kych

OAuth 2.0 API for Swiyu to enable Taler integration of Swiyu for KYC (experimental)
Log | Files | Refs | README | LICENSE

commit 93b9ea2c03898bec1c154f1f76009f1aa4258006
parent 0ada1c2dc18b80635e47b82e046b42ae43262534
Author: Christian Grothoff <christian@grothoff.org>
Date:   Sun,  9 Aug 2026 15:30:31 +0200

add Debian package definition and man pages

Diffstat:
M.gitignore | 13+++++++++++++
ACOPYING | 661+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/README.Debian | 78++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/README.source | 83+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/changelog | 6++++++
Adebian/control | 39+++++++++++++++++++++++++++++++++++++++
Adebian/copyright | 109+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/etc/kych/kych.conf | 173+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/kych.install | 18++++++++++++++++++
Adebian/kych.manpages | 2++
Adebian/kych.service | 49+++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/kych.sysusers | 7+++++++
Adebian/kych.tmpfiles | 5+++++
Adebian/rules | 56++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adebian/stamp-version.sh | 71+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mdocumentation/README | 25+++++++++++++++++++++++++
Adocumentation/sphinx-man/conf.py | 74++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mdocumentation/taler-docs/README | 19+++++++++++++++++++
Ddocumentation/taler-docs/kych.conf.5.rst | 206-------------------------------------------------------------------------------
Mdocumentation/taler-docs/manpages/kych-client-management.1.rst | 170+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++----------------
Mdocumentation/taler-docs/manpages/kych-oauth2-gateway.1.rst | 183+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++--------
Adocumentation/taler-docs/manpages/kych.conf.5.rst | 308+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Akych_oauth2_gateway/Cargo.lock | 3265+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/get_version.sh | 33+++++++++++++++++++++++++++++++++
24 files changed, 5397 insertions(+), 256 deletions(-)

diff --git a/.gitignore b/.gitignore @@ -15,3 +15,16 @@ target/ .vscode/ /codeql/ /swiyu-verifier-codeql-db/ + +# Version stamp written by scripts/get_version.sh +.version + +# Debian build artifacts +debian/cargo/ +debian/man/ +debian/kych/ +debian/files +debian/*.substvars +debian/*.debhelper +debian/debhelper-build-stamp +debian/.debhelper/ diff --git a/COPYING b/COPYING @@ -0,0 +1,661 @@ + GNU AFFERO GENERAL PUBLIC LICENSE + Version 3, 19 November 2007 + + Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/> + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + + Preamble + + The GNU Affero General Public License is a free, copyleft license for +software and other kinds of works, specifically designed to ensure +cooperation with the community in the case of network server software. + + The licenses for most software and other practical works are designed +to take away your freedom to share and change the works. By contrast, +our General Public Licenses are intended to guarantee your freedom to +share and change all versions of a program--to make sure it remains free +software for all its users. + + When we speak of free software, we are referring to freedom, not +price. Our General Public Licenses are designed to make sure that you +have the freedom to distribute copies of free software (and charge for +them if you wish), that you receive source code or can get it if you +want it, that you can change the software or use pieces of it in new +free programs, and that you know you can do these things. + + Developers that use our General Public Licenses protect your rights +with two steps: (1) assert copyright on the software, and (2) offer +you this License which gives you legal permission to copy, distribute +and/or modify the software. + + A secondary benefit of defending all users' freedom is that +improvements made in alternate versions of the program, if they +receive widespread use, become available for other developers to +incorporate. Many developers of free software are heartened and +encouraged by the resulting cooperation. However, in the case of +software used on network servers, this result may fail to come about. +The GNU General Public License permits making a modified version and +letting the public access it on a server without ever releasing its +source code to the public. + + The GNU Affero General Public License is designed specifically to +ensure that, in such cases, the modified source code becomes available +to the community. It requires the operator of a network server to +provide the source code of the modified version running there to the +users of that server. Therefore, public use of a modified version, on +a publicly accessible server, gives the public access to the source +code of the modified version. + + An older license, called the Affero General Public License and +published by Affero, was designed to accomplish similar goals. This is +a different license, not a version of the Affero GPL, but Affero has +released a new version of the Affero GPL which permits relicensing under +this license. + + The precise terms and conditions for copying, distribution and +modification follow. + + TERMS AND CONDITIONS + + 0. Definitions. + + "This License" refers to version 3 of the GNU Affero General Public License. + + "Copyright" also means copyright-like laws that apply to other kinds of +works, such as semiconductor masks. + + "The Program" refers to any copyrightable work licensed under this +License. Each licensee is addressed as "you". "Licensees" and +"recipients" may be individuals or organizations. + + To "modify" a work means to copy from or adapt all or part of the work +in a fashion requiring copyright permission, other than the making of an +exact copy. The resulting work is called a "modified version" of the +earlier work or a work "based on" the earlier work. + + A "covered work" means either the unmodified Program or a work based +on the Program. + + To "propagate" a work means to do anything with it that, without +permission, would make you directly or secondarily liable for +infringement under applicable copyright law, except executing it on a +computer or modifying a private copy. Propagation includes copying, +distribution (with or without modification), making available to the +public, and in some countries other activities as well. + + To "convey" a work means any kind of propagation that enables other +parties to make or receive copies. Mere interaction with a user through +a computer network, with no transfer of a copy, is not conveying. + + An interactive user interface displays "Appropriate Legal Notices" +to the extent that it includes a convenient and prominently visible +feature that (1) displays an appropriate copyright notice, and (2) +tells the user that there is no warranty for the work (except to the +extent that warranties are provided), that licensees may convey the +work under this License, and how to view a copy of this License. If +the interface presents a list of user commands or options, such as a +menu, a prominent item in the list meets this criterion. + + 1. Source Code. + + The "source code" for a work means the preferred form of the work +for making modifications to it. "Object code" means any non-source +form of a work. + + A "Standard Interface" means an interface that either is an official +standard defined by a recognized standards body, or, in the case of +interfaces specified for a particular programming language, one that +is widely used among developers working in that language. + + The "System Libraries" of an executable work include anything, other +than the work as a whole, that (a) is included in the normal form of +packaging a Major Component, but which is not part of that Major +Component, and (b) serves only to enable use of the work with that +Major Component, or to implement a Standard Interface for which an +implementation is available to the public in source code form. A +"Major Component", in this context, means a major essential component +(kernel, window system, and so on) of the specific operating system +(if any) on which the executable work runs, or a compiler used to +produce the work, or an object code interpreter used to run it. + + The "Corresponding Source" for a work in object code form means all +the source code needed to generate, install, and (for an executable +work) run the object code and to modify the work, including scripts to +control those activities. However, it does not include the work's +System Libraries, or general-purpose tools or generally available free +programs which are used unmodified in performing those activities but +which are not part of the work. For example, Corresponding Source +includes interface definition files associated with source files for +the work, and the source code for shared libraries and dynamically +linked subprograms that the work is specifically designed to require, +such as by intimate data communication or control flow between those +subprograms and other parts of the work. + + The Corresponding Source need not include anything that users +can regenerate automatically from other parts of the Corresponding +Source. + + The Corresponding Source for a work in source code form is that +same work. + + 2. Basic Permissions. + + All rights granted under this License are granted for the term of +copyright on the Program, and are irrevocable provided the stated +conditions are met. This License explicitly affirms your unlimited +permission to run the unmodified Program. The output from running a +covered work is covered by this License only if the output, given its +content, constitutes a covered work. This License acknowledges your +rights of fair use or other equivalent, as provided by copyright law. + + You may make, run and propagate covered works that you do not +convey, without conditions so long as your license otherwise remains +in force. You may convey covered works to others for the sole purpose +of having them make modifications exclusively for you, or provide you +with facilities for running those works, provided that you comply with +the terms of this License in conveying all material for which you do +not control copyright. Those thus making or running the covered works +for you must do so exclusively on your behalf, under your direction +and control, on terms that prohibit them from making any copies of +your copyrighted material outside their relationship with you. + + Conveying under any other circumstances is permitted solely under +the conditions stated below. Sublicensing is not allowed; section 10 +makes it unnecessary. + + 3. Protecting Users' Legal Rights From Anti-Circumvention Law. + + No covered work shall be deemed part of an effective technological +measure under any applicable law fulfilling obligations under article +11 of the WIPO copyright treaty adopted on 20 December 1996, or +similar laws prohibiting or restricting circumvention of such +measures. + + When you convey a covered work, you waive any legal power to forbid +circumvention of technological measures to the extent such circumvention +is effected by exercising rights under this License with respect to +the covered work, and you disclaim any intention to limit operation or +modification of the work as a means of enforcing, against the work's +users, your or third parties' legal rights to forbid circumvention of +technological measures. + + 4. Conveying Verbatim Copies. + + You may convey verbatim copies of the Program's source code as you +receive it, in any medium, provided that you conspicuously and +appropriately publish on each copy an appropriate copyright notice; +keep intact all notices stating that this License and any +non-permissive terms added in accord with section 7 apply to the code; +keep intact all notices of the absence of any warranty; and give all +recipients a copy of this License along with the Program. + + You may charge any price or no price for each copy that you convey, +and you may offer support or warranty protection for a fee. + + 5. Conveying Modified Source Versions. + + You may convey a work based on the Program, or the modifications to +produce it from the Program, in the form of source code under the +terms of section 4, provided that you also meet all of these conditions: + + a) The work must carry prominent notices stating that you modified + it, and giving a relevant date. + + b) The work must carry prominent notices stating that it is + released under this License and any conditions added under section + 7. This requirement modifies the requirement in section 4 to + "keep intact all notices". + + c) You must license the entire work, as a whole, under this + License to anyone who comes into possession of a copy. This + License will therefore apply, along with any applicable section 7 + additional terms, to the whole of the work, and all its parts, + regardless of how they are packaged. This License gives no + permission to license the work in any other way, but it does not + invalidate such permission if you have separately received it. + + d) If the work has interactive user interfaces, each must display + Appropriate Legal Notices; however, if the Program has interactive + interfaces that do not display Appropriate Legal Notices, your + work need not make them do so. + + A compilation of a covered work with other separate and independent +works, which are not by their nature extensions of the covered work, +and which are not combined with it such as to form a larger program, +in or on a volume of a storage or distribution medium, is called an +"aggregate" if the compilation and its resulting copyright are not +used to limit the access or legal rights of the compilation's users +beyond what the individual works permit. Inclusion of a covered work +in an aggregate does not cause this License to apply to the other +parts of the aggregate. + + 6. Conveying Non-Source Forms. + + You may convey a covered work in object code form under the terms +of sections 4 and 5, provided that you also convey the +machine-readable Corresponding Source under the terms of this License, +in one of these ways: + + a) Convey the object code in, or embodied in, a physical product + (including a physical distribution medium), accompanied by the + Corresponding Source fixed on a durable physical medium + customarily used for software interchange. + + b) Convey the object code in, or embodied in, a physical product + (including a physical distribution medium), accompanied by a + written offer, valid for at least three years and valid for as + long as you offer spare parts or customer support for that product + model, to give anyone who possesses the object code either (1) a + copy of the Corresponding Source for all the software in the + product that is covered by this License, on a durable physical + medium customarily used for software interchange, for a price no + more than your reasonable cost of physically performing this + conveying of source, or (2) access to copy the + Corresponding Source from a network server at no charge. + + c) Convey individual copies of the object code with a copy of the + written offer to provide the Corresponding Source. This + alternative is allowed only occasionally and noncommercially, and + only if you received the object code with such an offer, in accord + with subsection 6b. + + d) Convey the object code by offering access from a designated + place (gratis or for a charge), and offer equivalent access to the + Corresponding Source in the same way through the same place at no + further charge. You need not require recipients to copy the + Corresponding Source along with the object code. If the place to + copy the object code is a network server, the Corresponding Source + may be on a different server (operated by you or a third party) + that supports equivalent copying facilities, provided you maintain + clear directions next to the object code saying where to find the + Corresponding Source. Regardless of what server hosts the + Corresponding Source, you remain obligated to ensure that it is + available for as long as needed to satisfy these requirements. + + e) Convey the object code using peer-to-peer transmission, provided + you inform other peers where the object code and Corresponding + Source of the work are being offered to the general public at no + charge under subsection 6d. + + A separable portion of the object code, whose source code is excluded +from the Corresponding Source as a System Library, need not be +included in conveying the object code work. + + A "User Product" is either (1) a "consumer product", which means any +tangible personal property which is normally used for personal, family, +or household purposes, or (2) anything designed or sold for incorporation +into a dwelling. In determining whether a product is a consumer product, +doubtful cases shall be resolved in favor of coverage. For a particular +product received by a particular user, "normally used" refers to a +typical or common use of that class of product, regardless of the status +of the particular user or of the way in which the particular user +actually uses, or expects or is expected to use, the product. A product +is a consumer product regardless of whether the product has substantial +commercial, industrial or non-consumer uses, unless such uses represent +the only significant mode of use of the product. + + "Installation Information" for a User Product means any methods, +procedures, authorization keys, or other information required to install +and execute modified versions of a covered work in that User Product from +a modified version of its Corresponding Source. The information must +suffice to ensure that the continued functioning of the modified object +code is in no case prevented or interfered with solely because +modification has been made. + + If you convey an object code work under this section in, or with, or +specifically for use in, a User Product, and the conveying occurs as +part of a transaction in which the right of possession and use of the +User Product is transferred to the recipient in perpetuity or for a +fixed term (regardless of how the transaction is characterized), the +Corresponding Source conveyed under this section must be accompanied +by the Installation Information. But this requirement does not apply +if neither you nor any third party retains the ability to install +modified object code on the User Product (for example, the work has +been installed in ROM). + + The requirement to provide Installation Information does not include a +requirement to continue to provide support service, warranty, or updates +for a work that has been modified or installed by the recipient, or for +the User Product in which it has been modified or installed. Access to a +network may be denied when the modification itself materially and +adversely affects the operation of the network or violates the rules and +protocols for communication across the network. + + Corresponding Source conveyed, and Installation Information provided, +in accord with this section must be in a format that is publicly +documented (and with an implementation available to the public in +source code form), and must require no special password or key for +unpacking, reading or copying. + + 7. Additional Terms. + + "Additional permissions" are terms that supplement the terms of this +License by making exceptions from one or more of its conditions. +Additional permissions that are applicable to the entire Program shall +be treated as though they were included in this License, to the extent +that they are valid under applicable law. If additional permissions +apply only to part of the Program, that part may be used separately +under those permissions, but the entire Program remains governed by +this License without regard to the additional permissions. + + When you convey a copy of a covered work, you may at your option +remove any additional permissions from that copy, or from any part of +it. (Additional permissions may be written to require their own +removal in certain cases when you modify the work.) You may place +additional permissions on material, added by you to a covered work, +for which you have or can give appropriate copyright permission. + + Notwithstanding any other provision of this License, for material you +add to a covered work, you may (if authorized by the copyright holders of +that material) supplement the terms of this License with terms: + + a) Disclaiming warranty or limiting liability differently from the + terms of sections 15 and 16 of this License; or + + b) Requiring preservation of specified reasonable legal notices or + author attributions in that material or in the Appropriate Legal + Notices displayed by works containing it; or + + c) Prohibiting misrepresentation of the origin of that material, or + requiring that modified versions of such material be marked in + reasonable ways as different from the original version; or + + d) Limiting the use for publicity purposes of names of licensors or + authors of the material; or + + e) Declining to grant rights under trademark law for use of some + trade names, trademarks, or service marks; or + + f) Requiring indemnification of licensors and authors of that + material by anyone who conveys the material (or modified versions of + it) with contractual assumptions of liability to the recipient, for + any liability that these contractual assumptions directly impose on + those licensors and authors. + + All other non-permissive additional terms are considered "further +restrictions" within the meaning of section 10. If the Program as you +received it, or any part of it, contains a notice stating that it is +governed by this License along with a term that is a further +restriction, you