Skip to content
1,551 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
RFC 3339 timestamps in identity and repos16 /// RFC 3339.
17 pub created_at: String,
API and MCP server, Rust identity service, registration, site redesign18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
RFC 3339 timestamps in identity and repos25 /// RFC 3339.
26 pub created_at: String,
Agents as a team: lifecycle, merge queue, billing and a new shell27 /// RFC 3339, to within a few minutes. Null until it is first used.
28 pub last_used_at: Option<String>,
29 /// For a workspace's token, the username of the member who made it.
30 /// Null once that account is gone, and on personal tokens.
31 pub created_by: Option<String>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step32 /// Its scopes, as `resource:level`. Null: full access.
33 #[serde(default)]
34 pub scopes: Option<Vec<String>>,
35 /// Made before tokens had scopes: full access until someone narrows it.
36 #[serde(default)]
37 pub legacy: bool,
38 /// RFC 3339. Null: it does not expire.
39 #[serde(default)]
40 pub expires_at: Option<String>,
API and MCP server, Rust identity service, registration, site redesign41}
42
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look43/// `sign_in`: verifies a username, or any confirmed email address of the
44/// account, and its password, for website sign-in. Wrong passwords are
45/// counted against the account and `client`, and past a limit nothing is
46/// checked for a while (see identity's `throttle.rs`).
API and MCP server, Rust identity service, registration, site redesign47/// Returns `Outcome<SignedIn>`.
48#[derive(Debug, Serialize, Deserialize)]
49pub struct SignInArgs {
50 pub username: String,
51 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look52 /// Who is asking, such as the visitor's IP address, for rate limits.
53 #[serde(default)]
54 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign55}
56
57#[derive(Debug, Serialize, Deserialize)]
58#[serde(rename_all = "camelCase")]
59pub struct SignedIn {
60 pub user: User,
61 pub session_token: String,
62}
63
64/// `sign_out` and `user_for_session`.
65#[derive(Debug, Serialize, Deserialize)]
66#[serde(rename_all = "camelCase")]
67pub struct SessionArgs {
68 pub session_token: String,
69}
70
71/// `user_for_git_credentials`: the account password or an access token.
72#[derive(Debug, Serialize, Deserialize)]
73pub struct GitCredentialsArgs {
74 pub username: String,
75 pub secret: String,
76}
77
78/// `user_for_access_token`.
79#[derive(Debug, Serialize, Deserialize)]
80pub struct TokenArgs {
81 pub token: String,
82}
83
84/// `user_for_ssh_key`.
85#[derive(Debug, Serialize, Deserialize)]
86pub struct FingerprintArgs {
87 pub fingerprint: String,
88}
89
90/// `user_by_username`.
91#[derive(Debug, Serialize, Deserialize)]
92pub struct UsernameArgs {
93 pub username: String,
94}
95
What happened across an outcome, as a feed beside its graph96/// `usernames`: the names behind account and workspace ids, as events and
97/// other records store them. Returns a map from id to name; ids it does
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9798/// not know are left out. Also `accounts`: the accounts behind user ids,
99/// each with its username and avatar (`HashMap<String, accounts::EmailOwner>`).
What happened across an outcome, as a feed beside its graph100#[derive(Debug, Serialize, Deserialize)]
101pub struct UsernamesArgs {
102 pub ids: Vec<String>,
103}
104
API and MCP server, Rust identity service, registration, site redesign105/// `list_ssh_keys` and `list_access_tokens`.
106#[derive(Debug, Serialize, Deserialize)]
107pub struct UserArgs {
108 pub user: User,
109}
110
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge111/// `ssh_key_owners`: services only. The account (user id) that registered
112/// each key, by fingerprint (`SHA256:…`, as `ssh-keygen -lf` prints it),
113/// for verifying commits signed with SSH keys. Returns a map of the
114/// fingerprints found to user ids.
