Skip to content

g1t/crates/contracts/src/identity.rs

1,510 lines51,815 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
RFC 3339 timestamps in identity and repos16 /// RFC 3339.
17 pub created_at: String,
API and MCP server, Rust identity service, registration, site redesign18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
RFC 3339 timestamps in identity and repos25 /// RFC 3339.
26 pub created_at: String,
Agents as a team: lifecycle, merge queue, billing and a new shell27 /// RFC 3339, to within a few minutes. Null until it is first used.
28 pub last_used_at: Option<String>,
29 /// For a workspace's token, the username of the member who made it.
30 /// Null once that account is gone, and on personal tokens.
31 pub created_by: Option<String>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step32 /// Its scopes, as `resource:level`. Null: full access.
33 #[serde(default)]
34 pub scopes: Option<Vec<String>>,
35 /// Made before tokens had scopes: full access until someone narrows it.
36 #[serde(default)]
37 pub legacy: bool,
38 /// RFC 3339. Null: it does not expire.
39 #[serde(default)]
40 pub expires_at: Option<String>,
API and MCP server, Rust identity service, registration, site redesign41}
42
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look43/// `sign_in`: verifies a username, or any confirmed email address of the
44/// account, and its password, for website sign-in. Wrong passwords are
45/// counted against the account and `client`, and past a limit nothing is
46/// checked for a while (see identity's `throttle.rs`).
API and MCP server, Rust identity service, registration, site redesign47/// Returns `Outcome<SignedIn>`.
48#[derive(Debug, Serialize, Deserialize)]
49pub struct SignInArgs {
50 pub username: String,
51 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look52 /// Who is asking, such as the visitor's IP address, for rate limits.
53 #[serde(default)]
54 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign55}
56
57#[derive(Debug, Serialize, Deserialize)]
58#[serde(rename_all = "camelCase")]
59pub struct SignedIn {
60 pub user: User,
61 pub session_token: String,
62}
63
64/// `sign_out` and `user_for_session`.
65#[derive(Debug, Serialize, Deserialize)]
66#[serde(rename_all = "camelCase")]
67pub struct SessionArgs {
68 pub session_token: String,
69}
70
71/// `user_for_git_credentials`: the account password or an access token.
72#[derive(Debug, Serialize, Deserialize)]
73pub struct GitCredentialsArgs {
74 pub username: String,
75 pub secret: String,
76}
77
78/// `user_for_access_token`.
79#[derive(Debug, Serialize, Deserialize)]
80pub struct TokenArgs {
81 pub token: String,
82}
83
84/// `user_for_ssh_key`.
85#[derive(Debug, Serialize, Deserialize)]
86pub struct FingerprintArgs {
87 pub fingerprint: String,
88}
89
90/// `user_by_username`.
91#[derive(Debug, Serialize, Deserialize)]
92pub struct UsernameArgs {
93 pub username: String,
94}
95
What happened across an outcome, as a feed beside its graph96/// `usernames`: the names behind account and workspace ids, as events and
97/// other records store them. Returns a map from id to name; ids it does
98/// not know are left out.
99#[derive(Debug, Serialize, Deserialize)]
100pub struct UsernamesArgs {
101 pub ids: Vec<String>,
102}
103
API and MCP server, Rust identity service, registration, site redesign104/// `list_ssh_keys` and `list_access_tokens`.
105#[derive(Debug, Serialize, Deserialize)]
106pub struct UserArgs {
107 pub user: User,
108}
109
110/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
111/// Returns `Outcome<SshKey>`.
112#[derive(Debug, Serialize, Deserialize)]
113#[serde(rename_all = "camelCase")]
114pub struct AddSshKeyArgs {
115 pub user: User,
116 pub title: String,
117 pub public_key: String,
118}
119
120/// `remove_ssh_key` and `remove_access_token`.
121#[derive(Debug, Serialize, Deserialize)]
122pub struct RemoveArgs {
123 pub user: User,
124 pub id: String,
125}
126
Agents as a team: lifecycle, merge queue, billing and a new shell127/// `create_access_token`: a token that acts as `user`. For a workspace
128/// acting through a token of its own, the new token belongs to that
129/// workspace too.
API and MCP server, Rust identity service, registration, site redesign130#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)131#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign132pub struct CreateAccessTokenArgs {
133 pub user: User,
134 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)135 /// When set, the token stops working after this many seconds and is
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step136 /// left out of the user's token list, unless `listed`. Used for hosted
137 /// attempts.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)138 #[serde(default)]
139 pub ttl_seconds: Option<u64>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step140 /// Its scopes, as `resource:level`; unknown names are left out. Null:
141 /// full access.
142 #[serde(default)]
143 pub scopes: Option<Vec<String>>,
144 /// Listed with the person's tokens although it expires: one they made
145 /// themselves, with an expiry.
146 #[serde(default)]
147 pub listed: bool,
148}
149
150/// `update_access_token`: changes what one of a person's tokens may do.
151/// The token itself is unchanged. Returns `Outcome<AccessToken>`.
152#[derive(Debug, Serialize, Deserialize)]
153pub struct UpdateAccessTokenArgs {
154 pub user: User,
155 pub id: String,
156 /// Null: full access.
157 #[serde(default)]
158 pub scopes: Option<Vec<String>>,
API and MCP server, Rust identity service, registration, site redesign159}
160
161/// The plaintext token is returned once and never stored.
162#[derive(Debug, Serialize, Deserialize)]
163pub struct CreatedAccessToken {
164 pub token: String,
165 pub info: AccessToken,
166}
167
168/// `register`: creates an account and signs it in.
169/// Returns `Outcome<SignedIn>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look170///
171/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
172/// new account needs `invite_code`: an unused, unexpired invite, and, when
173/// the invite names an email, that address. See [`CreateInviteArgs`].
API and MCP server, Rust identity service, registration, site redesign174#[derive(Debug, Serialize, Deserialize)]
175pub struct RegisterArgs {
176 pub username: String,
177 pub email: String,
178 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look179 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
180 /// registration is open.
181 #[serde(default)]
182 pub invite_code: Option<String>,
183 /// Who is asking, such as the visitor's IP address, for rate limits.
184 #[serde(default)]
185 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign186}
Email verification, password reset, and Git for AI scale positioning187
188/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
189#[derive(Debug, Serialize, Deserialize)]
190pub struct EmailTokenArgs {
191 pub token: String,
192}
193
194/// `request_password_reset`. Always succeeds, so it cannot be used to find
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look195/// out which addresses have accounts. Any confirmed address of an account
196/// works: the link goes to the address given, and the primary (and the
197/// backup) are told a reset was asked for. A few requests an hour per
198/// address and per `client`; past that, nothing is sent.
Email verification, password reset, and Git for AI scale positioning199#[derive(Debug, Serialize, Deserialize)]
200pub struct EmailArgs {
201 pub email: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look202 /// Who is asking, such as the visitor's IP address, for rate limits.