may remove that term. If a license document contains +a further restriction but permits relicensing or conveying under this +License, you may add to a covered work material governed by the terms +of that license document, provided that the further restriction does +not survive such relicensing or conveying. + + If you add terms to a covered work in accord with this section, you +must place, in the relevant source files, a statement of the +additional terms that apply to those files, or a notice indicating +where to find the applicable terms. + + Additional terms, permissive or non-permissive, may be stated in the +form of a separately written license, or stated as exceptions; +the above requirements apply either way. + + 8. Termination. + + You may not propagate or modify a covered work except as expressly +provided under this License. Any attempt otherwise to propagate or +modify it is void, and will automatically terminate your rights under +this License (including any patent licenses granted under the third +paragraph of section 11). + + However, if you cease all violation of this License, then your +license from a particular copyright holder is reinstated (a) +provisionally, unless and until the copyright holder explicitly and +finally terminates your license, and (b) permanently, if the copyright +holder fails to notify you of the violation by some reasonable means +prior to 60 days after the cessation. + + Moreover, your license from a particular copyright holder is +reinstated permanently if the copyright holder notifies you of the +violation by some reasonable means, this is the first time you have +received notice of violation of this License (for any work) from that +copyright holder, and you cure the violation prior to 30 days after +your receipt of the notice. + + Termination of your rights under this section does not terminate the +licenses of parties who have received copies or rights from you under +this License. If your rights have been terminated and not permanently +reinstated, you do not qualify to receive new licenses for the same +material under section 10. + + 9. Acceptance Not Required for Having Copies. + + You are not required to accept this License in order to receive or +run a copy of the Program. Ancillary propagation of a covered work +occurring solely as a consequence of using peer-to-peer transmission +to receive a copy likewise does not require acceptance. However, +nothing other than this License grants you permission to propagate or +modify any covered work. These actions infringe copyright if you do +not accept this License. Therefore, by modifying or propagating a +covered work, you indicate your acceptance of this License to do so. + + 10. Automatic Licensing of Downstream Recipients. + + Each time you convey a covered work, the recipient automatically +receives a license from the original licensors, to run, modify and +propagate that work, subject to this License. You are not responsible +for enforcing compliance by third parties with this License. + + An "entity transaction" is a transaction transferring control of an +organization, or substantially all assets of one, or subdividing an +organization, or merging organizations. If propagation of a covered +work results from an entity transaction, each party to that +transaction who receives a copy of the work also receives whatever +licenses to the work the party's predecessor in interest had or could +give under the previous paragraph, plus a right to possession of the +Corresponding Source of the work from the predecessor in interest, if +the predecessor has it or can get it with reasonable efforts. + + You may not impose any further restrictions on the exercise of the +rights granted or affirmed under this License. For example, you may +not impose a license fee, royalty, or other charge for exercise of +rights granted under this License, and you may not initiate litigation +(including a cross-claim or counterclaim in a lawsuit) alleging that +any patent claim is infringed by making, using, selling, offering for +sale, or importing the Program or any portion of it. + + 11. Patents. + + A "contributor" is a copyright holder who authorizes use under this +License of the Program or a work on which the Program is based. The +work thus licensed is called the contributor's "contributor version". + + A contributor's "essential patent claims" are all patent claims +owned or controlled by the contributor, whether already acquired or +hereafter acquired, that would be infringed by some manner, permitted +by this License, of making, using, or selling its contributor version, +but do not include claims that would be infringed only as a +consequence of further modification of the contributor version. For +purposes of this definition, "control" includes the right to grant +patent sublicenses in a manner consistent with the requirements of +this License. + + Each contributor grants you a non-exclusive, worldwide, royalty-free +patent license under the contributor's essential patent claims, to +make, use, sell, offer for sale, import and otherwise run, modify and +propagate the contents of its contributor version. + + In the following three paragraphs, a "patent license" is any express +agreement or commitment, however denominated, not to enforce a patent +(such as an express permission to practice a patent or covenant not to +sue for patent infringement). To "grant" such a patent license to a +party means to make such an agreement or commitment not to enforce a +patent against the party. + + If you convey a covered work, knowingly relying on a patent license, +and the Corresponding Source of the work is not available for anyone +to copy, free of charge and under the terms of this License, through a +publicly available network server or other readily accessible means, +then you must either (1) cause the Corresponding Source to be so +available, or (2) arrange to deprive yourself of the benefit of the +patent license for this particular work, or (3) arrange, in a manner +consistent with the requirements of this License, to extend the patent +license to downstream recipients. "Knowingly relying" means you have +actual knowledge that, but for the patent license, your conveying the +covered work in a country, or your recipient's use of the covered work +in a country, would infringe one or more identifiable patents in that +country that you have reason to believe are valid. + + If, pursuant to or in connection with a single transaction or +arrangement, you convey, or propagate by procuring conveyance of, a +covered work, and grant a patent license to some of the parties +receiving the covered work authorizing them to use, propagate, modify +or convey a specific copy of the covered work, then the patent license +you grant is automatically extended to all recipients of the covered +work and works based on it. + + A patent license is "discriminatory" if it does not include within +the scope of its coverage, prohibits the exercise of, or is +conditioned on the non-exercise of one or more of the rights that are +specifically granted under this License. You may not convey a covered +work if you are a party to an arrangement with a third party that is +in the business of distributing software, under which you make payment +to the third party based on the extent of your activity of conveying +the work, and under which the third party grants, to any of the +parties who would receive the covered work from you, a discriminatory +patent license (a) in connection with copies of the covered work +conveyed by you (or copies made from those copies), or (b) primarily +for and in connection with specific products or compilations that +contain the covered work, unless you entered into that arrangement, +or that patent license was granted, prior to 28 March 2007. + + Nothing in this License shall be construed as excluding or limiting +any implied license or other defenses to infringement that may +otherwise be available to you under applicable patent law. + + 12. No Surrender of Others' Freedom. + + If conditions are imposed on you (whether by court order, agreement or +otherwise) that contradict the conditions of this License, they do not +excuse you from the conditions of this License. If you cannot convey a +covered work so as to satisfy simultaneously your obligations under this +License and any other pertinent obligations, then as a consequence you may +not convey it at all. For example, if you agree to terms that obligate you +to collect a royalty for further conveying from those to whom you convey +the Program, the only way you could satisfy both those terms and this +License would be to refrain entirely from conveying the Program. + + 13. Remote Network Interaction; Use with the GNU General Public License. + + Notwithstanding any other provision of this License, if you modify the +Program, your modified version must prominently offer all users +interacting with it remotely through a computer network (if your version +supports such interaction) an opportunity to receive the Corresponding +Source of your version by providing access to the Corresponding Source +from a network server at no charge, through some standard or customary +means of facilitating copying of software. This Corresponding Source +shall include the Corresponding Source for any work covered by version 3 +of the GNU General Public License that is incorporated pursuant to the +following paragraph. + + Notwithstanding any other provision of this License, you have +permission to link or combine any covered work with a work licensed +under version 3 of the GNU General Public License into a single +combined work, and to convey the resulting work. The terms of this +License will continue to apply to the part which is the covered work, +but the work with which it is combined will remain governed by version +3 of the GNU General Public License. + + 14. Revised Versions of this License. + + The Free Software Foundation may publish revised and/or new versions of +the GNU Affero General Public License from time to time. Such new versions +will be similar in spirit to the present version, but may differ in detail to +address new problems or concerns. + + Each version is given a distinguishing version number. If the +Program specifies that a certain numbered version of the GNU Affero General +Public License "or any later version" applies to it, you have the +option of following the terms and conditions either of that numbered +version or of any later version published by the Free Software +Foundation. If the Program does not specify a version number of the +GNU Affero General Public License, you may choose any version ever published +by the Free Software Foundation. + + If the Program specifies that a proxy can decide which future +versions of the GNU Affero General Public License can be used, that proxy's +public statement of acceptance of a version permanently authorizes you +to choose that version for the Program. + + Later license versions may give you additional or different +permissions. However, no additional obligations are imposed on any +author or copyright holder as a result of your choosing to follow a +later version. + + 15. Disclaimer of Warranty. + + THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY +APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT +HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY +OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, +THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM +IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF +ALL NECESSARY SERVICING, REPAIR OR CORRECTION. + + 16. Limitation of Liability. + + IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING +WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS +THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY +GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE +USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF +DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD +PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), +EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF +SUCH DAMAGES. + + 17. Interpretation of Sections 15 and 16. + + If the disclaimer of warranty and limitation of liability provided +above cannot be given local legal effect according to their terms, +reviewing courts shall apply local law that most closely approximates +an absolute waiver of all civil liability in connection with the +Program, unless a warranty or assumption of liability accompanies a +copy of the Program in return for a fee. + + END OF TERMS AND CONDITIONS + + How to Apply These Terms to Your New Programs + + If you develop a new program, and you want it to be of the greatest +possible use to the public, the best way to achieve this is to make it +free software which everyone can redistribute and change under these terms. + + To do so, attach the following notices to the program. It is safest +to attach them to the start of each source file to most effectively +state the exclusion of warranty; and each file should have at least +the "copyright" line and a pointer to where the full notice is found. + + <one line to give the program's name and a brief idea of what it does.> + Copyright (C) <year> <name of author> + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <http://www.gnu.org/licenses/>. + +Also add information on how to contact you by electronic and paper mail. + + If your software can interact with users remotely through a computer +network, you should also make sure that it provides a way for users to +get its source. For example, if your program is a web application, its +interface could display a "Source" link that leads users to an archive +of the code. There are many ways you could offer source, and different +solutions will be better for different programs; see section 13 for the +specific requirements. + + You should also get your employer (if you work as a programmer) or school, +if any, to sign a "copyright disclaimer" for the program, if necessary. +For more information on this, and how to apply and follow the GNU AGPL, see +<http://www.gnu.org/licenses/>. diff --git a/debian/README.Debian b/debian/README.Debian @@ -0,0 +1,78 @@ +kych for Debian +=============== + +The service is installed disabled and will not start until you have done the +three steps below: it has no usable defaults for the database or for the OAuth +2.0 clients it serves. + +1. Create the database +---------------------- + +The daemon runs as the system user "kych" and the shipped configuration +connects over the local PostgreSQL socket using peer authentication, so no +password is stored anywhere. Create a matching role and database: + + sudo -u postgres createuser kych + sudo -u postgres createdb -O kych kych + +Then load the schema. The SQL is installed under /usr/share/kych/sql; the +first file sets up the "Versioning" patch-level bookkeeping that upstream uses +for migrations, the second creates the oauth2gw schema itself: + + sudo -u kych psql kych -f /usr/share/kych/sql/versioning.sql + sudo -u kych psql kych -f /usr/share/kych/sql/oauth2gw-0001.sql + +Later upstream releases add further oauth2gw-000N.sql patches, which are +applied the same way, in order. /usr/share/kych/sql/drop.sql removes +everything again. + +To use a remote database or password authentication instead, set DATABASE in +/etc/kych/kych.conf to a full connection URI. + +2. Configure +------------ + +Edit /etc/kych/kych.conf. It is commented throughout; the parts you have to +touch are the credential settings (VC_*), the recommended ALLOWED_SCOPES +ceiling, and at least one [client_*] section. + +Then register the clients in the database -- the running gateway reads clients +from there, not from the configuration file: + + kych-client-management -c /etc/kych/kych.conf sync + kych-client-management -c /etc/kych/kych.conf list + +Re-run "sync" after every change to a [client_*] section. Note that it does +not rotate an existing client's secret; delete and re-create the client for +that. + +3. Start it +----------- + + systemctl enable --now kych + systemctl status kych + +Reverse proxy +------------- + +The gateway speaks plain HTTP on the Unix socket /run/kych/kych.sock and does +not terminate TLS. It is not socket-activated -- it creates the socket itself, +which is why the package ships no .socket unit. The socket is created with +group www-data and mode 0660, so a proxy running as www-data can reach it. No +web-server snippets are shipped; for nginx the essential part is + + location / { + proxy_pass http://unix:/run/kych/kych.sock; + proxy_set_header Host $host; + proxy_set_header X-Forwarded-Proto $scheme; + } + +Do not expose the gateway directly: /notification accepts unauthenticated +webhooks from the SWIYU verifier and should additionally be restricted to the +verifier's address at the proxy. + +Logs go to the journal: + + journalctl -u kych -f + + -- Taler Systems SA <deb@taler.net> diff --git a/debian/README.source b/debian/README.source @@ -0,0 +1,83 @@ +Building the kych package +========================= + +Binary-only builds from a git checkout, which is how this package is produced: + + ./debian/stamp-version.sh + dpkg-buildpackage -b -uc -us + +The first step rewrites debian/changelog with the version reported by +scripts/get_version.sh -- the same "git describe --tags" logic the other GNU +Taler repositories use -- because dpkg takes the package version from the +changelog and from nowhere else. It is idempotent, and it falls back to +0.0.0-<commits>-g<hash> while this repository still has no release tag. + +Notes for whoever touches this next +----------------------------------- + +* No debian/source/format is present, so the source format is the default 1.0. + This matches the other Rust packages in the GNU Taler tree (robocop, + taler-rust) and is fine for the "-b" builds above; producing a source package + would need a format decision and an orig tarball first. + +* The build is not offline: cargo fetches crates from crates.io, into + debian/cargo (CARGO_HOME) so that nothing outside the build tree is written. + There is no Cargo.lock in the repository, so builds are not reproducible + across dependency releases either. Both would have to be fixed before this + could go to the Debian archive; neither matters for the .deb builds we do. + +* Man pages are generated at build time by sphinx-build from + documentation/taler-docs/manpages/, the same reStructuredText that the + taler-docs repository renders for the website, so there is one source for + both. The configuration used here is documentation/sphinx-man/conf.py, a + minimal file holding little more than the man_pages entries; taler-docs has + its own conf.py with a long list of extensions, which is why we do not reuse + it. The NAME line of each page comes from the man_pages entry, not from the + document, which is why each source wraps its own "Name" section in + ".. only:: html". + + Consequences worth knowing: the man page sources may only use directives that + plain Sphinx understands (they currently use "only", "code-block", "note" and + "warning"), and the build prints "document isn't included in any toctree" for + two of the three pages. That warning is expected here - the toctree lives in + taler-docs - and cannot be suppressed, as it carries no warning type. + +* The daemon serves its QR-code JavaScript from a path relative to the process + working directory, so debian/kych.service sets WorkingDirectory to + /usr/share/kych, where debian/kych.install puts js/. Changing either without + the other breaks the /authorize page. + +Upstreaming the man pages +------------------------- + +documentation/taler-docs/manpages/ is copied into the taler-docs checkout as +described in documentation/taler-docs/README. Sphinx there will not build a +man page unless it is also listed in taler-docs/conf.py, so the three entries +from documentation/sphinx-man/conf.py have to be added to the man_pages list +there as well, with a "manpages/" prefix on the first field: + + ("manpages/kych-oauth2-gateway.1", "kych-oauth2-gateway", + "OAuth 2.0 gateway for SWIYU credential verification", + ["GNU Taler contributors"], 1), + ("manpages/kych-client-management.1", "kych-client-management", + "manage OAuth 2.0 clients of the KyCH gateway", + ["GNU Taler contributors"], 1), + ("manpages/kych.conf.5", "kych.conf", + "configuration file of the KyCH OAuth 2.0 gateway", + ["GNU Taler contributors"], 5), + +Keep the two lists identical, or the same source will produce a different NAME +line depending on who builds it. + +Known documentation bug +----------------------- + +kych.conf(5) documents the "@INLINE@" include directive, which the parser does +not implement -- and does not reject either: the directive line is read as the +start of a key and swallows the line after it, so that setting disappears +silently. The directive is documented with a note saying so, because it is the +behaviour KyCH ought to have (every other GNU Taler component supports it, and +without it there is no way to keep database credentials out of the main +configuration file). Remove the note, not the documentation, once it works. + + -- Taler Systems SA <deb@taler.net> diff --git a/debian/changelog b/debian/changelog @@ -0,0 +1,6 @@ +kych (0.0.0) UNRELEASED; urgency=medium + + * Initial Debian packaging of the KyCH OAuth2 gateway. + The version is stamped from git at build time; see debian/README.source. + + -- Christian Grothoff <grothoff@gnu.org> Sun, 09 Aug 2026 14:30:05 +0200 diff --git a/debian/control b/debian/control @@ -0,0 +1,39 @@ +Source: kych +Section: net +Priority: optional +Maintainer: Taler Systems SA <deb@taler.net> +Uploaders: Christian Grothoff <grothoff@gnu.org> +Rules-Requires-Root: no +Build-Depends: + debhelper-compat (= 13), + cargo, +# The crate is edition 2024, which needs rustc 1.85 or newer. Trixie ships +# 1.85, so no backport is required. + rustc (>= 1.85), +# reqwest is built with its default TLS backend (native-tls -> openssl-sys). + pkg-config, + libssl-dev, +# Builds the man pages from documentation/taler-docs/manpages/ using the +# minimal configuration in documentation/sphinx-man/. No Sphinx extensions +# are needed; keep it that way. + python3-sphinx +Standards-Version: 4.7.2 +Vcs-Git: https://git.taler.net/kych.git +Homepage: https://taler.net/ + +Package: kych +Architecture: any +Depends: ${misc:Depends}, ${shlibs:Depends} +Recommends: + nginx | apache2 | httpd, + postgresql (>= 14.0) +Description: OAuth 2.0 gateway for SWIYU identity verification + KyCH bridges OAuth 2.0 clients -- primarily a GNU Taler exchange performing + KYC -- to the Swiss SWIYU e-ID trust infrastructure. The client speaks a + plain OAuth 2.0 authorization code flow, while KyCH speaks OpenID4VP to a + SWIYU verifier, so that the user's SWIYU wallet presents an SD-JWT verifiable + credential with selective disclosure. The OAuth 2.0 scope names the + credential claims to be disclosed. + . + This package provides the gateway daemon, its systemd unit, the database + schema and the kych-client-management tool for registering OAuth 2.0 clients. diff --git a/debian/copyright b/debian/copyright @@ -0,0 +1,109 @@ +Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/ +Upstream-Name: KyCH +Upstream-Contact: Christian Grothoff <grothoff@gnu.org> +Source: https://git.taler.net/kych.git + +Files: * +Copyright: + (C) 2024-2026 Taler Systems SA +License: AGPL-3+ +Comment: + Stated by the COPYING file at the root of the source tree. Note that the + individual source files still carry no license headers of their own. + +Files: kych_oauth2_gateway/oauth2_gatewaydb/versioning.sql +Copyright: + (C) 2010 Hubert depesz Lubaczewski +License: BSD-3-clause + +Files: kych_oauth2_gateway/js/qrcode.min.js +Copyright: + (C) 2012 Sangmin Shim +License: MIT +Comment: + UNVERIFIED -- needs confirmation before this package is uploaded anywhere. + Upstream ships this file minified and with no copyright or license header of + its own; the attribution above is inferred from the code shape, which matches + davidshimjs/qrcodejs (MIT). Either confirm it and ask upstream to restore the + header, or replace the file with a packaged QR-code library. + +Files: debian/* +Copyright: + (C) 2026 Taler Systems SA +License: GPL-3+ + +License: AGPL-3+ + This program is free software: you can redistribute it and/or modify it + under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or (at your + option) any later version. + . + This program is distributed in the hope that it will be useful, but WITHOUT + ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or + FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public + License for more details. + . + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <http://www.gnu.org/licenses/>. + . + The complete text of the GNU Affero General Public License version 3 + can be found in the /usr/share/common-licenses/AGPL-3 file. + +License: GPL-3+ + This program is free software: you can redistribute it and/or modify it + under the terms of the GNU General Public License as published by the Free + Software Foundation, either version 3 of the License, or (at your option) + any later version. + . + This program is distributed in the hope that it will be useful, but WITHOUT + ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or + FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for + more details. + . + The complete text of the GNU General Public License version 3 + can be found in the /usr/share/common-licenses/GPL-3 file. + +License: BSD-3-clause + Redistribution and use in source and binary forms, with or without + modification, are permitted provided that the following conditions + are met: + . + * Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer. + * Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + * Neither the name of Hubert depesz Lubaczewski's Organization nor the + names of its contributors may be used to endorse or promote products + derived from this software without specific prior written permission. + . + THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" + AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE + LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + POSSIBILITY OF SUCH DAMAGE. + +License: MIT + Permission is hereby granted, free of charge, to any person obtaining a + copy of this software and associated documentation files (the "Software"), + to deal in the Software without restriction, including without limitation + the rights to use, copy, modify, merge, publish, distribute, sublicense, + and/or sell copies of the Software, and to permit persons to whom the + Software is furnished to do so, subject to the following conditions: + . + The above copyright notice and this permission notice shall be included in + all copies or substantial portions of the Software. + . + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE + AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING + FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER + DEALINGS IN THE SOFTWARE. diff --git a/debian/etc/kych/kych.conf b/debian/etc/kych/kych.conf @@ -0,0 +1,173 @@ +#################################################################### +# Configuration for the KyCH OAuth 2.0 gateway. +# +# See kych.conf(5) for the full reference and +# https://docs.taler.net/taler-kych-manual.html for the operator +# manual. /usr/share/doc/kych/README.Debian describes the steps +# needed to get from this file to a running service. +# +# Syntax notes, because they are easy to get wrong: +# +# * This is a plain INI file. Comments must stand on a line of +# their own, so write +# PORT = 8080 +# and never +# PORT = 8080 # the port +# which configures a port of "8080 # the port". The same mistake +# after a section header, "[client_x] # ...", is worse: it makes +# the whole file fail to load. +# +# * Lists are written in braces, comma-separated: {a, b, c}. +# +# * Unlike other GNU Taler components, this file is *not* parsed by +# GNUnet's configuration library. kych.conf(5) documents an +# @INLINE@ include directive, but it is not implemented -- and not +# rejected either: such a line silently swallows the setting on the +# line after it. There is likewise no @inline-secret@ and no +# conf.d/ directory. Everything lives here, including the database +# credentials and the OAuth 2.0 client secrets, which is why the +# package keeps this file at mode 0640, owned root:kych. +# +# * The gateway re-reads nothing at runtime: restart the service +# after editing ("systemctl restart kych"). +#################################################################### + +[kych-oauth2-gateway] + +# --- How the gateway listens ------------------------------------- +# +# Either a Unix domain socket (UNIXPATH) or a TCP socket (HOST and +# PORT together), never both -- the gateway refuses to start if both +# or neither are configured. +# +# The shipped systemd unit creates /run/kych for this, and runs the +# daemon as user kych with group www-data, so a reverse proxy running +# as www-data can reach the socket at mode 0660. The gateway speaks +# plain HTTP and does not terminate TLS; put nginx or Apache in front +# of it. +UNIXPATH = /run/kych/kych.sock + +# Permissions for the socket file, in octal. Upstream's default is +# 666; 660 is enough here because the socket is group www-data. +UNIXPATH_MODE = 660 + +# TCP alternative. If you enable these, comment out UNIXPATH above, +# and bind to the loopback interface only unless the gateway sits +# behind a firewall -- none of its endpoints are safe to expose +# directly to the internet. +#HOST = 127.0.0.1 +#PORT = 8080 + +# --- Database ---------------------------------------------------- +# +# PostgreSQL connection string. The default below connects over the +# local Unix socket and authenticates as the operating-system user the +# daemon runs as (kych), which is what "peer" authentication in a +# stock Debian PostgreSQL expects -- no password ends up in this file. +# +# For a remote database use the URI form instead, e.g. +# DATABASE = postgres://kych:SECRET@db.example.com/kych +# +# The schema must be loaded before first start; see README.Debian. +DATABASE = postgres:///kych?host=/var/run/postgresql + +# --- Cryptographic parameters ------------------------------------ +# +# Sizes are in bytes of raw randomness; the values are then base64url +# encoded, so 32 bytes yields a 43-character string. 32 bytes (256 +# bits) is the recommended value for all three -- lowering it weakens +# the unguessability that the /authorize nonce and the bearer tokens +# rely on for their security. + +# Nonce handed to the client by /setup and used as the secret part of +# the /authorize/{nonce} URL. +NONCE_BYTES = 32 + +# OAuth 2.0 access token returned by /token. +TOKEN_BYTES = 32 + +# OAuth 2.0 authorization code minted once verification succeeds. +AUTH_CODE_BYTES = 32 + +# How long an authorization code stays redeemable at /token, in +# minutes. RFC 6749 recommends a short lifetime; the code is consumed +# on first use in any case. +AUTH_CODE_TTL_MINUTES = 10 + +# --- Verifiable credential -------------------------------------- +# +# Describes the credential the gateway asks the SWIYU verifier for. +# These values must match the credential the issuer actually issues; +# they are also published to clients on the /config endpoint. + +# Credential type; matched against the "vct" claim of the presented +# SD-JWT. "betaid-sdjwt" is the Swiss e-ID beta credential. +VC_TYPE = betaid-sdjwt + +# Credential format. +VC_FORMAT = vc+sd-jwt + +# Signature algorithms accepted for the credential and for the key +# binding JWT. At least one must be listed. +VC_ALGORITHMS = {ES256} + +# Every claim that exists in the credential type above. A client may +# only request claims from this set: the claims it wants are passed as +# the OAuth 2.0 "scope" (space-separated) on /authorize, and anything +# not listed here is rejected with invalid_request. Requesting fewer +# claims is what makes the disclosure selective, so clients should ask +# for the minimum they need -- often just age_over_18. +VC_CLAIMS = {family_name, given_name, birth_date, sex, place_of_origin, birth_place, nationality, portrait, personal_administrative_number, age_over_16, age_over_18, age_over_65, age_birth_year, document_number, issuance_date, expiry_date, additional_person_info, reference_id_type, reference_id_expiry_date, verification_type, verification_organization, issuing_authority, issuing_country} + +# Optional, and strongly recommended: an operator-side ceiling on what +# clients may ask for, independent of what the credential contains. +# When set, a scope containing any claim outside this list is refused, +# even though the claim appears in VC_CLAIMS above. Leave it +# commented out to allow any claim of the credential to be requested. +#ALLOWED_SCOPES = {age_over_18} + +#################################################################### +# OAuth 2.0 clients +# +# One [client_*] section per client (the section name only has to +# start with "client_"; it is not otherwise significant). +# +# IMPORTANT: the running gateway does not read these sections. It +# resolves clients from the database, and these sections are merely +# the input to +# +# kych-client-management -c /etc/kych/kych.conf sync +# +# which creates or updates the corresponding database rows (add +# --prune to also delete clients that are no longer listed here). +# Adding a client and restarting the service does nothing; you must +# run sync. CLIENT_SECRET is only read when the client is first +# created -- changing it here and re-running sync will not rotate the +# stored secret, use "kych-client-management ... delete" and re-sync +# for that. +#################################################################### + +#[client_exchange] + +# Identifier the client authenticates with, at POST /setup/{CLIENT_ID} +# (as a bearer token holding CLIENT_SECRET) and at POST /token. +#CLIENT_ID = exchange-prod-01 + +# Shared secret. Stored bcrypt-hashed in the database; keep this file +# readable only by root and the kych user. +#CLIENT_SECRET = SECRET + +# Base URL of the SWIYU verifier this client's verifications go +# through, and the path of its management API on that host. +#VERIFIER_URL = https://verifier.example.com +#VERIFIER_MANAGEMENT_API_PATH = /management/api/verifications + +# Allowlist of OAuth 2.0 redirect URIs, comma-separated. The +# redirect_uri passed to /authorize must match one of them exactly, +# and the same value must be repeated on the /token request. +#REDIRECT_URI = https://exchange.example.com/kyc-proof/kych + +# Issuers whose credentials this client accepts. Despite what +# kych.conf(5) says, this is not optional in practice: /authorize +# fails with accepted_issuer_dids_not_configured when it is unset. +#ACCEPTED_ISSUER_DIDS = {did:tdw:example:issuer} diff --git a/debian/kych.install b/debian/kych.install @@ -0,0 +1,18 @@ +kych_oauth2_gateway/target/release/kych-oauth2-gateway usr/bin/ +kych_oauth2_gateway/target/release/kych-client-management usr/bin/ + +# The daemon serves /js from a path relative to its *working directory* +# (ServeDir::new("js") in main.rs), which is why the systemd unit sets +# WorkingDirectory=/usr/share/kych. Keep the two in sync. +kych_oauth2_gateway/js/qrcode.min.js usr/share/kych/js/ + +# Database schema; loaded by the administrator, see README.Debian. +kych_oauth2_gateway/oauth2_gatewaydb/versioning.sql usr/share/kych/sql/ +kych_oauth2_gateway/oauth2_gatewaydb/oauth2gw-0001.sql usr/share/kych/sql/ +kych_oauth2_gateway/oauth2_gatewaydb/drop.sql usr/share/kych/sql/ + +# Man pages are generated into debian/man by debian/rules and installed from +# there by dh_installman; see debian/kych.manpages. + +# Installed to /etc, hence registered as a conffile automatically. +debian/etc/kych/kych.conf etc/kych/ diff --git a/debian/kych.manpages b/debian/kych.manpages @@ -0,0 +1,2 @@ +debian/man/*.1 +debian/man/*.5 diff --git a/debian/kych.service b/debian/kych.service @@ -0,0 +1,49 @@ +[Unit] +Description=KyCH OAuth 2.0 gateway for SWIYU identity verification +Documentation=https://docs.taler.net/taler-kych-manual.html +After=network.target postgresql.service +Wants=postgresql.service + +[Service] +Type=exec +User=kych +# The socket file inherits the primary group of the process, so running with +# Group=www-data is what lets the reverse proxy connect to it (together with +# UNIXPATH_MODE = 660 in kych.conf). +Group=www-data + +# kych-oauth2-gateway serves the QR-code helper from "js/" relative to its +# working directory (ServeDir::new("js")); without this the /authorize page +# loads but the QR code silently fails. +WorkingDirectory=/usr/share/kych + +# Creates /run/kych (0755, kych:www-data) before start and removes it on stop. +# This is where UNIXPATH in the shipped kych.conf puts the listening socket. +RuntimeDirectory=kych +RuntimeDirectoryMode=0755 + +ExecStart=/usr/bin/kych-oauth2-gateway -c /etc/kych/kych.conf + +Restart=always +RestartSec=1s +StartLimitBurst=5 +StartLimitInterval=5s + +StandardOutput=journal +StandardError=journal + +PrivateTmp=yes +ProtectSystem=full +ProtectHome=yes +ProtectClock=yes +ProtectHostname=yes +ProtectControlGroups=yes +ProtectKernelLogs=yes +ProtectKernelModules=yes +ProtectKernelTunables=yes +ProtectProc=invisible +PrivateDevices=yes +NoNewPrivileges=yes + +[Install] +WantedBy=multi-user.target diff --git a/debian/kych.sysusers b/debian/kych.sysusers @@ -0,0 +1,7 @@ +#Type Name Gecos Home directory Shell +u kych "KyCH OAuth 2.0 gateway" - - +# Supplementary membership in www-data, so that the reverse proxy's group can +# be used for the Unix socket. debian/kych.service additionally runs the +# daemon with www-data as its primary group, which is what actually determines +# the group of the socket file it creates. +m kych www-data diff --git a/debian/kych.tmpfiles b/debian/kych.tmpfiles @@ -0,0 +1,5 @@ +# kych.conf holds the database connection string and the OAuth 2.0 client +# secrets, so it must not be world-readable. It is a conffile owned by the +# package (hence root:root 0644 on unpack); "z" re-applies ownership and mode +# on every install and upgrade without touching the contents. +z /etc/kych/kych.conf 0640 root kych - - diff --git a/debian/rules b/debian/rules @@ -0,0 +1,56 @@ +#!/usr/bin/make -f + +# The Cargo crate lives in a subdirectory, not at the top of the source tree. +CRATE = kych_oauth2_gateway + +# Man pages are generated from the reStructuredText that also feeds the website +# build in the taler-docs repository, so that there is a single source for +# them. documentation/sphinx-man/conf.py is a minimal Sphinx configuration +# holding just the man_pages entries; the sources themselves use only core +# directives, so python3-sphinx alone is enough. +MANSRC = documentation/taler-docs/manpages +MANCONF = documentation/sphinx-man +MANOUT = debian/man + +# Keep cargo's registry and cache inside the build tree. cargo fetches crates +# from the network at build time (this is not an archive-policy-clean offline +# build), and without this it would write to $HOME, which is not ours to touch +# under Rules-Requires-Root: no. +export CARGO_HOME = $(CURDIR)/debian/cargo + +# --with installsysusers: dh_installsysusers (which turns debian/kych.sysusers +# into the /usr/lib/sysusers.d entry that creates the "kych" system user) only +# joins the sequence automatically from debhelper compat 14 onwards. Without +# this the package would install but the service could not start. +%: + dh $@ --no-parallel --with installsysusers + +# Nothing to configure: debian/kych.install names explicit paths and the build +# only needs a cargo from $PATH (see Build-Depends). The step is still +# overridden so that dh does not try to auto-detect a build system in the +# top-level directory, which holds no build files of its own. +override_dh_auto_configure: + +override_dh_auto_build: + cargo build --release --manifest-path $(CRATE)/Cargo.toml + sphinx-build -b man -q -c $(MANCONF) $(MANSRC) $(MANOUT) + +# The unit tests would run without a database, but the two integration suites +# in $(CRATE)/tests/ need a live PostgreSQL reachable through $DATABASE_URL and +# silently skip themselves when it is absent -- running them here would report +# a pass without having tested anything. Test against a database instead: +# DATABASE_URL=postgres:///kych_test cargo test --manifest-path $(CRATE)/Cargo.toml +override_dh_auto_test: + +override_dh_auto_install: + +override_dh_auto_clean: + rm -rf $(CARGO_HOME) $(CRATE)/target $(MANOUT) + +# The daemon is not socket-activated: it binds UNIXPATH itself rather than +# accepting a descriptor from systemd, so there is no .socket unit to enable. +# Do not enable or start the service on install -- it cannot run before the +# administrator has created the database and edited kych.conf (see +# README.Debian). +override_dh_installsystemd: + dh_installsystemd --no-enable --no-start --no-stop-on-upgrade diff --git a/debian/stamp-version.sh b/debian/stamp-version.sh @@ -0,0 +1,71 @@ +#!/bin/sh +# Stamp debian/changelog with the version derived from the most recent git tag. +# +# Run this before dpkg-buildpackage. The Debian version has to be baked into +# debian/changelog: dpkg reads the package version from there and from nowhere +# else, so a git-derived version can only be applied by rewriting that file. +# +# ./debian/stamp-version.sh && dpkg-buildpackage -b -uc -us +# +# The version itself comes from scripts/get_version.sh, the same script the +# other GNU Taler repositories use ("git describe --tags" with the leading "v" +# stripped, cached in .version for builds from an exported tree). For a tagged +# commit that yields e.g. "0.1.0", further down the branch "0.1.0-3-gc0ffee12". +# Both are valid Debian versions -- dpkg splits on the *last* hyphen, so the +# commit hash becomes the Debian revision -- and this matches how the taler-rust +# packages are versioned. +# +# This script is idempotent: re-running it when the changelog already carries +# the current version does nothing. +set -eu + +top_dir=$(dirname "$0")/.. +cd "$top_dir" + +changelog=debian/changelog +package=$(dpkg-parsechangelog -l "$changelog" -S Source) + +version=$(./scripts/get_version.sh) + +# get_version.sh reports "unknown" when there is no tag reachable from HEAD +# (which is the case for this repository today). A Debian upstream version +# must start with a digit, so fall back to 0.0.0 plus the commit count, keeping +# the "<version>-<commits>-g<hash>" shape so the versions still sort correctly. +case "$version" in + [0-9]*) ;; + *) + if [ -e .git ]; then + version="0.0.0-$(git rev-list --count HEAD)-g$(git rev-parse --short=8 HEAD)" + else + echo "$0: no git tag and no git repository; cannot derive a version" >&2 + exit 1 + fi + # .version was written by get_version.sh with the bogus value. + rm -f .version + ;; +esac + +current=$(dpkg-parsechangelog -l "$changelog" -S Version) +if [ "$current" = "$version" ]; then + echo "debian/changelog is already at $version" + exit 0 +fi + +# Prefer the maintainer tooling when it is installed; it keeps the changelog +# formatting canonical and honours DEBEMAIL/DEBFULLNAME. +if command -v dch >/dev/null 2>&1; then + EDITOR=true dch --changelog "$changelog" --newversion "$version" \ + --distribution UNRELEASED --force-bad-version --force-distribution \ + "Build from git ($version)." +else + maintainer=$(dpkg-parsechangelog -l "$changelog" -S Maintainer) + { + printf '%s (%s) UNRELEASED; urgency=medium\n\n' "$package" "$version" + printf ' * Build from git (%s).