a7012b94c2
Document the provider-explicit auth/session and CSRF boundary for the SaaS tutorial. The recipe keeps cookies, sessions, CSRF policy, and rejection behavior in Axum/Tower/app code while hemx handlers continue to receive typed context/forms and return generated effects. req: laws/002 req: auth/001 req: auth/002 req: auth/003 req: auth/004 req: auth/005 req: failure/004 req: examples/001
30 lines
1.2 KiB
Markdown
30 lines
1.2 KiB
Markdown
# hemx SaaS tutorial skeleton
|
|
|
|
This is the compile-tested skeleton for the v1 production-shaped tutorial app. It is intentionally provider-light: auth/session, CSRF, persistence, deploy, metrics, and islands are explicit app boundaries, not hemx core services. req: examples/001 req: auth/001
|
|
|
|
What it proves today:
|
|
|
|
- typed form/newtype inputs for project creation
|
|
- auth/session context passed through normal Rust state
|
|
- CSRF-safe mutation checked before persistence
|
|
- local in-memory persistence adapter instead of a vendored SQL/auth provider
|
|
- generated form, slot, keyed row, page-swap, and live-status commands
|
|
- page shell with plain CSS and one explicit metrics island script
|
|
- compile-time surface generation plus interaction tests
|
|
|
|
For provider-explicit boundaries, see `../../docs/recipes/sqlx-persistence.md` and `../../docs/recipes/auth-session-csrf.md`.
|
|
|
|
What it deliberately does not claim yet:
|
|
|
|
- a checked-in SQLx migration crate or database pool
|
|
- production cookie/session middleware
|
|
- a deploy target, flags, analytics, billing, or offline sync
|
|
- browser automation for the metrics island
|
|
|
|
Run:
|
|
|
|
```sh
|
|
cargo run -p hemx-saas-example
|
|
cargo test -p hemx-saas-example
|
|
```
|