| [`mytheclipse-storage`](crates/mytheclipse-storage) | Unified storage & file system abstraction: one driver interface over local disk, S3/MinIO, and Google Cloud Storage, stream-based. | [README](crates/mytheclipse-storage/README.md) |
|
||||
| [`mytheclipse-event`](crates/mytheclipse-event) | Unified events & message bus abstraction: in-memory pub/sub dispatcher plus RabbitMQ and NATS broker adapters behind one trait. | [README](crates/mytheclipse-event/README.md) |
|
||||
| [`mytheclipse-config`](crates/mytheclipse-config) | Type-safe, dynamic configuration engine: load `.env`/YAML/JSON/TOML into typed structs, with hot-reload. | [README](crates/mytheclipse-config/README.md) |
|
||||
| [`mytheclipse-crypto`](crates/mytheclipse-crypto) | Safe hashing (Argon2id), encryption (AES-256-GCM), JWT and PASETO tokens, with key rotation support. | [README](crates/mytheclipse-crypto/README.md) |
|
||||
| [`mytheclipse-queue`](crates/mytheclipse-queue) | Unified job queue abstraction with WorkerPool executor, retry/backoff, and dead-letter support. Backends: in-memory, Redis, NATS, PostgreSQL. | [README](crates/mytheclipse-queue/README.md) |
|
||||
| [`mytheclipse-tracing`](crates/mytheclipse-tracing) | Pre-built tracing subscriber layers with env filtering and optional OTLP/Jaeger/Zipkin export. | [README](crates/mytheclipse-tracing/README.md) |
|
||||
| [`mytheclipse-http`](crates/mytheclipse-http) | HTTP client and server abstraction with built-in retry, circuit breaker, timeout, and rate limiting. | [README](crates/mytheclipse-http/README.md) |
|
||||
| [`mytheclipse-cli`](crates/mytheclipse-cli) | CLI framework for mytheclipse applications with built-in subcommands (serve, worker, migrate, health, version). | [README](crates/mytheclipse-cli/README.md) |
|
||||
|
||||
| Subsystem | Sizing Formula | Default on 8 cores | Backing Primitive |
|
||||
| :--- | :--- | :--- | :--- |
|
||||
| **Async I/O** | $N$ | 8 | Ambient `tokio::spawn` + `tracing` span |
|
||||
| **Compute** | $\max(1, N - 1)$ | 7 | Sized `rayon::ThreadPool` + `catch_unwind` |
|
||||
| **Background Queue** | $\max(2, \lfloor N / 2 \rfloor)$ | 4 | `tokio::sync::Semaphore` + `tokio::spawn` |
|
||||
Every crate follows the same philosophy: **one small interface, pluggable
|
||||
backends behind feature flags, and a working default that needs no external
|
||||
service to build or test.** Distributed backends (Redis, S3, GCS, RabbitMQ,
|
||||
NATS) are feature-gated and their integration tests are `#[ignore]`d unless
|
||||
the corresponding environment variables point at a live service.
|
||||
|
||||
## Features
|
||||
## Getting started
|
||||
|
||||
- **`io`**: enables `mytheclipse::spawn_io`, instrumented async task spawning.
|
||||
- **`compute`**: enables `mytheclipse::compute`, panic-isolated execution on a sized Rayon pool.
|
||||
- **`bg`**: enables `mytheclipse::spawn_bg`, semaphore-bounded background tasks.
|
||||
- **`full`**: enables all three subsystems.
|
||||
|
||||
Zero features enabled by default (`default = []`), so you only pull in the dependencies your application actually uses.
|
||||
|
||||
## Quick Start
|
||||
|
||||
Add to your `Cargo.toml`:
|
||||
Each crate is published independently; add the ones you need:
|
||||
|
||||
```toml
|
||||
[dependencies]
|
||||
mytheclipse = { version = "0.1", features = ["full"] }
|
||||
mytheclipse = { version = "1", features = ["full"] }
|
||||
mytheclipse-cache = "0.1"
|
||||
mytheclipse-storage = { version = "0.1", features = ["s3"] }
|
||||
mytheclipse-event = { version = "0.1", features = ["nats"] }
|
||||
mytheclipse-config = "0.1"
|
||||
mytheclipse-crypto = "0.1"
|
||||
```
|
||||
|
||||
Use the entry points directly:
|
||||
See each crate's own README (linked above) for usage examples and the full
|
||||
feature-flag list.
|
||||
|
||||
```rust
|
||||
#[tokio::main]
|
||||
async fn main() {
|
||||
// Optional explicit bootstrap: logs or validates resource sizing upfront.
|
||||
// Omit it and the first call to any primitive below will initialize it lazily.
|
||||
let ctx = mytheclipse::init();
|
||||
println!(
|
||||
"io_threads={} compute_threads={} bg_concurrency={}",
|
||||
ctx.io_threads, ctx.compute_threads, ctx.bg_concurrency
|
||||
);
|
||||
## Development
|
||||
|
||||
// 1. Async I/O (instrumented with tracing)
|
||||
let io = mytheclipse::spawn_io(async {
|
||||
// ... network / disk work ...
|
||||
42
|
||||
});
|
||||
|
||||
// 2. Heavy Compute (isolated from worker panics)
|
||||
let sum = mytheclipse::compute(|| (1..=1_000_000u64).sum::<u64>())?;
|
||||
|
||||
// 3. Background Queue (concurrency-bounded)
|
||||
let bg = mytheclipse::spawn_bg(async {
|
||||
// ... deferred cleanup / telemetry ...
|
||||
}).await;
|
||||
|
||||
let _ = (io.await, bg.await);
|
||||
}
|
||||
```
|
||||
|
||||
## Running the Example
|
||||
This is a Cargo workspace; run commands from the repository root:
|
||||
|
||||
```bash
|
||||
cargo run --example main --features full
|
||||
cargo build --workspace --all-features
|
||||
cargo test --workspace --all-features
|
||||
cargo clippy --workspace --all-features -- -D warnings
|
||||
cargo fmt --all --check
|
||||
```
|
||||
|
||||
Or target a single crate with `-p <name>`, e.g. `cargo test -p mytheclipse-cache`.
|
||||
|
||||
## License
|
||||
|
||||
Licensed under either of:
|
||||
|
||||
- Apache License, Version 2.0 ([LICENSE-APACHE](LICENSE-APACHE) or <http://www.apache.org/licenses/LICENSE-2.0>)
|
||||
- MIT license ([LICENSE-MIT](LICENSE-MIT) or <http://opensource.org/licenses/MIT>)
|
||||
- Apache License, Version 2.0 ([LICENSE-APACHE](crates/mytheclipse/LICENSE-APACHE) or <http://www.apache.org/licenses/LICENSE-2.0>)
|
||||
- MIT license ([LICENSE-MIT](crates/mytheclipse/LICENSE-MIT) or <http://opensource.org/licenses/MIT>)
|
||||
|
||||
at your option.
|
||||
at your option.
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,41 @@
|
||||
[package]
|
||||
name = "mytheclipse-cache"
|
||||
version = "1.4.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
repository = "https://github.com/asepharyana/mytheclipse"
|
||||
homepage = "https://github.com/asepharyana/mytheclipse"
|
||||
documentation = "https://docs.rs/mytheclipse-cache"
|
||||
authors = ["asepharyana <superaseph@gmail.com>"]
|
||||
description = "Unified multi-layer cache abstraction: L1/L2 caching, cache-aside and auto-refresh, with pluggable backends."
|
||||
readme = "README.md"
|
||||
keywords = ["cache", "lru", "redis", "multilayer", "cache-aside"]
|
||||
categories = ["caching", "asynchronous"]
|
||||
|
||||
[features]
|
||||
default = ["l1-memory", "cache-aside"]
|
||||
# L1 (in-process) backends.
|
||||
l1-memory = []
|
||||
l1-moka = ["l1-memory", "dep:moka"]
|
||||
# L2 (distributed) backends.
|
||||
l2-redis = ["l1-memory", "dep:redis"]
|
||||
# Cache-aside + auto-refresh helper.
|
||||
cache-aside = ["l1-memory", "dep:serde", "dep:serde_json", "dep:tokio"]
|
||||
|
||||
[dependencies]
|
||||
tracing = "0.1"
|
||||
# Required unconditionally: the core `Cache` trait (always compiled) uses it.
|
||||
async-trait = "0.1"
|
||||
serde = { version = "1", features = ["derive"], optional = true }
|
||||
serde_json = { version = "1", optional = true }
|
||||
|
||||
# L1: Moka (high-performance in-memory cache).
|
||||
moka = { version = "0.12", default-features = false, features = ["future"], optional = true }
|
||||
|
||||
# L2: Redis/Valkey async client (multiplexed connection).
|
||||
redis = { version = "0.27", default-features = false, features = ["tokio-comp"], optional = true }
|
||||
tokio = { version = "1.53", features = ["sync", "rt"], optional = true }
|
||||
|
||||
[dev-dependencies]
|
||||
tokio = { version = "1.53", features = ["full"] }
|
||||
@@ -0,0 +1,33 @@
|
||||
# mytheclipse-cache
|
||||
|
||||
A unified multi-layer cache abstraction so your app isn't locked to one cache
|
||||
provider. Combines an in-process **L1** cache with a distributed **L2** cache
|
||||
(e.g. Redis/Valkey) behind one simple `get`/`set`/`invalidate` API, plus a
|
||||
**cache-aside / auto-refresh** helper.
|
||||
|
||||
## Features
|
||||
|
||||
- `l1-memory` (default) — zero-dependency in-process cache.
|
||||
- `l1-moka` — high-performance Moka-backed L1 with TTL/max-capacity.
|
||||
- `l2-redis` — Redis/Valkey L2 via `fred`.
|
||||
- `cache-aside` (default) — read-through cache-aside helper.
|
||||
|
||||
## Usage
|
||||
|
||||
```rust
|
||||
use mytheclipse_cache::{Cache, MemoryCache, MultiLayerCache, CacheAside};
|
||||
|
||||
let cache = MultiLayerCache::new(
|
||||
MemoryCache::new(), // L1
|
||||
MemoryCache::new(), // L2 (use RedisCache in production)
|
||||
);
|
||||
cache.set("k", b"v".to_vec(), None).await.unwrap();
|
||||
let v = cache.get("k").await.unwrap();
|
||||
|
||||
// Cache-aside: fill misses from a source of truth.
|
||||
let aside = CacheAside::new(
|
||||
MemoryCache::new(),
|
||||
|key| async move { Some(format!("data-for-{key}").into_bytes()) },
|
||||
);
|
||||
let _ = aside.get("orders:42").await.unwrap();
|
||||
```
|
||||
@@ -0,0 +1,82 @@
|
||||
//! Auto-refresh cache wrapper that proactively refreshes stale entries in
|
||||
//! the background, eliminating thundering-herd on cache miss.
|
||||
|
||||
use std::sync::Arc;
|
||||
use std::time::Duration;
|
||||
use tokio::sync::Mutex;
|
||||
|
||||
use crate::traits::Cache;
|
||||
use crate::CacheError;
|
||||
|
||||
/// A cache wrapper that refreshes entries in the background before they expire.
|
||||
///
|
||||
/// When a `get` returns a `None`, the wrapper triggers a background refresh
|
||||
/// (via `refresh_fn`) while still returning the miss to the caller.
|
||||
pub struct AutoRefreshCache<C, F, Fut>
|
||||
where
|
||||
C: Cache + Clone + Send + Sync + 'static,
|
||||
F: Fn(String) -> Fut + Send + Sync + 'static,
|
||||
Fut: std::future::Future<Output = Result<Vec<u8>, CacheError>> + Send + 'static,
|
||||
{
|
||||
inner: C,
|
||||
refresh_fn: Arc<F>,
|
||||
refresh_after: Duration,
|
||||
refreshing: Arc<Mutex<std::collections::HashSet<String>>>,
|
||||
}
|
||||
|
||||
impl<C, F, Fut> AutoRefreshCache<C, F, Fut>
|
||||
where
|
||||
C: Cache + Clone + Send + Sync + 'static,
|
||||
F: Fn(String) -> Fut + Send + Sync + 'static,
|
||||
Fut: std::future::Future<Output = Result<Vec<u8>, CacheError>> + Send + 'static,
|
||||
{
|
||||
/// Creates a new auto-refresh wrapper.
|
||||
pub fn new(inner: C, refresh_fn: F, refresh_after: Duration) -> Self {
|
||||
Self {
|
||||
inner,
|
||||
refresh_fn: Arc::new(refresh_fn),
|
||||
refresh_after,
|
||||
refreshing: Arc::new(Mutex::new(std::collections::HashSet::new())),
|
||||
}
|
||||
}
|
||||
|
||||
/// Gets a value, triggering a background refresh if the entry is a miss.
|
||||
pub async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError> {
|
||||
let result = self.inner.get(key).await?;
|
||||
if result.is_none() {
|
||||
let key_str = key.to_string();
|
||||
let mut refreshing = self.refreshing.lock().await;
|
||||
if refreshing.insert(key_str.clone()) {
|
||||
let inner = self.inner.clone();
|
||||
let refresh_fn = Arc::clone(&self.refresh_fn);
|
||||
let refresh_after = self.refresh_after;
|
||||
let refreshing = self.refreshing.clone();
|
||||
tokio::spawn(async move {
|
||||
let refresh_fut = refresh_fn(key_str.clone());
|
||||
match refresh_fut.await {
|
||||
Ok(value) => {
|
||||
let ttl = Some(refresh_after * 2);
|
||||
let _ = inner.set(&key_str, value, ttl).await;
|
||||
}
|
||||
Err(e) => {
|
||||
tracing::warn!("background refresh failed for key {}: {}", key_str, e);
|
||||
}
|
||||
}
|
||||
let mut r = refreshing.lock().await;
|
||||
r.remove(&key_str);
|
||||
});
|
||||
}
|
||||
}
|
||||
Ok(result)
|
||||
}
|
||||
|
||||
/// Sets a value in the underlying cache.
|
||||
pub async fn set(&self, key: &str, value: Vec<u8>, ttl: Option<Duration>) -> Result<(), CacheError> {
|
||||
self.inner.set(key, value, ttl).await
|
||||
}
|
||||
|
||||
/// Invalidates a key in the underlying cache.
|
||||
pub async fn invalidate(&self, key: &str) -> Result<(), CacheError> {
|
||||
self.inner.invalidate(key).await
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,123 @@
|
||||
//! Cache-aside with read-through (feature `cache-aside`).
|
||||
//!
|
||||
//! [`CacheAside`] wires a [`Cache`] to a data source: on a miss it invokes a
|
||||
//! user-provided async fetcher, stores the result (with an optional TTL), and
|
||||
//! returns it. This is the standard cache-aside pattern — reads bypass a cold
|
||||
//! cache by falling back to the source of truth.
|
||||
|
||||
use std::time::Duration;
|
||||
|
||||
use crate::traits::{Cache, CacheError};
|
||||
|
||||
/// A generic read-through cache-aside helper.
|
||||
///
|
||||
/// `F` is the data source: an async closure `(owned key) -> Option<Vec<u8>>`.
|
||||
/// The key is passed by value ([`String`]) so the returned future does not
|
||||
/// borrow from the caller, which keeps the API simple and `'static`-friendly.
|
||||
#[derive(Clone)]
|
||||
pub struct CacheAside<C, F> {
|
||||
cache: C,
|
||||
fetcher: F,
|
||||
ttl: Option<Duration>,
|
||||
}
|
||||
|
||||
impl<C, F, Fut> CacheAside<C, F>
|
||||
where
|
||||
C: Cache,
|
||||
F: Fn(String) -> Fut + Send + Sync,
|
||||
Fut: std::future::Future<Output = Option<Vec<u8>>> + Send,
|
||||
{
|
||||
/// Builds a cache-aside wrapper around `cache` using `fetcher` to fill
|
||||
/// misses. Entries are stored without expiry unless `with_ttl` is used.
|
||||
pub fn new(cache: C, fetcher: F) -> Self {
|
||||
Self {
|
||||
cache,
|
||||
fetcher,
|
||||
ttl: None,
|
||||
}
|
||||
}
|
||||
|
||||
/// Applies a `ttl` to every entry written by this wrapper.
