aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--.build.yml41
-rw-r--r--.gitignore1
-rw-r--r--CONTRIBUTING.md25
-rw-r--r--Cargo.lock426
-rw-r--r--Cargo.toml40
-rw-r--r--LICENSE661
-rw-r--r--Makefile92
-rw-r--r--README.md107
-rw-r--r--clippy.toml3
-rwxr-xr-xextras/estampa-ssh26
-rw-r--r--extras/nginx.conf36
-rw-r--r--src/cleanup.rs72
-rw-r--r--src/main.rs35
-rw-r--r--src/render.rs102
-rw-r--r--src/serve.rs152
15 files changed, 1819 insertions, 0 deletions
diff --git a/.build.yml b/.build.yml
new file mode 100644
index 0000000..6b2257b
--- /dev/null
+++ b/.build.yml
@@ -0,0 +1,41 @@
+image: archlinux
+packages:
+ - make
+ - minisign
+ - rsync
+ - coreutils
+ - clang
+ - lld
+ - rustup
+ - aarch64-linux-gnu-gcc
+ - tar
+ - gzip
+sources:
+ - git@git.sr.ht:~rbdr/estampa
+environment:
+ GPG_TTY: /dev/pts/0
+secrets:
+ - a1e0e3da-c1ad-473a-ad69-8878f267a628
+ - deedaf0c-1534-445d-a9b8-0910b22478b4
+ - f80356df-eb81-487f-8739-fbf08bf204dc
+ - 05763ec6-2f17-46b5-90f6-963482975b8b
+tasks:
+ - set_rust: |
+ cd estampa
+ make set_rust
+ - install_binstall: |
+ curl -L --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh | bash
+ - install_coverage_tool: |
+ cargo binstall cargo-tarpaulin --no-confirm
+ - install_builders: |
+ cargo binstall cargo-generate-rpm --no-confirm
+ cargo binstall cargo-deb --no-confirm
+ - configure_linker: |
+ cd estampa
+ mkdir -p .cargo
+ echo '[target.aarch64-unknown-linux-gnu]' > .cargo/config.toml
+ echo 'linker = "aarch64-linux-gnu-gcc"' >> .cargo/config.toml
+ echo 'rustflags = ["-C", "link-arg=-fuse-ld=lld"]' >> .cargo/config.toml
+ - package: |
+ cd estampa
+ make ci
diff --git a/.gitignore b/.gitignore
new file mode 100644
index 0000000..ea8c4bf
--- /dev/null
+++ b/.gitignore
@@ -0,0 +1 @@
+/target
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
new file mode 100644
index 0000000..5d03c71
--- /dev/null
+++ b/CONTRIBUTING.md
@@ -0,0 +1,25 @@
+# Contributing to Estampa
+
+Estampa is a personal project, as such it may not be in the best
+condition for anyone to jump in or roll their own. However, if you find
+this useful and would like to send some improvements, please feel free
+to do so. I really appreciate any contribution!
+
+## The objective of estampa
+
+The goal of stampa is to have an ephemeral pastebin that uses ssh to upload
+arbitrary files and serve them without js required.
+
+## How to contribute
+
+Above All: Be nice, always.
+
+* Ensure the linter shows no warnings or errors
+* Send patches to estampa@r.bdr.sh using [git-send-mail][git-send-mail]
+
+## Things I'd like help with
+
+* General code quality
+* Better ephemeral model
+
+[git-send-mail]: http://git-send-mail.io/
diff --git a/Cargo.lock b/Cargo.lock
new file mode 100644
index 0000000..778d53e
--- /dev/null
+++ b/Cargo.lock
@@ -0,0 +1,426 @@
+# This file is automatically @generated by Cargo.
+# It is not intended for manual editing.
+version = 4
+
+[[package]]
+name = "adler2"
+version = "2.0.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "320119579fcad9c21884f5c4861d16174d0e06250625266f50fe6898340abefa"
+
+[[package]]
+name = "aho-corasick"
+version = "1.1.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ddd31a130427c27518df266943a5308ed92d4b226cc639f5a8f1002816174301"
+dependencies = [
+ "memchr",
+]
+
+[[package]]
+name = "base64"
+version = "0.22.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6"
+
+[[package]]
+name = "bincode"
+version = "1.3.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "b1f45e9417d87227c7a56d22e471c6206462cba514c7590c09aff4cf6d1ddcad"
+dependencies = [
+ "serde",
+]
+
+[[package]]
+name = "bit-set"
+version = "0.8.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "08807e080ed7f9d5433fa9b275196cfc35414f66a0c79d864dc51a0d825231a3"
+dependencies = [
+ "bit-vec",
+]
+
+[[package]]
+name = "bit-vec"
+version = "0.8.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "5e764a1d40d510daf35e07be9eb06e75770908c27d411ee6c92109c9840eaaf7"
+
+[[package]]
+name = "cfg-if"
+version = "1.0.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801"
+
+[[package]]
+name = "crc32fast"
+version = "1.5.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "9481c1c90cbf2ac953f07c8d4a58aa3945c425b7185c9154d67a65e4230da511"
+dependencies = [
+ "cfg-if",
+]
+
+[[package]]
+name = "deranged"
+version = "0.5.8"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "7cd812cc2bc1d69d4764bd80df88b4317eaef9e773c75226407d9bc0876b211c"
+dependencies = [
+ "powerfmt",
+]
+
+[[package]]
+name = "equivalent"
+version = "1.0.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f"
+
+[[package]]
+name = "estampa"
+version = "1.0.0"
+dependencies = [
+ "syntect",
+]
+
+[[package]]
+name = "fancy-regex"
+version = "0.16.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "998b056554fbe42e03ae0e152895cd1a7e1002aec800fdc6635d20270260c46f"
+dependencies = [
+ "bit-set",
+ "regex-automata",
+ "regex-syntax",
+]
+
+[[package]]
+name = "flate2"
+version = "1.1.9"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "843fba2746e448b37e26a819579957415c8cef339bf08564fe8b7ddbd959573c"
+dependencies = [
+ "crc32fast",
+ "miniz_oxide",
+]
+
+[[package]]
+name = "fnv"
+version = "1.0.7"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1"
+
+[[package]]
+name = "hashbrown"
+version = "0.17.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4f467dd6dccf739c208452f8014c75c18bb8301b050ad1cfb27153803edb0f51"
+
+[[package]]
+name = "indexmap"
+version = "2.14.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "d466e9454f08e4a911e14806c24e16fba1b4c121d1ea474396f396069cf949d9"
+dependencies = [
+ "equivalent",
+ "hashbrown",
+]
+
+[[package]]
+name = "itoa"
+version = "1.0.18"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682"
+
+[[package]]
+name = "linked-hash-map"
+version = "0.5.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "0717cef1bc8b636c6e1c1bbdefc09e6322da8a9321966e8928ef80d20f7f770f"
+
+[[package]]
+name = "memchr"
+version = "2.8.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "f8ca58f447f06ed17d5fc4043ce1b10dd205e060fb3ce5b979b8ed8e59ff3f79"
+
+[[package]]
+name = "miniz_oxide"
+version = "0.8.9"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "1fa76a2c86f704bdb222d66965fb3d63269ce38518b83cb0575fca855ebb6316"
+dependencies = [
+ "adler2",
+ "simd-adler32",
+]
+
+[[package]]
+name = "num-conv"
+version = "0.2.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c6673768db2d862beb9b39a78fdcb1a69439615d5794a1be50caa9bc92c81967"
+
+[[package]]
+name = "once_cell"
+version = "1.21.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50"
+
+[[package]]
+name = "plist"
+version = "1.9.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "092791278e026273c1b65bbdcfbba3a300f2994c896bd01ab01da613c29c46f1"
+dependencies = [
+ "base64",
+ "indexmap",
+ "quick-xml",
+ "serde",
+ "time",
+]
+
+[[package]]
+name = "powerfmt"
+version = "0.2.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "439ee305def115ba05938db6eb1644ff94165c5ab5e9420d1c1bcedbba909391"
+
+[[package]]
+name = "proc-macro2"