\n\n' "$version" + printf ' -- %s %s\n\n' "$maintainer" "$(date -R)" + cat "$changelog" + } > "$changelog.new" + mv "$changelog.new" "$changelog" +fi + +echo "debian/changelog stamped with $version" diff --git a/documentation/README b/documentation/README @@ -18,6 +18,31 @@ Files kych_verifier_logo.svg KYCH verifier logo +Man Pages +--------- + +The man page sources live with the rest of the documentation destined for +docs.taler.net, in taler-docs/manpages/, and are built with Sphinx. There +is no second, hand-written copy. + + taler-docs/manpages/kych-oauth2-gateway.1.rst The gateway daemon + taler-docs/manpages/kych-client-management.1.rst The client tool + taler-docs/manpages/kych.conf.5.rst The configuration file + +The website build renders them from the taler-docs repository. To build +just the man pages from this repository, using the minimal Sphinx +configuration in sphinx-man/: + + sphinx-build -b man -c documentation/sphinx-man \ + documentation/taler-docs/manpages /tmp/kych-man + man /tmp/kych-man/kych.conf.5 + +The Debian package does exactly this at build time. Note that the NAME +line of each page comes from the man_pages entry in the Sphinx +configuration rather than from the document itself, which is why every +source wraps its own "Name" section in ".. only:: html". + + Sequence Diagrams ----------------- diff --git a/documentation/sphinx-man/conf.py b/documentation/sphinx-man/conf.py @@ -0,0 +1,74 @@ +# Sphinx configuration for building the KyCH man pages out of this repository. +# +# The reStructuredText in ../taler-docs/manpages/ is the single source for the +# man pages. On the website they are rendered by the taler-docs repository, +# which has its own (much larger) conf.py; this file exists so that the same +# sources can be turned into troff here, with nothing but python3-sphinx +# installed, for the Debian package to install. +# +# It deliberately lives outside ../taler-docs/ so that directory stays a set of +# files that can be copied into the taler-docs checkout without clobbering +# anything of its own. +# +# Build with: +# +# sphinx-build -b man -c documentation/sphinx-man \ +# documentation/taler-docs/manpages <outdir> +# +# When these pages are upstreamed, the man_pages entries below have to be added +# to taler-docs/conf.py as well, with a "manpages/" prefix on the first field. + +project = "KyCH" +copyright = "2024-2026 Taler Systems SA" +author = "GNU Taler contributors" + +# No extensions: the man page sources use only core directives ("only", +# "code-block", "note"). Keep it that way, or this build grows dependencies. +extensions = [] + +# There is no index in the source directory -- it holds nothing but the three +# man pages -- so nominate one of them as the root document. Which one does +# not matter for the man builder; each entry in man_pages below is rendered +# from its own source file. +root_doc = "kych-oauth2-gateway.1" + +# Building this way emits "document isn't included in any toctree" for the two +# pages that are not the root document. That is expected and harmless: the +# toctree those pages belong to lives in the taler-docs repository, not here. +# The warning carries no type, so suppress_warnings cannot switch it off, and +# the alternative -- an ":orphan:" field in the shared sources -- would be a +# lie once they are built as part of taler-docs. +exclude_patterns = [] + +# (source file without .rst, name, description, authors, manual section) +# +# The description becomes the NAME line of the generated page, which is why the +# sources wrap their own "Name" section in ".. only:: html". Keep the two +# saying the same thing. +man_pages = [ + ( + "kych-oauth2-gateway.1", + "kych-oauth2-gateway", + "OAuth 2.0 gateway for SWIYU credential verification", + ["GNU Taler contributors"], + 1, + ), + ( + "kych-client-management.1", + "kych-client-management", + "manage OAuth 2.0 clients of the KyCH gateway", + ["GNU Taler contributors"], + 1, + ), + ( + "kych.conf.5", + "kych.conf", + "configuration file of the KyCH OAuth 2.0 gateway", + ["GNU Taler contributors"], + 5, + ), +] + +# Spell out the target of a hyperlink instead of hiding it behind link text, +# which a reader of a terminal cannot click. +man_show_urls = True diff --git a/documentation/taler-docs/README b/documentation/taler-docs/README @@ -83,6 +83,25 @@ Building the Documentation api-kych + The man pages are not reached through a toctree. Sphinx only builds them + if they are listed in the man_pages variable of taler-docs/conf.py, and + the description given there - not anything in the document - becomes the + NAME line of the generated page: + + ("manpages/kych-oauth2-gateway.1", "kych-oauth2-gateway", + "OAuth 2.0 gateway for SWIYU credential verification", + ["GNU Taler contributors"], 1), + ("manpages/kych-client-management.1", "kych-client-management", + "manage OAuth 2.0 clients of the KyCH gateway", + ["GNU Taler contributors"], 1), + ("manpages/kych.conf.5", "kych.conf", + "configuration file of the KyCH OAuth 2.0 gateway", + ["GNU Taler contributors"], 5), + + The same three entries live in kych's own + documentation/sphinx-man/conf.py, which is what the Debian package builds + the man pages with; keep the two copies identical. + 6. Build the HTML documentation: source .venv/bin/activate diff --git a/documentation/taler-docs/kych.conf.5.rst b/documentation/taler-docs/kych.conf.5.rst @@ -1,206 +0,0 @@ -kych.conf(5) -############ - -.. only:: html - - Name - ==== - - **kych.conf** - KyCH OAuth2 Gateway configuration file - - -Description -=========== - -The KyCH OAuth2 Gateway uses an INI-style configuration file. The configuration -defines server binding options, database connection, cryptographic parameters, -verifiable credential settings, and OAuth2 client configurations. - -A configuration file may include another, by using the ``@INLINE@`` directive, -for example, in ``main.conf``, you could write ``@INLINE@ sub.conf`` to -include the entirety of ``sub.conf`` at that point in ``main.conf``. - - -GLOBAL OPTIONS --------------- - -The following options are from the ``[kych-oauth2-gateway]`` section. - - -Server Binding -^^^^^^^^^^^^^^ - -The server can listen on either a TCP socket or a Unix domain socket, but not both. - -HOST - IP address or hostname to bind the TCP server to, e.g. ``127.0.0.1`` or ``0.0.0.0``. - Required when using TCP mode. Must be specified together with ``PORT``. - -PORT - TCP port number to listen on, e.g. ``8080``. - Required when using TCP mode. Must be specified together with ``HOST``. - -UNIXPATH - Path to the Unix domain socket file, e.g. ``/run/kych/kych.sock``. - Required when using Unix socket mode. Cannot be used together with ``HOST``/``PORT``. - -UNIXPATH_MODE - File permissions for the Unix domain socket in octal notation. - Default: ``666``. - Only used when ``UNIXPATH`` is set. - - -Database -^^^^^^^^ - -DATABASE - PostgreSQL connection string for the database. - Required. Example: ``postgres://user:password@localhost/kych``. - - -Cryptographic Parameters -^^^^^^^^^^^^^^^^^^^^^^^^ - -NONCE_BYTES - Number of random bytes to generate for nonces. - Required. Recommended value: ``32``. - -TOKEN_BYTES - Number of random bytes to generate for access tokens. - Required. Recommended value: ``32``. - -AUTH_CODE_BYTES - Number of random bytes to generate for authorization codes. - Required. Recommended value: ``32``. - -AUTH_CODE_TTL_MINUTES - Validity period for authorization codes in minutes. - Default: ``10``. - - -Verifiable Credential Configuration -^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ - -These options define the verifiable credential type that KyCH will request -from the Swiyu Verifier. - -VC_TYPE - The type identifier of the verifiable credential. - Required. Example: ``betaid-sdjwt``. - -VC_FORMAT - The format of the verifiable credential. - Required. Example: ``vc+sd-jwt``. - -VC_ALGORITHMS - List of acceptable cryptographic algorithms for credential verification. - Required. Format is a bracketed comma-separated list. - Example: ``{ES256}`` or ``{ES256, ES384}``. - -VC_CLAIMS - The complete set of claim names that exist in the verifiable credential type. - This defines which claims are valid and can be requested by clients via the - ``scope`` parameter. The gateway validates that all requested claims are in - this set. Required. Format is a bracketed comma-separated list. - Example: ``{family_name, given_name, birth_date, age_over_18}``. - - -Scope Restrictions -^^^^^^^^^^^^^^^^^^ - -ALLOWED_SCOPES - Optional policy restriction on which claims clients may request. If set, - only the listed claims can be requested, even if more claims are defined - in ``VC_CLAIMS``. If not set, clients may request any claim from ``VC_CLAIMS``. - Use this to limit what data clients can access without changing the credential - configuration. Format is a bracketed comma-separated list. - Example: ``{family_name, age_over_18}``. - - -CLIENT SECTIONS ---------------- - -Each OAuth2 client is configured in a separate section with a name starting with -``client_``, for example ``[client_merchant]`` or ``[client_exchange]``. - -CLIENT_ID - Unique identifier for this OAuth2 client. - Required. - -CLIENT_SECRET - Secret key for client authentication. - Required. - -VERIFIER_URL - Base URL of the Swiyu Verifier service that this client will use. - Required. Example: ``https://verifier.swiyu.admin.ch``. - -VERIFIER_MANAGEMENT_API_PATH - Path to the verifier's management API endpoint. - Default: ``/management/api/verifications``. - -REDIRECT_URI - OAuth2 callback URL where the authorization response will be sent. - Required. Must match the redirect URI registered with the client application. - Example: ``https://merchant.example.com/kyc/callback``. - -ACCEPTED_ISSUER_DIDS - Optional list of trusted issuer DIDs for verifiable credentials. - Format is a bracketed comma-separated list. - If not specified, credentials from any issuer are accepted. - Example: ``{did:tdw:issuer1, did:tdw:issuer2}``. - - -EXAMPLE CONFIGURATION -===================== - -:: - - [kych-oauth2-gateway] - # TCP binding (use either TCP or Unix socket, not both) - #HOST = 127.0.0.1 - #PORT = 8080 - - # Unix socket binding - UNIXPATH = /run/kych/kych.sock - UNIXPATH_MODE = 666 - - # Database connection - DATABASE = postgres://kych:secret@localhost/kych - - # Cryptographic parameters - NONCE_BYTES = 32 - TOKEN_BYTES = 32 - AUTH_CODE_BYTES = 32 - AUTH_CODE_TTL_MINUTES = 10 - - # Optional scope restriction - #ALLOWED_SCOPES = {family_name, given_name, birth_date} - - # Verifiable Credential configuration - VC_TYPE = betaid-sdjwt - VC_FORMAT = vc+sd-jwt - VC_ALGORITHMS = {ES256} - VC_CLAIMS = {family_name, given_name, birth_date, nationality} - - # Client configuration - [client_merchant] - CLIENT_ID = merchant_prod_01 - CLIENT_SECRET = supersecretkey - VERIFIER_URL = https://verifier.swiyu.admin.ch - VERIFIER_MANAGEMENT_API_PATH = /management/api/verifications - REDIRECT_URI = https://merchant.example.com/kyc/callback - ACCEPTED_ISSUER_DIDS = {did:tdw:trusted_issuer} - - -SEE ALSO -======== - -kych-oauth2-gateway(1), kych-client-management(1). - - -BUGS -==== - -Report bugs by using https://bugs.taler.net/ or by sending electronic -mail to <taler@gnu.org>. diff --git a/documentation/taler-docs/manpages/kych-client-management.1.rst b/documentation/taler-docs/manpages/kych-client-management.1.rst @@ -1,28 +1,55 @@ kych-client-management(1) ######################### -Name -==== +.. only:: html + + Name + ==== + + **kych-client-management** - manage OAuth 2.0 clients of the KyCH gateway -**kych-client-management** - Manage OAuth2 Gateway clients for KyCH Synopsis ======== -**kych-client-management** [**-c** *CONFIG* | **--config=**\ \ *CONFIG*] *COMMAND* [*OPTIONS*] +**kych-client-management** +**-c** *CONFIG* +*COMMAND* +[*OPTIONS*] + Description =========== -**kych-client-management** is a command-line tool for managing OAuth2 clients -in the KyCH OAuth2 Gateway. It allows administrators to create, update, delete, -list, and synchronize client configurations stored in the database. +**kych-client-management** maintains the table of OAuth 2.0 clients that +kych-oauth2-gateway(1) serves. It allows administrators to create, update, +delete, list and synchronize client registrations. + +This tool exists because the running gateway resolves clients from the +*database* and never from the configuration file. The ``[client_*]`` sections +of kych.conf(5) are only a declarative source for the **sync** command below; +adding a section and restarting the gateway has no effect. The configuration +file is nevertheless required for every invocation, because the database +connection string is read from it. + +Client secrets are stored bcrypt-hashed and cannot be recovered, only +replaced. + Global Options ============== -**-c** *CONFIG* \| **--config=**\ \ *CONFIG* - Use the configuration file *CONFIG*. This option is required for all commands. +**-c** *CONFIG* \| **--config=**\ *CONFIG* + Use the configuration file *CONFIG*. This option is required for all + commands. + +**-h** \| **--help** + Print short help. Also accepted after a command, as in + ``kych-client-management help create``, for the options of that command. + +**-V** \| **--version** + Print version information and exit. + Commands ======== @@ -30,72 +57,92 @@ Commands list ---- -List all registered OAuth2 clients. +List all registered OAuth 2.0 clients, followed by the total count. **kych-client-management** **-c** *CONFIG* **list** show ---- -Show details of a specific OAuth2 client. +Show details of one OAuth 2.0 client. Fails if it does not exist. **kych-client-management** **-c** *CONFIG* **show** *CLIENT_ID* *CLIENT_ID* The identifier of the client to display. +Both **list** and **show** report the internal UUID, the client identifier, a +truncated prefix of the secret hash, the verifier URL and management API +path, the redirect URI allowlist, the accepted issuer DIDs, and the creation +and modification times. + create ------ -Create a new OAuth2 client. +Create a new OAuth 2.0 client. **kych-client-management** **-c** *CONFIG* **create** [*OPTIONS*] -**--client-id=**\ \ *CLIENT_ID* +**--client-id=**\ *CLIENT_ID* The unique identifier for the new client. Required. -**--secret=**\ \ *SECRET* - The client secret for authentication. Required. +**--secret=**\ *SECRET* + The client secret for authentication. Required. Stored hashed. Note that it + is visible in the process list and in the shell history while this command + runs. -**--verifier-url=**\ \ *URL* - The URL of the verifier service. Required. +**--verifier-url=**\ *URL* + Base URL of the SWIYU verifier used for this client's verifications. + Required. -**--verifier-api-path=**\ \ *PATH* +**--verifier-api-path=**\ *PATH* The API path on the verifier for verifications. Default: ``/management/api/verifications`` -**--redirect-uri=**\ \ *URI* - The OAuth2 redirect URI for this client. Required. +**--redirect-uri=**\ *URI* + The OAuth 2.0 redirect URI for this client. Required. Several may be given + as one comma-separated value; a redirect URI presented at authorization + time must match one of them exactly. + +**--accepted-issuer-dids=**\ *DIDS* + Issuers whose credentials this client accepts, as a braced list such as + ``{did:tdw:a, did:tdw:b}``. A bare comma-separated list is also accepted. -**--accepted-issuer-dids=**\ \ *DIDS* - Comma-separated list of accepted issuer DIDs. + .. note:: + + Although this option is syntactically optional, ``/authorize`` fails + with ``accepted_issuer_dids_not_configured`` for a client that has no + issuer DIDs, so no verification can be started. It should always be + given. update ------ -Update an existing OAuth2 client. At least one option must be provided. +Update an existing OAuth 2.0 client. At least one option must be provided; +omitted fields keep their current value. The secret cannot be changed this +way. **kych-client-management** **-c** *CONFIG* **update** *CLIENT_ID* [*OPTIONS*] *CLIENT_ID* The identifier of the client to update. -**--verifier-url=**\ \ *URL* +**--verifier-url=**\ *URL* Update the verifier service URL. -**--verifier-api-path=**\ \ *PATH* +**--verifier-api-path=**\ *PATH* Update the verifier API path. -**--redirect-uri=**\ \ *URI* - Update the OAuth2 redirect URI. +**--redirect-uri=**\ *URI* + Update the OAuth 2.0 redirect URI allowlist. -**--accepted-issuer-dids=**\ \ *DIDS* +**--accepted-issuer-dids=**\ *DIDS* Update the accepted issuer DIDs. delete ------ -Delete an OAuth2 client. +Delete an OAuth 2.0 client. **kych-client-management** **-c** *CONFIG* **delete** [*OPTIONS*] *CLIENT_ID* @@ -103,22 +150,79 @@ Delete an OAuth2 client. The identifier of the client to delete. **-y** \| **--yes** - Skip the confirmation prompt. + Skip the confirmation prompt. Without it, the deletion must be confirmed by + typing ``yes`` on standard input. + +.. warning:: + + Deletion cascades in the database: all verification sessions of that + client, and with them the stored credentials, authorization codes and + access tokens, are removed. sync ---- -Synchronize clients from the configuration file to the database. +Read every ``[client_*]`` section of the configuration file and bring the +database in line with it. Sections whose client identifier is unknown are +created; the rest are updated. **kych-client-management** **-c** *CONFIG* **sync** [*OPTIONS*] **--prune** - Remove clients from the database that are not present in the configuration file. + Remove clients from the database that are not present in the configuration + file, with the same consequences as **delete** above. + +.. note:: + + **sync** never rotates a secret: ``CLIENT_SECRET`` is read only when a + client is first created, and editing it in the configuration file has no + effect. To change a secret, delete the client and synchronize again, or + recreate it with **create**. + + +Exit Status +=========== + +Zero on success. Non-zero if the configuration cannot be read, the database +is unreachable, the named client does not exist, or a client identifier being +created already exists. + + +Examples +======== + +Register the clients described in the configuration file, then check the +result: + +.. code-block:: shell + + $ kych-client-management -c /etc/kych/kych.conf sync + $ kych-client-management -c /etc/kych/kych.conf list + +Register one client directly: + +.. code-block:: shell + + $ kych-client-management -c /etc/kych/kych.conf create \ + --client-id exchange-prod-01 \ + --secret SECRET \ + --verifier-url https://verifier.example.com \ + --redirect-uri https://exchange.example.com/kyc-proof/kych \ + --accepted-issuer-dids '{did:tdw:example:issuer}' + +Point an existing client at a different verifier: + +.. code-block:: shell + + $ kych-client-management -c /etc/kych/kych.conf update exchange-prod-01 \ + --verifier-url https://verifier-staging.example.com + See Also ======== -kych.conf(5), kych-oauth2-gateway(1) +kych-oauth2-gateway(1), kych.conf(5). + Bugs ==== diff --git a/documentation/taler-docs/manpages/kych-oauth2-gateway.1.rst b/documentation/taler-docs/manpages/kych-oauth2-gateway.1.rst @@ -6,40 +6,186 @@ kych-oauth2-gateway(1) Name ==== - **kych-oauth2-gateway** - HTTP server providing OAuth 2.0 endpoints for KYC verification + **kych-oauth2-gateway** - OAuth 2.0 gateway for SWIYU credential verification Synopsis ======== **kych-oauth2-gateway** -[**-c** *FILE* | **--config=**\ ‌\ *FILE*] -[**-L** *LEVEL* | **--log-level=**\ \ *LEVEL*] -[**-h** | **--help**] -[**-V** | **--version**] +**-c** *FILE* +[**-L** *LEVEL*] + +**kych-oauth2-gateway** +[**-h** | **-V**] Description =========== -**kych-oauth2-gateway** is an HTTP server that provides OAuth 2.0 endpoints -for KYC (Know Your Customer) verification using OID4VP (OpenID for Verifiable -Presentations) with the Swiyu Verifier. +**kych-oauth2-gateway** is an HTTP server that lets an OAuth 2.0 client - +typically a GNU Taler exchange performing KYC - obtain identity attributes +from the Swiss SWIYU e-ID trust infrastructure. + +Towards the client it speaks a plain OAuth 2.0 authorization code flow. +Towards the SWIYU verifier it speaks OpenID for Verifiable Presentations +(OID4VP): it builds a presentation definition, has the user's SWIYU wallet +present an SD-JWT verifiable credential against it, and hands the disclosed +claims back to the client. The OAuth 2.0 *scope* of the authorization request +names the credential claims to disclose, which is what makes the disclosure +selective: a client that only needs proof of majority requests the scope +``age_over_18``, and learns nothing else. + +The gateway does not verify credentials itself and holds no signing keys. All +cryptographic verification happens in the SWIYU verifier that kych.conf(5) +points each client at; the gateway keeps the session state, mints the OAuth +2.0 codes and tokens, and stores the wallet's response until the client +collects it. Its options are as follows: -**-c** *FILE* \| **--config=**\ ‌\ *FILE* - Use the configuration from *FILE*. This option is required. +**-c** *FILE* \| **--config=**\ *FILE* + Read the configuration from *FILE*. This option is required; there is no + default location, and the server exits if it is omitted. + See kych.conf(5). + +**-L** *LEVEL* \| **--log-level=**\ *LEVEL* + Set the logging verbosity. Accepted values are ``OFF``, ``ERROR``, + ``WARN``, ``INFO``, ``DEBUG`` and ``TRACE``, or the numbers 0 to 5; case is + ignored. Defaults to ``INFO``. -**-L** *LEVEL* \| **--log-level=**\ \ *LEVEL* - Set the logging verbosity to *LEVEL*. Valid values are ERROR, WARN, - INFO, DEBUG, and TRACE. Defaults to INFO. + The level applies to the gateway's own modules only; the SQL layer is + pinned to ``WARN`` regardless. An unrecognised value is *not* an error: the + offending filter directives are reported on standard error and then + discarded, which leaves the server running with almost all logging + disabled. + + .. note:: + + At ``DEBUG`` the log includes the generated nonces, authorization codes + and the full request bodies exchanged with the verifier. Such logs + contain both secrets and personal data. **-h** \| **--help** - Print