Skip to content
1,548 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
RFC 3339 timestamps in identity and repos16 /// RFC 3339.
17 pub created_at: String,
API and MCP server, Rust identity service, registration, site redesign18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
RFC 3339 timestamps in identity and repos25 /// RFC 3339.
26 pub created_at: String,
Agents as a team: lifecycle, merge queue, billing and a new shell27 /// RFC 3339, to within a few minutes. Null until it is first used.
28 pub last_used_at: Option<String>,
29 /// For a workspace's token, the username of the member who made it.
30 /// Null once that account is gone, and on personal tokens.
31 pub created_by: Option<String>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step32 /// Its scopes, as `resource:level`. Null: full access.
33 #[serde(default)]
34 pub scopes: Option<Vec<String>>,
35 /// Made before tokens had scopes: full access until someone narrows it.
36 #[serde(default)]
37 pub legacy: bool,
38 /// RFC 3339. Null: it does not expire.
39 #[serde(default)]
40 pub expires_at: Option<String>,
API and MCP server, Rust identity service, registration, site redesign41}
42
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look43/// `sign_in`: verifies a username, or any confirmed email address of the
44/// account, and its password, for website sign-in. Wrong passwords are
45/// counted against the account and `client`, and past a limit nothing is
46/// checked for a while (see identity's `throttle.rs`).
API and MCP server, Rust identity service, registration, site redesign47/// Returns `Outcome<SignedIn>`.
48#[derive(Debug, Serialize, Deserialize)]
49pub struct SignInArgs {
50 pub username: String,
51 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look52 /// Who is asking, such as the visitor's IP address, for rate limits.
53 #[serde(default)]
54 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign55}
56
57#[derive(Debug, Serialize, Deserialize)]
58#[serde(rename_all = "camelCase")]
59pub struct SignedIn {
60 pub user: User,
61 pub session_token: String,
62}
63
64/// `sign_out` and `user_for_session`.
65#[derive(Debug, Serialize, Deserialize)]
66#[serde(rename_all = "camelCase")]
67pub struct SessionArgs {
68 pub session_token: String,
69}
70
71/// `user_for_git_credentials`: the account password or an access token.
72#[derive(Debug, Serialize, Deserialize)]
73pub struct GitCredentialsArgs {
74 pub username: String,
75 pub secret: String,
76}
77
78/// `user_for_access_token`.
79#[derive(Debug, Serialize, Deserialize)]
80pub struct TokenArgs {
81 pub token: String,
82}
83
84/// `user_for_ssh_key`.
85#[derive(Debug, Serialize, Deserialize)]
86pub struct FingerprintArgs {
87 pub fingerprint: String,
88}
89
90/// `user_by_username`.
91#[derive(Debug, Serialize, Deserialize)]
92pub struct UsernameArgs {
93 pub username: String,
94}
95
What happened across an outcome, as a feed beside its graph96/// `usernames`: the names behind account and workspace ids, as events and
97/// other records store them. Returns a map from id to name; ids it does
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9798/// not know are left out. Also `accounts`: the accounts behind user ids,
99/// each with its username and avatar (`HashMap<String, accounts::EmailOwner>`).
What happened across an outcome, as a feed beside its graph100#[derive(Debug, Serialize, Deserialize)]
101pub struct UsernamesArgs {
102 pub ids: Vec<String>,
103}
104
API and MCP server, Rust identity service, registration, site redesign105/// `list_ssh_keys` and `list_access_tokens`.
106#[derive(Debug, Serialize, Deserialize)]
107pub struct UserArgs {
108 pub user: User,
109}
110
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge111/// `ssh_key_owners`: services only. The account (user id) that registered
112/// each key, by fingerprint (`SHA256:…`, as `ssh-keygen -lf` prints it),
113/// for verifying commits signed with SSH keys. Returns a map of the
114/// fingerprints found to user ids.
115#[derive(Debug, Serialize, Deserialize)]
116pub struct SshKeyOwnersArgs {
117 pub fingerprints: Vec<String>,
118}
119
API and MCP server, Rust identity service, registration, site redesign120/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
121/// Returns `Outcome<SshKey>`.
122#[derive(Debug, Serialize, Deserialize)]
123#[serde(rename_all = "camelCase")]
124pub struct AddSshKeyArgs {
125 pub user: User,
126 pub title: String,
127 pub public_key: String,
128}
129
130/// `remove_ssh_key` and `remove_access_token`.
131#[derive(Debug, Serialize, Deserialize)]
132pub struct RemoveArgs {
133 pub user: User,
134 pub id: String,
135}
136
Agents as a team: lifecycle, merge queue, billing and a new shell137/// `create_access_token`: a token that acts as `user`. For a workspace
138/// acting through a token of its own, the new token belongs to that
139/// workspace too.
API and MCP server, Rust identity service, registration, site redesign140#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)141#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign142pub struct CreateAccessTokenArgs {
143 pub user: User,
144 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)145 /// When set, the token stops working after this many seconds and is
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step146 /// left out of the user's token list, unless `listed`. Used for hosted
147 /// attempts.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)148 #[serde(default)]
149 pub ttl_seconds: Option<u64>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step150 /// Its scopes, as `resource:level`; unknown names are left out. Null:
151 /// full access.
152 #[serde(default)]
153 pub scopes: Option<Vec<String>>,
154 /// Listed with the person's tokens although it expires: one they made
155 /// themselves, with an expiry.
156 #[serde(default)]
157 pub listed: bool,
158}
159
Actions: keep workflow runs safe160/// `create_job_token`: a workflow job's `G1T_TOKEN`. It acts as the
161/// repository's workspace, reaches that repository only, holds `scopes`
162/// (from the job's `permissions`), and is never listed. The actions service
163/// revokes it when the job ends (`revoke_job_tokens`); `ttl_seconds` is a
164/// backstop. Returns `CreatedAccessToken`.
165#[derive(Debug, Serialize, Deserialize)]
166#[serde(rename_all = "camelCase")]
167pub struct CreateJobTokenArgs {
168 /// The workspace the repository belongs to, as its own principal.
169 pub workspace: User,
170 pub repo: crate::repos::RepoPath,
171 pub run_id: String,
172 pub job_id: String,
173 /// What the token is listed as in logs: `G1T_TOKEN for acme/web run 4`.
174 pub name: String,
175 pub ttl_seconds: u64,
176 /// As `resource:level`; unknown names are left out.
177 pub scopes: Vec<String>,
178}
179
180/// `revoke_job_tokens`: ends a workflow job's tokens at once, when the job
181/// finishes or is cancelled. Only job tokens are touched. Returns `bool`.
182#[derive(Debug, Default, Serialize, Deserialize)]
183#[serde(rename_all = "camelCase")]
184pub struct RevokeJobTokensArgs {
185 pub job_id: String,
186}
187
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step188/// `update_access_token`: changes what one of a person's tokens may do.
189/// The token itself is unchanged. Returns `Outcome<AccessToken>`.
190#[derive(Debug, Serialize, Deserialize)]
191pub struct UpdateAccessTokenArgs {
192 pub user: User,
193 pub id: String,
194 /// Null: full access.