+version = "1.0.106"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "8fd00f0bb2e90d81d1044c2b32617f68fcb9fa3bb7640c23e9c748e53fb30934"
+dependencies = [
+ "unicode-ident",
+]
+
+[[package]]
+name = "quick-xml"
+version = "0.39.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "958f21e8e7ceb5a1aa7fa87fab28e7c75976e0bfe7e23ff069e0a260f894067d"
+dependencies = [
+ "memchr",
+]
+
+[[package]]
+name = "quote"
+version = "1.0.45"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "41f2619966050689382d2b44f664f4bc593e129785a36d6ee376ddf37259b924"
+dependencies = [
+ "proc-macro2",
+]
+
+[[package]]
+name = "regex-automata"
+version = "0.4.14"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "6e1dd4122fc1595e8162618945476892eefca7b88c52820e74af6262213cae8f"
+dependencies = [
+ "aho-corasick",
+ "memchr",
+ "regex-syntax",
+]
+
+[[package]]
+name = "regex-syntax"
+version = "0.8.10"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "dc897dd8d9e8bd1ed8cdad82b5966c3e0ecae09fb1907d58efaa013543185d0a"
+
+[[package]]
+name = "same-file"
+version = "1.0.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "93fc1dc3aaa9bfed95e02e6eadabb4baf7e3078b0bd1b4d7b6b0b68378900502"
+dependencies = [
+ "winapi-util",
+]
+
+[[package]]
+name = "serde"
+version = "1.0.228"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "9a8e94ea7f378bd32cbbd37198a4a91436180c5bb472411e48b5ec2e2124ae9e"
+dependencies = [
+ "serde_core",
+]
+
+[[package]]
+name = "serde_core"
+version = "1.0.228"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "41d385c7d4ca58e59fc732af25c3983b67ac852c1a25000afe1175de458b67ad"
+dependencies = [
+ "serde_derive",
+]
+
+[[package]]
+name = "serde_derive"
+version = "1.0.228"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "d540f220d3187173da220f885ab66608367b6574e925011a9353e4badda91d79"
+dependencies = [
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
+[[package]]
+name = "serde_json"
+version = "1.0.149"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "83fc039473c5595ace860d8c4fafa220ff474b3fc6bfdb4293327f1a37e94d86"
+dependencies = [
+ "itoa",
+ "memchr",
+ "serde",
+ "serde_core",
+ "zmij",
+]
+
+[[package]]
+name = "simd-adler32"
+version = "0.3.9"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "703d5c7ef118737c72f1af64ad2f6f8c5e1921f818cdcb97b8fe6fc69bf66214"
+
+[[package]]
+name = "syn"
+version = "2.0.117"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "e665b8803e7b1d2a727f4023456bbbbe74da67099c585258af0ad9c5013b9b99"
+dependencies = [
+ "proc-macro2",
+ "quote",
+ "unicode-ident",
+]
+
+[[package]]
+name = "syntect"
+version = "5.3.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "656b45c05d95a5704399aeef6bd0ddec7b2b3531b7c9e900abbf7c4d2190c925"
+dependencies = [
+ "bincode",
+ "fancy-regex",
+ "flate2",
+ "fnv",
+ "once_cell",
+ "plist",
+ "regex-syntax",
+ "serde",
+ "serde_derive",
+ "serde_json",
+ "thiserror",
+ "walkdir",
+ "yaml-rust",
+]
+
+[[package]]
+name = "thiserror"
+version = "2.0.18"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4288b5bcbc7920c07a1149a35cf9590a2aa808e0bc1eafaade0b80947865fbc4"
+dependencies = [
+ "thiserror-impl",
+]
+
+[[package]]
+name = "thiserror-impl"
+version = "2.0.18"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ebc4ee7f67670e9b64d05fa4253e753e016c6c95ff35b89b7941d6b856dec1d5"
+dependencies = [
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
+[[package]]
+name = "time"
+version = "0.3.47"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "743bd48c283afc0388f9b8827b976905fb217ad9e647fae3a379a9283c4def2c"
+dependencies = [
+ "deranged",
+ "itoa",
+ "num-conv",
+ "powerfmt",
+ "serde_core",
+ "time-core",
+ "time-macros",
+]
+
+[[package]]
+name = "time-core"
+version = "0.1.8"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "7694e1cfe791f8d31026952abf09c69ca6f6fa4e1a1229e18988f06a04a12dca"
+
+[[package]]
+name = "time-macros"
+version = "0.2.27"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "2e70e4c5a0e0a8a4823ad65dfe1a6930e4f4d756dcd9dd7939022b5e8c501215"
+dependencies = [
+ "num-conv",
+ "time-core",
+]
+
+[[package]]
+name = "unicode-ident"
+version = "1.0.24"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75"
+
+[[package]]
+name = "walkdir"
+version = "2.5.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "29790946404f91d9c5d06f9874efddea1dc06c5efe94541a7d6863108e3a5e4b"
+dependencies = [
+ "same-file",
+ "winapi-util",
+]
+
+[[package]]
+name = "winapi-util"
+version = "0.1.11"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c2a7b1c03c876122aa43f3020e6c3c3ee5c05081c9a00739faf7503aeba10d22"
+dependencies = [
+ "windows-sys",
+]
+
+[[package]]
+name = "windows-link"
+version = "0.2.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5"
+
+[[package]]
+name = "windows-sys"
+version = "0.61.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ae137229bcbd6cdf0f7b80a31df61766145077ddf49416a728b02cb3921ff3fc"
+dependencies = [
+ "windows-link",
+]
+
+[[package]]
+name = "yaml-rust"
+version = "0.4.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "56c1936c4cc7a1c9ab21a1ebb602eb942ba868cbd44a99cb7cdc5892335e1c85"
+dependencies = [
+ "linked-hash-map",
+]
+
+[[package]]
+name = "zmij"
+version = "1.0.21"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "b8848ee67ecc8aedbaf3e4122217aff892639231befc6a1b58d29fff4c2cabaa"
diff --git a/Cargo.toml b/Cargo.toml
new file mode 100644
index 0000000..bdd6fa1
--- /dev/null
+++ b/Cargo.toml
@@ -0,0 +1,40 @@
+[package]
+name = "estampa"
+version = "1.0.0"
+edition = "2024"
+license = "AGPL-3.0-or-later"
+description = "A very very tiny pastebin."
+homepage = "https://r.bdr.sh/estampa.html"
+authors = ["Rubén Beltrán del Río <estampa@r.bdr.sh>"]
+
+[dependencies]
+syntect = { version = "5.2", default-features = false, features = ["default-fancy"] }
+
+[profile.release]
+strip = true
+lto = true
+panic = "abort"
+
+[package.metadata.generate-rpm]
+assets = [
+ { source = "target/release/estampa", dest = "/usr/bin/estampa", mode = "755" },
+ { source = "man/estampa.1", dest = "/usr/share/man/man1/estampa.1", mode = "644" },
+]
+
+[package.metadata.deb]
+assets = [
+ ["target/release/estampa", "/usr/bin/estampa", "755" ],
+ ["man/estampa.1", "/usr/share/man/man1/estampa.1", "644" ],
+]
+
+[lints.clippy]
+pedantic = { level = "warn", priority = -1 }
+all = "deny"
+unwrap_used = "deny"
+expect_used = "deny"
+panic = "deny"
+indexing_slicing = "deny"
+unreachable = "deny"
+undocumented_unsafe_blocks = "deny"
+unwrap_in_result = "deny"
+ok_expect = "deny"
diff --git a/LICENSE b/LICENSE
new file mode 100644
index 0000000..1e78415
--- /dev/null
+++ b/LICENSE
@@ -0,0 +1,661 @@
+GNU AFFERO GENERAL PUBLIC LICENSE
+ Version 3, 19 November 2007
+
+ Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
+ Everyone is permitted to copy and distribute verbatim copies
+ of this license document, but changing it is not allowed.
+
+ Preamble
+
+ The GNU Affero General Public License is a free, copyleft license for
+software and other kinds of works, specifically designed to ensure
+cooperation with the community in the case of network server software.