115#[derive(Debug, Serialize, Deserialize)]
116pub struct SshKeyOwnersArgs {
117 pub fingerprints: Vec<String>,
118}
119
API and MCP server, Rust identity service, registration, site redesign120/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
121/// Returns `Outcome<SshKey>`.
122#[derive(Debug, Serialize, Deserialize)]
123#[serde(rename_all = "camelCase")]
124pub struct AddSshKeyArgs {
125 pub user: User,
126 pub title: String,
127 pub public_key: String,
128}
129
130/// `remove_ssh_key` and `remove_access_token`.
131#[derive(Debug, Serialize, Deserialize)]
132pub struct RemoveArgs {
133 pub user: User,
134 pub id: String,
135}
136
Agents as a team: lifecycle, merge queue, billing and a new shell137/// `create_access_token`: a token that acts as `user`. For a workspace
138/// acting through a token of its own, the new token belongs to that
139/// workspace too.
API and MCP server, Rust identity service, registration, site redesign140#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)141#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign142pub struct CreateAccessTokenArgs {
143 pub user: User,
144 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)145 /// When set, the token stops working after this many seconds and is
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step146 /// left out of the user's token list, unless `listed`. Used for hosted
147 /// attempts.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)148 #[serde(default)]
149 pub ttl_seconds: Option<u64>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step150 /// Its scopes, as `resource:level`; unknown names are left out. Null:
151 /// full access.
152 #[serde(default)]
153 pub scopes: Option<Vec<String>>,
154 /// Listed with the person's tokens although it expires: one they made
155 /// themselves, with an expiry.
156 #[serde(default)]
157 pub listed: bool,
158}
159
Actions: keep workflow runs safe160/// `create_job_token`: a workflow job's `G1T_TOKEN`. It acts as the
161/// repository's workspace, reaches that repository only, holds `scopes`
162/// (from the job's `permissions`), and is never listed. The actions service
163/// revokes it when the job ends (`revoke_job_tokens`); `ttl_seconds` is a
164/// backstop. Returns `CreatedAccessToken`.
165#[derive(Debug, Serialize, Deserialize)]
166#[serde(rename_all = "camelCase")]
167pub struct CreateJobTokenArgs {
168 /// The workspace the repository belongs to, as its own principal.
169 pub workspace: User,
170 pub repo: crate::repos::RepoPath,
171 pub run_id: String,
172 pub job_id: String,
173 /// What the token is listed as in logs: `G1T_TOKEN for acme/web run 4`.
174 pub name: String,
175 pub ttl_seconds: u64,
176 /// As `resource:level`; unknown names are left out.
177 pub scopes: Vec<String>,
Merge main into the run-protection branch178 /// Whether it may open and approve pull requests (`JobToken::pull_requests`).
179 #[serde(default)]
180 pub pull_requests: bool,
Actions: keep workflow runs safe181}
182
183/// `revoke_job_tokens`: ends a workflow job's tokens at once, when the job
184/// finishes or is cancelled. Only job tokens are touched. Returns `bool`.
185#[derive(Debug, Default, Serialize, Deserialize)]
186#[serde(rename_all = "camelCase")]
187pub struct RevokeJobTokensArgs {
188 pub job_id: String,
189}
190
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step191/// `update_access_token`: changes what one of a person's tokens may do.
192/// The token itself is unchanged. Returns `Outcome<AccessToken>`.
193#[derive(Debug, Serialize, Deserialize)]
194pub struct UpdateAccessTokenArgs {
195 pub user: User,
196 pub id: String,
197 /// Null: full access.
198 #[serde(default)]
199 pub scopes: Option<Vec<String>>,
API and MCP server, Rust identity service, registration, site redesign200}
201
202/// The plaintext token is returned once and never stored.
203#[derive(Debug, Serialize, Deserialize)]
204pub struct CreatedAccessToken {
205 pub token: String,
206 pub info: AccessToken,
207}
208
209/// `register`: creates an account and signs it in.
