generated from devjonatas/axum-template
Pixie log the backlog api
- Rust 78.3%
- HTML 11.6%
- Hurl 7.3%
- PLpgSQL 0.9%
- CSS 0.9%
- Other 1%
O step dependency-audit reprovou com
Crate: rustls
Version: 0.23.40
Title: TLS 1.3 handshake messages incorrectly accepted across
encryption level boundaries
ID: RUSTSEC-2026-0285 Severity: 5.3 (medium)
Solution: Upgrade to >=0.23.45
rustls vem por baixo do reqwest e do sqlx (runtime-tokio-rustls), nao e
dependencia direta. Um `cargo update -p rustls` sozinho parava em 0.23.43:
o resolver MSRV-aware da edition 2024 considera a 0.23.45 incompativel com
o rust-version = "1.90" declarado, por causa do aws-lc-sys 0.45. Na pratica
compila -- verificado com a toolchain exata do CI, rustc 1.90.0 (1159e78c4),
`cargo clippy --locked --all-targets -- -D warnings` sem achados. Dai o
--precise.
ATENCAO: por ser --precise, um `cargo update` amplo devolve o rustls para
0.23.43 e reabre o advisory. Se isso acontecer, refaca com
`cargo update -p rustls --precise 0.23.45` (ou suba o rust-version quando
o MSRV do projeto puder andar).
Junto, quatro dos seis warnings sairam de graca no mesmo update:
anyhow 1.0.102 -> 1.0.104 unsound RUSTSEC-2026-0190
event-listener 5.4.1 -> 5.4.2 unsound RUSTSEC-2026-0221
chacha20 0.10.0 -> 0.10.2 yanked
spin 0.9.8 -> 0.9.9 yanked
`cargo audit --ignore RUSTSEC-2023-0071` agora sai com codigo 0:
0 vulnerabilidades, 2 warnings (eram 6).
Os dois que restam sao "unmaintained", nao tem correcao e nao reprovam:
fxhash 0.2.1 <- selectors <- scraper 0.22.0
proc-macro-error2 2.0.1 <- validator_derive <- validator 0.20.0
Sair deles exige subir scraper (0.27) e validator (0.21), que trazem
mudanca de API, e fica para um commit proprio.
|
||
|---|---|---|
| .cargo | ||
| .githooks | ||
| .sqlx | ||
| .woodpecker | ||
| migrations | ||
| scripts | ||
| src | ||
| static | ||
| templates | ||
| test-results | ||
| tests | ||
| .audit.toml | ||
| .buildpacks | ||
| .env.example | ||
| .gitignore | ||
| .pre-commit-config.yaml | ||
| app.json | ||
| Cargo.lock | ||
| Cargo.toml | ||
| debug_render.sh | ||
| docker-compose.yml | ||
| Dockerfile | ||
| fix_migration.sql | ||
| init_db.sh | ||
| LICENSE | ||
| parse_lcov.py | ||
| Procfile | ||
| README.md | ||
| rust-toolchain | ||
Pixie API
A Rust-based API for Pixielog, featuring Keyrunes authentication, email confirmation, and Femtocat-styled views.
Prerequisites
- Rust (latest stable)
- Docker and Docker Compose
- Postgres client (optional, for debugging)
Configuration
The application requires the following environment variables. A .env file can be used locally.
| Variable | Description | Example |
|---|---|---|
DATABASE_URL |
Postgres connection string | postgres://postgres:password@localhost:5432/pixielog |
SMTP_URL |
SMTP server URL | smtp://localhost:1025 |
KEYRUNES_URL |
Keyrunes service URL | http://localhost:3000 (internal) or http://keyrunes:3000 (docker) |
APP_URL |
Public URL of this app | http://localhost:8000 |
Running the Application
1. Start Infrastructure
Start Postgres, Mailhog, and Keyrunes using Docker Compose:
docker-compose up -d
2. Initialize Keyrunes (First Run Only)
Setup superuser and organization in Keyrunes:
docker compose exec keyrunes sh /setup.sh
3. Run Database Migrations
Initialize the pixielog database schema:
sqlx migrate run
3. Run Locally (Development)
Start the API server:
cargo run
The server will be available at http://localhost:8000.
4. Run via Docker
To run the entire stack including the API in Docker (if a Dockerfile is provided, otherwise mostly used for deps):
docker-compose up -d
(Note: Ensure your config or env vars point to the keyrunes container name if running inside docker network)
Development
View Docs
Swagger UI is available at: http://localhost:8000/swagger-ui/
Running Tests
Run unit and integration tests:
# Unit tests
cargo test
# Hurl Integration tests (requires running server)
hurl --test tests/auth.hurl