Skip to content

g1t/services/identity/src/access.rs

1,587 lines66,062 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1//! Who has access to a repository: roles given on one repository, the
2//! invitations that offer them, and each workspace's base permission.
3//!
4//! The rules (which role may do what, and how a person's role is worked
5//! out) live in `g1t_contracts::access`; this is where the roles are kept.
6//! Every user identity resolves carries their grants ([`Identity::grants_of`],
7//! under the workspace's policy) beside their memberships, so services
8//! decide with `access::can` and never call here to authorize.
9//!
10//! **Adding someone** to a repository (Admin only, a person, never an
11//! agent's or a workspace's token):
12//!
13//! - a member of its workspace gets the role at once: it only matters when
14//! it is higher than the base permission;
15//! - anyone else with an account (by username, or a confirmed address) is
16//! sent an invitation, which they accept or decline; it lasts
17//! [`INVITATION_DAYS`];
18//! - an address without an account is sent an invite code (invites.rs,
19//! charged as a workspace invite is) that makes the account and accepts.
20//!
21//! Accepting is checked against the workspace's policy (security.rs), as
22//! joining it is. Removing someone from a workspace takes away their roles
23//! on its repositories (workspaces.rs); a repository that is purged takes
24//! its grants and invitations with it (`forget_repo_access`); a transfer or
25//! rename keeps them (deletion.rs, `transfer_repo_scopes`).
26//!
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar27//! **Teams** are another `principal_kind` in `repo_grants` (teams.rs):
28//! [`Identity::grants_of`] resolves a team's grants into the same
29//! `RepoGrant`s for each person in the team and in its child teams, and
30//! the access list shows where such a role comes from.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look31
32use g1t_contracts::access::*;
33use g1t_contracts::audit::{AuditActor, AuditOutcome, AuditTarget, NewAuditEntry, RecordAuditArgs, Surface};
34use g1t_contracts::events::{NewEvent, Publish, RepoCollaborator};
35use g1t_contracts::repos::{GetArgs, Repo, RepoPath};
36use g1t_contracts::time::{SQL_NOW, rfc3339};
37use g1t_contracts::{FailureCode, Outcome, PrincipalKind, Role, User, Viewer, new_id};
38use g1t_kit::now_ms;
39use serde::{Deserialize, Serialize};
40use worker::Result;
41use worker::wasm_bindgen::JsValue;
42
43use crate::Identity;
44use crate::invites::normalize_email;
45
46/// How long an invitation to someone with an account waits for an answer.
47pub const INVITATION_DAYS: u64 = 7;
48/// The most direct grants one person carries on every request.
49const MAX_GRANTS: u32 = 1000;
50/// The most people or invitations one list shows.
51const LIST_LIMIT: u32 = 500;
52
53const PEOPLE_ONLY: &str =
54 "Only a person can change who has access to a repository, signed in as themselves; never an agent's or a workspace's token.";
55const CONFIRM_FIRST: &str = "Confirm your email address before changing who has access.";
56const NO_SUCH_USER: &str = "There is no account with that username.";
57
58/// What was typed into "Add people".
59#[derive(Debug, PartialEq, Eq)]
60pub enum Invitee {
61 Username(String),
62 Email(String),
63}
64
65/// A username, or an email address, as typed; `None` if it is neither.
66pub fn invitee(text: &str) -> Option<Invitee> {
67 let text = text.trim().trim_start_matches('@');
68 if text.contains('@') {
69 return normalize_email(text).map(Invitee::Email);
70 }
71 let name = text.to_lowercase();
72 g1t_contracts::is_valid_namespace(&name).then_some(Invitee::Username(name))
73}
74
75/// A person's role on a repository, and where it comes from: ownership,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar76/// the base permission, a team's grant, or a direct grant. The highest
77/// wins; on a tie a direct grant is shown first, then a team's, so a role
78/// is shown where it can be changed.
79pub fn effective(
80 owner: bool,
81 base: Option<RepoRole>,
82 direct: Option<RepoRole>,
83 team: Option<RepoRole>,
84) -> Option<(RepoRole, AccessSource)> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look85 if owner {
86 return Some((RepoRole::Admin, AccessSource::Owner));
87 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar88 let mut best = base.map(|role| (role, AccessSource::Base));
89 for (role, source) in [(team, AccessSource::Team), (direct, AccessSource::Direct)] {
90 if let Some(role) = role
91 && best.is_none_or(|(had, _)| role >= had)
92 {
93 best = Some((role, source));
94 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look95 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar96 best
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look97}
98
99/// Where an invitation stands at `now`.
100pub fn invitation_status(row: &InvitationRow, now: &str) -> RepoInvitationStatus {
101 if row.accepted_at.is_some() {
102 RepoInvitationStatus::Accepted
103 } else if row.declined_at.is_some() {
104 RepoInvitationStatus::Declined
105 } else if row.revoked_at.is_some() {
106 RepoInvitationStatus::Revoked
107 } else if row.expires_at.as_str() <= now {
108 RepoInvitationStatus::Expired
109 } else {
110 RepoInvitationStatus::Pending
111 }
112}
113
114#[derive(Deserialize)]
115struct GrantRow {
116 repo_id: String,
117 workspace: String,
118 role: String,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar119 #[serde(default)]
120 team: Option<String>,
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA121 /// Whether the grant's workspace requires two-factor authentication.
122 #[serde(default)]
123 require_two_factor: u8,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look124}
125
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar126/// The highest role a team gives each person on a repository, and that
127/// team's slug, by user id.
128pub(crate) type TeamRoles = std::collections::HashMap<String, (RepoRole, String)>;
129
130/// Folds (user id, role, team slug) rows into each person's highest; on a
131/// tie, the first slug, so the answer never flips.
132pub(crate) fn highest_team_roles(rows: impl IntoIterator<Item = (String, RepoRole, String)>) -> TeamRoles {
133 let mut roles = TeamRoles::new();
134 for (user_id, role, team) in rows {
135 let entry = roles.entry(user_id).or_insert((role, team.clone()));
136 if role > entry.0 || (role == entry.0 && team < entry.1) {
137 *entry = (role, team);
138 }
139 }
140 roles
141}
142
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look143#[derive(Clone, Debug, Default, Deserialize)]
144pub struct InvitationRow {
145 pub id: String,
146 pub repo_id: String,
147 pub workspace: String,
148 pub workspace_id: String,
149 pub repo_name: String,
150 pub invitee: Option<String>,
151 pub email: Option<String>,
152 pub invite_id: Option<String>,
153 pub role: String,
154 pub inviter_id: Option<String>,
155 pub inviter: Option<String>,
156 #[serde(default)]
157 pub inviter_avatar: Option<String>,
158 pub created_at: String,
159 pub expires_at: String,
160 pub accepted_at: Option<String>,
161 pub declined_at: Option<String>,
162 pub revoked_at: Option<String>,
163}
164
165impl InvitationRow {
166 fn role(&self) -> RepoRole {
167 RepoRole::parse(&self.role).unwrap_or(RepoRole::Read)
168 }
169
170 fn shown(&self, now: &str, with_email: bool) -> RepoInvitation {
171 RepoInvitation {
172 id: self.id.clone(),
173 repo: format!("{}/{}", self.workspace, self.repo_name),
174 repo_id: self.repo_id.clone(),
175 invitee: self.invitee.clone(),
176 email: if with_email { self.email.clone() } else { None },
177 role: self.role(),
178 invited_by: self.inviter.clone(),
179 inviter_avatar: self.inviter_avatar.clone(),
180 status: invitation_status(self, now),
181 created_at: self.created_at.clone(),
182 expires_at: self.expires_at.clone(),
183 }
184 }
185}
186
187const INVITATION_COLUMNS: &str = "ri.id, ri.repo_id, w.slug AS workspace, ri.workspace_id, ri.repo_name,
188 ri.invitee_id, invitee.username AS invitee, ri.email, ri.invite_id, ri.role, ri.inviter_id, inviter.username AS inviter, inviter.avatar AS inviter_avatar,
189 ri.created_at, ri.expires_at, ri.accepted_at, ri.declined_at, ri.revoked_at
190 FROM repo_invitations ri
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member191 JOIN workspaces w ON w.id = ri.workspace_id AND w.deleted_at IS NULL
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look192 LEFT JOIN users invitee ON invitee.id = ri.invitee_id
193 LEFT JOIN users inviter ON inviter.id = ri.inviter_id";
194
195/// A person as an access list shows them.
