T1 探针式实现,接通端到端链路并验证双目标编译: - 依赖:rmcp=3.0.0-beta.3(server/macros/transport-streamable-http-server/ transport-worker)+ aes-gcm,均经 server feature 门控。 - 迁移 017_mcp_tokens:UUID 主键、scope 约束、token_enc 密文 + token_hash 唯一索引(仅未撤销),users.id 外键级联。 - 模型 src/models/mcp_token.rs:TokenScope(read<write<admin 偏序,grants)+ McpToken/McpTokenSummary/CreateTokenResponse DTO。 - src/mcp/(server-only): - crypto.rs:AES-GCM-256 加解密(hex 密钥、每次独立 nonce、8 项单测)。 - auth.rs:bearer→SHA-256→DB 常量查找→注入 McpPrincipal,刷新 last_used_at。 - server.rs:rmcp ServerHandler,search_posts 工具(read 作用域,pg_trgm 查询)。 - router.rs:StreamableHttpService(无状态+JSON 响应+Origin 白名单)挂载 /mcp。 - main.rs:merge mcp_route 到应用路由;models/mod.rs 注册 mcp_token 模块。 验证:rmcp+axum-0.8 兼容性经临时探针实测(tools/list、tools/call、Origin→403、 bearer→工具 principal 全链路);--features web 与 --features server 均编译通过; clippy --all-features -D warnings 干净;639 单测+1 集成 +13 新 MCP 测试全绿。
143 lines
6.6 KiB
TOML
143 lines
6.6 KiB
TOML
[package]
|
||
name = "yggdrasil"
|
||
version = "0.6.2"
|
||
edition = "2021"
|
||
|
||
# 构建时工具二进制:用 syntect(server-only 依赖)生成 highlight.css。
|
||
# 仅在启用 server feature 时编译——WASM 前端构建(--no-default-features --features web)
|
||
# 不会拉入 syntect,此二进制若也参与编译会因找不到 syntect 报错。
|
||
[[bin]]
|
||
name = "generate_highlight_css"
|
||
required-features = ["server"]
|
||
|
||
[dependencies]
|
||
dioxus = { version = "0.7.9", features = ["fullstack", "router"] }
|
||
serde = { version = "1.0", features = ["derive"] }
|
||
tokio = { version = "1.53", features = ["rt-multi-thread", "macros", "fs", "time", "sync"], optional = true }
|
||
tokio-postgres = { version = "0.7", features = ["with-chrono-0_4", "with-uuid-1"], optional = true }
|
||
deadpool-postgres = { version = "0.14", optional = true }
|
||
argon2 = { version = "0.5", optional = true }
|
||
uuid = { version = "1", features = ["v4"], optional = true }
|
||
chrono = { version = "0.4", features = ["serde"] }
|
||
regex = { version = "1.13", optional = true }
|
||
# mhchem 化学公式转译器(src/api/mhchem.rs)需要 lookahead 正则,
|
||
# Rust `regex` crate 不支持 `(?=...)`/`(?!...)`,故用 `fancy-regex`。
|
||
# 该 crate 已被 syntect 间接引入(0.16.2,见 Cargo.lock),此处显式声明为直接依赖。
|
||
fancy-regex = { version = "0.16", optional = true }
|
||
pulldown-cmark = { version = "0.13", optional = true }
|
||
dotenvy = { version = "0.15", optional = true }
|
||
tracing = { version = "0.1", optional = true, features = ["release_max_level_info"] }
|
||
tracing-subscriber = { version = "0.3", optional = true }
|
||
|
||
rand = { version = "0.8", features = ["getrandom"], optional = true }
|
||
http = { version = "1", optional = true }
|
||
axum = { version = "0.8", optional = true, features = ["multipart"] }
|
||
tower-http = { version = "0.7", optional = true, features = ["compression-full", "timeout", "trace"] }
|
||
|
||
serde_json = "1.0"
|
||
sha2 = { version = "0.10", optional = true }
|
||
hex = { version = "0.4", optional = true }
|
||
lol_html = { version = "3", optional = true }
|
||
syntect = { version = "5", default-features = false, features = ["default-syntaxes", "default-themes", "default-fancy", "html", "parsing", "dump-load", "yaml-load"], optional = true }