+
+ The licenses for most software and other practical works are designed
+to take away your freedom to share and change the works. By contrast,
+our General Public Licenses are intended to guarantee your freedom to
+share and change all versions of a program--to make sure it remains free
+software for all its users.
+
+ When we speak of free software, we are referring to freedom, not
+price. Our General Public Licenses are designed to make sure that you
+have the freedom to distribute copies of free software (and charge for
+them if you wish), that you receive source code or can get it if you
+want it, that you can change the software or use pieces of it in new
+free programs, and that you know you can do these things.
+
+ Developers that use our General Public Licenses protect your rights
+with two steps: (1) assert copyright on the software, and (2) offer
+you this License which gives you legal permission to copy, distribute
+and/or modify the software.
+
+ A secondary benefit of defending all users' freedom is that
+improvements made in alternate versions of the program, if they
+receive widespread use, become available for other developers to
+incorporate. Many developers of free software are heartened and
+encouraged by the resulting cooperation. However, in the case of
+software used on network servers, this result may fail to come about.
+The GNU General Public License permits making a modified version and
+letting the public access it on a server without ever releasing its
+source code to the public.
+
+ The GNU Affero General Public License is designed specifically to
+ensure that, in such cases, the modified source code becomes available
+to the community. It requires the operator of a network server to
+provide the source code of the modified version running there to the
+users of that server. Therefore, public use of a modified version, on
+a publicly accessible server, gives the public access to the source
+code of the modified version.
+
+ An older license, called the Affero General Public License and
+published by Affero, was designed to accomplish similar goals. This is
+a different license, not a version of the Affero GPL, but Affero has
+released a new version of the Affero GPL which permits relicensing under
+this license.
+
+ The precise terms and conditions for copying, distribution and
+modification follow.
+
+ TERMS AND CONDITIONS
+
+ 0. Definitions.
+
+ "This License" refers to version 3 of the GNU Affero General Public License.
+
+ "Copyright" also means copyright-like laws that apply to other kinds of
+works, such as semiconductor masks.
+
+ "The Program" refers to any copyrightable work licensed under this
+License. Each licensee is addressed as "you". "Licensees" and
+"recipients" may be individuals or organizations.
+
+ To "modify" a work means to copy from or adapt all or part of the work
+in a fashion requiring copyright permission, other than the making of an
+exact copy. The resulting work is called a "modified version" of the
+earlier work or a work "based on" the earlier work.
+
+ A "covered work" means either the unmodified Program or a work based
+on the Program.
+
+ To "propagate" a work means to do anything with it that, without
+permission, would make you directly or secondarily liable for
+infringement under applicable copyright law, except executing it on a
+computer or modifying a private copy. Propagation includes copying,
+distribution (with or without modification), making available to the
+public, and in some countries other activities as well.
+
+ To "convey" a work means any kind of propagation that enables other
+parties to make or receive copies. Mere interaction with a user through
+a computer network, with no transfer of a copy, is not conveying.
+
+ An interactive user interface displays "Appropriate Legal Notices"
+to the extent that it includes a convenient and prominently visible
+feature that (1) displays an appropriate copyright notice, and (2)
+tells the user that there is no warranty for the work (except to the
+extent that warranties are provided), that licensees may convey the
+work under this License, and how to view a copy of this License. If
+the interface presents a list of user commands or options, such as a
+menu, a prominent item in the list meets this criterion.
+
+ 1. Source Code.
+
+ The "source code" for a work means the preferred form of the work
+for making modifications to it. "Object code" means any non-source
+form of a work.
+
+ A "Standard Interface" means an interface that either is an official
+standard defined by a recognized standards body, or, in the case of
+interfaces specified for a particular programming language, one that
+is widely used among developers working in that language.
+
+ The "System Libraries" of an executable work include anything, other
+than the work as a whole, that (a) is included in the normal form of
+packaging a Major Component, but which is not part of that Major
+Component, and (b) serves only to enable use of the work with that
+Major Component, or to implement a Standard Interface for which an
+implementation is available to the public in source code form. A
+"Major Component", in this context, means a major essential component
+(kernel, window system, and so on) of the specific operating system
+(if any) on which the executable work runs, or a compiler used to
+produce the work, or an object code interpreter used to run it.
+
+ The "Corresponding Source" for a work in object code form means all
+the source code needed to generate, install, and (for an executable
+work) run the object code and to modify the work, including scripts to
+control those activities. However, it does not include the work's
+System Libraries, or general-purpose tools or generally available free
+programs which are used unmodified in performing those activities but
+which are not part of the work. For example, Corresponding Source
+includes interface definition files associated with source files for
+the work, and the source code for shared libraries and dynamically
+linked subprograms that the work is specifically designed to require,
+such as by intimate data communication or control flow between those
+subprograms and other parts of the work.
+
+ The Corresponding Source need not include anything that users
+can regenerate automatically from other parts of the Corresponding
+Source.
+
+ The Corresponding Source for a work in source code form is that
+same work.
+
+ 2. Basic Permissions.
+
+ All rights granted under this License are granted for the term of
+copyright on the Program, and are irrevocable provided the stated
+conditions are met. This License explicitly affirms your unlimited
+permission to run the unmodified Program. The output from running a
+covered work is covered by this License only if the output, given its
+content, constitutes a covered work. This License acknowledges your
+rights of fair use or other equivalent, as provided by copyright law.
+
+ You may make, run and propagate covered works that you do not
+convey, without conditions so long as your license otherwise remains
+in force. You may convey covered works to others for the sole purpose
+of having them make modifications exclusively for you, or provide you
+with facilities for running those works, provided that you comply with
+the terms of this License in conveying all material for which you do
+not control copyright. Those thus making or running the covered works
+for you must do so exclusively on your behalf, under your direction
+and control, on terms that prohibit them from making any copies of
+your copyrighted material outside their relationship with you.
+
+ Conveying under any other circumstances is permitted solely under
+the conditions stated below. Sublicensing is not allowed; section 10
+makes it unnecessary.
+
+ 3. Protecting Users' Legal Rights From Anti-Circumvention Law.
+
+ No covered work shall be deemed part of an effective technological
+measure under any applicable law fulfilling obligations under article
+11 of the WIPO copyright treaty adopted on 20 December 1996, or
+similar laws prohibiting or restricting circumvention of such
+measures.
+
+ When you convey a covered work, you waive any legal power to forbid
+circumvention of technological measures to the extent such circumvention
+is effected by exercising rights under this License with respect to
+the covered work, and you disclaim any intention to limit operation or
+modification of the work as a means of enforcing, against the work's
+users, your or third parties' legal rights to forbid circumvention of
+technological measures.
+
+ 4. Conveying Verbatim Copies.
+
+ You may convey verbatim copies of the Program's source code as you
+receive it, in any medium, provided that you conspicuously and
+appropriately publish on each copy an appropriate copyright notice;
+keep intact all notices stating that this License and any
+non-permissive terms added in accord with section 7 apply to the code;
+keep intact all notices of the absence of any warranty; and give all
+recipients a copy of this License along with the Program.
+
+ You may charge any price or no price for each copy that you convey,
+and you may offer support or warranty protection for a fee.
+
+ 5. Conveying Modified Source Versions.
+
+ You may convey a work based on the Program, or the modifications to
+produce it from the Program, in the form of source code under the
+terms of section 4, provided that you also meet all of these conditions:
+
+ a) The work must carry prominent notices stating that you modified
+ it, and giving a relevant date.
+
+ b) The work must carry prominent notices stating that it is
+ released under this License and any conditions added under section
+ 7. This requirement modifies the requirement in section 4 to
+ "keep intact all notices".
+
+ c) You must license the entire work, as a whole, under this
+ License to anyone who comes into possession of a copy. This
+ License will therefore apply, along with any applicable section 7
+ additional terms, to the whole of the work, and all its parts,
+ regardless of how they are packaged. This License gives no
+ permission to license the work in any other way, but it does not
+ invalidate such permission if you have separately received it.