196#[derive(Deserialize)]
197struct PersonRow {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar198 id: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look199 username: String,
200 name: Option<String>,
201 avatar: Option<String>,
202 /// `owner` or `member`; null when they are not in the workspace.
203 #[serde(default)]
204 workspace_role: Option<String>,
205 /// Their direct grant on the repository, if any.
206 #[serde(default)]
207 direct: Option<String>,
208}
209
210#[derive(Deserialize)]
211struct Id {
212 id: String,
213}
214
215#[derive(Deserialize)]
216struct Base {
217 base_permission: String,
218}
219
220/// A repository by id and path: what events and the audit log name.
221#[derive(Clone, Copy)]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar222pub(crate) struct Named<'a> {
223 pub id: &'a str,
224 pub namespace: &'a str,
225 pub name: &'a str,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look226}
227
228impl<'a> From<&'a Repo> for Named<'a> {
229 fn from(repo: &'a Repo) -> Self {
230 Named {
231 id: &repo.id,
232 namespace: &repo.namespace,
233 name: &repo.name,
234 }
235 }
236}
237
238/// A repository someone may manage the access of, with its workspace's id.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar239pub(crate) struct Target {
240 pub repo: Repo,
241 pub workspace_id: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look242}
243
244fn opt(value: Option<&str>) -> JsValue {
245 value.map_or(JsValue::NULL, JsValue::from)
246}
247
248fn full_name(repo: &Repo) -> String {
249 format!("{}/{}", repo.namespace, repo.name)
250}
251
252impl Identity {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar253 /// Every repository `user_id` has a role on, directly or through a
254 /// team they are in (or through that team's parents, whose roles child
255 /// teams inherit), with the slug of its workspace now. Attached to
256 /// every user resolved from credentials.
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA257 ///
258 /// Each comes with whether its workspace requires two-factor
259 /// authentication (security.rs).
260 pub async fn grants_of(&self, user_id: &str) -> Result<Vec<(RepoGrant, bool)>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look261 let rows = self
262 .db
263 .prepare(format!(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar264 "WITH RECURSIVE mine(id) AS (
265 SELECT team_id FROM team_members WHERE user_id = ?1
266 UNION
267 SELECT t.parent_id FROM teams t JOIN mine ON t.id = mine.id WHERE t.parent_id IS NOT NULL
268 )
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA269 SELECT g.repo_id, w.slug AS workspace, g.role, NULL AS team, w.require_two_factor FROM repo_grants g
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member270 JOIN workspaces w ON w.id = g.workspace_id AND w.deleted_at IS NULL
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar271 WHERE g.principal_kind = 'user' AND g.principal_id = ?1
272 UNION ALL
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA273 SELECT g.repo_id, w.slug AS workspace, g.role, t.slug AS team, w.require_two_factor FROM repo_grants g
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar274 JOIN mine ON g.principal_kind = 'team' AND g.principal_id = mine.id
275 JOIN teams t ON t.id = g.principal_id
276 JOIN workspaces w ON w.id = g.workspace_id AND w.deleted_at IS NULL
277 LIMIT {MAX_GRANTS}"
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look278 ))
279 .bind(&[user_id.into()])?
280 .all()
281 .await?
282 .results::<GrantRow>()?;
283 Ok(rows
284 .into_iter()
285 .filter_map(|row| {
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA286 Some((
287 RepoGrant {
288 repo_id: row.repo_id,
289 workspace: row.workspace,
290 role: RepoRole::parse(&row.role)?,
291 team: row.team,
292 },
293 row.require_two_factor != 0,
294 ))
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look295 })
296 .collect())
297 }
298
299 /// The repository at `path` as `viewer` sees it: missing when they
300 /// cannot read it. Asked of repos, which owns visibility.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar301 pub(crate) async fn repo_for(&self, path: &RepoPath, viewer: &Viewer) -> Result<Option<Repo>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look302 let repos = self.env.service("REPOS")?;
303 let found: Outcome<Repo> = g1t_kit::call(
304 &repos,
305 "get",
306 &GetArgs {
307 path: path.clone(),
308 viewer: viewer.clone(),
309 },
310 )
311 .await?;
312 Ok(match found {
313 // A pull request's working copy has no access of its own.
314 Outcome::Ok(repo) if repo.fork_of.is_none() => Some(repo),
315 _ => None,
316 })
317 }
318
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar319 /// The highest role a team gives each person on a repository: the
320 /// teams with a grant on it, and their child teams, whose people
321 /// inherit it. `user_id` narrows it to one person.
322 pub(crate) async fn team_roles_on(&self, repo_id: &str, user_id: Option<&str>) -> Result<TeamRoles> {
323 #[derive(Deserialize)]
324 struct Row {
325 user_id: String,
326 role: String,
327 via: String,
328 }
329 let rows = self
330 .db
331 .prepare(
332 "WITH RECURSIVE reach(id, role, via) AS (
333 SELECT g.principal_id, g.role, t.slug FROM repo_grants g JOIN teams t ON t.id = g.principal_id
334 WHERE g.repo_id = ?1 AND g.principal_kind = 'team'
335 UNION
336 SELECT c.id, reach.role, reach.via FROM teams c JOIN reach ON c.parent_id = reach.id
337 )
338 SELECT tm.user_id, reach.role, reach.via FROM reach JOIN team_members tm ON tm.team_id = reach.id
339 WHERE ?2 IS NULL OR tm.user_id = ?2",
340 )
341 .bind(&[repo_id.into(), opt(user_id)])?
342 .all()
343 .await?
344 .results::<Row>()?;
345 Ok(highest_team_roles(
346 rows.into_iter()
347 .filter_map(|row| Some((row.user_id, RepoRole::parse(&row.role)?, row.via))),
348 ))
349 }
350
351 /// The teams with a role of their own on a repository.
352 pub(crate) async fn teams_on(&self, repo_id: &str) -> Result<Vec<g1t_contracts::teams::RepoTeam>> {
353 #[derive(Deserialize)]
354 struct Row {
355 slug: String,
356 name: String,
357 role: String,
358 visibility: String,
359 members_count: u32,
360 }
361 let rows = self
362 .db
363 .prepare(format!(
364 "SELECT t.slug, t.name, g.role, t.visibility,
365 (SELECT count(*) FROM team_members tm WHERE tm.team_id = t.id) AS members_count
366 FROM repo_grants g JOIN teams t ON t.id = g.principal_id
367 WHERE g.repo_id = ? AND g.principal_kind = 'team'
368 ORDER BY t.name LIMIT {LIST_LIMIT}"
369 ))
370 .bind(&[repo_id.into()])?
371 .all()
372 .await?
373 .results::<Row>()?;
374 Ok(rows
375 .into_iter()
376 .filter_map(|row| {
377 Some(g1t_contracts::teams::RepoTeam {
378 slug: row.slug,
379 name: row.name,
380 role: RepoRole::parse(&row.role)?,
381 members_count: row.members_count,
382 visibility: g1t_contracts::teams::TeamVisibility::parse(&row.visibility).unwrap_or_default(),
383 })
384 })
385 .collect())
386 }
387
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily388 pub(crate) async fn workspace_id_of(&self, slug: &str) -> Result<Option<String>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look389 Ok(self
390 .db
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member391 // A deleted workspace's repositories are nobody's to share.
392 .prepare("SELECT id FROM workspaces WHERE slug = ? AND deleted_at IS NULL")
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look393 .bind(&[slug.to_lowercase().into()])?
394 .first::<Id>(None)
395 .await?
396 .map(|row| row.id))
397 }
398
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar399 pub(crate) async fn base_of(&self, workspace_id: &str) -> Result<BasePermission> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look400 Ok(self
401 .db
402 .prepare("SELECT base_permission FROM workspaces WHERE id = ?")
403 .bind(&[workspace_id.into()])?
404 .first::<Base>(None)
405 .await?
406 .and_then(|row| BasePermission::parse(&row.base_permission))
407 .unwrap_or_default())
408 }
409
410 /// The repository at `path`, if `actor` may change who has access to it.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar411 pub(crate) async fn manageable(&self, actor: &User, path: &RepoPath) -> Result<Outcome<Target>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look412 if !crate::security::is_person(actor) {
413 return Ok(Outcome::fail(FailureCode::Forbidden, PEOPLE_ONLY));
414 }
415 let viewer = Some(actor.clone());
416 let Some(repo) = self.repo_for(path, &viewer).await? else {
417 return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found."));
418 };
419 if !can(Some(actor), &repo, Capability::ManageAccess) {
420 return Ok(Outcome::fail(
421 FailureCode::Forbidden,
422 needs(Capability::ManageAccess, &full_name(&repo)),
423 ));
424 }
425 if !actor.verified {
426 return Ok(Outcome::fail(FailureCode::Forbidden, CONFIRM_FIRST));
427 }
428 let Some(workspace_id) = self.workspace_id_of(&repo.namespace).await? else {
429 return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found."));
430 };
431 Ok(Outcome::Ok(Target { repo, workspace_id }))
432 }
433
434 /// The members of the repository's workspace and the people with a
435 /// direct grant on it, each once.
436 async fn people_rows(&self, repo_id: &str, workspace_id: &str) -> Result<Vec<PersonRow>> {
437 self.db
438 .prepare(format!(
439 "SELECT u.id, u.username, u.display_name AS name, u.avatar,
440 m.role AS workspace_role, g.role AS direct
441 FROM users u
442 LEFT JOIN workspace_members m ON m.user_id = u.id AND m.workspace_id = ?2
443 LEFT JOIN repo_grants g ON g.principal_kind = 'user' AND g.principal_id = u.id AND g.repo_id = ?1
444 WHERE m.user_id IS NOT NULL OR g.principal_id IS NOT NULL
445 ORDER BY u.username LIMIT {LIST_LIMIT}"
446 ))
447 .bind(&[repo_id.into(), workspace_id.into()])?
448 .all()
449 .await?
450 .results::<PersonRow>()
451 }
452
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar453 fn collaborator(row: PersonRow, base: BasePermission, teams: &TeamRoles) -> Option<Collaborator> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look454 let workspace_role = match row.workspace_role.as_deref() {
455 Some("owner") => Some(Role::Owner),
456 Some(_) => Some(Role::Member),
457 None => None,
458 };
459 let direct = row.direct.as_deref().and_then(RepoRole::parse);
460 let base_role = workspace_role.and(base.role());
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar461 let team = teams.get(&row.id).cloned();
462 let (role, source) = effective(
463 workspace_role == Some(Role::Owner),
464 base_role,
465 direct,
466 team.as_ref().map(|(role, _)| *role),
467 )?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look468 Some(Collaborator {
469 username: row.username,
470 name: row.name,
471 avatar: row.avatar,
472 role,
473 source,
474 direct,
475 workspace_role,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar476 team_role: team.as_ref().map(|(role, _)| *role),
477 team: team.map(|(_, slug)| slug),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look478 })
479 }
480
481 async fn invitations(&self, filter: &str, binds: &[JsValue]) -> Result<Vec<InvitationRow>> {
482 self.db
483 .prepare(format!("SELECT {INVITATION_COLUMNS} {filter} ORDER BY ri.created_at DESC LIMIT {LIST_LIMIT}"))
484 .bind(binds)?
485 .all()
486 .await?
487 .results::<InvitationRow>()
488 }
489
490 async fn pending_invitations(&self, filter: &str, binds: &[JsValue]) -> Result<Vec<InvitationRow>> {
491 let filter = format!(
492 "{filter} AND ri.accepted_at IS NULL AND ri.declined_at IS NULL AND ri.revoked_at IS NULL
493 AND ri.expires_at > {SQL_NOW}"
494 );
495 self.invitations(&filter, binds).await
496 }
497
498 pub async fn repo_access(&self, a: RepoAccessArgs) -> Result<Outcome<RepoAccess>> {
499 let Some(repo) = self.repo_for(&a.path, &a.viewer).await? else {
500 return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found."));
501 };
502 let viewer_role = a.viewer.as_ref().and_then(|viewer| granted(viewer, (&repo).into()));
503 // Like the list of collaborators: for those who can push.
504 if !viewer_role.is_some_and(|role| role >= RepoRole::Write) {
505 return Ok(Outcome::fail(
506 FailureCode::Forbidden,
507 format!("You need the Write role or higher on {} to see who has access.", full_name(&repo)),
508 ));
509 }
510 let can_manage = can(a.viewer.as_ref(), &repo, Capability::ManageAccess);
511 let Some(workspace_id) = self.workspace_id_of(&repo.namespace).await? else {
512 return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found."));
513 };
514 let base = self.base_of(&workspace_id).await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar515 let rows = self.people_rows(&repo.id, &workspace_id).await?;
516 let team_roles = self.team_roles_on(&repo.id, None).await?;
517 let teams = self.teams_on(&repo.id).await?;
518 let mut people: Vec<Collaborator> = rows
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look519 .into_iter()
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar520 .filter_map(|row| Self::collaborator(row, base, &team_roles))
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look521 .collect();
522 people.sort_by(|a, b| b.role.cmp(&a.role).then_with(|| a.username.cmp(&b.username)));
523 let invitations = if can_manage {
524 let now = rfc3339(now_ms());
525 self.pending_invitations("WHERE ri.repo_id = ?", &[repo.id.as_str().into()])
526 .await?
527 .iter()
528 .map(|row| row.shown(&now, true))
529 .collect()
530 } else {
531 Vec::new()
532 };
533 Ok(Outcome::Ok(RepoAccess {
534 repo: full_name(&repo),
535 base_permission: base,
536 people,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar537 teams,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look538 invitations,
539 viewer_role,
540 can_manage,
541 }))
542 }
543
544 /// One person's place on the repository, as the access list shows it.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar545 pub(crate) async fn collaborator_on(&self, repo: &Repo, workspace_id: &str, user_id: &str) -> Result<Option<Collaborator>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look546 let base = self.base_of(workspace_id).await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar547 let teams = self.team_roles_on(&repo.id, Some(user_id)).await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look548 let row = self
549 .db
550 .prepare(
551 "SELECT u.id, u.username, u.display_name AS name, u.avatar,
552 m.role AS workspace_role, g.role AS direct
553 FROM users u
554 LEFT JOIN workspace_members m ON m.user_id = u.id AND m.workspace_id = ?2
555 LEFT JOIN repo_grants g ON g.principal_kind = 'user' AND g.principal_id = u.id AND g.repo_id = ?1
556 WHERE u.id = ?3",
557 )
558 .bind(&[repo.id.as_str().into(), workspace_id.into(), user_id.into()])?
559 .first::<PersonRow>(None)
560 .await?;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar561 Ok(row.and_then(|row| Self::collaborator(row, base, &teams)))
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look562 }
563
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar564 pub(crate) async fn person_by_username(&self, username: &str) -> Result<Option<(String, String)>> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look565 #[derive(Deserialize)]
566 struct Person {
567 id: String,
568 username: String,
569 }
570 Ok(self
571 .db
572 .prepare("SELECT id, username FROM users WHERE username = ?")
573 .bind(&[username.trim().trim_start_matches('@').to_lowercase().into()])?
574 .first::<Person>(None)
575 .await?
576 .map(|person| (person.id, person.username)))
577 }
578
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar579 pub(crate) async fn is_member_of(&self, workspace_id: &str, user_id: &str) -> Result<bool> {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look580 Ok(self
581 .db
582 .prepare("SELECT user_id AS id FROM workspace_members WHERE workspace_id = ? AND user_id = ?")
583 .bind(&[workspace_id.into(), user_id.into()])?
584 .first::<Id>(None)
585 .await?
586 .is_some())
587 }
588
589 async fn direct_role(&self, repo_id: &str, user_id: &str) -> Result<Option<RepoRole>> {
590 #[derive(Deserialize)]
591 struct RoleRow {
592 role: String,
593 }
594 Ok(self
595 .db
596 .prepare("SELECT role FROM repo_grants WHERE repo_id = ? AND principal_kind = 'user' AND principal_id = ?")
597 .bind(&[repo_id.into(), user_id.into()])?
598 .first::<RoleRow>(None)
599 .await?
600 .and_then(|row| RepoRole::parse(&row.role)))
601 }
602
603 /// Gives `user_id` `role` on the repository, or changes the role they
604 /// have; returns the role they had before.
605 async fn put_grant(
606 &self,
607 repo_id: &str,
608 workspace_id: &str,
609 repo_name: &str,
610 user_id: &str,
611 role: RepoRole,
612 granted_by: Option<&str>,
613 ) -> Result<Option<RepoRole>> {
614 let previous = self.direct_role(repo_id, user_id).await?;
615 let now = rfc3339(now_ms());
616 self.db
617 .prepare(
618 "INSERT INTO repo_grants
619 (repo_id, principal_kind, principal_id, workspace_id, repo_name, role, granted_by, created_at, updated_at)
620 VALUES (?1, 'user', ?2, ?3, ?4, ?5, ?6, ?7, ?7)
621 ON CONFLICT (repo_id, principal_kind, principal_id)
622 DO UPDATE SET role = excluded.role, workspace_id = excluded.workspace_id,
623 repo_name = excluded.repo_name, updated_at = excluded.updated_at",
624 )
625 .bind(&[
626 repo_id.into(),
627 user_id.into(),
628 workspace_id.into(),
629 repo_name.into(),
630 role.as_str().into(),
631 opt(granted_by),
632 now.as_str().into(),
633 ])?