195 #[serde(default)]
196 pub scopes: Option<Vec<String>>,
API and MCP server, Rust identity service, registration, site redesign197}
198
199/// The plaintext token is returned once and never stored.
200#[derive(Debug, Serialize, Deserialize)]
201pub struct CreatedAccessToken {
202 pub token: String,
203 pub info: AccessToken,
204}
205
206/// `register`: creates an account and signs it in.
207/// Returns `Outcome<SignedIn>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look208///
209/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
210/// new account needs `invite_code`: an unused, unexpired invite, and, when
211/// the invite names an email, that address. See [`CreateInviteArgs`].
API and MCP server, Rust identity service, registration, site redesign212#[derive(Debug, Serialize, Deserialize)]
213pub struct RegisterArgs {
214 pub username: String,
215 pub email: String,
216 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look217 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
218 /// registration is open.
219 #[serde(default)]
220 pub invite_code: Option<String>,
221 /// Who is asking, such as the visitor's IP address, for rate limits.
222 #[serde(default)]
223 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign224}
Email verification, password reset, and Git for AI scale positioning225
226/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
227#[derive(Debug, Serialize, Deserialize)]
228pub struct EmailTokenArgs {
229 pub token: String,
230}
231
232/// `request_password_reset`. Always succeeds, so it cannot be used to find
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look233/// out which addresses have accounts. Any confirmed address of an account
234/// works: the link goes to the address given, and the primary (and the
235/// backup) are told a reset was asked for. A few requests an hour per
236/// address and per `client`; past that, nothing is sent.
Email verification, password reset, and Git for AI scale positioning237#[derive(Debug, Serialize, Deserialize)]
238pub struct EmailArgs {
239 pub email: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look240 /// Who is asking, such as the visitor's IP address, for rate limits.
241 #[serde(default)]
242 pub client: Option<String>,
Email verification, password reset, and Git for AI scale positioning243}
244
245/// `reset_password`: sets a new password and ends every session.
246/// Returns `Outcome<User>`.
247#[derive(Debug, Serialize, Deserialize)]
248pub struct ResetPasswordArgs {
249 pub token: String,
250 pub password: String,
251}
Device sign-in replaces registering and minting tokens over the API252
253/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
254#[derive(Debug, Serialize, Deserialize)]
255#[serde(rename_all = "camelCase")]
256pub struct DeviceStartArgs {
257 /// What is asking, shown to the person approving, e.g. "Claude Code".
258 pub client_name: String,
259}
260
261#[derive(Debug, Serialize, Deserialize)]
262#[serde(rename_all = "camelCase")]
263pub struct DeviceStart {
264 /// Secret held by the tool and exchanged for a token once approved.
265 pub device_code: String,
266 /// Short code shown to the person, e.g. `WDJB-MJHT`.
267 pub user_code: String,
268 /// Seconds until both codes stop working.
269 pub expires_in: u32,
270 /// Seconds the tool should wait between polls.
271 pub interval: u32,
272}
273
274/// `device_lookup`: what a user code is asking for, or null if it is not
275/// valid. Returns `Option<DeviceRequest>`.
276#[derive(Debug, Serialize, Deserialize)]
277#[serde(rename_all = "camelCase")]
278pub struct DeviceLookupArgs {
279 pub user_code: String,
280}
281
282#[derive(Debug, Serialize, Deserialize)]
283#[serde(rename_all = "camelCase")]
284pub struct DeviceRequest {
285 pub user_code: String,
286 pub client_name: String,
287}
288
289/// `device_resolve`: the signed-in person approves or denies a request.
290/// Returns `Outcome<bool>`.
291#[derive(Debug, Serialize, Deserialize)]
292#[serde(rename_all = "camelCase")]
293pub struct DeviceResolveArgs {
294 pub user_code: String,
295 pub user: User,
296 pub approve: bool,
297}
298
299/// `device_claim`: the tool asks whether its request was approved.
300#[derive(Debug, Serialize, Deserialize)]
301#[serde(rename_all = "camelCase")]
302pub struct DeviceClaimArgs {
303 pub device_code: String,
304}
305
306/// The answer to a `device_claim`.
307#[derive(Debug, Serialize, Deserialize)]
308#[serde(tag = "status", rename_all = "snake_case")]
309pub enum DeviceClaim {
310 /// Nobody has approved or denied it yet; ask again after the interval.
311 Pending,
312 Denied,
313 /// The code was never issued, has expired, or was already used.
314 Expired,
315 /// The access token, returned once.
316 Approved {
317 token: String,
318 user: User,
319 },
320}
Workspaces own repositories321
322/// A workspace: the owner of repositories, and the first segment of their
323/// URLs. A person's own space and a team's are the same thing.
324#[derive(Clone, Debug, Serialize, Deserialize)]
325#[serde(rename_all = "camelCase")]
326pub struct Workspace {
327 pub id: String,
328 pub slug: String,
329 pub name: String,
Agents as a team: lifecycle, merge queue, billing and a new shell330 /// One line saying what the workspace is for.
331 pub description: Option<String>,
Workspaces own repositories332 /// RFC 3339.
333 pub created_at: String,
334 pub member_count: u32,
Workspace names and icons, and a component kit for every control335 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
336 /// `/avatars/<avatar>`. Null means the generated letter avatar.
337 #[serde(default)]
338 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look339 /// What every member gets on each of its repositories; owners have
340 /// Admin. See [`crate::access`].
341 #[serde(default)]
342 pub base_permission: crate::access::BasePermission,
Merge branch 'worktree-agent-ad7c6d88d93adc817'343 /// Who may create its teams. See [`crate::teams::TeamCreation`].
344 #[serde(default)]
345 pub team_creation: crate::teams::TeamCreation,
Workspaces own repositories346}
347
348#[derive(Clone, Debug, Serialize, Deserialize)]
349pub struct Member {
350 pub username: String,
351 pub role: crate::Role,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look352 /// Their display name, when they set one.
353 #[serde(default)]
354 pub name: Option<String>,
355 /// Their uploaded avatar: the SHA-256 of its bytes, served at
356 /// `/avatars/<avatar>`. None means the generated letter avatar.
357 #[serde(default)]
358 pub avatar: Option<String>,
Workspaces own repositories359}
360
Merge branch 'worktree-agent-a2013627e5ea4ab13'361/// Where a workspace keeps its repositories' git data: anywhere g1t
362/// stores it (the default), or in the EU only. It applies to repositories
363/// made after it is set; the repos service reads it when it places a new
364/// one (`storage_options` says whether the EU can be chosen).
365#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
366#[serde(rename_all = "lowercase")]
367pub enum DataResidency {
368 #[default]
369 Anywhere,
370 Eu,
371}
372
373impl DataResidency {
374 pub fn as_str(self) -> &'static str {
375 match self {
376 DataResidency::Anywhere => "anywhere",
377 DataResidency::Eu => "eu",
378 }
379 }
380
381 pub fn parse(text: &str) -> Option<Self> {
382 match text.trim().to_ascii_lowercase().as_str() {
383 "anywhere" => Some(DataResidency::Anywhere),
384 "eu" => Some(DataResidency::Eu),
385 _ => None,
386 }
387 }
388}
389
390/// `workspace_residency` takes [`SlugArgs`] and returns
391/// `Option<DataResidency>` (null when there is no such workspace).
