mirror of
https://github.com/ruvnet/RuView
synced 2026-07-22 17:23:19 +00:00
499cec7914
RuView's `/api/v1/*` is gated today by `RUVIEW_API_TOKEN`: one shared secret, no expiry, no per-user attribution. This adds the verifier half of replacing that with Cognitum identity — RuView as an OAuth **resource server**, so a user signs in to their own sensing server with their Cognitum account. Note the direction: RuView does not call Cognitum. It never obtains a token for its own use; it verifies tokens users present. Every other Cognitum OAuth integration in the org (meta-proxy, musica, metaharness, the dashboard CLI) is the client side of a plane RuView doesn't have. The one existing resource-server verifier is `meta-llm/src/auth/oauthBearer.ts`, and this crate is a port of its accept-rule — divergence would be a bug, not a preference: a token meta-llm rejects must not be one RuView accepts. Verification is OFFLINE, and that is a requirement rather than an optimisation. RuView runs on Pi-class hardware that loses WAN, and identity publishes no introspection endpoint even when the network is up. So: ES256 over identity's published JWKS, cached by `kid`. What it accepts, mirroring oauthBearer.ts: typ == "access" AND NOT setup AND NOT workload AND account_id non-empty AND exp in the future AND iss matches verbatim AND the required scope is held. Long-lived setup (365-day) and workload credentials are refused outright for identity's own stated reason: their revocation lives in `oauth_setup_tokens`, and RuView — like meta-llm — has no database to check it. A 15-minute access token needs no revocation round-trip because it expires faster than revocation propagates; a 365-day one does. Scope is the capability boundary, and it has to be. Cognitum access tokens carry no `aud`, and `client_id` cannot substitute because clients borrow each other's registrations (musica ships DEFAULT_CLIENT_ID = "meta-proxy"). `sensing:read` covers streams and inference; `sensing:admin` covers training, model delete and recording delete. No hierarchy — admin does not imply read; consent means what it said. Registered in identity migration 0016 (cognitum-one/dashboard#116). Design notes: - `ureq`, not `reqwest`: the sensing server deliberately chose ureq as "the smallest" HTTP client, and pulling reqwest in here would reverse that for the whole graph. Transport sits behind a `JwksFetcher` trait, so a host can supply its own and take no HTTP dependency at all (feature `ureq-transport`, default). - A JWKS refetch failure is survivable while a key set is already cached: a key that verified a minute ago has not stopped being valid because the network blipped, and failing closed there logs every user out of their own sensing server whenever their internet wobbles. We fail closed in exactly one case — no key set has ever been fetched. - Unknown `kid` forces one refetch so rotation is picked up without waiting out the TTL, rate-limited so junk-kid tokens can't become a request amplifier aimed at identity. - Expiry is reported distinctly from a bad signature: on an RTC-less Pi that is usually a clock-sync fault, and an operator must be able to tell them apart. - Test keypairs are generated at runtime, never committed. This repo tracks zero `.pem` files and committed key material shouldn't start here — it also means no fixture can drift out of sync with the JWKS it's served by. Tests: 41 green (19 unit + 21 matrix + 1 doctest) under BOTH `cargo test --no-default-features` (the repo's canonical gate) and default features. The matrix signs real ES256 tokens rather than asserting on strings, and covers alg:none, forged signature, spliced payload, unknown kid, expired, leeway boundaries both sides, wrong issuer, issuer differing only by a trailing slash, missing/!=access typ, setup and workload smuggled onto typ=access, missing and empty account_id, and scope escalation. The highest-value case is `g2_a_genuinely_valid_token_from_another_cognitum_ product_cannot_reach_the_sensing_surface`: a correctly signed, unexpired, right-issuer, right-typ token with client_id=meta-proxy and scope=inference is rejected. Nothing about its signature or identity claims distinguishes it — only scope does. A naive verifier accepts it, and an `inference` token becomes a key to someone's home sensor. No wiring into the sensing server yet; this crate is verification only, with no login flow and no outbound Cognitum calls. Co-Authored-By: Ruflo & AQE
241 lines
10 KiB
TOML
241 lines
10 KiB
TOML
[workspace]
|
|
resolver = "2"
|
|
members = [
|
|
"crates/wifi-densepose-core",
|
|
"crates/wifi-densepose-signal",
|
|
"crates/wifi-densepose-nn",
|
|
# wifi-densepose-api / -db / -config: removed in #578.
|
|
# The crate names were reserved early for an envisioned REST/database/config
|
|
# split, but no implementation followed and no code referenced them. The
|
|
# functionality they would provide is covered today by:
|
|
# - REST/WS: `wifi-densepose-sensing-server` (Axum)
|
|
# - Config: per-crate config + CLI args in `wifi-densepose-sensing-server`
|
|
# and `wifi-densepose-desktop`
|
|
# - DB: no persistent state; system is real-time
|
|
# If we ever need any of these as a published surface, they can be
|
|
# reintroduced with a real implementation.
|
|
"crates/wifi-densepose-hardware",
|
|
"crates/wifi-densepose-wasm",
|
|
"crates/wifi-densepose-cli",
|
|
"crates/wifi-densepose-mat",
|
|
"crates/wifi-densepose-train",
|
|
"crates/wifi-densepose-sensing-server",
|
|
"crates/wifi-densepose-wifiscan",
|
|
"crates/wifi-densepose-vitals",
|
|
"crates/wifi-densepose-ruvector",
|
|
"crates/wifi-densepose-desktop",
|
|
"crates/wifi-densepose-pointcloud",
|
|
# geo + worldgraph extracted to ruvnet/worldgraph submodule (see crates/worldgraph)
|
|
"crates/wifi-densepose-engine", # ADR-135..146 integration/composition layer
|
|
"crates/wifi-densepose-calibration", # ADR-151 — per-room calibration & specialist training
|
|
# ADR-271 — Cognitum OAuth access-token verification. RuView as an OAuth
|
|
# RESOURCE SERVER: offline ES256/JWKS verification of tokens issued by
|
|
# auth.cognitum.one, so a user signs in to their own sensing server with
|
|
# their Cognitum identity instead of a shared static bearer. No login flow
|
|
# and no outbound Cognitum API calls live here — verification only.
|
|
"crates/ruview-auth",
|
|
"crates/nvsim",
|
|
"crates/nvsim-server",
|
|
"crates/homecore", # ADR-127 — HOMECORE state machine
|
|
"crates/homecore-plugins", # ADR-128 — HOMECORE-PLUGINS WASM runtime (P1 scaffold)