short help on options. + Print short help on options and exit. **-V** \| **--version** - Print version information. + Print version information and exit. + + +Endpoints +========= + +The server exposes the following HTTP endpoints. The REST API is specified in +detail in the KyCH OAuth2 Gateway RESTful API documentation; the summary here +is limited to what an administrator needs in order to place the service +behind a reverse proxy. + +``GET /config`` + Public. Reports the credential type, format, algorithms and the complete + set of claims a client may request, as configured by ``VC_TYPE``, + ``VC_FORMAT``, ``VC_ALGORITHMS`` and ``VC_CLAIMS``. + +``POST /setup/{client_id}`` + Authenticated with the client secret as an HTTP bearer token. Opens a + verification session and returns its *nonce*, the unguessable part of the + authorization URL handed to the user. The session expires after 15 minutes. + +``GET /authorize/{nonce}`` + Entered by the user's browser. Takes the OAuth 2.0 parameters + *response_type* (which must be ``code``), *client_id*, *redirect_uri*, + *state* and *scope* as query arguments, creates the verification at the + SWIYU verifier and returns the wallet's verification URL. With an *Accept* + header naming ``text/html`` the reply is a page showing a QR code and a + wallet deep link; otherwise it is JSON. + + The *redirect_uri* must appear in the client's registered allowlist, and + every claim in *scope* must be permitted, or the request is refused. + Re-entering the URL replays the existing verification instead of starting a + second one. + +``POST /notification`` + Unauthenticated webhook, called by the SWIYU verifier when a wallet has + responded. The gateway then fetches the result from the verifier, stores + the disclosed credential and mints the authorization code. It answers + ``200 OK`` in all cases, including every failure, so that the verifier does + not retry; problems are visible only in the log. + +``GET /status/{verification_id}`` + Polled by the browser during verification, authorised by the OAuth 2.0 + *state* value as a query argument. Reports ``pending``, ``authorized``, + ``verified``, ``completed``, ``failed`` or ``expired``. + +``GET /finalize/{verification_id}`` + Also authorised by *state*. Redirects the browser back to the client's + *redirect_uri* with the authorization code, once the session is verified. + +``POST /token`` + The OAuth 2.0 token endpoint, form-encoded, authenticated with *client_id* + and *client_secret*. Exchanges the authorization code for a bearer token + valid for one hour. The code is single-use, and the *redirect_uri* must + match the one used at authorization time. + +``GET /info`` + Authenticated with the bearer token from ``/token``. Returns the disclosed + credential as JSON. + + +Environment +=========== + +``RUST_LOG`` + If set, it replaces the logging configuration entirely and **--log-level** + is ignored. The value is a *tracing* filter, for example + ``kych_oauth2_gateway=debug,sqlx=warn``. + +``PGHOST``, ``PGPORT``, ``PGUSER``, ``PGPASSWORD``, ``PGDATABASE``, ``PGSSLMODE`` + Supply defaults for any part that the ``DATABASE`` connection string leaves + out. Note that ``~/.pgpass`` is *not* consulted when ``DATABASE`` is given + in URI form, which it normally is. + + +Files +===== + +``/etc/kych/kych.conf`` + Configuration file, as installed by the Debian package. The path is not + built in; it must be given with **-c**. + +``./js/`` + The QR code helper served under the ``/js`` URL prefix is read from a path + *relative to the working directory* of the process, not from an installed + location. Start the server from the directory that holds ``js/`` - the + packaged systemd unit uses ``/usr/share/kych`` - or the authorization page + will render without its QR code. + +``/run/kych/kych.sock`` + Listening socket created by the packaged service, per ``UNIXPATH``. + + +Security +======== + +The server speaks plain HTTP and never terminates TLS; run it behind a +reverse proxy. It is not socket-activated - it creates and unlinks +``UNIXPATH`` itself - and it performs no privilege separation, so run it as +an unprivileged user. + +Access control differs per endpoint, and none of it is a substitute for a +proxy that restricts who may reach what. In particular ``/notification`` +accepts unauthenticated requests and should be reachable only from the +verifier's address, while ``/status`` and ``/finalize`` are protected merely +by knowledge of the OAuth 2.0 *state* value. + + +Exit Status +=========== + +The server runs until terminated by a signal. It exits non-zero before +serving any request if the configuration cannot be read or is inconsistent +(for instance if both ``HOST``/``PORT`` and ``UNIXPATH`` are set, or +neither), if the database is unreachable, or if the listening socket cannot +be bound. Examples @@ -61,11 +207,14 @@ Start the server with debug logging enabled: See Also ======== -kych.conf(5), kych-client-management(1). +kych-client-management(1), kych.conf(5). + +The KyCH operator manual, https://docs.taler.net/taler-kych-manual.html, and +the REST API specification, https://docs.taler.net/core/api-kych.html. Bugs ==== -Report bugs by using https://bugs.taler.net or by sending electronic +Report bugs by using https://bugs.taler.net/ or by sending electronic mail to <taler@gnu.org>. diff --git a/documentation/taler-docs/manpages/kych.conf.5.rst b/documentation/taler-docs/manpages/kych.conf.5.rst @@ -0,0 +1,308 @@ +kych.conf(5) +############ + +.. only:: html + + Name + ==== + + **kych.conf** - configuration file of the KyCH OAuth 2.0 gateway + + +Description +=========== + +kych-oauth2-gateway(1) and kych-client-management(1) read their configuration +from an INI-style file named with the **-c** option; the Debian package +installs one at ``/etc/kych/kych.conf``. It holds one +``[kych-oauth2-gateway]`` section with the settings of the service itself, +and any number of ``[client_*]`` sections describing OAuth 2.0 clients. + +The file contains the database credentials and the client secrets, and should +not be world-readable. + +Nothing is re-read at run time; restart the service after editing. + +A configuration file may include another, by using the ``@INLINE@`` +directive: in ``main.conf``, writing ``@INLINE@ sub.conf`` includes the +entirety of ``sub.conf`` at that point in ``main.conf``. + +.. note:: + + ``@INLINE@`` is **not implemented**. The parser used by KyCH is a plain + INI reader with no notion of includes, and it does not diagnose the + directive either: the line is taken to be the beginning of a key, and it + swallows the line that follows it, so the setting on that next line is + silently lost. Until this is fixed, keep everything in a single file - and + in particular note that the ``@inline-secret@`` mechanism other GNU Taler + components use to keep credentials out of the main configuration is not + available here. + + +Syntax +------ + +Comments are introduced by ``#`` or ``;`` and **must stand on a line of their +own**. The parser has no notion of a trailing comment, and the two places +where one might be written fail differently: + +* after a value, as in ``PORT = 8080 # the port``, the ``#`` and everything + after it become part of the value, which then fails to parse as a number; + +* after a section header, as in ``[client_x] # the exchange``, the whole + file is rejected with ``doesn't support inline comment``. + +Values are trimmed of surrounding whitespace. Several options take a list, +written in braces and separated by commas, for example ``{ES256, ES384}``. +The list parsers are not uniformly strict - ``VC_ALGORITHMS`` and +``VC_CLAIMS`` insist on the braces, while ``ALLOWED_SCOPES`` and +``ACCEPTED_ISSUER_DIDS`` also accept a bare comma- or space-separated list - +but writing the braces everywhere is correct and portable. + + +GLOBAL OPTIONS +-------------- + +The following options are from the ``[kych-oauth2-gateway]`` section. + + +Server Binding +^^^^^^^^^^^^^^ + +The server can listen on either a TCP socket or a Unix domain socket, but not +both. Configuring both, or neither, is an error and the server refuses to +start. + +HOST + IP address or hostname to bind the TCP server to, e.g. ``127.0.0.1`` or + ``0.0.0.0``. Required when using TCP mode. Must be specified together with + ``PORT``. The server speaks plain HTTP; do not bind an address reachable + from outside the host. + +PORT + TCP port number to listen on, e.g. ``8080``. + Required when using TCP mode. Must be specified together with ``HOST``. + +UNIXPATH + Path to the Unix domain socket file, e.g. ``/run/kych/kych.sock``. + Required when using Unix socket mode. Cannot be used together with + ``HOST``/``PORT``. The server creates the socket itself - it does not + accept one from systemd - and unlinks a leftover socket of a previous run + at startup. The directory must already exist. + +UNIXPATH_MODE + File permissions for the Unix domain socket in octal notation. + Default: ``666``. + Only used when ``UNIXPATH`` is set. The socket's group is the group the + server runs as, so ``660`` plus a shared group is the usual way to restrict + it to the reverse proxy. + + +Database +^^^^^^^^ + +DATABASE + PostgreSQL connection string for the database. Required. + + Both the URI form, ``postgres://user:secret@localhost/kych``, and a URI + naming a Unix socket directory, ``postgres:///kych?host=/var/run/postgresql``, + are understood. Anything the string leaves out is taken from the usual + ``PGHOST``, ``PGPORT``, ``PGUSER``, ``PGPASSWORD``, ``PGDATABASE`` and + ``PGSSLMODE`` environment variables, or, for the user name, from the + account the process runs as - which is what makes peer authentication work + without a password in the file. The ``~/.pgpass`` file is *not* consulted + for a connection string in URI form. + + The schema is not created automatically; it must be loaded from the SQL + shipped with the software before the first start. + + +Cryptographic Parameters +^^^^^^^^^^^^^^^^^^^^^^^^ + +All three sizes are counts of random bytes, before base64url encoding. The +recommended value is 32 in each case, and lowering it directly weakens the +unguessability that the corresponding secret relies on. + +NONCE_BYTES + Number of random bytes to generate for the nonce created by ``/setup``, + which forms the secret part of the authorization URL given to the user. + Required. Recommended value: ``32``. + +TOKEN_BYTES + Number of random bytes to generate for the OAuth 2.0 access token issued by + ``/token``. Required. Recommended value: ``32``. + +AUTH_CODE_BYTES + Number of random bytes to generate for the OAuth 2.0 authorization code. + Required. Recommended value: ``32``. + +AUTH_CODE_TTL_MINUTES + Validity period for authorization codes in minutes. + Default: ``10``. + The code is single-use in any case. + + +Verifiable Credential Configuration +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +These options define the verifiable credential type that KyCH will request +from the Swiyu Verifier. They are also published to clients on the +``/config`` endpoint, and must match what the issuer actually issues. + +VC_TYPE + The type identifier of the verifiable credential, matched against the + ``vct`` claim of the presented SD-JWT. + Required. Example: ``betaid-sdjwt``. + +VC_FORMAT + The format of the verifiable credential. + Required. Example: ``vc+sd-jwt``. + +VC_ALGORITHMS + List of acceptable cryptographic algorithms for the credential and for the + key binding JWT. + Required, and must not be empty. Format is a bracketed comma-separated + list. Example: ``{ES256}`` or ``{ES256, ES384}``. + +VC_CLAIMS + The complete set of claim names that exist in the verifiable credential + type. This defines which claims are valid and can be requested by clients + via the ``scope`` parameter. The gateway validates that all requested + claims are in this set. Required, and must not be empty. Format is a + bracketed comma-separated list. + Example: ``{family_name, given_name, birth_date, age_over_18}``. + + +Scope Restrictions +^^^^^^^^^^^^^^^^^^ + +ALLOWED_SCOPES + Optional policy restriction on which claims clients may request. If set, + only the listed claims can be requested, even if more claims are defined + in ``VC_CLAIMS``. If not set, clients may request any claim from + ``VC_CLAIMS``. + Use this to limit what data clients can access without changing the + credential configuration. Format is a bracketed comma-separated list. + Example: ``{family_name, age_over_18}``. + + This is the operator's lever for data minimisation, and it is worth + setting: without it, a client is trusted to ask only for what it needs. + + +CLIENT SECTIONS +--------------- + +Each OAuth2 client is configured in a separate section with a name starting +with ``client_``, for example ``[client_merchant]`` or ``[client_exchange]``; +the rest of the name is arbitrary. + +.. note:: + + These sections are **not read by the running gateway**, which resolves + clients from the database. They are the input to + + .. code-block:: shell + + $ kych-client-management -c /etc/kych/kych.conf sync + + which creates or updates the corresponding database rows; see + kych-client-management(1). Until that command has been run, a newly + described client does not exist, and requests on its behalf are rejected + as unauthorized. + +CLIENT_ID + Unique identifier for this OAuth2 client, used at ``/setup`` and at + ``/token``. + Required. + +CLIENT_SECRET + Secret key for client authentication, stored bcrypt-hashed in the database. + Required. + + It is read only when the client is first created. Changing it here and + running **sync** again does *not* rotate the stored secret; delete the + client and synchronize again for that. + +VERIFIER_URL + Base URL of the Swiyu Verifier service that this client will use. + Required. Example: ``https://verifier.swiyu.admin.ch``. + +VERIFIER_MANAGEMENT_API_PATH + Path to the verifier's management API endpoint. + Default: ``/management/api/verifications``. + +REDIRECT_URI + OAuth2 callback URL where the authorization response will be sent. + Required, and must not be empty. Must match the redirect URI registered + with the client application. Several may be given as one comma-separated + value; the *redirect_uri* of an authorization request must match one of + them exactly, and the same value must be repeated on the token request. + Example: ``https://merchant.example.com/kyc/callback``. + +ACCEPTED_ISSUER_DIDS + List of trusted issuer DIDs for verifiable credentials. + Format is a bracketed comma-separated list. + Example: ``{did:tdw:issuer1, did:tdw:issuer2}``. + + .. note:: + + Formally optional - the configuration parses without it - but in + practice required: ``/authorize`` fails with + ``accepted_issuer_dids_not_configured`` for a client that has no issuer + DIDs, so no verification can be started. + + +EXAMPLE CONFIGURATION +===================== + +:: + + [kych-oauth2-gateway] + # TCP binding (use either TCP or Unix socket, not both) + #HOST = 127.0.0.1 + #PORT = 8080 + + # Unix socket binding + UNIXPATH = /run/kych/kych.sock + UNIXPATH_MODE = 660 + + # Database connection + DATABASE = postgres:///kych?host=/var/run/postgresql + + # Cryptographic parameters + NONCE_BYTES = 32 + TOKEN_BYTES = 32 + AUTH_CODE_BYTES = 32 + AUTH_CODE_TTL_MINUTES = 10 + + # Optional scope restriction + #ALLOWED_SCOPES = {family_name, given_name, birth_date} + + # Verifiable Credential configuration + VC_TYPE = betaid-sdjwt + VC_FORMAT = vc+sd-jwt + VC_ALGORITHMS = {ES256} + VC_CLAIMS = {family_name, given_name, birth_date, nationality} + + # Client configuration + [client_merchant] + CLIENT_ID = merchant_prod_01 + CLIENT_SECRET = supersecretkey + VERIFIER_URL = https://verifier.swiyu.admin.ch + VERIFIER_MANAGEMENT_API_PATH = /management/api/verifications + REDIRECT_URI = https://merchant.example.com/kyc/callback + ACCEPTED_ISSUER_DIDS = {did:tdw:trusted_issuer} + + +SEE ALSO +======== + +kych-oauth2-gateway(1), kych-client-management(1). + + +BUGS +==== + +Report bugs by using https://bugs.taler.net/ or by sending electronic +mail to <taler@gnu.org>. diff --git a/kych_oauth2_gateway/Cargo.lock b/kych_oauth2_gateway/Cargo.lock @@ -0,0 +1,3265 @@ +# This file is automatically @generated by Cargo. +# It is not intended for manual editing. +version = 4 + +[[package]] +name = "aho-corasick" +version = "1.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c982642fa9e8606056828ee9a8505737230110bb1099153c79efe865c59d12ba" +dependencies = [ + "memchr", +] + +[[package]] +name = "allocator-api2" +version = "0.2.21" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "683d7910e743518b0e34f1186f92494becacb047c7b6bf616c96772180fef923" + +[[package]] +name = "android_system_properties" +version = "0.1.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ae221649c9976a6f6c56ae1facf410f3ddb33cc661c4b7b61020a912d4237fbc" +dependencies = [ + "libc", +] + +[[package]] +name = "anstream" +version = "1.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "824a212faf96e9acacdbd09febd34438f8f711fb84e09a8916013cd7815ca28d" +dependencies = [ + "anstyle", + "anstyle-parse", + "anstyle-query", + "anstyle-wincon", + "colorchoice", + "is_terminal_polyfill", + "utf8parse", +] + +[[package]] +name = "anstyle" +version = "1.0.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "940b3a0ca603d1eade50a4846a2afffd5ef57a9feac2c0e2ec2e14f9ead76000" + +[[package]] +name = "anstyle-parse" +version = "1.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "52ce7f38b242319f7cabaa6813055467063ecdc9d355bbb4ce0c68908cd8130e" +dependencies = [ + "utf8parse", +] + +[[package]] +name = "anstyle-query" +version = "1.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "40c48f72fd53cd289104fc64099abca73db4166ad86ea0b4341abe65af83dadc" +dependencies = [ + "windows-sys 0.61.2", +] + +[[package]] +name = "anstyle-wincon" +version = "3.0.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "291e6a250ff86cd4a820112fb8898808a366d8f9f58ce16d1f538353ad55747d" +dependencies = [ + "anstyle", + "once_cell_polyfill", + "windows-sys 0.61.2", +] + +[[package]] +name = "anyhow" +version = "1.0.104" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "330a5ed07fa54e4702c9d6c4174f74427fc0ef6e214bbd677ae50a5099946470" + +[[package]] +name = "askama" +version = "0.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b79091df18a97caea757e28cd2d5fda49c6cd4bd01ddffd7ff01ace0c0ad2c28" +dependencies = [ + "askama_derive", + "askama_escape", + "humansize", + "num-traits", + "percent-encoding", +] + +[[package]] +name = "askama_derive" +version = "0.12.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "19fe8d6cb13c4714962c072ea496f3392015f0989b1a2847bb4b2d9effd71d83" +dependencies = [ + "askama_parser", + "basic-toml", + "mime", + "mime_guess", + "proc-macro2", + "quote", + "serde", + "syn 2.0.119", +] + +[[package]] +name = "askama_escape" +version = "0.10.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "619743e34b5ba4e9703bba34deac3427c72507c7159f5fd030aea8cac0cfe341" + +[[package]] +name = "askama_parser" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "acb1161c6b64d1c3d83108213c2a2533a342ac225aabd0bda218278c2ddb00c0" +dependencies = [ + "nom", +] + +[[package]] +name = "assert-json-diff" +version = "2.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "47e4f2b81832e72834d7518d8487a0396a28cc408186a2e8854c0f98011faf12" +dependencies = [ + "serde", + "serde_json", +] + +[[package]] +name = "atoi" +version = "2.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f28d99ec8bfea296261ca1af174f24225171fea9664ba9003cbebee704810528" +dependencies = [ + "num-traits", +] + +[[package]] +name = "atomic-waker" +version = "1.1.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1505bd5d3d116872e7271a6d4e16d81d0c8570876c8de68093a09ac269d8aac0" + +[[package]] +name = "autocfg" +version = "1.5.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53" + +[[package]] +name = "axum" +version = "0.8.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "31b698c5f9a010f6573133b09e0de5408834d0c82f8d7475a89fc1867a71cd90" +dependencies = [ + "axum-core", + "bytes", + "form_urlencoded", + "futures-util", + "http", + "http-body", + "http-body-util", + "hyper", + "hyper-util", + "itoa", + "matchit", + "memchr", + "mime", + "percent-encoding", + "pin-project-lite", + "serde_core", + "serde_json", + "serde_path_to_error", + "serde_urlencoded", + "sync_wrapper", + "tokio", + "tower", + "tower-layer", + "tower-service", + "tracing", +] + +[[package]] +name = "axum-core" +version = "0.5.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "08c78f31d7b1291f7ee735c1c6780ccde7785daae9a9206026862dab7d8792d1" +dependencies = [ + "bytes", + "futures-core", + "http", + "http-body", + "http-body-util", + "mime", + "pin-project-lite", + "sync_wrapper", + "tower-layer", + "tower-service", + "tracing", +] + +[[package]] +name = "base64" +version = "0.22.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6" + +[[package]] +name = "base64ct" +version = "1.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2af50177e190e07a26ab74f8b1efbfe2ef87da2116221318cb1c2e82baf7de06" + +[[package]] +name = "basic-toml" +version = "0.1.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ba62675e8242a4c4e806d12f11d136e626e6c8361d6b829310732241652a178a" +dependencies = [ + "serde", +] + +[[package]] +name = "bcrypt" +version = "0.15.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e65938ed058ef47d92cf8b346cc76ef48984572ade631927e9937b5ffc7662c7" +dependencies = [ + "base64", + "blowfish", + "getrandom 0.2.17", + "subtle", + "zeroize", +] + +[[package]] +name = "bitflags" +version = "2.13.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da" +dependencies = [ + "serde_core", +] + +[[package]] +name = "block-buffer" +version = "0.10.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3078c7629b62d3f0439517fa394996acacc5cbc91c5a20d8c658e77abd503a71" +dependencies = [ + "generic-array", +] + +[[package]] +name = "blowfish" +version = "0.9.