g1t/crates/contracts/src/lib.rs

194 lines7,055 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod access;
8pub mod accounts;
9pub mod actions;
10pub mod agents;
11pub mod audit;
12pub mod billing;
13pub mod capture;
14pub mod credentials;
15pub mod events;
16pub mod github;
17pub mod guardrails;
18pub mod identity;
19pub mod integrations;
20mod ids;
21mod names;
22mod outcome;
23pub mod packages;
24pub mod projects;
25pub mod repos;
26pub mod runners;
27pub mod scopes;
28pub mod search;
29pub mod security;
30pub mod time;
31pub mod webhooks;
32pub mod work;
33
34pub use ids::new_id;
35pub use names::{claimable_namespace, is_reserved_name, is_valid_namespace, is_valid_repo_name};
36pub use outcome::{Failure, FailureCode, Outcome};
37
38use serde::{Deserialize, Serialize};
39
40/// What a member may do in a workspace.
41#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
42#[serde(rename_all = "lowercase")]
43pub enum Role {
44 /// Everything a member can, plus managing members.
45 Owner,
46 /// Create repositories, push, manage issues and merge pull requests.
47 Member,
48}
49
50/// One workspace a user belongs to.
51#[derive(Clone, Debug, Serialize, Deserialize)]
52pub struct Membership {
53 /// The workspace's name in URLs: `g1t.sh/<slug>`.
54 pub slug: String,
55 pub role: Role,
56 /// The workspace's display name, for showing it to people. Set when a
57 /// user is resolved from credentials; absent on principals made up by
58 /// a service.
59 #[serde(default, skip_serializing_if = "Option::is_none")]
60 pub name: Option<String>,
61 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
62 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
63 #[serde(default, skip_serializing_if = "Option::is_none")]
64 pub avatar: Option<String>,
65 /// What a member gets on each of the workspace's repositories: the
66 /// workspace's base permission. Set when a user is resolved from
67 /// credentials; absent means the default, Write. Owners have Admin
68 /// whatever it says. See [`access`].
69 #[serde(default, skip_serializing_if = "Option::is_none")]
70 pub base_permission: Option<access::BasePermission>,
71}
72
73impl Membership {
74 /// A plain member of `slug`, as services act inside one workspace.
75 pub fn member(slug: impl Into<String>) -> Self {
76 Membership {
77 slug: slug.into(),
78 role: Role::Member,
79 name: None,
80 avatar: None,
81 base_permission: None,
82 }
83 }
84}
85
86/// What a set of credentials resolved to.
87#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
88#[serde(rename_all = "lowercase")]
89pub enum PrincipalKind {
90 /// A person's account.
91 #[default]
92 User,
93 /// A workspace, acting through one of its own access tokens. Its `id`
94 /// is the workspace's, its `username` the workspace's slug, and it is a
95 /// member of that workspace and no other.
96 Workspace,
97 /// A g1t agent at work in a sandbox, acting through a token that lives
98 /// as long as its run and can do only what that token's scope lists, in
99 /// one repository. Its `username` is `g1t`.
100 Agent,
101 /// g1t itself: the platform acting on its own, as when it opens a
102 /// pull request to upgrade a vulnerable dependency or merges from the
103 /// queue. Never resolved from credentials: only services make one,
104 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
105 /// register.
106 System,
107}
108
109/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
110pub mod system {
111 /// Its id wherever an author or actor id is stored.
112 pub const ID: &str = "g1t";
113 /// Its name, shown as the author of what it does.
114 pub const USERNAME: &str = "g1t";
115 /// The address on the commits it makes, which no mailbox receives.
116 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
117 /// Ids that earlier versions stored for g1t's own actions, such as a
118 /// merge its settings made. Read as g1t too.
119 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
120
121 /// Whether `id` is g1t's own.
122 pub fn is_system_id(id: &str) -> bool {
123 id == ID || LEGACY_IDS.contains(&id)
124 }
125}
126
127#[derive(Clone, Debug, Default, Serialize, Deserialize)]
128pub struct User {
129 pub id: String,
130 pub username: String,
131 #[serde(default)]
132 pub kind: PrincipalKind,
133 /// Whether the account's email address has been confirmed. Unverified
134 /// accounts can sign in but cannot create or change anything.
135 #[serde(default)]
136 pub verified: bool,
137 /// The workspaces this user belongs to. Filled in when a user is
138 /// resolved from credentials, so any service can authorize from it.
139 #[serde(default)]
140 pub workspaces: Vec<Membership>,
141 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
142 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
143 #[serde(default, skip_serializing_if = "Option::is_none")]
144 pub avatar: Option<String>,
145 /// Set on an agent resolved from its token: who it acts for, with which
146 /// credential, and what it may do. See [`credentials`].
147 #[serde(default, skip_serializing_if = "Option::is_none")]
148 pub acting: Option<Box<credentials::Acting>>,
149 /// The repositories this user has been given a role on directly,
150 /// whether or not they belong to its workspace. Filled in with
151 /// `workspaces`; see [`access`].
152 #[serde(default, skip_serializing_if = "Vec::is_empty")]
153 pub grants: Vec<access::RepoGrant>,
154 /// Set on a user resolved from an access token: its scopes and the
155 /// workspaces or repositories it is limited to. Absent on a signed-in
156 /// session and on an agent (whose `acting` scope applies instead).
157 /// See [`scopes`].
158 #[serde(default, skip_serializing_if = "Option::is_none")]
159 pub token: Option<Box<scopes::TokenAccess>>,
160}
161
162impl User {
163 /// g1t itself, acting in `workspace`: what the platform's own work,
164 /// such as security updates, is done and recorded as.
165 pub fn system(workspace: &str) -> User {
166 User {
167 id: system::ID.to_owned(),
168 username: system::USERNAME.to_owned(),
169 kind: PrincipalKind::System,
170 verified: true,
171 workspaces: vec![Membership::member(workspace.to_lowercase())],
172 ..User::default()
173 }
174 }
175
176 /// Whether this is g1t itself.
177 pub fn is_system(&self) -> bool {
178 self.kind == PrincipalKind::System
179 }
180
181 pub fn role_in(&self, slug: &str) -> Option<Role> {
182 self.workspaces
183 .iter()
184 .find(|membership| membership.slug == slug)
185 .map(|membership| membership.role)
186 }
187
188 pub fn is_member(&self, slug: &str) -> bool {
189 self.role_in(slug).is_some()
190 }
191}
192
193/// Who is asking. Every read and write in every service takes one.
194pub type Viewer = Option<User>;