|
|
"crates/homecore-api", # ADR-130 — HOMECORE REST + WS API
|
|
"crates/homecore-automation", # ADR-129 — HOMECORE automation engine
|
|
"crates/homecore-recorder", # ADR-132 — HOMECORE state recorder
|
|
"crates/homecore-migrate", # ADR-134 — HOMECORE migration from Python HA
|
|
# ADR-100/ADR-101: Cognitum Cog packaging — first Cog from this repo.
|
|
# Ships the wifi-densepose pose-estimation model as a signed binary +
|
|
# JSONL manifest installable by the Cognitum V0 appliance (cognitum-v0,
|
|
# cognitum-cluster-*, ruvultra). The companion appliance-side crate
|
|
# lives in cognitum-one/v0-appliance as `cognitum-pose-estimation`.
|
|
"crates/cog-pose-estimation",
|
|
# ADR-103: Learned multi-person counter (SOTA path) — replaces the
|
|
# PR #491 slot heuristic with a Candle network + Stoer-Wagner fusion.
|
|
# Motivated by #499 ghost-skeleton reports.
|
|
"crates/cog-person-count",
|
|
# ADR-116: Home Assistant + Matter Cognitum Seed cog. Wraps the
|
|
# ADR-115 MQTT publisher as a Seed-installable artifact with
|
|
# mDNS, embedded broker, RuVector thresholds, Ed25519 witness.
|
|
"crates/cog-ha-matter",
|
|
# ADR-118: BFLD — Beamforming Feedback Layer for Detection. The
|
|
# privacy/safety layer that measures and gates identity leakage from
|
|
# WiFi BFI captures. Sub-ADRs: 119 (frame), 120 (privacy class),
|
|
# 121 (identity risk), 122 (HA/Matter), 123 (capture path).
|
|
"crates/wifi-densepose-bfld",
|
|
# ADR-147: OccWorld thin-client bridge — WorldGraph PersonTrack history →
|
|
# OccWorld Python subprocess → TrajectoryPrior injection into pose tracker.
|
|
# worldmodel extracted to ruvnet/worldgraph submodule (consumed via path dep)
|
|
# ADR-147 (Phase 5): OccWorld TransVQVAE ported to Candle — native Rust
|
|
# inference without Python/IPC overhead. Loaded alongside the Python bridge
|
|
# as a faster alternative once Phase-5 weights are available.
|
|
"crates/wifi-densepose-occworld-candle",
|
|
# rvCSI — edge RF sensing runtime (ADR-095 platform, ADR-096 FFI/crate layout):
|
|
# lives in its own repo (https://github.com/ruvnet/rvcsi), vendored here as
|
|
# `vendor/rvcsi` and published to crates.io as `rvcsi-*` 0.3.x. Depend on the
|
|
# published crates (or the submodule's `crates/rvcsi-*` paths) — not as v2
|
|
# workspace members, since `vendor/rvcsi/Cargo.toml` is its own workspace.
|
|
"crates/homecore-hap", # ADR-125 — Apple Home HomeKit Accessory Protocol bridge
|
|
"crates/homecore-assist", # ADR-133 — HOMECORE voice assistant + ruflo bridge
|
|
"crates/homecore-server", # iter-9 — HOMECORE integration binary (all 8 crates wired together)
|
|
"crates/ruview-swarm", # ADR-148 — drone swarm control system
|
|
# ADR-262 P1 — anti-corruption bridge converting RuView WiFi-CSI sensing
|
|
# output into signed RuField FieldEvents. Path-deps the `vendor/rufield`
|
|
# submodule crates (rufield-core/-provenance/-privacy/-fusion); single
|
|
# coupling point between RuView and the standalone RuField MFS spec.
|
|
"crates/wifi-densepose-rufield",
|
|
]
|
|
# ADR-040: WASM edge crate targets wasm32-unknown-unknown (no_std),
|
|
# excluded from workspace to avoid breaking `cargo test --workspace`.
|
|
# Build separately: cargo build -p wifi-densepose-wasm-edge --target wasm32-unknown-unknown --release
|
|
#
|
|
# ADR-128 P2: example WASM plugin — also wasm32-only (no_std, cdylib),
|
|
# excluded for the same reason. Build separately:
|
|
# cargo build --target wasm32-unknown-unknown --release -p homecore-plugin-example
|
|
exclude = [
|
|
"crates/wifi-densepose-wasm-edge",
|
|
"crates/homecore-plugin-example",
|
|
"crates/worldgraph", # ruvnet/worldgraph submodule — its own workspace (geo/worldgraph/worldmodel)
|
|
]
|
|
|
|
[workspace.package]
|
|
version = "0.3.0"
|
|
edition = "2021"
|
|
authors = ["rUv <ruv@ruv.net>", "WiFi-DensePose Contributors"]
|
|
license = "MIT OR Apache-2.0"
|
|
repository = "https://github.com/ruvnet/wifi-densepose"
|
|
documentation = "https://docs.rs/wifi-densepose"
|
|
keywords = ["wifi", "densepose", "csi", "pose-estimation", "rust"]
|
|
categories = ["science", "computer-vision", "wasm"]
|
|
|
|
[workspace.dependencies]
|
|
# Core utilities
|
|
thiserror = "2.0"
|
|
anyhow = "1.0"
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_json = "1.0"
