[package] name = "swarm-nats-auth" version.workspace = true readme = "README.md" edition.workspace = true [[bin]] name = "swarm-nats-auth" path = "src/main.rs" [dependencies] anyhow.workspace = true clap.workspace = true reqwest.workspace = true serde.workspace = true serde_json.workspace = true tokio.workspace = true tracing.workspace = true tracing-subscriber.workspace = true # The NATS protocol client. `default-features = false` because the default set # is broad - jetstream, kv, object-store, websockets, service - and a callout # responder speaks none of them. What is named here is the whole requirement: # the server generation we actually deploy, nkey auth, and a TLS backend. # (Checked what dropping the defaults costs, the way `internal-logs` was once # lost that way: nothing in the unused set is a diagnostic.) async-nats = { version = "0.50", default-features = false, features = [ "server_2_14", "nkeys", "ring", ] } # base64url for decoding the inbound request JWT. Already in the tree via # nkeys; named directly because this crate uses it directly. data-encoding = "2" # StreamExt::next on the subscription. async-nats returns a Stream, not an # iterator, and futures is already in the tree. futures = "0.3" # nkey seed handling + signing. The primitives (ed25519-dalek, data-encoding) # are already in the tree, but the nkey *format* - ed25519 + base32 + CRC16 - # is not, and hand-rolling a key format on an auth path is how you get a # CRC bug nobody reviews. nkeys = "0.4" # The jti digest: base32hex(sha256(claims)) over every JWT this crate signs. sha2 = "0.10" [dev-dependencies] # A TEST ORACLE, not part of the production path. Neither JWT this crate emits # is expressible through it - `Claims` has no `aud`, which the response wrapper # needs (the server id) and the user token needs (the account name), and # `Token::new_user` always sets `issuer_account`, which a non-operator server # rejects outright. So both are hand-built, and this crate is what the encoder # is checked *against*: `respond::tests::hand_built_matches_the_reference` # builds a user token both ways and requires byte equality, on the one shape # nats-jwt does model. nats-jwt = "0.3" [lints] workspace = true