mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-09-01 09:09:19 +00:00
feat: admin secrets provisioning API + API documentation
- Add PUT/GET/DELETE /api/admin/users/{id}/secrets/{name} endpoints for
application backends to provision per-user secrets (AES-256-GCM encrypted)
- Add secrets_store field to GatewayState with builder wiring
- Create docs/USER_MANAGEMENT_API.md with full API spec covering users,
secrets, tokens, profile, and usage endpoints
- Update web gateway CLAUDE.md route table
Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
This commit is contained in:
@@ -16,7 +16,7 @@ use axum::{
|
||||
IntoResponse,
|
||||
sse::{Event, KeepAlive, Sse},
|
||||
},
|
||||
routing::{get, post},
|
||||
routing::{get, post, put},
|
||||
};
|
||||
use serde::Deserialize;
|
||||
use sha2::{Digest, Sha256};
|
||||
@@ -378,6 +378,8 @@ pub struct GatewayState {
|
||||
pub startup_time: std::time::Instant,
|
||||
/// Snapshot of active (resolved) configuration for the frontend.
|
||||
pub active_config: ActiveConfigSnapshot,
|
||||
/// Secrets store for admin secret provisioning.
|
||||
pub secrets_store: Option<Arc<dyn crate::secrets::SecretsStore + Send + Sync>>,
|
||||
}
|
||||
|
||||
/// Start the gateway HTTP server.
|
||||
@@ -532,6 +534,16 @@ pub async fn start_server(
|
||||
"/api/admin/users/{id}/activate",
|
||||
post(super::handlers::users::users_activate_handler),
|
||||
)
|
||||
// Admin secrets provisioning (per-user)
|
||||
.route(
|
||||
"/api/admin/users/{user_id}/secrets",
|
||||
get(super::handlers::secrets::secrets_list_handler),
|
||||
)
|
||||
.route(
|
||||
"/api/admin/users/{user_id}/secrets/{name}",
|
||||
put(super::handlers::secrets::secrets_put_handler)
|
||||
.delete(super::handlers::secrets::secrets_delete_handler),
|
||||
)
|
||||
// Usage reporting (admin)
|
||||
.route(
|
||||
"/api/admin/usage",
|
||||
@@ -3041,6 +3053,7 @@ mod tests {
|
||||
routine_engine: Arc::new(tokio::sync::RwLock::new(None)),
|
||||
startup_time: std::time::Instant::now(),
|
||||
active_config: ActiveConfigSnapshot::default(),
|
||||
secrets_store: None,
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user