|
|
serde_yaml = "0.9"
|
|
tokio = { version = "1.35", features = ["full"] }
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
|
|
# Signal processing
|
|
ndarray = { version = "0.17", features = ["serde"] }
|
|
ndarray-linalg = { version = "0.18", features = ["openblas-static"] }
|
|
rustfft = "6.1"
|
|
num-complex = "0.4"
|
|
num-traits = "0.2"
|
|
|
|
# Neural network
|
|
tch = "0.24"
|
|
ort = { version = "2.0.0-rc.11" }
|
|
candle-core = "0.4"
|
|
candle-nn = "0.4"
|
|
|
|
# Web framework
|
|
axum = { version = "0.7", features = ["ws", "macros"] }
|
|
tower = { version = "0.4", features = ["full"] }
|
|
tower-http = { version = "0.6", features = ["cors", "trace", "compression-gzip"] }
|
|
hyper = { version = "1.1", features = ["full"] }
|
|
|
|
# Database
|
|
sqlx = { version = "0.7", features = ["runtime-tokio", "postgres", "sqlite", "uuid", "chrono", "json"] }
|
|
redis = { version = "0.24", features = ["tokio-comp", "connection-manager"] }
|
|
|
|
# Configuration
|
|
config = "0.14"
|
|
dotenvy = "0.15"
|
|
envy = "0.4"
|
|
|
|
# WASM
|
|
wasm-bindgen = "0.2"
|
|
wasm-bindgen-futures = "0.4"
|
|
js-sys = "0.3"
|
|
web-sys = { version = "0.3", features = ["console", "Window", "WebSocket"] }
|
|
getrandom = { version = "0.2", features = ["js"] }
|
|
|
|
# Hardware
|
|
serialport = "4.3"
|
|
pcap = "1.1"
|
|
|
|
# Graph algorithms (for min-cut assignment in metrics)
|
|
petgraph = "0.6"
|
|
|
|
# Data loading
|
|
ndarray-npy = "0.10"
|
|
walkdir = "2.4"
|
|
|
|
# Hashing (for proof)
|
|
sha2 = "0.10"
|
|
|
|
# CSV logging
|
|
csv = "1.3"
|
|
|
|
# Progress bars
|
|
indicatif = "0.17"
|
|
|
|
# CLI
|
|
clap = { version = "4.4", features = ["derive", "env"] }
|
|
|
|
# rvCSI: napi-rs (Rust -> Node bindings) + napi-c (C-shim build glue)
|
|
napi = { version = "2.16", default-features = false, features = ["napi8"] }
|
|
napi-derive = "2.16"
|
|
napi-build = "2.1"
|
|
cc = "1.0"
|
|
libc = "0.2"
|
|
|
|
# Testing
|
|
criterion = { version = "0.5", features = ["html_reports"] }
|
|
proptest = "1.4"
|
|
mockall = "0.12"
|
|
wiremock = "0.5"
|
|
|
|
# midstreamer integration (published on crates.io)
|
|
# 0.1.0 was yanked; upgrade to latest 0.3/0.2 releases which pull in
|
|
# quinn-proto >=0.11.14 (fixes RUSTSEC-2026-0037) and
|
|
# rustls-webpki >=0.103.13 (fixes RUSTSEC-2026-0049/0098/0099/0104).
|
|
midstreamer-quic = "0.3"
|
|
midstreamer-scheduler = "0.2"
|
|
midstreamer-temporal-compare = "0.2"
|
|
midstreamer-attractor = "0.2"
|
|
|
|
# ruvector integration (published on crates.io)
|
|
# Vendored at origin/main (a083bd77f) in vendor/ruvector; using crates.io versions
|
|
# until published. Bumps per ADR-152 §2.6 (2026-06-10 vendor sync survey).
|
|
ruvector-core = "2.2.0"
|
|
ruvector-mincut = "2.0.6"
|
|
ruvector-attn-mincut = "2.0.4"
|
|
ruvector-temporal-tensor = "2.0.6"
|
|
ruvector-solver = "2.0.6"
|
|
ruvector-attention = "2.1.0"
|
|
ruvector-crv = "0.1.1"
|
|
ruvector-gnn = { version = "2.2.0", default-features = false }
|
|
|
|
|
|
# Internal crates
|
|
wifi-densepose-core = { version = "0.3.0", path = "crates/wifi-densepose-core" }
|
|
wifi-densepose-signal = { version = "0.3.0", path = "crates/wifi-densepose-signal" }
|
|
wifi-densepose-nn = { version = "0.3.0", path = "crates/wifi-densepose-nn" }
|
|
wifi-densepose-api = { version = "0.3.0", path = "crates/wifi-densepose-api" }
|
|
wifi-densepose-db = { version = "0.3.0", path = "crates/wifi-densepose-db" }
|
|
wifi-densepose-config = { version = "0.3.0", path = "crates/wifi-densepose-config" }
|
|
wifi-densepose-hardware = { version = "0.3.0", path = "crates/wifi-densepose-hardware" }
|
|
wifi-densepose-wasm = { version = "0.3.0", path = "crates/wifi-densepose-wasm" }
|
|
wifi-densepose-mat = { version = "0.3.0", path = "crates/wifi-densepose-mat" }
|
|
wifi-densepose-ruvector = { version = "0.3.0", path = "crates/wifi-densepose-ruvector" }
|
|
wifi-densepose-worldmodel = { version = "0.3.0", path = "crates/worldgraph/wifi-densepose-worldmodel" }
|
|
|
|
[profile.release]
|
|
lto = true
|
|
codegen-units = 1
|
|
panic = "abort"
|
|
strip = true
|
|
opt-level = 3
|
|
|
|
[profile.release-with-debug]
|
|
inherits = "release"
|
|
debug = true
|
|
strip = false
|
|
|
|
[profile.bench]
|
|
inherits = "release"
|
|
debug = true
|