203 #[serde(default)]
204 pub client: Option<String>,
Email verification, password reset, and Git for AI scale positioning205}
206
207/// `reset_password`: sets a new password and ends every session.
208/// Returns `Outcome<User>`.
209#[derive(Debug, Serialize, Deserialize)]
210pub struct ResetPasswordArgs {
211 pub token: String,
212 pub password: String,
213}
Device sign-in replaces registering and minting tokens over the API214
215/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
216#[derive(Debug, Serialize, Deserialize)]
217#[serde(rename_all = "camelCase")]
218pub struct DeviceStartArgs {
219 /// What is asking, shown to the person approving, e.g. "Claude Code".
220 pub client_name: String,
221}
222
223#[derive(Debug, Serialize, Deserialize)]
224#[serde(rename_all = "camelCase")]
225pub struct DeviceStart {
226 /// Secret held by the tool and exchanged for a token once approved.
227 pub device_code: String,
228 /// Short code shown to the person, e.g. `WDJB-MJHT`.
229 pub user_code: String,
230 /// Seconds until both codes stop working.
231 pub expires_in: u32,
232 /// Seconds the tool should wait between polls.
233 pub interval: u32,
234}
235
236/// `device_lookup`: what a user code is asking for, or null if it is not
237/// valid. Returns `Option<DeviceRequest>`.
238#[derive(Debug, Serialize, Deserialize)]
239#[serde(rename_all = "camelCase")]
240pub struct DeviceLookupArgs {
241 pub user_code: String,
242}
243
244#[derive(Debug, Serialize, Deserialize)]
245#[serde(rename_all = "camelCase")]
246pub struct DeviceRequest {
247 pub user_code: String,
248 pub client_name: String,
249}
250
251/// `device_resolve`: the signed-in person approves or denies a request.
252/// Returns `Outcome<bool>`.
253#[derive(Debug, Serialize, Deserialize)]
254#[serde(rename_all = "camelCase")]
255pub struct DeviceResolveArgs {
256 pub user_code: String,
257 pub user: User,
258 pub approve: bool,
259}
260
261/// `device_claim`: the tool asks whether its request was approved.
262#[derive(Debug, Serialize, Deserialize)]
263#[serde(rename_all = "camelCase")]
264pub struct DeviceClaimArgs {
265 pub device_code: String,
266}
267
268/// The answer to a `device_claim`.
269#[derive(Debug, Serialize, Deserialize)]
270#[serde(tag = "status", rename_all = "snake_case")]
271pub enum DeviceClaim {
272 /// Nobody has approved or denied it yet; ask again after the interval.
273 Pending,
274 Denied,
275 /// The code was never issued, has expired, or was already used.
276 Expired,
277 /// The access token, returned once.
278 Approved {
279 token: String,
280 user: User,
281 },
282}
Workspaces own repositories283
284/// A workspace: the owner of repositories, and the first segment of their
285/// URLs. A person's own space and a team's are the same thing.
286#[derive(Clone, Debug, Serialize, Deserialize)]
287#[serde(rename_all = "camelCase")]
288pub struct Workspace {
289 pub id: String,
290 pub slug: String,
291 pub name: String,
Agents as a team: lifecycle, merge queue, billing and a new shell292 /// One line saying what the workspace is for.
293 pub description: Option<String>,
Workspaces own repositories294 /// RFC 3339.
295 pub created_at: String,
296 pub member_count: u32,
Workspace names and icons, and a component kit for every control297 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
298 /// `/avatars/<avatar>`. Null means the generated letter avatar.
299 #[serde(default)]
300 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look301 /// What every member gets on each of its repositories; owners have
302 /// Admin. See [`crate::access`].
303 #[serde(default)]
304 pub base_permission: crate::access::BasePermission,
Merge branch 'worktree-agent-ad7c6d88d93adc817'305 /// Who may create its teams. See [`crate::teams::TeamCreation`].
306 #[serde(default)]
307 pub team_creation: crate::teams::TeamCreation,
Workspaces own repositories308}
309
310#[derive(Clone, Debug, Serialize, Deserialize)]
311pub struct Member {
312 pub username: String,
313 pub role: crate::Role,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look314 /// Their display name, when they set one.
315 #[serde(default)]
316 pub name: Option<String>,
317 /// Their uploaded avatar: the SHA-256 of its bytes, served at
318 /// `/avatars/<avatar>`. None means the generated letter avatar.
319 #[serde(default)]
320 pub avatar: Option<String>,
Workspaces own repositories321}
322
Merge branch 'worktree-agent-a2013627e5ea4ab13'323/// Where a workspace keeps its repositories' git data: anywhere g1t
324/// stores it (the default), or in the EU only. It applies to repositories
325/// made after it is set; the repos service reads it when it places a new
326/// one (`storage_options` says whether the EU can be chosen).
327#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
328#[serde(rename_all = "lowercase")]
329pub enum DataResidency {
330 #[default]
331 Anywhere,
332 Eu,
333}
334
335impl DataResidency {
336 pub fn as_str(self) -> &'static str {
337 match self {
338 DataResidency::Anywhere => "anywhere",
339 DataResidency::Eu => "eu",
340 }
341 }
342
343 pub fn parse(text: &str) -> Option<Self> {
344 match text.trim().to_ascii_lowercase().as_str() {
345 "anywhere" => Some(DataResidency::Anywhere),
346 "eu" => Some(DataResidency::Eu),
347 _ => None,
348 }
349 }
350}
351
352/// `workspace_residency` takes [`SlugArgs`] and returns
353/// `Option<DataResidency>` (null when there is no such workspace).
354/// `set_workspace_residency`: owners only. Returns `Outcome<DataResidency>`.
355#[derive(Debug, Serialize, Deserialize)]
356pub struct SetResidencyArgs {
357 pub actor: User,
358 pub slug: String,
359 pub residency: DataResidency,
360}
361
Workspaces own repositories362/// `create_workspace`. Returns `Outcome<Workspace>`.
363#[derive(Debug, Serialize, Deserialize)]
364pub struct CreateWorkspaceArgs {
365 pub user: User,
366 pub slug: String,
367 #[serde(default)]
368 pub name: String,
369}
370
371/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
372#[derive(Debug, Serialize, Deserialize)]
373pub struct SlugArgs {
374 pub slug: String,
375}
376
377/// `list_members`: members only. Returns `Outcome<Vec<Member>>`.
378#[derive(Debug, Serialize, Deserialize)]
379pub struct ListMembersArgs {
380 pub slug: String,
381 pub viewer: crate::Viewer,
382}
383
384/// `add_member` and `remove_member`: owners only.
385/// Each returns `Outcome<bool>`.
386#[derive(Debug, Serialize, Deserialize)]
387pub struct MemberArgs {
388 pub actor: User,
389 pub slug: String,
390 pub username: String,
391}
OAuth 2.1 sign-in for MCP clients and other applications392
Agents as a team: lifecycle, merge queue, billing and a new shell393/// `update_workspace`: owners only. An empty name falls back to the slug;
394/// an empty description clears it. Returns `Outcome<Workspace>`.
