Skip to content
281 linesCodeBlameRaw
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod about;
8pub mod access;
9pub mod account_deletion;
10pub mod accounts;
11pub mod actions;
12pub mod agents;
13pub mod audit;
14pub mod backups;
15pub mod billing;
16pub mod capture;
17pub mod checks;
18pub mod codeowners;
19pub mod credentials;
20pub mod deploy_keys;
21pub mod events;
22pub mod fine_grained;
23pub mod github;
24pub mod guardrails;
25pub mod identity;
26pub mod inbox;
27pub mod integrations;
28pub mod members;
29mod ids;
30mod names;
31mod outcome;
32pub mod packages;
33pub mod projects;
34pub mod repos;
35pub mod rules;
36pub mod runners;
37pub mod scopes;
38pub mod search;
39pub mod security;
40pub mod teams;
41pub mod security_suite;
42pub mod time;
43pub mod tokens;
44pub mod updates;
45pub mod webhooks;
46pub mod work;
47
48pub use ids::new_id;
49pub use names::{
50 aliasable_name, claimable_namespace, is_namespace_shaped, is_reserved_name, is_route_name, is_valid_namespace,
51 is_valid_repo_name,
52};
53pub use outcome::{Failure, FailureCode, Outcome};
54
55use serde::{Deserialize, Serialize};
56
57/// What a member may do in a workspace. A member may also hold
58/// [`members::OrgRole`]s, which add to it.
59#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
60#[serde(rename_all = "lowercase")]
61pub enum Role {
62 /// Everything: Admin on every repository, the workspace's members,
63 /// settings, billing and security.
64 Owner,
65 /// The workspace's base permission on each repository, and what its
66 /// member privileges allow (see [`members::MemberPrivileges`]).
67 Member,
68}
69
70pub use members::{MemberPrivileges, OrgRole};
71
72/// One workspace a user belongs to.
73#[derive(Clone, Debug, Serialize, Deserialize)]
74pub struct Membership {
75 /// The workspace's name in URLs: `g1t.sh/<slug>`.
76 pub slug: String,
77 pub role: Role,
78 /// The workspace's display name, for showing it to people. Set when a
79 /// user is resolved from credentials; absent on principals made up by
80 /// a service.
81 #[serde(default, skip_serializing_if = "Option::is_none")]
82 pub name: Option<String>,
83 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
84 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
85 #[serde(default, skip_serializing_if = "Option::is_none")]
86 pub avatar: Option<String>,
87 /// What a member gets on each of the workspace's repositories: the
88 /// workspace's base permission. Set when a user is resolved from
89 /// credentials; absent means the default, Write. Owners have Admin
90 /// whatever it says. See [`access`].
91 #[serde(default, skip_serializing_if = "Option::is_none")]
92 pub base_permission: Option<access::BasePermission>,
93 /// Who may create the workspace's teams. Set when a user is resolved
94 /// from credentials; absent means the default, any member. See
95 /// [`teams::TeamCreation`].
96 #[serde(default, skip_serializing_if = "Option::is_none")]
97 pub team_creation: Option<teams::TeamCreation>,
98 /// The roles the member holds besides `role`: billing manager,
99 /// security manager. Set when a user is resolved from credentials.
100 #[serde(default, skip_serializing_if = "Vec::is_empty")]
101 pub org_roles: Vec<OrgRole>,
102 /// What the workspace lets members (and repository admins) do. Set
103 /// when a user is resolved from credentials; absent means the
104 /// defaults. See [`members::MemberPrivileges`].
105 #[serde(default, skip_serializing_if = "Option::is_none")]
106 pub privileges: Option<MemberPrivileges>,
107}
108
109impl Membership {
110 /// A plain member of `slug`, as services act inside one workspace.
111 pub fn member(slug: impl Into<String>) -> Self {
112 Membership {
113 slug: slug.into(),
114 role: Role::Member,
115 name: None,
116 avatar: None,
117 base_permission: None,
118 team_creation: None,
119 org_roles: Vec::new(),
120 privileges: None,
121 }
122 }
123
124 /// Whether the member holds `role` besides owner or member.
125 pub fn has(&self, role: OrgRole) -> bool {
126 self.org_roles.contains(&role)
127 }
128}
129
130/// What a set of credentials resolved to.
131#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
132#[serde(rename_all = "lowercase")]
133pub enum PrincipalKind {
134 /// A person's account.
135 #[default]
136 User,
137 /// A workspace, acting through one of its own access tokens. Its `id`
138 /// is the workspace's, its `username` the workspace's slug, and it is a
139 /// member of that workspace and no other.
140 Workspace,
141 /// A g1t agent at work in a sandbox, acting through a token that lives
142 /// as long as its run and can do only what that token's scope lists, in
143 /// one repository. Its `username` is `g1t`.
144 Agent,
145 /// g1t itself: the platform acting on its own, as when it opens a
146 /// pull request to upgrade a vulnerable dependency or merges from the
147 /// queue. Never resolved from credentials: only services make one,
148 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
149 /// register.
150 System,
151}
152
153/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
154pub mod system {
155 /// Its id wherever an author or actor id is stored.
