mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 23:18:24 +00:00
Private repository events and Git objects must not be readable merely because an endpoint is reachable. Add an opt-in, fail-closed single-service mode that requires NIP-42 authentication before bridging WebSocket traffic and a repository-scoped GRASP-08 NIP-98 credential before serving Smart HTTP. The Git credential signs the canonical repository root with method GET and is reusable across the standard Git endpoints for its 60-second validity window. Authentication precedes repository lookup, every failure returns the same empty 401 challenge, canonical paths cannot escape the Git root, browser clients can inspect the challenge through CORS, and ordinary GRASP-01 push authorization remains authoritative after authentication. The canonical public origin is operator-controlled so reverse proxies cannot influence signed identity. This commit deliberately implements one configured private service and excludes dynamic relay-owner membership, encrypted kind-10318 client discovery, and multi-service fleet orchestration. Validation before consolidation: cargo check --all-targets passed on current master. Focused unit coverage exercises credential reuse, signature/member/URL/method rejection, canonical origin and repository paths, fail-closed configuration, authentication framing, and empty indistinguishable failures.
161 lines
3.9 KiB
TOML
161 lines
3.9 KiB
TOML
[package]
|
|
name = "ngit-grasp"
|
|
version = "2.1.2"
|
|
edition = "2021"
|
|
authors = ["ngit-grasp contributors"]
|
|
license = "MIT"
|
|
description = "A GRASP (Git Relays Authorized via Signed-Nostr Proofs) implementation in Rust"
|
|
repository = "https://gitworkshop.dev/danconwaydev.com/ngit-grasp"
|
|
|
|
[dependencies]
|
|
# Async runtime
|
|
tokio = { version = "1.35", features = ["full"] }
|
|
|
|
# HTTP server (hyper for relay integration)
|
|
hyper = { version = "1.4", features = ["full"] }
|
|
hyper-util = { version = "0.1", features = ["tokio", "server", "http1", "http2"] }
|
|
http-body-util = "0.1"
|
|
|
|
# Nostr
|
|
#
|
|
# The stable 0.45 series contains the upstream NEG-OPEN handling fix used by
|
|
# the embedded relay. Caret requirements accept compatible patch releases.
|
|
nostr = "0.45.0"
|
|
# `local-relay` carries the embedded relay implementation, previously the
|
|
# separate `nostr-relay-builder` crate.
|
|
nostr-sdk = { version = "0.45.0", features = ["local-relay"] }
|
|
nostr-lmdb = "0.45.0"
|
|
nostr-memory = "0.45.0"
|
|
|
|
# Utilities
|
|
# SHA-1 for the `Sec-WebSocket-Accept` handshake. `nostr` uses this same crate
|
|
# internally but stopped re-exporting it as `nostr::hashes` in 0.45,
|
|
# so depend on it directly rather than pulling in a second hash implementation.
|
|
bitcoin_hashes = "0.14"
|
|
futures-util = "0.3"
|
|
tokio-tungstenite = { version = "0.28", default-features = false }
|
|
base64 = "0.22"
|
|
flate2 = "1.0"
|
|
tar = "0.4"
|
|
fs2 = "0.4"
|
|
ipnet = { version = "2", features = ["serde"] }
|
|
libc = "0.2"
|
|
|
|
# Metrics
|
|
prometheus = { version = "0.14", features = ["process"] }
|
|
dashmap = "6"
|
|
lazy_static = "1.4"
|
|
|
|
# Data structures
|
|
indexmap = "2"
|
|
|
|
# Random (for startup jitter)
|
|
rand = "0.10"
|
|
|
|
# Serialization
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_json = "1.0"
|
|
|
|
# Logging
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
|
|
# Configuration
|
|
dotenvy = "0.15"
|
|
clap = { version = "4.5", features = ["derive", "env"] }
|
|
|
|
# Error handling
|
|
anyhow = "1.0"
|
|
|
|
# Async traits
|
|
async-trait = "0.1"
|
|
|
|
# Temporary directories (used for GRASP-06 empty-repo synthesis)
|
|
tempfile = "3"
|
|
reqwest = { version = "0.13", default-features = false, features = ["native-tls"] }
|
|
|
|
# Git (for future use)
|
|
# git-http-backend = "0.3"
|
|
|
|
[dev-dependencies]
|
|
# Testing
|
|
grasp-audit = { path = "grasp-audit", version = "0.2.0" }
|
|
tempfile = "3"
|
|
tokio = { version = "1.35", features = ["full", "test-util"] }
|
|
tokio-tungstenite = "0.28.0"
|
|
|
|
[lib]
|
|
name = "ngit_grasp"
|
|
path = "src/lib.rs"
|
|
|
|
[[bin]]
|
|
name = "ngit-grasp"
|
|
path = "src/main.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_announcement_cascade"
|
|
path = "tests/lifecycle/nip09_announcement_cascade.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_blacklist_ops"
|
|
path = "tests/lifecycle/nip09_blacklist_ops.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_cascade_event_types"
|
|
path = "tests/lifecycle/nip09_cascade_event_types.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_disrespector"
|
|
path = "tests/lifecycle/nip09_disrespector.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_git_archive_cleanup"
|
|
path = "tests/lifecycle/nip09_git_archive_cleanup.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_holding_cleanup"
|
|
path = "tests/lifecycle/nip09_holding_cleanup.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_holding_db"
|
|
path = "tests/lifecycle/nip09_holding_db.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_multi_maintainer"
|
|
path = "tests/lifecycle/nip09_multi_maintainer.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_recovery"
|
|
path = "tests/lifecycle/nip09_recovery.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_state_cascade"
|
|
path = "tests/lifecycle/nip09_state_cascade.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_state_multi_maintainer"
|
|
path = "tests/lifecycle/nip09_state_multi_maintainer.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_validation"
|
|
path = "tests/lifecycle/nip09_validation.rs"
|
|
|
|
[[test]]
|
|
name = "deletion_request_retention"
|
|
path = "tests/lifecycle/deletion_request_retention.rs"
|
|
|
|
[[test]]
|
|
name = "nip62_lifecycle"
|
|
path = "tests/lifecycle/nip62_lifecycle.rs"
|
|
|
|
[[test]]
|
|
name = "nip62_validation"
|
|
path = "tests/lifecycle/nip62_validation.rs"
|
|
|
|
[[test]]
|
|
name = "replaceable_history"
|
|
path = "tests/lifecycle/replaceable_history.rs"
|
|
|
|
[workspace]
|
|
members = [".", "grasp-audit"]
|