395#[derive(Debug, Serialize, Deserialize)]
396pub struct UpdateWorkspaceArgs {
397 pub actor: User,
398 pub slug: String,
399 pub name: String,
400 pub description: String,
401}
402
Agents and memory, checks and conflicts, profiles, slug renames, custom domains403/// `rename_workspace`: owners only. Changes the workspace's slug, the first
404/// segment of its URLs, to `new_slug`; the display name is untouched. The
405/// old slug redirects to the new one, and is held for this workspace, for
406/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
407/// `Outcome<Workspace>`.
408///
409/// `check_workspace_rename` takes the same arguments and answers whether
410/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
411#[derive(Debug, Serialize, Deserialize)]
412#[serde(rename_all = "camelCase")]
413pub struct RenameWorkspaceArgs {
414 pub actor: User,
415 pub slug: String,
416 pub new_slug: String,
417}
418
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look419/// `delete_workspace`: owners only, and only a person. `confirm` must be
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member420/// the workspace's slug, typed out. Refused for a protected workspace
421/// ([`protected_names`]), whoever asks, and while billing cannot settle it
422/// (`close_workspace`). Everything in it goes with it at once: nobody can
423/// reach it, its tokens stop working, its pages are not found, and its
424/// repositories, projects and apps are deleted with it. It is kept for
425/// [`WORKSPACE_RESTORE_DAYS`] so g1t's staff can restore it, then purged:
426/// its memberships, access tokens and old-slug redirects go, and billing's
427/// ledger and the audit log keep its history. The slug is never given to
428/// another workspace; the person whose username it is may make a workspace
429/// of that name again once it is purged. Publishes `workspace.deleting`,
430/// and `workspace.deleted` at the purge. Returns `Outcome<bool>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look431///
432/// `check_workspace_deletion` takes the same arguments (with `confirm`
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member433/// ignored) and says what would go and whether anything stands in the way,
434/// changing nothing. Returns `Outcome<WorkspaceDeletion>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look435#[derive(Debug, Serialize, Deserialize)]
436pub struct DeleteWorkspaceArgs {
437 pub actor: User,
438 pub slug: String,
439 #[serde(default)]
440 pub confirm: String,
441 /// Where the request came in, for the audit log; g1t.sh when absent.
442 #[serde(default)]
443 pub surface: Option<crate::audit::Surface>,
444}
445
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member446/// What deleting a workspace takes with it, and what stands in the way.
447/// Nothing does when `billing` is null and it is not `protected`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look448#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
449pub struct WorkspaceDeletion {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member450 /// Its live repositories, which are deleted with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look451 pub repositories: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member452 /// Its projects, hidden with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look453 pub projects: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member454 #[serde(default)]
455 pub members: u32,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look456 /// Why billing cannot close the workspace yet, in words for its owner.
457 pub billing: Option<String>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member458 /// It can never be deleted, by anyone ([`protected_names`]).
459 #[serde(default)]
460 pub protected: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look461}
462
463impl WorkspaceDeletion {
464 pub fn blocked(&self) -> bool {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member465 self.protected || self.billing.is_some()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look466 }
467
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member468 /// Why the workspace cannot be deleted, as one sentence, or `None`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look469 pub fn reason(&self, slug: &str) -> Option<String> {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member470 if self.protected {
471 return Some(protected_refusal(slug));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look472 }
473 self.billing.clone()
474 }
475}
476
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member477/// How long a deleted workspace is kept, for staff to restore, before it is
478/// purged.
479pub const WORKSPACE_RESTORE_DAYS: u64 = 30;
480
481/// Workspaces nobody can delete, whatever identity's `PROTECTED_WORKSPACES`
482/// says: Flagon's, which runs g1t.
483pub const ALWAYS_PROTECTED: &[&str] = &["flagon-io"];
484
485/// The protected workspaces: `configured` (comma-separated slugs or
486/// workspace ids, as identity's `PROTECTED_WORKSPACES` holds them), and
487/// [`ALWAYS_PROTECTED`] whatever it says, so an empty or missing variable
488/// still protects them. Lowercased, without duplicates.
489pub fn protected_names(configured: Option<&str>) -> Vec<String> {
490 let mut names: Vec<String> = Vec::new();
491 let given = configured.unwrap_or_default().split(',');
492 for name in ALWAYS_PROTECTED.iter().copied().chain(given) {
493 let name = name.trim().to_lowercase();
494 if !name.is_empty() && !names.contains(&name) {
495 names.push(name);
496 }
497 }
498 names
499}
500
501/// Why a protected workspace is not deleted, purged or acted on.
502pub fn protected_refusal(slug: &str) -> String {
503 format!("{slug} is protected and can never be deleted.")
504}
505
506/// `admin_deleted_workspaces` takes no arguments (`{}`) and returns
507/// `Vec<DeletedWorkspace>`, newest first. Staff only.
508///
509/// A workspace an owner deleted, kept until `purge_after` for staff to
510/// restore.
511#[derive(Clone, Debug, Serialize, Deserialize)]
512#[serde(rename_all = "camelCase")]
513pub struct DeletedWorkspace {
514 pub workspace_id: String,
515 pub slug: String,
516 pub name: String,
517 /// RFC 3339.
518 pub deleted_at: String,
519 /// The username of the owner who deleted it.
520 pub deleted_by: String,
521 /// RFC 3339: when it is purged unless restored first.
522 pub purge_after: String,
523 /// What went with it, counted when it was deleted.
524 pub went: WorkspaceDeletion,
525 /// Whether staff can still restore it.
526 pub restorable: bool,
527}
528
529/// `admin_restore_workspace` and `admin_purge_workspace`: staff restore a
530/// deleted workspace within [`WORKSPACE_RESTORE_DAYS`], or purge it now.
531/// `staff` is who, for the audit logs. Purging needs `confirm`, the slug
532/// typed out, and is refused for a protected workspace. Restoring publishes
533/// `workspace.restored`; purging, `workspace.deleted`. Both return
534/// `Outcome<bool>`.
535#[derive(Debug, Serialize, Deserialize)]
536#[serde(rename_all = "camelCase")]
537pub struct AdminDeletedWorkspaceArgs {
538 pub workspace_id: String,
539 pub staff: String,
540 #[serde(default)]
541 pub confirm: String,
542}
543
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look544/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
545/// tokens of agents at work on it are kept pointing at it. For repos'
546/// `transfer`. Returns `bool`.
547#[derive(Debug, Serialize, Deserialize)]
548pub struct TransferRepoScopesArgs {
549 pub from: crate::repos::RepoPath,
550 pub to: crate::repos::RepoPath,
551}
552
Agents and memory, checks and conflicts, profiles, slug renames, custom domains553/// How long a workspace's old slug keeps redirecting to it, and stays
554/// reserved for it, after a rename.
555pub const SLUG_HOLD_DAYS: u64 = 90;
556
557/// How long a workspace must wait between renames.
558pub const RENAME_COOLDOWN_HOURS: u64 = 24;
559
560// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
561// workspace's current slug when `slug` is one it was renamed from within
562// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
Merge branch 'worktree-agent-a8385d293d42c913a'563// is in use), or the workspace's slug when `slug` is one of its aliases.
564
565// `resolve_alias` takes `SlugArgs` and returns `Option<String>`: the slug
566// now of the workspace `slug` is an alias of, and null when it is none.
567// Aliases are set by g1t's staff only: `g1t` is Flagon, Inc.'s `flagon-io`.
568// An alias follows its workspace through renames.
569
570/// `admin_aliases` takes no arguments (`{}`) and returns
571/// `Vec<WorkspaceAlias>`, by alias. Staff only.
572///
573/// A name staff point at a workspace, so that its addresses (pages, git,
574/// the API, packages) lead to the workspace under its own name.
575#[derive(Clone, Debug, Serialize, Deserialize)]
576#[serde(rename_all = "camelCase")]
577pub struct WorkspaceAlias {
578 pub alias: String,
579 pub workspace_id: String,
580 /// The workspace's slug and name now.
581 pub workspace: String,
582 pub workspace_name: String,
583 /// Why it exists, as staff wrote it.
584 pub note: String,
585 /// The staff member who set it, or `migration`.
586 pub created_by: String,
587 /// RFC 3339.
588 pub created_at: String,
589}
590
591/// `admin_set_alias`: points `alias` at the workspace whose slug is
592/// `workspace`. The alias must have a namespace's shape, must not be one of
593/// the site's routes, and must not be anyone's username, a workspace's slug
594/// (deleted, or held after a rename) or another alias. `note` is required:
595/// it is the reason, kept with the alias and in sudo's audit log. Staff
596/// only. Returns `Outcome<WorkspaceAlias>`.
597#[derive(Debug, Serialize, Deserialize)]
598#[serde(rename_all = "camelCase")]
599pub struct AdminSetAliasArgs {
600 pub alias: String,
601 pub workspace: String,
602 pub note: String,
603 pub staff: String,
604}
605
606/// `admin_remove_alias`: the alias stops leading anywhere, and the name is
607/// nobody's again unless it is reserved. `reason` goes in sudo's audit log.
608/// Staff only. Returns `Outcome<bool>`.
609#[derive(Debug, Serialize, Deserialize)]
610#[serde(rename_all = "camelCase")]
611pub struct AdminRemoveAliasArgs {
612 pub alias: String,
613 pub reason: String,
614 pub staff: String,
615}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains616
Workspace names and icons, and a component kit for every control617/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
618/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
619/// the icon. Returns `Outcome<Workspace>`.
620#[derive(Debug, Serialize, Deserialize)]
621pub struct SetWorkspaceAvatarArgs {
622 pub actor: User,
623 pub slug: String,
624 pub image: Option<String>,
625}
626
627/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
628/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
629#[derive(Debug, Serialize, Deserialize)]
630pub struct SetUserAvatarArgs {
631 pub user: User,
632 pub image: Option<String>,
633}
634
635/// The largest avatar that can be uploaded, in bytes.
636pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
637
Agents as a team: lifecycle, merge queue, billing and a new shell638/// `list_workspace_tokens`: members only. Returns
639/// `Outcome<Vec<AccessToken>>`.
640#[derive(Debug, Serialize, Deserialize)]
641pub struct WorkspaceTokensArgs {
642 pub slug: String,
643 pub viewer: crate::Viewer,
644}
645
646/// `create_workspace_token`: owners only. The token belongs to the
647/// workspace, acts as it, and keeps working when the member who made it
648/// leaves. Returns `Outcome<CreatedAccessToken>`.
649#[derive(Debug, Serialize, Deserialize)]
650pub struct CreateWorkspaceTokenArgs {
651 pub actor: User,
652 pub slug: String,
653 pub name: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step654 /// Its scopes; null for full access.
655 #[serde(default)]
656 pub scopes: Option<Vec<String>>,
657 /// When set, the token stops working after this many seconds. It is
658 /// listed with the workspace's tokens either way. Null: no expiry.
659 #[serde(default)]
660 pub ttl_seconds: Option<u64>,
Agents as a team: lifecycle, merge queue, billing and a new shell661}
662
663/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
664#[derive(Debug, Serialize, Deserialize)]
665pub struct RemoveWorkspaceTokenArgs {
666 pub actor: User,
667 pub slug: String,
668 pub id: String,
669}
670
OAuth 2.1 sign-in for MCP clients and other applications671/// `oauth_authorize`: the signed-in person approved an application. The
672/// caller has checked the client and that it may be redirected to
673/// `redirect_uri`. Returns `OAuthCode`.
674#[derive(Debug, Serialize, Deserialize)]
675#[serde(rename_all = "camelCase")]
676pub struct OAuthAuthorizeArgs {
677 pub user: User,
678 pub client_id: String,
679 /// Shown wherever the application's access is listed.
680 pub client_name: String,
681 pub redirect_uri: String,
682 /// PKCE challenge, method S256.
683 pub code_challenge: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step684 /// What the person granted, as `resource:level`. Null: full access.
685 #[serde(default)]
686 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications687}
688
689#[derive(Debug, Serialize, Deserialize)]
690pub struct OAuthCode {
691 pub code: String,
692}
693
694/// `oauth_exchange`: redeems an authorization code.
695/// Returns `Outcome<OAuthTokens>`.
696#[derive(Debug, Serialize, Deserialize)]
697#[serde(rename_all = "camelCase")]
698pub struct OAuthExchangeArgs {
699 pub code: String,
700 pub code_verifier: String,
701 pub client_id: String,
702 pub redirect_uri: String,
703}
704
705/// `oauth_refresh`: trades a refresh token for new tokens.
706/// Returns `Outcome<OAuthTokens>`.
707#[derive(Debug, Serialize, Deserialize)]
708#[serde(rename_all = "camelCase")]
709pub struct OAuthRefreshArgs {
710 pub refresh_token: String,
711 pub client_id: String,
712}
713
714#[derive(Debug, Serialize, Deserialize)]
715#[serde(rename_all = "camelCase")]
716pub struct OAuthTokens {
717 pub access_token: String,
718 /// Works once; using it returns the next one.
719 pub refresh_token: String,
720 /// Seconds until the access token stops working.
721 pub expires_in: u64,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step722 /// The scopes granted, space-separated, or `*` for full access.
723 #[serde(default)]
724 pub scope: Option<String>,
OAuth 2.1 sign-in for MCP clients and other applications725}
726
727/// An application a person has signed in to. Listed by `list_oauth_grants`
728/// and ended by `revoke_oauth_grant`.
