g1t/packages/contracts/src/identity.ts

64 lines2,641 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Initial g1t: services, event bus, intents and attempts1import type { Result } from "./result";
2
Email verification, password reset, and Git for AI scale positioning3export type User = {
4 id: string;
5 username: string;
6 /**
7 * Whether the account's email address is confirmed. Only set on users
8 * resolved from credentials; unverified accounts cannot change anything.
9 */
10 verified?: boolean;
11};
Initial g1t: services, event bus, intents and attempts12
13/** Who is asking. Every read and write in every service takes one. */
14export type Viewer = User | null;
15
16export type SshKey = {
17 id: string;
18 title: string;
19 fingerprint: string;
20 createdAt: number;
21};
22
23export type AccessToken = { id: string; name: string; createdAt: number };
24
25/** Accounts, credentials and sessions. */
26export interface IdentityApi {
API and MCP server, Rust identity service, registration, site redesign27 /** Creates an account and signs it in. */
28 register(username: string, email: string, password: string): Promise<Result<{ user: User; sessionToken: string }>>;
Initial g1t: services, event bus, intents and attempts29 /** Verifies a username and password for website sign-in. */
30 signIn(username: string, password: string): Promise<Result<{ user: User; sessionToken: string }>>;
31 signOut(sessionToken: string): Promise<void>;
Email verification, password reset, and Git for AI scale positioning32
33 /** Sends the confirmation email again. */
34 resendVerification(user: User): Promise<Result<boolean>>;
35 /** Confirms the address the emailed token was sent to. */
36 verifyEmail(token: string): Promise<Result<User>>;
37 /** Emails a reset link if the address has an account. Always resolves. */
38 requestPasswordReset(email: string): Promise<boolean>;
39 /** Sets a new password from an emailed token and ends every session. */
40 resetPassword(token: string, password: string): Promise<Result<User>>;
41
Initial g1t: services, event bus, intents and attempts42 userForSession(sessionToken: string): Promise<Viewer>;
43
44 /** Verifies git credentials: the account password or an access token. */
45 userForGitCredentials(username: string, secret: string): Promise<Viewer>;
API and MCP server, Rust identity service, registration, site redesign46 /** Resolves a `g1t_…` access token, as sent to the API and MCP server. */
47 userForAccessToken(token: string): Promise<Viewer>;
Initial g1t: services, event bus, intents and attempts48 userForSshKey(fingerprint: string): Promise<Viewer>;
49 userByUsername(username: string): Promise<Viewer>;
50
51 listSshKeys(user: User): Promise<SshKey[]>;
52 /** Takes one line in OpenSSH public key format. */
53 addSshKey(user: User, title: string, publicKey: string): Promise<Result<SshKey>>;
54 removeSshKey(user: User, id: string): Promise<void>;
55
56 listAccessTokens(user: User): Promise<AccessToken[]>;
57 /** The plaintext token is returned once and never stored. */
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)58 /**
59 * With `ttlSeconds` the token expires and is left out of the user's list;
60 * that form is used for hosted attempts.
61 */
62 createAccessToken(user: User, name: string, ttlSeconds?: number): Promise<{ token: string; info: AccessToken }>;
Initial g1t: services, event bus, intents and attempts63 removeAccessToken(user: User, id: string): Promise<void>;
64}