-
1
-
2
-
3
-
4
-
5
-
6
-
7
-
8
-
9
-
10
-
11
-
12
-
13
-
14
-
15
-
16
-
17
-
18
-
19
-
20
-
21
-
22
-
23
-
24
-
25
-
26
-
27
-
28
-
29
-
30
-
31
-
32
-
33
-
34
-
35
-
36
-
37
-
38
-
39
-
40
-
41
-
42
-
43
-
44
-
45
-
46
-
47
-
48
-
49
-
50
-
51
-
52
-
53
-
54
= 管理者向け概要
////
SPDX-License-Identifier: AGPL-3.0-only
Copyright 2026 Shota FUJI
This program is free software: you can redistribute it and/or modify it under the terms
of the GNU Affero General Public License as published by the Free Software Foundation,
either version 3 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY
WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
PARTICULAR PURPOSE. See the GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License along
with this program. If not, see <http://www.gnu.org/licenses/>.
////
== 全体構成
Yamori はブラウザ上で動作する SPA 、 SPA 向けの静的ファイルと API を提供する HTTP/2 サーバから成り立ちます。
サーバは SQLite3 データベースにアプリケーションデータを読み書きします。
image::overview-architecture.svg[構成図]
アプリケーション側で TLS の終端を担うため、リバースプロキシを前段に設置する際は Yamori サーバ起動時にリバースプロキシが信頼する証明書を指定してください。
image::overview-reverse-proxy.svg[リバースプロキシ設置例]
== アクセス制御
アクセス制御は全て https://webassembly.org/[WebAssembly] プログラムとしてサーバに登録されます。
HTTP リクエストが来るとサーバは対応する WebAssembly 関数を実行し、返り値を基にアクセス許可判断を行います。
関数は https://flatbuffers.dev/[FlatBuffers] のバイト文字列を受け取ります。
FlatBuffers のメッセージにはログインユーザとリクエスト、サーバの状態を含むコンテキストオブジェクトが含まれています。
[source,zig]
----
// users-api-acl-wasm.zig
export fn allowV1GetUsers(buffer_ptr: [*]const u8, buffer_len: u32) bool {
const buffer = buffer_ptr[0..buffer_len];
const root = flatbuffers.decodeRoot(
yamori_users_acl.V1GetUsers, buffer,
) catch return false;
if (getAttribute(root.user.attributes, "role")) |attr| {
return std.mem.eql(u8, attr, "admin");
}
return false;
}
----