210/// Returns `Outcome<SignedIn>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look211///
212/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
213/// new account needs `invite_code`: an unused, unexpired invite, and, when
214/// the invite names an email, that address. See [`CreateInviteArgs`].
API and MCP server, Rust identity service, registration, site redesign215#[derive(Debug, Serialize, Deserialize)]
216pub struct RegisterArgs {
217 pub username: String,
218 pub email: String,
219 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look220 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
221 /// registration is open.
222 #[serde(default)]
223 pub invite_code: Option<String>,
224 /// Who is asking, such as the visitor's IP address, for rate limits.
225 #[serde(default)]
226 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign227}
Email verification, password reset, and Git for AI scale positioning228
229/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
230#[derive(Debug, Serialize, Deserialize)]
231pub struct EmailTokenArgs {
232 pub token: String,
233}
234
235/// `request_password_reset`. Always succeeds, so it cannot be used to find
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look236/// out which addresses have accounts. Any confirmed address of an account
237/// works: the link goes to the address given, and the primary (and the
238/// backup) are told a reset was asked for. A few requests an hour per
239/// address and per `client`; past that, nothing is sent.
Email verification, password reset, and Git for AI scale positioning240#[derive(Debug, Serialize, Deserialize)]
241pub struct EmailArgs {
242 pub email: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look243 /// Who is asking, such as the visitor's IP address, for rate limits.
244 #[serde(default)]
245 pub client: Option<String>,
Email verification, password reset, and Git for AI scale positioning246}
247
248/// `reset_password`: sets a new password and ends every session.
249/// Returns `Outcome<User>`.
250#[derive(Debug, Serialize, Deserialize)]
251pub struct ResetPasswordArgs {
252 pub token: String,
253 pub password: String,
254}
Device sign-in replaces registering and minting tokens over the API255
256/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
257#[derive(Debug, Serialize, Deserialize)]
258#[serde(rename_all = "camelCase")]
259pub struct DeviceStartArgs {
260 /// What is asking, shown to the person approving, e.g. "Claude Code".
261 pub client_name: String,
262}
263
264#[derive(Debug, Serialize, Deserialize)]
265#[serde(rename_all = "camelCase")]
266pub struct DeviceStart {
267 /// Secret held by the tool and exchanged for a token once approved.
268 pub device_code: String,
269 /// Short code shown to the person, e.g. `WDJB-MJHT`.
270 pub user_code: String,
271 /// Seconds until both codes stop working.
272 pub expires_in: u32,
273 /// Seconds the tool should wait between polls.
274 pub interval: u32,
275}
276
277/// `device_lookup`: what a user code is asking for, or null if it is not
278/// valid. Returns `Option<DeviceRequest>`.
279#[derive(Debug, Serialize, Deserialize)]
280#[serde(rename_all = "camelCase")]
281pub struct DeviceLookupArgs {
282 pub user_code: String,
283}
284
285#[derive(Debug, Serialize, Deserialize)]
286#[serde(rename_all = "camelCase")]
287pub struct DeviceRequest {
288 pub user_code: String,
289 pub client_name: String,
290}
291
292/// `device_resolve`: the signed-in person approves or denies a request.
293/// Returns `Outcome<bool>`.
294#[derive(Debug, Serialize, Deserialize)]
295#[serde(rename_all = "camelCase")]
296pub struct DeviceResolveArgs {
297 pub user_code: String,
298 pub user: User,
299 pub approve: bool,
300}
301
302/// `device_claim`: the tool asks whether its request was approved.
303#[derive(Debug, Serialize, Deserialize)]
304#[serde(rename_all = "camelCase")]
305pub struct DeviceClaimArgs {
306 pub device_code: String,
307}
308
309/// The answer to a `device_claim`.
310#[derive(Debug, Serialize, Deserialize)]
311#[serde(tag = "status", rename_all = "snake_case")]
312pub enum DeviceClaim {
313 /// Nobody has approved or denied it yet; ask again after the interval.
314 Pending,
315 Denied,
316 /// The code was never issued, has expired, or was already used.
