Skip to content
1,547 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
RFC 3339 timestamps in identity and repos16 /// RFC 3339.
17 pub created_at: String,
API and MCP server, Rust identity service, registration, site redesign18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
RFC 3339 timestamps in identity and repos25 /// RFC 3339.
26 pub created_at: String,
Agents as a team: lifecycle, merge queue, billing and a new shell27 /// RFC 3339, to within a few minutes. Null until it is first used.
28 pub last_used_at: Option<String>,
29 /// For a workspace's token, the username of the member who made it.
30 /// Null once that account is gone, and on personal tokens.
31 pub created_by: Option<String>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step32 /// Its scopes, as `resource:level`. Null: full access.
33 #[serde(default)]
34 pub scopes: Option<Vec<String>>,
35 /// Made before tokens had scopes: full access until someone narrows it.
36 #[serde(default)]
37 pub legacy: bool,
38 /// RFC 3339. Null: it does not expire.
39 #[serde(default)]
40 pub expires_at: Option<String>,
API and MCP server, Rust identity service, registration, site redesign41}
42
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look43/// `sign_in`: verifies a username, or any confirmed email address of the
44/// account, and its password, for website sign-in. Wrong passwords are
45/// counted against the account and `client`, and past a limit nothing is
46/// checked for a while (see identity's `throttle.rs`).
API and MCP server, Rust identity service, registration, site redesign47/// Returns `Outcome<SignedIn>`.
48#[derive(Debug, Serialize, Deserialize)]
49pub struct SignInArgs {
50 pub username: String,
51 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look52 /// Who is asking, such as the visitor's IP address, for rate limits.
53 #[serde(default)]
54 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign55}
56
57#[derive(Debug, Serialize, Deserialize)]
58#[serde(rename_all = "camelCase")]
59pub struct SignedIn {
60 pub user: User,
Membership as GitHub has it: owners, roles, member privileges, 2FA61 /// Empty while `two_factor_challenge` is set: no session is made until
62 /// the code is given.
API and MCP server, Rust identity service, registration, site redesign63 pub session_token: String,
Membership as GitHub has it: owners, roles, member privileges, 2FA64 /// Set when the account has two-factor authentication on: the token to
65 /// pass to `two_factor_sign_in` with a code. Valid for
66 /// `accounts::TWO_FACTOR_CHALLENGE_SECONDS`.
67 #[serde(default, skip_serializing_if = "Option::is_none")]
68 pub two_factor_challenge: Option<String>,
API and MCP server, Rust identity service, registration, site redesign69}
70
71/// `sign_out` and `user_for_session`.
72#[derive(Debug, Serialize, Deserialize)]
73#[serde(rename_all = "camelCase")]
74pub struct SessionArgs {
75 pub session_token: String,
76}
77
78/// `user_for_git_credentials`: the account password or an access token.
79#[derive(Debug, Serialize, Deserialize)]
80pub struct GitCredentialsArgs {
81 pub username: String,
82 pub secret: String,
83}
84
85/// `user_for_access_token`.
86#[derive(Debug, Serialize, Deserialize)]
87pub struct TokenArgs {
88 pub token: String,
89}
90
91/// `user_for_ssh_key`.
92#[derive(Debug, Serialize, Deserialize)]
93pub struct FingerprintArgs {
94 pub fingerprint: String,
95}
96
97/// `user_by_username`.
98#[derive(Debug, Serialize, Deserialize)]
99pub struct UsernameArgs {
100 pub username: String,
101}
102
What happened across an outcome, as a feed beside its graph103/// `usernames`: the names behind account and workspace ids, as events and
104/// other records store them. Returns a map from id to name; ids it does
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97105/// not know are left out. Also `accounts`: the accounts behind user ids,
106/// each with its username and avatar (`HashMap<String, accounts::EmailOwner>`).
What happened across an outcome, as a feed beside its graph107#[derive(Debug, Serialize, Deserialize)]
108pub struct UsernamesArgs {
109 pub ids: Vec<String>,
110}
111
API and MCP server, Rust identity service, registration, site redesign112/// `list_ssh_keys` and `list_access_tokens`.
113#[derive(Debug, Serialize, Deserialize)]
114pub struct UserArgs {
115 pub user: User,
116}
117
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge118/// `ssh_key_owners`: services only. The account (user id) that registered
119/// each key, by fingerprint (`SHA256:…`, as `ssh-keygen -lf` prints it),
120/// for verifying commits signed with SSH keys. Returns a map of the
121/// fingerprints found to user ids.
122#[derive(Debug, Serialize, Deserialize)]
123pub struct SshKeyOwnersArgs {
124 pub fingerprints: Vec<String>,
125}
126
API and MCP server, Rust identity service, registration, site redesign127/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
128/// Returns `Outcome<SshKey>`.
129#[derive(Debug, Serialize, Deserialize)]
130#[serde(rename_all = "camelCase")]
131pub struct AddSshKeyArgs {
132 pub user: User,
133 pub title: String,
134 pub public_key: String,
135}
136
137/// `remove_ssh_key` and `remove_access_token`.
138#[derive(Debug, Serialize, Deserialize)]
139pub struct RemoveArgs {
140 pub user: User,
141 pub id: String,
142}
143
Agents as a team: lifecycle, merge queue, billing and a new shell144/// `create_access_token`: a token that acts as `user`. For a workspace
145/// acting through a token of its own, the new token belongs to that
146/// workspace too.
API and MCP server, Rust identity service, registration, site redesign147#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)148#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign149pub struct CreateAccessTokenArgs {
150 pub user: User,
151 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)152 /// When set, the token stops working after this many seconds and is
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step153 /// left out of the user's token list, unless `listed`. Used for hosted
154 /// attempts.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)155 #[serde(default)]
156 pub ttl_seconds: Option<u64>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step157 /// Its scopes, as `resource:level`; unknown names are left out. Null:
158 /// full access.
159 #[serde(default)]
160 pub scopes: Option<Vec<String>>,
161 /// Listed with the person's tokens although it expires: one they made
162 /// themselves, with an expiry.
163 #[serde(default)]
164 pub listed: bool,
165}
166
167/// `update_access_token`: changes what one of a person's tokens may do.
168/// The token itself is unchanged. Returns `Outcome<AccessToken>`.
169#[derive(Debug, Serialize, Deserialize)]
170pub struct UpdateAccessTokenArgs {
171 pub user: User,
172 pub id: String,
173 /// Null: full access.
174 #[serde(default)]
175 pub scopes: Option<Vec<String>>,
API and MCP server, Rust identity service, registration, site redesign176}
177
178/// The plaintext token is returned once and never stored.
179#[derive(Debug, Serialize, Deserialize)]
180pub struct CreatedAccessToken {
181 pub token: String,
182 pub info: AccessToken,
183}
184
185/// `register`: creates an account and signs it in.
186/// Returns `Outcome<SignedIn>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look187///
188/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
189/// new account needs `invite_code`: an unused, unexpired invite, and, when
190/// the invite names an email, that address. See [`CreateInviteArgs`].
API and MCP server, Rust identity service, registration, site redesign191#[derive(Debug, Serialize, Deserialize)]
192pub struct RegisterArgs {
193 pub username: String,
194 pub email: String,
195 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look196 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
197 /// registration is open.