634 .run()
635 .await?;
636 Ok(previous)
637 }
638
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA639 /// Why `actor` may not give someone outside the workspace a role on one
640 /// of its repositories: its member privileges leave that to owners
641 /// (`members_can_invite_outside_collaborators`). Read from the workspace
642 /// itself, so an outside collaborator with Admin is held to it too.
643 async fn outside_refusal<T>(&self, actor: &User, namespace: &str, workspace_id: &str) -> Result<Option<Outcome<T>>> {
644 if actor.role_in(&namespace.to_lowercase()) == Some(Role::Owner) || actor.kind == PrincipalKind::Workspace {
645 return Ok(None);
646 }
647 if self.privileges_of(workspace_id).await?.members_can_invite_outside_collaborators {
648 return Ok(None);
649 }
650 Ok(Some(Outcome::fail(
651 FailureCode::Forbidden,
652 format!("Only owners of {namespace} can add people from outside the workspace to its repositories."),
653 )))
654 }
655
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look656 pub async fn add_collaborator(&self, a: AddCollaboratorArgs) -> Result<Outcome<Added>> {
657 let Target { repo, workspace_id } = match self.manageable(&a.actor, &a.path).await? {
658 Outcome::Ok(target) => target,
659 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
660 };
661 let surface = a.surface.unwrap_or(Surface::Web);
662 let invitee = match invitee(&a.invitee) {
663 Some(invitee) => invitee,
664 None => return Ok(Outcome::fail(FailureCode::Invalid, "Enter a username or an email address.")),
665 };
666 // Who it names: an account by username, or by a confirmed address.
667 let person = match &invitee {
668 Invitee::Username(name) => match self.person_by_username(name).await? {
669 Some(person) => Some(person),
670 None => return Ok(Outcome::fail(FailureCode::NotFound, NO_SUCH_USER)),
671 },
672 Invitee::Email(email) => match self.user_with_verified_email(email).await? {
673 Some(id) => self
674 .find_public_user(
675 "SELECT id, username, email_verified_at IS NOT NULL AS verified FROM users WHERE id = ?",
676 &id,
677 )
678 .await?
679 .map(|user| (user.id, user.username)),
680 None => None,
681 },
682 };
683 let Some((user_id, username)) = person else {
684 let Invitee::Email(email) = invitee else {
685 return Ok(Outcome::fail(FailureCode::NotFound, NO_SUCH_USER));
686 };
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA687 if let Some(refused) = self.outside_refusal(&a.actor, &repo.namespace, &workspace_id).await? {
688 return Ok(refused);
689 }
Merge Stripe Tax, the card fee on card payments, and one free workspace per person690 // An address is always someone from outside: a free workspace
691 // invites no one (paid.rs).
692 if let Some(refused) = self.free_workspace_refusal(&repo.namespace).await? {
693 return Ok(refused);
694 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look695 return self.invite_address(&a.actor, &repo, &workspace_id, &email, a.role, surface).await;
696 };
697 // What the workspace asks of anyone with access to it (security.rs).
698 if let Some(why) = self.policy_refusal(&user_id, &repo.namespace).await? {
699 return Ok(Outcome::fail(FailureCode::Forbidden, why));
700 }
701 if self.is_member_of(&workspace_id, &user_id).await? {
702 let previous = self
703 .put_grant(&repo.id, &workspace_id, &repo.name, &user_id, a.role, Some(&a.actor.id))
704 .await?;
705 self.changed(&a.actor, (&repo).into(), &username, Some(a.role), previous, surface).await;
706 let Some(collaborator) = self.collaborator_on(&repo, &workspace_id, &user_id).await? else {
707 return Ok(Outcome::fail(FailureCode::NotFound, NO_SUCH_USER));
708 };
709 return Ok(Outcome::Ok(Added::Granted { collaborator }));
710 }
711 if self.direct_role(&repo.id, &user_id).await?.is_some() {
712 return Ok(Outcome::fail(
713 FailureCode::Conflict,
714 format!("{username} already has access to {}. Change their role instead.", full_name(&repo)),
715 ));
716 }
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA717 if let Some(refused) = self.outside_refusal(&a.actor, &repo.namespace, &workspace_id).await? {
718 return Ok(refused);
719 }
Merge Stripe Tax, the card fee on card payments, and one free workspace per person720 // An outside collaborator is someone added: a free workspace adds
721 // no one (paid.rs). Its members' roles above are its own business,
722 // and g1t's agent is never someone added.
723 if !crate::paid::is_g1t(&username)
724 && let Some(refused) = self.free_workspace_refusal(&repo.namespace).await?
725 {
726 return Ok(refused);
727 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look728 let pending = self
729 .pending_invitations(
730 "WHERE ri.repo_id = ? AND ri.invitee_id = ?",
731 &[repo.id.as_str().into(), user_id.as_str().into()],
732 )
733 .await?;
734 if !pending.is_empty() {
735 return Ok(Outcome::fail(
736 FailureCode::Conflict,
737 format!("{username} already has a pending invitation to {}. Change its role, or revoke it to send a new one.", full_name(&repo)),
738 ));
739 }
740 let id = self
741 .insert_invitation(&repo, &workspace_id, Some(&user_id), None, None, a.role, &a.actor.id, INVITATION_DAYS)
742 .await?;
743 let now = rfc3339(now_ms());
744 let Some(row) = self.invitation_by_id(&id).await? else {
745 return Ok(Outcome::fail(FailureCode::NotFound, "Invitation not found."));
746 };
747 // Told by email, at their primary address and the one typed.
748 let mut to = self.notice_recipients(&user_id, false).await.unwrap_or_default();
749 if let Invitee::Email(email) = &invitee
750 && !to.iter().any(|address| address.eq_ignore_ascii_case(email))
751 {
752 to.push(email.clone());
753 }
754 for address in to.iter().take(2) {
755 if let Err(error) = crate::email::send_repo_invite(
756 &self.env,
757 address,
758 &a.actor.username,
759 &full_name(&repo),
760 a.role.label(),
761 None,
762 INVITATION_DAYS,
763 )
764 .await
765 {
766 worker::console_error!("repository invitation email failed: {error}");
767 }
768 }
769 self.audit(&a.actor, "repo.invitation_created", (&repo).into(), surface, format!("Invited {username} as {}", a.role.label()))
770 .await;
771 Ok(Outcome::Ok(Added::Invited {
772 invitation: row.shown(&now, true),
773 }))
774 }
775
776 /// An address without an account: an invite code that makes it and
777 /// accepts (invites.rs).
778 async fn invite_address(
779 &self,
780 actor: &User,
781 repo: &Repo,
782 workspace_id: &str,
783 email: &str,
784 role: RepoRole,
785 surface: Surface,
786 ) -> Result<Outcome<Added>> {
787 let pending = self
788 .pending_invitations(
789 "WHERE ri.repo_id = ? AND ri.email = ?",
790 &[repo.id.as_str().into(), email.into()],
791 )
792 .await?;
793 if !pending.is_empty() {
794 return Ok(Outcome::fail(
795 FailureCode::Conflict,
796 "That address already has a pending invitation to this repository. Revoke it to send a new one.",
797 ));
798 }
799 let invite = match self.repo_invite_code(actor, email, workspace_id).await? {
800 Outcome::Ok(invite) => invite,
801 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
802 };
803 let days = self.invite_days();
804 let id = self
805 .insert_invitation(repo, workspace_id, None, Some(email), Some(&invite.id), role, &actor.id, days)
806 .await?;
807 if let Some(code) = &invite.code
808 && let Err(error) = crate::email::send_repo_invite(
809 &self.env,
810 email,
811 &actor.username,
812 &full_name(repo),
813 role.label(),
814 Some(code),
815 days,
816 )
817 .await
818 {
819 worker::console_error!("repository invitation email failed: {error}");
820 }
821 self.audit(
822 actor,
823 "repo.invitation_created",
824 repo.into(),
825 surface,
826 format!("Invited {} as {}", crate::invites::mask_email(email), role.label()),
827 )
828 .await;
829 let now = rfc3339(now_ms());
830 Ok(match self.invitation_by_id(&id).await? {
831 Some(row) => Outcome::Ok(Added::Invited {
832 invitation: row.shown(&now, true),
833 }),
834 None => Outcome::fail(FailureCode::NotFound, "Invitation not found."),
835 })
836 }
837
838 #[allow(clippy::too_many_arguments)]
839 async fn insert_invitation(
840 &self,
841 repo: &Repo,
842 workspace_id: &str,
843 invitee_id: Option<&str>,
844 email: Option<&str>,
845 invite_id: Option<&str>,
846 role: RepoRole,
847 inviter_id: &str,
848 days: u64,
849 ) -> Result<String> {
850 let now = now_ms();
851 let id = new_id("rin", now);
852 self.db
853 .prepare(
854 "INSERT INTO repo_invitations
855 (id, repo_id, workspace_id, repo_name, invitee_id, email, invite_id, role, inviter_id, created_at, expires_at)
856 VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)",
857 )
858 .bind(&[
859 id.as_str().into(),
860 repo.id.as_str().into(),
861 workspace_id.into(),
862 repo.name.as_str().into(),
863 opt(invitee_id),
864 opt(email),
865 opt(invite_id),
866 role.as_str().into(),
867 inviter_id.into(),
868 rfc3339(now).into(),
869 rfc3339(now + days * 86_400_000).into(),
870 ])?