317 Expired,
318 /// The access token, returned once.
319 Approved {
320 token: String,
321 user: User,
322 },
323}
Workspaces own repositories324
325/// A workspace: the owner of repositories, and the first segment of their
326/// URLs. A person's own space and a team's are the same thing.
327#[derive(Clone, Debug, Serialize, Deserialize)]
328#[serde(rename_all = "camelCase")]
329pub struct Workspace {
330 pub id: String,
331 pub slug: String,
332 pub name: String,
Agents as a team: lifecycle, merge queue, billing and a new shell333 /// One line saying what the workspace is for.
334 pub description: Option<String>,
Workspaces own repositories335 /// RFC 3339.
336 pub created_at: String,
337 pub member_count: u32,
Workspace names and icons, and a component kit for every control338 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
339 /// `/avatars/<avatar>`. Null means the generated letter avatar.
340 #[serde(default)]
341 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look342 /// What every member gets on each of its repositories; owners have
343 /// Admin. See [`crate::access`].
344 #[serde(default)]
345 pub base_permission: crate::access::BasePermission,
Merge branch 'worktree-agent-ad7c6d88d93adc817'346 /// Who may create its teams. See [`crate::teams::TeamCreation`].
347 #[serde(default)]
348 pub team_creation: crate::teams::TeamCreation,
Workspaces own repositories349}
350
351#[derive(Clone, Debug, Serialize, Deserialize)]
352pub struct Member {
353 pub username: String,
354 pub role: crate::Role,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look355 /// Their display name, when they set one.
356 #[serde(default)]
357 pub name: Option<String>,
358 /// Their uploaded avatar: the SHA-256 of its bytes, served at
359 /// `/avatars/<avatar>`. None means the generated letter avatar.
360 #[serde(default)]
361 pub avatar: Option<String>,
Workspaces own repositories362}
363
Merge branch 'worktree-agent-a2013627e5ea4ab13'364/// Where a workspace keeps its repositories' git data: anywhere g1t
365/// stores it (the default), or in the EU only. It applies to repositories
366/// made after it is set; the repos service reads it when it places a new
367/// one (`storage_options` says whether the EU can be chosen).
368#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
369#[serde(rename_all = "lowercase")]
370pub enum DataResidency {
371 #[default]
372 Anywhere,
373 Eu,
374}
375
376impl DataResidency {
377 pub fn as_str(self) -> &'static str {
378 match self {
379 DataResidency::Anywhere => "anywhere",
380 DataResidency::Eu => "eu",
381 }
382 }
383
384 pub fn parse(text: &str) -> Option<Self> {
385 match text.trim().to_ascii_lowercase().as_str() {
386 "anywhere" => Some(DataResidency::Anywhere),
387 "eu" => Some(DataResidency::Eu),
388 _ => None,
389 }
390 }
391}
392
393/// `workspace_residency` takes [`SlugArgs`] and returns
394/// `Option<DataResidency>` (null when there is no such workspace).
395/// `set_workspace_residency`: owners only. Returns `Outcome<DataResidency>`.
396#[derive(Debug, Serialize, Deserialize)]
397pub struct SetResidencyArgs {
398 pub actor: User,
399 pub slug: String,
400 pub residency: DataResidency,
401}
402
Workspaces own repositories403/// `create_workspace`. Returns `Outcome<Workspace>`.
404#[derive(Debug, Serialize, Deserialize)]
405pub struct CreateWorkspaceArgs {
406 pub user: User,
407 pub slug: String,
408 #[serde(default)]
409 pub name: String,
410}
411
412/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
413#[derive(Debug, Serialize, Deserialize)]
414pub struct SlugArgs {
415 pub slug: String,
416}
417
418/// `list_members`: members only. Returns `Outcome<Vec<Member>>`.
419#[derive(Debug, Serialize, Deserialize)]
420pub struct ListMembersArgs {
421 pub slug: String,
422 pub viewer: crate::Viewer,
423}
424
425/// `add_member` and `remove_member`: owners only.
