Dependency cleanup (ponytail audit): - Drop 14 unused dependency declarations across 7 crates; quick-xml and x509-parser leave the tree entirely (SAML cert/XML work is handled by bergshamra + roxmltree). Fixes: - introspect: drop the over-broad "microsoft" UTF-16 bulk-scan marker that mislabeled Secure-Boot-signed non-Windows bootables (memtest86, signed BSDs, firmware tools) as Windows — the string lives in their MS-signed EFI loader's FAT long-filename entries. INTROSPECT_REV 3 -> 4 re-probes existing local ISOs on startup so the bogus label clears on upgrade. - upload: begin_upload now reclaims an abandoned <id>.partial instead of rejecting the re-upload with "already uploading". Robust against browser refresh, tab close, and dropped connections (the chunked protocol can't resume a dead session anyway). Features: - Storage upload: multi-file + concurrent. Each dropped/selected .iso gets its own progress row and uploads independently; a single page-leave guard plus a pagehide keepalive-abort replace the old shared singletons. - Operator API key (x-api-key): a persisted key authenticates /api/* exactly like an operator session, for Postman/scripts. New core ApiKeyStore (generated on first run, regenerable), accepted in require_auth alongside the session cookie, surfaced in Settings -> Advanced with copy + regenerate and a usage reference. GET /api/api-key + POST /api/api-key/regenerate. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
46 lines
1.4 KiB
TOML
46 lines
1.4 KiB
TOML
[package]
|
|
name = "openpxe-core"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
authors.workspace = true
|
|
description = "Shared types, config, and arch detection for OpenPXE"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
toml.workspace = true
|
|
figment.workspace = true
|
|
thiserror.workspace = true
|
|
anyhow.workspace = true
|
|
tracing.workspace = true
|
|
tracing-subscriber.workspace = true
|
|
time.workspace = true
|
|
uuid.workspace = true
|
|
parking_lot.workspace = true
|
|
tokio = { workspace = true, features = ["sync", "rt", "macros", "time"] }
|
|
# bcrypt for the admin Forms auth (v0.4.5). Already in the workspace
|
|
# for per-ISO boot passwords; just re-exported here.
|
|
bcrypt.workspace = true
|
|
|
|
# v0.5.1: pure-Rust SAML 2.0 SP. bergshamra = XML-DSig verify + exclusive
|
|
# c14n (no OpenSSL/C), plus IdP signing-cert extraction from metadata.
|
|
# roxmltree parses the SAML/metadata XML; flate2+base64 encode the
|
|
# HTTP-Redirect binding's SAMLRequest.
|
|
bergshamra.workspace = true
|
|
roxmltree.workspace = true
|
|
flate2.workspace = true
|
|
base64.workspace = true
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3.12"
|
|
# v0.5.4: figment's `Jail` (hermetic env/file sandbox) for the config
|
|
# loader tests lives behind the `test` feature.
|
|
figment = { workspace = true, features = ["test"] }
|
|
# v0.5.1: generate a throwaway self-signed signing cert/key so SAML
|
|
# verification tests can produce genuinely signed SAMLResponses.
|
|
rcgen = "0.13"
|