+
+ d) If the work has interactive user interfaces, each must display
+ Appropriate Legal Notices; however, if the Program has interactive
+ interfaces that do not display Appropriate Legal Notices, your
+ work need not make them do so.
+
+ A compilation of a covered work with other separate and independent
+works, which are not by their nature extensions of the covered work,
+and which are not combined with it such as to form a larger program,
+in or on a volume of a storage or distribution medium, is called an
+"aggregate" if the compilation and its resulting copyright are not
+used to limit the access or legal rights of the compilation's users
+beyond what the individual works permit. Inclusion of a covered work
+in an aggregate does not cause this License to apply to the other
+parts of the aggregate.
+
+ 6. Conveying Non-Source Forms.
+
+ You may convey a covered work in object code form under the terms
+of sections 4 and 5, provided that you also convey the
+machine-readable Corresponding Source under the terms of this License,
+in one of these ways:
+
+ a) Convey the object code in, or embodied in, a physical product
+ (including a physical distribution medium), accompanied by the
+ Corresponding Source fixed on a durable physical medium
+ customarily used for software interchange.
+
+ b) Convey the object code in, or embodied in, a physical product
+ (including a physical distribution medium), accompanied by a
+ written offer, valid for at least three years and valid for as
+ long as you offer spare parts or customer support for that product
+ model, to give anyone who possesses the object code either (1) a
+ copy of the Corresponding Source for all the software in the
+ product that is covered by this License, on a durable physical
+ medium customarily used for software interchange, for a price no
+ more than your reasonable cost of physically performing this
+ conveying of source, or (2) access to copy the
+ Corresponding Source from a network server at no charge.
+
+ c) Convey individual copies of the object code with a copy of the
+ written offer to provide the Corresponding Source. This
+ alternative is allowed only occasionally and noncommercially, and
+ only if you received the object code with such an offer, in accord
+ with subsection 6b.
+
+ d) Convey the object code by offering access from a designated
+ place (gratis or for a charge), and offer equivalent access to the
+ Corresponding Source in the same way through the same place at no
+ further charge. You need not require recipients to copy the
+ Corresponding Source along with the object code. If the place to
+ copy the object code is a network server, the Corresponding Source
+ may be on a different server (operated by you or a third party)
+ that supports equivalent copying facilities, provided you maintain
+ clear directions next to the object code saying where to find the
+ Corresponding Source. Regardless of what server hosts the
+ Corresponding Source, you remain obligated to ensure that it is
+ available for as long as needed to satisfy these requirements.
+
+ e) Convey the object code using peer-to-peer transmission, provided
+ you inform other peers where the object code and Corresponding
+ Source of the work are being offered to the general public at no
+ charge under subsection 6d.
+
+ A separable portion of the object code, whose source code is excluded
+from the Corresponding Source as a System Library, need not be
+included in conveying the object code work.
+
+ A "User Product" is either (1) a "consumer product", which means any
+tangible personal property which is normally used for personal, family,
+or household purposes, or (2) anything designed or sold for incorporation
+into a dwelling. In determining whether a product is a consumer product,
+doubtful cases shall be resolved in favor of coverage. For a particular
+product received by a particular user, "normally used" refers to a
+typical or common use of that class of product, regardless of the status
+of the particular user or of the way in which the particular user
+actually uses, or expects or is expected to use, the product. A product
+is a consumer product regardless of whether the product has substantial
+commercial, industrial or non-consumer uses, unless such uses represent
+the only significant mode of use of the product.
+
+ "Installation Information" for a User Product means any methods,
+procedures, authorization keys, or other information required to install
+and execute modified versions of a covered work in that User Product from
+a modified version of its Corresponding Source. The information must
+suffice to ensure that the continued functioning of the modified object
+code is in no case prevented or interfered with solely because
+modification has been made.
+
+ If you convey an object code work under this section in, or with, or
+specifically for use in, a User Product, and the conveying occurs as
+part of a transaction in which the right of possession and use of the
+User Product is transferred to the recipient in perpetuity or for a
+fixed term (regardless of how the transaction is characterized), the
+Corresponding Source conveyed under this section must be accompanied
+by the Installation Information. But this requirement does not apply
+if neither you nor any third party retains the ability to install
+modified object code on the User Product (for example, the work has
+been installed in ROM).
+
+ The requirement to provide Installation Information does not include a
+requirement to continue to provide support service, warranty, or updates
+for a work that has been modified or installed by the recipient, or for
+the User Product in which it has been modified or installed. Access to a
+network may be denied when the modification itself materially and
+adversely affects the operation of the network or violates the rules and
+protocols for communication across the network.
+
+ Corresponding Source conveyed, and Installation Information provided,
+in accord with this section must be in a format that is publicly
+documented (and with an implementation available to the public in
+source code form), and must require no special password or key for
+unpacking, reading or copying.
+
+ 7. Additional Terms.
+
+ "Additional permissions" are terms that supplement the terms of this
+License by making exceptions from one or more of its conditions.
+Additional permissions that are applicable to the entire Program shall
+be treated as though they were included in this License, to the extent
+that they are valid under applicable law. If additional permissions
+apply only to part of the Program, that part may be used separately
+under those permissions, but the entire Program remains governed by
+this License without regard to the additional permissions.
+
+ When you convey a copy of a covered work, you may at your option
+remove any additional permissions from that copy, or from any part of
+it. (Additional permissions may be written to require their own
+removal in certain cases when you modify the work.) You may place
+additional permissions on material, added by you to a covered work,
+for which you have or can give appropriate copyright permission.
+
+ Notwithstanding any other provision of this License, for material you
+add to a covered work, you may (if authorized by the copyright holders of
+that material) supplement the terms of this License with terms:
+
+ a) Disclaiming warranty or limiting liability differently from the
+ terms of sections 15 and 16 of this License; or
+
+ b) Requiring preservation of specified reasonable legal notices or
+ author attributions in that material or in the Appropriate Legal
+ Notices displayed by works containing it; or
+
+ c) Prohibiting misrepresentation of the origin of that material, or
+ requiring that modified versions of such material be marked in
+ reasonable ways as different from the original version; or
+
+ d) Limiting the use for publicity purposes of names of licensors or
+ authors of the material; or
+
+ e) Declining to grant rights under trademark law for use of some
+ trade names, trademarks, or service marks; or
+
+ f) Requiring indemnification of licensors and authors of that
+ material by anyone who conveys the material (or modified versions of
+ it) with contractual assumptions of liability to the recipient, for
+ any liability that these contractual assumptions directly impose on
+ those licensors and authors.
+
+ All other non-permissive additional terms are considered "further
+restrictions" within the meaning of section 10. If the Program as you
+received it, or any part of it, contains a notice stating that it is
+governed by this License along with a term that is a further
+restriction, you may remove that term. If a license document contains
+a further restriction but permits relicensing or conveying under this
+License, you may add to a covered work material governed by the terms
+of that license document, provided that the further restriction does
+not survive such relicensing or conveying.
+
+ If you add terms to a covered work in accord with this section, you
+must place, in the relevant source files, a statement of the
+additional terms that apply to those files, or a notice indicating
+where to find the applicable terms.
+
+ Additional terms, permissive or non-permissive, may be stated in the
+form of a separately written license, or stated as exceptions;
+the above requirements apply either way.
+
+ 8. Termination.
+
+ You may not propagate or modify a covered work except as expressly
+provided under this License. Any attempt otherwise to propagate or
+modify it is void, and will automatically terminate your rights under
+this License (including any patent licenses granted under the third
+paragraph of section 11).
+
+ However, if you cease all violation of this License, then your
+license from a particular copyright holder is reinstated (a)
+provisionally, unless and until the copyright holder explicitly and
+finally terminates your license, and (b) permanently, if the copyright
+holder fails to notify you of the violation by some reasonable means
+prior to 60 days after the cessation.
+
+ Moreover, your license from a particular copyright holder is
+reinstated permanently if the copyright holder notifies you of the
+violation by some reasonable means, this is the first time you have
+received notice of violation of this License (for any work) from that
+copyright holder, and you cure the violation prior to 30 days after
+your receipt of the notice.