426/// Each returns `Outcome<bool>`.
427#[derive(Debug, Serialize, Deserialize)]
428pub struct MemberArgs {
429 pub actor: User,
430 pub slug: String,
431 pub username: String,
432}
OAuth 2.1 sign-in for MCP clients and other applications433
Agents as a team: lifecycle, merge queue, billing and a new shell434/// `update_workspace`: owners only. An empty name falls back to the slug;
435/// an empty description clears it. Returns `Outcome<Workspace>`.
436#[derive(Debug, Serialize, Deserialize)]
437pub struct UpdateWorkspaceArgs {
438 pub actor: User,
439 pub slug: String,
440 pub name: String,
441 pub description: String,
442}
443
Agents and memory, checks and conflicts, profiles, slug renames, custom domains444/// `rename_workspace`: owners only. Changes the workspace's slug, the first
445/// segment of its URLs, to `new_slug`; the display name is untouched. The
446/// old slug redirects to the new one, and is held for this workspace, for
447/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
448/// `Outcome<Workspace>`.
449///
450/// `check_workspace_rename` takes the same arguments and answers whether
451/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
452#[derive(Debug, Serialize, Deserialize)]
453#[serde(rename_all = "camelCase")]
454pub struct RenameWorkspaceArgs {
455 pub actor: User,
456 pub slug: String,
457 pub new_slug: String,
458}
459
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look460/// `delete_workspace`: owners only, and only a person. `confirm` must be
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member461/// the workspace's slug, typed out. Refused for a protected workspace
462/// ([`protected_names`]), whoever asks, and while billing cannot settle it
463/// (`close_workspace`). Everything in it goes with it at once: nobody can
464/// reach it, its tokens stop working, its pages are not found, and its
465/// repositories, projects and apps are deleted with it. It is kept for
466/// [`WORKSPACE_RESTORE_DAYS`] so g1t's staff can restore it, then purged:
467/// its memberships, access tokens and old-slug redirects go, and billing's
468/// ledger and the audit log keep its history. The slug is never given to
469/// another workspace; the person whose username it is may make a workspace
470/// of that name again once it is purged. Publishes `workspace.deleting`,
471/// and `workspace.deleted` at the purge. Returns `Outcome<bool>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look472///
473/// `check_workspace_deletion` takes the same arguments (with `confirm`
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member474/// ignored) and says what would go and whether anything stands in the way,
475/// changing nothing. Returns `Outcome<WorkspaceDeletion>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look476#[derive(Debug, Serialize, Deserialize)]
477pub struct DeleteWorkspaceArgs {
478 pub actor: User,
479 pub slug: String,
480 #[serde(default)]
481 pub confirm: String,
482 /// Where the request came in, for the audit log; g1t.sh when absent.
483 #[serde(default)]
484 pub surface: Option<crate::audit::Surface>,
485}
486
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member487/// What deleting a workspace takes with it, and what stands in the way.
488/// Nothing does when `billing` is null and it is not `protected`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look489#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
490pub struct WorkspaceDeletion {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member491 /// Its live repositories, which are deleted with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look492 pub repositories: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member493 /// Its projects, hidden with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look494 pub projects: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member495 #[serde(default)]
496 pub members: u32,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look497 /// Why billing cannot close the workspace yet, in words for its owner.
498 pub billing: Option<String>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member499 /// It can never be deleted, by anyone ([`protected_names`]).
500 #[serde(default)]
501 pub protected: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look502}
503
504impl WorkspaceDeletion {
505 pub fn blocked(&self) -> bool {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member506 self.protected || self.billing.is_some()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look507 }
508
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member509 /// Why the workspace cannot be deleted, as one sentence, or `None`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look510 pub fn reason(&self, slug: &str) -> Option<String> {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member511 if self.protected {
512 return Some(protected_refusal(slug));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look513 }
514 self.billing.clone()
515 }
516}
517
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member518/// How long a deleted workspace is kept, for staff to restore, before it is
519/// purged.