392/// `set_workspace_residency`: owners only. Returns `Outcome<DataResidency>`.
393#[derive(Debug, Serialize, Deserialize)]
394pub struct SetResidencyArgs {
395 pub actor: User,
396 pub slug: String,
397 pub residency: DataResidency,
398}
399
Workspaces own repositories400/// `create_workspace`. Returns `Outcome<Workspace>`.
401#[derive(Debug, Serialize, Deserialize)]
402pub struct CreateWorkspaceArgs {
403 pub user: User,
404 pub slug: String,
405 #[serde(default)]
406 pub name: String,
407}
408
409/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
410#[derive(Debug, Serialize, Deserialize)]
411pub struct SlugArgs {
412 pub slug: String,
413}
414
415/// `list_members`: members only. Returns `Outcome<Vec<Member>>`.
416#[derive(Debug, Serialize, Deserialize)]
417pub struct ListMembersArgs {
418 pub slug: String,
419 pub viewer: crate::Viewer,
420}
421
422/// `add_member` and `remove_member`: owners only.
423/// Each returns `Outcome<bool>`.
424#[derive(Debug, Serialize, Deserialize)]
425pub struct MemberArgs {
426 pub actor: User,
427 pub slug: String,
428 pub username: String,
429}
OAuth 2.1 sign-in for MCP clients and other applications430
Agents as a team: lifecycle, merge queue, billing and a new shell431/// `update_workspace`: owners only. An empty name falls back to the slug;
432/// an empty description clears it. Returns `Outcome<Workspace>`.
433#[derive(Debug, Serialize, Deserialize)]
434pub struct UpdateWorkspaceArgs {
435 pub actor: User,
436 pub slug: String,
437 pub name: String,
438 pub description: String,
439}
440
Agents and memory, checks and conflicts, profiles, slug renames, custom domains441/// `rename_workspace`: owners only. Changes the workspace's slug, the first
442/// segment of its URLs, to `new_slug`; the display name is untouched. The
443/// old slug redirects to the new one, and is held for this workspace, for
444/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
445/// `Outcome<Workspace>`.
446///
447/// `check_workspace_rename` takes the same arguments and answers whether
448/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
449#[derive(Debug, Serialize, Deserialize)]
450#[serde(rename_all = "camelCase")]
451pub struct RenameWorkspaceArgs {
452 pub actor: User,
453 pub slug: String,
454 pub new_slug: String,
455}
456
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look457/// `delete_workspace`: owners only, and only a person. `confirm` must be
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member458/// the workspace's slug, typed out. Refused for a protected workspace
459/// ([`protected_names`]), whoever asks, and while billing cannot settle it
460/// (`close_workspace`). Everything in it goes with it at once: nobody can
461/// reach it, its tokens stop working, its pages are not found, and its
462/// repositories, projects and apps are deleted with it. It is kept for
463/// [`WORKSPACE_RESTORE_DAYS`] so g1t's staff can restore it, then purged:
464/// its memberships, access tokens and old-slug redirects go, and billing's
465/// ledger and the audit log keep its history. The slug is never given to
466/// another workspace; the person whose username it is may make a workspace
467/// of that name again once it is purged. Publishes `workspace.deleting`,
468/// and `workspace.deleted` at the purge. Returns `Outcome<bool>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look469///
470/// `check_workspace_deletion` takes the same arguments (with `confirm`
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member471/// ignored) and says what would go and whether anything stands in the way,
472/// changing nothing. Returns `Outcome<WorkspaceDeletion>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look473#[derive(Debug, Serialize, Deserialize)]
474pub struct DeleteWorkspaceArgs {
475 pub actor: User,
476 pub slug: String,
477 #[serde(default)]
478 pub confirm: String,
479 /// Where the request came in, for the audit log; g1t.sh when absent.
480 #[serde(default)]
481 pub surface: Option<crate::audit::Surface>,
482}
483
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member484/// What deleting a workspace takes with it, and what stands in the way.
485/// Nothing does when `billing` is null and it is not `protected`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look486#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
487pub struct WorkspaceDeletion {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member488 /// Its live repositories, which are deleted with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look489 pub repositories: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member490 /// Its projects, hidden with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look491 pub projects: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member492 #[serde(default)]
493 pub members: u32,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look494 /// Why billing cannot close the workspace yet, in words for its owner.
495 pub billing: Option<String>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member496 /// It can never be deleted, by anyone ([`protected_names`]).
497 #[serde(default)]
498 pub protected: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look499}
500
501impl WorkspaceDeletion {
502 pub fn blocked(&self) -> bool {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member503 self.protected || self.billing.is_some()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look504 }
505
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member506 /// Why the workspace cannot be deleted, as one sentence, or `None`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look507 pub fn reason(&self, slug: &str) -> Option<String> {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member508 if self.protected {
509 return Some(protected_refusal(slug));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look510 }
511 self.billing.clone()
512 }
513}
514
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member515/// How long a deleted workspace is kept, for staff to restore, before it is
516/// purged.
517pub const WORKSPACE_RESTORE_DAYS: u64 = 30;
518
519/// Workspaces nobody can delete, whatever identity's `PROTECTED_WORKSPACES`
520/// says: Flagon's, which runs g1t.
521pub const ALWAYS_PROTECTED: &[&str] = &["flagon-io"];
522
523/// The protected workspaces: `configured` (comma-separated slugs or
524/// workspace ids, as identity's `PROTECTED_WORKSPACES` holds them), and
525/// [`ALWAYS_PROTECTED`] whatever it says, so an empty or missing variable
526/// still protects them. Lowercased, without duplicates.
527pub fn protected_names(configured: Option<&str>) -> Vec<String> {
528 let mut names: Vec<String> = Vec::new();
529 let given = configured.unwrap_or_default().split(',');
530 for name in ALWAYS_PROTECTED.iter().copied().chain(given) {
531 let name = name.trim().to_lowercase();
532 if !name.is_empty() && !names.contains(&name) {
533 names.push(name);
534 }
535 }
536 names
537}
538
539/// Why a protected workspace is not deleted, purged or acted on.
540pub fn protected_refusal(slug: &str) -> String {
541 format!("{slug} is protected and can never be deleted.")
542}
543
544/// `admin_deleted_workspaces` takes no arguments (`{}`) and returns
545/// `Vec<DeletedWorkspace>`, newest first. Staff only.
546///
547/// A workspace an owner deleted, kept until `purge_after` for staff to
548/// restore.
549#[derive(Clone, Debug, Serialize, Deserialize)]
550#[serde(rename_all = "camelCase")]
551pub struct DeletedWorkspace {
552 pub workspace_id: String,
553 pub slug: String,
554 pub name: String,
555 /// RFC 3339.
556 pub deleted_at: String,
557 /// The username of the owner who deleted it.
558 pub deleted_by: String,
559 /// RFC 3339: when it is purged unless restored first.
560 pub purge_after: String,
561 /// What went with it, counted when it was deleted.
562 pub went: WorkspaceDeletion,
563 /// Whether staff can still restore it.
