admin

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: MPL-2.0 Imports: 13 Imported by: 0

README

Admin shell

admin supplies a small compiled same-origin HTTPS shell; each owning Module supplies its real forms and operations. It has no Core registry, database, roles, alternative authentication or business authorization. Products register a finite set of Surface values with New, serve Handler() under the fixed /admin namespace and mount the existing identity.Web independently at the configured AuthPath (for example /auth). Pass identity/admin.Authenticator(web) plus the product Application as Authorizer. Identity owns cookie/CSRF validation; the shell separately authorizes each surface's navigation capability/target and each operation still calls its owning public Service.

A navigation grant is an explicit product choice, never an account-wide domain grant. Request.Allowed is only a presentation hint. Trusted compiled surfaces render an html/template definition named content through Request.Render; request/domain strings must stay template data. Rendering finishes into bounded 128 KiB buffers before writing. Module templates are trusted code, not user-installed templates. Surface IDs stay stable while Text selects English/Persian labels. The shell uses semantic layout/navigation/forms, a skip link, keyboard focus feedback, logical responsive CSS and lang/dir; domain values are neither normalized nor translated.

The first Identity-owned surface is identity/admin.New(service): create an account, inspect one opaque ID or separately authorized exact login, conditionally set status/password and revoke all sessions. Exact-login read reconciles an unknown create response without automatic replay; the product separately grants identity.AccountLookup against the exact validated login. AccountRead with an empty target gates this surface's navigation; actual ID reads still authorize their exact IDs. Password/status forms use the current revision as an exact decimal string through JSON/DOM, never a JavaScript number; RevokeAll uses the existing non-CAS API. No list, profiles or product role model is supplied.

The second real surface is media/admin: a bounded private file library whose upload hints follow the composed Media format selection with module-owned upload, metadata pages, known-ID status, authenticated attachment download and confirmed conditional deletion. Its List collection grant is separate from exact-ID Read/Delete; it exposes no maintenance grant or static paths. Native FormData and delegated form handlers support actual upload and refreshed rows without a frontend framework.

Call ConfigureServer before TLS serving to apply bounded header/total read/write/idle/header-size defaults. The product owns TLS keys/listener, trusted proxy topology if any, and graceful ingress shutdown before Application/Module shutdown. The shell additionally admits at most 16 requests without a queue, bounds bodies to 12 MiB (room for a 10 MiB Media file plus bounded multipart framing), derives a 10 second context and sets actual read/write deadlines through http.ResponseController no later than the caller's deadline. Unsupported writer wrappers fail closed; wrappers must support deadlines or expose Unwrap. Identity's JSON forms further bound reads to 2 KiB/two seconds.

Sensitive responses use no-store, nosniff, no-referrer, frame denial and a same-origin CSP without inline scripts/styles. HSTS belongs to the deployment profile; there is no CORS. Exact TLS/Host, empty query/raw paths, strict JSON and same-origin mutation admission remain required. Existing Identity/Web endpoints own non-simple header/CSRF behavior. The CSRF GET explicitly supplies only the same-origin root referrer with a request-local same-origin policy, refuses cross-origin requests/redirects and preserves Identity's exact origin checks; document responses retain no-referrer. Initial JavaScript uses only a request-local CSRF value, never persistent browser storage; each operation has one finite 15 second AbortController wait, no automatic retry. Password fields clear after completion/failure. An interrupted mutation reports an unknown outcome; inspect the retained exact login or known ID before another action. A not-found read does not prove that an earlier in-flight transaction can never commit.

Focused package tests cover registration, permission/error separation, escaping, browser headers, bounded admission/deadlines and owning Service dispatch. The normal pinned independent consumer and actual TLS/browser proof own end-to-end session, two-surface, keyboard/RTL and payload evidence; no source copy or module replacement is a supported proving path. This shell belongs to the pre-v1 v0.2 source dependency. Product deployment and the real-product lifecycle proof remain separately owned and gated.

Documentation

Overview

SPDX-License-Identifier: MPL-2.0 Package admin composes trusted, compiled Module-owned administration screens. It owns presentation and bounded HTTP admission, never a domain permission or session.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrConfiguration = errors.New("invalid admin configuration")
	// Product adapters translate only genuine missing/invalid sessions to this
	// error. Other authentication failures are unavailable, never a login prompt.
	ErrUnauthenticated = errors.New("admin authentication required")
)

Functions

func ConfigureServer

func ConfigureServer(server *http.Server)

ConfigureServer provides the supported ingress bounds before TLS serving. The product owns address/TLS keys, listener, graceful Shutdown and Module Stop. Compose Admin/Identity/other handlers before calling this helper.

Types

type Authenticator

type Authenticator interface {
	AuthenticateRequest(*http.Request, bool) (achrix.Principal, error)
}

type Authorizer

type Authorizer interface {
	Authorize(context.Context, achrix.Principal, string, string) error
}

type Config

type Config struct {
	Origin string
	// AuthPath is a same-origin absolute mount for the public Identity.Web handler.
	// The product serves it separately; Admin never proxies credentials.
	AuthPath string
	// Language is en or fa. It changes display only, never domain content.
	Language string
}

type Page

type Page struct {
	Title string
	// Template is compile-time Module-owned HTML with a definition named content.
	Template *template.Template
	Data     any
}

type Request

type Request struct {
	Principal achrix.Principal
	Language  string
	Render    func(Page) error
	// Allowed is only a presentation hint; it never grants domain permission.
	Allowed func(capability, target string) bool
}

type Shell

type Shell struct {
	// contains filtered or unexported fields
}

func New

func New(config Config, auth Authenticator, policy Authorizer, surfaces ...Surface) (*Shell, error)

func (*Shell) Handler

func (s *Shell) Handler() http.Handler

type Surface

type Surface struct {
	ID                 string
	Title              Text
	Capability, Target string
	Handler            func(http.ResponseWriter, *http.Request, Request)
}

Surface is a finite, instance-owned registration of trusted compiled code. Capability/Target gate navigation; every operation still uses its domain Service.

type Text

type Text struct{ English, Persian string }

Text keeps protocol IDs independent from translated presentation text.

func (Text) In

func (t Text) In(language string) string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL