Skip to content

g1t/crates/contracts/src/lib.rs

209 lines7,549 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod access;
8pub mod accounts;
9pub mod actions;
10pub mod agents;
11pub mod audit;
12pub mod backups;
13pub mod billing;
14pub mod capture;
15pub mod codeowners;
16pub mod credentials;
17pub mod events;
18pub mod github;
19pub mod guardrails;
20pub mod identity;
21pub mod inbox;
22pub mod integrations;
23mod ids;
24mod names;
25mod outcome;
26pub mod packages;
27pub mod projects;
28pub mod repos;
29pub mod runners;
30pub mod scopes;
31pub mod search;
32pub mod security;
33pub mod teams;
34pub mod security_suite;
35pub mod time;
36pub mod updates;
37pub mod webhooks;
38pub mod work;
39
40pub use ids::new_id;
41pub use names::{
42 aliasable_name, claimable_namespace, is_namespace_shaped, is_reserved_name, is_route_name, is_valid_namespace,
43 is_valid_repo_name,
44};
45pub use outcome::{Failure, FailureCode, Outcome};
46
47use serde::{Deserialize, Serialize};
48
49/// What a member may do in a workspace.
50#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
51#[serde(rename_all = "lowercase")]
52pub enum Role {
53 /// Everything a member can, plus managing members.
54 Owner,
55 /// Create repositories, push, manage issues and merge pull requests.
56 Member,
57}
58
59/// One workspace a user belongs to.
60#[derive(Clone, Debug, Serialize, Deserialize)]
61pub struct Membership {
62 /// The workspace's name in URLs: `g1t.sh/<slug>`.
63 pub slug: String,
64 pub role: Role,
65 /// The workspace's display name, for showing it to people. Set when a
66 /// user is resolved from credentials; absent on principals made up by
67 /// a service.
68 #[serde(default, skip_serializing_if = "Option::is_none")]
69 pub name: Option<String>,
70 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
71 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
72 #[serde(default, skip_serializing_if = "Option::is_none")]
73 pub avatar: Option<String>,
74 /// What a member gets on each of the workspace's repositories: the
75 /// workspace's base permission. Set when a user is resolved from
76 /// credentials; absent means the default, Write. Owners have Admin
77 /// whatever it says. See [`access`].
78 #[serde(default, skip_serializing_if = "Option::is_none")]
79 pub base_permission: Option<access::BasePermission>,
80 /// Who may create the workspace's teams. Set when a user is resolved
81 /// from credentials; absent means the default, any member. See
82 /// [`teams::TeamCreation`].
83 #[serde(default, skip_serializing_if = "Option::is_none")]
84 pub team_creation: Option<teams::TeamCreation>,
85}
86
87impl Membership {
88 /// A plain member of `slug`, as services act inside one workspace.
89 pub fn member(slug: impl Into<String>) -> Self {
90 Membership {
91 slug: slug.into(),
92 role: Role::Member,
93 name: None,
94 avatar: None,
95 base_permission: None,
96 team_creation: None,
97 }
98 }
99}
100
101/// What a set of credentials resolved to.
102#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
103#[serde(rename_all = "lowercase")]
104pub enum PrincipalKind {
105 /// A person's account.
106 #[default]
107 User,
108 /// A workspace, acting through one of its own access tokens. Its `id`
109 /// is the workspace's, its `username` the workspace's slug, and it is a
110 /// member of that workspace and no other.
111 Workspace,
112 /// A g1t agent at work in a sandbox, acting through a token that lives
113 /// as long as its run and can do only what that token's scope lists, in
114 /// one repository. Its `username` is `g1t`.
115 Agent,
116 /// g1t itself: the platform acting on its own, as when it opens a
117 /// pull request to upgrade a vulnerable dependency or merges from the
118 /// queue. Never resolved from credentials: only services make one,
119 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
120 /// register.
121 System,
122}
123
124/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
125pub mod system {
126 /// Its id wherever an author or actor id is stored.
127 pub const ID: &str = "g1t";
128 /// Its name, shown as the author of what it does.
129 pub const USERNAME: &str = "g1t";
130 /// The address on the commits it makes, which no mailbox receives.
131 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
132 /// Ids that earlier versions stored for g1t's own actions, such as a
133 /// merge its settings made. Read as g1t too.
134 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
135
136 /// Whether `id` is g1t's own.
137 pub fn is_system_id(id: &str) -> bool {
138 id == ID || LEGACY_IDS.contains(&id)
139 }
140}
141
142#[derive(Clone, Debug, Default, Serialize, Deserialize)]
143pub struct User {
144 pub id: String,
145 pub username: String,
146 #[serde(default)]
147 pub kind: PrincipalKind,
148 /// Whether the account's email address has been confirmed. Unverified
149 /// accounts can sign in but cannot create or change anything.
150 #[serde(default)]
151 pub verified: bool,
152 /// The workspaces this user belongs to. Filled in when a user is
153 /// resolved from credentials, so any service can authorize from it.
154 #[serde(default)]
155 pub workspaces: Vec<Membership>,
156 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
157 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
158 #[serde(default, skip_serializing_if = "Option::is_none")]
159 pub avatar: Option<String>,
160 /// Set on an agent resolved from its token: who it acts for, with which
161 /// credential, and what it may do. See [`credentials`].
162 #[serde(default, skip_serializing_if = "Option::is_none")]
163 pub acting: Option<Box<credentials::Acting>>,
164 /// The repositories this user has been given a role on directly,
165 /// whether or not they belong to its workspace. Filled in with
166 /// `workspaces`; see [`access`].
167 #[serde(default, skip_serializing_if = "Vec::is_empty")]
168 pub grants: Vec<access::RepoGrant>,
169 /// Set on a user resolved from an access token: its scopes and the
170 /// workspaces or repositories it is limited to. Absent on a signed-in
171 /// session and on an agent (whose `acting` scope applies instead).
172 /// See [`scopes`].
173 #[serde(default, skip_serializing_if = "Option::is_none")]
174 pub token: Option<Box<scopes::TokenAccess>>,
175}
176
177impl User {
178 /// g1t itself, acting in `workspace`: what the platform's own work,
179 /// such as security updates, is done and recorded as.
180 pub fn system(workspace: &str) -> User {
181 User {
182 id: system::ID.to_owned(),
183 username: system::USERNAME.to_owned(),
184 kind: PrincipalKind::System,
185 verified: true,
186 workspaces: vec![Membership::member(workspace.to_lowercase())],
187 ..User::default()
188 }
189 }
190
191 /// Whether this is g1t itself.
192 pub fn is_system(&self) -> bool {
193 self.kind == PrincipalKind::System
194 }
195
196 pub fn role_in(&self, slug: &str) -> Option<Role> {
197 self.workspaces
198 .iter()
199 .find(|membership| membership.slug == slug)
200 .map(|membership| membership.role)
201 }
202
203 pub fn is_member(&self, slug: &str) -> bool {
204 self.role_in(slug).is_some()
205 }
206}
207
208/// Who is asking. Every read and write in every service takes one.
209pub type Viewer = Option<User>;