871 .run()
872 .await?;
873 Ok(id)
874 }
875
876 async fn invitation_by_id(&self, id: &str) -> Result<Option<InvitationRow>> {
877 Ok(self
878 .invitations("WHERE ri.id = ?", &[id.into()])
879 .await?
880 .into_iter()
881 .next())
882 }
883
884 fn invite_days(&self) -> u64 {
885 self.env
886 .var("INVITE_TTL_DAYS")
887 .ok()
888 .and_then(|value| value.to_string().parse().ok())
889 .unwrap_or(g1t_contracts::identity::INVITE_TTL_DAYS)
890 }
891
892 pub async fn set_collaborator_role(&self, a: SetCollaboratorRoleArgs) -> Result<Outcome<Collaborator>> {
893 let Target { repo, workspace_id } = match self.manageable(&a.actor, &a.path).await? {
894 Outcome::Ok(target) => target,
895 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
896 };
897 let Some((user_id, username)) = self.person_by_username(&a.username).await? else {
898 return Ok(Outcome::fail(FailureCode::NotFound, NO_SUCH_USER));
899 };
900 let surface = a.surface.unwrap_or(Surface::Web);
901 match self.direct_role(&repo.id, &user_id).await? {
902 Some(previous) => {
903 self.put_grant(&repo.id, &workspace_id, &repo.name, &user_id, a.role, Some(&a.actor.id))
904 .await?;
905 if previous != a.role {
906 self.changed(&a.actor, (&repo).into(), &username, Some(a.role), Some(previous), surface).await;
907 }
908 }
909 None => {
910 // A pending invitation's role changes until it is answered.
911 let changed = self
912 .db
913 .prepare(format!(
914 "UPDATE repo_invitations SET role = ?1
915 WHERE repo_id = ?2 AND invitee_id = ?3 AND accepted_at IS NULL AND declined_at IS NULL
916 AND revoked_at IS NULL AND expires_at > {SQL_NOW}
917 RETURNING id"
918 ))
919 .bind(&[a.role.as_str().into(), repo.id.as_str().into(), user_id.as_str().into()])?
920 .first::<Id>(None)
921 .await?;
922 if changed.is_none() {
923 return Ok(Outcome::fail(
924 FailureCode::NotFound,
925 format!(
926 "{username} has no role of their own on {}. Owners have Admin, and members the base permission; add them to give them more.",
927 full_name(&repo)
928 ),
929 ));
930 }
931 }
932 }
933 Ok(match self.collaborator_on(&repo, &workspace_id, &user_id).await? {
934 Some(collaborator) => Outcome::Ok(collaborator),
935 // Invited, not yet a collaborator: say what they will be.
936 None => Outcome::Ok(Collaborator {
937 username,
938 name: None,
939 avatar: None,
940 role: a.role,
941 source: AccessSource::Direct,
942 direct: Some(a.role),
943 workspace_role: None,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar944 team_role: None,
945 team: None,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look946 }),
947 })
948 }
949
950 pub async fn remove_collaborator(&self, a: RemoveCollaboratorArgs) -> Result<Outcome<bool>> {
951 let Some((user_id, username)) = self.person_by_username(&a.username).await? else {
952 return Ok(Outcome::fail(FailureCode::NotFound, NO_SUCH_USER));
953 };
954 let surface = a.surface.unwrap_or(Surface::Web);
955 // Anyone may give up their own role; otherwise, Admin only.
956 let leaving = crate::security::is_person(&a.actor) && a.actor.id == user_id;
957 let repo = if leaving {
958 match self.repo_for(&a.path, &Some(a.actor.clone())).await? {
959 Some(repo) => repo,
960 None => return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found.")),
961 }
962 } else {
963 match self.manageable(&a.actor, &a.path).await? {
964 Outcome::Ok(target) => target.repo,
965 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
966 }
967 };
968 let Some(previous) = self.direct_role(&repo.id, &user_id).await? else {
969 return Ok(Outcome::fail(
970 FailureCode::NotFound,
971 format!(
972 "{username} has no role of their own on {}. To take away a member's access, change the base permission or remove them from the workspace.",
973 full_name(&repo)
974 ),
975 ));
976 };
977 self.db
978 .batch(vec![
979 self.db
980 .prepare("DELETE FROM repo_grants WHERE repo_id = ? AND principal_kind = 'user' AND principal_id = ?")
981 .bind(&[repo.id.as_str().into(), user_id.as_str().into()])?,
982 self.db
983 .prepare(format!(
984 "UPDATE repo_invitations SET revoked_at = {SQL_NOW}
985 WHERE repo_id = ? AND invitee_id = ? AND accepted_at IS NULL AND declined_at IS NULL AND revoked_at IS NULL"
986 ))
987 .bind(&[repo.id.as_str().into(), user_id.as_str().into()])?,
988 ])
989 .await?;
990 self.changed(&a.actor, (&repo).into(), &username, None, Some(previous), surface).await;
991 Ok(Outcome::Ok(true))
992 }
993
994 pub async fn collaborator_permission(&self, a: CollaboratorPermissionArgs) -> Result<Outcome<PermissionInfo>> {
995 let Some(repo) = self.repo_for(&a.path, &a.viewer).await? else {
996 return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found."));
997 };
998 let asking_about_self = a
999 .viewer
1000 .as_ref()
1001 .is_some_and(|viewer| viewer.username.eq_ignore_ascii_case(a.username.trim()));
1002 if !asking_about_self && !can(a.viewer.as_ref(), &repo, Capability::Push) {
1003 return Ok(Outcome::fail(
1004 FailureCode::Forbidden,
1005 format!("You need the Write role or higher on {} to see others' permissions.", full_name(&repo)),
1006 ));
1007 }
1008 let Some((user_id, username)) = self.person_by_username(&a.username).await? else {
1009 return Ok(Outcome::fail(FailureCode::NotFound, NO_SUCH_USER));
1010 };
1011 let Some(workspace_id) = self.workspace_id_of(&repo.namespace).await? else {
1012 return Ok(Outcome::fail(FailureCode::NotFound, "Repository not found."));
1013 };
1014 // Held to the workspace's policy as their requests are.
1015 let within = self.policy_refusal(&user_id, &repo.namespace).await?.is_none();
1016 let place = if within {
1017 self.collaborator_on(&repo, &workspace_id, &user_id).await?
1018 } else {
1019 None
1020 };
1021 let role = place.as_ref().map(|place| place.role);
1022 Ok(Outcome::Ok(PermissionInfo {
1023 username,
1024 role,
1025 source: place.map(|place| place.source),
1026 capabilities: capabilities_of(role),
1027 }))
1028 }
1029
1030 pub async fn my_repo_invitations(&self, a: MyRepoInvitationsArgs) -> Result<Vec<RepoInvitation>> {
1031 if !crate::security::is_person(&a.user) {
1032 return Ok(Vec::new());
1033 }
1034 let now = rfc3339(now_ms());
1035 Ok(self
1036 .invitations_for(&a.user, None)
1037 .await?
1038 .iter()
1039 .map(|row| row.shown(&now, false))
1040 .collect())
1041 }
1042
1043 /// The pending invitations for `user`: sent to them, or to one of
1044 /// their confirmed addresses before they had an account (and made it
1045 /// some other way than with the code). `id` narrows it to one.