564 pub restorable: bool,
565}
566
567/// `admin_restore_workspace` and `admin_purge_workspace`: staff restore a
568/// deleted workspace within [`WORKSPACE_RESTORE_DAYS`], or purge it now.
569/// `staff` is who, for the audit logs. Purging needs `confirm`, the slug
570/// typed out, and is refused for a protected workspace. Restoring publishes
571/// `workspace.restored`; purging, `workspace.deleted`. Both return
572/// `Outcome<bool>`.
573#[derive(Debug, Serialize, Deserialize)]
574#[serde(rename_all = "camelCase")]
575pub struct AdminDeletedWorkspaceArgs {
576 pub workspace_id: String,
577 pub staff: String,
578 #[serde(default)]
579 pub confirm: String,
580}
581
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look582/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
583/// tokens of agents at work on it are kept pointing at it. For repos'
584/// `transfer`. Returns `bool`.
585#[derive(Debug, Serialize, Deserialize)]
586pub struct TransferRepoScopesArgs {
587 pub from: crate::repos::RepoPath,
588 pub to: crate::repos::RepoPath,
589}
590
Agents and memory, checks and conflicts, profiles, slug renames, custom domains591/// How long a workspace's old slug keeps redirecting to it, and stays
592/// reserved for it, after a rename.
593pub const SLUG_HOLD_DAYS: u64 = 90;
594
595/// How long a workspace must wait between renames.
596pub const RENAME_COOLDOWN_HOURS: u64 = 24;
597
598// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
599// workspace's current slug when `slug` is one it was renamed from within
600// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
Merge branch 'worktree-agent-a8385d293d42c913a'601// is in use), or the workspace's slug when `slug` is one of its aliases.
602
603// `resolve_alias` takes `SlugArgs` and returns `Option<String>`: the slug
604// now of the workspace `slug` is an alias of, and null when it is none.
605// Aliases are set by g1t's staff only: `g1t` is Flagon, Inc.'s `flagon-io`.
606// An alias follows its workspace through renames.
607
608/// `admin_aliases` takes no arguments (`{}`) and returns
609/// `Vec<WorkspaceAlias>`, by alias. Staff only.
610///
611/// A name staff point at a workspace, so that its addresses (pages, git,
612/// the API, packages) lead to the workspace under its own name.
613#[derive(Clone, Debug, Serialize, Deserialize)]
614#[serde(rename_all = "camelCase")]
615pub struct WorkspaceAlias {
616 pub alias: String,
617 pub workspace_id: String,
618 /// The workspace's slug and name now.
619 pub workspace: String,
620 pub workspace_name: String,
621 /// Why it exists, as staff wrote it.
622 pub note: String,
623 /// The staff member who set it, or `migration`.
624 pub created_by: String,
625 /// RFC 3339.
626 pub created_at: String,
627}
628
629/// `admin_set_alias`: points `alias` at the workspace whose slug is
630/// `workspace`. The alias must have a namespace's shape, must not be one of
631/// the site's routes, and must not be anyone's username, a workspace's slug
632/// (deleted, or held after a rename) or another alias. `note` is required:
633/// it is the reason, kept with the alias and in sudo's audit log. Staff
634/// only. Returns `Outcome<WorkspaceAlias>`.
635#[derive(Debug, Serialize, Deserialize)]
636#[serde(rename_all = "camelCase")]
637pub struct AdminSetAliasArgs {
638 pub alias: String,
639 pub workspace: String,
640 pub note: String,
641 pub staff: String,
642}
643
644/// `admin_remove_alias`: the alias stops leading anywhere, and the name is
645/// nobody's again unless it is reserved. `reason` goes in sudo's audit log.
646/// Staff only. Returns `Outcome<bool>`.
647#[derive(Debug, Serialize, Deserialize)]
648#[serde(rename_all = "camelCase")]
649pub struct AdminRemoveAliasArgs {
650 pub alias: String,
651 pub reason: String,
652 pub staff: String,
653}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains654
Workspace names and icons, and a component kit for every control655/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
656/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
657/// the icon. Returns `Outcome<Workspace>`.
658#[derive(Debug, Serialize, Deserialize)]
659pub struct SetWorkspaceAvatarArgs {
660 pub actor: User,
661 pub slug: String,
662 pub image: Option<String>,
663}
664
665/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
666/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
667#[derive(Debug, Serialize, Deserialize)]
668pub struct SetUserAvatarArgs {
669 pub user: User,
670 pub image: Option<String>,
671}
672
673/// The largest avatar that can be uploaded, in bytes.
674pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
675
Agents as a team: lifecycle, merge queue, billing and a new shell676/// `list_workspace_tokens`: members only. Returns
677/// `Outcome<Vec<AccessToken>>`.
678#[derive(Debug, Serialize, Deserialize)]
679pub struct WorkspaceTokensArgs {
680 pub slug: String,
681 pub viewer: crate::Viewer,
682}
683
684/// `create_workspace_token`: owners only. The token belongs to the
685/// workspace, acts as it, and keeps working when the member who made it
686/// leaves. Returns `Outcome<CreatedAccessToken>`.
687#[derive(Debug, Serialize, Deserialize)]
688pub struct CreateWorkspaceTokenArgs {
689 pub actor: User,
690 pub slug: String,
691 pub name: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step692 /// Its scopes; null for full access.
693 #[serde(default)]
694 pub scopes: Option<Vec<String>>,
695 /// When set, the token stops working after this many seconds. It is
696 /// listed with the workspace's tokens either way. Null: no expiry.
697 #[serde(default)]
698 pub ttl_seconds: Option<u64>,
Agents as a team: lifecycle, merge queue, billing and a new shell699}
700
701/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
702#[derive(Debug, Serialize, Deserialize)]
703pub struct RemoveWorkspaceTokenArgs {
704 pub actor: User,
705 pub slug: String,
706 pub id: String,
707}
708
OAuth 2.1 sign-in for MCP clients and other applications709/// `oauth_authorize`: the signed-in person approved an application. The
710/// caller has checked the client and that it may be redirected to
711/// `redirect_uri`. Returns `OAuthCode`.
712#[derive(Debug, Serialize, Deserialize)]
713#[serde(rename_all = "camelCase")]
714pub struct OAuthAuthorizeArgs {
715 pub user: User,
716 pub client_id: String,
717 /// Shown wherever the application's access is listed.
718 pub client_name: String,
719 pub redirect_uri: String,
720 /// PKCE challenge, method S256.
721 pub code_challenge: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step722 /// What the person granted, as `resource:level`. Null: full access.
723 #[serde(default)]
724 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications725}
726
727#[derive(Debug, Serialize, Deserialize)]
728pub struct OAuthCode {
729 pub code: String,
730}
731
732/// `oauth_exchange`: redeems an authorization code.
733/// Returns `Outcome<OAuthTokens>`.
734#[derive(Debug, Serialize, Deserialize)]
735#[serde(rename_all = "camelCase")]
736pub struct OAuthExchangeArgs {
737 pub code: String,
738 pub code_verifier: String,
739 pub client_id: String,
740 pub redirect_uri: String,
741}
742
743/// `oauth_refresh`: trades a refresh token for new tokens.
744/// Returns `Outcome<OAuthTokens>`.