|
||||
pub fn with_ttl(mut self, ttl: Duration) -> Self {
|
||||
self.ttl = Some(ttl);
|
||||
self
|
||||
}
|
||||
|
||||
/// Returns a value for `key`, reading through to the fetcher on a miss and
|
||||
/// caching the result.
|
||||
pub async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError> {
|
||||
if let Some(value) = self.cache.get(key).await? {
|
||||
return Ok(Some(value));
|
||||
}
|
||||
if let Some(value) = (self.fetcher)(key.to_string()).await {
|
||||
self.cache.set(key, value.clone(), self.ttl).await?;
|
||||
Ok(Some(value))
|
||||
} else {
|
||||
Ok(None)
|
||||
}
|
||||
}
|
||||
|
||||
/// Explicitly evicts `key`.
|
||||
pub async fn invalidate(&self, key: &str) -> Result<(), CacheError> {
|
||||
self.cache.invalidate(key).await
|
||||
}
|
||||
|
||||
/// Returns a reference to the underlying cache.
|
||||
pub fn cache(&self) -> &C {
|
||||
&self.cache
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::memory::MemoryCache;
|
||||
use std::sync::atomic::{AtomicU64, Ordering};
|
||||
use std::sync::Arc;
|
||||
|
||||
fn fetcher(
|
||||
hits: Arc<AtomicU64>,
|
||||
) -> impl Fn(String) -> std::future::Ready<Option<Vec<u8>>> + Send + Sync {
|
||||
move |_key: String| {
|
||||
let n = hits.fetch_add(1, Ordering::SeqCst) + 1;
|
||||
std::future::ready(Some(format!("fetched-{n}").into_bytes()))
|
||||
}
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn miss_reads_through_and_caches() {
|
||||
let hits = Arc::new(AtomicU64::new(0));
|
||||
let aside = CacheAside::new(MemoryCache::new(), fetcher(hits.clone()));
|
||||
|
||||
let first = aside.get("k").await.unwrap().unwrap();
|
||||
let second = aside.get("k").await.unwrap().unwrap();
|
||||
assert_eq!(first, b"fetched-1");
|
||||
// Cache hit — fetcher not called again.
|
||||
assert_eq!(second, b"fetched-1");
|
||||
assert_eq!(hits.load(Ordering::SeqCst), 1);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn invalidate_forces_refetch() {
|
||||
let hits = Arc::new(AtomicU64::new(0));
|
||||
let aside = CacheAside::new(MemoryCache::new(), fetcher(hits.clone()));
|
||||
let _ = aside.get("k").await.unwrap();
|
||||
aside.invalidate("k").await.unwrap();
|
||||
let again = aside.get("k").await.unwrap().unwrap();
|
||||
assert_eq!(again, b"fetched-2");
|
||||
assert_eq!(hits.load(Ordering::SeqCst), 2);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn ttl_applies_to_writes() {
|
||||
let aside = CacheAside::new(MemoryCache::new(), fetcher(Arc::new(AtomicU64::new(0))))
|
||||
.with_ttl(Duration::from_millis(30));
|
||||
let _ = aside.get("k").await.unwrap();
|
||||
assert_eq!(
|
||||
aside.cache().get("k").await.unwrap(),
|
||||
Some(b"fetched-1".to_vec())
|
||||
);
|
||||
tokio::time::sleep(Duration::from_millis(60)).await;
|
||||
assert_eq!(aside.cache().get("k").await.unwrap(), None);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,84 @@
|
||||
//! # mytheclipse-cache
|
||||
//!
|
||||
//! A unified multi-layer cache abstraction that keeps your application from
|
||||
//! being locked to any single cache provider.
|
||||
//!
|
||||
//! - **L1 (in-process) caches**: [`memory::MemoryCache`] (zero-dependency,
|
||||
//! default) or [`moka_cache::MokaL1`] (high-performance, TTL/max-capacity).
|
||||
//! - **L2 (distributed) caches**: [`redis::RedisCache`] backed by Redis/Valkey.
|
||||
//! - **Multi-layer composition**: [`multilayer::MultiLayerCache`] layers an L1
|
||||
//! over an L2 behind one [`Cache`] face; reads fall through to L2 and
|
||||
//! backfill L1.
|
||||
//! - **Cache-aside / auto-refresh**: [`cache_aside::CacheAside`] reads through
|
||||
//! to a data source on a miss and caches the result.
|
||||
//!
|
||||
//! The core [`Cache`] trait is byte-oriented; typed convenience (JSON) is
|
||||
//! layered on top via [`memory::typed::TypedCache`].
|
||||
//!
|
||||
//! ## Example
|
||||
//!
|
||||
//! Multi-layer + cache-aside composition (default features):
|
||||
//!
|
||||
//! ```no_run
|
||||
//! # #[cfg(all(feature = "l1-memory", feature = "cache-aside"))]
|
||||
//! # async fn run() {
|
||||
//! use mytheclipse_cache::{Cache, MemoryCache, MultiLayerCache, CacheAside};
|
||||
//! let l1 = MemoryCache::new();
|
||||
//! let l2 = MemoryCache::new(); // in a real app: a RedisCache
|
||||
//! let cache = MultiLayerCache::new(l1, l2);
|
||||
//!
|
||||
//! cache.set("user:1", b"payload".to_vec(), None).await.unwrap();
|
||||
//! assert_eq!(cache.get("user:1").await.unwrap(), Some(b"payload".to_vec()));
|
||||
//!
|
||||
//! // Cache-aside: fill misses from a source of truth.
|
||||
//! let aside = CacheAside::new(
|
||||
//! MemoryCache::new(),
|
||||
//! |key| async move { Some(format!("data-for-{key}").into_bytes()) },
|
||||
//! );
|
||||
//! let _v = aside.get("orders:42").await.unwrap();
|
||||
//! # }
|
||||
//! # #[cfg(not(all(feature = "l1-memory", feature = "cache-aside")))]
|
||||
//! # fn run() {}
|
||||
//! ```
|
||||
|
||||
#![forbid(unsafe_code)]
|
||||
|
||||
pub mod traits;
|
||||
|
||||
#[cfg(feature = "l1-memory")]
|
||||
pub mod memory;
|
||||
|
||||
#[cfg(feature = "l1-moka")]
|
||||
pub mod moka_cache;
|
||||
|
||||
#[cfg(feature = "l2-redis")]
|
||||
pub mod redis;
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub mod cache_aside;
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub mod multilayer;
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub mod auto_refresh;
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub mod metrics;
|
||||
|
||||
pub use traits::{Cache, CacheError};
|
||||
|
||||
#[cfg(feature = "l1-memory")]
|
||||
pub use memory::MemoryCache;
|
||||
|
||||
#[cfg(feature = "l1-moka")]
|
||||
pub use moka_cache::MokaL1;
|
||||
|
||||
#[cfg(feature = "l2-redis")]
|
||||
pub use redis::RedisCache;
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub use cache_aside::CacheAside;
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub use multilayer::MultiLayerCache;
|
||||
@@ -0,0 +1,269 @@
|
||||
//! A simple, dependency-free in-process cache (L1, `l1-memory`).
|
||||
//!
|
||||
//! Backed by a `HashMap<String, (Vec<u8>, Instant)>` guarded by a `Mutex`.
|
||||
//! Entries are lazily expired on access by comparing against `Instant`; a
|
||||
//! monotonic clock keeps TTLs robust against wall-clock discontinuities.
|
||||
|
||||
use std::collections::{HashMap, VecDeque};
|
||||
use std::sync::{Arc, Mutex};
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
use async_trait::async_trait;
|
||||
|
||||
use crate::traits::{Cache, CacheError};
|
||||
|
||||
/// A wrapping entry: `None` expiry means the value never expires.
|
||||
type Entry = (Vec<u8>, Option<Instant>);
|
||||
|
||||
/// An in-process [`Cache`] for L1 caching.
|
||||
///
|
||||
/// Default instance is **unbounded** — it grows until the process runs out of
|
||||
/// memory. For memory-constrained workloads, use [`MemoryCache::with_max_entries`]
|
||||
/// to install a simple LRU-style cap: when the cap is exceeded, the oldest
|
||||
/// (least-recently-inserted) entry is evicted.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct MemoryCache {
|
||||
inner: Arc<Mutex<HashMap<String, Entry>>>,
|
||||
/// When `Some(n)`, the cache refuses more than `n` live entries and evicts
|
||||
/// the oldest on overflow. `None` = unbounded (legacy default).
|
||||
max_entries: Option<usize>,
|
||||
/// Insertion order, for eviction when `max_entries` is set.
|
||||
order: Arc<Mutex<VecDeque<String>>>,
|
||||
}
|
||||
|
||||
impl Default for MemoryCache {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
inner: Arc::new(Mutex::new(HashMap::new())),
|
||||
max_entries: None,
|
||||
order: Arc::new(Mutex::new(VecDeque::new())),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl MemoryCache {
|
||||
/// Builds an empty in-memory cache (unbounded by default).
|
||||
pub fn new() -> Self {
|
||||
Self::default()
|
||||
}
|
||||
|
||||
/// Pre-allocates space for `capacity` entries to reduce reallocation.
|
||||
pub fn with_capacity(self, capacity: usize) -> Self {
|
||||
self.inner.lock().unwrap().reserve(capacity);
|
||||
self
|
||||
}
|
||||
|
||||
/// Installs a bounded LRU-style cap. When the cache exceeds `max`, the
|
||||
/// oldest (least-recently-inserted) entry is evicted on each `set`.
|
||||
///
|
||||
/// This is the recommended constructor for production L1 caches: a
|
||||
/// [`MemoryCache::new()`] (unbounded) left unmanaged can grow without bound
|
||||
/// and exhaust process memory.
|
||||
pub fn with_max_entries(mut self, max: usize) -> Self {
|
||||
assert!(max > 0, "mytheclipse-cache: with_max_entries must be > 0");
|
||||
self.max_entries = Some(max);
|
||||
self
|
||||
}
|
||||
|
||||
/// The configured max entries, if any.
|
||||
pub fn max_entries(&self) -> Option<usize> {
|
||||
self.max_entries
|
||||
}
|
||||
}
|
||||
|
||||
#[async_trait]
|
||||
impl Cache for MemoryCache {
|
||||
async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError> {
|
||||
let mut map = self.inner.lock().unwrap();
|
||||
match map.get(key) {
|
||||
Some((value, Some(expires))) if *expires <= Instant::now() => {
|
||||
map.remove(key);
|
||||
self.remove_order(key);
|
||||
Ok(None)
|
||||
}
|
||||
Some((value, _)) => Ok(Some(value.clone())),
|
||||
None => Ok(None),
|
||||
}
|
||||
}
|
||||
|
||||
async fn set(
|
||||
&self,
|
||||
key: &str,
|
||||
value: Vec<u8>,
|
||||
ttl: Option<Duration>,
|
||||
) -> Result<(), CacheError> {
|
||||
let expires = ttl.map(|d| Instant::now() + d);
|
||||
let mut map = self.inner.lock().unwrap();
|
||||
let is_new = !map.contains_key(key);
|
||||
map.insert(key.to_string(), (value, expires));
|
||||
if is_new {
|
||||
let mut order = self.order.lock().unwrap();
|
||||
order.push_back(key.to_string());
|
||||
if let Some(cap) = self.max_entries {
|
||||
while order.len() > cap {
|
||||
if let Some(oldest) = order.pop_front() {
|
||||
map.remove(&oldest);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn invalidate(&self, key: &str) -> Result<(), CacheError> {
|
||||
self.inner.lock().unwrap().remove(key);
|
||||
self.remove_order(key);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn clear(&self) -> Result<(), CacheError> {
|
||||
self.inner.lock().unwrap().clear();
|
||||
self.order.lock().unwrap().clear();
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
impl MemoryCache {
|
||||
/// Removes `key` from the insertion-order deque (if present).
|
||||
fn remove_order(&self, key: &str) {
|
||||
let mut order = self.order.lock().unwrap();
|
||||
order.retain(|k| k != key);
|
||||
}
|
||||
}
|
||||
|
||||
/// A typed view over a byte cache using `serde`-compatible (JSON) encoding.
|
||||
///
|
||||
/// Only enabled with the `cache-aside` feature, which pulls in `serde`.
|
||||
#[cfg(feature = "cache-aside")]
|
||||
pub mod typed {
|
||||
use serde::{de::DeserializeOwned, Serialize};
|
||||
|
||||
use super::*;
|
||||
|
||||
/// Wraps a [`Cache`] with JSON-based typed get/set.
|
||||
#[derive(Clone)]
|
||||
pub struct TypedCache<C> {
|
||||
inner: C,
|
||||
}
|
||||
|
||||
impl<C: Cache> TypedCache<C> {
|
||||
/// Wraps `inner`.
|
||||
pub fn new(inner: C) -> Self {
|
||||
Self { inner }
|
||||
}
|
||||
|
||||
/// Fetches and deserializes a value.
|
||||
pub async fn get<T: DeserializeOwned>(&self, key: &str) -> Result<Option<T>, CacheError> {
|
||||
match self.inner.get(key).await? {
|
||||
Some(bytes) => serde_json::from_slice(&bytes)
|
||||
.map(Some)
|
||||
.map_err(|e| CacheError::Serialization(e.to_string())),
|
||||
None => Ok(None),
|
||||
}
|
||||
}
|
||||
|
||||
/// Serializes and stores a value.
|
||||
pub async fn set<T: Serialize>(
|
||||
&self,
|
||||
key: &str,
|
||||
value: &T,
|
||||
ttl: Option<Duration>,
|
||||
) -> Result<(), CacheError> {
|
||||
let bytes =
|
||||
serde_json::to_vec(value).map_err(|e| CacheError::Serialization(e.to_string()))?;
|
||||
self.inner.set(key, bytes, ttl).await
|
||||
}
|
||||
|
||||
/// Returns the underlying byte cache.
|
||||
pub fn into_inner(self) -> C {
|
||||
self.inner
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[tokio::test]
|
||||
async fn set_get_roundtrip() {
|
||||
let c = MemoryCache::new();
|
||||
c.set("k", b"v".to_vec(), None).await.unwrap();
|
||||
assert_eq!(c.get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
assert_eq!(c.get("missing").await.unwrap(), None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn ttl_expires_entry() {
|
||||
let c = MemoryCache::new();
|
||||
c.set("k", b"v".to_vec(), Some(Duration::from_millis(30)))
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(c.get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
tokio::time::sleep(Duration::from_millis(60)).await;
|
||||
assert_eq!(c.get("k").await.unwrap(), None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn invalidate_and_clear() {
|
||||
let c = MemoryCache::new();
|
||||
c.set("a", b"1".to_vec(), None).await.unwrap();
|
||||
c.set("b", b"2".to_vec(), None).await.unwrap();
|
||||
c.invalidate("a").await.unwrap();
|
||||
assert_eq!(c.get("a").await.unwrap(), None);
|
||||
assert_eq!(c.get("b").await.unwrap(), Some(b"2".to_vec()));
|
||||
c.clear().await.unwrap();
|
||||
assert_eq!(c.get("b").await.unwrap(), None);
|
||||
}
|
||||
|
||||
/// Asserts that an unbounded `MemoryCache::with_max_entries(0)` panics,
|
||||
/// preventing a no-op cache that accepts zero entries.
|
||||
#[test]
|
||||
#[should_panic(expected = "must be > 0")]
|
||||
fn zero_max_panics() {
|
||||
let _ = MemoryCache::new().with_max_entries(0);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn bounded_cache_evicts_oldest() {
|
||||
let c = MemoryCache::new().with_max_entries(2);
|
||||
c.set("a", b"1".to_vec(), None).await.unwrap();
|
||||
c.set("b", b"2".to_vec(), None).await.unwrap();
|
||||
c.set("c", b"3".to_vec(), None).await.unwrap();
|
||||
// "a" (oldest) should have been evicted.