|
||
# NOTE: WebP decoder is intentionally excluded from the image crate.
|
||
# We use zenwebp for both encoding and decoding to ensure consistency.
|
||
# Do NOT add "webp" to the features list without updating src/webp.rs.
|
||
image = { version = "0.25", optional = true, default-features = false, features = ["jpeg", "png", "gif"] }
|
||
zenwebp = { version = "0.4", optional = true }
|
||
moka = { version = "0.12", features = ["future", "sync"], optional = true }
|
||
governor = { version = "0.10", optional = true }
|
||
sysinfo = { version = "0.39", optional = true }
|
||
sqlparser = { version = "0.62", optional = true }
|
||
dashmap = { version = "6.2", optional = true }
|
||
# 中文标题 → 拼音 slug(纯 Rust、零依赖,安全交叉编译到 musl/FreeBSD)。
|
||
pinyin = { version = "0.11", optional = true }
|
||
md-5 = { version = "0.10", optional = true }
|
||
futures = { version = "0.3", optional = true }
|
||
bytes = { version = "1", optional = true }
|
||
bollard = { version = "0.21", optional = true }
|
||
# 把 mpsc::Receiver 包成 Stream,供 axum SSE handler 使用。
|
||
# axum::response::sse::{Sse,KeepAlive,Event} 随 axum 0.8 自带,无需额外 dep。
|
||
tokio-stream = { version = "0.1", features = ["sync"], optional = true }
|
||
# 全局分配器:用 mimalloc 替换系统 malloc。多线程高频小对象分配吞吐显著提升,
|
||
# 且对全静态 musl 链接友好(生产 Docker 镜像即 musl 目标)。
|
||
# server-only:经 server feature 启用;WASM 前端构建不编译(见 main.rs cfg 门控)。
|
||
mimalloc = { version = "0.1", optional = true }
|
||
# KaTeX 服务端数学公式渲染:纯 Rust 重实现(无 JS 运行时),渲染 $...$ / $$...$$
|
||
# 为 HTML span。库名是 katex(crate 名 katex-rs),代码用 `use katex::...`。
|
||
# 默认 features 为空即原生服务端编译;wasm feature 仅前端构建才需,这里不开。
|
||
# 配套前端需引入 katex.min.css + 字体(见 public/katex/、Makefile katex-css)。
|
||
katex-rs = { version = "0.2", optional = true }
|
||
# MCP(Model Context Protocol)服务器:官方 Rust SDK rmcp。
|
||
# 必须锁在 3.x beta 线(稳定版 0.2.1 缺 Origin 校验/协议版本头/体积上限/无状态默认等
|
||
# spec 强制项)。2026-07-28 经临时 axum-0.8 探针验证可挂载(见 docs/mcp-spec.md)。
|
||
# transport-worker 必须显式加:LocalSessionManager 无条件引用 transport::worker。
|
||
rmcp = { version = "=3.0.0-beta.3", optional = true, features = ["server", "macros", "transport-streamable-http-server", "transport-worker"] }
|
||
# MCP token 静态加密(AES-GCM):管理员可在后台重查明文,DB 不裸存。
|
||
aes-gcm = { version = "0.10", optional = true }
|
||
|
||
[target.'cfg(target_arch = "wasm32")'.dependencies]
|
||
web-sys = { version = "0.3", features = ["Document", "Window", "Storage", "Element", "HtmlElement", "DomTokenList", "MediaQueryList", "HtmlImageElement", "MouseEvent", "KeyboardEvent", "Node", "EventTarget", "Navigator", "Clipboard", "File", "FileList", "FormData", "Request", "RequestInit", "Response", "Headers", "ClipboardEvent", "DataTransfer", "HtmlInputElement", "EventSource", "MessageEvent"] }
|
||
wasm-bindgen = "0.2"
|
||
wasm-bindgen-futures = "0.4"
|
||
js-sys = "0.3"
|
||
# 把 serde 类型(如 SqlSchema)序列化为 JsValue,供 wasm-bindgen extern 传递。
|
||
serde-wasm-bindgen = "0.6"
|
||
|
||
[dev-dependencies]
|
||
tokio = { version = "1.53", features = ["rt-multi-thread", "macros", "fs", "time", "sync"] }
|
||
serial_test = "3"
|
||
|
||
[profile.release]
|
||
debug = false
|
||
opt-level = 3
|
||
lto = "thin"
|
||
codegen-units = 1
|
||
strip = "symbols"
|
||
# panic 直接终止:WASM 去掉 unwind 元数据以减小体积;server 端错误处理走
|
||
# Result + ?(见 src/api/error.rs),不依赖 panic unwind,进程级崩溃由
|
||
# systemd/k8s 拉起。这是 Dioxus 官方 optimizing 指南推荐的 WASM 瘦身项。
|
||
panic = "abort"
|
||
|
||
[features]
|
||
default = ["web", "server"]
|
||
web = ["dioxus/web"]
|
||
server = [
|
||
"dioxus/server",
|
||
"dep:tokio",
|
||
"dep:tokio-postgres",
|
||
"dep:deadpool-postgres",
|
||
"dep:argon2",
|
||
"dep:uuid",
|
||
"dep:regex",
|
||
"dep:fancy-regex",
|
||
"dep:pulldown-cmark",
|
||
"dep:rand",
|
||
"dep:http",
|
||
"dep:sha2",
|
||
"dep:hex",
|
||
"dep:dotenvy",
|
||
"dep:tracing",
|
||
"dep:tracing-subscriber",
|
||
"dep:lol_html",
|
||
"dep:syntect",
|
||
"dep:axum",
|
||
"dep:tower-http",
|
||
"dep:image",
|
||
"dep:zenwebp",
|
||
"dep:moka",
|
||
"dep:governor",
|
||
"dep:sysinfo",
|
||
"dep:sqlparser",
|
||
"dep:dashmap",
|
||
"dep:pinyin",
|
||
"dep:md-5",
|
||
"dep:futures",
|
||
"dep:bytes",
|
||
"dep:bollard",
|
||
"dep:tokio-stream",
|
||
"dep:mimalloc",
|
||
"dep:katex-rs",
|
||
"dep:rmcp",
|
||
"dep:aes-gcm",
|
||
]
|