1046 async fn invitations_for(&self, user: &User, id: Option<&str>) -> Result<Vec<InvitationRow>> {
1047 let emails = serde_json::to_string(&self.verified_emails(&user.id).await?)?;
1048 let mut filter = "WHERE (ri.invitee_id = ? OR (ri.invitee_id IS NULL AND ri.email IN (SELECT value FROM json_each(?))))".to_owned();
1049 let mut binds = vec![JsValue::from(user.id.as_str()), emails.into()];
1050 if let Some(id) = id {
1051 filter.push_str(" AND ri.id = ?");
1052 binds.push(id.into());
1053 }
1054 self.pending_invitations(&filter, &binds).await
1055 }
1056
1057 pub async fn respond_repo_invitation(&self, a: RespondRepoInvitationArgs) -> Result<Outcome<RepoInvitation>> {
1058 if !crate::security::is_person(&a.user) {
1059 return Ok(Outcome::fail(FailureCode::Forbidden, "Only a person can answer an invitation."));
1060 }
1061 let now = rfc3339(now_ms());
1062 let row = self
1063 .invitations_for(&a.user, Some(&a.id))
1064 .await?
1065 .into_iter()
1066 .next();
1067 let Some(row) = row else {
1068 return Ok(Outcome::fail(
1069 FailureCode::NotFound,
1070 "There is no pending invitation of yours with that id. It may have expired or been revoked.",
1071 ));
1072 };
1073 if !a.accept {
1074 self.db
1075 .prepare(format!("UPDATE repo_invitations SET declined_at = {SQL_NOW} WHERE id = ?"))
1076 .bind(&[row.id.as_str().into()])?
1077 .run()
1078 .await?;
1079 let mut shown = row.shown(&now, false);
1080 shown.status = RepoInvitationStatus::Declined;
1081 return Ok(Outcome::Ok(shown));
1082 }
1083 if let Some(why) = self.policy_refusal(&a.user.id, &row.workspace).await? {
1084 return Ok(Outcome::fail(FailureCode::Forbidden, why));
1085 }
Merge Stripe Tax, the card fee on card payments, and one free workspace per person1086 // Sent before the workspace was free, or before this rule: it waits
1087 // until the workspace starts the plan (paid.rs).
1088 if let Some(refused) = self.free_workspace_refusal(&row.workspace).await? {
1089 return Ok(refused);
1090 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1091 self.accept(&row, &a.user).await?;
1092 let mut shown = row.shown(&now, false);
1093 shown.status = RepoInvitationStatus::Accepted;
1094 Ok(Outcome::Ok(shown))
1095 }
1096
1097 /// Turns an invitation into a grant, once.
1098 async fn accept(&self, row: &InvitationRow, user: &User) -> Result<()> {
1099 let claimed = self
1100 .db
1101 .prepare(format!(
1102 "UPDATE repo_invitations SET accepted_at = {SQL_NOW}, invitee_id = ?1
1103 WHERE id = ?2 AND accepted_at IS NULL AND declined_at IS NULL AND revoked_at IS NULL
1104 RETURNING id"
1105 ))
1106 .bind(&[user.id.as_str().into(), row.id.as_str().into()])?
1107 .first::<Id>(None)
1108 .await?;
1109 if claimed.is_none() {
1110 return Ok(());
1111 }
1112 let role = row.role();
1113 // Never lowers a role they already have.
1114 let current = self.direct_role(&row.repo_id, &user.id).await?;
1115 let role = current.map_or(role, |current| current.max(role));
1116 let previous = self
1117 .put_grant(&row.repo_id, &row.workspace_id, &row.repo_name, &user.id, role, row.inviter_id.as_deref())
1118 .await?;
1119 let repo = Named {
1120 id: &row.repo_id,
1121 namespace: &row.workspace,
1122 name: &row.repo_name,
1123 };
1124 self.changed(user, repo, &user.username, Some(role), previous, Surface::Web).await;
1125 Ok(())
1126 }
1127
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1128 /// The repository an invite code was sent with, for the invite's page
1129 /// (invites.rs): whatever became of the invitation since.
1130 pub(crate) async fn repository_of_code(
1131 &self,
1132 invite_id: &str,
1133 ) -> Result<Option<g1t_contracts::identity::InviteRepository>> {
1134 Ok(self
1135 .invitations("WHERE ri.invite_id = ?", &[invite_id.into()])
1136 .await?
1137 .into_iter()
1138 .next()
1139 .map(|row| g1t_contracts::identity::InviteRepository {
1140 name: format!("{}/{}", row.workspace, row.repo_name),
1141 role: row.role().as_str().to_owned(),
1142 }))
1143 }
1144
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1145 /// Accepts the repository invitations sent with an invite code, once
1146 /// the code made `user`'s account (invites.rs).
1147 pub(crate) async fn accept_invitations_of_code(&self, invite_id: &str, user: &User) -> Result<()> {
1148 let rows = self
1149 .pending_invitations("WHERE ri.invite_id = ?", &[invite_id.into()])
1150 .await?;
1151 for row in rows {
1152 if self.policy_refusal(&user.id, &row.workspace).await?.is_some() {
1153 continue;
1154 }
Merge Stripe Tax, the card fee on card payments, and one free workspace per person1155 // A free workspace adds no one (paid.rs): the invitation stays
1156 // pending until it starts the plan.
1157 if self.is_free_workspace(&row.workspace).await {
1158 continue;
1159 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1160 self.accept(&row, user).await?;
1161 }
1162 Ok(())
1163 }
1164
1165 pub async fn revoke_repo_invitation(&self, a: RevokeRepoInvitationArgs) -> Result<Outcome<RepoInvitation>> {
1166 let Target { repo, .. } = match self.manageable(&a.actor, &a.path).await? {
1167 Outcome::Ok(target) => target,
1168 Outcome::Fail(failure) => return Ok(Outcome::Fail(failure)),
1169 };
1170 let revoked = self
1171 .db
1172 .prepare(format!(
1173 "UPDATE repo_invitations SET revoked_at = {SQL_NOW}
1174 WHERE id = ? AND repo_id = ? AND accepted_at IS NULL AND declined_at IS NULL AND revoked_at IS NULL
1175 RETURNING id"
1176 ))
1177 .bind(&[a.id.as_str().into(), repo.id.as_str().into()])?
1178 .first::<Id>(None)
1179 .await?;
1180 if revoked.is_none() {
1181 return Ok(Outcome::fail(FailureCode::NotFound, "There is no pending invitation with that id."));
1182 }
1183 let Some(row) = self.invitation_by_id(&a.id).await? else {
1184 return Ok(Outcome::fail(FailureCode::NotFound, "Invitation not found."));
1185 };
1186 if let Some(invite_id) = &row.invite_id {
1187 self.revoke_code(invite_id).await?;
1188 }
1189 let who = row
1190 .invitee
1191 .clone()
1192 .or_else(|| row.email.as_deref().map(crate::invites::mask_email))
1193 .unwrap_or_default();
1194 self.audit(
1195 &a.actor,
1196 "repo.invitation_revoked",
1197 (&repo).into(),
1198 a.surface.unwrap_or(Surface::Web),
1199 format!("Revoked the invitation to {who}"),
1200 )
1201 .await;
1202 Ok(Outcome::Ok(row.shown(&rfc3339(now_ms()), true)))
1203 }
1204
1205 pub async fn set_base_permission(&self, a: SetBasePermissionArgs) -> Result<Outcome<BasePermission>> {
1206 let slug = a.slug.trim().to_lowercase();
1207 if !crate::security::is_person(&a.actor) || a.actor.role_in(&slug) != Some(Role::Owner) {
1208 return Ok(Outcome::fail(
1209 FailureCode::Forbidden,
1210 "Only an owner can change what members get on every repository.",
1211 ));
1212 }
1213 if !a.actor.verified {
1214 return Ok(Outcome::fail(FailureCode::Forbidden, CONFIRM_FIRST));
1215 }
1216 let Some(workspace_id) = self.workspace_id_of(&slug).await? else {
1217 return Ok(Outcome::fail(FailureCode::NotFound, "Workspace not found."));
1218 };
1219 let previous = self.base_of(&workspace_id).await?;
1220 self.db
1221 .prepare("UPDATE workspaces SET base_permission = ? WHERE id = ?")
1222 .bind(&[a.base_permission.as_str().into(), workspace_id.as_str().into()])?
