feat(tauth): rework TAuth

This commit is contained in:
Alois 2026-09-14 19:31:37 +02:00
commit 3685babebf
Signed by: alois
SSH key fingerprint: SHA256:GBzT2DXvAuGV9XIV5W3WrzVpjU54FThmxHXdbz95J24
31 changed files with 3418 additions and 502 deletions

View file

@ -45,6 +45,23 @@ pub enum LocalRequest {
GetStatus,
ListTasks,
ListUsers,
ListTAuthApps,
GetTAuthApp {
app_id: String,
},
CreateTAuthApp {
owner_user_id: i64,
domain: String,
name: String,
redirects: Vec<String>,
connection: TAuthConnectionInput,
},
ExportTAuthApp {
app_id: String,
},
DeleteTAuthApp {
app_id: String,
},
CreateInvitation {
authority: InvitationAuthority,
lifetime_seconds: u64,
@ -79,11 +96,11 @@ pub enum LocalRequest {
GetUserDiagnostics {
user_id: i64,
},
RevokeTrustedApp {
RevokeTAuthGrant {
user_id: i64,
app_id: String,
},
RevokeAllTrustedApps {
RevokeAllTAuthGrants {
user_id: i64,
},
ExportUserCredential {
@ -161,6 +178,8 @@ impl LocalRequest {
Self::GetStatus
| Self::ListTasks
| Self::ListUsers
| Self::ListTAuthApps
| Self::GetTAuthApp { .. }
| Self::ListInvitations { .. }
| Self::GetDaemonStatus
| Self::GetOmikronStatus
@ -174,6 +193,9 @@ impl LocalRequest {
Self::ReconnectOmikron | Self::ReloadConfig => IpcRole::Operate,
Self::CreateUser { .. }
| Self::CreateTAuthApp { .. }
| Self::ExportTAuthApp { .. }
| Self::DeleteTAuthApp { .. }
| Self::CreateInvitation { .. }
| Self::RevokeInvitation { .. }
| Self::InspectTuCredential { .. }
@ -181,8 +203,8 @@ impl LocalRequest {
| Self::ReconcileUser { .. }
| Self::ForceDetachUser { .. }
| Self::ForgetReleasedUser { .. }
| Self::RevokeTrustedApp { .. }
| Self::RevokeAllTrustedApps { .. }
| Self::RevokeTAuthGrant { .. }
| Self::RevokeAllTAuthGrants { .. }
| Self::ExportUserCredential { .. }
| Self::PurgeUserData { .. }
| Self::ReleaseUser { .. }
@ -265,6 +287,18 @@ pub enum ResponsePayload {
Status(StatusResponse),
Tasks(Vec<TaskSummary>),
Users(Vec<UserSummary>),
TAuthApps(Vec<TAuthAppSummary>),
TAuthApp(TAuthAppSummary),
TAuthAppCreated {
app: TAuthAppSummary,
credential: SecretString,
txt_record: String,
manifest_template: String,
},
TAuthAppCredentialExport {
app_id: String,
credential: SecretString,
},
InvitationCreated(InvitationCreated),
Invitations(Vec<InvitationSummary>),
InvitationUpdated(InvitationSummary),
@ -311,6 +345,29 @@ pub struct OmikronStatusResponse {
pub iota_id: Option<u64>,
}
#[derive(Clone, Debug, Deserialize, Serialize, PartialEq, Eq)]
#[serde(tag = "mode", rename_all = "snake_case")]
pub enum TAuthConnectionInput {
Hosted {
omega_url: String,
},
ForcedOmikron {
omikron_url: String,
omikron_public_key: String,
},
}
#[derive(Clone, Debug, Deserialize, Serialize)]
pub struct TAuthAppSummary {
pub app_id: String,
pub owner_user_id: i64,
pub domain: String,
pub public_key: String,
pub connection_mode: String,
pub endpoint_url: String,
pub created_at: i64,
}
#[derive(Clone, Debug, Deserialize, Serialize)]
pub struct ComponentStatusResponse {
pub id: ComponentId,
@ -324,7 +381,7 @@ pub struct UserDetailResponse {
pub username: String,
pub display_name: Option<String>,
pub created_at: i64,
pub trusted_apps: Vec<String>,
pub tauth_grants: Vec<String>,
pub state: LocalUserState,
pub data_present: bool,
pub credential_status: CredentialStatus,
@ -467,7 +524,7 @@ pub struct UserDiagnostics {
pub local_state: LocalUserState,
pub data_present: bool,
pub credential_status: CredentialStatus,
pub trusted_app_count: usize,
pub tauth_grant_count: usize,
pub pending_operation: Option<String>,
}