156 pub const ID: &str = "g1t";
157 /// Its name, shown as the author of what it does.
158 pub const USERNAME: &str = "g1t";
159 /// The address on the commits it makes, which no mailbox receives.
160 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
161 /// Ids that earlier versions stored for g1t's own actions, such as a
162 /// merge its settings made. Read as g1t too.
163 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
164
165 /// Whether `id` is g1t's own.
166 pub fn is_system_id(id: &str) -> bool {
167 id == ID || LEGACY_IDS.contains(&id)
168 }
169}
170
171#[derive(Clone, Debug, Default, Serialize, Deserialize)]
172pub struct User {
173 pub id: String,
174 pub username: String,
175 #[serde(default)]
176 pub kind: PrincipalKind,
177 /// Whether the account's email address has been confirmed. Unverified
178 /// accounts can sign in but cannot create or change anything.
179 #[serde(default)]
180 pub verified: bool,
181 /// The workspaces this user belongs to. Filled in when a user is
182 /// resolved from credentials, so any service can authorize from it.
183 #[serde(default)]
184 pub workspaces: Vec<Membership>,
185 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
186 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
187 #[serde(default, skip_serializing_if = "Option::is_none")]
188 pub avatar: Option<String>,
189 /// Set on an agent resolved from its token: who it acts for, with which
190 /// credential, and what it may do. See [`credentials`].
191 #[serde(default, skip_serializing_if = "Option::is_none")]
192 pub acting: Option<Box<credentials::Acting>>,
193 /// The repositories this user has been given a role on directly,
194 /// whether or not they belong to its workspace. Filled in with
195 /// `workspaces`; see [`access`].
196 #[serde(default, skip_serializing_if = "Vec::is_empty")]
197 pub grants: Vec<access::RepoGrant>,
198 /// Set on a user resolved from an access token: its scopes and the
199 /// workspaces or repositories it is limited to. Absent on a signed-in
200 /// session and on an agent (whose `acting` scope applies instead).
201 /// See [`scopes`].
202 #[serde(default, skip_serializing_if = "Option::is_none")]
203 pub token: Option<Box<scopes::TokenAccess>>,
204 /// The workspaces this person belongs to but cannot use until they
205 /// meet its policy, such as turning on two-factor authentication.
206 /// They are left out of `workspaces` and `grants` meanwhile. Set when
207 /// a person is resolved from a session.
208 #[serde(default, skip_serializing_if = "Vec::is_empty")]
209 pub held: Vec<members::PolicyHold>,
210}
211
212impl User {
213 /// g1t itself, acting in `workspace`: what the platform's own work,
214 /// such as security updates, is done and recorded as.
215 pub fn system(workspace: &str) -> User {
216 User {
217 id: system::ID.to_owned(),
218 username: system::USERNAME.to_owned(),
219 kind: PrincipalKind::System,
220 verified: true,
221 workspaces: vec![Membership::member(workspace.to_lowercase())],
222 ..User::default()
223 }
224 }
225
226 /// Whether this is g1t itself.
227 pub fn is_system(&self) -> bool {
228 self.kind == PrincipalKind::System
229 }
230
231 /// Whether this is a person whose account has not confirmed its email
232 /// address. Such an account can only confirm it (or change it, or sign
233 /// out): the site, the API, MCP and git refuse it everything else
234 /// ([`accounts::confirm_email_first`]).
235 pub fn awaits_confirmation(&self) -> bool {
236 self.kind == PrincipalKind::User && !self.verified
237 }
238
239 pub fn role_in(&self, slug: &str) -> Option<Role> {
240 self.workspaces
241 .iter()
242 .find(|membership| membership.slug == slug)
243 .map(|membership| membership.role)
244 }
245
246 pub fn is_member(&self, slug: &str) -> bool {
247 self.role_in(slug).is_some()
248 }
249
250 /// The membership in `slug`, if any.
251 pub fn membership(&self, slug: &str) -> Option<&Membership> {
252 self.workspaces.iter().find(|membership| membership.slug.eq_ignore_ascii_case(slug))
253 }
254
255 /// Whether this is a person who owns `slug`, or holds `role` in it.
256 pub fn owns_or_has(&self, slug: &str, role: OrgRole) -> bool {
257 self.membership(slug)
258 .is_some_and(|membership| membership.role == Role::Owner || membership.has(role))
259 }
260
261 /// Whether the user may manage `slug`'s billing: an owner or a billing
262 /// manager.
263 pub fn manages_billing(&self, slug: &str) -> bool {
264 self.owns_or_has(slug, OrgRole::BillingManager)
265 }
266
267 /// Whether the user may see and manage security across `slug`: an
268 /// owner or a security manager.
269 pub fn manages_security(&self, slug: &str) -> bool {
270 self.owns_or_has(slug, OrgRole::SecurityManager)
271 }
272
273 /// The workspace's member privileges as this user sees them: the
274 /// defaults when the membership does not say.
275 pub fn privileges_in(&self, slug: &str) -> MemberPrivileges {
276 self.membership(slug).and_then(|membership| membership.privileges).unwrap_or_default()
277 }
278}
279
280/// Who is asking. Every read and write in every service takes one.
281pub type Viewer = Option<User>;