1223 .run()
1224 .await?;
1225 if previous != a.base_permission {
1226 self.audit_workspace(
1227 &a.actor,
1228 "workspace.base_permission_changed",
1229 &slug,
1230 a.surface.unwrap_or(Surface::Web),
1231 format!(
1232 "Changed the base permission from {} to {}",
1233 previous.as_str(),
1234 a.base_permission.as_str()
1235 ),
1236 )
1237 .await;
1238 self.announce_workspace(&workspace_id, &slug, Some(&a.actor.id)).await;
1239 }
1240 Ok(Outcome::Ok(a.base_permission))
1241 }
1242
Merge branch 'worktree-agent-a2013627e5ea4ab13'1243 /// `workspace_residency`: where a workspace keeps its repositories'
1244 /// git data, for the repos service as it places a new one, and for its
1245 /// settings page. Null when there is no such workspace.
1246 pub async fn workspace_residency(&self, a: g1t_contracts::identity::SlugArgs) -> Result<Option<g1t_contracts::identity::DataResidency>> {
1247 #[derive(Deserialize)]
1248 struct Row {
1249 #[serde(default)]
1250 data_residency: Option<String>,
1251 }
1252 let row = self
1253 .db
1254 .prepare("SELECT data_residency FROM workspaces WHERE slug = ? AND deleted_at IS NULL")
1255 .bind(&[a.slug.trim().to_lowercase().into()])?
1256 .first::<Row>(None)
1257 .await?;
1258 Ok(row.map(|row| {
1259 row.data_residency
1260 .as_deref()
1261 .and_then(g1t_contracts::identity::DataResidency::parse)
1262 .unwrap_or_default()
1263 }))
1264 }
1265
1266 /// `set_workspace_residency`: owners only. Applies to repositories
1267 /// made from then on; those it has stay where they are. Whether the EU
1268 /// can be chosen is the repos service's to say (`storage_options`);
1269 /// the site offers it only then, and the repos service refuses to
1270 /// place an EU workspace's repository anywhere else.
1271 pub async fn set_workspace_residency(
1272 &self,
1273 a: g1t_contracts::identity::SetResidencyArgs,
1274 ) -> Result<Outcome<g1t_contracts::identity::DataResidency>> {
1275 let slug = a.slug.trim().to_lowercase();
1276 if !crate::security::is_person(&a.actor) || a.actor.role_in(&slug) != Some(Role::Owner) {
1277 return Ok(Outcome::fail(FailureCode::Forbidden, "Only an owner can change where a workspace keeps its data."));
1278 }
1279 if !a.actor.verified {
1280 return Ok(Outcome::fail(FailureCode::Forbidden, "Confirm your email address before changing where the workspace keeps its data."));
1281 }
1282 let Some(previous) = self.workspace_residency(g1t_contracts::identity::SlugArgs { slug: slug.clone() }).await? else {
1283 return Ok(Outcome::fail(FailureCode::NotFound, "Workspace not found."));
1284 };
1285 if previous == a.residency {
1286 return Ok(Outcome::Ok(previous));
1287 }
1288 let stored = match a.residency {
1289 g1t_contracts::identity::DataResidency::Anywhere => JsValue::NULL,
1290 other => other.as_str().into(),
1291 };
1292 self.db
1293 .prepare("UPDATE workspaces SET data_residency = ? WHERE slug = ? AND deleted_at IS NULL")
1294 .bind(&[stored, slug.as_str().into()])?
1295 .run()
1296 .await?;
1297 self.audit_workspace(
1298 &a.actor,
1299 "workspace.residency_changed",
1300 &slug,
1301 Surface::Web,
1302 format!("Changed where new repositories keep their data from {} to {}", previous.as_str(), a.residency.as_str()),
1303 )
1304 .await;
1305 Ok(Outcome::Ok(a.residency))
1306 }
1307
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1308 pub async fn outside_collaborators(&self, a: OutsideCollaboratorsArgs) -> Result<Outcome<Vec<OutsideCollaborator>>> {
1309 let slug = a.slug.trim().to_lowercase();
1310 if !a.viewer.as_ref().is_some_and(|viewer| viewer.role_in(&slug) == Some(Role::Owner)) {
1311 return Ok(Outcome::fail(FailureCode::Forbidden, "Only owners can see a workspace's outside collaborators."));
1312 }
1313 let Some(workspace_id) = self.workspace_id_of(&slug).await? else {
1314 return Ok(Outcome::fail(FailureCode::NotFound, "Workspace not found."));
1315 };
1316 #[derive(Deserialize)]
1317 struct Row {
1318 username: String,
1319 name: Option<String>,
1320 avatar: Option<String>,
1321 repo_name: String,
1322 role: String,
1323 }
1324 let rows = self
1325 .db
1326 .prepare(format!(
1327 "SELECT u.username, u.display_name AS name, u.avatar, g.repo_name, g.role
1328 FROM repo_grants g JOIN users u ON u.id = g.principal_id
1329 WHERE g.workspace_id = ?1 AND g.principal_kind = 'user'
1330 AND NOT EXISTS (SELECT 1 FROM workspace_members m WHERE m.workspace_id = ?1 AND m.user_id = g.principal_id)
1331 ORDER BY u.username, g.repo_name LIMIT {LIST_LIMIT}"
1332 ))
1333 .bind(&[workspace_id.as_str().into()])?
1334 .all()
1335 .await?
1336 .results::<Row>()?;
1337 let mut people: Vec<OutsideCollaborator> = Vec::new();
1338 for row in rows {
1339 let Some(role) = RepoRole::parse(&row.role) else {
1340 continue;
1341 };
1342 let repo = CollaboratorRepo {
1343 repo: format!("{slug}/{}", row.repo_name),
1344 role,
1345 };
1346 match people.last_mut().filter(|person| person.username == row.username) {
1347 Some(person) => person.repos.push(repo),
1348 None => people.push(OutsideCollaborator {
1349 username: row.username,
1350 name: row.name,
1351 avatar: row.avatar,
1352 repos: vec![repo],
1353 }),
1354 }
1355 }
1356 Ok(Outcome::Ok(people))
1357 }
1358
1359 pub async fn forget_repo_access(&self, a: ForgetRepoAccessArgs) -> Result<bool> {
1360 self.db
1361 .batch(vec![
1362 self.db
1363 .prepare("DELETE FROM repo_grants WHERE repo_id = ?")
1364 .bind(&[a.repo_id.as_str().into()])?,
1365 self.db
1366 .prepare("DELETE FROM repo_invitations WHERE repo_id = ?")
1367 .bind(&[a.repo_id.as_str().into()])?,
1368 ])
1369 .await?;
1370 Ok(true)
1371 }
1372
1373 /// A repository moved or was renamed: its grants and invitations follow
1374 /// it (deletion.rs, `transfer_repo_scopes`).
1375 pub(crate) async fn move_repo_access(&self, from: &RepoPath, to: &RepoPath) -> Result<()> {
1376 let (Some(from_id), Some(to_id)) = (
1377 self.workspace_id_of(&from.namespace).await?,
1378 self.workspace_id_of(&to.namespace).await?,
1379 ) else {
1380 return Ok(());
1381 };
1382 let binds = [
1383 JsValue::from(to_id.as_str()),
1384 to.name.to_lowercase().into(),
1385 from_id.as_str().into(),
1386 from.name.to_lowercase().into(),
1387 ];
1388 self.db
1389 .batch(vec![
1390 self.db
1391 .prepare("UPDATE repo_grants SET workspace_id = ?1, repo_name = ?2 WHERE workspace_id = ?3 AND repo_name = ?4")
1392 .bind(&binds)?,
1393 self.db
1394 .prepare("UPDATE repo_invitations SET workspace_id = ?1, repo_name = ?2 WHERE workspace_id = ?3 AND repo_name = ?4")
1395 .bind(&binds)?,
1396 ])
1397 .await?;
1398 Ok(())
1399 }
1400
1401 // --- Telling others ---
1402
1403 /// Publishes the change of a person's own role, and records it in the
1404 /// workspace's audit log.