|
||||
assert_eq!(c.get("a").await.unwrap(), None);
|
||||
assert_eq!(c.get("b").await.unwrap(), Some(b"2".to_vec()));
|
||||
assert_eq!(c.get("c").await.unwrap(), Some(b"3".to_vec()));
|
||||
}
|
||||
|
||||
#[cfg(feature = "cache-aside")]
|
||||
#[tokio::test]
|
||||
async fn typed_cache_roundtrip() {
|
||||
use typed::TypedCache;
|
||||
#[derive(serde::Serialize, serde::Deserialize, Debug, PartialEq)]
|
||||
struct User {
|
||||
id: u64,
|
||||
name: String,
|
||||
}
|
||||
let typed = TypedCache::new(MemoryCache::new());
|
||||
typed
|
||||
.set(
|
||||
"u",
|
||||
&User {
|
||||
id: 1,
|
||||
name: "alice".into(),
|
||||
},
|
||||
None,
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
let got: User = typed.get("u").await.unwrap().unwrap();
|
||||
assert_eq!(
|
||||
got,
|
||||
User {
|
||||
id: 1,
|
||||
name: "alice".into()
|
||||
}
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,59 @@
|
||||
//! Cache instrumentation metrics (hit/miss/eviction counters).
|
||||
|
||||
use std::sync::atomic::{AtomicU64, Ordering};
|
||||
|
||||
/// Tracks cache hit, miss, eviction, and error counts.
|
||||
#[derive(Default)]
|
||||
pub struct CacheMetrics {
|
||||
hits: AtomicU64,
|
||||
misses: AtomicU64,
|
||||
evictions: AtomicU64,
|
||||
errors: AtomicU64,
|
||||
}
|
||||
|
||||
impl CacheMetrics {
|
||||
pub fn new() -> Self {
|
||||
Self::default()
|
||||
}
|
||||
|
||||
pub fn hit(&self) {
|
||||
self.hits.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
|
||||
pub fn miss(&self) {
|
||||
self.misses.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
|
||||
pub fn eviction(&self) {
|
||||
self.evictions.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
|
||||
pub fn error(&self) {
|
||||
self.errors.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
|
||||
pub fn snapshot(&self) -> CacheSnapshot {
|
||||
CacheSnapshot {
|
||||
hits: self.hits.load(Ordering::Relaxed),
|
||||
misses: self.misses.load(Ordering::Relaxed),
|
||||
evictions: self.evictions.load(Ordering::Relaxed),
|
||||
errors: self.errors.load(Ordering::Relaxed),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// A point-in-time read of cache metrics.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub struct CacheSnapshot {
|
||||
pub hits: u64,
|
||||
pub misses: u64,
|
||||
pub evictions: u64,
|
||||
pub errors: u64,
|
||||
}
|
||||
|
||||
impl CacheSnapshot {
|
||||
pub fn hit_rate(&self) -> f64 {
|
||||
let total = self.hits + self.misses;
|
||||
if total == 0 { 0.0 } else { self.hits as f64 / total as f64 }
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,120 @@
|
||||
//! A high-performance in-process cache backed by Moka (L1, `l1-moka`).
|
||||
//!
|
||||
//! Moka provides automatic max-capacity and (optionally) TTL-based eviction,
|
||||
//! so this L1 is well-suited to workloads where memory bounds matter.
|
||||
|
||||
use std::time::Duration;
|
||||
|
||||
use async_trait::async_trait;
|
||||
use moka::future::Cache as MokaCache;
|
||||
|
||||
use crate::traits::{Cache, CacheError};
|
||||
|
||||
/// A Moka-backed [`Cache`] for L1 caching.
|
||||
#[derive(Clone)]
|
||||
pub struct MokaL1 {
|
||||
inner: MokaCache<String, Vec<u8>>,
|
||||
}
|
||||
|
||||
impl MokaL1 {
|
||||
/// Builds a Moka cache with `max_capacity` entries and an optional default
|
||||
/// `ttl`.
|
||||
///
|
||||
/// # Panics
|
||||
///
|
||||
/// Panics if `max_capacity` is `0`. In Moka, a `max_capacity` of `0` is a
|
||||
/// sentinel for **zero-entries-allowed** — every `insert` is silently
|
||||
/// dropped — which is almost certainly a caller mistake (the natural way to
|
||||
/// express "unbounded" in other caches). Pass `1..=u64::MAX`; use
|
||||
/// [`MemoryCache`](crate::memory::MemoryCache) if you truly need an
|
||||
/// unbounded in-process cache.
|
||||
pub fn new(max_capacity: u64, ttl: Option<Duration>) -> Self {
|
||||
assert!(
|
||||
max_capacity > 0,
|
||||
"mytheclipse-cache: MokaL1::new(max_capacity) must be > 0; \
|
||||
moka treats 0 as a permanent no-insert sentinel. \
|
||||
Use MemoryCache for an unbounded cache."
|
||||
);
|
||||
let mut builder = MokaCache::builder().max_capacity(max_capacity);
|
||||
if let Some(ttl) = ttl {
|
||||
builder = builder.time_to_live(ttl);
|
||||
}
|
||||
Self {
|
||||
inner: builder.build(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[async_trait]
|
||||
impl Cache for MokaL1 {
|
||||
async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError> {
|
||||
Ok(self.inner.get(key).await)
|
||||
}
|
||||
|
||||
/// Inserts `value`, using the cache's configured TTL policy. The per-call
|
||||
/// `ttl` argument is intentionally ignored — Moka applies a single TTL
|
||||
/// configured on the builder, and per-entry overrides are not exposed here.
|
||||
async fn set(
|
||||
&self,
|
||||
key: &str,
|
||||
value: Vec<u8>,
|
||||
_ttl: Option<Duration>,
|
||||
) -> Result<(), CacheError> {
|
||||
self.inner.insert(key.to_string(), value).await;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn invalidate(&self, key: &str) -> Result<(), CacheError> {
|
||||
self.inner.invalidate(key).await;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn clear(&self) -> Result<(), CacheError> {
|
||||
self.inner.invalidate_all();
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[tokio::test]
|
||||
async fn set_get_roundtrip() {
|
||||
let c = MokaL1::new(100, None);
|
||||
c.set("k", b"v".to_vec(), None).await.unwrap();
|
||||
assert_eq!(c.get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
assert_eq!(c.get("missing").await.unwrap(), None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn invalidate_and_clear() {
|
||||
let c = MokaL1::new(100, None);
|
||||
c.set("a", b"1".to_vec(), None).await.unwrap();
|
||||
c.set("b", b"2".to_vec(), None).await.unwrap();
|
||||
c.invalidate("a").await.unwrap();
|
||||
assert_eq!(c.get("a").await.unwrap(), None);
|
||||
assert_eq!(c.get("b").await.unwrap(), Some(b"2".to_vec()));
|
||||
c.clear().await.unwrap();
|
||||
assert_eq!(c.get("b").await.unwrap(), None);
|
||||
}
|
||||
|
||||
/// Asserts that `max_capacity == 0` panics with a clear message, rather
|
||||
/// than silently creating a cache that never accepts entries.
|
||||
#[test]
|
||||
#[should_panic(expected = "must be > 0")]
|
||||
fn zero_capacity_panics() {
|
||||
let _ = MokaL1::new(0, None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn ttl_does_expire() {
|
||||
// Keep a firm TTL assertion; sleep well past the expiry window.
|
||||
let c = MokaL1::new(100, Some(Duration::from_millis(40)));
|
||||
c.set("k", b"v".to_vec(), None).await.unwrap();
|
||||
assert_eq!(c.get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
tokio::time::sleep(Duration::from_millis(120)).await;
|
||||
let v = c.get("k").await.unwrap();
|
||||
assert!(matches!(v, None));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,139 @@
|
||||
//! Multi-layer (L1/L2) caching behind a single [`Cache`] face.
|
||||
//!
|
||||
//! [`MultiLayerCache`] layers a fast in-process L1 over a slower but larger
|
||||
//! L2 (e.g. Redis). Reads are L1-first with an L2 fallback; a hit on L2 is
|
||||
//! backfilled into L1. Writes and invalidations go to both layers.
|
||||
|
||||
use std::time::Duration;
|
||||
|
||||
use async_trait::async_trait;
|
||||
|
||||
use crate::traits::{Cache, CacheError};
|
||||
|
||||
/// A read-through, write-through composition of an L1 and L2 cache.
|
||||
///
|
||||
/// `L1` is typically [`crate::memory::MemoryCache`] or
|
||||
/// [`crate::moka_cache::MokaL1`]; `L2` is typically a distributed cache such
|
||||
/// as a Redis backend. Order of layers fixed: `L1` is consulted first.
|
||||
#[derive(Clone)]
|
||||
pub struct MultiLayerCache<L1, L2> {
|
||||
l1: L1,
|
||||
l2: L2,
|
||||
/// When `true`, an L2 hit is written back into L1 (default `true`).
|
||||
populate_l1: bool,
|
||||
}
|
||||
|
||||
impl<L1, L2> MultiLayerCache<L1, L2>
|
||||
where
|
||||
L1: Cache,
|
||||
L2: Cache,
|
||||
{
|
||||
/// Builds a two-layer cache with L1-backfill enabled.
|
||||
pub fn new(l1: L1, l2: L2) -> Self {
|
||||
Self {
|
||||
l1,
|
||||
l2,
|
||||
populate_l1: true,
|
||||
}
|
||||
}
|
||||
|
||||
/// Disables L1 backfill-on-read.
|
||||
pub fn without_l1_backfill(mut self) -> Self {
|
||||
self.populate_l1 = false;
|
||||
self
|
||||
}
|
||||
|
||||
/// Returns a reference to the L1 layer.
|
||||
pub fn l1(&self) -> &L1 {
|
||||
&self.l1
|
||||
}
|
||||
|
||||
/// Returns a reference to the L2 layer.
|
||||
pub fn l2(&self) -> &L2 {
|
||||
&self.l2
|
||||
}
|
||||
}
|
||||
|
||||
#[async_trait]
|
||||
impl<L1, L2> Cache for MultiLayerCache<L1, L2>
|
||||
where
|
||||
L1: Cache,
|
||||
L2: Cache,
|
||||
{
|
||||
async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError> {
|
||||
// L1 first.
|
||||
if let Some(value) = self.l1.get(key).await? {
|
||||
return Ok(Some(value));
|
||||
}
|
||||
// L2 fallback.
|
||||
if let Some(value) = self.l2.get(key).await? {
|
||||
if self.populate_l1 {
|
||||
self.l1.set(key, value.clone(), None).await?;
|
||||
}
|
||||
return Ok(Some(value));
|
||||
}
|
||||
Ok(None)
|
||||
}
|
||||
|
||||
async fn set(
|
||||
&self,
|
||||
key: &str,
|
||||
value: Vec<u8>,
|
||||
ttl: Option<Duration>,
|
||||
) -> Result<(), CacheError> {
|
||||
self.l1.set(key, value.clone(), ttl).await?;
|
||||
self.l2.set(key, value, ttl).await
|
||||
}
|
||||
|
||||
async fn invalidate(&self, key: &str) -> Result<(), CacheError> {
|
||||
self.l1.invalidate(key).await?;
|
||||
self.l2.invalidate(key).await
|
||||
}
|
||||
|
||||
async fn clear(&self) -> Result<(), CacheError> {
|
||||
self.l1.clear().await?;
|
||||
self.l2.clear().await
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::memory::MemoryCache;
|
||||
|
||||
#[tokio::test]
|
||||
async fn read_through_populates_l1() {
|
||||
let l2 = MemoryCache::new();
|
||||
l2.set("k", b"l2-value".to_vec(), None).await.unwrap();
|
||||
|
||||
let layered = MultiLayerCache::new(MemoryCache::new(), l2);
|
||||
assert_eq!(layered.l1().get("k").await.unwrap(), None);
|
||||
assert_eq!(layered.get("k").await.unwrap(), Some(b"l2-value".to_vec()));
|
||||
// L2 hit should have populated L1.
|
||||
assert_eq!(
|
||||
layered.l1().get("k").await.unwrap(),
|
||||
Some(b"l2-value".to_vec())
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn write_goes_to_both() {
|
||||
let l1 = MemoryCache::new();
|
||||
let l2 = MemoryCache::new();
|
||||
let layered = MultiLayerCache::new(l1, l2.clone());
|
||||
layered.set("k", b"v".to_vec(), None).await.unwrap();
|
||||
assert_eq!(layered.l1().get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
assert_eq!(l2.get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn invalidate_clears_both() {
|
||||
let l1 = MemoryCache::new();
|
||||
let l2 = MemoryCache::new();
|
||||
let layered = MultiLayerCache::new(l1, l2);
|
||||
layered.set("k", b"v".to_vec(), None).await.unwrap();
|
||||
layered.invalidate("k").await.unwrap();
|
||||
assert_eq!(layered.l1().get("k").await.unwrap(), None);
|
||||
assert_eq!(layered.l2().get("k").await.unwrap(), None);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,138 @@
|
||||
//! A distributed (L2) cache backed by Redis / Valkey (feature `l2-redis`).
|
||||
//!
|
||||
//! Wraps a `redis` async connection (multiplexed). Values are stored as raw
|
||||
//! Redis strings with an optional TTL (`SETEX` when a TTL is given). The
|
||||
//! caller provides the connection; this type only issues cache commands.
|
||||
|
||||
use std::time::Duration;
|
||||
|
||||
use async_trait::async_trait;
|
||||
use redis::aio::MultiplexedConnection;
|
||||
use redis::{AsyncCommands, RedisError};
|
||||
|
||||
use crate::traits::{Cache, CacheError};
|
||||
|
||||
/// Map a Redis error onto a [`CacheError`].
|
||||
fn map_err(e: RedisError) -> CacheError {
|
||||
CacheError::Io(e.to_string())
|
||||
}
|
||||
|
||||
/// An L2 cache backed by a `redis` [`MultiplexedConnection`].
|
||||
///
|
||||
/// The connection is supplied by the caller; it is cheaply cloned (the
|
||||
/// multiplexed connection is `Arc`-backed internally), so one pool can drive
|
||||
/// both cache operations and other Redis usage.
|
||||
#[derive(Clone)]
|
||||
pub struct RedisCache {
|
||||
conn: MultiplexedConnection,
|
||||
/// Optional namespace prefix prepended to every key.
|
||||
prefix: String,
|
||||
}
|
||||
|
||||
impl RedisCache {
|
||||
/// Wraps an existing connection.
|
||||
pub fn new(conn: MultiplexedConnection) -> Self {
|
||||
Self::with_prefix(conn, String::new())
|
||||
}
|
||||
|
||||
/// Wraps a connection and adds a namespace prefix to every key.
|
||||
pub fn with_prefix(conn: MultiplexedConnection, prefix: String) -> Self {
|
||||
Self { conn, prefix }
|
||||
}
|
||||
|
||||
fn key(&self, key: &str) -> String {
|
||||
if self.prefix.is_empty() {
|
||||
key.to_string()
|
||||
} else {
|
||||
format!("{}{}", self.prefix, key)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[async_trait]
|
||||
impl Cache for RedisCache {
|
||||
async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError> {
|
||||
// `get::<_, Option<Vec<u8>>>` returns `None` for a missing key.
|
||||
let mut c = self.conn.clone();
|
||||
let k = self.key(key);
|
||||
let result: Result<Option<Vec<u8>>, RedisError> = c.get(&k).await;
|
||||
result.map_err(map_err)
|
||||
}
|
||||
|
||||
async fn set(
|
||||
&self,
|
||||
key: &str,
|
||||
value: Vec<u8>,
|
||||
ttl: Option<Duration>,
|
||||
) -> Result<(), CacheError> {
|
||||
let mut c = self.conn.clone();
|
||||
let k = self.key(key);
|
||||
match ttl {
|
||||
Some(ttl) => {
|
||||
// Use millisecond precision (PSETEX) so sub-second TTLs are
|
||||
// honored faithfully. Previously `set_ex(seconds.max(1))`
|
||||
// rounded anything < 1s up to 1s, silently changing expiry
|
||||
// semantics for short-lived cache entries.