198 #[serde(default)]
199 pub invite_code: Option<String>,
200 /// Who is asking, such as the visitor's IP address, for rate limits.
201 #[serde(default)]
202 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign203}
Email verification, password reset, and Git for AI scale positioning204
205/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
206#[derive(Debug, Serialize, Deserialize)]
207pub struct EmailTokenArgs {
208 pub token: String,
209}
210
211/// `request_password_reset`. Always succeeds, so it cannot be used to find
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look212/// out which addresses have accounts. Any confirmed address of an account
213/// works: the link goes to the address given, and the primary (and the
214/// backup) are told a reset was asked for. A few requests an hour per
215/// address and per `client`; past that, nothing is sent.
Email verification, password reset, and Git for AI scale positioning216#[derive(Debug, Serialize, Deserialize)]
217pub struct EmailArgs {
218 pub email: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look219 /// Who is asking, such as the visitor's IP address, for rate limits.
220 #[serde(default)]
221 pub client: Option<String>,
Email verification, password reset, and Git for AI scale positioning222}
223
224/// `reset_password`: sets a new password and ends every session.
225/// Returns `Outcome<User>`.
226#[derive(Debug, Serialize, Deserialize)]
227pub struct ResetPasswordArgs {
228 pub token: String,
229 pub password: String,
230}
Device sign-in replaces registering and minting tokens over the API231
232/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
233#[derive(Debug, Serialize, Deserialize)]
234#[serde(rename_all = "camelCase")]
235pub struct DeviceStartArgs {
236 /// What is asking, shown to the person approving, e.g. "Claude Code".
237 pub client_name: String,
238}
239
240#[derive(Debug, Serialize, Deserialize)]
241#[serde(rename_all = "camelCase")]
242pub struct DeviceStart {
243 /// Secret held by the tool and exchanged for a token once approved.
244 pub device_code: String,
245 /// Short code shown to the person, e.g. `WDJB-MJHT`.
246 pub user_code: String,
247 /// Seconds until both codes stop working.
248 pub expires_in: u32,
249 /// Seconds the tool should wait between polls.
250 pub interval: u32,
251}
252
253/// `device_lookup`: what a user code is asking for, or null if it is not
254/// valid. Returns `Option<DeviceRequest>`.
255#[derive(Debug, Serialize, Deserialize)]
256#[serde(rename_all = "camelCase")]
257pub struct DeviceLookupArgs {
258 pub user_code: String,
259}
260
261#[derive(Debug, Serialize, Deserialize)]
262#[serde(rename_all = "camelCase")]
263pub struct DeviceRequest {
264 pub user_code: String,
265 pub client_name: String,
266}
267
268/// `device_resolve`: the signed-in person approves or denies a request.
269/// Returns `Outcome<bool>`.
270#[derive(Debug, Serialize, Deserialize)]
271#[serde(rename_all = "camelCase")]
272pub struct DeviceResolveArgs {
273 pub user_code: String,
274 pub user: User,
275 pub approve: bool,
276}
277
278/// `device_claim`: the tool asks whether its request was approved.
279#[derive(Debug, Serialize, Deserialize)]
280#[serde(rename_all = "camelCase")]
281pub struct DeviceClaimArgs {
282 pub device_code: String,
283}
284
285/// The answer to a `device_claim`.
286#[derive(Debug, Serialize, Deserialize)]
287#[serde(tag = "status", rename_all = "snake_case")]
288pub enum DeviceClaim {
289 /// Nobody has approved or denied it yet; ask again after the interval.
290 Pending,
291 Denied,
292 /// The code was never issued, has expired, or was already used.
293 Expired,
294 /// The access token, returned once.
295 Approved {
296 token: String,
297 user: User,
298 },
299}
Workspaces own repositories300
301/// A workspace: the owner of repositories, and the first segment of their
302/// URLs. A person's own space and a team's are the same thing.
303#[derive(Clone, Debug, Serialize, Deserialize)]
304#[serde(rename_all = "camelCase")]
305pub struct Workspace {
306 pub id: String,
307 pub slug: String,
308 pub name: String,
Agents as a team: lifecycle, merge queue, billing and a new shell309 /// One line saying what the workspace is for.
310 pub description: Option<String>,
Workspaces own repositories311 /// RFC 3339.
312 pub created_at: String,
313 pub member_count: u32,
Workspace names and icons, and a component kit for every control314 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
315 /// `/avatars/<avatar>`. Null means the generated letter avatar.
316 #[serde(default)]
317 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look318 /// What every member gets on each of its repositories; owners have
319 /// Admin. See [`crate::access`].
320 #[serde(default)]
321 pub base_permission: crate::access::BasePermission,
Merge branch 'worktree-agent-ad7c6d88d93adc817'322 /// Who may create its teams. See [`crate::teams::TeamCreation`].
323 #[serde(default)]
324 pub team_creation: crate::teams::TeamCreation,
Membership as GitHub has it: owners, roles, member privileges, 2FA325 /// What members may do, by GitHub's names for each
326 /// (`members_can_create_public_repositories`...), at the top level as
327 /// GitHub's organization has them. See [`crate::MemberPrivileges`].
328 #[serde(flatten)]
329 pub privileges: crate::MemberPrivileges,
330 /// Whether members and outside collaborators need two-factor
331 /// authentication to use it.
332 #[serde(default)]
333 pub two_factor_requirement_enabled: bool,
Workspaces own repositories334}
335
336#[derive(Clone, Debug, Serialize, Deserialize)]
337pub struct Member {
338 pub username: String,
339 pub role: crate::Role,
Membership as GitHub has it: owners, roles, member privileges, 2FA340 /// The roles they hold besides `role`.
341 #[serde(default)]
342 pub org_roles: Vec<crate::OrgRole>,
343 /// Whether they have two-factor authentication on. Shown to owners
344 /// only; null for anyone else.
345 #[serde(default)]
346 pub two_factor: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look347 /// Their display name, when they set one.
348 #[serde(default)]
349 pub name: Option<String>,
350 /// Their uploaded avatar: the SHA-256 of its bytes, served at
351 /// `/avatars/<avatar>`. None means the generated letter avatar.
352 #[serde(default)]
353 pub avatar: Option<String>,
Workspaces own repositories354}
355
Merge branch 'worktree-agent-a2013627e5ea4ab13'356/// Where a workspace keeps its repositories' git data: anywhere g1t
357/// stores it (the default), or in the EU only. It applies to repositories
358/// made after it is set; the repos service reads it when it places a new
359/// one (`storage_options` says whether the EU can be chosen).
360#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
361#[serde(rename_all = "lowercase")]
362pub enum DataResidency {
363 #[default]
364 Anywhere,
365 Eu,
366}
367
368impl DataResidency {
369 pub fn as_str(self) -> &'static str {
370 match self {
371 DataResidency::Anywhere => "anywhere",
372 DataResidency::Eu => "eu",
373 }
374 }
375
376 pub fn parse(text: &str) -> Option<Self> {
377 match text.trim().to_ascii_lowercase().as_str() {
378 "anywhere" => Some(DataResidency::Anywhere),
379 "eu" => Some(DataResidency::Eu),
380 _ => None,
381 }
382 }
383}
384
385/// `workspace_residency` takes [`SlugArgs`] and returns
386/// `Option<DataResidency>` (null when there is no such workspace).