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e412e2cd0f2b2d93e02543ceae7917b3c70331573df19ee046bcbc35e45e87d7" +dependencies = [ + "byteorder", + "cipher", +] + +[[package]] +name = "bumpalo" +version = "3.20.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "72f5acc6cb2ba439de613abc23857ec3d78374d8ed5ac84e9d11336e87da8649" + +[[package]] +name = "byteorder" +version = "1.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1fd0f2584146f6f2ef48085050886acf353beff7305ebd1ae69500e27c67f64b" + +[[package]] +name = "bytes" +version = "1.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "fc652a48c352aef3ea3aed32080501cf3ef6ed5da78602a020c991775b0aff04" + +[[package]] +name = "cc" +version = "1.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5d262e149917187838d5b42777c8253bcb64500067342904e7d429499a6f277e" +dependencies = [ + "find-msvc-tools", + "shlex", +] + +[[package]] +name = "cfg-if" +version = "1.0.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" + +[[package]] +name = "chrono" +version = "0.4.45" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1aa79e62e7697b8e29b513a68abacf485adcd1fe8284a4316c5ae868e6633327" +dependencies = [ + "iana-time-zone", + "js-sys", + "num-traits", + "serde", + "wasm-bindgen", + "windows-link", +] + +[[package]] +name = "cipher" +version = "0.4.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "773f3b9af64447d2ce9850330c473515014aa235e6a783b02db81ff39e4a3dad" +dependencies = [ + "crypto-common", + "inout", +] + +[[package]] +name = "clap" +version = "4.6.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "473c7e07f409a8d772161724aa8db6a765a2532a70f9667eeb7b49d3d02fbdca" +dependencies = [ + "clap_builder", + "clap_derive", +] + +[[package]] +name = "clap_builder" +version = "4.6.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7b48fea5a88e9ae728a2dcbedbfc0e730f7d60da42e1cb049a83c9fb8b789889" +dependencies = [ + "anstream", + "anstyle", + "clap_lex", + "strsim", +] + +[[package]] +name = "clap_derive" +version = "4.6.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d012d2b9d65aca7f18f4d9878a045bc17899bba951561ba5ec3c2ba1eed9a061" +dependencies = [ + "heck", + "proc-macro2", + "quote", + "syn 3.0.3", +] + +[[package]] +name = "clap_lex" +version = "1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c8d4a3bb8b1e0c1050499d1815f5ab16d04f0959b233085fb31653fbfc9d98f9" + +[[package]] +name = "colorchoice" +version = "1.0.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1d07550c9036bf2ae0c684c4297d503f838287c83c53686d05370d0e139ae570" + +[[package]] +name = "colored" +version = "3.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "faf9468729b8cbcea668e36183cb69d317348c2e08e994829fb56ebfdfbaac34" +dependencies = [ + "windows-sys 0.61.2", +] + +[[package]] +name = "const-oid" +version = "0.9.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c2459377285ad874054d797f3ccebf984978aa39129f6eafde5cdc8315b612f8" + +[[package]] +name = "const-random" +version = "0.1.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "87e00182fe74b066627d63b85fd550ac2998d4b0bd86bfed477a0ae4c7c71359" +dependencies = [ + "const-random-macro", +] + +[[package]] +name = "const-random-macro" +version = "0.1.16" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f9d839f2a20b0aee515dc581a6172f2321f96cab76c1a38a4c584a194955390e" +dependencies = [ + "getrandom 0.2.17", + "once_cell", + "tiny-keccak", +] + +[[package]] +name = "core-foundation" +version = "0.9.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "91e195e091a93c46f7102ec7818a2aa394e1e1771c3ab4825963fa03e45afb8f" +dependencies = [ + "core-foundation-sys", + "libc", +] + +[[package]] +name = "core-foundation" +version = "0.10.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b2a6cd9ae233e7f62ba4e9353e81a88df7fc8a5987b8d445b4d90c879bd156f6" +dependencies = [ + "core-foundation-sys", + "libc", +] + +[[package]] +name = "core-foundation-sys" +version = "0.8.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "773648b94d0e5d620f64f280777445740e61fe701025087ec8b57f45c791888b" + +[[package]] +name = "cpufeatures" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "59ed5838eebb26a2bb2e58f6d5b5316989ae9d08bab10e0e6d103e656d1b0280" +dependencies = [ + "libc", +] + +[[package]] +name = "crc" +version = "3.4.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5eb8a2a1cd12ab0d987a5d5e825195d372001a4094a0376319d5a0ad71c1ba0d" +dependencies = [ + "crc-catalog", +] + +[[package]] +name = "crc-catalog" +version = "2.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "217698eaf96b4a3f0bc4f3662aaa55bdf913cd54d7204591faa790070c6d0853" + +[[package]] +name = "crossbeam-queue" +version = "0.3.13" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "803d13fb3b09d88be9f4dbc29062c66b19bf7170867ceb746d2a8689bf6c7a26" +dependencies = [ + "crossbeam-utils", +] + +[[package]] +name = "crossbeam-utils" +version = "0.8.22" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "61803da095bee82a81bb1a452ecc25d3b2f1416d1897eb86430c6159ef717c17" + +[[package]] +name = "crunchy" +version = "0.2.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "460fbee9c2c2f33933d720630a6a0bac33ba7053db5344fac858d4b8952d77d5" + +[[package]] +name = "crypto-common" +version = "0.1.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "78c8292055d1c1df0cce5d180393dc8cce0abec0a7102adb6c7b1eef6016d60a" +dependencies = [ + "generic-array", + "typenum", +] + +[[package]] +name = "der" +version = "0.7.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb" +dependencies = [ + "const-oid", + "pem-rfc7468", + "zeroize", +] + +[[package]] +name = "deranged" +version = "0.5.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7cd812cc2bc1d69d4764bd80df88b4317eaef9e773c75226407d9bc0876b211c" + +[[package]] +name = "digest" +version = "0.10.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292" +dependencies = [ + "block-buffer", + "const-oid", + "crypto-common", + "subtle", +] + +[[package]] +name = "displaydoc" +version = "0.2.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c6232dd377dcc64799954cbd3a9bb882e9cdc1308ccd87b1c098f1fb2eaf82a8" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.3", +] + +[[package]] +name = "dlv-list" +version = "0.5.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "442039f5147480ba31067cb00ada1adae6892028e40e45fc5de7b7df6dcc1b5f" +dependencies = [ + "const-random", +] + +[[package]] +name = "dotenvy" +version = "0.15.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1aaf95b3e5c8f23aa320147307562d361db0ae0d51242340f558153b4eb2439b" + +[[package]] +name = "either" +version = "1.17.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9e5e8f6c15a24b9a3ee5efec809ccd006d3b30e8b3bb63c39af737c7f87daa1d" +dependencies = [ + "serde", +] + +[[package]] +name = "encoding_rs" +version = "0.8.35" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "75030f3c4f45dafd7586dd6780965a8c7e8e285a5ecb86713e63a79c5b2766f3" +dependencies = [ + "cfg-if", +] + +[[package]] +name = "equivalent" +version = "1.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" + +[[package]] +name = "errno" +version = "0.3.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb" +dependencies = [ + "libc", + "windows-sys 0.61.2", +] + +[[package]] +name = "etcetera" +version = "0.8.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "136d1b5283a1ab77bd9257427ffd09d8667ced0570b6f938942bc7568ed5b943" +dependencies = [ + "cfg-if", + "home", + "windows-sys 0.48.0", +] + +[[package]] +name = "event-listener" +version = "5.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5a23add41df1562121a9393cb065eab5146a1242410f23a644851e90cfd669d2" +dependencies = [ + "parking", + "pin-project-lite", +] + +[[package]] +name = "fastrand" +version = "2.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "da7c62ceae207dd37ea5b845da6a0696c799f85e97da1ab5b7910be3c1c80223" + +[[package]] +name = "find-msvc-tools" +version = "0.1.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "26b73573e6edcd2af0cdf47bd6cb58f0b3839491263c314eaad1ccf24430e1de" + +[[package]] +name = "flume" +version = "0.11.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "da0e4dd2a88388a1f4ccc7c9ce104604dab68d9f408dc34cd45823d5a9069095" +dependencies = [ + "futures-core", + "futures-sink", + "spin", +] + +[[package]] +name = "fnv" +version = "1.0.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1" + +[[package]] +name = "foldhash" +version = "0.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d9c4f5dac5e15c24eb999c26181a6ca40b39fe946cbe4c263c7209467bc83af2" + +[[package]] +name = "foreign-types" +version = "0.3.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f6f339eb8adc052cd2ca78910fda869aefa38d22d5cb648e6485e4d3fc06f3b1" +dependencies = [ + "foreign-types-shared", +] + +[[package]] +name = "foreign-types-shared" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "00b0228411908ca8685dba7fc2cdd70ec9990a6e753e89b6ac91a84c40fbaf4b" + +[[package]] +name = "form_urlencoded" +version = "1.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cb4cb245038516f5f85277875cdaa4f7d2c9a0fa0468de06ed190163b1581fcf" +dependencies = [ + "percent-encoding", +] + +[[package]] +name = "futures-channel" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "262590f4fe6afeb0bc83be1daa64e52657fe185690a958af7f3ad0e92085c5ae" +dependencies = [ + "futures-core", + "futures-sink", +] + +[[package]] +name = "futures-core" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2cd50c473c80f6d7c3670a752354b8e569b1a7cbfdc0419ec88e5edad85e0dc7" + +[[package]] +name = "futures-executor" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6754879cc9f2c66f88c6e5c35344bb0bdb0708b0352b1201815667c7eabc7458" +dependencies = [ + "futures-core", + "futures-task", + "futures-util", +] + +[[package]] +name = "futures-intrusive" +version = "0.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1d930c203dd0b6ff06e0201a4a2fe9149b43c684fd4420555b26d21b1a02956f" +dependencies = [ + "futures-core", + "lock_api", + "parking_lot", +] + +[[package]] +name = "futures-io" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4577ecaa3c4f96589d473f679a71b596316f6641bc350038b962a5daf0085d7a" + +[[package]] +name = "futures-sink" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e34418ac499d6305c2fb5ad0ed2f6ac998c5f8ca209b4510f7f94242c647e307" + +[[package]] +name = "futures-task" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b231ed28831efb4a61a08580c4bc233ec56bc009f4cd8f52da2c3cb97df0c109" + +[[package]] +name = "futures-util" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a77a90a256fce34da66415271e30f94ee91c57b04b8a2c042d9cf3220179deaa" +dependencies = [ + "futures-core", + "futures-io", + "futures-sink", + "futures-task", + "memchr", + "pin-project-lite", + "slab", +] + +[[package]] +name = "generic-array" +version = "0.14.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "85649ca51fd72272d7821adaf274ad91c288277713d9c18820d8499a7ff69e9a" +dependencies = [ + "typenum", + "version_check", +] + +[[package]] +name = "getrandom" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ff2abc00be7fca6ebc474524697ae276ad847ad0a6b3faa4bcb027e9a4614ad0" +dependencies = [ + "cfg-if", + "libc", + "wasi", +] + +[[package]] +name = "getrandom" +version = "0.3.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "899def5c37c4fd7b2664648c28120ecec138e4d395b459e5ca34f9cce2dd77fd" +dependencies = [ + "cfg-if", + "libc", + "r-efi 5.3.0", + "wasip2", +] + +[[package]] +name = "getrandom" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "300e883d756b2e4ec94e02791f39b04b522276138852cfc41d9fb7e904106099" +dependencies = [ + "cfg-if", + "libc", + "r-efi 6.0.0", +] + +[[package]] +name = "h2" +version = "0.4.15" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6cb093c84e8bd9b188d4c4a8cb6579fc016968d14c99882163cd3ff402a4f155" +dependencies = [ + "atomic-waker", + "bytes", + "fnv", + "futures-core", + "futures-sink", + "http", + "indexmap", + "slab", + "tokio", + "tokio-util", + "tracing", +] + +[[package]] +name = "hashbrown" +version = "0.14.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e5274423e17b7c9fc20b6e7e208532f9b19825d82dfd615708b70edd83df41f1" + +[[package]] +name = "hashbrown" +version = "0.15.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9229cfe53dfd69f0609a49f65461bd93001ea1ef889cd5529dd176593f5338a1" +dependencies = [ + "allocator-api2", + "equivalent", + "foldhash", +] + +[[package]] +name = "hashbrown" +version = "0.17.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed5909b6e89a2db4456e54cd5f673791d7eca6732202bbf2a9cc504fe2f9b84a" + +[[package]] +name = "hashlink" +version = "0.10.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7382cf6263419f2d8df38c55d7da83da5c18aef87fc7a7fc1fb1e344edfe14c1" +dependencies = [ + "hashbrown 0.15.5", +] + +[[package]] +name = "heck" +version = "0.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea" + +[[package]] +name = "hex" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70" + +[[package]] +name = "hkdf" +version = "0.12.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7b5f8eb2ad728638ea2c7d47a21db23b7b58a72ed6a38256b8a1849f15fbbdf7" +dependencies = [ + "hmac", +] + +[[package]] +name = "hmac" +version = "0.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6c49c37c09c17a53d937dfbb742eb3a961d65a994e6bcdcf37e7399d0cc8ab5e" +dependencies = [ + "digest", +] + +[[package]] +name = "home" +version = "0.5.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cc627f471c528ff0c4a49e1d5e60450c8f6461dd6d10ba9dcd3a61d3dff7728d" +dependencies = [ + "windows-sys 0.61.2", +] + +[[package]] +name = "http" +version = "1.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "918d3568bebf352712bc2ef3d46a8bcf1a75b373be6539de198e9105cbbf9ce0" +dependencies = [ + "bytes", + "itoa", +] + +[[package]] +name = "http-body" +version = "1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ca2a8f2913ee65f60facd6a5905613afaa448497a0230cc41ce022d93290bc2c" +dependencies = [ + "bytes", + "http", +] + +[[package]] +name = "http-body-util" +version = "0.1.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e9f41fd6a08e4d4ec69df65976da761afd5ad5e58a9d4acb46bd1c953a9e3ff2" +dependencies = [ + "bytes", + "futures-core", + "http", + "http-body", + "pin-project-lite", +] + +[[package]] +name = "http-range-header" +version = "0.4.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9171a2ea8a68358193d15dd5d70c1c10a2afc3e7e4c5bc92bc9f025cebd7359c" + +[[package]] +name = "httparse" +version = "1.10.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6dbf3de79e51f3d586ab4cb9d5c3e2c14aa28ed23d180cf89b4df0454a69cc87" + +[[package]] +name = "httpdate" +version = "1.0.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "df3b46402a9d5adb4c86a0cf463f42e19994e3ee891101b1841f30a545cb49a9" + +[[package]] +name = "humansize" +version = "2.1.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6cb51c9a029ddc91b07a787f1d86b53ccfa49b0e86688c946ebe8d3555685dd7" +dependencies = [ + "libm", +] + +[[package]] +name = "hyper" +version = "1.11.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d22053281f852e11534f5198498373cbb59295120a20771d90f7ed1897490a72" +dependencies = [ + "atomic-waker", + "bytes", + "futures-channel", + "futures-core", + "h2", + "http", + "http-body", + "httparse", + "httpdate", + "itoa", + "pin-project-lite", + "smallvec", + "tokio", + "want", +] + +[[package]] +name = "hyper-rustls" +version = "0.27.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "33ca68d021ef39cf6463ab54c1d0f5daf03377b70561305bb89a8f83aab66e0f" +dependencies = [ + "http", + "hyper", + "hyper-util", + "rustls", + "tokio", + "tokio-rustls", + "tower-service", +] + +[[package]] +name = "hyper-tls" +version = "0.6.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "70206fc6890eaca9fde8a0bf71caa2ddfc9fe045ac9e5c70df101a7dbde866e0" +dependencies = [ + "bytes", + "http-body-util", + "hyper", + "hyper-util", + "native-tls", + "tokio", + "tokio-native-tls", + "tower-service", +] + +[[package]] +name = "hyper-util" +version = "0.1.20" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "96547c2556ec9d12fb1578c4eaf448b04993e7fb79cbaad930a656880a6bdfa0" +dependencies = [ + "base64", + "bytes", + "futures-channel", + "futures-util", + "http", + "http-body", + "hyper", + "ipnet", + "libc", + "percent-encoding", + "pin-project-lite", + "socket2", + "system-configuration", + "tokio", + "tower-service", + "tracing", + "windows-registry", +] + +[[package]] +name = "iana-time-zone" +version = "0.1.65" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e31bc9ad994ba00e440a8aa5c9ef0ec67d5cb5e5cb0cc7f8b744a35b389cc470" +dependencies = [ + "android_system_properties", + "core-foundation-sys", + "iana-time-zone-haiku", + "js-sys", + "log", + "wasm-bindgen", + "windows-core", +] + +[[package]] +name = "iana-time-zone-haiku" +version = "0.1.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f31827a206f56af32e590ba56d5d2d085f558508192593743f16b2306495269f" +dependencies = [ + "cc", +] + +[[package]] +name = "icu_collections" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2984d1cd16c883d7935b9e07e44071dca8d917fd52ecc02c04d5fa0b5a3f191c" +dependencies = [ + "displaydoc", + "potential_utf", + "utf8_iter", + "yoke", + "zerofrom", + "zerovec", +] + +[[package]] +name = "icu_locale_core" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "92219b62b3e2b4d88ac5119f8904c10f8f61bf7e95b640d25ba3075e6cac2c29" +dependencies = [ + "displaydoc", + "litemap", + "tinystr", + "writeable", + "zerovec", +] + +[[package]] +name = "icu_normalizer" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c56e5ee99d6e3d33bd91c5d85458b6005a22140021cc324cea84dd0e72cff3b4" +dependencies = [ + "icu_collections", + "icu_normalizer_data", + "icu_properties", + "icu_provider", + "smallvec", + "zerovec", +] + +[[package]] +name = "icu_normalizer_data" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "da3be0ae77ea334f4da67c12f149704f19f81d1adf7c51cf482943e84a2bad38" + +[[package]] +name = "icu_properties" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bee3b67d0ea5c2cca5003417989af8996f8604e34fb9ddf96208a033901e70de" +dependencies = [ + "icu_collections", + "icu_locale_core", + "icu_properties_data", + "icu_provider", + "zerotrie", + "zerovec", +] + +[[package]] +name = "icu_properties_data" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8e2bbb201e0c04f7b4b3e14382af113e17ba4f63e2c9d2ee626b720cbce54a14" + +[[package]] +name = "icu_provider" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "139c4cf31c8b5f33d7e199446eff9c1e02decfc2f0eec2c8d71f65befa45b421" +dependencies = [ + "displaydoc", + "icu_locale_core", + "writeable", + "yoke", + "zerofrom", + "zerotrie", + "zerovec", +] + +[[package]] +name = "idna" +version = "1.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3b0875f23caa03898994f6ddc501886a45c7d3d62d04d2d90788d47be1b1e4de" +dependencies = [ + "idna_adapter", + "smallvec", + "utf8_iter", +] + +[[package]] +name = "idna_adapter" +version = "1.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cb68373c0d6620ef8105e855e7745e18b0d00d3bdb07fb532e434244cdb9a714" +dependencies = [ + "icu_normalizer", + "icu_properties", +] + +[[package]] +name = "indexmap" +version = "2.14.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d466e9454f08e4a911e14806c24e16fba1b4c121d1ea474396f396069cf949d9" +dependencies = [ + "equivalent", + "hashbrown 0.17.1", +] + +[[package]] +name = "inout" +version = "0.1.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "879f10e63c20629ecabbb64a8010319738c66a5cd0c29b02d63d272b03751d01" +dependencies = [ + "generic-array", +] + +[[package]] +name = "ipnet" +version = "2.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6a756c3fac73139e83f14c2d742155dd2b78d3ee56597b419a0579b7bdd6dd78" + +[[package]] +name = "is_terminal_polyfill" +version = "1.70.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a6cb138bb79a146c1bd460005623e142ef0181e3d0219cb493e02f7d08a35695" + +[[package]] +name = "itoa" +version = "1.0.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682" + +[[package]] +name = "js-sys" +version = "0.3.104" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0e0c1080212aad755ea003d18543e8768dd432c48819efd73a7bf1e39b7a5a3a" +dependencies = [ + "cfg-if", + "futures-util", + "wasm-bindgen", +] + +[[package]] +name = "kych" +version = "0.0.1" +dependencies = [ + "anyhow", + "askama", + "axum", + "base64", + "bcrypt", + "chrono", + "clap", + "mockito", + "rand 0.8.7", + "reqwest", + "rust-ini", + "serde", + "serde_json", + "sqlx", + "tokio", + "tower", + "tower-http", + "tracing", + "tracing-subscriber", + "urlencoding", + "uuid", +] + +[[package]] +name = "lazy_static" +version = "1.5.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe" +dependencies = [ + "spin", +] + +[[package]] +name = "libc" +version = "0.2.189" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" + +[[package]] +name = "libm" +version = "0.2.16" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b6d2cec3eae94f9f509c767b45932f1ada8350c4bdb85af2fcab4a3c14807981" + +[[package]] +name = "libredox" +version = "0.1.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2026a5056764a10b2bf5d56488cba40da507f5493a6a429340e2004d9ed085fa" +dependencies = [ + "bitflags", + "libc", + "plain", + "redox_syscall 0.9.1", +] + +[[package]] +name = "libsqlite3-sys" +version = "0.30.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2e99fb7a497b1e3339bc746195567ed8d3e24945ecd636e3619d20b9de9e9149" +dependencies = [ + "pkg-config", + "vcpkg", +] + +[[package]] +name = "linux-raw-sys" +version = "0.12.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "32a66949e030da00e8c7d4434b251670a91556f4144941d37452769c25d58a53" + +[[package]] +name = "litemap" +version = "0.8.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "92daf443525c4cce67b150400bc2316076100ce0b3686209eb8cf3c31612e6f0" + +[[package]] +name = "lock_api" +version = "0.4.