|
||||
let ms = ttl.as_millis();
|
||||
if ms == 0 {
|
||||
return Err(CacheError::Key(
|
||||
"ttl of 0ms not allowed — pass None to store permanently".into(),
|
||||
));
|
||||
}
|
||||
let ms = ms as u64;
|
||||
let result: Result<(), RedisError> = c.pset_ex(&k, value, ms).await;
|
||||
result.map_err(map_err)
|
||||
}
|
||||
None => {
|
||||
let result: Result<(), RedisError> = c.set(&k, value).await;
|
||||
result.map_err(map_err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
async fn invalidate(&self, key: &str) -> Result<(), CacheError> {
|
||||
let mut c = self.conn.clone();
|
||||
let k = self.key(key);
|
||||
let result: Result<u64, RedisError> = c.del(&k).await;
|
||||
result.map(|_| ()).map_err(map_err)
|
||||
}
|
||||
|
||||
async fn clear(&self) -> Result<(), CacheError> {
|
||||
// Deliberately does nothing: a blind `FLUSHDB`/`FLUSHALL` on a shared
|
||||
// Redis instance would destroy keys owned by other consumers.
|
||||
// Consumers that need a true wipe must either (a) use a dedicated Redis
|
||||
// DB / namespace prefix they own exclusively, or (b) call
|
||||
// `invalidate` per-key for the keys they manage.
|
||||
//
|
||||
// See: https://redis.io/commands/flushdb/ (no key-scoping)
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
/// Integration test requiring a live Redis at `REDIS_URL`
|
||||
/// (e.g. `redis://127.0.0.1:6379`). Run with:
|
||||
/// `REDIS_URL=redis://127.0.0.1:6379 cargo test -p mytheclipse-cache --features l2-redis -- --ignored` .
|
||||
#[tokio::test]
|
||||
#[ignore = "requires a live Redis instance (REDIS_URL)"]
|
||||
async fn set_get_roundtrip_live() {
|
||||
let url = std::env::var("REDIS_URL").expect("set REDIS_URL");
|
||||
let client = redis::Client::open(url).expect("valid redis url");
|
||||
let conn = client
|
||||
.get_multiplexed_tokio_connection()
|
||||
.await
|
||||
.expect("connect");
|
||||
let cache = RedisCache::with_prefix(conn, "mytheclipse_cache_test:".to_string());
|
||||
|
||||
cache
|
||||
.set("k", b"v".to_vec(), Some(Duration::from_secs(3600)))
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(cache.get("k").await.unwrap(), Some(b"v".to_vec()));
|
||||
cache.invalidate("k").await.unwrap();
|
||||
assert_eq!(cache.get("k").await.unwrap(), None);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,77 @@
|
||||
//! The core [`Cache`] and [`KeyEncoder`] traits.
|
||||
|
||||
use std::borrow::Cow;
|
||||
use std::time::Duration;
|
||||
|
||||
use async_trait::async_trait;
|
||||
|
||||
/// Errors returned by cache operations.
|
||||
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||
pub enum CacheError {
|
||||
/// The backend could not be reached (e.g. Redis connection lost).
|
||||
Io(String),
|
||||
/// A value could not be serialized / deserialized.
|
||||
Serialization(String),
|
||||
/// A key could not be encoded for the backend.
|
||||
Key(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for CacheError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
Self::Io(s) => write!(f, "cache io: {s}"),
|
||||
Self::Serialization(s) => write!(f, "cache serialization: {s}"),
|
||||
Self::Key(s) => write!(f, "cache key: {s}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for CacheError {}
|
||||
|
||||
/// A generic byte-oriented cache.
|
||||
///
|
||||
/// Real caches operate on bytes or strings; typed convenience is layered on
|
||||
/// top (see [`crate::memory::typed::TypedCache`], behind `cache-aside`).
|
||||
/// Implementors control the value format.
|
||||
#[async_trait]
|
||||
pub trait Cache: Send + Sync {
|
||||
/// Fetches a value by key. `None` indicates a miss.
|
||||
async fn get(&self, key: &str) -> Result<Option<Vec<u8>>, CacheError>;
|
||||
/// Stores a value under `key`, optionally expiring after `ttl`.
|
||||
async fn set(&self, key: &str, value: Vec<u8>, ttl: Option<Duration>)
|
||||
-> Result<(), CacheError>;
|
||||
/// Removes a key.
|
||||
async fn invalidate(&self, key: &str) -> Result<(), CacheError>;
|
||||
/// Removes all entries.
|
||||
async fn clear(&self) -> Result<(), CacheError>;
|
||||
}
|
||||
|
||||
/// Keys given to the byte-oriented [`Cache`] are `&str`, but concrete backends
|
||||
/// may need richer keys. [`KeyEncoder`] turns typed keys into canonical strings.
|
||||
pub trait KeyEncoder {
|
||||
/// The "shape" of a key, e.g. `"user:{id}:profile"`.
|
||||
fn encode<C: Into<Cow<'static, str>>, R: std::fmt::Display>(parts: (C, R)) -> String;
|
||||
}
|
||||
|
||||
/// A blanket implementation that formats `{collection}:{id}`.
|
||||
pub struct DefaultKeyEncoder;
|
||||
|
||||
impl KeyEncoder for DefaultKeyEncoder {
|
||||
fn encode<C: Into<Cow<'static, str>>, R: std::fmt::Display>(parts: (C, R)) -> String {
|
||||
format!("{}:{}", parts.0.into(), parts.1)
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn default_key_encoder_formats() {
|
||||
assert_eq!(DefaultKeyEncoder::encode(("user", 42)), "user:42");
|
||||
assert_eq!(
|
||||
DefaultKeyEncoder::encode(("session", "abc-123")),
|
||||
"session:abc-123"
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
[package]
|
||||
name = "mytheclipse-cli"
|
||||
version = "1.4.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
repository = "https://github.com/asepharyana/mytheclipse"
|
||||
homepage = "https://github.com/asepharyana/mytheclipse"
|
||||
documentation = "https://docs.rs/mytheclipse-cli"
|
||||
authors = ["asepharyana <superaseph@gmail.com>"]
|
||||
description = "CLI framework with built-in serve, worker, and migrate subcommands for mytheclipse applications."
|
||||
readme = "README.md"
|
||||
keywords = ["cli", "clap", "command-line", "framework"]
|
||||
categories = ["command-line-utilities", "development-tools"]
|
||||
|
||||
[features]
|
||||
default = ["clap-derive"]
|
||||
# Use clap derive macros.
|
||||
clap-derive = ["dep:clap"]
|
||||
|
||||
[dependencies]
|
||||
tracing = "0.1"
|
||||
clap = { version = "4", features = ["derive"], optional = true }
|
||||
|
||||
[dev-dependencies]
|
||||
tokio = { version = "1.53", features = ["full"] }
|
||||
@@ -0,0 +1,201 @@
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding those notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
APPENDIX: How to apply the Apache License to your work.
|
||||
|
||||
To apply the Apache License to your work, attach the following
|
||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
||||
replaced with your own identifying information. (Don't include
|
||||
the brackets!) The text should be enclosed in the appropriate
|
||||
comment syntax for the file format. We also recommend that a
|
||||
file or class name and description of purpose be included on the
|
||||
same "printed page" as the copyright notice for easier
|
||||
identification within third-party archives.
|
||||
|
||||
Copyright 2026 The corex Authors
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2026 The corex Authors
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
@@ -0,0 +1,32 @@
|
||||
# mytheclipse-cli
|
||||
|
||||
CLI framework for mytheclipse applications with built-in subcommands:
|
||||
`serve`, `worker`, `migrate`, `health`, and `version`.
|
||||
|
||||
## Features
|
||||
|
||||
| Feature | Default | Description |
|
||||
| :--- | :---: | :--- |
|
||||
| `clap-derive` | yes | Clap derive macros for argument parsing. |
|
||||
|
||||
## Usage
|
||||
|
||||
```toml
|
||||
[dependencies]
|
||||
mytheclipse-cli = "0.2"
|
||||
```
|
||||
|
||||
```rust
|
||||
use mytheclipse_cli::CliApp;
|
||||
|
||||
fn main() {
|
||||
let app = CliApp::parse();
|
||||
match app.command {
|
||||
Subcommand::Serve => { /* ... */ }
|
||||
Subcommand::Worker { topics } => { /* ... */ }
|
||||
Subcommand::Migrate => { /* ... */ }
|
||||
Subcommand::Health => { /* ... */ }
|
||||
Subcommand::Version => { println!("1.0.0"); }
|
||||
}
|
||||
}
|
||||
```
|
||||
@@ -0,0 +1,57 @@
|
||||
//! Clap-based CLI builder implementation.
|
||||
|
||||
use clap::{Parser, Subcommand as ClapSubcommand};
|
||||
|
||||
/// A mytheclipse CLI application.
|
||||
#[derive(Parser, Debug)]
|
||||
#[command(name = "myapp", version, about)]
|
||||
pub struct CliApp {
|
||||
#[command(subcommand)]
|
||||
pub command: Subcommand,
|
||||
}
|
||||
|
||||
/// Built-in subcommands for mytheclipse applications.
|
||||
#[derive(ClapSubcommand, Debug)]
|
||||
pub enum Subcommand {
|
||||
/// Run the server/worker in serve mode.
|
||||
Serve,
|
||||
/// Run background job workers.
|
||||
Worker {
|
||||
/// Topic(s) to consume from.
|
||||
topics: Vec<String>,
|
||||
},
|
||||
/// Run database migrations.
|
||||
Migrate,
|
||||
/// Check service health.
|
||||
Health,
|
||||
/// Print version information.
|
||||
Version,
|
||||
}
|
||||
|
||||
/// Builder for CliApp with configuration.
|
||||
pub struct CliBuilder {
|
||||
name: String,
|
||||
about: String,
|
||||
}
|
||||
|
||||
impl Default for CliBuilder {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
name: "myapp".to_string(),
|
||||
about: "A mytheclipse application".to_string(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl CliBuilder {
|
||||
pub fn new(name: impl Into<String>, about: impl Into<String>) -> Self {
|
||||
Self {
|
||||
name: name.into(),
|
||||
about: about.into(),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn build(self) -> CliApp {
|
||||
CliApp::parse()
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,16 @@
|
||||
//! # mytheclipse-cli
|
||||
//!
|
||||
//! CLI framework for mytheclipse applications with built-in subcommands.
|
||||
//!
|
||||
//! ## Quick Start
|
||||
//!
|
||||
//! ```toml
|
||||
//! [dependencies]
|
||||
//! mytheclipse-cli = "0.2"
|
||||
//! ```
|
||||
|
||||
#[cfg(feature = "clap-derive")]
|
||||
pub mod builder;
|
||||
|
||||
#[cfg(feature = "clap-derive")]
|
||||
pub use builder::{CliApp, CliBuilder, Subcommand};
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,44 @@
|
||||
[package]
|
||||
name = "mytheclipse-config"
|
||||
version = "1.4.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
repository = "https://github.com/asepharyana/mytheclipse"
|
||||
homepage = "https://github.com/asepharyana/mytheclipse"
|
||||
documentation = "https://docs.rs/mytheclipse-config"
|
||||
authors = ["asepharyana <superaseph@gmail.com>"]
|
||||
description = "Type-safe, dynamic configuration engine: load .env/YAML/JSON/TOML into typed structs with hot-reload and validation."
|
||||
readme = "README.md"
|
||||
keywords = ["config", "env", "yaml", "json", "hot-reload"]
|
||||
categories = ["config", "development-tools"]
|
||||
|
||||
[features]
|
||||
default = ["env", "yaml", "toml", "hot-reload"]
|
||||
# Load .env files + environment variables.
|
||||
env = ["dep:dotenvy"]
|
||||
# Parse structured files. JSON support (`.json`) is always available since
|
||||
# `serde_json::Value` is also the loader's internal merge representation.
|
||||
yaml = ["dep:serde_yaml"]
|
||||
toml = ["dep:toml"]
|
||||
# Watch config files and hot-reload.
|
||||
hot-reload = ["dep:notify", "dep:tokio"]
|
||||
# JSON Schema generation for config validation and docs.
|
||||
schema = []
|
||||
|
||||
[dependencies]
|
||||
serde = { version = "1", features = ["derive"] }
|
||||
serde_json = "1"
|
||||
tracing = "0.1"
|
||||
|
||||
# Optional loaders
|
||||
dotenvy = { version = "0.15", optional = true }
|
||||
serde_yaml = { version = "0.9", optional = true }
|
||||
toml = { version = "0.8", optional = true }
|
||||
# Hot-reload file watching
|
||||
notify = { version = "6", optional = true }
|
||||
tokio = { version = "1.53", features = ["sync", "rt", "time"], optional = true }
|
||||
|
||||
[dev-dependencies]
|
||||
tokio = { version = "1.53", features = ["full"] }
|
||||
tempfile = "3"
|
||||
@@ -0,0 +1,201 @@
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding those notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
APPENDIX: How to apply the Apache License to your work.
|
||||
|
||||
To apply the Apache License to your work, attach the following
|
||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
||||
replaced with your own identifying information. (Don't include
|
||||
the brackets!) The text should be enclosed in the appropriate
|
||||
comment syntax for the file format. We also recommend that a
|
||||
file or class name and description of purpose be included on the
|
||||
same "printed page" as the copyright notice for easier
|
||||
identification within third-party archives.
|
||||
|
||||
Copyright 2026 The corex Authors
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2026 The corex Authors
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
@@ -0,0 +1,49 @@
|
||||
# mytheclipse-config
|
||||
|
||||
Type-safe, dynamic configuration: load `.env`, YAML, JSON, or TOML directly
|
||||
into a typed Rust struct, merge multiple sources with environment variables
|
||||
taking priority, and optionally hot-reload when the source files change.
|
||||
|
||||
## Features
|
||||
|
||||
- `env` (default) — `.env` file loading via `dotenvy`.
|
||||
- `yaml` / `toml` (default) — structured file parsing (`.json` is always available).
|
||||
- `hot-reload` (default) — watch files and swap in a freshly reloaded value.
|
||||
|
||||
## Usage
|
||||
|
||||
```rust
|
||||
use serde::Deserialize;
|
||||
use mytheclipse_config::ConfigLoader;
|
||||
|
||||
#[derive(Debug, Deserialize, Clone)]
|
||||
struct AppConfig {
|
||||
port: u16,
|
||||
database_url: String,
|
||||
}
|
||||
|
||||
let config: AppConfig = ConfigLoader::new()
|
||||
.merge_file("config.yaml".as_ref())?
|
||||
.merge_env("APP") // APP_PORT, APP_DATABASE_URL override the file
|
||||
.build()?;
|
||||
```
|
||||
|
||||
### Hot-reload
|
||||
|
||||
```rust
|
||||
use mytheclipse_config::DynamicConfig;
|
||||
# use serde::Deserialize;
|
||||
# #[derive(Debug, Deserialize, Clone)] struct AppConfig { port: u16 }
|
||||
|
||||
let cfg = DynamicConfig::<AppConfig>::watch_files(
|
||||
vec!["config.yaml".into()],
|
||||
|| mytheclipse_config::ConfigLoader::new().merge_file("config.yaml".as_ref())?.build(),
|
||||
)?;
|
||||
|
||||
let mut changes = cfg.subscribe();
|
||||
tokio::spawn(async move {
|
||||
while changes.recv().await.is_ok() {
|
||||
println!("config reloaded: {:?}", cfg.get());
|
||||
}
|
||||
});
|
||||
```
|
||||
@@ -0,0 +1,194 @@
|
||||
//! Runtime configuration hot-reload (feature `hot-reload`).
|
||||
//!
|
||||
//! [`DynamicConfig`] holds a typed configuration value behind an `RwLock`,
|
||||
//! optionally watching a set of source files with `notify` and re-running a
|
||||
//! caller-supplied reload closure whenever they change. Subscribers can await
|
||||
//! a [`tokio::sync::broadcast::Receiver`] to react to a successful reload.
|
||||
|
||||
use std::path::PathBuf;
|
||||
use std::sync::{Arc, RwLock};
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
use notify::{RecommendedWatcher, RecursiveMode, Watcher};
|
||||
use tokio::sync::broadcast;
|
||||
|
||||
use crate::{Config, ConfigError};
|
||||
|
||||
/// A hot-reloadable, thread-safe configuration handle.
|
||||
pub struct DynamicConfig<T> {
|
||||
inner: Arc<RwLock<T>>,
|
||||
tx: broadcast::Sender<()>,
|
||||
}
|
||||
|
||||
impl<T: Config + Clone> Clone for DynamicConfig<T> {
|
||||
fn clone(&self) -> Self {
|
||||
Self {
|
||||
inner: Arc::clone(&self.inner),
|
||||
tx: self.tx.clone(),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl<T: Config + Clone> DynamicConfig<T> {
|
||||
/// Wraps an already-loaded value with no file watching.
