Skip to content

g1t/packages/contracts/src/members.ts

37 lines1,461 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA1/**
2 * A workspace's members: owners and members, the roles that add to a
3 * member, and what members are allowed to do. Mirrors
4 * `crates/contracts/src/members.rs`.
5 */
6
7/** A role a member can hold besides owner or member. Owners have both already. */
8export type OrgRole = "billing_manager" | "security_manager";
9
10export const ORG_ROLES: readonly OrgRole[] = ["billing_manager", "security_manager"];
11
12export const ORG_ROLE_LABELS: Record<OrgRole, string> = {
13 billing_manager: "Billing manager",
14 security_manager: "Security manager",
15};
16
17/** One line on what each role gives, as People shows it. */
18export const ORG_ROLE_SUMMARIES: Record<OrgRole, string> = {
19 billing_manager: "Manages the budget, AI credit, payment, invoices and billing details. Nothing on repositories.",
20 security_manager: "Reads every repository, and sees and manages every security alert and security setting.",
21};
22
23/** What a workspace lets its members do. The names are the REST API's. */
24export type MemberPrivileges = {
25 members_can_create_public_repositories: boolean;
26 members_can_create_private_repositories: boolean;
27 members_can_change_repo_visibility: boolean;
28 members_can_delete_repositories: boolean;
29 members_can_invite_outside_collaborators: boolean;
30};
31
32/** A workspace a person belongs to and cannot use until they meet its policy. */
33export type PolicyHold = {
34 slug: string;
35 reason: string;
36 gap: "two_factor" | "verified_email" | "email_domain";
37};

This file's history is long; its oldest lines are credited to the oldest commit read.