387/// `set_workspace_residency`: owners only. Returns `Outcome<DataResidency>`.
388#[derive(Debug, Serialize, Deserialize)]
389pub struct SetResidencyArgs {
390 pub actor: User,
391 pub slug: String,
392 pub residency: DataResidency,
393}
394
Workspaces own repositories395/// `create_workspace`. Returns `Outcome<Workspace>`.
396#[derive(Debug, Serialize, Deserialize)]
397pub struct CreateWorkspaceArgs {
398 pub user: User,
399 pub slug: String,
400 #[serde(default)]
401 pub name: String,
402}
403
404/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
405#[derive(Debug, Serialize, Deserialize)]
406pub struct SlugArgs {
407 pub slug: String,
408}
409
Membership as GitHub has it: owners, roles, member privileges, 2FA410/// `list_members`: members only. Owners also see each member's
411/// `two_factor`. Returns `Outcome<Vec<Member>>`.
Workspaces own repositories412#[derive(Debug, Serialize, Deserialize)]
413pub struct ListMembersArgs {
414 pub slug: String,
415 pub viewer: crate::Viewer,
416}
417
Membership as GitHub has it: owners, roles, member privileges, 2FA418/// `add_member` and `remove_member`: owners only. Removing yourself is
419/// leaving (`members::LeaveWorkspaceArgs`); removing an owner is refused
420/// when they are the last. Each returns `Outcome<bool>`.
Workspaces own repositories421#[derive(Debug, Serialize, Deserialize)]
422pub struct MemberArgs {
423 pub actor: User,
424 pub slug: String,
425 pub username: String,
Membership as GitHub has it: owners, roles, member privileges, 2FA426 #[serde(default)]
427 pub surface: Option<crate::audit::Surface>,
Workspaces own repositories428}
OAuth 2.1 sign-in for MCP clients and other applications429
Agents as a team: lifecycle, merge queue, billing and a new shell430/// `update_workspace`: owners only. An empty name falls back to the slug;
431/// an empty description clears it. Returns `Outcome<Workspace>`.
432#[derive(Debug, Serialize, Deserialize)]
433pub struct UpdateWorkspaceArgs {
434 pub actor: User,
435 pub slug: String,
436 pub name: String,
437 pub description: String,
438}
439
Agents and memory, checks and conflicts, profiles, slug renames, custom domains440/// `rename_workspace`: owners only. Changes the workspace's slug, the first
441/// segment of its URLs, to `new_slug`; the display name is untouched. The
442/// old slug redirects to the new one, and is held for this workspace, for
443/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
444/// `Outcome<Workspace>`.
445///
446/// `check_workspace_rename` takes the same arguments and answers whether
447/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
448#[derive(Debug, Serialize, Deserialize)]
449#[serde(rename_all = "camelCase")]
450pub struct RenameWorkspaceArgs {
451 pub actor: User,
452 pub slug: String,
453 pub new_slug: String,
454}
455
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look456/// `delete_workspace`: owners only, and only a person. `confirm` must be
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member457/// the workspace's slug, typed out. Refused for a protected workspace
458/// ([`protected_names`]), whoever asks, and while billing cannot settle it
459/// (`close_workspace`). Everything in it goes with it at once: nobody can
460/// reach it, its tokens stop working, its pages are not found, and its
461/// repositories, projects and apps are deleted with it. It is kept for
462/// [`WORKSPACE_RESTORE_DAYS`] so g1t's staff can restore it, then purged:
463/// its memberships, access tokens and old-slug redirects go, and billing's
464/// ledger and the audit log keep its history. The slug is never given to
465/// another workspace; the person whose username it is may make a workspace
466/// of that name again once it is purged. Publishes `workspace.deleting`,
467/// and `workspace.deleted` at the purge. Returns `Outcome<bool>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look468///
469/// `check_workspace_deletion` takes the same arguments (with `confirm`
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member470/// ignored) and says what would go and whether anything stands in the way,
471/// changing nothing. Returns `Outcome<WorkspaceDeletion>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look472#[derive(Debug, Serialize, Deserialize)]
473pub struct DeleteWorkspaceArgs {
474 pub actor: User,
475 pub slug: String,
476 #[serde(default)]
477 pub confirm: String,
478 /// Where the request came in, for the audit log; g1t.sh when absent.
479 #[serde(default)]
480 pub surface: Option<crate::audit::Surface>,
481}
482
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member483/// What deleting a workspace takes with it, and what stands in the way.
484/// Nothing does when `billing` is null and it is not `protected`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look485#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
486pub struct WorkspaceDeletion {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member487 /// Its live repositories, which are deleted with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look488 pub repositories: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member489 /// Its projects, hidden with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look490 pub projects: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member491 #[serde(default)]
492 pub members: u32,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look493 /// Why billing cannot close the workspace yet, in words for its owner.
494 pub billing: Option<String>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member495 /// It can never be deleted, by anyone ([`protected_names`]).
496 #[serde(default)]
497 pub protected: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look498}
499
500impl WorkspaceDeletion {
501 pub fn blocked(&self) -> bool {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member502 self.protected || self.billing.is_some()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look503 }
504
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member505 /// Why the workspace cannot be deleted, as one sentence, or `None`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look506 pub fn reason(&self, slug: &str) -> Option<String> {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member507 if self.protected {
508 return Some(protected_refusal(slug));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look509 }
510 self.billing.clone()
511 }
512}
513
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member514/// How long a deleted workspace is kept, for staff to restore, before it is
515/// purged.
516pub const WORKSPACE_RESTORE_DAYS: u64 = 30;
517
518/// Workspaces nobody can delete, whatever identity's `PROTECTED_WORKSPACES`
519/// says: Flagon's, which runs g1t.
520pub const ALWAYS_PROTECTED: &[&str] = &["flagon-io"];
521
522/// The protected workspaces: `configured` (comma-separated slugs or
523/// workspace ids, as identity's `PROTECTED_WORKSPACES` holds them), and
524/// [`ALWAYS_PROTECTED`] whatever it says, so an empty or missing variable
525/// still protects them. Lowercased, without duplicates.
526pub fn protected_names(configured: Option<&str>) -> Vec<String> {
527 let mut names: Vec<String> = Vec::new();
528 let given = configured.unwrap_or_default().split(',');
529 for name in ALWAYS_PROTECTED.iter().copied().chain(given) {
530 let name = name.trim().to_lowercase();
531 if !name.is_empty() && !names.contains(&name) {
532 names.push(name);
533 }
534 }
535 names
536}
537
538/// Why a protected workspace is not deleted, purged or acted on.
539pub fn protected_refusal(slug: &str) -> String {
540 format!("{slug} is protected and can never be deleted.")
541}
542
543/// `admin_deleted_workspaces` takes no arguments (`{}`) and returns
544/// `Vec<DeletedWorkspace>`, newest first. Staff only.
545///
546/// A workspace an owner deleted, kept until `purge_after` for staff to
547/// restore.
548#[derive(Clone, Debug, Serialize, Deserialize)]
549#[serde(rename_all = "camelCase")]
550pub struct DeletedWorkspace {
551 pub workspace_id: String,
552 pub slug: String,
553 pub name: String,
554 /// RFC 3339.