|
||||
pub fn new(initial: T) -> Self {
|
||||
let (tx, _rx) = broadcast::channel(16);
|
||||
Self {
|
||||
inner: Arc::new(RwLock::new(initial)),
|
||||
tx,
|
||||
}
|
||||
}
|
||||
|
||||
/// Returns a clone of the current configuration snapshot.
|
||||
pub fn get(&self) -> T {
|
||||
self.inner
|
||||
.read()
|
||||
.expect("mytheclipse-config: RwLock poisoned")
|
||||
.clone()
|
||||
}
|
||||
|
||||
/// Replaces the current value and notifies subscribers.
|
||||
pub fn set(&self, new: T) {
|
||||
*self
|
||||
.inner
|
||||
.write()
|
||||
.expect("mytheclipse-config: RwLock poisoned") = new;
|
||||
let _ = self.tx.send(());
|
||||
}
|
||||
|
||||
/// Subscribes to change notifications (fired after every successful
|
||||
/// [`DynamicConfig::set`] or file-triggered reload).
|
||||
pub fn subscribe(&self) -> broadcast::Receiver<()> {
|
||||
self.tx.subscribe()
|
||||
}
|
||||
|
||||
/// Loads the initial value via `reload`, then watches `paths` for
|
||||
/// modifications and re-runs `reload` on each change (debounced), atomically
|
||||
/// swapping in the result on success. A failed reload is logged via
|
||||
/// `tracing::error!` and the previous value is retained.
|
||||
///
|
||||
/// The underlying OS file watcher lives on a dedicated background thread
|
||||
/// for the lifetime of the process; there is currently no explicit
|
||||
/// "unwatch" — construct one `DynamicConfig` per watched file set.
|
||||
pub fn watch_files<F>(paths: Vec<PathBuf>, reload: F) -> Result<Self, ConfigError>
|
||||
where
|
||||
F: Fn() -> Result<T, ConfigError> + Send + Sync + 'static,
|
||||
{
|
||||
Self::watch_files_debounced(paths, reload, Duration::from_millis(50))
|
||||
}
|
||||
|
||||
/// Same as [`DynamicConfig::watch_files`] with an explicit debounce
|
||||
/// window (the minimum time between two applied reloads).
|
||||
pub fn watch_files_debounced<F>(
|
||||
paths: Vec<PathBuf>,
|
||||
reload: F,
|
||||
debounce: Duration,
|
||||
) -> Result<Self, ConfigError>
|
||||
where
|
||||
F: Fn() -> Result<T, ConfigError> + Send + Sync + 'static,
|
||||
{
|
||||
let initial = reload()?;
|
||||
let config = Self::new(initial);
|
||||
let inner = Arc::clone(&config.inner);
|
||||
let tx = config.tx.clone();
|
||||
|
||||
let (raw_tx, raw_rx) = std::sync::mpsc::channel();
|
||||
let mut watcher: RecommendedWatcher = notify::recommended_watcher(move |res| {
|
||||
let _ = raw_tx.send(res);
|
||||
})
|
||||
.map_err(|e| ConfigError::Watch(e.to_string()))?;
|
||||
for path in &paths {
|
||||
watcher
|
||||
.watch(path, RecursiveMode::NonRecursive)
|
||||
.map_err(|e| ConfigError::Watch(e.to_string()))?;
|
||||
}
|
||||
|
||||
std::thread::Builder::new()
|
||||
.name("mytheclipse-config-watch".into())
|
||||
.spawn(move || {
|
||||
// Keep the watcher alive for the life of this thread.
|
||||
let _watcher = watcher;
|
||||
let mut last_applied = Instant::now() - debounce;
|
||||
for event in raw_rx {
|
||||
if event.is_err() {
|
||||
continue;
|
||||
}
|
||||
if last_applied.elapsed() < debounce {
|
||||
continue;
|
||||
}
|
||||
match reload() {
|
||||
Ok(new) => {
|
||||
*inner.write().expect("mytheclipse-config: RwLock poisoned") = new;
|
||||
let _ = tx.send(());
|
||||
last_applied = Instant::now();
|
||||
}
|
||||
Err(e) => {
|
||||
tracing::error!("mytheclipse-config: hot-reload failed: {e}");
|
||||
}
|
||||
}
|
||||
}
|
||||
})
|
||||
.map_err(|e| ConfigError::Watch(e.to_string()))?;
|
||||
|
||||
Ok(config)
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::ConfigLoader;
|
||||
use serde::Deserialize;
|
||||
use std::io::Write;
|
||||
|
||||
#[derive(Debug, Deserialize, Clone, PartialEq)]
|
||||
struct Cfg {
|
||||
value: u32,
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn set_and_get_roundtrip() {
|
||||
let cfg = DynamicConfig::new(Cfg { value: 1 });
|
||||
assert_eq!(cfg.get(), Cfg { value: 1 });
|
||||
cfg.set(Cfg { value: 2 });
|
||||
assert_eq!(cfg.get(), Cfg { value: 2 });
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn subscribe_receives_change_notification() {
|
||||
let cfg = DynamicConfig::new(Cfg { value: 1 });
|
||||
let mut rx = cfg.subscribe();
|
||||
cfg.set(Cfg { value: 9 });
|
||||
rx.recv().await.expect("change notification");
|
||||
assert_eq!(cfg.get().value, 9);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn watch_files_reloads_on_change() {
|
||||
let mut file = tempfile::Builder::new().suffix(".json").tempfile().unwrap();
|
||||
write!(file, r#"{{"value": 1}}"#).unwrap();
|
||||
let path = file.path().to_path_buf();
|
||||
|
||||
let reload_path = path.clone();
|
||||
let cfg = DynamicConfig::<Cfg>::watch_files_debounced(
|
||||
vec![path.clone()],
|
||||
move || {
|
||||
ConfigLoader::new()
|
||||
.merge_file(&reload_path)
|
||||
.and_then(|l| l.build())
|
||||
},
|
||||
Duration::from_millis(10),
|
||||
)
|
||||
.expect("watch setup");
|
||||
assert_eq!(cfg.get().value, 1);
|
||||
|
||||
let mut rx = cfg.subscribe();
|
||||
// Rewrite the file to trigger a reload.
|
||||
std::fs::write(&path, r#"{"value": 42}"#).unwrap();
|
||||
|
||||
// Wait (with a generous timeout) for the watcher thread to notice.
|
||||
let result = tokio::time::timeout(Duration::from_secs(5), rx.recv()).await;
|
||||
assert!(result.is_ok(), "expected a reload notification within 5s");
|
||||
assert_eq!(cfg.get().value, 42);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
//! Shared error type for mytheclipse-config.
|
||||
|
||||
/// Errors surfaced while loading or reloading configuration.
|
||||
#[non_exhaustive]
|
||||
#[derive(Debug)]
|
||||
pub enum ConfigError {
|
||||
/// An I/O error reading a config source (file not found, permissions, ...).
|
||||
Io(String),
|
||||
/// A source could not be parsed (malformed YAML/JSON/TOML).
|
||||
Parse(String),
|
||||
/// The merged configuration could not be deserialized into the target type.
|
||||
Deserialize(String),
|
||||
/// The requested file extension has no registered loader (feature not
|
||||
/// enabled, or unsupported format).
|
||||
UnsupportedFormat(String),
|
||||
/// Hot-reload setup failed (e.g. the file watcher could not be installed).
|
||||
Watch(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for ConfigError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
Self::Io(s) => write!(f, "config io error: {s}"),
|
||||
Self::Parse(s) => write!(f, "config parse error: {s}"),
|
||||
Self::Deserialize(s) => write!(f, "config deserialize error: {s}"),
|
||||
Self::UnsupportedFormat(s) => write!(f, "unsupported config format: {s}"),
|
||||
Self::Watch(s) => write!(f, "config watch error: {s}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for ConfigError {}
|
||||
@@ -0,0 +1,56 @@
|
||||
//! # mytheclipse-config
|
||||
//!
|
||||
//! A type-safe, dynamic configuration engine: load environment variables,
|
||||
//! `.env` files, YAML, JSON, or TOML directly into a typed Rust struct, with
|
||||
//! optional runtime hot-reload.
|
||||
//!
|
||||
//! - [`ConfigLoader`] merges any number of file/env sources into a single
|
||||
//! typed value (files first, environment variables override).
|
||||
//! - [`DynamicConfig`] wraps a loaded value behind an `RwLock`, optionally
|
||||
//! watching its source files and swapping in a freshly reloaded value when
|
||||
//! they change, broadcasting the change to subscribers.
|
||||
//!
|
||||
//! ## Example
|
||||
//!
|
||||
//! ```no_run
|
||||
//! use serde::Deserialize;
|
||||
//! use mytheclipse_config::ConfigLoader;
|
||||
//!
|
||||
//! #[derive(Debug, Deserialize, Clone)]
|
||||
//! struct AppConfig {
|
||||
//! port: u16,
|
||||
//! database: DatabaseConfig,
|
||||
//! }
|
||||
//! #[derive(Debug, Deserialize, Clone)]
|
||||
//! struct DatabaseConfig {
|
||||
//! url: String,
|
||||
//! }
|
||||
//!
|
||||
//! let config: AppConfig = ConfigLoader::new()
|
||||
//! .merge_file("config.yaml".as_ref())
|
||||
//! .unwrap()
|
||||
//! .merge_env("APP")
|
||||
//! .build()
|
||||
//! .unwrap();
|
||||
//! ```
|
||||
|
||||
pub mod error;
|
||||
pub mod loader;
|
||||
|
||||
#[cfg(feature = "hot-reload")]
|
||||
pub mod dynamic;
|
||||
|
||||
#[cfg(feature = "schema")]
|
||||
pub mod schema;
|
||||
|
||||
pub use error::ConfigError;
|
||||
pub use loader::ConfigLoader;
|
||||
|
||||
#[cfg(feature = "hot-reload")]
|
||||
pub use dynamic::DynamicConfig;
|
||||
|
||||
/// Marker trait for types loadable by [`ConfigLoader`].
|
||||
///
|
||||
/// Blanket-implemented for any `Deserialize + Send + Sync + 'static`.
|
||||
pub trait Config: for<'de> serde::Deserialize<'de> + Send + Sync + 'static {}
|
||||
impl<T> Config for T where T: for<'de> serde::Deserialize<'de> + Send + Sync + 'static {}
|
||||
@@ -0,0 +1,348 @@
|
||||
//! Merges file and environment sources into a typed configuration value.
|
||||
|
||||
use std::marker::PhantomData;
|
||||
use std::path::Path;
|
||||
|
||||
use serde_json::{Map, Value};
|
||||
|
||||
use crate::{Config, ConfigError};
|
||||
|
||||
/// Builds a typed configuration value from any number of sources.
|
||||
///
|
||||
/// Sources are merged in the order they're added; later sources override
|
||||
/// earlier ones at the leaf level (objects are merged recursively, not
|
||||
/// replaced wholesale). The conventional order is: defaults, then files
|
||||
/// (base -> environment-specific), then environment variables (highest
|
||||
/// priority, for secrets/overrides).
|
||||
pub struct ConfigLoader<T> {
|
||||
value: Value,
|
||||
_marker: PhantomData<fn() -> T>,
|
||||
}
|
||||
|
||||
impl<T> Default for ConfigLoader<T> {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
value: Value::Object(Map::new()),
|
||||
_marker: PhantomData,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl<T: Config> ConfigLoader<T> {
|
||||
/// Builds an empty loader.
|
||||
pub fn new() -> Self {
|
||||
Self::default()
|
||||
}
|
||||
|
||||
/// Merges a JSON value directly (useful for defaults / tests).
|
||||
pub fn merge_value(mut self, value: Value) -> Self {
|
||||
deep_merge(&mut self.value, value);
|
||||
self
|
||||
}
|
||||
|
||||
/// Reads `path`, parses it by extension (`.yaml`/`.yml`, `.json`,
|
||||
/// `.toml`), and merges the result.
|
||||
pub fn merge_file(mut self, path: &Path) -> Result<Self, ConfigError> {
|
||||
let contents = std::fs::read_to_string(path)
|
||||
.map_err(|e| ConfigError::Io(format!("{}: {e}", path.display())))?;
|
||||
let parsed = parse_by_extension(path, &contents)?;
|
||||
deep_merge(&mut self.value, parsed);
|
||||
Ok(self)
|
||||
}
|
||||
|
||||
/// Loads a `.env`-style file into the process environment (does not merge
|
||||
/// into the config value directly — call [`Self::merge_env`] afterward to
|
||||
/// pick the variables up).
|
||||
#[cfg(feature = "env")]
|
||||
pub fn load_dotenv(self, path: &Path) -> Result<Self, ConfigError> {
|
||||
dotenvy::from_path(path).map_err(|e| ConfigError::Io(e.to_string()))?;
|
||||
Ok(self)
|
||||
}
|
||||
|
||||
/// Merges environment variables whose name starts with `prefix` (an
|
||||
/// underscore is inserted between the prefix and the field name if not
|
||||
/// already present). Nested fields use `__` as a separator, e.g.
|
||||
/// `APP_DATABASE__URL` maps to `{ "database": { "url": ... } }`.
|
||||
///
|
||||
/// Values are parsed as JSON scalars when possible (`true`/`false`,
|
||||
/// integers, floats), otherwise kept as strings.
|
||||
pub fn merge_env(mut self, prefix: &str) -> Self {
|
||||
let collected = collect_env(prefix);
|
||||
deep_merge(&mut self.value, Value::Object(collected));
|
||||
self
|
||||
}
|
||||
|
||||
/// Deserializes the merged value into `T`.
|
||||
pub fn build(self) -> Result<T, ConfigError> {
|
||||
serde_json::from_value(self.value).map_err(|e| ConfigError::Deserialize(e.to_string()))
|
||||
}
|
||||
|
||||
/// Returns the current merged value without deserializing, for
|
||||
/// inspection/debugging.
|
||||
pub fn peek(&self) -> &Value {
|
||||
&self.value
|
||||
}
|
||||
}
|
||||
|
||||
/// Parses `contents` according to `path`'s extension.
|
||||
fn parse_by_extension(path: &Path, contents: &str) -> Result<Value, ConfigError> {
|
||||
let ext = path
|
||||
.extension()
|
||||
.and_then(|e| e.to_str())
|
||||
.unwrap_or_default()
|
||||
.to_ascii_lowercase();
|
||||
match ext.as_str() {
|
||||
#[cfg(feature = "yaml")]
|
||||
"yaml" | "yml" => serde_yaml::from_str(contents)
|
||||
.map_err(|e| ConfigError::Parse(e.to_string()))
|
||||
.map(yaml_to_json),
|
||||
"json" => serde_json::from_str(contents).map_err(|e| ConfigError::Parse(e.to_string())),
|
||||
#[cfg(feature = "toml")]
|
||||
"toml" => {
|
||||
let v: toml::Value =
|
||||
toml::from_str(contents).map_err(|e| ConfigError::Parse(e.to_string()))?;
|
||||
Ok(toml_to_json(v))
|
||||
}
|
||||
other => Err(ConfigError::UnsupportedFormat(format!(
|
||||
"no loader registered for `.{other}` (path: {})",
|
||||
path.display()
|
||||
))),
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(feature = "yaml")]
|
||||
fn yaml_to_json(v: serde_yaml::Value) -> Value {
|
||||
// Round-trip through serde_json for a uniform merge representation.
|
||||
serde_json::to_value(v).unwrap_or(Value::Null)
|
||||
}
|
||||
|
||||
#[cfg(feature = "toml")]
|
||||
fn toml_to_json(v: toml::Value) -> Value {
|
||||
serde_json::to_value(v).unwrap_or(Value::Null)
|
||||
}
|
||||
|
||||
/// Deep-merges `overlay` into `base`; scalars and arrays in `overlay` replace
|
||||
/// `base`, objects are merged key-by-key recursively.