745#[derive(Debug, Serialize, Deserialize)]
746#[serde(rename_all = "camelCase")]
747pub struct OAuthRefreshArgs {
748 pub refresh_token: String,
749 pub client_id: String,
750}
751
752#[derive(Debug, Serialize, Deserialize)]
753#[serde(rename_all = "camelCase")]
754pub struct OAuthTokens {
755 pub access_token: String,
756 /// Works once; using it returns the next one.
757 pub refresh_token: String,
758 /// Seconds until the access token stops working.
759 pub expires_in: u64,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step760 /// The scopes granted, space-separated, or `*` for full access.
761 #[serde(default)]
762 pub scope: Option<String>,
OAuth 2.1 sign-in for MCP clients and other applications763}
764
765/// An application a person has signed in to. Listed by `list_oauth_grants`
766/// and ended by `revoke_oauth_grant`.
767#[derive(Debug, Serialize, Deserialize)]
768#[serde(rename_all = "camelCase")]
769pub struct OAuthGrant {
770 pub id: String,
771 pub client_name: String,
772 /// RFC 3339.
773 pub created_at: String,
774 /// RFC 3339.
775 pub last_used_at: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step776 /// What the person granted. Null: full access.
777 #[serde(default)]
778 pub scopes: Option<Vec<String>>,
779 /// Signed in before applications were given scopes: full access until
780 /// someone narrows it.
781 #[serde(default)]
782 pub legacy: bool,
783}
784
785/// `update_oauth_grant`: changes what an application the person signed in
786/// to may do, at once and when it refreshes. Returns `Outcome<OAuthGrant>`.
787#[derive(Debug, Serialize, Deserialize)]
788pub struct UpdateOAuthGrantArgs {
789 pub user: User,
790 pub id: String,
791 #[serde(default)]
792 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications793}
Agents as a team: lifecycle, merge queue, billing and a new shell794
795
796/// What an agent's token may do: these operations, in this repository.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API797#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
Agents as a team: lifecycle, merge queue, billing and a new shell798pub struct AgentScope {
799 pub repo: crate::repos::RepoPath,
800 /// API and MCP operation names, such as `create_issue`.
801 pub operations: Vec<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API802 /// Set on a run credential: the run it belongs to, and what it may do
803 /// with git. See [`crate::credentials`].
804 #[serde(default, skip_serializing_if = "Option::is_none")]
805 pub run: Option<crate::credentials::RunBinding>,
Agents as a team: lifecycle, merge queue, billing and a new shell806}
807
808/// `create_agent_token`: a token for a g1t agent working on someone's
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent809/// behalf. It acts as `g1t`, a member of the repository's workspace,
Agents as a team: lifecycle, merge queue, billing and a new shell810/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
811#[derive(Debug, Serialize, Deserialize)]
812#[serde(rename_all = "camelCase")]
813pub struct CreateAgentTokenArgs {
814 /// The person the agent works for; the token is recorded as theirs.
815 pub on_behalf_of: User,
816 pub scope: AgentScope,
817 pub ttl_seconds: u64,
818}
819
820// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
821// agent's token may do, or null for any other token.
822
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent823/// The id g1t's agent acts under. Only ever stored, never shown: it keeps
824/// the agent's work apart from g1t's own ([`crate::system::ID`]) where
825/// that matters, such as whether its approval counts.
Agents as a team: lifecycle, merge queue, billing and a new shell826pub const AGENT_ID: &str = "usr_g1t_agent";
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent827/// The name g1t's agent is shown by: g1t's own, [`crate::system::USERNAME`].
828/// Everything it does, people see g1t do.
829pub const AGENT_NAME: &str = crate::system::USERNAME;
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace830
831// --- Staff ---------------------------------------------------------------
832//
833// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
834// membership: only sudo calls them, over its service binding, after it has
835// verified a Cloudflare Access sign-in and its staff list. Nothing a
836// customer can reach should ever forward to them.
837
838/// `notify_owners`: emails a short notice, with one link, to each owner of
839/// a workspace with a confirmed address. Called by other services (billing
840/// warns owners near their usage limit), never on a person's behalf.
841/// Returns how many were sent.
842#[derive(Clone, Debug, Serialize, Deserialize)]
843pub struct NotifyOwnersArgs {
844 pub workspace: String,
845 pub subject: String,
846 /// One or two sentences: what happened and what it means.
847 pub intro: String,
848 /// The button's words, such as `Open billing`.
849 pub action: String,
850 /// Where the button goes; must be on g1t.sh.
851 pub link: String,
852 /// Small print: why they got it.
853 pub footer: String,
854}
855
856/// `admin_workspaces`: every workspace, newest first, at most
857/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
858/// an owner's username or email contains `query`. Returns
859/// `Vec<AdminWorkspace>`. Staff only.
860#[derive(Debug, Default, Serialize, Deserialize)]
861pub struct AdminWorkspacesArgs {
862 #[serde(default)]
863 pub query: Option<String>,
864}
865
866/// The most workspaces one `admin_workspaces` call returns.
867pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
868
869/// An owner of a workspace, as staff see them.
870#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
871pub struct AdminOwner {
872 pub username: String,
873 pub email: Option<String>,
874}
875
876/// A workspace as staff see it: who owns it and how many belong to it.
877#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
878#[serde(rename_all = "camelCase")]
879pub struct AdminWorkspace {
880 pub slug: String,
881 pub name: String,
882 /// RFC 3339.
883 pub created_at: String,
884 pub owners: Vec<AdminOwner>,
885 pub member_count: u32,
886}
887
888/// `admin_workspace`: one workspace with every member, or null. Takes
889/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
890#[derive(Clone, Debug, Serialize, Deserialize)]
891#[serde(rename_all = "camelCase")]
892pub struct AdminWorkspaceDetail {
893 pub slug: String,
894 pub name: String,
895 pub description: Option<String>,
896 /// RFC 3339.
897 pub created_at: String,
898 /// Owners first, then by username.
899 pub members: Vec<AdminMember>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member900 /// It can never be deleted ([`protected_names`]).
901 #[serde(default)]
902 pub protected: bool,
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace903}
904
905/// A member of a workspace, as staff see them.
906#[derive(Clone, Debug, Serialize, Deserialize)]
907pub struct AdminMember {
908 pub username: String,
909 pub email: Option<String>,
910 pub role: crate::Role,
911 /// When they joined the workspace. RFC 3339.
912 pub joined: String,
913}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains914
915// --- Profiles ------------------------------------------------------------
916//
917// A person's public page at `g1t.sh/u/<username>`. Everything in a
918// `Profile` is shown to anyone, signed in or not; an email address never is.
919
920/// The most characters each profile field takes.
921pub const MAX_PROFILE_NAME: usize = 80;
922pub const MAX_PROFILE_BIO: usize = 160;
923pub const MAX_PROFILE_LOCATION: usize = 80;
924pub const MAX_PROFILE_WEBSITE: usize = 200;
925pub const MAX_PROFILE_PRONOUNS: usize = 40;
926
927/// What anyone may see about a person.
928#[derive(Clone, Debug, Default, Serialize, Deserialize)]
929#[serde(rename_all = "camelCase")]
930pub struct Profile {
931 pub username: String,
932 /// The name they go by, if they gave one.