555 pub deleted_at: String,
556 /// The username of the owner who deleted it.
557 pub deleted_by: String,
558 /// RFC 3339: when it is purged unless restored first.
559 pub purge_after: String,
560 /// What went with it, counted when it was deleted.
561 pub went: WorkspaceDeletion,
562 /// Whether staff can still restore it.
563 pub restorable: bool,
564}
565
566/// `admin_restore_workspace` and `admin_purge_workspace`: staff restore a
567/// deleted workspace within [`WORKSPACE_RESTORE_DAYS`], or purge it now.
568/// `staff` is who, for the audit logs. Purging needs `confirm`, the slug
569/// typed out, and is refused for a protected workspace. Restoring publishes
570/// `workspace.restored`; purging, `workspace.deleted`. Both return
571/// `Outcome<bool>`.
572#[derive(Debug, Serialize, Deserialize)]
573#[serde(rename_all = "camelCase")]
574pub struct AdminDeletedWorkspaceArgs {
575 pub workspace_id: String,
576 pub staff: String,
577 #[serde(default)]
578 pub confirm: String,
579}
580
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look581/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
582/// tokens of agents at work on it are kept pointing at it. For repos'
583/// `transfer`. Returns `bool`.
584#[derive(Debug, Serialize, Deserialize)]
585pub struct TransferRepoScopesArgs {
586 pub from: crate::repos::RepoPath,
587 pub to: crate::repos::RepoPath,
588}
589
Agents and memory, checks and conflicts, profiles, slug renames, custom domains590/// How long a workspace's old slug keeps redirecting to it, and stays
591/// reserved for it, after a rename.
592pub const SLUG_HOLD_DAYS: u64 = 90;
593
594/// How long a workspace must wait between renames.
595pub const RENAME_COOLDOWN_HOURS: u64 = 24;
596
597// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
598// workspace's current slug when `slug` is one it was renamed from within
599// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
Merge branch 'worktree-agent-a8385d293d42c913a'600// is in use), or the workspace's slug when `slug` is one of its aliases.
601
602// `resolve_alias` takes `SlugArgs` and returns `Option<String>`: the slug
603// now of the workspace `slug` is an alias of, and null when it is none.
604// Aliases are set by g1t's staff only: `g1t` is Flagon, Inc.'s `flagon-io`.
605// An alias follows its workspace through renames.
606
607/// `admin_aliases` takes no arguments (`{}`) and returns
608/// `Vec<WorkspaceAlias>`, by alias. Staff only.
609///
610/// A name staff point at a workspace, so that its addresses (pages, git,
611/// the API, packages) lead to the workspace under its own name.
612#[derive(Clone, Debug, Serialize, Deserialize)]
613#[serde(rename_all = "camelCase")]
614pub struct WorkspaceAlias {
615 pub alias: String,
616 pub workspace_id: String,
617 /// The workspace's slug and name now.
618 pub workspace: String,
619 pub workspace_name: String,
620 /// Why it exists, as staff wrote it.
621 pub note: String,
622 /// The staff member who set it, or `migration`.
623 pub created_by: String,
624 /// RFC 3339.
625 pub created_at: String,
626}
627
628/// `admin_set_alias`: points `alias` at the workspace whose slug is
629/// `workspace`. The alias must have a namespace's shape, must not be one of
630/// the site's routes, and must not be anyone's username, a workspace's slug
631/// (deleted, or held after a rename) or another alias. `note` is required:
632/// it is the reason, kept with the alias and in sudo's audit log. Staff
633/// only. Returns `Outcome<WorkspaceAlias>`.
634#[derive(Debug, Serialize, Deserialize)]
635#[serde(rename_all = "camelCase")]
636pub struct AdminSetAliasArgs {
637 pub alias: String,
638 pub workspace: String,
639 pub note: String,
640 pub staff: String,
641}
642
643/// `admin_remove_alias`: the alias stops leading anywhere, and the name is
644/// nobody's again unless it is reserved. `reason` goes in sudo's audit log.
645/// Staff only. Returns `Outcome<bool>`.
646#[derive(Debug, Serialize, Deserialize)]
647#[serde(rename_all = "camelCase")]
648pub struct AdminRemoveAliasArgs {
649 pub alias: String,
650 pub reason: String,
651 pub staff: String,
652}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains653
Workspace names and icons, and a component kit for every control654/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
655/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
656/// the icon. Returns `Outcome<Workspace>`.
657#[derive(Debug, Serialize, Deserialize)]
658pub struct SetWorkspaceAvatarArgs {
659 pub actor: User,
660 pub slug: String,
661 pub image: Option<String>,
662}
663
664/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
665/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
666#[derive(Debug, Serialize, Deserialize)]
667pub struct SetUserAvatarArgs {
668 pub user: User,
669 pub image: Option<String>,
670}
671
672/// The largest avatar that can be uploaded, in bytes.
673pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
674
Agents as a team: lifecycle, merge queue, billing and a new shell675/// `list_workspace_tokens`: members only. Returns
676/// `Outcome<Vec<AccessToken>>`.
677#[derive(Debug, Serialize, Deserialize)]
678pub struct WorkspaceTokensArgs {
679 pub slug: String,
680 pub viewer: crate::Viewer,
681}
682
683/// `create_workspace_token`: owners only. The token belongs to the
684/// workspace, acts as it, and keeps working when the member who made it
685/// leaves. Returns `Outcome<CreatedAccessToken>`.
686#[derive(Debug, Serialize, Deserialize)]
687pub struct CreateWorkspaceTokenArgs {
688 pub actor: User,
689 pub slug: String,
690 pub name: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step691 /// Its scopes; null for full access.
692 #[serde(default)]
693 pub scopes: Option<Vec<String>>,
694 /// When set, the token stops working after this many seconds. It is
695 /// listed with the workspace's tokens either way. Null: no expiry.
696 #[serde(default)]
697 pub ttl_seconds: Option<u64>,
Agents as a team: lifecycle, merge queue, billing and a new shell698}
699
700/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
701#[derive(Debug, Serialize, Deserialize)]
702pub struct RemoveWorkspaceTokenArgs {
703 pub actor: User,
704 pub slug: String,
705 pub id: String,
706}
707
OAuth 2.1 sign-in for MCP clients and other applications708/// `oauth_authorize`: the signed-in person approved an application. The
709/// caller has checked the client and that it may be redirected to
710/// `redirect_uri`. Returns `OAuthCode`.
711#[derive(Debug, Serialize, Deserialize)]
712#[serde(rename_all = "camelCase")]
713pub struct OAuthAuthorizeArgs {
714 pub user: User,
715 pub client_id: String,
716 /// Shown wherever the application's access is listed.
717 pub client_name: String,
718 pub redirect_uri: String,
719 /// PKCE challenge, method S256.
720 pub code_challenge: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step721 /// What the person granted, as `resource:level`. Null: full access.
722 #[serde(default)]
723 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications724}
725
726#[derive(Debug, Serialize, Deserialize)]
727pub struct OAuthCode {
728 pub code: String,
729}
730
731/// `oauth_exchange`: redeems an authorization code.
732/// Returns `Outcome<OAuthTokens>`.
