mirror of
https://github.com/thegeneralist01/archivr
synced 2026-10-09 12:55:00 +02:00
feat(server): configurable bind address with loopback default and non-loopback warning
- Add optional `bind` field to ServerRegistry (TOML + ARCHIVR_BIND env var) - Default bind address remains 127.0.0.1:8080; non-loopback prints a warning - Add route security classification comment block (READ/ADMIN/WRITE/STATIC) - Add Security and Deployment section to docs/README.md - Replace vague auth note in ARCHIVR-MENTAL-MODEL.md with concrete model description - Add three registry tests covering bind field round-trip and defaults
This commit is contained in:
parent
10c41ef84f
commit
2d7a4f1766
5 changed files with 118 additions and 4 deletions
|
|
@ -1,9 +1,11 @@
|
|||
mod registry;
|
||||
mod routes;
|
||||
|
||||
use anyhow::Result;
|
||||
use anyhow::{Context, Result};
|
||||
use std::{net::SocketAddr, path::PathBuf};
|
||||
|
||||
const DEFAULT_BIND: &str = "127.0.0.1:8080";
|
||||
|
||||
#[tokio::main]
|
||||
async fn main() -> Result<()> {
|
||||
let config_path = std::env::args()
|
||||
|
|
@ -11,8 +13,27 @@ async fn main() -> Result<()> {
|
|||
.map(PathBuf::from)
|
||||
.unwrap_or_else(|| PathBuf::from("archivr-server.toml"));
|
||||
let registry = registry::load_registry(&config_path)?;
|
||||
let app = routes::app(registry);
|
||||
let addr = SocketAddr::from(([127, 0, 0, 1], 8080));
|
||||
let app = routes::app(registry.clone());
|
||||
|
||||
// Bind address priority: ARCHIVR_BIND env var > TOML bind field > default loopback.
|
||||
let bind_str = std::env::var("ARCHIVR_BIND")
|
||||
.ok()
|
||||
.or_else(|| registry.bind.clone())
|
||||
.unwrap_or_else(|| DEFAULT_BIND.to_string());
|
||||
|
||||
let addr: SocketAddr = bind_str
|
||||
.parse()
|
||||
.with_context(|| format!("invalid bind address: {bind_str}"))?;
|
||||
|
||||
// Warn when the server is reachable beyond localhost — it has no authentication.
|
||||
if !addr.ip().is_loopback() {
|
||||
eprintln!(
|
||||
"warn: archivr-server is bound to {addr} — \
|
||||
this server has no authentication. \
|
||||
Only expose it on a trusted network."
|
||||
);
|
||||
}
|
||||
|
||||
let listener = tokio::net::TcpListener::bind(addr).await?;
|
||||
println!("archivr-server listening on http://{addr}");
|
||||
axum::serve(listener, app).await?;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue