g1t/crates/contracts/src/lib.rs

150 lines5,330 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod access;
8pub mod accounts;
9pub mod actions;
10pub mod agents;
11pub mod audit;
12pub mod billing;
13pub mod capture;
14pub mod credentials;
15pub mod events;
16pub mod github;
17pub mod guardrails;
18pub mod identity;
19pub mod integrations;
20mod ids;
21mod names;
22mod outcome;
23pub mod projects;
24pub mod repos;
25pub mod scopes;
26pub mod search;
27pub mod security;
28pub mod time;
29pub mod webhooks;
30pub mod work;
31
32pub use ids::new_id;
33pub use names::{is_valid_namespace, is_valid_repo_name};
34pub use outcome::{Failure, FailureCode, Outcome};
35
36use serde::{Deserialize, Serialize};
37
38/// What a member may do in a workspace.
39#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
40#[serde(rename_all = "lowercase")]
41pub enum Role {
42 /// Everything a member can, plus managing members.
43 Owner,
44 /// Create repositories, push, manage issues and merge pull requests.
45 Member,
46}
47
48/// One workspace a user belongs to.
49#[derive(Clone, Debug, Serialize, Deserialize)]
50pub struct Membership {
51 /// The workspace's name in URLs: `g1t.sh/<slug>`.
52 pub slug: String,
53 pub role: Role,
54 /// The workspace's display name, for showing it to people. Set when a
55 /// user is resolved from credentials; absent on principals made up by
56 /// a service.
57 #[serde(default, skip_serializing_if = "Option::is_none")]
58 pub name: Option<String>,
59 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
60 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
61 #[serde(default, skip_serializing_if = "Option::is_none")]
62 pub avatar: Option<String>,
63 /// What a member gets on each of the workspace's repositories: the
64 /// workspace's base permission. Set when a user is resolved from
65 /// credentials; absent means the default, Write. Owners have Admin
66 /// whatever it says. See [`access`].
67 #[serde(default, skip_serializing_if = "Option::is_none")]
68 pub base_permission: Option<access::BasePermission>,
69}
70
71impl Membership {
72 /// A plain member of `slug`, as services act inside one workspace.
73 pub fn member(slug: impl Into<String>) -> Self {
74 Membership {
75 slug: slug.into(),
76 role: Role::Member,
77 name: None,
78 avatar: None,
79 base_permission: None,
80 }
81 }
82}
83
84/// What a set of credentials resolved to.
85#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
86#[serde(rename_all = "lowercase")]
87pub enum PrincipalKind {
88 /// A person's account.
89 #[default]
90 User,
91 /// A workspace, acting through one of its own access tokens. Its `id`
92 /// is the workspace's, its `username` the workspace's slug, and it is a
93 /// member of that workspace and no other.
94 Workspace,
95 /// A g1t agent at work in a sandbox, acting through a token that lives
96 /// as long as its run and can do only what that token's scope lists, in
97 /// one repository. Its `username` is `g1t-agent`.
98 Agent,
99}
100
101#[derive(Clone, Debug, Default, Serialize, Deserialize)]
102pub struct User {
103 pub id: String,
104 pub username: String,
105 #[serde(default)]
106 pub kind: PrincipalKind,
107 /// Whether the account's email address has been confirmed. Unverified
108 /// accounts can sign in but cannot create or change anything.
109 #[serde(default)]
110 pub verified: bool,
111 /// The workspaces this user belongs to. Filled in when a user is
112 /// resolved from credentials, so any service can authorize from it.
113 #[serde(default)]
114 pub workspaces: Vec<Membership>,
115 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
116 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
117 #[serde(default, skip_serializing_if = "Option::is_none")]
118 pub avatar: Option<String>,
119 /// Set on an agent resolved from its token: who it acts for, with which
120 /// credential, and what it may do. See [`credentials`].
121 #[serde(default, skip_serializing_if = "Option::is_none")]
122 pub acting: Option<Box<credentials::Acting>>,
123 /// The repositories this user has been given a role on directly,
124 /// whether or not they belong to its workspace. Filled in with
125 /// `workspaces`; see [`access`].
126 #[serde(default, skip_serializing_if = "Vec::is_empty")]
127 pub grants: Vec<access::RepoGrant>,
128 /// Set on a user resolved from an access token: its scopes and the
129 /// workspaces or repositories it is limited to. Absent on a signed-in
130 /// session and on an agent (whose `acting` scope applies instead).
131 /// See [`scopes`].
132 #[serde(default, skip_serializing_if = "Option::is_none")]
133 pub token: Option<Box<scopes::TokenAccess>>,
134}
135
136impl User {
137 pub fn role_in(&self, slug: &str) -> Option<Role> {
138 self.workspaces
139 .iter()
140 .find(|membership| membership.slug == slug)
141 .map(|membership| membership.role)
142 }
143
144 pub fn is_member(&self, slug: &str) -> bool {
145 self.role_in(slug).is_some()
146 }
147}
148
149/// Who is asking. Every read and write in every service takes one.
150pub type Viewer = Option<User>;