933 pub name: Option<String>,
934 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
935 pub bio: Option<String>,
936 pub location: Option<String>,
937 /// An `https://` address.
938 pub website: Option<String>,
939 pub pronouns: Option<String>,
940 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
941 pub avatar: Option<String>,
942 /// When the account was made. RFC 3339.
943 pub created_at: String,
944}
945
946// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
947// an account that does not exist.
948
949/// `update_profile`: a person changes their own profile. Every field is
950/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
951#[derive(Debug, Default, Serialize, Deserialize)]
952#[serde(rename_all = "camelCase")]
953pub struct UpdateProfileArgs {
954 pub actor: User,
955 #[serde(default)]
956 pub name: String,
957 #[serde(default)]
958 pub bio: String,
959 #[serde(default)]
960 pub location: String,
961 #[serde(default)]
962 pub website: String,
963 #[serde(default)]
964 pub pronouns: String,
965}
966
967/// `profile_workspaces`: the workspaces shown on a person's profile, as
968/// `viewer` may see them. A membership is shown only when it is no secret
969/// from the viewer: a workspace the viewer belongs to as well, or one of
970/// `public`, the workspaces the caller found the person has made a public
971/// project in (whose page shows that already). Returns
972/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
973#[derive(Debug, Serialize, Deserialize)]
974pub struct ProfileWorkspacesArgs {
975 pub username: String,
976 pub viewer: crate::Viewer,
977 #[serde(default)]
978 pub public: Vec<String>,
979}
980
981/// A workspace on a person's profile.
982#[derive(Clone, Debug, Serialize, Deserialize)]
983pub struct ProfileWorkspace {
984 pub slug: String,
985 pub name: String,
986 pub avatar: Option<String>,
987}
Search across all of g1t, Explore, and a command palette988
989/// `directory`: every account or every workspace, as their public pages
990/// show them, a page at a time in name order. For services that index
991/// them, such as search; nothing private is in it. Returns
992/// `DirectoryPage`.
993#[derive(Debug, Default, Serialize, Deserialize)]
994pub struct DirectoryArgs {
995 /// `user` or `workspace`.
996 pub kind: String,
997 /// Names after this one.
998 #[serde(default)]
999 pub after: Option<String>,
1000 pub limit: u32,
1001}
1002
1003/// One account or workspace in the directory.
1004#[derive(Clone, Debug, Serialize, Deserialize)]
1005#[serde(rename_all = "camelCase")]
1006pub struct DirectoryEntry {
1007 /// The account's or workspace's id.
1008 pub id: String,
1009 /// A username or a workspace's slug.
1010 pub slug: String,
1011 /// A person's display name or a workspace's name.
1012 pub name: Option<String>,
1013 /// A person's bio or a workspace's description.
1014 pub bio: Option<String>,
1015 pub avatar: Option<String>,
1016 /// RFC 3339.
1017 pub created_at: String,
1018}
1019
1020#[derive(Clone, Debug, Default, Serialize, Deserialize)]
1021pub struct DirectoryPage {
1022 pub entries: Vec<DirectoryEntry>,
1023 /// Where the next page starts; null on the last.
1024 pub next: Option<String>,
1025}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1026
1027// --- Invites ---------------------------------------------------------------
1028//
1029// While registration is invite-only, every new account (with a password or
1030// through GitHub) needs an invite code. Each person may have
1031// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
1032// to a workspace, whose owners share them. Inviting an email with no
1033// account into a workspace makes an invite bound to that address, which
1034// registers and joins in one step. See services/identity/src/invites.rs.
1035
1036/// Whether anyone may make an account, or only someone with an invite. Set
1037/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
1038/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
1039#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1040#[serde(rename_all = "snake_case")]
1041pub enum RegistrationMode {
1042 #[default]
1043 Invite,
1044 Open,
1045}
1046
1047impl RegistrationMode {
1048 pub fn parse(text: Option<&str>) -> RegistrationMode {
1049 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
1050 Some("open") => RegistrationMode::Open,
1051 _ => RegistrationMode::Invite,
1052 }
1053 }
1054}
1055
1056/// How many invites a person may have out at once, unless identity's
1057/// `INVITES_PER_USER` var says otherwise.
1058pub const INVITES_PER_USER: u32 = 5;
1059
1060/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
1061/// otherwise.
1062pub const INVITE_TTL_DAYS: u64 = 30;
1063
1064/// Where an invite stands. Only a pending invite can be used or revoked.
1065/// An expired or revoked invite that was never used gives its inviter the
1066/// invite back.
1067#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1068#[serde(rename_all = "snake_case")]
1069pub enum InviteStatus {
1070 Pending,
1071 Redeemed,
1072 Expired,
1073 Revoked,
1074}
1075
1076/// What using an invite does.
1077#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1078#[serde(rename_all = "snake_case")]
1079pub enum InviteKind {
1080 /// Makes a new account, and joins `workspace` when one is set.
1081 Account,
1082 /// An existing account joins `workspace`. Never makes an account.
1083 Workspace,
1084}
1085
1086/// Whose allowance an invite uses.
1087#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1088#[serde(rename_all = "snake_case")]
1089pub enum InviteCharge {
1090 /// Its inviter's own.
1091 User,
1092 /// The workspace's, granted by staff and shared by its owners.
1093 Workspace,
1094 /// Nobody's: staff minted it, or it invites an existing account.
1095 None,
1096}
1097
1098/// One invite, as the person who made it sees it.
1099#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1100#[serde(rename_all = "camelCase")]
1101pub struct Invite {
1102 pub id: String,
1103 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
1104 /// is made, and afterwards to whoever made it while it is pending.
1105 /// Null otherwise.
1106 pub code: Option<String>,
1107 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
1108 pub hint: String,
1109 /// Only an account with this address can use it. Null: anyone with
1110 /// the code.
1111 pub email: Option<String>,
1112 pub kind: InviteKind,
1113 /// The workspace it joins, by slug.
1114 pub workspace: Option<String>,
1115 pub status: InviteStatus,
1116 pub charged_to: InviteCharge,
1117 /// Who made it, by username. Null when g1t staff did.
1118 pub invited_by: Option<String>,
1119 /// The account that used it, by username.
1120 pub redeemed_by: Option<String>,
1121 /// RFC 3339.
1122 pub created_at: String,
1123 /// RFC 3339.
1124 pub expires_at: String,
1125 /// RFC 3339.
1126 pub redeemed_at: Option<String>,
1127 /// RFC 3339.
1128 pub revoked_at: Option<String>,
1129 /// The staff member who minted it. Only in staff views.
1130 #[serde(default, skip_serializing_if = "Option::is_none")]
1131 pub staff: Option<String>,
1132}
1133
1134/// How many invites someone may have out, and how many they have.
1135#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1136pub struct Allowance {
1137 /// Null: no limit.
1138 pub limit: Option<u32>,
1139 /// Pending and used invites; revoked and expired ones are not counted.
1140 pub used: u32,
1141 /// Null: no limit.
