g1t/crates/contracts/src/lib.rs

90 lines2,773 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod billing;
8pub mod events;
9pub mod identity;
10pub mod integrations;
11mod ids;
12mod names;
13mod outcome;
14pub mod repos;
15pub mod time;
16pub mod webhooks;
17pub mod work;
18
19pub use ids::new_id;
20pub use names::{is_valid_namespace, is_valid_repo_name};
21pub use outcome::{Failure, FailureCode, Outcome};
22
23use serde::{Deserialize, Serialize};
24
25/// What a member may do in a workspace.
26#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
27#[serde(rename_all = "lowercase")]
28pub enum Role {
29 /// Everything a member can, plus managing members.
30 Owner,
31 /// Create repositories, push, manage issues and merge pull requests.
32 Member,
33}
34
35/// One workspace a user belongs to.
36#[derive(Clone, Debug, Serialize, Deserialize)]
37pub struct Membership {
38 /// The workspace's name in URLs: `g1t.sh/<slug>`.
39 pub slug: String,
40 pub role: Role,
41}
42
43/// What a set of credentials resolved to.
44#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
45#[serde(rename_all = "lowercase")]
46pub enum PrincipalKind {
47 /// A person's account.
48 #[default]
49 User,
50 /// A workspace, acting through one of its own access tokens. Its `id`
51 /// is the workspace's, its `username` the workspace's slug, and it is a
52 /// member of that workspace and no other.
53 Workspace,
54 /// A g1t agent at work in a sandbox, acting through a token that lives
55 /// as long as its run and can do only what that token's scope lists, in
56 /// one repository. Its `username` is `g1t-agent`.
57 Agent,
58}
59
60#[derive(Clone, Debug, Default, Serialize, Deserialize)]
61pub struct User {
62 pub id: String,
63 pub username: String,
64 #[serde(default)]
65 pub kind: PrincipalKind,
66 /// Whether the account's email address has been confirmed. Unverified
67 /// accounts can sign in but cannot create or change anything.
68 #[serde(default)]
69 pub verified: bool,
70 /// The workspaces this user belongs to. Filled in when a user is
71 /// resolved from credentials, so any service can authorize from it.
72 #[serde(default)]
73 pub workspaces: Vec<Membership>,
74}
75
76impl User {
77 pub fn role_in(&self, slug: &str) -> Option<Role> {
78 self.workspaces
79 .iter()
80 .find(|membership| membership.slug == slug)
81 .map(|membership| membership.role)
82 }
83
84 pub fn is_member(&self, slug: &str) -> bool {
85 self.role_in(slug).is_some()
86 }
87}
88
89/// Who is asking. Every read and write in every service takes one.
90pub type Viewer = Option<User>;