flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/deployments/src/access.ts

33 lines1,249 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1/**
2 * Who may do what with a project's deployments: each method's capability
3 * on the project's repository. Seeing deployments takes Read; deploying,
4 * redeploying and taking an app down spend compute and take Write (`run`);
5 * deployment settings and domains take Admin (`manage_integrations`).
6 * Types only, so the table is tested apart from the service.
7 */
8
9import type { Capability, Project, RepoRef } from "@g1t/contracts";
10
11export const NEEDS = {
12 settings: "read",
13 list: "read",
14 get: "read",
15 listDomains: "read",
16 redeploy: "run",
17 stack: "run",
18 takeDown: "run",
19 updateSettings: "manage_integrations",
20 addDomain: "manage_integrations",
21 removeDomain: "manage_integrations",
22 refreshDomain: "manage_integrations",
23} as const satisfies Record<string, Capability>;
24
25export type Method = keyof typeof NEEDS;
26
27/** The repository a project's permission comes from. A mirrored one has none: its workspace's base permission decides. */
28export function repoRef(project: Project): RepoRef {
29 if (project.source.kind === "hosted") {
30 return { id: project.source.repoId, namespace: project.source.repo.namespace, isPrivate: project.private };
31 }
32 return { id: "", namespace: project.workspace, isPrivate: project.private };
33}