1142 pub remaining: Option<u32>,
1143}
1144
1145impl Allowance {
1146 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
1147 Allowance {
1148 limit,
1149 used,
1150 remaining: limit.map(|limit| limit.saturating_sub(used)),
1151 }
1152 }
1153
1154 pub fn exhausted(&self) -> bool {
1155 self.remaining == Some(0)
1156 }
1157}
1158
1159/// A workspace's shared invites, for one of its owners.
1160#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
1161pub struct WorkspaceAllowance {
1162 pub slug: String,
1163 pub allowance: Allowance,
1164}
1165
1166/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
1167/// and what they have left. Returns `InvitesOverview`.
1168#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1169pub struct InvitesOverview {
1170 pub mode: RegistrationMode,
1171 pub allowance: Allowance,
1172 /// Workspaces the person owns that staff granted invites to.
1173 pub workspaces: Vec<WorkspaceAllowance>,
1174 pub invites: Vec<Invite>,
1175}
1176
1177/// `create_invite`: a person makes an invite, optionally for one email
1178/// address. People only; never an agent or a workspace's token, and not
1179/// before their email is confirmed. Uses one of the person's invites, or,
1180/// with `workspace`, one of the invites staff granted that workspace (its
1181/// owners only). Emails the address when one is given. Returns
1182/// `Outcome<Invite>`, with the code.
1183///
1184/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
1185/// invite; a workspace's owners may revoke one made for the workspace.
1186/// The invite comes back to whoever it was charged to. Returns
1187/// `Outcome<Invite>`.
1188#[derive(Debug, Serialize, Deserialize)]
1189pub struct CreateInviteArgs {
1190 pub user: User,
1191 #[serde(default)]
1192 pub email: Option<String>,
1193 /// Use this workspace's granted invites, by slug.
1194 #[serde(default)]
1195 pub workspace: Option<String>,
1196 /// Where the request came in, for the audit log; g1t.sh when absent.
1197 #[serde(default)]
1198 pub surface: Option<crate::audit::Surface>,
1199}
1200
1201/// `check_invite`: what an invite code is for, before using it. Returns
1202/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1203/// expired gets the same answer, so codes cannot be probed. With
1204/// `any_status`, a real code that can no longer be used is described
1205/// instead (its `status` says why), so the page can say whom to ask for a
1206/// new one; an unknown code still gets the one answer.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1207#[derive(Debug, Serialize, Deserialize)]
1208pub struct InviteCodeArgs {
1209 pub code: String,
1210 /// Who is asking, such as the visitor's IP address, for rate limits.
1211 #[serde(default)]
1212 pub client: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1213 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
1214 #[serde(default)]
1215 pub viewer: Option<User>,
1216 #[serde(default)]
1217 pub any_status: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1218}
1219
1220/// Someone shown on an invite.
1221#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1222pub struct InviteFrom {
1223 pub username: String,
1224 pub name: Option<String>,
1225 pub avatar: Option<String>,
1226}
1227
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1228/// A repository an invite code was sent with: using the code accepts the
1229/// invitation to collaborate on it.
1230#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1231pub struct InviteRepository {
1232 /// `workspace/repo`.
1233 pub name: String,
1234 /// The role it gives, such as `write`.
1235 pub role: String,
1236}
1237
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1238/// What a valid invite code is for.
1239#[derive(Clone, Debug, Serialize, Deserialize)]
1240#[serde(rename_all = "camelCase")]
1241pub struct InvitePreview {
1242 pub kind: InviteKind,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1243 /// Pending, unless `any_status` asked about a code that is spent.
1244 pub status: InviteStatus,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1245 /// Null when g1t staff sent it.
1246 pub invited_by: Option<InviteFrom>,
1247 pub workspace: Option<ProfileWorkspace>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1248 /// The repository it accepts an invitation to, if it was sent with one.
1249 pub repository: Option<InviteRepository>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1250 /// The address it is for, partly hidden, such as `a•••@example.com`.
1251 pub email: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1252 /// The address in full, while it is pending: whoever holds the code
1253 /// was sent it there. Fills in and locks the sign-up form.
1254 pub address: Option<String>,
1255 /// Whether the address it is for has a g1t account already, so the
1256 /// page asks them to sign in rather than sign up.
1257 pub has_account: bool,
1258 /// With a viewer: whether the invite is theirs (it is for one of their
1259 /// confirmed addresses, or they used it). Null without a viewer or,
1260 /// for a pending invite, when it is for anyone with the code.
1261 pub for_viewer: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1262 /// RFC 3339.
1263 pub expires_at: String,
1264}
1265
1266/// `accept_invite`: a signed-in person uses a workspace invite made for
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1267/// their confirmed address, and joins the workspace, or an invite sent with
1268/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1269/// workspace's slug, or `workspace/repo`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1270#[derive(Debug, Serialize, Deserialize)]
1271pub struct AcceptInviteArgs {
1272 pub user: User,
1273 pub code: String,
1274}
1275
1276/// `invite_member`: an owner invites an email address into a workspace.
1277/// It always makes an invite bound to that address and emails it, so the
1278/// answer never says whether the address has an account. Without one, the
1279/// invite registers and joins in one step, and uses one of the workspace's
1280/// granted invites or else one of the owner's own. With one, it costs
1281/// nothing. Returns `Outcome<Invite>`, with the code.
1282#[derive(Debug, Serialize, Deserialize)]
1283pub struct InviteMemberArgs {
1284 pub actor: User,
1285 pub slug: String,
1286 pub email: String,
1287 /// Where the request came in, for the audit log; g1t.sh when absent.
1288 #[serde(default)]
1289 pub surface: Option<crate::audit::Surface>,
1290}
1291
1292/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1293/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1294///
1295/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1296#[derive(Debug, Serialize, Deserialize)]
1297pub struct WorkspaceInviteArgs {
1298 pub actor: User,
1299 pub slug: String,
1300 pub id: String,
1301}
1302
1303/// `request_access`: someone without an invite asks for one. Kept on the
1304/// waitlist, one entry per address. Answers the same way whether or not
1305/// the address is already on it. Returns `Outcome<bool>`.
1306#[derive(Debug, Default, Serialize, Deserialize)]
1307pub struct RequestAccessArgs {
1308 pub email: String,
1309 /// What they will build, if they said.
1310 #[serde(default)]
1311 pub about: String,
1312 /// Who is asking, such as the visitor's IP address, for rate limits.
1313 #[serde(default)]
1314 pub client: Option<String>,
1315}
1316
1317/// The most characters `RequestAccessArgs::about` keeps.
1318pub const MAX_WAITLIST_ABOUT: usize = 1000;
1319
1320// `registration` takes `{}` and returns `RegistrationMode`.
1321
1322// --- Invites, staff only ---
1323
1324#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1325#[serde(rename_all = "snake_case")]
1326pub enum WaitlistStatus {
1327 Waiting,
1328 Invited,
1329 Dismissed,
1330}
1331
1332impl WaitlistStatus {
1333 pub fn as_str(self) -> &'static str {
1334 match self {
1335 WaitlistStatus::Waiting => "waiting",
1336 WaitlistStatus::Invited => "invited",
1337 WaitlistStatus::Dismissed => "dismissed",
1338 }
1339 }
1340}
1341
1342/// Someone who asked for access.