+
+ Termination of your rights under this section does not terminate the
+licenses of parties who have received copies or rights from you under
+this License. If your rights have been terminated and not permanently
+reinstated, you do not qualify to receive new licenses for the same
+material under section 10.
+
+ 9. Acceptance Not Required for Having Copies.
+
+ You are not required to accept this License in order to receive or
+run a copy of the Program. Ancillary propagation of a covered work
+occurring solely as a consequence of using peer-to-peer transmission
+to receive a copy likewise does not require acceptance. However,
+nothing other than this License grants you permission to propagate or
+modify any covered work. These actions infringe copyright if you do
+not accept this License. Therefore, by modifying or propagating a
+covered work, you indicate your acceptance of this License to do so.
+
+ 10. Automatic Licensing of Downstream Recipients.
+
+ Each time you convey a covered work, the recipient automatically
+receives a license from the original licensors, to run, modify and
+propagate that work, subject to this License. You are not responsible
+for enforcing compliance by third parties with this License.
+
+ An "entity transaction" is a transaction transferring control of an
+organization, or substantially all assets of one, or subdividing an
+organization, or merging organizations. If propagation of a covered
+work results from an entity transaction, each party to that
+transaction who receives a copy of the work also receives whatever
+licenses to the work the party's predecessor in interest had or could
+give under the previous paragraph, plus a right to possession of the
+Corresponding Source of the work from the predecessor in interest, if
+the predecessor has it or can get it with reasonable efforts.
+
+ You may not impose any further restrictions on the exercise of the
+rights granted or affirmed under this License. For example, you may
+not impose a license fee, royalty, or other charge for exercise of
+rights granted under this License, and you may not initiate litigation
+(including a cross-claim or counterclaim in a lawsuit) alleging that
+any patent claim is infringed by making, using, selling, offering for
+sale, or importing the Program or any portion of it.
+
+ 11. Patents.
+
+ A "contributor" is a copyright holder who authorizes use under this
+License of the Program or a work on which the Program is based. The
+work thus licensed is called the contributor's "contributor version".
+
+ A contributor's "essential patent claims" are all patent claims
+owned or controlled by the contributor, whether already acquired or
+hereafter acquired, that would be infringed by some manner, permitted
+by this License, of making, using, or selling its contributor version,
+but do not include claims that would be infringed only as a
+consequence of further modification of the contributor version. For
+purposes of this definition, "control" includes the right to grant
+patent sublicenses in a manner consistent with the requirements of
+this License.
+
+ Each contributor grants you a non-exclusive, worldwide, royalty-free
+patent license under the contributor's essential patent claims, to
+make, use, sell, offer for sale, import and otherwise run, modify and
+propagate the contents of its contributor version.
+
+ In the following three paragraphs, a "patent license" is any express
+agreement or commitment, however denominated, not to enforce a patent
+(such as an express permission to practice a patent or covenant not to
+sue for patent infringement). To "grant" such a patent license to a
+party means to make such an agreement or commitment not to enforce a
+patent against the party.
+
+ If you convey a covered work, knowingly relying on a patent license,
+and the Corresponding Source of the work is not available for anyone
+to copy, free of charge and under the terms of this License, through a
+publicly available network server or other readily accessible means,
+then you must either (1) cause the Corresponding Source to be so
+available, or (2) arrange to deprive yourself of the benefit of the
+patent license for this particular work, or (3) arrange, in a manner
+consistent with the requirements of this License, to extend the patent
+license to downstream recipients. "Knowingly relying" means you have
+actual knowledge that, but for the patent license, your conveying the
+covered work in a country, or your recipient's use of the covered work
+in a country, would infringe one or more identifiable patents in that
+country that you have reason to believe are valid.
+
+ If, pursuant to or in connection with a single transaction or
+arrangement, you convey, or propagate by procuring conveyance of, a
+covered work, and grant a patent license to some of the parties
+receiving the covered work authorizing them to use, propagate, modify
+or convey a specific copy of the covered work, then the patent license
+you grant is automatically extended to all recipients of the covered
+work and works based on it.
+
+ A patent license is "discriminatory" if it does not include within
+the scope of its coverage, prohibits the exercise of, or is
+conditioned on the non-exercise of one or more of the rights that are
+specifically granted under this License. You may not convey a covered
+work if you are a party to an arrangement with a third party that is
+in the business of distributing software, under which you make payment
+to the third party based on the extent of your activity of conveying
+the work, and under which the third party grants, to any of the
+parties who would receive the covered work from you, a discriminatory
+patent license (a) in connection with copies of the covered work
+conveyed by you (or copies made from those copies), or (b) primarily
+for and in connection with specific products or compilations that
+contain the covered work, unless you entered into that arrangement,
+or that patent license was granted, prior to 28 March 2007.
+
+ Nothing in this License shall be construed as excluding or limiting
+any implied license or other defenses to infringement that may
+otherwise be available to you under applicable patent law.
+
+ 12. No Surrender of Others' Freedom.
+
+ If conditions are imposed on you (whether by court order, agreement or
+otherwise) that contradict the conditions of this License, they do not
+excuse you from the conditions of this License. If you cannot convey a
+covered work so as to satisfy simultaneously your obligations under this
+License and any other pertinent obligations, then as a consequence you may
+not convey it at all. For example, if you agree to terms that obligate you
+to collect a royalty for further conveying from those to whom you convey
+the Program, the only way you could satisfy both those terms and this
+License would be to refrain entirely from conveying the Program.
+
+ 13. Remote Network Interaction; Use with the GNU General Public License.
+
+ Notwithstanding any other provision of this License, if you modify the
+Program, your modified version must prominently offer all users
+interacting with it remotely through a computer network (if your version
+supports such interaction) an opportunity to receive the Corresponding
+Source of your version by providing access to the Corresponding Source
+from a network server at no charge, through some standard or customary
+means of facilitating copying of software. This Corresponding Source
+shall include the Corresponding Source for any work covered by version 3
+of the GNU General Public License that is incorporated pursuant to the
+following paragraph.
+
+ Notwithstanding any other provision of this License, you have
+permission to link or combine any covered work with a work licensed
+under version 3 of the GNU General Public License into a single
+combined work, and to convey the resulting work. The terms of this
+License will continue to apply to the part which is the covered work,
+but the work with which it is combined will remain governed by version
+3 of the GNU General Public License.
+
+ 14. Revised Versions of this License.
+
+ The Free Software Foundation may publish revised and/or new versions of
+the GNU Affero General Public License from time to time. Such new versions
+will be similar in spirit to the present version, but may differ in detail to
+address new problems or concerns.
+
+ Each version is given a distinguishing version number. If the
+Program specifies that a certain numbered version of the GNU Affero General
+Public License "or any later version" applies to it, you have the
+option of following the terms and conditions either of that numbered
+version or of any later version published by the Free Software
+Foundation. If the Program does not specify a version number of the
+GNU Affero General Public License, you may choose any version ever published
+by the Free Software Foundation.
+
+ If the Program specifies that a proxy can decide which future
+versions of the GNU Affero General Public License can be used, that proxy's
+public statement of acceptance of a version permanently authorizes you
+to choose that version for the Program.
+
+ Later license versions may give you additional or different
+permissions. However, no additional obligations are imposed on any
+author or copyright holder as a result of your choosing to follow a
+later version.
+
+ 15. Disclaimer of Warranty.
+
+ THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
+APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
+HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY
+OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO,
+THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
+IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF
+ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
+
+ 16. Limitation of Liability.
+
+ IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
+WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS
+THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY
+GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE
+USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF
+DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD
+PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS),
+EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF
+SUCH DAMAGES.
+
+ 17. Interpretation of Sections 15 and 16.
+
+ If the disclaimer of warranty and limitation of liability provided
+above cannot be given local legal effect according to their terms,
+reviewing courts shall apply local law that most closely approximates
+an absolute waiver of all civil liability in connection with the
+Program, unless a warranty or assumption of liability accompanies a
+copy of the Program in return for a fee.