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "224399e74b87b5f3557511d98dff8b14089b3dadafcab6bb93eab67d3aace965" +dependencies = [ + "scopeguard", +] + +[[package]] +name = "log" +version = "0.4.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0ceec5bc11778974d1bcb055b18002eba7f4b3518b6a0081b3af5f21666da9ad" + +[[package]] +name = "matchers" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d1525a2a28c7f4fa0fc98bb91ae755d1e2d1505079e05539e35bc876b5d65ae9" +dependencies = [ + "regex-automata", +] + +[[package]] +name = "matchit" +version = "0.8.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "47e1ffaa40ddd1f3ed91f717a33c8c0ee23fff369e3aa8772b9605cc1d22f4c3" + +[[package]] +name = "md-5" +version = "0.10.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d89e7ee0cfbedfc4da3340218492196241d89eefb6dab27de5df917a6d2e78cf" +dependencies = [ + "cfg-if", + "digest", +] + +[[package]] +name = "memchr" +version = "2.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cf8baf1c55e62ffcace7a9f06f4bd9cd3f0c4beb022d3b367256b91b87513d98" + +[[package]] +name = "mime" +version = "0.3.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6877bb514081ee2a7ff5ef9de3281f14a4dd4bceac4c09388074a6b5df8a139a" + +[[package]] +name = "mime_guess" +version = "2.0.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f7c44f8e672c00fe5308fa235f821cb4198414e1c77935c1ab6948d3fd78550e" +dependencies = [ + "mime", + "unicase", +] + +[[package]] +name = "minimal-lexical" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "68354c5c6bd36d73ff3feceb05efa59b6acb7626617f4962be322a825e61f79a" + +[[package]] +name = "mio" +version = "1.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "30d65c71f1ce40ab09135ce117d742b9f8a19ff91a41a8b57ed50bc2de59c427" +dependencies = [ + "libc", + "wasi", + "windows-sys 0.61.2", +] + +[[package]] +name = "mockito" +version = "1.7.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "90820618712cab19cfc46b274c6c22546a82affcb3c3bdf0f29e3db8e1bb92c0" +dependencies = [ + "assert-json-diff", + "bytes", + "colored", + "futures-core", + "http", + "http-body", + "http-body-util", + "hyper", + "hyper-util", + "log", + "pin-project-lite", + "rand 0.9.5", + "regex", + "serde_json", + "serde_urlencoded", + "similar", + "tokio", +] + +[[package]] +name = "native-tls" +version = "0.2.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "465500e14ea162429d264d44189adc38b199b62b1c21eea9f69e4b73cb03bbf2" +dependencies = [ + "libc", + "log", + "openssl", + "openssl-probe", + "openssl-sys", + "schannel", + "security-framework", + "security-framework-sys", + "tempfile", +] + +[[package]] +name = "nom" +version = "7.1.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d273983c5a657a70a3e8f2a01329822f3b8c8172b73826411a55751e404a0a4a" +dependencies = [ + "memchr", + "minimal-lexical", +] + +[[package]] +name = "nu-ansi-term" +version = "0.50.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7957b9740744892f114936ab4a57b3f487491bbeafaf8083688b16841a4240e5" +dependencies = [ + "windows-sys 0.61.2", +] + +[[package]] +name = "num-bigint-dig" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e661dda6640fad38e827a6d4a310ff4763082116fe217f279885c97f511bb0b7" +dependencies = [ + "lazy_static", + "libm", + "num-integer", + "num-iter", + "num-traits", + "rand 0.8.7", + "smallvec", + "zeroize", +] + +[[package]] +name = "num-conv" +version = "0.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "521739c6d2bac4aa25192232afe6841231376b2b26d4d9fae5ecf8ca5772e441" + +[[package]] +name = "num-integer" +version = "0.1.46" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7969661fd2958a5cb096e56c8e1ad0444ac2bbcd0061bd28660485a44879858f" +dependencies = [ + "num-traits", +] + +[[package]] +name = "num-iter" +version = "0.1.46" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c92800bd69a1eac91786bcfe9da64a897eb72911b8dc3095decbd07429e8048b" +dependencies = [ + "num-integer", + "num-traits", +] + +[[package]] +name = "num-traits" +version = "0.2.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841" +dependencies = [ + "autocfg", + "libm", +] + +[[package]] +name = "num_threads" +version = "0.1.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5c7398b9c8b70908f6371f47ed36737907c87c52af34c268fed0bf0ceb92ead9" +dependencies = [ + "libc", +] + +[[package]] +name = "once_cell" +version = "1.21.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50" + +[[package]] +name = "once_cell_polyfill" +version = "1.70.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "384b8ab6d37215f3c5301a95a4accb5d64aa607f1fcb26a11b5303878451b4fe" + +[[package]] +name = "openssl" +version = "0.10.81" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "77823a27f0babb03091cb9ed9ef80af3b39dbc82f97e8fa530374b7dafd87a45" +dependencies = [ + "bitflags", + "cfg-if", + "foreign-types", + "libc", + "openssl-macros", + "openssl-sys", +] + +[[package]] +name = "openssl-macros" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a948666b637a0f465e8564c73e89d4dde00d72d4d473cc972f390fc3dcee7d9c" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "openssl-probe" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7c87def4c32ab89d880effc9e097653c8da5d6ef28e6b539d313baaacfbafcbe" + +[[package]] +name = "openssl-sys" +version = "0.9.117" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b47e7e6bb2c38cd930d25a23b40fa52e068c10e85f3e03a7f5ba5aaca5713695" +dependencies = [ + "cc", + "libc", + "pkg-config", + "vcpkg", +] + +[[package]] +name = "ordered-multimap" +version = "0.7.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "49203cdcae0030493bad186b28da2fa25645fa276a51b6fec8010d281e02ef79" +dependencies = [ + "dlv-list", + "hashbrown 0.14.5", +] + +[[package]] +name = "parking" +version = "2.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f38d5652c16fde515bb1ecef450ab0f6a219d619a7274976324d5e377f7dceba" + +[[package]] +name = "parking_lot" +version = "0.12.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "93857453250e3077bd71ff98b6a65ea6621a19bb0f559a85248955ac12c45a1a" +dependencies = [ + "lock_api", + "parking_lot_core", +] + +[[package]] +name = "parking_lot_core" +version = "0.9.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2621685985a2ebf1c516881c026032ac7deafcda1a2c9b7850dc81e3dfcb64c1" +dependencies = [ + "cfg-if", + "libc", + "redox_syscall 0.5.18", + "smallvec", + "windows-link", +] + +[[package]] +name = "pem-rfc7468" +version = "0.7.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "88b39c9bfcfc231068454382784bb460aae594343fb030d46e9f50a645418412" +dependencies = [ + "base64ct", +] + +[[package]] +name = "percent-encoding" +version = "2.3.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220" + +[[package]] +name = "pin-project-lite" +version = "0.2.17" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd" + +[[package]] +name = "pkcs1" +version = "0.7.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c8ffb9f10fa047879315e6625af03c164b16962a5368d724ed16323b68ace47f" +dependencies = [ + "der", + "pkcs8", + "spki", +] + +[[package]] +name = "pkcs8" +version = "0.10.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f950b2377845cebe5cf8b5165cb3cc1a5e0fa5cfa3e1f7f55707d8fd82e0a7b7" +dependencies = [ + "der", + "spki", +] + +[[package]] +name = "pkg-config" +version = "0.3.33" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "19f132c84eca552bf34cab8ec81f1c1dcc229b811638f9d283dceabe58c5569e" + +[[package]] +name = "plain" +version = "0.2.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b4596b6d070b27117e987119b4dac604f3c58cfb0b191112e24771b2faeac1a6" + +[[package]] +name = "potential_utf" +version = "0.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0103b1cef7ec0cf76490e969665504990193874ea05c85ff9bab8b911d0a0564" +dependencies = [ + "zerovec", +] + +[[package]] +name = "powerfmt" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "439ee305def115ba05938db6eb1644ff94165c5ab5e9420d1c1bcedbba909391" + +[[package]] +name = "ppv-lite86" +version = "0.2.21" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "85eae3c4ed2f50dcfe72643da4befc30deadb458a9b590d720cde2f2b1e97da9" +dependencies = [ + "zerocopy", +] + +[[package]] +name = "proc-macro2" +version = "1.0.107" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "985e7ec9bb745e6ce6535b544d84d6cd6f7ad8bd711c398938ae983b91a766d9" +dependencies = [ + "unicode-ident", +] + +[[package]] +name = "quote" +version = "1.0.47" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" +dependencies = [ + "proc-macro2", +] + +[[package]] +name = "r-efi" +version = "5.3.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "69cdb34c158ceb288df11e18b4bd39de994f6657d83847bdffdbd7f346754b0f" + +[[package]] +name = "r-efi" +version = "6.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" + +[[package]] +name = "rand" +version = "0.8.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "22f6172bdec972074665ed81ed53b71da00bfc44b65a753cfde883ec4c702a1a" +dependencies = [ + "libc", + "rand_chacha 0.3.1", + "rand_core 0.6.4", +] + +[[package]] +name = "rand" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b9ef1d0d795eb7d84685bca4f72f3649f064e6641543d3a8c415898726a57b41" +dependencies = [ + "rand_chacha 0.9.0", + "rand_core 0.9.5", +] + +[[package]] +name = "rand_chacha" +version = "0.3.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88" +dependencies = [ + "ppv-lite86", + "rand_core 0.6.4", +] + +[[package]] +name = "rand_chacha" +version = "0.9.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d3022b5f1df60f26e1ffddd6c66e8aa15de382ae63b3a0c1bfc0e4d3e3f325cb" +dependencies = [ + "ppv-lite86", + "rand_core 0.9.5", +] + +[[package]] +name = "rand_core" +version = "0.6.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c" +dependencies = [ + "getrandom 0.2.17", +] + +[[package]] +name = "rand_core" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "76afc826de14238e6e8c374ddcc1fa19e374fd8dd986b0d2af0d02377261d83c" +dependencies = [ + "getrandom 0.3.4", +] + +[[package]] +name = "redox_syscall" +version = "0.5.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed2bf2547551a7053d6fdfafda3f938979645c44812fbfcda098faae3f1a362d" +dependencies = [ + "bitflags", +] + +[[package]] +name = "redox_syscall" +version = "0.9.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "07507be7b4a5f9f26eeb41eeaebb1f5a7ff29dfb29739facc21d35bf8b11c21e" +dependencies = [ + "bitflags", +] + +[[package]] +name = "regex" +version = "1.13.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f020237b6c8eed93db2e2cb53c00c60a8e1bc73da7d073199a1180401450218d" +dependencies = [ + "aho-corasick", + "memchr", + "regex-automata", + "regex-syntax", +] + +[[package]] +name = "regex-automata" +version = "0.4.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ad8553b9b26413251cbf30e620595c7a41b3887f03da04579c0e6b0d6a06b4b2" +dependencies = [ + "aho-corasick", + "memchr", + "regex-syntax", +] + +[[package]] +name = "regex-syntax" +version = "0.8.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d6f6ff9a378485b298a5286656da665ba74413d36db0979633275d2e708145d4" + +[[package]] +name = "reqwest" +version = "0.12.28" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "eddd3ca559203180a307f12d114c268abf583f59b03cb906fd0b3ff8646c1147" +dependencies = [ + "base64", + "bytes", + "encoding_rs", + "futures-core", + "h2", + "http", + "http-body", + "http-body-util", + "hyper", + "hyper-rustls", + "hyper-tls", + "hyper-util", + "js-sys", + "log", + "mime", + "native-tls", + "percent-encoding", + "pin-project-lite", + "rustls-pki-types", + "serde", + "serde_json", + "serde_urlencoded", + "sync_wrapper", + "tokio", + "tokio-native-tls", + "tower", + "tower-http", + "tower-service", + "url", + "wasm-bindgen", + "wasm-bindgen-futures", + "web-sys", +] + +[[package]] +name = "ring" +version = "0.17.14" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a4689e6c2294d81e88dc6261c768b63bc4fcdb852be6d1352498b114f61383b7" +dependencies = [ + "cc", + "cfg-if", + "getrandom 0.2.17", + "libc", + "untrusted", + "windows-sys 0.52.0", +] + +[[package]] +name = "rsa" +version = "0.9.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b8573f03f5883dcaebdfcf4725caa1ecb9c15b2ef50c43a07b816e06799bb12d" +dependencies = [ + "const-oid", + "digest", + "num-bigint-dig", + "num-integer", + "num-traits", + "pkcs1", + "pkcs8", + "rand_core 0.6.4", + "signature", + "spki", + "subtle", + "zeroize", +] + +[[package]] +name = "rust-ini" +version = "0.21.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "796e8d2b6696392a43bea58116b667fb4c29727dc5abd27d6acf338bb4f688c7" +dependencies = [ + "cfg-if", + "ordered-multimap", +] + +[[package]] +name = "rustix" +version = "1.1.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b6fe4565b9518b83ef4f91bb47ce29620ca828bd32cb7e408f0062e9930ba190" +dependencies = [ + "bitflags", + "errno", + "libc", + "linux-raw-sys", + "windows-sys 0.61.2", +] + +[[package]] +name = "rustls" +version = "0.23.43" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06" +dependencies = [ + "once_cell", + "rustls-pki-types", + "rustls-webpki", + "subtle", + "zeroize", +] + +[[package]] +name = "rustls-pki-types" +version = "1.15.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2f4925028c7eb5d1fcdaf196971378ed9d2c1c4efc7dc5d011256f76c99c0a96" +dependencies = [ + "zeroize", +] + +[[package]] +name = "rustls-webpki" +version = "0.103.13" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e" +dependencies = [ + "ring", + "rustls-pki-types", + "untrusted", +] + +[[package]] +name = "rustversion" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cf54715a573b99ac80df0bc206da022bcd442c974952c7b9720069370852e21f" + +[[package]] +name = "ryu" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9774ba4a74de5f7b1c1451ed6cd5285a32eddb5cccb8cc655a4e50009e06477f" + +[[package]] +name = "schannel" +version = "0.1.29" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "91c1b7e4904c873ef0710c1f407dde2e6287de2bebc1bbbf7d430bb7cbffd939" +dependencies = [ + "windows-sys 0.61.2", +] + +[[package]] +name = "scopeguard" +version = "1.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "94143f37725109f92c262ed2cf5e59bce7498c01bcc1502d7b9afe439a4e9f49" + +[[package]] +name = "security-framework" +version = "3.7.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b7f4bc775c73d9a02cde8bf7b2ec4c9d12743edf609006c7facc23998404cd1d" +dependencies = [ + "bitflags", + "core-foundation 0.10.1", + "core-foundation-sys", + "libc", + "security-framework-sys", +] + +[[package]] +name = "security-framework-sys" +version = "2.17.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6ce2691df843ecc5d231c0b14ece2acc3efb62c0a398c7e1d875f3983ce020e3" +dependencies = [ + "core-foundation-sys", + "libc", +] + +[[package]] +name = "serde" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4148590afebada386688f18773da617792bf2ef03ffc1e4cbd2b1d45b023e0ba" +dependencies = [ + "serde_core", + "serde_derive", +] + +[[package]] +name = "serde_core" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "67dca2c9c51e58a4791a4b1ed58308b39c64224d349a935ab5039aa360942a48" +dependencies = [ + "serde_derive", +] + +[[package]] +name = "serde_derive" +version = "1.0.229" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e7a5d71263a5a7d47b41f6b3f06ba276f10cc18b0931f1799f710578e2309348" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.3", +] + +[[package]] +name = "serde_json" +version = "1.0.151" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c841b55ecdae098c80dcae9cf767f6f8a0c2cdb3416bbef72181df4d0fe73f14" +dependencies = [ + "itoa", + "memchr", + "serde", + "serde_core", + "zmij", +] + +[[package]] +name = "serde_path_to_error" +version = "0.1.20" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "10a9ff822e371bb5403e391ecd83e182e0e77ba7f6fe0160b795797109d1b457" +dependencies = [ + "itoa", + "serde", + "serde_core", +] + +[[package]] +name = "serde_urlencoded" +version = "0.7.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d3491c14715ca2294c4d6a88f15e84739788c1d030eed8c110436aafdaa2f3fd" +dependencies = [ + "form_urlencoded", + "itoa", + "ryu", + "serde", +] + +[[package]] +name = "sha1" +version = "0.10.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a978451301f4db1d02937a4ab3ccce137717b81826e79b7d49ffe3244a13c3b8" +dependencies = [ + "cfg-if", + "cpufeatures", + "digest", +] + +[[package]] +name = "sha2" +version = "0.10.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a7507d819769d01a365ab707794a4084392c824f54a7a6a7862f8c3d0892b283" +dependencies = [ + "cfg-if", + "cpufeatures", + "digest", +] + +[[package]] +name = "sharded-slab" +version = "0.1.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f40ca3c46823713e0d4209592e8d6e826aa57e928f09752619fc696c499637f6" +dependencies = [ + "lazy_static", +] + +[[package]] +name = "shlex" +version = "2.0.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f8fadd59c855ef2080decdef8ff161eb6661b86933c9d82e5ba29dc602a55aba" + +[[package]] +name = "signal-hook-registry" +version = "1.4.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c4db69cba1110affc0e9f7bcd48bbf87b3f4fc7c61fc9155afd4c469eb3d6c1b" +dependencies = [ + "errno", + "libc", +] + +[[package]] +name = "signature" +version = "2.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "77549399552de45a898a580c1b41d445bf730df867cc44e6c0233bbc4b8329de" +dependencies = [ + "digest", + "rand_core 0.6.4", +] + +[[package]] +name = "similar" +version = "2.7.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bbbb5d9659141646ae647b42fe094daf6c6192d1620870b449d9557f748b2daa" + +[[package]] +name = "slab" +version = "0.4.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0c790de23124f9ab44544d7ac05d60440adc586479ce501c1d6d7da3cd8c9cf5" + +[[package]] +name = "smallvec" +version = "1.15.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90" +dependencies = [ + "serde", +] + +[[package]] +name = "socket2" +version = "0.6.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c3d1e2c7f27f8d4cb10542a02c49005dbd6e93095799d6f3be745fae9f8fedd4" +dependencies = [ + "libc", + "windows-sys 0.61.2", +] + +[[package]] +name = "spin" +version = "0.9.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3763264f6b73151db08c50ff20d7d8a0b8796e021cdea7ceedad07b80155fa0e" +dependencies = [ + "lock_api", +] + +[[package]] +name = "spki" +version = "0.7.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "d91ed6c858b01f942cd56b37a94b3e0a1798290327d1236e4d9cf4eaca44d29d" +dependencies = [ + "base64ct", + "der", +] + +[[package]] +name = "sqlx" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1fefb893899429669dcdd979aff487bd78f4064e5e7907e4269081e0ef7d97dc" +dependencies = [ + "sqlx-core", + "sqlx-macros", + "sqlx-mysql", + "sqlx-postgres", + "sqlx-sqlite", +] + +[[package]] +name = "sqlx-core" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ee6798b1838b6a0f69c007c133b8df5866302197e404e8b6ee8ed3e3a5e68dc6" +dependencies = [ + "base64", + "bytes", + "chrono", + "crc", + "crossbeam-queue", + "either", + "event-listener", + "futures-core", + "futures-intrusive", + "futures-io", + "futures-util", + "hashbrown 0.15.5", + "hashlink", + "indexmap", + "log", + "memchr", + "once_cell", + "percent-encoding", + "serde", + "serde_json", + "sha2", + "smallvec", + "thiserror", + "tokio", + "tokio-stream", + "tracing", + "url", + "uuid", +] + +[[package]] +name = "sqlx-macros" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a2d452988ccaacfbf5e0bdbc348fb91d7c8af5bee192173ac3636b5fb6e6715d" +dependencies = [ + "proc-macro2", + "quote", + "sqlx-core", + "sqlx-macros-core", + "syn 2.0.119", +] + +[[package]] +name = "sqlx-macros-core" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "19a9c1841124ac5a61741f96e1d9e2ec77424bf323962dd894bdb93f37d5219b" +dependencies = [ + "dotenvy", + "either", + "heck", + "hex", + "once_cell", + "proc-macro2", + "quote", + "serde", + "serde_json", + "sha2", + "sqlx-core", + "sqlx-mysql", + "sqlx-postgres", + "sqlx-sqlite", + "syn 2.0.119", + "tokio", + "url", +] + +[[package]] +name = "sqlx-mysql" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "aa003f0038df784eb8fecbbac13affe3da23b45194bd57dba231c8f48199c526" +dependencies = [ + "atoi", + "base64", + "bitflags", + "byteorder", + "bytes", + "chrono", + "crc", + "digest", + "dotenvy", + "either", + "futures-channel", + "futures-core", + "futures-io", + "futures-util", + "generic-array", + "hex", + "hkdf", + "hmac", + "itoa", + "log", + "md-5", + "memchr", + "once_cell", + "percent-encoding", + "rand 0.8.7", + "rsa", + "serde", + "sha1", + "sha2", + "smallvec", + "sqlx-core", + "stringprep", + "thiserror", + "tracing", + "uuid", + "whoami", +] + +[[package]] +name = "sqlx-postgres" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "db58fcd5a53cf07c184b154801ff91347e4c30d17a3562a635ff028ad5deda46" +dependencies = [ + "atoi", + "base64", + "bitflags", + "byteorder", + "chrono", + "crc", + "dotenvy", + "etcetera", + "futures-channel", + "futures-core", + "futures-util", + "hex", + "hkdf", + "hmac", + "home", + "itoa", + "log", + "md-5", + "memchr", + "once_cell", + "rand 0.8.7", + "serde", + "serde_json", + "sha2", + "smallvec", + "sqlx-core", + "stringprep", + "thiserror", + "tracing", + "uuid", + "whoami", +] + +[[package]] +name = "sqlx-sqlite" +version = "0.8.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c2d12fe70b2c1b4401038055f90f151b78208de1f9f89a7dbfd41587a10c3eea" +dependencies = [ + "atoi", + "chrono", + "flume", + "futures-channel", + "futures-core", + "futures-executor", + "futures-intrusive", + "futures-util", + "libsqlite3-sys", + "log", + "percent-encoding", + "serde", + "serde_urlencoded", + "sqlx-core", + "thiserror", + "tracing", + "url", + "uuid", +] + +[[package]] +name = "stable_deref_trait" +version = "1.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" + +[[package]] +name = "stringprep" +version = "0.1.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7b4df3d392d81bd458a8a621b8bffbd2302a12ffe288a9d931670948749463b1" +dependencies = [ + "unicode-bidi", + "unicode-normalization", + "unicode-properties", +] + +[[package]] +name = "strsim" +version = "0.11.