flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/crates/contracts/src/lib.rs

117 lines3,847 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
GitHub Actions on g1t, part two: running workflows7pub mod actions;
Agents as a team: lifecycle, merge queue, billing and a new shell8pub mod billing;
Rust repos service with shipping; pull requests kept in the model9pub mod events;
API and MCP server, Rust identity service, registration, site redesign10pub mod identity;
Integrations: your own model provider, alerts that open issues, tickets agents read11pub mod integrations;
API and MCP server, Rust identity service, registration, site redesign12mod ids;
13mod names;
14mod outcome;
Projects: what a workspace builds and runs, first on every page15pub mod projects;
Rust repos service with shipping; pull requests kept in the model16pub mod repos;
RFC 3339 timestamps in identity and repos17pub mod time;
Webhooks: every event, to your own addresses, signed and retried18pub mod webhooks;
Work service in Rust, with RFC 3339 timestamps19pub mod work;
API and MCP server, Rust identity service, registration, site redesign20
21pub use ids::new_id;
22pub use names::{is_valid_namespace, is_valid_repo_name};
23pub use outcome::{Failure, FailureCode, Outcome};
24
25use serde::{Deserialize, Serialize};
26
Workspaces own repositories27/// What a member may do in a workspace.
28#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
29#[serde(rename_all = "lowercase")]
30pub enum Role {
31 /// Everything a member can, plus managing members.
32 Owner,
Issues and pull requests replace intents and attempts33 /// Create repositories, push, manage issues and merge pull requests.
Workspaces own repositories34 Member,
35}
36
37/// One workspace a user belongs to.
API and MCP server, Rust identity service, registration, site redesign38#[derive(Clone, Debug, Serialize, Deserialize)]
Workspaces own repositories39pub struct Membership {
40 /// The workspace's name in URLs: `g1t.sh/<slug>`.
41 pub slug: String,
42 pub role: Role,
Workspace names and icons, and a component kit for every control43 /// The workspace's display name, for showing it to people. Set when a
44 /// user is resolved from credentials; absent on principals made up by
45 /// a service.
46 #[serde(default, skip_serializing_if = "Option::is_none")]
47 pub name: Option<String>,
48 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
49 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
50 #[serde(default, skip_serializing_if = "Option::is_none")]
51 pub avatar: Option<String>,
Workspaces own repositories52}
53
Workspace names and icons, and a component kit for every control54impl Membership {
55 /// A plain member of `slug`, as services act inside one workspace.
56 pub fn member(slug: impl Into<String>) -> Self {
57 Membership {
58 slug: slug.into(),
59 role: Role::Member,
60 name: None,
61 avatar: None,
62 }
63 }
64}
65
Agents as a team: lifecycle, merge queue, billing and a new shell66/// What a set of credentials resolved to.
67#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
68#[serde(rename_all = "lowercase")]
69pub enum PrincipalKind {
70 /// A person's account.
71 #[default]
72 User,
73 /// A workspace, acting through one of its own access tokens. Its `id`
74 /// is the workspace's, its `username` the workspace's slug, and it is a
75 /// member of that workspace and no other.
76 Workspace,
77 /// A g1t agent at work in a sandbox, acting through a token that lives
78 /// as long as its run and can do only what that token's scope lists, in
79 /// one repository. Its `username` is `g1t-agent`.
80 Agent,
81}
82
Workspaces own repositories83#[derive(Clone, Debug, Default, Serialize, Deserialize)]
API and MCP server, Rust identity service, registration, site redesign84pub struct User {
85 pub id: String,
86 pub username: String,
Agents as a team: lifecycle, merge queue, billing and a new shell87 #[serde(default)]
88 pub kind: PrincipalKind,
Email verification, password reset, and Git for AI scale positioning89 /// Whether the account's email address has been confirmed. Unverified
90 /// accounts can sign in but cannot create or change anything.
91 #[serde(default)]
92 pub verified: bool,
Workspaces own repositories93 /// The workspaces this user belongs to. Filled in when a user is
94 /// resolved from credentials, so any service can authorize from it.
95 #[serde(default)]
96 pub workspaces: Vec<Membership>,
Workspace names and icons, and a component kit for every control97 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
98 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
99 #[serde(default, skip_serializing_if = "Option::is_none")]
100 pub avatar: Option<String>,
Workspaces own repositories101}
102
103impl User {
104 pub fn role_in(&self, slug: &str) -> Option<Role> {
105 self.workspaces
106 .iter()
107 .find(|membership| membership.slug == slug)
108 .map(|membership| membership.role)
109 }
110
111 pub fn is_member(&self, slug: &str) -> bool {
112 self.role_in(slug).is_some()
113 }
API and MCP server, Rust identity service, registration, site redesign114}
115
116/// Who is asking. Every read and write in every service takes one.
117pub type Viewer = Option<User>;