729#[derive(Debug, Serialize, Deserialize)]
730#[serde(rename_all = "camelCase")]
731pub struct OAuthGrant {
732 pub id: String,
733 pub client_name: String,
734 /// RFC 3339.
735 pub created_at: String,
736 /// RFC 3339.
737 pub last_used_at: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step738 /// What the person granted. Null: full access.
739 #[serde(default)]
740 pub scopes: Option<Vec<String>>,
741 /// Signed in before applications were given scopes: full access until
742 /// someone narrows it.
743 #[serde(default)]
744 pub legacy: bool,
745}
746
747/// `update_oauth_grant`: changes what an application the person signed in
748/// to may do, at once and when it refreshes. Returns `Outcome<OAuthGrant>`.
749#[derive(Debug, Serialize, Deserialize)]
750pub struct UpdateOAuthGrantArgs {
751 pub user: User,
752 pub id: String,
753 #[serde(default)]
754 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications755}
Agents as a team: lifecycle, merge queue, billing and a new shell756
757
758/// What an agent's token may do: these operations, in this repository.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API759#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
Agents as a team: lifecycle, merge queue, billing and a new shell760pub struct AgentScope {
761 pub repo: crate::repos::RepoPath,
762 /// API and MCP operation names, such as `create_issue`.
763 pub operations: Vec<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API764 /// Set on a run credential: the run it belongs to, and what it may do
765 /// with git. See [`crate::credentials`].
766 #[serde(default, skip_serializing_if = "Option::is_none")]
767 pub run: Option<crate::credentials::RunBinding>,
Agents as a team: lifecycle, merge queue, billing and a new shell768}
769
770/// `create_agent_token`: a token for a g1t agent working on someone's
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent771/// behalf. It acts as `g1t`, a member of the repository's workspace,
Agents as a team: lifecycle, merge queue, billing and a new shell772/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
773#[derive(Debug, Serialize, Deserialize)]
774#[serde(rename_all = "camelCase")]
775pub struct CreateAgentTokenArgs {
776 /// The person the agent works for; the token is recorded as theirs.
777 pub on_behalf_of: User,
778 pub scope: AgentScope,
779 pub ttl_seconds: u64,
780}
781
782// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
783// agent's token may do, or null for any other token.
784
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent785/// The id g1t's agent acts under. Only ever stored, never shown: it keeps
786/// the agent's work apart from g1t's own ([`crate::system::ID`]) where
787/// that matters, such as whether its approval counts.
Agents as a team: lifecycle, merge queue, billing and a new shell788pub const AGENT_ID: &str = "usr_g1t_agent";
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent789/// The name g1t's agent is shown by: g1t's own, [`crate::system::USERNAME`].
790/// Everything it does, people see g1t do.
791pub const AGENT_NAME: &str = crate::system::USERNAME;
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace792
793// --- Staff ---------------------------------------------------------------
794//
795// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
796// membership: only sudo calls them, over its service binding, after it has
797// verified a Cloudflare Access sign-in and its staff list. Nothing a
798// customer can reach should ever forward to them.
799
800/// `notify_owners`: emails a short notice, with one link, to each owner of
801/// a workspace with a confirmed address. Called by other services (billing
802/// warns owners near their usage limit), never on a person's behalf.
803/// Returns how many were sent.
804#[derive(Clone, Debug, Serialize, Deserialize)]
805pub struct NotifyOwnersArgs {
806 pub workspace: String,
807 pub subject: String,
808 /// One or two sentences: what happened and what it means.
809 pub intro: String,
810 /// The button's words, such as `Open billing`.
811 pub action: String,
812 /// Where the button goes; must be on g1t.sh.
813 pub link: String,
814 /// Small print: why they got it.
815 pub footer: String,
816}
817
818/// `admin_workspaces`: every workspace, newest first, at most
819/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
820/// an owner's username or email contains `query`. Returns
821/// `Vec<AdminWorkspace>`. Staff only.
822#[derive(Debug, Default, Serialize, Deserialize)]
823pub struct AdminWorkspacesArgs {
824 #[serde(default)]
825 pub query: Option<String>,
826}
827
828/// The most workspaces one `admin_workspaces` call returns.
829pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
830
831/// An owner of a workspace, as staff see them.
832#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
833pub struct AdminOwner {
834 pub username: String,
835 pub email: Option<String>,
836}
837
838/// A workspace as staff see it: who owns it and how many belong to it.
839#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
840#[serde(rename_all = "camelCase")]
841pub struct AdminWorkspace {
842 pub slug: String,
843 pub name: String,
844 /// RFC 3339.
845 pub created_at: String,
846 pub owners: Vec<AdminOwner>,
847 pub member_count: u32,
848}
849
850/// `admin_workspace`: one workspace with every member, or null. Takes
851/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
852#[derive(Clone, Debug, Serialize, Deserialize)]
853#[serde(rename_all = "camelCase")]
854pub struct AdminWorkspaceDetail {
855 pub slug: String,
856 pub name: String,
857 pub description: Option<String>,
858 /// RFC 3339.
859 pub created_at: String,
860 /// Owners first, then by username.
861 pub members: Vec<AdminMember>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member862 /// It can never be deleted ([`protected_names`]).
863 #[serde(default)]
864 pub protected: bool,
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace865}
866
867/// A member of a workspace, as staff see them.
868#[derive(Clone, Debug, Serialize, Deserialize)]
869pub struct AdminMember {
870 pub username: String,
871 pub email: Option<String>,
872 pub role: crate::Role,
873 /// When they joined the workspace. RFC 3339.
874 pub joined: String,
875}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains876
877// --- Profiles ------------------------------------------------------------
878//
879// A person's public page at `g1t.sh/u/<username>`. Everything in a
880// `Profile` is shown to anyone, signed in or not; an email address never is.
881
882/// The most characters each profile field takes.
883pub const MAX_PROFILE_NAME: usize = 80;
884pub const MAX_PROFILE_BIO: usize = 160;
885pub const MAX_PROFILE_LOCATION: usize = 80;
886pub const MAX_PROFILE_WEBSITE: usize = 200;
887pub const MAX_PROFILE_PRONOUNS: usize = 40;
888
889/// What anyone may see about a person.
890#[derive(Clone, Debug, Default, Serialize, Deserialize)]
891#[serde(rename_all = "camelCase")]
892pub struct Profile {
893 pub username: String,
894 /// The name they go by, if they gave one.
895 pub name: Option<String>,
896 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
897 pub bio: Option<String>,
898 pub location: Option<String>,
899 /// An `https://` address.
900 pub website: Option<String>,
901 pub pronouns: Option<String>,
902 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
903 pub avatar: Option<String>,
904 /// When the account was made. RFC 3339.
905 pub created_at: String,
906}
907
908// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
909// an account that does not exist.
