Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions core/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,19 @@ readme = "README.md"
keywords = ["oauth", "jwt", "security", "mcp", "authplane"]
categories = ["authentication", "api-bindings"]

# Tests, examples and benches are not shipped in the published crate. They are
# not what a consumer compiles against, they are all readable in the repository,
# and `core/tests/fixtures/` holds RSA and EC private keys the unit tests and the
# DPoP example use. Those keys are test material — nothing verifies against them —
# but a crates.io version is immutable, so anything that ships stays shipped, and
# key-shaped files in a published tarball are permanent noise for every downstream
# secret scanner and SBOM. Keeping them out of the tarball costs nothing here.
#
# `examples/` goes with `tests/` rather than staying behind: the DPoP example
# reads `tests/fixtures/test-private.pem` through `include_str!`, so shipping the
# example without the fixture would leave it unbuildable from the tarball.
exclude = ["tests/", "examples/", "benches/"]

[dependencies]
async-trait = "0.1"
base64 = "0.22"
Expand Down
13 changes: 13 additions & 0 deletions fastmcp/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,19 @@ readme = "README.md"
keywords = ["oauth", "jwt", "fastmcp", "adapter", "authplane"]
categories = ["authentication", "api-bindings"]

# Tests, examples and benches are not shipped in the published crate. They are
# not what a consumer compiles against, they are all readable in the repository,
# and `core/tests/fixtures/` holds RSA and EC private keys the unit tests and the
# DPoP example use. Those keys are test material — nothing verifies against them —
# but a crates.io version is immutable, so anything that ships stays shipped, and
# key-shaped files in a published tarball are permanent noise for every downstream
# secret scanner and SBOM. Keeping them out of the tarball costs nothing here.
#
# `examples/` goes with `tests/` rather than staying behind: the DPoP example
# reads `tests/fixtures/test-private.pem` through `include_str!`, so shipping the
# example without the fixture would leave it unbuildable from the tarball.
exclude = ["tests/", "examples/", "benches/"]

[dependencies]
authplane-sdk = { path = "../core", version = "0.1.0" }
fastmcp-rust = "0.3.0"
Expand Down
13 changes: 13 additions & 0 deletions mcp/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,19 @@ readme = "README.md"
keywords = ["oauth", "jwt", "mcp", "adapter", "authplane"]
categories = ["authentication", "api-bindings"]

# Tests, examples and benches are not shipped in the published crate. They are
# not what a consumer compiles against, they are all readable in the repository,
# and `core/tests/fixtures/` holds RSA and EC private keys the unit tests and the
# DPoP example use. Those keys are test material — nothing verifies against them —
# but a crates.io version is immutable, so anything that ships stays shipped, and
# key-shaped files in a published tarball are permanent noise for every downstream
# secret scanner and SBOM. Keeping them out of the tarball costs nothing here.
#
# `examples/` goes with `tests/` rather than staying behind: the DPoP example
# reads `tests/fixtures/test-private.pem` through `include_str!`, so shipping the
# example without the fixture would leave it unbuildable from the tarball.
exclude = ["tests/", "examples/", "benches/"]

[dependencies]
authplane-sdk = { path = "../core", version = "0.1.0" }
axum = "0.8"
Expand Down
Loading