1343#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1344#[serde(rename_all = "camelCase")]
1345pub struct WaitlistEntry {
1346 pub id: String,
1347 pub email: String,
1348 pub about: Option<String>,
1349 pub status: WaitlistStatus,
1350 pub invite_id: Option<String>,
1351 pub decided_by: Option<String>,
1352 /// RFC 3339.
1353 pub decided_at: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1354 /// What staff wrote when approving; it went in the invite email.
1355 #[serde(default)]
1356 pub note: Option<String>,
1357 /// The account made with the invite, once it was used.
1358 #[serde(default)]
1359 pub joined_as: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1360 /// When they first asked. RFC 3339.
1361 pub created_at: String,
1362 /// When they last asked. RFC 3339.
1363 pub updated_at: String,
1364}
1365
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1366/// `admin_waitlist`: the waitlist, newest first, at most
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1367/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1368///
1369/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1370/// still waiting, for sudo's navigation.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1371#[derive(Debug, Default, Serialize, Deserialize)]
1372pub struct AdminWaitlistArgs {
1373 /// Part of an email address or of what they said.
1374 #[serde(default)]
1375 pub query: Option<String>,
1376 /// Null: every status.
1377 #[serde(default)]
1378 pub status: Option<WaitlistStatus>,
1379}
1380
1381/// The most rows one staff listing of invites or the waitlist returns.
1382pub const ADMIN_INVITES_LIMIT: usize = 500;
1383
1384/// `admin_decide_waitlist`: approving mints an invite bound to the
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1385/// address, charged to nobody, and emails it, with `note` if given;
1386/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1387#[derive(Debug, Serialize, Deserialize)]
1388pub struct AdminDecideWaitlistArgs {
1389 pub id: String,
1390 pub approve: bool,
1391 /// The staff member, by email.
1392 pub staff: String,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1393 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1394 #[serde(default)]
1395 pub note: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1396}
1397
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1398/// The most characters an approval's note keeps.
1399pub const MAX_WAITLIST_NOTE: usize = 500;
1400
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1401/// `admin_invites`: every invite, newest first, at most
1402/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1403/// `query`, or whose email, inviter or redeemer contains it. Returns
1404/// `Vec<Invite>`.
1405#[derive(Debug, Default, Serialize, Deserialize)]
1406pub struct AdminInvitesArgs {
1407 #[serde(default)]
1408 pub query: Option<String>,
1409}
1410
1411/// `admin_revoke_invite`: revokes any pending invite. Returns
1412/// `Outcome<Invite>`.
1413#[derive(Debug, Serialize, Deserialize)]
1414pub struct AdminRevokeInviteArgs {
1415 pub id: String,
1416 pub staff: String,
1417}
1418
1419/// `admin_mint_invite`: staff make an invite that uses nobody's
1420/// allowance, optionally bound to (and emailed to) an address. Returns
1421/// `Outcome<Invite>`, with the code.
1422#[derive(Debug, Serialize, Deserialize)]
1423pub struct AdminMintInviteArgs {
1424 #[serde(default)]
1425 pub email: Option<String>,
1426 pub staff: String,
1427}
1428
1429/// Who staff grant invites to.
1430#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1431#[serde(rename_all = "snake_case")]
1432pub enum GrantTarget {
1433 User,
1434 Workspace,
1435}
1436
1437impl GrantTarget {
1438 pub fn as_str(self) -> &'static str {
1439 match self {
1440 GrantTarget::User => "user",
1441 GrantTarget::Workspace => "workspace",
1442 }
1443 }
1444}
1445
1446/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1447/// slug) `amount` more invites; a negative amount takes some back. Returns
1448/// `Outcome<Allowance>`: theirs afterwards.
1449#[derive(Debug, Serialize, Deserialize)]
1450pub struct AdminGrantInvitesArgs {
1451 pub target: GrantTarget,
1452 pub name: String,
1453 pub amount: i32,
1454 #[serde(default)]
1455 pub note: String,
1456 pub staff: String,
1457}
1458
1459/// The most invites one grant gives or takes back.
1460pub const MAX_INVITE_GRANT: i32 = 1000;
1461
1462/// Invites staff granted.
1463#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1464#[serde(rename_all = "camelCase")]
1465pub struct InviteGrant {
1466 pub amount: i32,
1467 pub note: Option<String>,
1468 pub granted_by: String,
1469 /// RFC 3339.
1470 pub created_at: String,
1471}
1472
1473/// Someone a person invited, and whom they invited in turn.
1474#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1475#[serde(rename_all = "camelCase")]
1476pub struct InviteTreeNode {
1477 pub username: String,
1478 /// When they used the invite. RFC 3339.
1479 pub joined_at: String,
1480 pub invited: Vec<InviteTreeNode>,
1481}
1482
1483/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1484/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1485///
1486/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1487/// invites, grants and invites. Returns `Option<InviteTree>` with
1488/// `username` the slug and no `invited_by`.
1489#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1490#[serde(rename_all = "camelCase")]
1491pub struct InviteTree {
1492 pub username: String,
1493 /// Who invited them, then who invited that person, and so on. Empty
1494 /// for an account made without an invite.
1495 pub invited_by: Vec<String>,
1496 /// The staff member who minted their invite, when staff did.
1497 pub staff: Option<String>,
1498 pub allowance: Allowance,
1499 pub grants: Vec<InviteGrant>,
1500 /// Their invites, newest first.
1501 pub invites: Vec<Invite>,
1502 /// Whom they invited, three levels down.
1503 pub invited: Vec<InviteTreeNode>,
1504}
1505
1506#[cfg(test)]
1507mod deletion_tests {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1508 use super::{WorkspaceDeletion, protected_names};
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1509
1510 #[test]
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1511 fn only_billing_or_protection_stands_in_the_way() {
1512 let clear = WorkspaceDeletion {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1513 repositories: 2,
1514 projects: 1,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1515 members: 3,
1516 ..WorkspaceDeletion::default()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1517 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1518 assert!(!clear.blocked());
1519 assert_eq!(clear.reason("acme"), None);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1520 let owing = WorkspaceDeletion {
1521 billing: Some("Pay first.".into()),
1522 ..WorkspaceDeletion::default()
1523 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1524 assert!(owing.blocked());
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1525 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1526 let protected = WorkspaceDeletion {
1527 billing: Some("Pay first.".into()),
1528 protected: true,
1529 ..WorkspaceDeletion::default()
1530 };
1531 assert!(protected.blocked());
1532 assert_eq!(
1533 protected.reason("flagon-io").as_deref(),
1534 Some("flagon-io is protected and can never be deleted.")
1535 );
1536 }
1537
1538 #[test]
1539 fn flagon_is_protected_whatever_the_variable_says() {
1540 assert_eq!(protected_names(None), ["flagon-io"]);
1541 assert_eq!(protected_names(Some("")), ["flagon-io"]);
1542 assert_eq!(protected_names(Some(" , ")), ["flagon-io"]);
1543 assert_eq!(
1544 protected_names(Some("Flagon-IO, acme ,wsp_1")),
1545 ["flagon-io", "acme", "wsp_1"]
1546 );
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1547 }
1548}

This file's history is long; its oldest lines are credited to the oldest commit read.