910
911/// `update_profile`: a person changes their own profile. Every field is
912/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
913#[derive(Debug, Default, Serialize, Deserialize)]
914#[serde(rename_all = "camelCase")]
915pub struct UpdateProfileArgs {
916 pub actor: User,
917 #[serde(default)]
918 pub name: String,
919 #[serde(default)]
920 pub bio: String,
921 #[serde(default)]
922 pub location: String,
923 #[serde(default)]
924 pub website: String,
925 #[serde(default)]
926 pub pronouns: String,
927}
928
929/// `profile_workspaces`: the workspaces shown on a person's profile, as
930/// `viewer` may see them. A membership is shown only when it is no secret
931/// from the viewer: a workspace the viewer belongs to as well, or one of
932/// `public`, the workspaces the caller found the person has made a public
933/// project in (whose page shows that already). Returns
934/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
935#[derive(Debug, Serialize, Deserialize)]
936pub struct ProfileWorkspacesArgs {
937 pub username: String,
938 pub viewer: crate::Viewer,
939 #[serde(default)]
940 pub public: Vec<String>,
941}
942
943/// A workspace on a person's profile.
944#[derive(Clone, Debug, Serialize, Deserialize)]
945pub struct ProfileWorkspace {
946 pub slug: String,
947 pub name: String,
948 pub avatar: Option<String>,
949}
Search across all of g1t, Explore, and a command palette950
951/// `directory`: every account or every workspace, as their public pages
952/// show them, a page at a time in name order. For services that index
953/// them, such as search; nothing private is in it. Returns
954/// `DirectoryPage`.
955#[derive(Debug, Default, Serialize, Deserialize)]
956pub struct DirectoryArgs {
957 /// `user` or `workspace`.
958 pub kind: String,
959 /// Names after this one.
960 #[serde(default)]
961 pub after: Option<String>,
962 pub limit: u32,
963}
964
965/// One account or workspace in the directory.
966#[derive(Clone, Debug, Serialize, Deserialize)]
967#[serde(rename_all = "camelCase")]
968pub struct DirectoryEntry {
969 /// The account's or workspace's id.
970 pub id: String,
971 /// A username or a workspace's slug.
972 pub slug: String,
973 /// A person's display name or a workspace's name.
974 pub name: Option<String>,
975 /// A person's bio or a workspace's description.
976 pub bio: Option<String>,
977 pub avatar: Option<String>,
978 /// RFC 3339.
979 pub created_at: String,
980}
981
982#[derive(Clone, Debug, Default, Serialize, Deserialize)]
983pub struct DirectoryPage {
984 pub entries: Vec<DirectoryEntry>,
985 /// Where the next page starts; null on the last.
986 pub next: Option<String>,
987}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look988
989// --- Invites ---------------------------------------------------------------
990//
991// While registration is invite-only, every new account (with a password or
992// through GitHub) needs an invite code. Each person may have
993// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
994// to a workspace, whose owners share them. Inviting an email with no
995// account into a workspace makes an invite bound to that address, which
996// registers and joins in one step. See services/identity/src/invites.rs.
997
998/// Whether anyone may make an account, or only someone with an invite. Set
999/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
1000/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
1001#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1002#[serde(rename_all = "snake_case")]
1003pub enum RegistrationMode {
1004 #[default]
1005 Invite,
1006 Open,
1007}
1008
1009impl RegistrationMode {
1010 pub fn parse(text: Option<&str>) -> RegistrationMode {
1011 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
1012 Some("open") => RegistrationMode::Open,
1013 _ => RegistrationMode::Invite,
1014 }
1015 }
1016}
1017
1018/// How many invites a person may have out at once, unless identity's
1019/// `INVITES_PER_USER` var says otherwise.
1020pub const INVITES_PER_USER: u32 = 5;
1021
1022/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
1023/// otherwise.
1024pub const INVITE_TTL_DAYS: u64 = 30;
1025
1026/// Where an invite stands. Only a pending invite can be used or revoked.
1027/// An expired or revoked invite that was never used gives its inviter the
1028/// invite back.
1029#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1030#[serde(rename_all = "snake_case")]
1031pub enum InviteStatus {
1032 Pending,
1033 Redeemed,
1034 Expired,
1035 Revoked,
1036}
1037
1038/// What using an invite does.
1039#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1040#[serde(rename_all = "snake_case")]
1041pub enum InviteKind {
1042 /// Makes a new account, and joins `workspace` when one is set.
1043 Account,
1044 /// An existing account joins `workspace`. Never makes an account.
1045 Workspace,
1046}
1047
1048/// Whose allowance an invite uses.
1049#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1050#[serde(rename_all = "snake_case")]
1051pub enum InviteCharge {
1052 /// Its inviter's own.
1053 User,
1054 /// The workspace's, granted by staff and shared by its owners.
1055 Workspace,
1056 /// Nobody's: staff minted it, or it invites an existing account.
1057 None,
1058}
1059
1060/// One invite, as the person who made it sees it.
1061#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1062#[serde(rename_all = "camelCase")]
1063pub struct Invite {
1064 pub id: String,
1065 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
1066 /// is made, and afterwards to whoever made it while it is pending.
1067 /// Null otherwise.
1068 pub code: Option<String>,
1069 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
1070 pub hint: String,
1071 /// Only an account with this address can use it. Null: anyone with
1072 /// the code.
1073 pub email: Option<String>,
1074 pub kind: InviteKind,
1075 /// The workspace it joins, by slug.
1076 pub workspace: Option<String>,
1077 pub status: InviteStatus,
1078 pub charged_to: InviteCharge,
1079 /// Who made it, by username. Null when g1t staff did.
1080 pub invited_by: Option<String>,
1081 /// The account that used it, by username.
1082 pub redeemed_by: Option<String>,
1083 /// RFC 3339.
1084 pub created_at: String,
1085 /// RFC 3339.
1086 pub expires_at: String,
1087 /// RFC 3339.
1088 pub redeemed_at: Option<String>,
1089 /// RFC 3339.
1090 pub revoked_at: Option<String>,
1091 /// The staff member who minted it. Only in staff views.
1092 #[serde(default, skip_serializing_if = "Option::is_none")]
1093 pub staff: Option<String>,
1094}
1095
1096/// How many invites someone may have out, and how many they have.
1097#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1098pub struct Allowance {
1099 /// Null: no limit.
1100 pub limit: Option<u32>,
1101 /// Pending and used invites; revoked and expired ones are not counted.
1102 pub used: u32,
1103 /// Null: no limit.
1104 pub remaining: Option<u32>,
1105}
1106
1107impl Allowance {
1108 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
1109 Allowance {
1110 limit,
1111 used,
1112 remaining: limit.map(|limit| limit.saturating_sub(used)),
1113 }
1114 }
1115
1116 pub fn exhausted(&self) -> bool {
1117 self.remaining == Some(0)
1118 }
1119}
1120
1121/// A workspace's shared invites, for one of its owners.
1122#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
1123pub struct WorkspaceAllowance {
1124 pub slug: String,
1125 pub allowance: Allowance,
1126}
1127
1128/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
1129/// and what they have left. Returns `InvitesOverview`.