520pub const WORKSPACE_RESTORE_DAYS: u64 = 30;
521
522/// Workspaces nobody can delete, whatever identity's `PROTECTED_WORKSPACES`
523/// says: Flagon's, which runs g1t.
524pub const ALWAYS_PROTECTED: &[&str] = &["flagon-io"];
525
526/// The protected workspaces: `configured` (comma-separated slugs or
527/// workspace ids, as identity's `PROTECTED_WORKSPACES` holds them), and
528/// [`ALWAYS_PROTECTED`] whatever it says, so an empty or missing variable
529/// still protects them. Lowercased, without duplicates.
530pub fn protected_names(configured: Option<&str>) -> Vec<String> {
531 let mut names: Vec<String> = Vec::new();
532 let given = configured.unwrap_or_default().split(',');
533 for name in ALWAYS_PROTECTED.iter().copied().chain(given) {
534 let name = name.trim().to_lowercase();
535 if !name.is_empty() && !names.contains(&name) {
536 names.push(name);
537 }
538 }
539 names
540}
541
542/// Why a protected workspace is not deleted, purged or acted on.
543pub fn protected_refusal(slug: &str) -> String {
544 format!("{slug} is protected and can never be deleted.")
545}
546
547/// `admin_deleted_workspaces` takes no arguments (`{}`) and returns
548/// `Vec<DeletedWorkspace>`, newest first. Staff only.
549///
550/// A workspace an owner deleted, kept until `purge_after` for staff to
551/// restore.
552#[derive(Clone, Debug, Serialize, Deserialize)]
553#[serde(rename_all = "camelCase")]
554pub struct DeletedWorkspace {
555 pub workspace_id: String,
556 pub slug: String,
557 pub name: String,
558 /// RFC 3339.
559 pub deleted_at: String,
560 /// The username of the owner who deleted it.
561 pub deleted_by: String,
562 /// RFC 3339: when it is purged unless restored first.
563 pub purge_after: String,
564 /// What went with it, counted when it was deleted.
565 pub went: WorkspaceDeletion,
566 /// Whether staff can still restore it.
567 pub restorable: bool,
568}
569
570/// `admin_restore_workspace` and `admin_purge_workspace`: staff restore a
571/// deleted workspace within [`WORKSPACE_RESTORE_DAYS`], or purge it now.
572/// `staff` is who, for the audit logs. Purging needs `confirm`, the slug
573/// typed out, and is refused for a protected workspace. Restoring publishes
574/// `workspace.restored`; purging, `workspace.deleted`. Both return
575/// `Outcome<bool>`.
576#[derive(Debug, Serialize, Deserialize)]
577#[serde(rename_all = "camelCase")]
578pub struct AdminDeletedWorkspaceArgs {
579 pub workspace_id: String,
580 pub staff: String,
581 #[serde(default)]
582 pub confirm: String,
583}
584
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look585/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
586/// tokens of agents at work on it are kept pointing at it. For repos'
587/// `transfer`. Returns `bool`.
588#[derive(Debug, Serialize, Deserialize)]
589pub struct TransferRepoScopesArgs {
590 pub from: crate::repos::RepoPath,
591 pub to: crate::repos::RepoPath,
592}
593
Agents and memory, checks and conflicts, profiles, slug renames, custom domains594/// How long a workspace's old slug keeps redirecting to it, and stays
595/// reserved for it, after a rename.
596pub const SLUG_HOLD_DAYS: u64 = 90;
597
598/// How long a workspace must wait between renames.
599pub const RENAME_COOLDOWN_HOURS: u64 = 24;
600
601// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
602// workspace's current slug when `slug` is one it was renamed from within
603// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
Merge branch 'worktree-agent-a8385d293d42c913a'604// is in use), or the workspace's slug when `slug` is one of its aliases.
605
606// `resolve_alias` takes `SlugArgs` and returns `Option<String>`: the slug
607// now of the workspace `slug` is an alias of, and null when it is none.