+
+ END OF TERMS AND CONDITIONS
+
+ How to Apply These Terms to Your New Programs
+
+ If you develop a new program, and you want it to be of the greatest
+possible use to the public, the best way to achieve this is to make it
+free software which everyone can redistribute and change under these terms.
+
+ To do so, attach the following notices to the program. It is safest
+to attach them to the start of each source file to most effectively
+state the exclusion of warranty; and each file should have at least
+the "copyright" line and a pointer to where the full notice is found.
+
+ Estampa, friend-to-friend application platform.
+ Copyright (C) 2026 Ruben Beltran del Rio
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published
+ by the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see <https://www.gnu.org/licenses/>.
+
+Also add information on how to contact you by electronic and paper mail.
+
+ If your software can interact with users remotely through a computer
+network, you should also make sure that it provides a way for users to
+get its source. For example, if your program is a web application, its
+interface could display a "Source" link that leads users to an archive
+of the code. There are many ways you could offer source, and different
+solutions will be better for different programs; see section 13 for the
+specific requirements.
+
+ You should also get your employer (if you work as a programmer) or school,
+if any, to sign a "copyright disclaimer" for the program, if necessary.
+For more information on this, and how to apply and follow the GNU AGPL, see
+<https://www.gnu.org/licenses/>.
diff --git a/Makefile b/Makefile
new file mode 100644
index 0000000..aeb2434
--- /dev/null
+++ b/Makefile
@@ -0,0 +1,92 @@
+profile := dev
+target = $(shell rustc -vV | grep host | awk '{print $$2}')
+architectures := x86_64-unknown-linux-gnu aarch64-unknown-linux-gnu
+app_name := estampa
+deploy_host := deploy@conchos.bdr.sh
+deploy_path := /srv/http/build.r.bdr.sh/$(app_name)
+
+define sign_and_deploy
+ @./scripts/sign.sh "$(1)" "$(channel)" "$(architecture)"
+ rsync -avz $(1) $(deploy_host):$(deploy_path)
+ rsync -avz $(1).minisig $(deploy_host):$(deploy_path)
+endef
+
+default: build
+
+set_rust:
+ rustup default stable
+
+prepare:
+ rustup target add $(target)
+
+build: prepare
+ cargo build --profile $(profile) --target $(target)
+
+test:
+ cargo test
+
+coverage:
+ cargo tarpaulin
+
+format:
+ cargo fmt && cargo clippy --fix
+
+lint:
+ cargo fmt -- --check && cargo clippy
+
+audit:
+ cargo vet
+ # cargo crev verify --show-all
+
+supply-chain-report:
+ cargo supply-chain publishers
+
+release: rpm tar deb
+ @$(eval filename := $(app_name)-$(target)-$(channel))
+
+$(architectures):
+ifneq ($(channel),)
+ $(MAKE) -e channel=$(channel) -e target=$@ release
+else
+ $(MAKE) -e target=$@ build
+endif
+
+deb: build
+ifeq ($(findstring linux,$(target)),linux)
+ @$(eval filename := $(app_name)-$(target)-$(channel))
+ cargo deb --profile $(profile) --target $(target)
+ mv target/$(target)/debian/*.deb $(filename).deb
+ @$(call sign_and_deploy,$(filename).deb)
+endif
+
+rpm: build
+ifeq ($(findstring linux,$(target)),linux)
+ @$(eval filename := $(app_name)-$(target)-$(channel))
+ cargo generate-rpm --profile $(profile) --target $(target)
+ mv target/$(target)/generate-rpm/*.rpm $(filename).rpm
+ @$(call sign_and_deploy,$(filename).rpm)
+endif
+
+tar: build
+ @$(eval filename := $(app_name)-$(target)-$(channel))
+ tar -czvf $(filename).tar.gz -C target/$(target)/$(profile)/ $(app_name)
+ @$(call sign_and_deploy,$(filename).tar.gz)
+
+package: $(architectures)
+
+mac:
+ @$(eval mac_architectures := x86_64-apple-darwin aarch64-apple-darwin)
+ifeq ($(tag),)
+ $(MAKE) -e profile=release -e architectures='$(mac_architectures)' -e channel=unstable package
+else
+ $(MAKE) -e profile=release -e architectures='$(mac_architectures)' -e channel=$(tag) package
+endif
+
+ci: lint coverage
+ifeq ($(GIT_REF),refs/heads/main)
+ $(MAKE) -e profile=release -e channel=unstable package
+else ifneq (,$(findstring refs/tags/,$(GIT_REF)))
+ $(MAKE) -e profile=release -e channel=$(subst refs/tags/,,$(GIT_REF)) package
+endif
+
+.PHONY: default build $(architectures) rpm package prepare set_rust ci release
diff --git a/README.md b/README.md
new file mode 100644
index 0000000..2cce13b
--- /dev/null
+++ b/README.md
@@ -0,0 +1,107 @@
+# estampa
+
+A very very tiny pastebin. Files are uploaded over `scp` and served as
+syntax-highlighted HTML by a CGI handler in front of nginx. Pastes
+expire after a week. No JavaScript ever involved!
+
+## How it works
+
+Estampa is a single binary with two modes:
+
+- `estampa`: CGI handler (no arguments). Reads `DOCUMENT_ROOT` and
+ `DOCUMENT_URI` from the environment, joins them safely, and writes a
+ CGI response to stdout.
+- `estampa --run <directory>`: Deletes regular files in `<directory>` whose
+ mtime is more than seven days old.
+
+The serving side is text-only. Anything that doesn't decode as UTF-8
+returns 404.
+
+## Install
+
+Build from source:
+
+```sh
+cargo build --release
+sudo install -m 755 target/release/estampa /usr/bin/estampa
+```
+
+Prebuilt packages are available on [build.r.bdr.sh][build].
+
+## Serving (nginx + fcgiwrap)
+
+`estampa` with no arguments is a CGI program.
+See [`extras/nginx.conf`](extras/nginx.conf).
+
+```nginx
+server {
+ listen 80;
+ server_name paste.example.com;
+
+ root /srv/estampa;
+
+ # Only serve top-level, non-dotfile names.
+ location ~ /\. { return 404; } # .ssh/, .bashrc, ...
+ location ~ /.+/ { return 404; } # anything inside a subdirectory
+
+ location / {
+ fastcgi_pass unix:/run/fcgiwrap.socket;
+ include fastcgi_params;
+ fastcgi_param SCRIPT_FILENAME /usr/bin/estampa;
+ }
+}
+```
+
+Status codes:
+
+| code | when |
+| ---- | ----------------------------------------------------------------- |
+| 200 | file exists, is a regular top-level file, and is valid UTF-8 |
+| 404 | file is missing, in a subdirectory, starts with `.`, isn't a regular file, isn't valid UTF-8, or the request escapes the root |
+| 500 | `DOCUMENT_ROOT` not set, or read error |
+
+## Uploading and expiring (scp + ssh)
+
+The smoothest setup is a dedicated `estampa` user whose home directory
+*is* the paste root, so uploads need no destination path:
+
+```sh
+scp paste.txt estampa@paste.example.com:
+# https://paste.example.com/paste.txt
+```
+
+To wire that up:
+
+```sh
+sudo install -d -m 755 /srv/estampa
+sudo useradd estampa -s /usr/sbin/nologin --home /srv/http/estampa
+sudo chown estampa:estampa /srv/estampa
+sudo install -d -m 700 -o estampa -g estampa /srv/estampa/.ssh
+sudo -u estampa touch /srv/estampa/.ssh/authorized_keys
+sudo chmod 600 /srv/estampa/.ssh/authorized_keys
+```
+
+Add the upload key to `/srv/estampa/.ssh/authorized_keys` with the
+forced-command wrapper from [`extras/estampa-ssh`](extras/estampa-ssh):
+
+```
+command="/usr/local/bin/estampa-ssh /srv/estampa",no-pty,no-agent-forwarding,no-port-forwarding,no-X11-forwarding ssh-ed25519 AAAA... uploader
+```
+
+That wrapper runs `estampa --run "$1"` as a side-effect of every
+incoming session and then `exec`s the original `scp` or `sftp-server`
+the client wanted, so a normal upload also triggers a cleanup pass.
