mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* chore(policy): restart schema implementation Signed-off-by: Johnny Greco <jogreco@nvidia.com> * feat(policy-schema): add canonical authored policy model Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(policy): use canonical authored schema Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(prover): project canonical policy documents Signed-off-by: Johnny Greco <jogreco@nvidia.com> * docs(policy): describe shared schema boundary Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(policy): close reviewed parser gaps Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(policy-schema): fail closed on unsupported fields Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(policy): preserve partial process identities Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(policy-schema): harden authored policy inspection Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(policy): rename policy schema crate Signed-off-by: Johnny Greco <jogreco@nvidia.com> * revert(policy): restore policy schema crate Signed-off-by: Johnny Greco <jogreco@nvidia.com> * test(e2e): serialize OIDC PKCE scenarios Signed-off-by: Johnny Greco <jogreco@nvidia.com> --------- Signed-off-by: Johnny Greco <jogreco@nvidia.com>
70 lines
2.4 KiB
TOML
70 lines
2.4 KiB
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
[package]
|
|
name = "openshell-core"
|
|
description = "Shared library for OpenShell - proto definitions, config, and errors"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
rust-version.workspace = true
|
|
license.workspace = true
|
|
repository.workspace = true
|
|
|
|
[dependencies]
|
|
async-trait = "0.1"
|
|
openshell-extension-core = { path = "../openshell-extension-core" }
|
|
openshell-policy-schema = { path = "../openshell-policy-schema" }
|
|
glob = { workspace = true }
|
|
prost = { workspace = true }
|
|
prost-types = { workspace = true }
|
|
tonic = { workspace = true, features = ["channel", "tls-aws-lc"] }
|
|
tonic-prost = { workspace = true }
|
|
tonic-types = { workspace = true }
|
|
tokio = { workspace = true }
|
|
tokio-stream = { workspace = true }
|
|
thiserror = { workspace = true }
|
|
miette = { workspace = true }
|
|
serde = { workspace = true }
|
|
serde_json = { workspace = true }
|
|
sha2 = { workspace = true }
|
|
tracing = { workspace = true }
|
|
url = { workspace = true }
|
|
uuid = { workspace = true }
|
|
ipnet = "2"
|
|
rustls = { workspace = true }
|
|
rustls-pemfile = { workspace = true }
|
|
base64 = { workspace = true }
|
|
jsonwebtoken = { workspace = true, optional = true }
|
|
zeroize = { workspace = true, optional = true }
|
|
chrono = { version = "0.4", default-features = false, features = ["clock", "std"], optional = true }
|
|
reqwest = { workspace = true, features = ["blocking", "rustls-tls-native-roots-no-provider"], optional = true }
|
|
tar = { version = "0.4", optional = true }
|
|
tempfile = { version = "3", optional = true }
|
|
|
|
[target.'cfg(unix)'.dependencies]
|
|
nix = { workspace = true }
|
|
rustix = { workspace = true }
|
|
|
|
[features]
|
|
default = ["telemetry"]
|
|
## Compile in anonymous telemetry emission support. On by default; disable with
|
|
## `--no-default-features` (plus any other features you need) for a build that
|
|
## contains no telemetry endpoint, no HTTP client, and no emission code at all.
|
|
driver-extraction = ["dep:tar", "dep:tempfile"]
|
|
telemetry = ["dep:reqwest", "dep:chrono", "reqwest?/blocking"]
|
|
## OAuth2 token request helpers used by supervisor and gateway.
|
|
oauth = ["dep:reqwest"]
|
|
## Strict Ed25519 JWT issuance and verification for authenticated sandbox sessions.
|
|
jwt = ["dep:jsonwebtoken", "dep:zeroize"]
|
|
|
|
[build-dependencies]
|
|
tonic-prost-build = { workspace = true }
|
|
protoc-bin-vendored = { workspace = true }
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3"
|
|
rcgen = { workspace = true }
|
|
|
|
[lints]
|
|
workspace = true
|