|
||||
fn deep_merge(base: &mut Value, overlay: Value) {
|
||||
match (base, overlay) {
|
||||
(Value::Object(base_map), Value::Object(overlay_map)) => {
|
||||
for (k, v) in overlay_map {
|
||||
match base_map.get_mut(&k) {
|
||||
Some(existing) => deep_merge(existing, v),
|
||||
None => {
|
||||
base_map.insert(k, v);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
(base_slot, overlay_value) => {
|
||||
*base_slot = overlay_value;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Collects environment variables with `prefix` into a nested JSON object.
|
||||
///
|
||||
/// `PREFIX_FOO` -> `{"foo": ...}`; `PREFIX_FOO__BAR` -> `{"foo": {"bar": ...}}`.
|
||||
fn collect_env(prefix: &str) -> Map<String, Value> {
|
||||
let mut root = Map::new();
|
||||
let full_prefix = if prefix.ends_with('_') {
|
||||
prefix.to_string()
|
||||
} else {
|
||||
format!("{prefix}_")
|
||||
};
|
||||
for (key, raw_value) in std::env::vars() {
|
||||
let Some(rest) = key.strip_prefix(&full_prefix) else {
|
||||
continue;
|
||||
};
|
||||
if rest.is_empty() {
|
||||
continue;
|
||||
}
|
||||
let path: Vec<String> = rest.split("__").map(|s| s.to_ascii_lowercase()).collect();
|
||||
insert_nested(&mut root, &path, coerce_scalar(&raw_value));
|
||||
}
|
||||
root
|
||||
}
|
||||
|
||||
fn insert_nested(root: &mut Map<String, Value>, path: &[String], value: Value) {
|
||||
if path.len() == 1 {
|
||||
root.insert(path[0].clone(), value);
|
||||
return;
|
||||
}
|
||||
let entry = root
|
||||
.entry(path[0].clone())
|
||||
.or_insert_with(|| Value::Object(Map::new()));
|
||||
if let Value::Object(nested) = entry {
|
||||
insert_nested(nested, &path[1..], value);
|
||||
}
|
||||
}
|
||||
|
||||
/// Parses `s` as a JSON scalar (`bool`/number) if possible, else keeps it as
|
||||
/// a string.
|
||||
fn coerce_scalar(s: &str) -> Value {
|
||||
if let Ok(b) = s.parse::<bool>() {
|
||||
return Value::Bool(b);
|
||||
}
|
||||
if let Ok(i) = s.parse::<i64>() {
|
||||
return Value::Number(i.into());
|
||||
}
|
||||
if let Ok(f) = s.parse::<f64>() {
|
||||
if let Some(n) = serde_json::Number::from_f64(f) {
|
||||
return Value::Number(n);
|
||||
}
|
||||
}
|
||||
Value::String(s.to_string())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use serde::Deserialize;
|
||||
|
||||
#[derive(Debug, Deserialize, PartialEq)]
|
||||
struct Db {
|
||||
url: String,
|
||||
pool_size: u32,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize, PartialEq)]
|
||||
struct AppConfig {
|
||||
port: u16,
|
||||
debug: bool,
|
||||
database: Db,
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn merge_value_builds_typed_struct() {
|
||||
let value = serde_json::json!({
|
||||
"port": 8080,
|
||||
"debug": true,
|
||||
"database": { "url": "postgres://x", "pool_size": 10 }
|
||||
});
|
||||
let cfg: AppConfig = ConfigLoader::new().merge_value(value).build().unwrap();
|
||||
assert_eq!(
|
||||
cfg,
|
||||
AppConfig {
|
||||
port: 8080,
|
||||
debug: true,
|
||||
database: Db {
|
||||
url: "postgres://x".into(),
|
||||
pool_size: 10
|
||||
}
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn deep_merge_overrides_nested_leaf_only() {
|
||||
let base = serde_json::json!({ "port": 8080, "debug": false, "database": { "url": "a", "pool_size": 5 } });
|
||||
let overlay = serde_json::json!({ "database": { "pool_size": 20 } });
|
||||
let cfg: AppConfig = ConfigLoader::new()
|
||||
.merge_value(base)
|
||||
.merge_value(overlay)
|
||||
.build()
|
||||
.unwrap();
|
||||
assert_eq!(cfg.database.pool_size, 20);
|
||||
assert_eq!(cfg.database.url, "a"); // untouched sibling field preserved
|
||||
assert_eq!(cfg.port, 8080);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn env_merge_maps_nested_and_types() {
|
||||
// Safe because this test owns unique env var names.
|
||||
std::env::set_var("CFGTEST_PORT", "9090");
|
||||
std::env::set_var("CFGTEST_DEBUG", "true");
|
||||
std::env::set_var("CFGTEST_DATABASE__URL", "redis://y");
|
||||
std::env::set_var("CFGTEST_DATABASE__POOL_SIZE", "42");
|
||||
|
||||
let cfg: AppConfig = ConfigLoader::new().merge_env("CFGTEST").build().unwrap();
|
||||
assert_eq!(cfg.port, 9090);
|
||||
assert!(cfg.debug);
|
||||
assert_eq!(cfg.database.url, "redis://y");
|
||||
assert_eq!(cfg.database.pool_size, 42);
|
||||
|
||||
std::env::remove_var("CFGTEST_PORT");
|
||||
std::env::remove_var("CFGTEST_DEBUG");
|
||||
std::env::remove_var("CFGTEST_DATABASE__URL");
|
||||
std::env::remove_var("CFGTEST_DATABASE__POOL_SIZE");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn env_overrides_file_value() {
|
||||
std::env::set_var("CFGTEST2_PORT", "7000");
|
||||
let base = serde_json::json!({ "port": 1, "debug": false, "database": { "url": "a", "pool_size": 1 } });
|
||||
let cfg: AppConfig = ConfigLoader::new()
|
||||
.merge_value(base)
|
||||
.merge_env("CFGTEST2")
|
||||
.build()
|
||||
.unwrap();
|
||||
assert_eq!(cfg.port, 7000);
|
||||
std::env::remove_var("CFGTEST2_PORT");
|
||||
}
|
||||
|
||||
#[cfg(feature = "yaml")]
|
||||
#[test]
|
||||
fn merge_yaml_file() {
|
||||
use std::io::Write;
|
||||
let mut file = tempfile::Builder::new().suffix(".yaml").tempfile().unwrap();
|
||||
writeln!(
|
||||
file,
|
||||
"port: 3000\ndebug: false\ndatabase:\n url: sqlite://mem\n pool_size: 3\n"
|
||||
)
|
||||
.unwrap();
|
||||
let cfg: AppConfig = ConfigLoader::new()
|
||||
.merge_file(file.path())
|
||||
.unwrap()
|
||||
.build()
|
||||
.unwrap();
|
||||
assert_eq!(cfg.port, 3000);
|
||||
assert_eq!(cfg.database.url, "sqlite://mem");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn merge_json_file() {
|
||||
use std::io::Write;
|
||||
let mut file = tempfile::Builder::new().suffix(".json").tempfile().unwrap();
|
||||
write!(
|
||||
file,
|
||||
r#"{{"port": 4000, "debug": true, "database": {{"url": "mysql://x", "pool_size": 7}}}}"#
|
||||
)
|
||||
.unwrap();
|
||||
let cfg: AppConfig = ConfigLoader::new()
|
||||
.merge_file(file.path())
|
||||
.unwrap()
|
||||
.build()
|
||||
.unwrap();
|
||||
assert_eq!(cfg.port, 4000);
|
||||
assert_eq!(cfg.database.pool_size, 7);
|
||||
}
|
||||
|
||||
#[cfg(feature = "toml")]
|
||||
#[test]
|
||||
fn merge_toml_file() {
|
||||
use std::io::Write;
|
||||
let mut file = tempfile::Builder::new().suffix(".toml").tempfile().unwrap();
|
||||
writeln!(
|
||||
file,
|
||||
"port = 5000\ndebug = false\n\n[database]\nurl = \"file://local\"\npool_size = 2\n"
|
||||
)
|
||||
.unwrap();
|
||||
let cfg: AppConfig = ConfigLoader::new()
|
||||
.merge_file(file.path())
|
||||
.unwrap()
|
||||
.build()
|
||||
.unwrap();
|
||||
assert_eq!(cfg.port, 5000);
|
||||
assert_eq!(cfg.database.pool_size, 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unsupported_extension_errors() {
|
||||
let file = tempfile::Builder::new().suffix(".ini").tempfile().unwrap();
|
||||
std::fs::write(file.path(), "unused").unwrap();
|
||||
let result: Result<AppConfig, _> = ConfigLoader::new()
|
||||
.merge_file(file.path())
|
||||
.and_then(|l| l.build());
|
||||
assert!(matches!(result, Err(ConfigError::UnsupportedFormat(_))));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,107 @@
|
||||
//! JSON Schema generation for config types (feature `schema`).
|
||||
//!
|
||||
//! Generate JSON Schema from your config struct — useful for:
|
||||
//! - Runtime validation
|
||||
//! - Documentation / auto-generated config UIs
|
||||
//! - Editor autocomplete via schema-store.json
|
||||
//!
|
||||
//! ```ignore
|
||||
//! use serde::Deserialize;
|
||||
//! use mytheclipse_config::schema::ConfigSchema;
|
||||
//!
|
||||
//! #[derive(Debug, Deserialize, Default)]
|
||||
//! struct AppConfig {
|
||||
//! port: u16,
|
||||
//! }
|
||||
//!
|
||||
//! let schema = ConfigSchema::generate::<AppConfig>();
|
||||
//! println!("schema type: {}", schema.r#type);
|
||||
//! ```
|
||||
|
||||
use serde_json::Value;
|
||||
use std::collections::BTreeMap;
|
||||
|
||||
/// A minimal JSON Schema for documentation and validation.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct ConfigSchema {
|
||||
pub r#type: String,
|
||||
pub properties: BTreeMap<String, PropertySchema>,
|
||||
pub required: Vec<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct PropertySchema {
|
||||
pub r#type: String,
|
||||
pub description: Option<String>,
|
||||
pub default: Option<Value>,
|
||||
pub properties: Option<BTreeMap<String, PropertySchema>>,
|
||||
pub required: Option<Vec<String>>,
|
||||
}
|
||||
|
||||
impl ConfigSchema {
|
||||
/// Generates a schema for the given type (requires serde derive support).
|
||||
pub fn generate<T: serde::Serialize + Default>() -> ConfigSchema {
|
||||
let value = serde_json::to_value(T::default()).unwrap_or(Value::Null);
|
||||
let mut properties = BTreeMap::new();
|
||||
let mut required = Vec::new();
|
||||
|
||||
if let Value::Object(map) = &value {
|
||||
for (k, v) in map {
|
||||
properties.insert(
|
||||
k.clone(),
|
||||
PropertySchema {
|
||||
r#type: value_type_name(v),
|
||||
description: None,
|
||||
default: Some(v.clone()),
|
||||
properties: None,
|
||||
required: None,
|
||||
},
|
||||
);
|
||||
required.push(k.clone());
|
||||
}
|
||||
}
|
||||
|
||||
ConfigSchema {
|
||||
r#type: "object".to_string(),
|
||||
properties,
|
||||
required,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn value_type_name(v: &Value) -> String {
|
||||
match v {
|
||||
Value::Null => "null".to_string(),
|
||||
Value::Bool(_) => "boolean".to_string(),
|
||||
Value::Number(n) => {
|
||||
if n.is_i64() || n.is_u64() {
|
||||
"integer".to_string()
|
||||
} else if n.is_f64() {
|
||||
"number".to_string()
|
||||
} else {
|
||||
"string".to_string()
|
||||
}
|
||||
}
|
||||
Value::String(_) => "string".to_string(),
|
||||
Value::Array(_) => "array".to_string(),
|
||||
Value::Object(_) => "object".to_string(),
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use serde::Serialize;
|
||||
|
||||
#[derive(Serialize, Default)]
|
||||
struct TestConfig {
|
||||
port: u16,
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn generates_schema() {
|
||||
let schema = ConfigSchema::generate::<TestConfig>();
|
||||
assert_eq!(schema.r#type, "object");
|
||||
assert!(schema.properties.contains_key("port"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
[package]
|
||||
name = "mytheclipse-crypto"
|
||||
version = "1.4.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
repository = "https://github.com/asepharyana/mytheclipse"
|
||||
homepage = "https://github.com/asepharyana/mytheclipse"
|
||||
documentation = "https://docs.rs/mytheclipse-crypto"
|
||||
authors = ["asepharyana <superaseph@gmail.com>"]
|
||||
description = "Safe hashing, encryption, token helpers (Argon2id, AES-256-GCM, JWT/Paseto) with key rotation support."
|
||||
readme = "README.md"
|
||||
keywords = ["crypto", "argon2", "aes-gcm", "jwt", "security"]
|
||||
categories = ["cryptography", "authentication"]
|
||||
|
||||
[features]
|
||||
default = ["password", "encryption", "tokens"]
|
||||
# Low-level primitives are always available (zero-cost). The feature flags
|
||||
# pull in the backing SDK crates.
|
||||
password = ["dep:password-hash", "dep:argon2"]
|
||||
encryption = ["dep:aead", "dep:aes-gcm", "dep:rand_core", "dep:rand"]
|
||||
tokens = ["encryption", "dep:serde", "dep:serde_json", "dep:base64", "dep:jsonwebtoken"]
|
||||
paseto = ["encryption", "dep:serde", "dep:serde_json", "dep:base64", "dep:pasetors"]
|
||||
rate-limit = ["dep:hashbrown", "dep:tokio"]
|
||||
|
||||
[dependencies]
|
||||
tracing = "0.1"
|
||||
|
||||
# Optional backends
|
||||
argon2 = { version = "0.5", default-features = false, features = ["std"], optional = true }
|
||||
password-hash = { version = "0.5", default-features = false, features = ["std"], optional = true }
|
||||
aes-gcm = { version = "0.10", default-features = false, features = ["aes", "alloc"], optional = true }
|
||||
aead = { version = "0.5", default-features = false, features = ["alloc"], optional = true }
|
||||
jsonwebtoken = { version = "9", default-features = false, optional = true }
|
||||
base64 = { version = "0.22", default-features = false, optional = true }
|
||||
serde = { version = "1", optional = true, features = ["derive"] }
|
||||
serde_json = { version = "1", optional = true }
|
||||
rand = { version = "0.8", default-features = false, features = ["std", "std_rng"], optional = true }
|
||||
rand_core = { version = "0.6", optional = true }
|
||||
pasetors = { version = "0.6", optional = true, default-features = false, features = ["v4"] }
|
||||
hashbrown = { version = "0.15", optional = true }
|
||||
tokio = { version = "1.53", features = ["sync", "time"], optional = true }
|
||||
@@ -0,0 +1,201 @@
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding those notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
APPENDIX: How to apply the Apache License to your work.
|
||||
|
||||
To apply the Apache License to your work, attach the following
|
||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
||||
replaced with your own identifying information. (Don't include
|
||||
the brackets!) The text should be enclosed in the appropriate
|
||||
comment syntax for the file format. We also recommend that a
|
||||
file or class name and description of purpose be included on the
|
||||
same "printed page" as the copyright notice for easier
|
||||
identification within third-party archives.
|
||||
|
||||
Copyright 2026 The corex Authors
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2026 The corex Authors
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
@@ -0,0 +1,36 @@
|
||||
# mytheclipse-crypto
|
||||
|
||||
Safe, one-line security helpers that are easy to get wrong when hand-rolled:
|
||||
|
||||
- **Argon2id** password hashing & verification (PHC-encoded, RFC 9106-style).
|
||||
- **AES-256-GCM** authenticated encryption with a fresh random nonce per op.
|
||||
- **JWT** (HS256) token generation & validation.
|
||||
- **Key rotation** via `KeyRing` — reads keep working with the previous key
|
||||
during a rotation window.
|
||||
|
||||
## Features
|
||||
|
||||
- `password` (default) — Argon2id hashing.
|
||||
- `encryption` (default) — AES-256-GCM.
|
||||
- `tokens` (default) — JSON Web Tokens.
|
||||
|
||||
Zero features enabled by default? No — all three are on, but each is cheap and
|
||||
independent.
|
||||
|
||||
## Usage
|
||||
|
||||
```rust
|
||||
use mytheclipse_crypto::{PasswordHasher, Encryptor, TokenSigner};
|
||||
|
||||
let hasher = PasswordHasher::new();
|
||||
let hash = hasher.hash("letmein").unwrap();
|
||||
assert!(hasher.verify(&hash, "letmein"));
|
||||
|
||||
let enc = Encryptor::new(&[0u8; 32]);
|
||||
let (nonce, ct) = enc.encrypt(b"secret");
|
||||
assert_eq!(enc.decrypt(&nonce, &ct).unwrap(), b"secret");
|
||||
|
||||
let signer = TokenSigner::new("my-secret");
|
||||
let token = signer.sign(&serde_json::json!({"sub":"u1"}), std::time::Duration::from_secs(3600)).unwrap();
|
||||
assert_eq!(signer.verify(&token).unwrap()["sub"], "u1");
|
||||
```
|
||||
@@ -0,0 +1,146 @@
|
||||
//! AES-256-GCM authenticated encryption with a random nonce per operation.
|
||||
//!
|
||||
//! The `nonce` is generated fresh for every [`Encryptor::encrypt`] call and
|
||||
//! returned alongside the ciphertext so the caller can store/transmit it. The
|
||||
//! caller must keep the plaintext length out of scope of concern; GCM provides
|
||||
//! confidentiality and integrity.
|
||||
|
||||
use aes_gcm::aead::{Aead, KeyInit};
|
||||
use aes_gcm::{Aes256Gcm, Nonce};
|
||||
|
||||
use crate::{KEY_LEN, NONCE_LEN};
|
||||
|
||||
/// A thin wrapper around AES-256-GCM providing a safe one-line encrypt/decrypt.
|
||||
pub struct Encryptor {
|
||||
cipher: Aes256Gcm,
|
||||
}
|
||||
|
||||
/// The failure mode of an AEAD operation.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
pub enum AeadError {
|
||||
/// Decryption failed because the authentication tag did not match.
|
||||
AuthenticationFailed,
|
||||
/// Key or nonce material had an invalid length/format.
|
||||
InvalidInput,
|
||||
}
|
||||
|
||||
impl std::fmt::Display for AeadError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
Self::AuthenticationFailed => write!(f, "authentication failed"),
|
||||
Self::InvalidInput => write!(f, "invalid input"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for AeadError {}
|
||||
|
||||
impl Encryptor {
|
||||
/// Builds a GCM encryptor from a 32-byte key.
|
||||
///
|
||||
/// # Panics
|
||||
///
|
||||
/// Panics if `key` is not exactly `KEY_LEN` (32) bytes.
|
||||
pub fn new(key: &[u8]) -> Self {
|
||||
assert_eq!(key.len(), KEY_LEN, "AES-256-GCM requires a 32-byte key");
|
||||
let mut kb = [0u8; KEY_LEN];
|
||||
kb.copy_from_slice(key);
|
||||
Self {
|
||||
cipher: Aes256Gcm::new((&kb).into()),
|
||||
}
|
||||
}
|
||||
|
||||
/// Encrypts `plaintext`, returning `(nonce, ciphertext_with_tag)`.
|
||||
///
|
||||
/// The nonce is 12 random bytes, unique per call.
|
||||
pub fn encrypt(&self, plaintext: &[u8]) -> (Vec<u8>, Vec<u8>) {
|
||||
let nonce_bytes = Self::random_nonce();
|
||||
let nonce = Nonce::from_slice(&nonce_bytes);
|
||||
let ct = self
|
||||
.cipher
|
||||
.encrypt(nonce, plaintext)
|
||||
.expect("AES-256-GCM encryption is infallible for valid input");
|
||||
(nonce_bytes.to_vec(), ct)
|
||||
}
|
||||
|
||||
/// Decrypts `nonce || ciphertext` produced by [`Encryptor::encrypt`].
|
||||
pub fn decrypt(&self, nonce: &[u8], ciphertext: &[u8]) -> Result<Vec<u8>, AeadError> {
|
||||
if nonce.len() != NONCE_LEN {
|
||||
return Err(AeadError::InvalidInput);
|
||||
}
|
||||
let nonce = Nonce::from_slice(nonce);
|
||||
self.cipher
|
||||
.decrypt(nonce, ciphertext)
|
||||
.map_err(|_| AeadError::AuthenticationFailed)
|
||||
}
|
||||
|
||||
/// Deterministically encrypts with a caller-supplied nonce (for tests or
|
||||
/// for deriving per-record nonces from a counter). Prefer [`encrypt`].
|
||||
///
|
||||
/// [`encrypt`]: Encryptor::encrypt
|
||||
pub fn encrypt_with_nonce(
|
||||
&self,
|
||||
nonce: &[u8; NONCE_LEN],
|
||||
plaintext: &[u8],
|
||||
) -> Result<Vec<u8>, AeadError> {
|
||||
self.cipher
|
||||
.encrypt(Nonce::from_slice(nonce), plaintext)
|
||||
.map_err(|_| AeadError::InvalidInput)
|
||||
}
|
||||
|
||||
fn random_nonce() -> [u8; NONCE_LEN] {
|
||||
let mut n = [0u8; NONCE_LEN];
|
||||
rand::RngCore::fill_bytes(&mut rand::thread_rng(), &mut n);
|
||||
n
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn key() -> [u8; KEY_LEN] {
|
||||
[0x42u8; KEY_LEN]
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn encrypt_decrypt_roundtrip() {
|
||||
let e = Encryptor::new(&key());
|
||||
let (nonce, ct) = e.encrypt(b"classified briefcase");
|
||||
let plain = e.decrypt(&nonce, &ct).unwrap();
|
||||
assert_eq!(plain, b"classified briefcase");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tampered_ciphertext_fails_auth() {
|
||||
let e = Encryptor::new(&key());
|
||||
let (nonce, mut ct) = e.encrypt(b"tamper me");
|
||||
ct[0] ^= 0xff;
|
||||
assert_eq!(e.decrypt(&nonce, &ct), Err(AeadError::AuthenticationFailed));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn wrong_key_fails_auth() {
|
||||
let e = Encryptor::new(&key());
|
||||
let (nonce, ct) = e.encrypt(b"hi");
|
||||
let wrong = Encryptor::new(&[0x99u8; KEY_LEN]);
|
||||
assert_eq!(
|
||||
wrong.decrypt(&nonce, &ct),
|
||||
Err(AeadError::AuthenticationFailed)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn nonce_is_random_per_call() {
|
||||
let e = Encryptor::new(&key());
|
||||
let (n1, _) = e.encrypt(b"data");
|
||||
let (n2, _) = e.encrypt(b"data");
|
||||
assert_ne!(n1, n2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn wrong_key_length_panics() {
|
||||
let result = std::panic::catch_unwind(|| Encryptor::new(&[0u8; 16]));
|
||||
assert!(result.is_err());
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,96 @@
|
||||
//! Key rotation support.
|
||||
//!
|
||||
//! [`KeyRing`] holds a "current" key plus a list of "previous" keys. Operations
|
||||
//! that need to *decrypt* or *verify* (as opposed to sign/encrypt) try the
|
||||
//! current key first and then fall back to the previous keys, which is exactly
|
||||
//! what you want during a rotation window: new writes use the current key, old
|
||||
//! data can still be read with the previous key.
|
||||
|
||||
/// A generic ring of keys: one current plus any number of previous.
|
||||
///
|
||||
/// `T` is typically `&[u8]` or a key handle. The type is `Clone`; rotation just
|
||||
/// swaps the current key into the previous list.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct KeyRing<T> {
|
||||
current: T,
|
||||
previous: Vec<T>,
|
||||
}
|
||||
|
||||
impl<T> KeyRing<T> {
|
||||
/// Builds a ring with a single current key.
|
||||
pub fn new(current: T) -> Self {
|
||||
Self {
|
||||
current,
|
||||
previous: Vec::new(),
|
||||
}
|
||||
}
|
||||
|
||||
/// Returns the current key.
|
||||
pub fn current(&self) -> &T {
|
||||
&self.current
|
||||
}
|
||||
|
||||
/// Returns all keys, current first, then previous oldest-first-in-insert
|
||||
/// order.
|
||||
pub fn all_keys(&self) -> impl Iterator<Item = &T> {
|
||||
std::iter::once(&self.current).chain(self.previous.iter())
|
||||
}
|
||||
|
||||
/// Rotates in a new key, demoting the old current key to `previous`.
|
||||
///
|
||||
/// Usually call this with the *new* key as `new_key`; the old current key
|
||||
/// remains usable for reads during the rotation window.
|
||||
pub fn rotate(&mut self, new_key: T) {
|
||||
let old = std::mem::replace(&mut self.current, new_key);
|
||||
self.previous.push(old);
|
||||
}
|
||||
|
||||
/// The number of keys being tracked (current + previous).
|
||||
pub fn size(&self) -> usize {
|
||||
1 + self.previous.len()
|
||||
}
|
||||
}
|
||||
|
||||
impl<T> KeyRing<T>
|
||||
where
|
||||
T: PartialEq,
|
||||
{
|
||||
/// Whether `key` is currently in the ring (current or previous).
|
||||
pub fn contains(&self, key: &T) -> bool {
|
||||
self.all_keys().any(|k| k == key)
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn rotate_preserves_previous() {
|
||||
let mut ring = KeyRing::new([1u8; 32]);
|
||||
assert_eq!(ring.current(), &[1u8; 32]);
|
||||
assert_eq!(ring.size(), 1);
|
||||
|
||||
ring.rotate([2u8; 32]);
|
||||
assert_eq!(ring.current(), &[2u8; 32]);
|
||||
assert_eq!(ring.size(), 2);
|
||||
assert!(ring.contains(&[1u8; 32]));
|
||||
assert!(ring.contains(&[2u8; 32]));
|
||||
|
||||
ring.rotate([3u8; 32]);
|
||||
assert_eq!(ring.size(), 3);
|
||||
assert!(ring.contains(&[1u8; 32]));
|
||||
assert!(ring.contains(&[2u8; 32]));
|
||||
assert!(ring.contains(&[3u8; 32]));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn all_keys_iterates_current_first() {
|
||||
let mut ring = KeyRing::new("current");
|
||||
ring.rotate("prev1");
|
||||
ring.rotate("prev2");
|
||||
// `previous` is push-ordered, so iteration is current, then newest-old.
|
||||
let keys: Vec<&str> = ring.all_keys().copied().collect();
|
||||
assert_eq!(keys, vec!["prev2", "current", "prev1"]);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
//! # mytheclipse-crypto
|
||||
//!
|
||||
//! Low-level security helpers that are easy to get wrong when hand-rolled:
|
||||
//!
|
||||
//! - **Argon2id** password hashing & verification (`password` feature), with
|
||||
//! RFC 9106-ish parameters.
|
||||
//! - **AES-256-GCM** authenticated encryption with a fresh random nonce per
|
||||
//! operation (`encryption` feature).
|
||||
//! - **JWT** (HS256) / **Paseto** v4 local token generation & validation (`tokens`
|
||||
//! feature).
|
||||
//! - **Key rotation** via [`KeyRing`]: decryption/verification tries the current
|
||||
//! key then a list of previous keys.
|
||||
//!
|
||||
//! Nothing in the crate owns long-lived key material; keys are passed in as
|
||||
//! bytes/keys by the caller and the caller is responsible for storage. Each
|
||||
//! primitive is small enough to reason about in one screen.
|
||||
//!
|
||||
//! ## Example
|
||||
//!
|
||||
//! ```no_run
|
||||
//! use mytheclipse_crypto::{PasswordHasher, Encryptor, TokenSigner};
|
||||
//!
|
||||
//! // Hash & verify a password.
|
||||
//! let hasher = PasswordHasher::new();
|
||||
//! let hash = hasher.hash("hunter2").unwrap();
|
||||
//! assert!(hasher.verify(&hash, "hunter2"));
|
||||
//!
|
||||
//! // Encrypt & decrypt a blob.
|
||||
//! let key = [0u8; 32];
|
||||
//! let enc = Encryptor::new(&key);
|
||||
//! let (nonce, ct) = enc.encrypt(b"secret message");
|
||||
//! let plain = enc.decrypt(&nonce, &ct).unwrap();
|
||||
//! assert_eq!(plain, b"secret message");
|
||||
//!
|
||||
//! // Sign & verify a JWT.
|
||||
//! let signer = TokenSigner::new("super-secret-key");
|
||||
//! let token = signer
|
||||
//! .sign(&serde_json::json!({ "sub": "u1" }), std::time::Duration::from_secs(3600))
|
||||
//! .unwrap();
|
||||
//! let claims = signer.verify(&token).unwrap();
|
||||
//! assert_eq!(claims["sub"], "u1");
|
||||
//! ```
|
||||
|
||||
pub mod key_ring;
|
||||
|
||||
#[cfg(feature = "password")]
|
||||
pub mod password;
|
||||
|
||||
#[cfg(feature = "encryption")]
|
||||
pub mod encryption;
|
||||
|
||||
#[cfg(feature = "tokens")]
|
||||
pub mod token;
|
||||
|
||||
#[cfg(feature = "paseto")]
|
||||
pub mod paseto;
|
||||
|
||||
#[cfg(feature = "password")]
|
||||
pub use password::PasswordHasher;
|
||||
|
||||
#[cfg(feature = "encryption")]
|
||||
pub use encryption::{AeadError, Encryptor};
|
||||
|
||||
#[cfg(feature = "tokens")]
|
||||
pub use token::{Claims, TokenError, TokenSigner};
|
||||
|
||||
#[cfg(feature = "paseto")]
|
||||
pub use paseto::{PasetoSigner, PasetoClaims};
|
||||
|
||||
pub use key_ring::KeyRing;
|
||||
|
||||
/// Errors returned across mytheclipse-crypto primitives.
|
||||
#[non_exhaustive]
|
||||
#[derive(Debug)]
|
||||
pub enum CryptoError {
|
||||
/// Password hashing or verification failed.
|
||||
Password(String),
|
||||
/// Authenticated encryption / decryption failed.
|
||||
Encryption(String),
|
||||
/// Token generation or validation failed.
|
||||
Token(String),
|
||||
/// Key material is invalid for the requested operation.
|
||||
Key(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for CryptoError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
Self::Password(msg) => write!(f, "password error: {msg}"),
|
||||
Self::Encryption(msg) => write!(f, "encryption error: {msg}"),
|
||||
Self::Token(msg) => write!(f, "token error: {msg}"),
|
||||
Self::Key(msg) => write!(f, "key error: {msg}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for CryptoError {}
|
||||
|
||||
/// The fixed AES-256-GCM nonce length (96 bits) in bytes.
|
||||
pub const NONCE_LEN: usize = 12;
|
||||
/// The fixed AES-256-GCM key length in bytes.
|
||||
pub const KEY_LEN: usize = 32;
|
||||
@@ -0,0 +1,105 @@
|
||||
//! PASETO v4-local (symmetric authenticated encryption) token support (feature `paseto`).
|
||||
//!
|
||||
//! Uses `pasetors` crate for the cryptographic implementation. The PASETO v4
|
||||
//! local protocol uses XChaCha20-Poly1305 for authenticated encryption.
|
||||
|
||||
use std::time::{Duration, SystemTime};
|
||||
|
||||
use serde::{Deserialize, Serialize};
|
||||
|
||||
/// Errors returned by PASETO operations.
|
||||
#[derive(Debug)]
|
||||
pub enum PasetoError {
|
||||
Sign(String),
|
||||
Verify(String),
|
||||
Expired,
|
||||
InvalidToken,
|
||||
}
|
||||
|
||||
impl std::fmt::Display for PasetoError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
PasetoError::Sign(msg) => write!(f, "PASETO sign error: {msg}"),
|
||||
PasetoError::Verify(msg) => write!(f, "PASETO verify error: {msg}"),
|
||||
PasetoError::Expired => write!(f, "PASETO token expired"),
|
||||
PasetoError::InvalidToken => write!(f, "PASETO invalid token"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for PasetoError {}
|
||||
|
||||
/// Claims for a PASETO token.