608// Aliases are set by g1t's staff only: `g1t` is Flagon, Inc.'s `flagon-io`.
609// An alias follows its workspace through renames.
610
611/// `admin_aliases` takes no arguments (`{}`) and returns
612/// `Vec<WorkspaceAlias>`, by alias. Staff only.
613///
614/// A name staff point at a workspace, so that its addresses (pages, git,
615/// the API, packages) lead to the workspace under its own name.
616#[derive(Clone, Debug, Serialize, Deserialize)]
617#[serde(rename_all = "camelCase")]
618pub struct WorkspaceAlias {
619 pub alias: String,
620 pub workspace_id: String,
621 /// The workspace's slug and name now.
622 pub workspace: String,
623 pub workspace_name: String,
624 /// Why it exists, as staff wrote it.
625 pub note: String,
626 /// The staff member who set it, or `migration`.
627 pub created_by: String,
628 /// RFC 3339.
629 pub created_at: String,
630}
631
632/// `admin_set_alias`: points `alias` at the workspace whose slug is
633/// `workspace`. The alias must have a namespace's shape, must not be one of
634/// the site's routes, and must not be anyone's username, a workspace's slug
635/// (deleted, or held after a rename) or another alias. `note` is required:
636/// it is the reason, kept with the alias and in sudo's audit log. Staff
637/// only. Returns `Outcome<WorkspaceAlias>`.
638#[derive(Debug, Serialize, Deserialize)]
639#[serde(rename_all = "camelCase")]
640pub struct AdminSetAliasArgs {
641 pub alias: String,
642 pub workspace: String,
643 pub note: String,
644 pub staff: String,
645}
646
647/// `admin_remove_alias`: the alias stops leading anywhere, and the name is
648/// nobody's again unless it is reserved. `reason` goes in sudo's audit log.
649/// Staff only. Returns `Outcome<bool>`.
650#[derive(Debug, Serialize, Deserialize)]
651#[serde(rename_all = "camelCase")]
652pub struct AdminRemoveAliasArgs {
653 pub alias: String,
654 pub reason: String,
655 pub staff: String,
656}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains657
Workspace names and icons, and a component kit for every control658/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
659/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
660/// the icon. Returns `Outcome<Workspace>`.
661#[derive(Debug, Serialize, Deserialize)]
662pub struct SetWorkspaceAvatarArgs {
663 pub actor: User,
664 pub slug: String,
665 pub image: Option<String>,
666}
667
668/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
669/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
670#[derive(Debug, Serialize, Deserialize)]
671pub struct SetUserAvatarArgs {
672 pub user: User,
673 pub image: Option<String>,
674}
675
676/// The largest avatar that can be uploaded, in bytes.
677pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
678
Agents as a team: lifecycle, merge queue, billing and a new shell679/// `list_workspace_tokens`: members only. Returns
680/// `Outcome<Vec<AccessToken>>`.
681#[derive(Debug, Serialize, Deserialize)]
682pub struct WorkspaceTokensArgs {
683 pub slug: String,
684 pub viewer: crate::Viewer,
685}
686
687/// `create_workspace_token`: owners only. The token belongs to the
688/// workspace, acts as it, and keeps working when the member who made it
689/// leaves. Returns `Outcome<CreatedAccessToken>`.
690#[derive(Debug, Serialize, Deserialize)]
691pub struct CreateWorkspaceTokenArgs {
692 pub actor: User,
693 pub slug: String,
694 pub name: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step695 /// Its scopes; null for full access.
696 #[serde(default)]
697 pub scopes: Option<Vec<String>>,
698 /// When set, the token stops working after this many seconds. It is
699 /// listed with the workspace's tokens either way. Null: no expiry.