1130#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1131pub struct InvitesOverview {
1132 pub mode: RegistrationMode,
1133 pub allowance: Allowance,
1134 /// Workspaces the person owns that staff granted invites to.
1135 pub workspaces: Vec<WorkspaceAllowance>,
1136 pub invites: Vec<Invite>,
1137}
1138
1139/// `create_invite`: a person makes an invite, optionally for one email
1140/// address. People only; never an agent or a workspace's token, and not
1141/// before their email is confirmed. Uses one of the person's invites, or,
1142/// with `workspace`, one of the invites staff granted that workspace (its
1143/// owners only). Emails the address when one is given. Returns
1144/// `Outcome<Invite>`, with the code.
1145///
1146/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
1147/// invite; a workspace's owners may revoke one made for the workspace.
1148/// The invite comes back to whoever it was charged to. Returns
1149/// `Outcome<Invite>`.
1150#[derive(Debug, Serialize, Deserialize)]
1151pub struct CreateInviteArgs {
1152 pub user: User,
1153 #[serde(default)]
1154 pub email: Option<String>,
1155 /// Use this workspace's granted invites, by slug.
1156 #[serde(default)]
1157 pub workspace: Option<String>,
1158 /// Where the request came in, for the audit log; g1t.sh when absent.
1159 #[serde(default)]
1160 pub surface: Option<crate::audit::Surface>,
1161}
1162
1163/// `check_invite`: what an invite code is for, before using it. Returns
1164/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1165/// expired gets the same answer, so codes cannot be probed. With
1166/// `any_status`, a real code that can no longer be used is described
1167/// instead (its `status` says why), so the page can say whom to ask for a
1168/// new one; an unknown code still gets the one answer.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1169#[derive(Debug, Serialize, Deserialize)]
1170pub struct InviteCodeArgs {
1171 pub code: String,
1172 /// Who is asking, such as the visitor's IP address, for rate limits.
1173 #[serde(default)]
1174 pub client: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1175 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
1176 #[serde(default)]
1177 pub viewer: Option<User>,
1178 #[serde(default)]
1179 pub any_status: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1180}
1181
1182/// Someone shown on an invite.
1183#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1184pub struct InviteFrom {
1185 pub username: String,
1186 pub name: Option<String>,
1187 pub avatar: Option<String>,
1188}
1189
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1190/// A repository an invite code was sent with: using the code accepts the
1191/// invitation to collaborate on it.
1192#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1193pub struct InviteRepository {
1194 /// `workspace/repo`.
1195 pub name: String,
1196 /// The role it gives, such as `write`.
1197 pub role: String,
1198}
1199
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1200/// What a valid invite code is for.
1201#[derive(Clone, Debug, Serialize, Deserialize)]
1202#[serde(rename_all = "camelCase")]
1203pub struct InvitePreview {
1204 pub kind: InviteKind,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1205 /// Pending, unless `any_status` asked about a code that is spent.
1206 pub status: InviteStatus,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1207 /// Null when g1t staff sent it.
1208 pub invited_by: Option<InviteFrom>,
1209 pub workspace: Option<ProfileWorkspace>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1210 /// The repository it accepts an invitation to, if it was sent with one.
1211 pub repository: Option<InviteRepository>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1212 /// The address it is for, partly hidden, such as `a•••@example.com`.
1213 pub email: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1214 /// The address in full, while it is pending: whoever holds the code
1215 /// was sent it there. Fills in and locks the sign-up form.
1216 pub address: Option<String>,
1217 /// Whether the address it is for has a g1t account already, so the
1218 /// page asks them to sign in rather than sign up.
1219 pub has_account: bool,
1220 /// With a viewer: whether the invite is theirs (it is for one of their
1221 /// confirmed addresses, or they used it). Null without a viewer or,
1222 /// for a pending invite, when it is for anyone with the code.
1223 pub for_viewer: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1224 /// RFC 3339.
1225 pub expires_at: String,
1226}
1227
1228/// `accept_invite`: a signed-in person uses a workspace invite made for
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1229/// their confirmed address, and joins the workspace, or an invite sent with
1230/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1231/// workspace's slug, or `workspace/repo`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1232#[derive(Debug, Serialize, Deserialize)]
1233pub struct AcceptInviteArgs {
1234 pub user: User,
1235 pub code: String,
1236}
1237
1238/// `invite_member`: an owner invites an email address into a workspace.
1239/// It always makes an invite bound to that address and emails it, so the
1240/// answer never says whether the address has an account. Without one, the
1241/// invite registers and joins in one step, and uses one of the workspace's
1242/// granted invites or else one of the owner's own. With one, it costs
1243/// nothing. Returns `Outcome<Invite>`, with the code.
1244#[derive(Debug, Serialize, Deserialize)]
1245pub struct InviteMemberArgs {
1246 pub actor: User,
1247 pub slug: String,
1248 pub email: String,
1249 /// Where the request came in, for the audit log; g1t.sh when absent.
1250 #[serde(default)]
1251 pub surface: Option<crate::audit::Surface>,
1252}
1253
1254/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1255/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1256///
1257/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1258#[derive(Debug, Serialize, Deserialize)]
1259pub struct WorkspaceInviteArgs {
1260 pub actor: User,
1261 pub slug: String,
1262 pub id: String,
1263}
1264
1265/// `request_access`: someone without an invite asks for one. Kept on the
1266/// waitlist, one entry per address. Answers the same way whether or not
1267/// the address is already on it. Returns `Outcome<bool>`.
1268#[derive(Debug, Default, Serialize, Deserialize)]
1269pub struct RequestAccessArgs {
1270 pub email: String,
1271 /// What they will build, if they said.
1272 #[serde(default)]
1273 pub about: String,
1274 /// Who is asking, such as the visitor's IP address, for rate limits.
1275 #[serde(default)]
1276 pub client: Option<String>,
1277}
1278
1279/// The most characters `RequestAccessArgs::about` keeps.
1280pub const MAX_WAITLIST_ABOUT: usize = 1000;
1281
1282// `registration` takes `{}` and returns `RegistrationMode`.
1283
1284// --- Invites, staff only ---
1285
1286#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1287#[serde(rename_all = "snake_case")]
1288pub enum WaitlistStatus {
1289 Waiting,
1290 Invited,
1291 Dismissed,
1292}
1293
1294impl WaitlistStatus {
1295 pub fn as_str(self) -> &'static str {
1296 match self {
1297 WaitlistStatus::Waiting => "waiting",
1298 WaitlistStatus::Invited => "invited",
1299 WaitlistStatus::Dismissed => "dismissed",
1300 }
1301 }
1302}
1303
1304/// Someone who asked for access.
1305#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1306#[serde(rename_all = "camelCase")]
1307pub struct WaitlistEntry {
1308 pub id: String,
1309 pub email: String,
1310 pub about: Option<String>,
1311 pub status: WaitlistStatus,
1312 pub invite_id: Option<String>,
1313 pub decided_by: Option<String>,
1314 /// RFC 3339.