+`--run` only looks at the top level of the directory, so subdirectories
+(like `.ssh/`) are not traversed and not deleted.
+
+Because the upload account's home lives inside the web root, the nginx
+config in `extras/nginx.conf` returns 404 for any dotfile-prefixed path
+— that's what keeps `/.ssh/authorized_keys` and friends private.
+
+## Development
+
+Build with `make`.
+Test with `make test`
+Lint with `make lint`
+
+[build]: https://build.r.bdr.sh/estampa
diff --git a/clippy.toml b/clippy.toml
new file mode 100644
index 0000000..4c47523
--- /dev/null
+++ b/clippy.toml
@@ -0,0 +1,3 @@
+allow-panic-in-tests = true
+allow-unwrap-in-tests = true
+allow-expect-in-tests = true
diff --git a/extras/estampa-ssh b/extras/estampa-ssh
new file mode 100755
index 0000000..f1cbd08
--- /dev/null
+++ b/extras/estampa-ssh
@@ -0,0 +1,26 @@
+#!/bin/sh
+# estampa-ssh: forced command for the upload account in ~/.ssh/authorized_keys.
+#
+# Usage in authorized_keys:
+# command="/usr/local/bin/estampa-ssh /srv/estampa/pastes",no-pty,no-agent-forwarding,no-port-forwarding,no-X11-forwarding ssh-ed25519 AAAA... uploader
+#
+# On every incoming SSH session this:
+# 1. prunes pastes older than one week from $1 (best-effort, never blocks),
+# 2. then exec's the original scp/sftp command the client wanted to run.
+# Any other command is rejected.
+
+set -eu
+
+PASTE_DIR="${1:?usage: estampa-ssh <paste-dir>}"
+
+estampa --run "$PASTE_DIR" >/dev/null 2>&1 || true
+
+case "${SSH_ORIGINAL_COMMAND:-}" in
+ "scp -t "*|"scp -f "*|"/usr/lib/openssh/sftp-server"|"internal-sftp")
+ exec $SSH_ORIGINAL_COMMAND
+ ;;
+ *)
+ echo "estampa-ssh: only scp/sftp uploads are allowed" >&2
+ exit 1
+ ;;
+esac
diff --git a/extras/nginx.conf b/extras/nginx.conf
new file mode 100644
index 0000000..0afc365
--- /dev/null
+++ b/extras/nginx.conf
@@ -0,0 +1,36 @@
+# Example nginx server block for estampa.
+#
+# estampa speaks CGI: when invoked with no arguments it reads
+# DOCUMENT_ROOT and DOCUMENT_URI from the env (both populated by
+# nginx's stock fastcgi_params) and serves the file at
+# $document_root$document_uri as a syntax-highlighted HTML page.
+# Files that aren't valid UTF-8 return 404.
+#
+# Pastes live under the `root` directory below; uploading via scp
+# is enough to publish a new paste, and `estampa --run` is what
+# expires them (see extras/estampa-ssh).
+#
+# Requires fcgiwrap (or any CGI-over-FastCGI gateway).
+
+server {
+ listen 80;
+ server_name paste.example.com;
+
+ # Where pastes live. Change to taste.
+ # If this is also the home directory of an upload account (see
+ # README), the dotfile guard below is what keeps .ssh/ private.
+ root /srv/estampa;
+
+ # Estampa only serves top-level, non-dotfile names. These rules
+ # short-circuit obvious misses so the CGI doesn't even fork.
+ location ~ /\. { return 404; } # dotfiles (.ssh/, .bashrc, ...)
+ location ~ /.+/ { return 404; } # anything inside a subdirectory
+
+ location / {
+ fastcgi_pass unix:/run/fcgiwrap.socket;
+ include fastcgi_params;
+
+ # No wrapper script needed: estampa with no args is the CGI mode.
+ fastcgi_param SCRIPT_FILENAME /usr/bin/estampa;
+ }
+}
diff --git a/src/cleanup.rs b/src/cleanup.rs
new file mode 100644
index 0000000..4856400
--- /dev/null
+++ b/src/cleanup.rs
@@ -0,0 +1,72 @@
+use std::fs;
+use std::path::Path;
+use std::process::ExitCode;
+use std::time::{Duration, SystemTime};
+
+const ONE_WEEK: Duration = Duration::from_secs(7 * 24 * 60 * 60);
+
+pub fn run(dir: &str) -> ExitCode {
+ let entries = match fs::read_dir(Path::new(dir)) {
+ Ok(e) => e,
+ Err(e) => {
+ eprintln!("estampa: cannot read directory '{dir}': {e}");
+ return ExitCode::from(1);
+ }
+ };
+
+ let now = SystemTime::now();
+ let mut had_error = false;
+
+ for entry in entries {
+ let entry = match entry {
+ Ok(e) => e,
+ Err(e) => {
+ eprintln!("estampa: cannot read directory entry: {e}");
+ had_error = true;
+ continue;
+ }
+ };
+
+ let path = entry.path();
+
+ // symlink_metadata so we never follow links out of the dir
+ let metadata = match entry.path().symlink_metadata() {
+ Ok(m) => m,
+ Err(e) => {
+ eprintln!("estampa: cannot stat '{}': {e}", path.display());
+ had_error = true;
+ continue;
+ }
+ };
+
+ if !metadata.is_file() {
+ continue;
+ }
+
+ let modified = match metadata.modified() {
+ Ok(m) => m,
+ Err(e) => {
+ eprintln!("estampa: cannot read mtime for '{}': {e}", path.display());
+ had_error = true;
+ continue;
+ }
+ };
+
+ let Ok(age) = now.duration_since(modified) else {
+ continue;
+ };
+
+ if age > ONE_WEEK
+ && let Err(e) = fs::remove_file(&path)
+ {
+ eprintln!("estampa: cannot remove '{}': {e}", path.display());
+ had_error = true;
+ }
+ }
+
+ if had_error {
+ ExitCode::from(1)
+ } else {
+ ExitCode::SUCCESS
+ }
+}
diff --git a/src/main.rs b/src/main.rs
new file mode 100644
index 0000000..223fd24
--- /dev/null
+++ b/src/main.rs
@@ -0,0 +1,35 @@
+use std::env;
+use std::process::ExitCode;
+
+mod cleanup;
+mod render;
+mod serve;
+
+fn main() -> ExitCode {
+ let args: Vec<String> = env::args().collect();
+ let command = args.get(1).map(String::as_str);
+
+ match command {
+ None => serve::run(),
+ Some("--run") => {
+ if let Some(dir) = args.get(2) {
+ cleanup::run(dir)
+ } else {
+ eprintln!("estampa: --run requires a directory argument");
+ print_usage();
+ ExitCode::from(2)
+ }
+ }
+ Some(other) => {
+ eprintln!("estampa: unknown argument '{other}'");
+ print_usage();
+ ExitCode::from(2)
+ }
+ }
+}
+
+fn print_usage() {
+ eprintln!("usage:");
+ eprintln!(" estampa serve a paste via CGI (DOCUMENT_ROOT + DOCUMENT_URI)");
+ eprintln!(" estampa --run <directory> delete files older than one week");
+}
diff --git a/src/render.rs b/src/render.rs
new file mode 100644
index 0000000..8e366dd
--- /dev/null
+++ b/src/render.rs
@@ -0,0 +1,102 @@
+use std::path::Path;
+
+use syntect::highlighting::ThemeSet;
+use syntect::html::highlighted_html_for_string;
+use syntect::parsing::SyntaxSet;
+
+const THEME: &str = "base16-ocean.dark";
+const STYLE: &str = "html,body{margin:0;background:#2b303b}\
+pre{margin:0;padding:1rem;font:14px/1.5 ui-monospace,SFMono-Regular,Menlo,monospace;overflow:auto}";
+
+pub fn page(path: &Path, text: &str) -> String {
+ let title = path
+ .file_name()
+ .and_then(|n| n.to_str())
+ .unwrap_or("paste");
+