1405 async fn changed(
1406 &self,
1407 actor: &User,
1408 repo: Named<'_>,
1409 username: &str,
1410 role: Option<RepoRole>,
1411 previous: Option<RepoRole>,
1412 surface: Surface,
1413 ) {
1414 let (kind, message) = match (previous, role) {
1415 (None, Some(role)) => ("repo.collaborator_added", format!("Gave {username} the {} role", role.label())),
1416 (Some(previous), Some(role)) => (
1417 "repo.collaborator_role_changed",
1418 format!("Changed {username}'s role from {} to {}", previous.label(), role.label()),
1419 ),
1420 (Some(previous), None) => ("repo.collaborator_removed", format!("Removed {username}'s {} role", previous.label())),
1421 (None, None) => return,
1422 };
1423 self.publish_repo(
1424 kind,
1425 repo.id,
1426 &actor.id,
1427 RepoCollaborator {
1428 repo_id: repo.id.to_owned(),
1429 namespace: repo.namespace.to_owned(),
1430 name: repo.name.to_owned(),
1431 username: username.to_owned(),
1432 role,
1433 previous_role: previous,
1434 },
1435 )
1436 .await;
1437 self.audit(actor, kind, repo, surface, message).await;
1438 }
1439
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1440 pub(crate) async fn publish_repo<T: Serialize>(&self, kind: &'static str, repo_id: &str, actor: &str, data: T) {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1441 let Ok(events) = self.env.service("EVENTS") else {
1442 return;
1443 };
1444 let publish = Publish {
1445 events: vec![NewEvent {
1446 kind,
1447 source: "identity",
1448 repo_id: Some(repo_id.to_owned()),
1449 actor: Some(actor.to_owned()),
1450 data,
1451 }],
1452 };
1453 if let Err(error) = g1t_kit::call::<_, serde_json::Value>(&events, "publish", &publish).await {
1454 worker::console_error!("{kind} not published: {error}");
1455 }
1456 }
1457
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1458 pub(crate) async fn audit(&self, actor: &User, action: &str, repo: Named<'_>, surface: Surface, message: String) {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1459 let full = format!("{}/{}", repo.namespace, repo.name);
1460 self.record(actor, action, repo.namespace, Some(full), surface, message).await;
1461 }
1462
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1463 pub(crate) async fn audit_workspace(&self, actor: &User, action: &str, slug: &str, surface: Surface, message: String) {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1464 self.record(actor, action, slug, None, surface, message).await;
1465 }
1466
1467 async fn record(&self, actor: &User, action: &str, workspace: &str, repo: Option<String>, surface: Surface, message: String) {
1468 let Ok(events) = self.env.service("EVENTS") else {
1469 return;
1470 };
1471 let entry = NewAuditEntry {
1472 actor: AuditActor::of(actor),
1473 action: action.to_owned(),
1474 surface,
1475 target: AuditTarget {
1476 workspace: workspace.to_lowercase(),
1477 repo,
1478 ..AuditTarget::default()
1479 },
1480 outcome: AuditOutcome::Allowed,
1481 rule: if actor.kind == PrincipalKind::User { "access" } else { "access:token" }.to_owned(),
1482 result: Some("ok".to_owned()),
1483 message: Some(message),
1484 request_id: new_id("req", now_ms()),
1485 };
1486 let recorded: Result<u32> =
1487 g1t_kit::call(&events, "audit_record", &RecordAuditArgs { entries: vec![entry] }).await;
1488 if let Err(error) = recorded {
1489 worker::console_error!("{action} not recorded: {error}");
1490 }
1491 }
1492}
1493
1494#[cfg(test)]
1495mod tests {
1496 use super::*;
1497
1498 #[test]
1499 fn people_are_added_by_username_or_address() {
1500 assert_eq!(invitee(" Ada "), Some(Invitee::Username("ada".into())));
1501 assert_eq!(invitee("@ada"), Some(Invitee::Username("ada".into())));
1502 assert_eq!(invitee("Ada@Example.com"), Some(Invitee::Email("ada@example.com".into())));
1503 assert_eq!(invitee("not a name"), None);
1504 assert_eq!(invitee("ada@"), None);
1505 }
1506
1507 #[test]
1508 fn a_role_comes_from_ownership_the_base_or_a_grant() {
1509 use AccessSource::*;
1510 use RepoRole::*;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1511 assert_eq!(effective(true, Some(Read), Some(Write), None), Some((Admin, Owner)));
1512 assert_eq!(effective(false, Some(Write), None, None), Some((Write, Base)));
1513 assert_eq!(effective(false, Some(Write), Some(Maintain), None), Some((Maintain, Direct)));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1514 // A grant as high as the base is shown as direct, where it can be changed.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1515 assert_eq!(effective(false, Some(Write), Some(Write), None), Some((Write, Direct)));
1516 assert_eq!(effective(false, Some(Admin), Some(Read), None), Some((Admin, Base)));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1517 // An outside collaborator.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1518 assert_eq!(effective(false, None, Some(Triage), None), Some((Triage, Direct)));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1519 // A member of a workspace whose base is none, with no grant.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1520 assert_eq!(effective(false, None, None, None), None);
1521 }
1522
1523 #[test]
1524 fn a_teams_role_counts_where_it_is_the_highest() {
1525 use AccessSource::*;
1526 use RepoRole::*;
1527 assert_eq!(effective(false, Some(Read), None, Some(Maintain)), Some((Maintain, Team)));
1528 assert_eq!(effective(false, None, None, Some(Triage)), Some((Triage, Team)));
1529 // Lower than the base: the base.
1530 assert_eq!(effective(false, Some(Write), None, Some(Read)), Some((Write, Base)));
1531 // As high as the base: shown as the team's, where it can be changed.
1532 assert_eq!(effective(false, Some(Write), None, Some(Write)), Some((Write, Team)));
1533 // A direct grant as high as the team's is shown as direct.
1534 assert_eq!(effective(false, Some(Read), Some(Admin), Some(Admin)), Some((Admin, Direct)));
1535 assert_eq!(effective(false, Some(Read), Some(Write), Some(Admin)), Some((Admin, Team)));
1536 // Owners are owners.
1537 assert_eq!(effective(true, None, None, Some(Write)), Some((Admin, Owner)));
1538 }
1539
1540 #[test]
1541 fn each_person_keeps_the_highest_role_any_team_gives() {
1542 let roles = highest_team_roles([
1543 ("usr_a".to_owned(), RepoRole::Read, "docs".to_owned()),
1544 ("usr_a".to_owned(), RepoRole::Maintain, "platform".to_owned()),
1545 ("usr_a".to_owned(), RepoRole::Write, "backend".to_owned()),
1546 ("usr_b".to_owned(), RepoRole::Write, "web".to_owned()),
1547 ("usr_b".to_owned(), RepoRole::Write, "api".to_owned()),
1548 ]);
1549 assert_eq!(roles["usr_a"], (RepoRole::Maintain, "platform".to_owned()));
1550 assert_eq!(roles["usr_b"], (RepoRole::Write, "api".to_owned()));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1551 }
1552
1553 #[test]
1554 fn an_invitation_is_pending_until_answered_revoked_or_expired() {
1555 let row = InvitationRow {
1556 expires_at: "2026-10-12T00:00:00.000Z".into(),
1557 ..InvitationRow::default()
1558 };
1559 let now = "2026-10-05T00:00:00.000Z";
1560 assert_eq!(invitation_status(&row, now), RepoInvitationStatus::Pending);
1561 assert_eq!(invitation_status(&row, "2026-10-12T00:00:00.000Z"), RepoInvitationStatus::Expired);
1562 let accepted = InvitationRow { accepted_at: Some(now.into()), ..row.clone() };
1563 assert_eq!(invitation_status(&accepted, now), RepoInvitationStatus::Accepted);
1564 let declined = InvitationRow { declined_at: Some(now.into()), ..row.clone() };
1565 assert_eq!(invitation_status(&declined, now), RepoInvitationStatus::Declined);
1566 let revoked = InvitationRow { revoked_at: Some(now.into()), ..row };
1567 assert_eq!(invitation_status(&revoked, now), RepoInvitationStatus::Revoked);
1568 }
1569
1570 #[test]
1571 fn invitations_show_addresses_only_to_those_who_manage_access() {
1572 let row = InvitationRow {
1573 id: "rin_1".into(),
1574 workspace: "acme".into(),
1575 repo_name: "rocket".into(),
1576 email: Some("ada@example.com".into()),
1577 role: "triage".into(),
1578 expires_at: "2099-01-01T00:00:00.000Z".into(),
1579 ..InvitationRow::default()
1580 };
1581 let now = "2026-10-05T00:00:00.000Z";
1582 assert_eq!(row.shown(now, true).email.as_deref(), Some("ada@example.com"));
1583 assert_eq!(row.shown(now, false).email, None);
1584 assert_eq!(row.shown(now, false).repo, "acme/rocket");
1585 assert_eq!(row.shown(now, false).role, RepoRole::Triage);
1586 }
1587}

This file's history is long; its oldest lines are credited to the oldest commit read.