733#[derive(Debug, Serialize, Deserialize)]
734#[serde(rename_all = "camelCase")]
735pub struct OAuthExchangeArgs {
736 pub code: String,
737 pub code_verifier: String,
738 pub client_id: String,
739 pub redirect_uri: String,
740}
741
742/// `oauth_refresh`: trades a refresh token for new tokens.
743/// Returns `Outcome<OAuthTokens>`.
744#[derive(Debug, Serialize, Deserialize)]
745#[serde(rename_all = "camelCase")]
746pub struct OAuthRefreshArgs {
747 pub refresh_token: String,
748 pub client_id: String,
749}
750
751#[derive(Debug, Serialize, Deserialize)]
752#[serde(rename_all = "camelCase")]
753pub struct OAuthTokens {
754 pub access_token: String,
755 /// Works once; using it returns the next one.
756 pub refresh_token: String,
757 /// Seconds until the access token stops working.
758 pub expires_in: u64,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step759 /// The scopes granted, space-separated, or `*` for full access.
760 #[serde(default)]
761 pub scope: Option<String>,
OAuth 2.1 sign-in for MCP clients and other applications762}
763
764/// An application a person has signed in to. Listed by `list_oauth_grants`
765/// and ended by `revoke_oauth_grant`.
766#[derive(Debug, Serialize, Deserialize)]
767#[serde(rename_all = "camelCase")]
768pub struct OAuthGrant {
769 pub id: String,
770 pub client_name: String,
771 /// RFC 3339.
772 pub created_at: String,
773 /// RFC 3339.
774 pub last_used_at: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step775 /// What the person granted. Null: full access.
776 #[serde(default)]
777 pub scopes: Option<Vec<String>>,
778 /// Signed in before applications were given scopes: full access until
779 /// someone narrows it.
780 #[serde(default)]
781 pub legacy: bool,
782}
783
784/// `update_oauth_grant`: changes what an application the person signed in
785/// to may do, at once and when it refreshes. Returns `Outcome<OAuthGrant>`.
786#[derive(Debug, Serialize, Deserialize)]
787pub struct UpdateOAuthGrantArgs {
788 pub user: User,
789 pub id: String,
790 #[serde(default)]
791 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications792}
Agents as a team: lifecycle, merge queue, billing and a new shell793
794
795/// What an agent's token may do: these operations, in this repository.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API796#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
Agents as a team: lifecycle, merge queue, billing and a new shell797pub struct AgentScope {
798 pub repo: crate::repos::RepoPath,
799 /// API and MCP operation names, such as `create_issue`.
800 pub operations: Vec<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API801 /// Set on a run credential: the run it belongs to, and what it may do
802 /// with git. See [`crate::credentials`].
803 #[serde(default, skip_serializing_if = "Option::is_none")]
804 pub run: Option<crate::credentials::RunBinding>,
Agents as a team: lifecycle, merge queue, billing and a new shell805}
806
807/// `create_agent_token`: a token for a g1t agent working on someone's
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent808/// behalf. It acts as `g1t`, a member of the repository's workspace,
Agents as a team: lifecycle, merge queue, billing and a new shell809/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
810#[derive(Debug, Serialize, Deserialize)]
811#[serde(rename_all = "camelCase")]
812pub struct CreateAgentTokenArgs {
813 /// The person the agent works for; the token is recorded as theirs.
814 pub on_behalf_of: User,
815 pub scope: AgentScope,
816 pub ttl_seconds: u64,
817}
818
819// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
820// agent's token may do, or null for any other token.
821
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent822/// The id g1t's agent acts under. Only ever stored, never shown: it keeps
823/// the agent's work apart from g1t's own ([`crate::system::ID`]) where
824/// that matters, such as whether its approval counts.
Agents as a team: lifecycle, merge queue, billing and a new shell825pub const AGENT_ID: &str = "usr_g1t_agent";
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent826/// The name g1t's agent is shown by: g1t's own, [`crate::system::USERNAME`].
827/// Everything it does, people see g1t do.
828pub const AGENT_NAME: &str = crate::system::USERNAME;
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace829
830// --- Staff ---------------------------------------------------------------
831//
832// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
833// membership: only sudo calls them, over its service binding, after it has
834// verified a Cloudflare Access sign-in and its staff list. Nothing a
835// customer can reach should ever forward to them.
836
837/// `notify_owners`: emails a short notice, with one link, to each owner of
838/// a workspace with a confirmed address. Called by other services (billing
839/// warns owners near their usage limit), never on a person's behalf.
840/// Returns how many were sent.
841#[derive(Clone, Debug, Serialize, Deserialize)]
842pub struct NotifyOwnersArgs {
843 pub workspace: String,
844 pub subject: String,
845 /// One or two sentences: what happened and what it means.
846 pub intro: String,
847 /// The button's words, such as `Open billing`.
848 pub action: String,
849 /// Where the button goes; must be on g1t.sh.
850 pub link: String,
851 /// Small print: why they got it.
852 pub footer: String,
853}
854
855/// `admin_workspaces`: every workspace, newest first, at most
856/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
857/// an owner's username or email contains `query`. Returns
858/// `Vec<AdminWorkspace>`. Staff only.
859#[derive(Debug, Default, Serialize, Deserialize)]
860pub struct AdminWorkspacesArgs {
861 #[serde(default)]
862 pub query: Option<String>,
863}
864
865/// The most workspaces one `admin_workspaces` call returns.
866pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
867
868/// An owner of a workspace, as staff see them.
869#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
870pub struct AdminOwner {
871 pub username: String,
872 pub email: Option<String>,
873}
874
875/// A workspace as staff see it: who owns it and how many belong to it.
876#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
877#[serde(rename_all = "camelCase")]
878pub struct AdminWorkspace {
879 pub slug: String,
880 pub name: String,
881 /// RFC 3339.
882 pub created_at: String,
883 pub owners: Vec<AdminOwner>,
884 pub member_count: u32,
885}
886
887/// `admin_workspace`: one workspace with every member, or null. Takes
888/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
889#[derive(Clone, Debug, Serialize, Deserialize)]
890#[serde(rename_all = "camelCase")]
891pub struct AdminWorkspaceDetail {
892 pub slug: String,
893 pub name: String,
894 pub description: Option<String>,
895 /// RFC 3339.
896 pub created_at: String,
897 /// Owners first, then by username.
898 pub members: Vec<AdminMember>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member899 /// It can never be deleted ([`protected_names`]).
900 #[serde(default)]
901 pub protected: bool,
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace902}
903
904/// A member of a workspace, as staff see them.
905#[derive(Clone, Debug, Serialize, Deserialize)]
906pub struct AdminMember {
907 pub username: String,
908 pub email: Option<String>,
909 pub role: crate::Role,
910 /// When they joined the workspace. RFC 3339.
911 pub joined: String,
912}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains913
914// --- Profiles ------------------------------------------------------------
915//
916// A person's public page at `g1t.sh/u/<username>`. Everything in a
917// `Profile` is shown to anyone, signed in or not; an email address never is.
918
919/// The most characters each profile field takes.
920pub const MAX_PROFILE_NAME: usize = 80;
921pub const MAX_PROFILE_BIO: usize = 160;
922pub const MAX_PROFILE_LOCATION: usize = 80;
923pub const MAX_PROFILE_WEBSITE: usize = 200;
924pub const MAX_PROFILE_PRONOUNS: usize = 40;
925
926/// What anyone may see about a person.