1315 pub decided_at: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1316 /// What staff wrote when approving; it went in the invite email.
1317 #[serde(default)]
1318 pub note: Option<String>,
1319 /// The account made with the invite, once it was used.
1320 #[serde(default)]
1321 pub joined_as: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1322 /// When they first asked. RFC 3339.
1323 pub created_at: String,
1324 /// When they last asked. RFC 3339.
1325 pub updated_at: String,
1326}
1327
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1328/// `admin_waitlist`: the waitlist, newest first, at most
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1329/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1330///
1331/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1332/// still waiting, for sudo's navigation.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1333#[derive(Debug, Default, Serialize, Deserialize)]
1334pub struct AdminWaitlistArgs {
1335 /// Part of an email address or of what they said.
1336 #[serde(default)]
1337 pub query: Option<String>,
1338 /// Null: every status.
1339 #[serde(default)]
1340 pub status: Option<WaitlistStatus>,
1341}
1342
1343/// The most rows one staff listing of invites or the waitlist returns.
1344pub const ADMIN_INVITES_LIMIT: usize = 500;
1345
1346/// `admin_decide_waitlist`: approving mints an invite bound to the
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1347/// address, charged to nobody, and emails it, with `note` if given;
1348/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1349#[derive(Debug, Serialize, Deserialize)]
1350pub struct AdminDecideWaitlistArgs {
1351 pub id: String,
1352 pub approve: bool,
1353 /// The staff member, by email.
1354 pub staff: String,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1355 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1356 #[serde(default)]
1357 pub note: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1358}
1359
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1360/// The most characters an approval's note keeps.
1361pub const MAX_WAITLIST_NOTE: usize = 500;
1362
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1363/// `admin_invites`: every invite, newest first, at most
1364/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1365/// `query`, or whose email, inviter or redeemer contains it. Returns
1366/// `Vec<Invite>`.
1367#[derive(Debug, Default, Serialize, Deserialize)]
1368pub struct AdminInvitesArgs {
1369 #[serde(default)]
1370 pub query: Option<String>,
1371}
1372
1373/// `admin_revoke_invite`: revokes any pending invite. Returns
1374/// `Outcome<Invite>`.
1375#[derive(Debug, Serialize, Deserialize)]
1376pub struct AdminRevokeInviteArgs {
1377 pub id: String,
1378 pub staff: String,
1379}
1380
1381/// `admin_mint_invite`: staff make an invite that uses nobody's
1382/// allowance, optionally bound to (and emailed to) an address. Returns
1383/// `Outcome<Invite>`, with the code.
1384#[derive(Debug, Serialize, Deserialize)]
1385pub struct AdminMintInviteArgs {
1386 #[serde(default)]
1387 pub email: Option<String>,
1388 pub staff: String,
1389}
1390
1391/// Who staff grant invites to.
1392#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1393#[serde(rename_all = "snake_case")]
1394pub enum GrantTarget {
1395 User,
1396 Workspace,
1397}
1398
1399impl GrantTarget {
1400 pub fn as_str(self) -> &'static str {
1401 match self {
1402 GrantTarget::User => "user",
1403 GrantTarget::Workspace => "workspace",
1404 }
1405 }
1406}
1407
1408/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1409/// slug) `amount` more invites; a negative amount takes some back. Returns
1410/// `Outcome<Allowance>`: theirs afterwards.
1411#[derive(Debug, Serialize, Deserialize)]
1412pub struct AdminGrantInvitesArgs {
1413 pub target: GrantTarget,
1414 pub name: String,
1415 pub amount: i32,
1416 #[serde(default)]
1417 pub note: String,
1418 pub staff: String,
1419}
1420
1421/// The most invites one grant gives or takes back.
1422pub const MAX_INVITE_GRANT: i32 = 1000;
1423
1424/// Invites staff granted.
1425#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1426#[serde(rename_all = "camelCase")]
1427pub struct InviteGrant {
1428 pub amount: i32,
1429 pub note: Option<String>,
1430 pub granted_by: String,
1431 /// RFC 3339.
1432 pub created_at: String,
1433}
1434
1435/// Someone a person invited, and whom they invited in turn.
1436#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1437#[serde(rename_all = "camelCase")]
1438pub struct InviteTreeNode {
1439 pub username: String,
1440 /// When they used the invite. RFC 3339.
1441 pub joined_at: String,
1442 pub invited: Vec<InviteTreeNode>,
1443}
1444
1445/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1446/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1447///
1448/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1449/// invites, grants and invites. Returns `Option<InviteTree>` with
1450/// `username` the slug and no `invited_by`.
1451#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1452#[serde(rename_all = "camelCase")]
1453pub struct InviteTree {
1454 pub username: String,
1455 /// Who invited them, then who invited that person, and so on. Empty
1456 /// for an account made without an invite.
1457 pub invited_by: Vec<String>,
1458 /// The staff member who minted their invite, when staff did.
1459 pub staff: Option<String>,
1460 pub allowance: Allowance,
1461 pub grants: Vec<InviteGrant>,
1462 /// Their invites, newest first.
1463 pub invites: Vec<Invite>,
1464 /// Whom they invited, three levels down.
1465 pub invited: Vec<InviteTreeNode>,
1466}
1467
1468#[cfg(test)]
1469mod deletion_tests {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1470 use super::{WorkspaceDeletion, protected_names};
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1471
1472 #[test]
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1473 fn only_billing_or_protection_stands_in_the_way() {
1474 let clear = WorkspaceDeletion {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1475 repositories: 2,
1476 projects: 1,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1477 members: 3,
1478 ..WorkspaceDeletion::default()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1479 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1480 assert!(!clear.blocked());
1481 assert_eq!(clear.reason("acme"), None);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1482 let owing = WorkspaceDeletion {
1483 billing: Some("Pay first.".into()),
1484 ..WorkspaceDeletion::default()
1485 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1486 assert!(owing.blocked());
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1487 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1488 let protected = WorkspaceDeletion {
1489 billing: Some("Pay first.".into()),
1490 protected: true,
1491 ..WorkspaceDeletion::default()
1492 };
1493 assert!(protected.blocked());
1494 assert_eq!(
1495 protected.reason("flagon-io").as_deref(),
1496 Some("flagon-io is protected and can never be deleted.")
1497 );
1498 }
1499
1500 #[test]
1501 fn flagon_is_protected_whatever_the_variable_says() {
1502 assert_eq!(protected_names(None), ["flagon-io"]);
1503 assert_eq!(protected_names(Some("")), ["flagon-io"]);
1504 assert_eq!(protected_names(Some(" , ")), ["flagon-io"]);
1505 assert_eq!(
1506 protected_names(Some("Flagon-IO, acme ,wsp_1")),
1507 ["flagon-io", "acme", "wsp_1"]
1508 );
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1509 }
1510}

This file's history is long; its oldest lines are credited to the oldest commit read.