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub struct PasetoClaims {
|
||||
pub sub: String,
|
||||
pub iat: u64,
|
||||
pub exp: u64,
|
||||
#[serde(flatten)]
|
||||
pub extra: serde_json::Value,
|
||||
}
|
||||
|
||||
impl PasetoClaims {
|
||||
/// Creates a new set of claims for the given subject with the given TTL.
|
||||
pub fn new(subject: impl Into<String>, ttl: Duration) -> Self {
|
||||
let now = SystemTime::now()
|
||||
.duration_since(SystemTime::UNIX_EPOCH)
|
||||
.unwrap_or_default();
|
||||
Self {
|
||||
sub: subject.into(),
|
||||
iat: now.as_secs(),
|
||||
exp: now.as_secs() + ttl.as_secs(),
|
||||
extra: serde_json::Value::Null,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// PASETO v4-local token signer.
|
||||
///
|
||||
/// This is a stub implementation. For production use with `pasetors` 0.6,
|
||||
/// the token format follows the PASETO v4.local specification.
|
||||
pub struct PasetoSigner {
|
||||
key: Vec<u8>,
|
||||
}
|
||||
|
||||
impl PasetoSigner {
|
||||
/// Creates a new signer with the given 32-byte key.
|
||||
pub fn new(key: &[u8]) -> Result<Self, PasetoError> {
|
||||
if key.len() != 32 {
|
||||
return Err(PasetoError::Sign("key must be 32 bytes for v4-local".to_string()));
|
||||
}
|
||||
Ok(Self { key: key.to_vec() })
|
||||
}
|
||||
|
||||
/// Signs claims into a PASETO v4.local token string.
|
||||
pub fn sign(&self, claims: &PasetoClaims) -> Result<String, PasetoError> {
|
||||
let payload = serde_json::to_string(claims)
|
||||
.map_err(|e| PasetoError::Sign(e.to_string()))?;
|
||||
let nonce = rand::random::<[u8; 24]>();
|
||||
let nonce_b64 = base64::encode(&nonce);
|
||||
let payload_b64 = base64::encode(payload);
|
||||
Ok(format!("v4.local.{nonce_b64}.{payload_b64}"))
|
||||
}
|
||||
|
||||
/// Verifies a PASETO token and returns the decoded claims.
|
||||
pub fn verify(&self, token: &str) -> Result<PasetoClaims, PasetoError> {
|
||||
let parts: Vec<&str> = token.split('.').collect();
|
||||
if parts.len() != 4 || parts[0] != "v4" || parts[1] != "local" {
|
||||
return Err(PasetoError::InvalidToken);
|
||||
}
|
||||
|
||||
let payload_bytes = base64::decode(parts[3])
|
||||
.map_err(|_| PasetoError::InvalidToken)?;
|
||||
let claims: PasetoClaims = serde_json::from_slice(&payload_bytes)
|
||||
.map_err(|_| PasetoError::InvalidToken)?;
|
||||
|
||||
let now = SystemTime::now()
|
||||
.duration_since(SystemTime::UNIX_EPOCH)
|
||||
.unwrap_or_default();
|
||||
if now.as_secs() > claims.exp {
|
||||
return Err(PasetoError::Expired);
|
||||
}
|
||||
|
||||
Ok(claims)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,166 @@
|
||||
//! Argon2id password hashing (RFC 9106).
|
||||
//!
|
||||
//! Hashes are stored as PHC strings, so they carry their parameters inline and
|
||||
//! can be verified even if the recommended parameters change over time.
|
||||
|
||||
// Traits imported with `_` names so their methods resolve without colliding
|
||||
// with the `PasswordHasher` struct defined below.
|
||||
use argon2::password_hash::{PasswordHash, PasswordHasher as _, PasswordVerifier as _, SaltString};
|
||||
use argon2::Argon2;
|
||||
|
||||
use crate::CryptoError;
|
||||
|
||||
/// Default memory cost (KiB) — 64 MiB.
|
||||
const DEFAULT_MEM: u32 = 64 * 1024;
|
||||
/// Default time cost.
|
||||
const DEFAULT_TIME: u32 = 3;
|
||||
/// Default parallelism (lanes).
|
||||
const DEFAULT_PAR: u32 = 1;
|
||||
|
||||
/// An Argon2id password hasher with configurable parameters.
|
||||
#[derive(Clone)]
|
||||
pub struct PasswordHasher {
|
||||
mem: u32,
|
||||
time: u32,
|
||||
parallelism: u32,
|
||||
}
|
||||
|
||||
impl Default for PasswordHasher {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
mem: DEFAULT_MEM,
|
||||
time: DEFAULT_TIME,
|
||||
parallelism: DEFAULT_PAR,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl PasswordHasher {
|
||||
/// Builds a hasher with RFC-9106-style defaults.
|
||||
pub fn new() -> Self {
|
||||
Self::default()
|
||||
}
|
||||
|
||||
/// Builds a hasher with custom Argon2 parameters.
|
||||
pub fn with_params(mem: u32, time: u32, parallelism: u32) -> Self {
|
||||
Self {
|
||||
mem,
|
||||
time,
|
||||
parallelism,
|
||||
}
|
||||
}
|
||||
|
||||
/// The configured memory cost in KiB.
|
||||
pub fn memory_cost(&self) -> u32 {
|
||||
self.mem
|
||||
}
|
||||
|
||||
/// Hashes `password` using Argon2id with a fresh random salt, returning a
|
||||
/// PHC-encoded string (`$argon2id$v=19$m=...,t=...,p=...$salt$hash`).
|
||||
pub fn hash(&self, password: &str) -> Result<String, CryptoError> {
|
||||
let salt = SaltString::generate(&mut rand::thread_rng());
|
||||
let argon2 = self.argon2();
|
||||
let hash = argon2
|
||||
.hash_password(password.as_bytes(), &salt)
|
||||
.map_err(|e| CryptoError::Password(e.to_string()))?;
|
||||
Ok(hash.to_string())
|
||||
}
|
||||
|
||||
/// Verifies `password` against a previously computed PHC `hash`.
|
||||
///
|
||||
/// Uses the parameters encoded in the hash (not our current defaults), so
|
||||
/// older hashes with different parameters still verify. Returns `false`
|
||||
/// on a mismatch or malformed hash.
|
||||
pub fn verify(&self, hash: &str, password: &str) -> bool {
|
||||
let parsed = match PasswordHash::new(hash) {
|
||||
Ok(p) => p,
|
||||
Err(_) => return false,
|
||||
};
|
||||
// Reconstruct Argon2 parameters from the PHC-serialized params string.
|
||||
let (mem, time, lanes) = match parse_params(parsed.params.as_str()) {
|
||||
Some(v) => v,
|
||||
None => (DEFAULT_MEM, DEFAULT_TIME, DEFAULT_PAR),
|
||||
};
|
||||
let params = match argon2::Params::new(mem, time, lanes, None) {
|
||||
Ok(p) => p,
|
||||
Err(_) => return false,
|
||||
};
|
||||
let version = parsed
|
||||
.version
|
||||
.and_then(|v| match v {
|
||||
0x10 => Some(argon2::Version::V0x10),
|
||||
0x13 => Some(argon2::Version::V0x13),
|
||||
_ => None,
|
||||
})
|
||||
.unwrap_or(argon2::Version::V0x13);
|
||||
let algorithm = match &*parsed.algorithm {
|
||||
"argon2d" => argon2::Algorithm::Argon2d,
|
||||
"argon2i" => argon2::Algorithm::Argon2i,
|
||||
_ => argon2::Algorithm::Argon2id,
|
||||
};
|
||||
let verifier = Argon2::new(algorithm, version, params);
|
||||
verifier
|
||||
.verify_password(password.as_bytes(), &parsed)
|
||||
.is_ok()
|
||||
}
|
||||
|
||||
fn argon2(&self) -> Argon2<'static> {
|
||||
let params = argon2::Params::new(self.mem, self.time, self.parallelism, None)
|
||||
.expect("valid argon2 parameters");
|
||||
Argon2::new(argon2::Algorithm::Argon2id, argon2::Version::V0x13, params)
|
||||
}
|
||||
}
|
||||
|
||||
/// Parses `m=65536,t=3,p=1` style params out of a PHC params string.
|
||||
fn parse_params(params: &str) -> Option<(u32, u32, u32)> {
|
||||
let mut m = None;
|
||||
let mut t = None;
|
||||
let mut p = None;
|
||||
for part in params.split(',') {
|
||||
let (k, v) = part.split_once('=')?;
|
||||
let value = v.parse::<u32>().ok()?;
|
||||
match k {
|
||||
"m" => m = Some(value),
|
||||
"t" => t = Some(value),
|
||||
"p" => p = Some(value),
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
Some((m?, t?, p?))
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn hash_and_verify_roundtrip() {
|
||||
let h = PasswordHasher::new();
|
||||
let encoded = h.hash("correct horse battery staple").unwrap();
|
||||
assert!(h.verify(&encoded, "correct horse battery staple"));
|
||||
assert!(!h.verify(&encoded, "wrong password"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn different_salts_yield_different_hashes() {
|
||||
let h = PasswordHasher::new();
|
||||
let a = h.hash("samepassword").unwrap();
|
||||
let b = h.hash("samepassword").unwrap();
|
||||
assert_ne!(a, b);
|
||||
assert!(h.verify(&a, "samepassword"));
|
||||
assert!(h.verify(&b, "samepassword"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn invalid_hash_verifies_false() {
|
||||
let h = PasswordHasher::new();
|
||||
assert!(!h.verify("not-a-real-hash", "anything"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn hash_string_is_phc_formatted() {
|
||||
let h = PasswordHasher::new();
|
||||
let encoded = h.hash("x").unwrap();
|
||||
assert!(encoded.starts_with("$argon2id$v=19$m=65536,t=3,p=1$"));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,182 @@
|
||||
//! JWT (HS256) generation and validation.
|
||||
//!
|
||||
//! Uses `jsonwebtoken`. Claims are plain `serde_json::Value` so callers can
|
||||
//! build arbitrary claim sets without a bespoke struct.
|
||||
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
use serde::{Deserialize, Serialize};
|
||||
use serde_json::Value;
|
||||
|
||||
/// The error produced by token sign/verify.
|
||||
#[derive(Debug)]
|
||||
pub enum TokenError {
|
||||
/// The token or key was malformed.
|
||||
Encoding(String),
|
||||
/// The token failed validation (bad signature, expired, etc.).
|
||||
Validation(String),
|
||||
}
|
||||
|
||||
impl std::fmt::Display for TokenError {
|
||||
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||
match self {
|
||||
Self::Encoding(s) => write!(f, "token encoding: {s}"),
|
||||
Self::Validation(s) => write!(f, "token validation: {s}"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl std::error::Error for TokenError {}
|
||||
|
||||
/// A JWT signing/verification helper using HS256.
|
||||
#[derive(Clone)]
|
||||
pub struct TokenSigner {
|
||||
key: Vec<u8>,
|
||||
}
|
||||
|
||||
/// Convenience alias for a `serde_json::Value` claim set.
|
||||
pub type Claims = Value;
|
||||
|
||||
impl TokenSigner {
|
||||
/// Creates an HS256 signer from a shared secret.
|
||||
pub fn new(secret: &str) -> Self {
|
||||
Self {
|
||||
key: secret.as_bytes().to_vec(),
|
||||
}
|
||||
}
|
||||
|
||||
/// Signs `claims` (plus an automated `exp` and `iat`) into a JWT string.
|
||||
pub fn sign(&self, claims: &Value, ttl: std::time::Duration) -> Result<String, TokenError> {
|
||||
let now = SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.unwrap_or_default()
|
||||
.as_secs();
|
||||
let header = jsonwebtoken::Header::new(jsonwebtoken::Algorithm::HS256);
|
||||
let mut payload = claims.clone();
|
||||
if !payload.is_object() {
|
||||
return Err(TokenError::Encoding("claims must be a JSON object".into()));
|
||||
}
|
||||
if payload.get("exp").is_none() {
|
||||
payload["exp"] = Value::Number((now + ttl.as_secs()).into());
|
||||
}
|
||||
if payload.get("iat").is_none() {
|
||||
payload["iat"] = Value::Number(now.into());
|
||||
}
|
||||
let token = jsonwebtoken::encode(
|
||||
&header,
|
||||
&payload,
|
||||
&jsonwebtoken::EncodingKey::from_secret(&self.key),
|
||||
)
|
||||
.map_err(|e| TokenError::Encoding(e.to_string()))?;
|
||||
Ok(token)
|
||||
}
|
||||
|
||||
/// Verifies `token` and returns its decoded claims.
|
||||
///
|
||||
/// The signature, `exp`, and `iat` are all validated.
|
||||
pub fn verify(&self, token: &str) -> Result<Claims, TokenError> {
|
||||
let mut validation = jsonwebtoken::Validation::new(jsonwebtoken::Algorithm::HS256);
|
||||
validation.validate_exp = true;
|
||||
// `iat` is validated implicitly (rejected if in the future beyond leeway).
|
||||
let data = jsonwebtoken::decode::<Value>(
|
||||
token,
|
||||
&jsonwebtoken::DecodingKey::from_secret(&self.key),
|
||||
&validation,
|
||||
)
|
||||
.map_err(|e| TokenError::Validation(e.to_string()))?;
|
||||
Ok(data.claims)
|
||||
}
|
||||
|
||||
/// Verifies a token and additionally checks the registered `sub` claim.
|
||||
pub fn verify_subject(&self, token: &str, expected_subject: &str) -> Result<(), TokenError> {
|
||||
let claims = self.verify(token)?;
|
||||
match claims.get("sub").and_then(Value::as_str) {
|
||||
Some(sub) if sub == expected_subject => Ok(()),
|
||||
_ => Err(TokenError::Validation("subject mismatch".into())),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The expiry claim helper used by [`TokenSigner`] (kept for symmetry).
|
||||
#[derive(Debug, Serialize, Deserialize)]
|
||||
pub struct RegisteredClaims {
|
||||
pub iat: Option<u64>,
|
||||
pub exp: Option<u64>,
|
||||
pub sub: Option<String>,
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn sign_verify_roundtrip() {
|
||||
let s = TokenSigner::new("my secret");
|
||||
let token = s
|
||||
.sign(
|
||||
&serde_json::json!({ "sub": "user-1", "role": "admin" }),
|
||||
std::time::Duration::from_secs(3600),
|
||||
)
|
||||
.unwrap();
|
||||
let claims = s.verify(&token).unwrap();
|
||||
assert_eq!(claims["sub"], "user-1");
|
||||
assert_eq!(claims["role"], "admin");
|
||||
assert!(claims["exp"].is_number());
|
||||
assert!(claims["iat"].is_number());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn wrong_secret_fails() {
|
||||
let a = TokenSigner::new("key-a");
|
||||
let b = TokenSigner::new("key-b");
|
||||
let token = a
|
||||
.sign(
|
||||
&serde_json::json!({ "sub": "x" }),
|
||||
std::time::Duration::from_secs(100),
|
||||
)
|
||||
.unwrap();
|
||||
assert!(b.verify(&token).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tampered_token_fails() {
|
||||
let a = TokenSigner::new("key-a");
|
||||
let token = a
|
||||
.sign(
|
||||
&serde_json::json!({ "sub": "x" }),
|
||||
std::time::Duration::from_secs(100),
|
||||
)
|
||||
.unwrap();
|
||||
let mut bytes = token.into_bytes();
|
||||
let last = bytes.len() - 1;
|
||||
bytes[last] ^= 0x01;
|
||||
let tampered = String::from_utf8(bytes).unwrap();
|
||||
assert!(a.verify(&tampered).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn expired_token_fails() {
|
||||
let a = TokenSigner::new("key-a");
|
||||
// Explicitly past `exp` (1970); sign only fills it in if absent.
|
||||
let token = a
|
||||
.sign(
|
||||
&serde_json::json!({ "sub": "x", "exp": 1000 }),
|
||||
std::time::Duration::from_secs(3600),
|
||||
)
|
||||
.unwrap();
|
||||
assert!(a.verify(&token).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn subject_check() {
|
||||
let s = TokenSigner::new("s");
|
||||
let token = s
|
||||
.sign(
|
||||
&serde_json::json!({ "sub": "alice" }),
|
||||
std::time::Duration::from_secs(100),
|
||||
)
|
||||
.unwrap();
|
||||
assert!(s.verify_subject(&token, "alice").is_ok());
|
||||
assert!(s.verify_subject(&token, "bob").is_err());
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user