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f" + +[[package]] +name = "subtle" +version = "2.6.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "13c2bddecc57b384dee18652358fb23172facb8a2c51ccc10d74c157bdea3292" + +[[package]] +name = "syn" +version = "2.0.119" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "872831b642d1a07999a962a351ed35b955ea2cfc8f3862091e2a240a84f17297" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "syn" +version = "3.0.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "53e9bae58849f64dfa4f5d5ae372c8341f7305f82a3868709269343628b659a3" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "sync_wrapper" +version = "1.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0bf256ce5efdfa370213c1dabab5935a12e49f2c58d15e9eac2870d3b4f27263" +dependencies = [ + "futures-core", +] + +[[package]] +name = "synstructure" +version = "0.13.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "728a70f3dbaf5bab7f0c4b1ac8d7ae5ea60a4b5549c8a5914361c99147a709d2" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "system-configuration" +version = "0.7.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a13f3d0daba03132c0aa9767f98351b3488edc2c100cda2d2ec2b04f3d8d3c8b" +dependencies = [ + "bitflags", + "core-foundation 0.9.4", + "system-configuration-sys", +] + +[[package]] +name = "system-configuration-sys" +version = "0.6.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8e1d1b10ced5ca923a1fcb8d03e96b8d3268065d724548c0211415ff6ac6bac4" +dependencies = [ + "core-foundation-sys", + "libc", +] + +[[package]] +name = "tempfile" +version = "3.27.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "32497e9a4c7b38532efcdebeef879707aa9f794296a4f0244f6f69e9bc8574bd" +dependencies = [ + "fastrand", + "getrandom 0.4.3", + "once_cell", + "rustix", + "windows-sys 0.61.2", +] + +[[package]] +name = "thiserror" +version = "2.0.20" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ec86235f5fcc2a73650310756d2ac5b138a5780bbbdfae3eeccec992c435ba4f" +dependencies = [ + "thiserror-impl", +] + +[[package]] +name = "thiserror-impl" +version = "2.0.20" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bc04cd3e1236dd4a98afca4569f2deb3f120e5422a4023be2cb683f8486292af" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.3", +] + +[[package]] +name = "thread_local" +version = "1.1.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1ad99c4c6d32803332c548b1af0540b357b3f5fc0be8f6c6bfe8b2e6ae784070" +dependencies = [ + "cfg-if", +] + +[[package]] +name = "time" +version = "0.3.55" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cdb87b95ec50ddfa440816d227a17b2ccbdda963a316a727fda0fc4334f7d134" +dependencies = [ + "deranged", + "libc", + "num-conv", + "num_threads", + "powerfmt", + "serde_core", + "time-core", + "time-macros", +] + +[[package]] +name = "time-core" +version = "0.1.9" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9e1c906769ad99c88eaa54e728060edef082f8e358ff32030cb7c7d315e81109" + +[[package]] +name = "time-macros" +version = "0.2.32" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7e689342a48d2ea927c87ea50cabf8594854bf940e9310208848d680d668ed85" +dependencies = [ + "num-conv", + "time-core", +] + +[[package]] +name = "tiny-keccak" +version = "2.0.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2c9d3793400a45f954c52e73d068316d76b6f4e36977e3fcebb13a2721e80237" +dependencies = [ + "crunchy", +] + +[[package]] +name = "tinystr" +version = "0.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c8323304221c2a851516f22236c5722a72eaa19749016521d6dff0824447d96d" +dependencies = [ + "displaydoc", + "zerovec", +] + +[[package]] +name = "tinyvec" +version = "1.12.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bb4ebadaa0af04fab11ae01eb5f9fdb5f9c5b875506e210e71c07873528baa7f" +dependencies = [ + "tinyvec_macros", +] + +[[package]] +name = "tinyvec_macros" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20" + +[[package]] +name = "tokio" +version = "1.53.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "202caea871b69668250d242070849eb495be178ed697a3e98aebce5bc81a0bed" +dependencies = [ + "bytes", + "libc", + "mio", + "parking_lot", + "pin-project-lite", + "signal-hook-registry", + "socket2", + "tokio-macros", + "windows-sys 0.61.2", +] + +[[package]] +name = "tokio-macros" +version = "2.7.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "78773a2a397f451582ce068015985c33193cf6dea8b74d2a639fe457b2f07b0e" +dependencies = [ + "proc-macro2", + "quote", + "syn 3.0.3", +] + +[[package]] +name = "tokio-native-tls" +version = "0.3.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bbae76ab933c85776efabc971569dd6119c580d8f5d448769dec1764bf796ef2" +dependencies = [ + "native-tls", + "tokio", +] + +[[package]] +name = "tokio-rustls" +version = "0.26.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1729aa945f29d91ba541258c8df89027d5792d85a8841fb65e8bf0f4ede4ef61" +dependencies = [ + "rustls", + "tokio", +] + +[[package]] +name = "tokio-stream" +version = "0.1.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a3d06f0b082ba57c26b79407372e57cf2a1e28124f78e9479fe80322cf53420b" +dependencies = [ + "futures-core", + "pin-project-lite", + "tokio", +] + +[[package]] +name = "tokio-util" +version = "0.7.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "494815d09bf52b5548659851081238f0ca39ff638363907596da739561c62c52" +dependencies = [ + "bytes", + "futures-core", + "futures-sink", + "libc", + "pin-project-lite", + "tokio", +] + +[[package]] +name = "tower" +version = "0.5.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ebe5ef63511595f1344e2d5cfa636d973292adc0eec1f0ad45fae9f0851ab1d4" +dependencies = [ + "futures-core", + "futures-util", + "pin-project-lite", + "sync_wrapper", + "tokio", + "tower-layer", + "tower-service", + "tracing", +] + +[[package]] +name = "tower-http" +version = "0.6.11" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4cfcf7e2740e6fc6d4d688b4ef00650406bb94adf4731e43c096c3a19fe40840" +dependencies = [ + "bitflags", + "bytes", + "futures-core", + "futures-util", + "http", + "http-body", + "http-body-util", + "http-range-header", + "httpdate", + "mime", + "mime_guess", + "percent-encoding", + "pin-project-lite", + "tokio", + "tokio-util", + "tower", + "tower-layer", + "tower-service", + "tracing", + "url", +] + +[[package]] +name = "tower-layer" +version = "0.3.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "121c2a6cda46980bb0fcd1647ffaf6cd3fc79a013de288782836f6df9c48780e" + +[[package]] +name = "tower-service" +version = "0.3.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8df9b6e13f2d32c91b9bd719c00d1958837bc7dec474d94952798cc8e69eeec3" + +[[package]] +name = "tracing" +version = "0.1.44" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "63e71662fa4b2a2c3a26f570f037eb95bb1f85397f3cd8076caed2f026a6d100" +dependencies = [ + "log", + "pin-project-lite", + "tracing-attributes", + "tracing-core", +] + +[[package]] +name = "tracing-attributes" +version = "0.1.31" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7490cfa5ec963746568740651ac6781f701c9c5ea257c58e057f3ba8cf69e8da" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "tracing-core" +version = "0.1.36" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "db97caf9d906fbde555dd62fa95ddba9eecfd14cb388e4f491a66d74cd5fb79a" +dependencies = [ + "once_cell", + "valuable", +] + +[[package]] +name = "tracing-log" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ee855f1f400bd0e5c02d150ae5de3840039a3f54b025156404e34c23c03f47c3" +dependencies = [ + "log", + "once_cell", + "tracing-core", +] + +[[package]] +name = "tracing-subscriber" +version = "0.3.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "cb7f578e5945fb242538965c2d0b04418d38ec25c79d160cd279bf0731c8d319" +dependencies = [ + "matchers", + "nu-ansi-term", + "once_cell", + "regex-automata", + "sharded-slab", + "smallvec", + "thread_local", + "time", + "tracing", + "tracing-core", + "tracing-log", +] + +[[package]] +name = "try-lock" +version = "0.2.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e421abadd41a4225275504ea4d6566923418b7f05506fbc9c0fe86ba7396114b" + +[[package]] +name = "typenum" +version = "1.20.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b6f5e870be6c3b371b77fe0ee0bafb859fa4964b4404c27de1d380043c4dda20" + +[[package]] +name = "unicase" +version = "2.9.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "dbc4bc3a9f746d862c45cb89d705aa10f187bb96c76001afab07a0d35ce60142" + +[[package]] +name = "unicode-bidi" +version = "0.3.18" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5c1cb5db39152898a79168971543b1cb5020dff7fe43c8dc468b0885f5e29df5" + +[[package]] +name = "unicode-ident" +version = "1.0.24" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75" + +[[package]] +name = "unicode-normalization" +version = "0.1.25" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5fd4f6878c9cb28d874b009da9e8d183b5abc80117c40bbd187a1fde336be6e8" +dependencies = [ + "tinyvec", +] + +[[package]] +name = "unicode-properties" +version = "0.1.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7df058c713841ad818f1dc5d3fd88063241cc61f49f5fbea4b951e8cf5a8d71d" + +[[package]] +name = "untrusted" +version = "0.9.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8ecb6da28b8a351d773b68d5825ac39017e680750f980f3a1a85cd8dd28a47c1" + +[[package]] +name = "url" +version = "2.5.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ff67a8a4397373c3ef660812acab3268222035010ab8680ec4215f38ba3d0eed" +dependencies = [ + "form_urlencoded", + "idna", + "percent-encoding", + "serde", +] + +[[package]] +name = "urlencoding" +version = "2.1.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "daf8dba3b7eb870caf1ddeed7bc9d2a049f3cfdfae7cb521b087cc33ae4c49da" + +[[package]] +name = "utf8_iter" +version = "1.0.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b6c140620e7ffbb22c2dee59cafe6084a59b5ffc27a8859a5f0d494b5d52b6be" + +[[package]] +name = "utf8parse" +version = "0.2.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "06abde3611657adf66d383f00b093d7faecc7fa57071cce2578660c9f1010821" + +[[package]] +name = "uuid" +version = "1.24.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bf3923a6f5c4c6382e0b653c4117f48d631ea17f38ed86e2a828e6f7412f5239" +dependencies = [ + "getrandom 0.4.3", + "js-sys", + "serde_core", + "wasm-bindgen", +] + +[[package]] +name = "valuable" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ba73ea9cf16a25df0c8caa16c51acb937d5712a8429db78a3ee29d5dcacd3a65" + +[[package]] +name = "vcpkg" +version = "0.2.15" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "accd4ea62f7bb7a82fe23066fb0957d48ef677f6eeb8215f372f52e48bb32426" + +[[package]] +name = "version_check" +version = "0.9.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0b928f33d975fc6ad9f86c8f283853ad26bdd5b10b7f1542aa2fa15e2289105a" + +[[package]] +name = "want" +version = "0.3.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "bfa7760aed19e106de2c7c0b581b509f2f25d3dacaf737cb82ac61bc6d760b0e" +dependencies = [ + "try-lock", +] + +[[package]] +name = "wasi" +version = "0.11.1+wasi-snapshot-preview1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ccf3ec651a847eb01de73ccad15eb7d99f80485de043efb2f370cd654f4ea44b" + +[[package]] +name = "wasip2" +version = "1.0.4+wasi-0.2.12" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b67efb37e106e55ce722a510d6b5f9c17f083e5fc79afc2badeb12cc313d9487" +dependencies = [ + "wit-bindgen", +] + +[[package]] +name = "wasite" +version = "0.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b8dad83b4f25e74f184f64c43b150b91efe7647395b42289f38e50566d82855b" + +[[package]] +name = "wasm-bindgen" +version = "0.2.127" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1b70935747edd64d89de3efa29d73789b806c15798f8e7dca4d8ac356b50ce70" +dependencies = [ + "cfg-if", + "once_cell", + "rustversion", + "wasm-bindgen-macro", + "wasm-bindgen-shared", +] + +[[package]] +name = "wasm-bindgen-futures" +version = "0.4.77" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "6b7777d5cc23d0e91404e53ce2d5e8ec7acae3026b16233dba62cd3246457950" +dependencies = [ + "js-sys", + "wasm-bindgen", +] + +[[package]] +name = "wasm-bindgen-macro" +version = "0.2.127" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "77775f8f3f7217702089053b94958f8f54061a3f663417df76e19cbdcca29bc1" +dependencies = [ + "quote", + "wasm-bindgen-macro-support", +] + +[[package]] +name = "wasm-bindgen-macro-support" +version = "0.2.127" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e11d33f857dc2fb11b8bc75aee111aa9cbeb12cd9f25efd3d4c2a3dd4e235284" +dependencies = [ + "bumpalo", + "proc-macro2", + "quote", + "syn 2.0.119", + "wasm-bindgen-shared", +] + +[[package]] +name = "wasm-bindgen-shared" +version = "0.2.127" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7ef64dbcc55df09c7e5a46182d181c2cfa3e925f3da937ea764728b4bbb9dcbf" +dependencies = [ + "unicode-ident", +] + +[[package]] +name = "web-sys" +version = "0.3.104" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c435338968042f4f59a557f690a253676d47ce13ceb55d70100e7facf6620a30" +dependencies = [ + "js-sys", + "wasm-bindgen", +] + +[[package]] +name = "whoami" +version = "1.6.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5d4a4db5077702ca3015d3d02d74974948aba2ad9e12ab7df718ee64ccd7e97d" +dependencies = [ + "libredox", + "wasite", +] + +[[package]] +name = "windows-core" +version = "0.62.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b8e83a14d34d0623b51dce9581199302a221863196a1dde71a7663a4c2be9deb" +dependencies = [ + "windows-implement", + "windows-interface", + "windows-link", + "windows-result", + "windows-strings", +] + +[[package]] +name = "windows-implement" +version = "0.60.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "053e2e040ab57b9dc951b72c264860db7eb3b0200ba345b4e4c3b14f67855ddf" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "windows-interface" +version = "0.59.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3f316c4a2570ba26bbec722032c4099d8c8bc095efccdc15688708623367e358" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "windows-link" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5" + +[[package]] +name = "windows-registry" +version = "0.6.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "02752bf7fbdcce7f2a27a742f798510f3e5ad88dbe84871e5168e2120c3d5720" +dependencies = [ + "windows-link", + "windows-result", + "windows-strings", +] + +[[package]] +name = "windows-result" +version = "0.4.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7781fa89eaf60850ac3d2da7af8e5242a5ea78d1a11c49bf2910bb5a73853eb5" +dependencies = [ + "windows-link", +] + +[[package]] +name = "windows-strings" +version = "0.5.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7837d08f69c77cf6b07689544538e017c1bfcf57e34b4c0ff58e6c2cd3b37091" +dependencies = [ + "windows-link", +] + +[[package]] +name = "windows-sys" +version = "0.48.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "677d2418bec65e3338edb076e806bc1ec15693c5d0104683f2efe857f61056a9" +dependencies = [ + "windows-targets 0.48.5", +] + +[[package]] +name = "windows-sys" +version = "0.52.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d" +dependencies = [ + "windows-targets 0.52.6", +] + +[[package]] +name = "windows-sys" +version = "0.61.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ae137229bcbd6cdf0f7b80a31df61766145077ddf49416a728b02cb3921ff3fc" +dependencies = [ + "windows-link", +] + +[[package]] +name = "windows-targets" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9a2fa6e2155d7247be68c096456083145c183cbbbc2764150dda45a87197940c" +dependencies = [ + "windows_aarch64_gnullvm 0.48.5", + "windows_aarch64_msvc 0.48.5", + "windows_i686_gnu 0.48.5", + "windows_i686_msvc 0.48.5", + "windows_x86_64_gnu 0.48.5", + "windows_x86_64_gnullvm 0.48.5", + "windows_x86_64_msvc 0.48.5", +] + +[[package]] +name = "windows-targets" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973" +dependencies = [ + "windows_aarch64_gnullvm 0.52.6", + "windows_aarch64_msvc 0.52.6", + "windows_i686_gnu 0.52.6", + "windows_i686_gnullvm", + "windows_i686_msvc 0.52.6", + "windows_x86_64_gnu 0.52.6", + "windows_x86_64_gnullvm 0.52.6", + "windows_x86_64_msvc 0.52.6", +] + +[[package]] +name = "windows_aarch64_gnullvm" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2b38e32f0abccf9987a4e3079dfb67dcd799fb61361e53e2882c3cbaf0d905d8" + +[[package]] +name = "windows_aarch64_gnullvm" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3" + +[[package]] +name = "windows_aarch64_msvc" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "dc35310971f3b2dbbf3f0690a219f40e2d9afcf64f9ab7cc1be722937c26b4bc" + +[[package]] +name = "windows_aarch64_msvc" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469" + +[[package]] +name = "windows_i686_gnu" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a75915e7def60c94dcef72200b9a8e58e5091744960da64ec734a6c6e9b3743e" + +[[package]] +name = "windows_i686_gnu" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8e9b5ad5ab802e97eb8e295ac6720e509ee4c243f69d781394014ebfe8bbfa0b" + +[[package]] +name = "windows_i686_gnullvm" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66" + +[[package]] +name = "windows_i686_msvc" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "8f55c233f70c4b27f66c523580f78f1004e8b5a8b659e05a4eb49d4166cca406" + +[[package]] +name = "windows_i686_msvc" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66" + +[[package]] +name = "windows_x86_64_gnu" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "53d40abd2583d23e4718fddf1ebec84dbff8381c07cae67ff7768bbf19c6718e" + +[[package]] +name = "windows_x86_64_gnu" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78" + +[[package]] +name = "windows_x86_64_gnullvm" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0b7b52767868a23d5bab768e390dc5f5c55825b6d30b86c844ff2dc7414044cc" + +[[package]] +name = "windows_x86_64_gnullvm" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d" + +[[package]] +name = "windows_x86_64_msvc" +version = "0.48.5" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ed94fce61571a4006852b7389a063ab983c02eb1bb37b47f8272ce92d06d9538" + +[[package]] +name = "windows_x86_64_msvc" +version = "0.52.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "589f6da84c646204747d1270a2a5661ea66ed1cced2631d546fdfb155959f9ec" + +[[package]] +name = "wit-bindgen" +version = "0.57.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1ebf944e87a7c253233ad6766e082e3cd714b5d03812acc24c318f549614536e" + +[[package]] +name = "writeable" +version = "0.6.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1ffae5123b2d3fc086436f8834ae3ab053a283cfac8fe0a0b8eaae044768a4c4" + +[[package]] +name = "yoke" +version = "0.8.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "709fe23a0424b6a435d82152b1bd3fdfb0833487d5fa90d05d42762a9891fef5" +dependencies = [ + "stable_deref_trait", + "yoke-derive", + "zerofrom", +] + +[[package]] +name = "yoke-derive" +version = "0.8.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "de844c262c8848816172cef550288e7dc6c7b7814b4ee56b3e1553f275f1858e" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", + "synstructure", +] + +[[package]] +name = "zerocopy" +version = "0.8.56" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "556764e583adb45a9f8d413c2a147fa7e8d821e48e12b14fd560b607998b75eb" +dependencies = [ + "zerocopy-derive", +] + +[[package]] +name = "zerocopy-derive" +version = "0.8.56" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f2ab42fc20575779bd240faa45f94a74256f755c0fa9e89f0ede20d91d0cdfc1" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "zerofrom" +version = "0.1.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0ec05a11813ea801ff6d75110ad09cd0824ddba17dfe17128ea0d5f68e6c5272" +dependencies = [ + "zerofrom-derive", +] + +[[package]] +name = "zerofrom-derive" +version = "0.1.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "11532158c46691caf0f2593ea8358fed6bbf68a0315e80aae9bd41fbade684a1" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", + "synstructure", +] + +[[package]] +name = "zeroize" +version = "1.9.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e" + +[[package]] +name = "zerotrie" +version = "0.2.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "0f9152d31db0792fa83f70fb2f83148effb5c1f5b8c7686c3459e361d9bc20bf" +dependencies = [ + "displaydoc", + "yoke", + "zerofrom", +] + +[[package]] +name = "zerovec" +version = "0.11.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "90f911cbc359ab6af17377d242225f4d75119aec87ea711a880987b18cd7b239" +dependencies = [ + "yoke", + "zerofrom", + "zerovec-derive", +] + +[[package]] +name = "zerovec-derive" +version = "0.11.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "625dc425cab0dca6dc3c3319506e6593dcb08a9f387ea3b284dbd52a92c40555" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.119", +] + +[[package]] +name = "zmij" +version = "1.0.23" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "29666d0abbfad1e3dc4dcf6144730dd3a3ab225bbbdac83319345b1b44ccfc1b" diff --git a/scripts/get_version.sh b/scripts/get_version.sh @@ -0,0 +1,33 @@ +#!/bin/sh +# Gets the version number from git, or from the contents of .version +VERSION= +if test -f ".version"; then + VERSION=$(cat .version) +fi +if [ -e ./.git ]; then + # With sparse checkouts, we have a .git dir but possibly no tags + gitver=$(git describe --tags 2>/dev/null || echo no-git-version) + if test "$gitver" != "no-git-version"; then + VERSION=${gitver#v} + echo "$VERSION" > .version + fi +fi +if test "x$VERSION" = "x"; then + VERSION="unknown" +fi +case $1 in +"--major") + echo "$VERSION" | sed 's/\(^[0-9]*\)\.\([0-9]*\)\.\([0-9]*\).*/\1/g' + ;; +"--minor") + echo "$VERSION" | sed 's/\(^[0-9]*\)\.\([0-9]*\)\.\([0-9]*\).*/\2/g' + ;; +"--micro") + echo "$VERSION" | sed 's/\(^[0-9]*\)\.\([0-9]*\)\.\([0-9]*\).*/\3/g' + ;; +"--git") + echo "$VERSION" | sed 's/\(^[0-9]*\)\.\([0-9]*\)\.\([0-9]*\)\(.*\)/\4/g' + ;; +*) + echo "$VERSION" +esac