927#[derive(Clone, Debug, Default, Serialize, Deserialize)]
928#[serde(rename_all = "camelCase")]
929pub struct Profile {
930 pub username: String,
931 /// The name they go by, if they gave one.
932 pub name: Option<String>,
933 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
934 pub bio: Option<String>,
935 pub location: Option<String>,
936 /// An `https://` address.
937 pub website: Option<String>,
938 pub pronouns: Option<String>,
939 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
940 pub avatar: Option<String>,
941 /// When the account was made. RFC 3339.
942 pub created_at: String,
943}
944
945// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
946// an account that does not exist.
947
948/// `update_profile`: a person changes their own profile. Every field is
949/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
950#[derive(Debug, Default, Serialize, Deserialize)]
951#[serde(rename_all = "camelCase")]
952pub struct UpdateProfileArgs {
953 pub actor: User,
954 #[serde(default)]
955 pub name: String,
956 #[serde(default)]
957 pub bio: String,
958 #[serde(default)]
959 pub location: String,
960 #[serde(default)]
961 pub website: String,
962 #[serde(default)]
963 pub pronouns: String,
964}
965
966/// `profile_workspaces`: the workspaces shown on a person's profile, as
967/// `viewer` may see them. A membership is shown only when it is no secret
968/// from the viewer: a workspace the viewer belongs to as well, or one of
969/// `public`, the workspaces the caller found the person has made a public
970/// project in (whose page shows that already). Returns
971/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
972#[derive(Debug, Serialize, Deserialize)]
973pub struct ProfileWorkspacesArgs {
974 pub username: String,
975 pub viewer: crate::Viewer,
976 #[serde(default)]
977 pub public: Vec<String>,
978}
979
980/// A workspace on a person's profile.
981#[derive(Clone, Debug, Serialize, Deserialize)]
982pub struct ProfileWorkspace {
983 pub slug: String,
984 pub name: String,
985 pub avatar: Option<String>,
986}
Search across all of g1t, Explore, and a command palette987
988/// `directory`: every account or every workspace, as their public pages
989/// show them, a page at a time in name order. For services that index
990/// them, such as search; nothing private is in it. Returns
991/// `DirectoryPage`.
992#[derive(Debug, Default, Serialize, Deserialize)]
993pub struct DirectoryArgs {
994 /// `user` or `workspace`.
995 pub kind: String,
996 /// Names after this one.
997 #[serde(default)]
998 pub after: Option<String>,
999 pub limit: u32,
1000}
1001
1002/// One account or workspace in the directory.
1003#[derive(Clone, Debug, Serialize, Deserialize)]
1004#[serde(rename_all = "camelCase")]
1005pub struct DirectoryEntry {
1006 /// The account's or workspace's id.
1007 pub id: String,
1008 /// A username or a workspace's slug.
1009 pub slug: String,
1010 /// A person's display name or a workspace's name.
1011 pub name: Option<String>,
1012 /// A person's bio or a workspace's description.
1013 pub bio: Option<String>,
1014 pub avatar: Option<String>,
1015 /// RFC 3339.
1016 pub created_at: String,
1017}
1018
1019#[derive(Clone, Debug, Default, Serialize, Deserialize)]
1020pub struct DirectoryPage {
1021 pub entries: Vec<DirectoryEntry>,
1022 /// Where the next page starts; null on the last.
1023 pub next: Option<String>,
1024}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1025
1026// --- Invites ---------------------------------------------------------------
1027//
1028// While registration is invite-only, every new account (with a password or
1029// through GitHub) needs an invite code. Each person may have
1030// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
1031// to a workspace, whose owners share them. Inviting an email with no
1032// account into a workspace makes an invite bound to that address, which
1033// registers and joins in one step. See services/identity/src/invites.rs.
1034
1035/// Whether anyone may make an account, or only someone with an invite. Set
1036/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
1037/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
1038#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1039#[serde(rename_all = "snake_case")]
1040pub enum RegistrationMode {
1041 #[default]
1042 Invite,
1043 Open,
1044}
1045
1046impl RegistrationMode {
1047 pub fn parse(text: Option<&str>) -> RegistrationMode {
1048 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
1049 Some("open") => RegistrationMode::Open,
1050 _ => RegistrationMode::Invite,
1051 }
1052 }
1053}
1054
1055/// How many invites a person may have out at once, unless identity's
1056/// `INVITES_PER_USER` var says otherwise.
1057pub const INVITES_PER_USER: u32 = 5;
1058
1059/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
1060/// otherwise.
1061pub const INVITE_TTL_DAYS: u64 = 30;
1062
1063/// Where an invite stands. Only a pending invite can be used or revoked.
1064/// An expired or revoked invite that was never used gives its inviter the
1065/// invite back.
1066#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1067#[serde(rename_all = "snake_case")]
1068pub enum InviteStatus {
1069 Pending,
1070 Redeemed,
1071 Expired,
1072 Revoked,
1073}
1074
1075/// What using an invite does.
1076#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1077#[serde(rename_all = "snake_case")]
1078pub enum InviteKind {
1079 /// Makes a new account, and joins `workspace` when one is set.
1080 Account,
1081 /// An existing account joins `workspace`. Never makes an account.
1082 Workspace,
1083}
1084
1085/// Whose allowance an invite uses.
1086#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1087#[serde(rename_all = "snake_case")]
1088pub enum InviteCharge {
1089 /// Its inviter's own.
1090 User,
1091 /// The workspace's, granted by staff and shared by its owners.
1092 Workspace,
1093 /// Nobody's: staff minted it, or it invites an existing account.
1094 None,
1095}
1096
1097/// One invite, as the person who made it sees it.
1098#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1099#[serde(rename_all = "camelCase")]
1100pub struct Invite {
1101 pub id: String,
1102 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
1103 /// is made, and afterwards to whoever made it while it is pending.
1104 /// Null otherwise.
1105 pub code: Option<String>,
1106 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
1107 pub hint: String,
1108 /// Only an account with this address can use it. Null: anyone with
1109 /// the code.
1110 pub email: Option<String>,
1111 pub kind: InviteKind,
1112 /// The workspace it joins, by slug.
1113 pub workspace: Option<String>,
1114 pub status: InviteStatus,
1115 pub charged_to: InviteCharge,
1116 /// Who made it, by username. Null when g1t staff did.
1117 pub invited_by: Option<String>,
1118 /// The account that used it, by username.
1119 pub redeemed_by: Option<String>,
1120 /// RFC 3339.
1121 pub created_at: String,
1122 /// RFC 3339.
1123 pub expires_at: String,
1124 /// RFC 3339.
1125 pub redeemed_at: Option<String>,
1126 /// RFC 3339.
1127 pub revoked_at: Option<String>,
1128 /// The staff member who minted it. Only in staff views.
1129 #[serde(default, skip_serializing_if = "Option::is_none")]
1130 pub staff: Option<String>,
1131}
1132
1133/// How many invites someone may have out, and how many they have.
1134#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1135pub struct Allowance {
1136 /// Null: no limit.
1137 pub limit: Option<u32>,
1138 /// Pending and used invites; revoked and expired ones are not counted.
1139 pub used: u32,
1140 /// Null: no limit.