+ let body = highlight(path, text);
+
+ let mut out = String::with_capacity(body.len() + 256);
+ out.push_str("<!doctype html>\n<meta charset=\"utf-8\">\n<title>");
+ push_escaped(&mut out, title);
+ out.push_str("</title>\n<style>");
+ out.push_str(STYLE);
+ out.push_str("</style>\n");
+ out.push_str(&body);
+ out.push('\n');
+ out
+}
+
+fn highlight(path: &Path, text: &str) -> String {
+ let syntaxes = SyntaxSet::load_defaults_newlines();
+ let themes = ThemeSet::load_defaults();
+
+ let syntax = path
+ .extension()
+ .and_then(|e| e.to_str())
+ .and_then(|e| syntaxes.find_syntax_by_extension(e))
+ .or_else(|| syntaxes.find_syntax_by_first_line(text))
+ .unwrap_or_else(|| syntaxes.find_syntax_plain_text());
+
+ let Some(theme) = themes.themes.get(THEME) else {
+ return fallback_pre(text);
+ };
+
+ match highlighted_html_for_string(text, &syntaxes, syntax, theme) {
+ Ok(html) => html,
+ Err(_) => fallback_pre(text),
+ }
+}
+
+fn fallback_pre(text: &str) -> String {
+ let mut out = String::with_capacity(text.len() + 16);
+ out.push_str("<pre>");
+ push_escaped(&mut out, text);
+ out.push_str("</pre>");
+ out
+}
+
+fn push_escaped(out: &mut String, s: &str) {
+ for c in s.chars() {
+ match c {
+ '&' => out.push_str("&amp;"),
+ '<' => out.push_str("&lt;"),
+ '>' => out.push_str("&gt;"),
+ '"' => out.push_str("&quot;"),
+ '\'' => out.push_str("&#39;"),
+ other => out.push(other),
+ }
+ }
+}
+
+#[cfg(test)]
+mod tests {
+ use super::*;
+
+ #[test]
+ fn page_contains_filename_in_title() {
+ let html = page(Path::new("/srv/x.rs"), "fn main() {}\n");
+ assert!(html.contains("<title>x.rs</title>"));
+ }
+
+ #[test]
+ fn page_escapes_filename() {
+ let html = page(Path::new("/srv/<script>.txt"), "hi");
+ assert!(html.contains("&lt;script&gt;.txt"));
+ assert!(!html.contains("<title><script>"));
+ }
+
+ #[test]
+ fn page_emits_pre_block() {
+ let html = page(Path::new("/srv/x.txt"), "hello");
+ assert!(html.contains("<pre"));
+ assert!(html.contains("hello"));
+ }
+
+ #[test]
+ fn page_highlights_known_extension() {
+ // Rust syntax should produce styled spans, not just a plain <pre>hello</pre>.
+ let html = page(Path::new("/srv/x.rs"), "fn main() {}\n");
+ assert!(html.contains("<span"));
+ }
+}
diff --git a/src/serve.rs b/src/serve.rs
new file mode 100644
index 0000000..c5d2efd
--- /dev/null
+++ b/src/serve.rs
@@ -0,0 +1,152 @@
+use std::env;
+use std::fs;
+use std::io::{self, Write};
+use std::path::{Component, Path, PathBuf};
+use std::process::ExitCode;
+
+use crate::render;
+
+pub fn run() -> ExitCode {
+ let Ok(document_root) = env::var("DOCUMENT_ROOT") else {
+ return respond_error(500, "DOCUMENT_ROOT is not set");
+ };
+
+ let Some(raw_request) = request_path() else {
+ return respond_error(500, "no request path available");
+ };
+
+ let request = strip_query(&raw_request);
+
+ let Some(target) = safe_join(Path::new(&document_root), request) else {
+ return respond_error(404, "not found");
+ };
+
+ let Ok(metadata) = fs::metadata(&target) else {
+ return respond_error(404, "not found");
+ };
+
+ if !metadata.is_file() {
+ return respond_error(404, "not found");
+ }
+
+ let Ok(bytes) = fs::read(&target) else {
+ return respond_error(500, "read error");
+ };
+
+ let Ok(text) = String::from_utf8(bytes) else {
+ return respond_error(404, "not found");
+ };
+
+ let html = render::page(&target, &text);
+ let body = html.as_bytes();
+
+ let header = format!(
+ "Status: 200 OK\nContent-Type: text/html; charset=utf-8\nContent-Length: {}\n\n",
+ body.len()
+ );
+
+ let stdout = io::stdout();
+ let mut handle = stdout.lock();
+ if handle.write_all(header.as_bytes()).is_err() {
+ return ExitCode::from(1);
+ }
+ if handle.write_all(body).is_err() {
+ return ExitCode::from(1);
+ }
+
+ ExitCode::SUCCESS
+}
+
+fn request_path() -> Option<String> {
+ env::var("DOCUMENT_URI")
+ .or_else(|_| env::var("PATH_INFO"))
+ .ok()
+}
+
+fn strip_query(s: &str) -> &str {
+ let s = s.split('?').next().unwrap_or(s);
+ s.split('#').next().unwrap_or(s)
+}
+
+// Only top-level, non-dotfile names are servable: rejects paths with
+// `..`, with subdirectories, and with names starting with `.`.
+fn safe_join(root: &Path, request: &str) -> Option<PathBuf> {
+ let mut name = None;
+ for component in Path::new(request).components() {
+ match component {
+ Component::Normal(c) => {
+ if name.is_some() {
+ return None;
+ }
+ if c.as_encoded_bytes().first() == Some(&b'.') {
+ return None;
+ }
+ name = Some(c);
+ }
+ Component::RootDir | Component::CurDir => {}
+ Component::ParentDir | Component::Prefix(_) => return None,
+ }
+ }
+ name.map(|n| root.join(n))
+}
+
+fn respond_error(code: u16, message: &str) -> ExitCode {
+ let status = match code {
+ 400 => "400 Bad Request",
+ 403 => "403 Forbidden",
+ 404 => "404 Not Found",
+ _ => "500 Internal Server Error",
+ };
+
+ println!("Status: {status}");
+ println!("Content-Type: text/plain; charset=utf-8");
+ println!();
+ println!("{message}");
+
+ ExitCode::SUCCESS
+}
+
+#[cfg(test)]
+mod tests {
+ use super::*;
+
+ #[test]
+ fn safe_join_normal() {
+ let r = safe_join(Path::new("/srv/p"), "/x.txt").unwrap();
+ assert_eq!(r, PathBuf::from("/srv/p/x.txt"));
+ }
+
+ #[test]
+ fn safe_join_rejects_subdirectories() {
+ assert!(safe_join(Path::new("/srv/p"), "/sub/x.txt").is_none());
+ assert!(safe_join(Path::new("/srv/p"), "/a/b/c").is_none());
+ }
+
+ #[test]
+ fn safe_join_rejects_dotfiles() {
+ assert!(safe_join(Path::new("/srv/p"), "/.ssh").is_none());
+ assert!(safe_join(Path::new("/srv/p"), "/.bashrc").is_none());
+ assert!(safe_join(Path::new("/srv/p"), ".env").is_none());
+ }
+
+ #[test]
+ fn safe_join_rejects_parent() {
+ assert!(safe_join(Path::new("/srv/p"), "/../etc/passwd").is_none());
+ assert!(safe_join(Path::new("/srv/p"), "../etc/passwd").is_none());
+ assert!(safe_join(Path::new("/srv/p"), "/sub/../../etc").is_none());
+ }
+
+ #[test]
+ fn safe_join_rejects_empty() {
+ assert!(safe_join(Path::new("/srv/p"), "").is_none());
+ assert!(safe_join(Path::new("/srv/p"), "/").is_none());
+ }
+
+ #[test]
+ fn strip_query_removes_query_and_fragment() {
+ assert_eq!(strip_query("/x.txt?foo=bar"), "/x.txt");
+ assert_eq!(strip_query("/x.txt#frag"), "/x.txt");
+ assert_eq!(strip_query("/x.txt?a=b#frag"), "/x.txt");
+ assert_eq!(strip_query("/x.txt"), "/x.txt");
+ }
+}