1141 pub remaining: Option<u32>,
1142}
1143
1144impl Allowance {
1145 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
1146 Allowance {
1147 limit,
1148 used,
1149 remaining: limit.map(|limit| limit.saturating_sub(used)),
1150 }
1151 }
1152
1153 pub fn exhausted(&self) -> bool {
1154 self.remaining == Some(0)
1155 }
1156}
1157
1158/// A workspace's shared invites, for one of its owners.
1159#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
1160pub struct WorkspaceAllowance {
1161 pub slug: String,
1162 pub allowance: Allowance,
1163}
1164
1165/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
1166/// and what they have left. Returns `InvitesOverview`.
1167#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1168pub struct InvitesOverview {
1169 pub mode: RegistrationMode,
1170 pub allowance: Allowance,
1171 /// Workspaces the person owns that staff granted invites to.
1172 pub workspaces: Vec<WorkspaceAllowance>,
1173 pub invites: Vec<Invite>,
1174}
1175
1176/// `create_invite`: a person makes an invite, optionally for one email
1177/// address. People only; never an agent or a workspace's token, and not
1178/// before their email is confirmed. Uses one of the person's invites, or,
1179/// with `workspace`, one of the invites staff granted that workspace (its
1180/// owners only). Emails the address when one is given. Returns
1181/// `Outcome<Invite>`, with the code.
1182///
1183/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
1184/// invite; a workspace's owners may revoke one made for the workspace.
1185/// The invite comes back to whoever it was charged to. Returns
1186/// `Outcome<Invite>`.
1187#[derive(Debug, Serialize, Deserialize)]
1188pub struct CreateInviteArgs {
1189 pub user: User,
1190 #[serde(default)]
1191 pub email: Option<String>,
1192 /// Use this workspace's granted invites, by slug.
1193 #[serde(default)]
1194 pub workspace: Option<String>,
1195 /// Where the request came in, for the audit log; g1t.sh when absent.
1196 #[serde(default)]
1197 pub surface: Option<crate::audit::Surface>,
1198}
1199
1200/// `check_invite`: what an invite code is for, before using it. Returns
1201/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1202/// expired gets the same answer, so codes cannot be probed. With
1203/// `any_status`, a real code that can no longer be used is described
1204/// instead (its `status` says why), so the page can say whom to ask for a
1205/// new one; an unknown code still gets the one answer.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1206#[derive(Debug, Serialize, Deserialize)]
1207pub struct InviteCodeArgs {
1208 pub code: String,
1209 /// Who is asking, such as the visitor's IP address, for rate limits.
1210 #[serde(default)]
1211 pub client: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1212 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
1213 #[serde(default)]
1214 pub viewer: Option<User>,
1215 #[serde(default)]
1216 pub any_status: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1217}
1218
1219/// Someone shown on an invite.
1220#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1221pub struct InviteFrom {
1222 pub username: String,
1223 pub name: Option<String>,
1224 pub avatar: Option<String>,
1225}
1226
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1227/// A repository an invite code was sent with: using the code accepts the
1228/// invitation to collaborate on it.
1229#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1230pub struct InviteRepository {
1231 /// `workspace/repo`.
1232 pub name: String,
1233 /// The role it gives, such as `write`.
1234 pub role: String,
1235}
1236
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1237/// What a valid invite code is for.
1238#[derive(Clone, Debug, Serialize, Deserialize)]
1239#[serde(rename_all = "camelCase")]
1240pub struct InvitePreview {
1241 pub kind: InviteKind,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1242 /// Pending, unless `any_status` asked about a code that is spent.
1243 pub status: InviteStatus,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1244 /// Null when g1t staff sent it.
1245 pub invited_by: Option<InviteFrom>,
1246 pub workspace: Option<ProfileWorkspace>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1247 /// The repository it accepts an invitation to, if it was sent with one.
1248 pub repository: Option<InviteRepository>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1249 /// The address it is for, partly hidden, such as `a•••@example.com`.
1250 pub email: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1251 /// The address in full, while it is pending: whoever holds the code
1252 /// was sent it there. Fills in and locks the sign-up form.
1253 pub address: Option<String>,
1254 /// Whether the address it is for has a g1t account already, so the
1255 /// page asks them to sign in rather than sign up.
1256 pub has_account: bool,
1257 /// With a viewer: whether the invite is theirs (it is for one of their
1258 /// confirmed addresses, or they used it). Null without a viewer or,
1259 /// for a pending invite, when it is for anyone with the code.
1260 pub for_viewer: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1261 /// RFC 3339.
1262 pub expires_at: String,
1263}
1264
1265/// `accept_invite`: a signed-in person uses a workspace invite made for
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1266/// their confirmed address, and joins the workspace, or an invite sent with
1267/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1268/// workspace's slug, or `workspace/repo`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1269#[derive(Debug, Serialize, Deserialize)]
1270pub struct AcceptInviteArgs {
1271 pub user: User,
1272 pub code: String,
1273}
1274
1275/// `invite_member`: an owner invites an email address into a workspace.
1276/// It always makes an invite bound to that address and emails it, so the
1277/// answer never says whether the address has an account. Without one, the
1278/// invite registers and joins in one step, and uses one of the workspace's
1279/// granted invites or else one of the owner's own. With one, it costs
1280/// nothing. Returns `Outcome<Invite>`, with the code.
1281#[derive(Debug, Serialize, Deserialize)]
1282pub struct InviteMemberArgs {
1283 pub actor: User,
1284 pub slug: String,
1285 pub email: String,
1286 /// Where the request came in, for the audit log; g1t.sh when absent.
1287 #[serde(default)]
1288 pub surface: Option<crate::audit::Surface>,
1289}
1290
1291/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1292/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1293///
1294/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1295#[derive(Debug, Serialize, Deserialize)]
1296pub struct WorkspaceInviteArgs {
1297 pub actor: User,
1298 pub slug: String,
1299 pub id: String,
1300}
1301
1302/// `request_access`: someone without an invite asks for one. Kept on the
1303/// waitlist, one entry per address. Answers the same way whether or not
1304/// the address is already on it. Returns `Outcome<bool>`.
1305#[derive(Debug, Default, Serialize, Deserialize)]
1306pub struct RequestAccessArgs {
1307 pub email: String,
1308 /// What they will build, if they said.
1309 #[serde(default)]
1310 pub about: String,
1311 /// Who is asking, such as the visitor's IP address, for rate limits.
1312 #[serde(default)]
1313 pub client: Option<String>,
1314}
1315
1316/// The most characters `RequestAccessArgs::about` keeps.
1317pub const MAX_WAITLIST_ABOUT: usize = 1000;
1318
1319// `registration` takes `{}` and returns `RegistrationMode`.
1320
1321// --- Invites, staff only ---
1322
1323#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1324#[serde(rename_all = "snake_case")]
1325pub enum WaitlistStatus {
1326 Waiting,
1327 Invited,
1328 Dismissed,
1329}
1330
1331impl WaitlistStatus {
1332 pub fn as_str(self) -> &'static str {
1333 match self {
1334 WaitlistStatus::Waiting => "waiting",
1335 WaitlistStatus::Invited => "invited",
1336 WaitlistStatus::Dismissed => "dismissed",
1337 }
1338 }
1339}
1340
1341/// Someone who asked for access.
1342#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1343#[serde(rename_all = "camelCase")]
1344pub struct WaitlistEntry {
1345 pub id: String,
1346 pub email: String,
1347 pub about: Option<String>,
1348 pub status: WaitlistStatus,
1349 pub invite_id: Option<String>,
1350 pub decided_by: Option<String>,
1351 /// RFC 3339.
1352 pub decided_at: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1353 /// What staff wrote when approving; it went in the invite email.
1354 #[serde(default)]
1355 pub note: Option<String>,
1356 /// The account made with the invite, once it was used.
1357 #[serde(default)]
1358 pub joined_as: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1359 /// When they first asked. RFC 3339.
1360 pub created_at: String,
1361 /// When they last asked. RFC 3339.
1362 pub updated_at: String,
1363}
1364
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1365/// `admin_waitlist`: the waitlist, newest first, at most
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1366/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1367///
1368/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1369/// still waiting, for sudo's navigation.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1370#[derive(Debug, Default, Serialize, Deserialize)]
1371pub struct AdminWaitlistArgs {
1372 /// Part of an email address or of what they said.
1373 #[serde(default)]
1374 pub query: Option<String>,
1375 /// Null: every status.
1376 #[serde(default)]
1377 pub status: Option<WaitlistStatus>,
1378}
1379
1380/// The most rows one staff listing of invites or the waitlist returns.
1381pub const ADMIN_INVITES_LIMIT: usize = 500;
1382
1383/// `admin_decide_waitlist`: approving mints an invite bound to the
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1384/// address, charged to nobody, and emails it, with `note` if given;
1385/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1386#[derive(Debug, Serialize, Deserialize)]
1387pub struct AdminDecideWaitlistArgs {
1388 pub id: String,
1389 pub approve: bool,
1390 /// The staff member, by email.
1391 pub staff: String,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1392 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1393 #[serde(default)]
1394 pub note: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1395}
1396
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1397/// The most characters an approval's note keeps.
1398pub const MAX_WAITLIST_NOTE: usize = 500;
1399
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1400/// `admin_invites`: every invite, newest first, at most
1401/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1402/// `query`, or whose email, inviter or redeemer contains it. Returns
1403/// `Vec<Invite>`.
1404#[derive(Debug, Default, Serialize, Deserialize)]
1405pub struct AdminInvitesArgs {
1406 #[serde(default)]
1407 pub query: Option<String>,
1408}
1409
1410/// `admin_revoke_invite`: revokes any pending invite. Returns
1411/// `Outcome<Invite>`.
1412#[derive(Debug, Serialize, Deserialize)]
1413pub struct AdminRevokeInviteArgs {
1414 pub id: String,
1415 pub staff: String,
1416}
1417
1418/// `admin_mint_invite`: staff make an invite that uses nobody's
1419/// allowance, optionally bound to (and emailed to) an address. Returns
1420/// `Outcome<Invite>`, with the code.
1421#[derive(Debug, Serialize, Deserialize)]
1422pub struct AdminMintInviteArgs {
1423 #[serde(default)]
1424 pub email: Option<String>,
1425 pub staff: String,
1426}
1427
1428/// Who staff grant invites to.
1429#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1430#[serde(rename_all = "snake_case")]
1431pub enum GrantTarget {
1432 User,
1433 Workspace,
1434}
1435
1436impl GrantTarget {
1437 pub fn as_str(self) -> &'static str {
1438 match self {
1439 GrantTarget::User => "user",
1440 GrantTarget::Workspace => "workspace",
1441 }
1442 }
1443}
1444
1445/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1446/// slug) `amount` more invites; a negative amount takes some back. Returns
1447/// `Outcome<Allowance>`: theirs afterwards.
1448#[derive(Debug, Serialize, Deserialize)]
1449pub struct AdminGrantInvitesArgs {
1450 pub target: GrantTarget,
1451 pub name: String,
1452 pub amount: i32,
1453 #[serde(default)]
1454 pub note: String,
1455 pub staff: String,
1456}
1457
1458/// The most invites one grant gives or takes back.
1459pub const MAX_INVITE_GRANT: i32 = 1000;
1460
1461/// Invites staff granted.
1462#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1463#[serde(rename_all = "camelCase")]
1464pub struct InviteGrant {
1465 pub amount: i32,
1466 pub note: Option<String>,
1467 pub granted_by: String,
1468 /// RFC 3339.
1469 pub created_at: String,
1470}
1471
1472/// Someone a person invited, and whom they invited in turn.
1473#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1474#[serde(rename_all = "camelCase")]
1475pub struct InviteTreeNode {
1476 pub username: String,
1477 /// When they used the invite. RFC 3339.
1478 pub joined_at: String,
1479 pub invited: Vec<InviteTreeNode>,
1480}
1481
1482/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1483/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1484///
1485/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1486/// invites, grants and invites. Returns `Option<InviteTree>` with
1487/// `username` the slug and no `invited_by`.
1488#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1489#[serde(rename_all = "camelCase")]
1490pub struct InviteTree {
1491 pub username: String,
1492 /// Who invited them, then who invited that person, and so on. Empty
1493 /// for an account made without an invite.
1494 pub invited_by: Vec<String>,
1495 /// The staff member who minted their invite, when staff did.
1496 pub staff: Option<String>,
1497 pub allowance: Allowance,
1498 pub grants: Vec<InviteGrant>,
1499 /// Their invites, newest first.
1500 pub invites: Vec<Invite>,
1501 /// Whom they invited, three levels down.
1502 pub invited: Vec<InviteTreeNode>,
1503}
1504
1505#[cfg(test)]
1506mod deletion_tests {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1507 use super::{WorkspaceDeletion, protected_names};
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1508
1509 #[test]
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1510 fn only_billing_or_protection_stands_in_the_way() {
1511 let clear = WorkspaceDeletion {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1512 repositories: 2,
1513 projects: 1,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1514 members: 3,
1515 ..WorkspaceDeletion::default()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1516 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1517 assert!(!clear.blocked());
1518 assert_eq!(clear.reason("acme"), None);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1519 let owing = WorkspaceDeletion {
1520 billing: Some("Pay first.".into()),
1521 ..WorkspaceDeletion::default()
1522 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1523 assert!(owing.blocked());
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1524 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1525 let protected = WorkspaceDeletion {
1526 billing: Some("Pay first.".into()),
1527 protected: true,
1528 ..WorkspaceDeletion::default()
1529 };
1530 assert!(protected.blocked());
1531 assert_eq!(
1532 protected.reason("flagon-io").as_deref(),
1533 Some("flagon-io is protected and can never be deleted.")
1534 );
1535 }
1536
1537 #[test]
1538 fn flagon_is_protected_whatever_the_variable_says() {
1539 assert_eq!(protected_names(None), ["flagon-io"]);
1540 assert_eq!(protected_names(Some("")), ["flagon-io"]);
1541 assert_eq!(protected_names(Some(" , ")), ["flagon-io"]);
1542 assert_eq!(
1543 protected_names(Some("Flagon-IO, acme ,wsp_1")),
1544 ["flagon-io", "acme", "wsp_1"]
1545 );
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1546 }
1547}

This file's history is long; its oldest lines are credited to the oldest commit read.