700 #[serde(default)]
701 pub ttl_seconds: Option<u64>,
Agents as a team: lifecycle, merge queue, billing and a new shell702}
703
704/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
705#[derive(Debug, Serialize, Deserialize)]
706pub struct RemoveWorkspaceTokenArgs {
707 pub actor: User,
708 pub slug: String,
709 pub id: String,
710}
711
OAuth 2.1 sign-in for MCP clients and other applications712/// `oauth_authorize`: the signed-in person approved an application. The
713/// caller has checked the client and that it may be redirected to
714/// `redirect_uri`. Returns `OAuthCode`.
715#[derive(Debug, Serialize, Deserialize)]
716#[serde(rename_all = "camelCase")]
717pub struct OAuthAuthorizeArgs {
718 pub user: User,
719 pub client_id: String,
720 /// Shown wherever the application's access is listed.
721 pub client_name: String,
722 pub redirect_uri: String,
723 /// PKCE challenge, method S256.
724 pub code_challenge: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step725 /// What the person granted, as `resource:level`. Null: full access.
726 #[serde(default)]
727 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications728}
729
730#[derive(Debug, Serialize, Deserialize)]
731pub struct OAuthCode {
732 pub code: String,
733}
734
735/// `oauth_exchange`: redeems an authorization code.
736/// Returns `Outcome<OAuthTokens>`.
737#[derive(Debug, Serialize, Deserialize)]
738#[serde(rename_all = "camelCase")]
739pub struct OAuthExchangeArgs {
740 pub code: String,
741 pub code_verifier: String,
742 pub client_id: String,
743 pub redirect_uri: String,
744}
745
746/// `oauth_refresh`: trades a refresh token for new tokens.
747/// Returns `Outcome<OAuthTokens>`.
748#[derive(Debug, Serialize, Deserialize)]
749#[serde(rename_all = "camelCase")]
750pub struct OAuthRefreshArgs {
751 pub refresh_token: String,
752 pub client_id: String,
753}
754
755#[derive(Debug, Serialize, Deserialize)]
756#[serde(rename_all = "camelCase")]
757pub struct OAuthTokens {
758 pub access_token: String,
759 /// Works once; using it returns the next one.
760 pub refresh_token: String,
761 /// Seconds until the access token stops working.
762 pub expires_in: u64,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step763 /// The scopes granted, space-separated, or `*` for full access.
764 #[serde(default)]
765 pub scope: Option<String>,
OAuth 2.1 sign-in for MCP clients and other applications766}
767
768/// An application a person has signed in to. Listed by `list_oauth_grants`
769/// and ended by `revoke_oauth_grant`.
770#[derive(Debug, Serialize, Deserialize)]
771#[serde(rename_all = "camelCase")]
772pub struct OAuthGrant {
773 pub id: String,
774 pub client_name: String,
775 /// RFC 3339.
776 pub created_at: String,
777 /// RFC 3339.
778 pub last_used_at: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step779 /// What the person granted. Null: full access.
780 #[serde(default)]
781 pub scopes: Option<Vec<String>>,
782 /// Signed in before applications were given scopes: full access until
783 /// someone narrows it.
784 #[serde(default)]
785 pub legacy: bool,
786}
787
788/// `update_oauth_grant`: changes what an application the person signed in
789/// to may do, at once and when it refreshes. Returns `Outcome<OAuthGrant>`.
790#[derive(Debug, Serialize, Deserialize)]
791pub struct UpdateOAuthGrantArgs {
792 pub user: User,
793 pub id: String,
794 #[serde(default)]
795 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications796}
Agents as a team: lifecycle, merge queue, billing and a new shell797
798
799/// What an agent's token may do: these operations, in this repository.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API800#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
Agents as a team: lifecycle, merge queue, billing and a new shell801pub struct AgentScope {
802 pub repo: crate::repos::RepoPath,
803 /// API and MCP operation names, such as `create_issue`.
804 pub operations: Vec<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API805 /// Set on a run credential: the run it belongs to, and what it may do
806 /// with git. See [`crate::credentials`].
807 #[serde(default, skip_serializing_if = "Option::is_none")]
808 pub run: Option<crate::credentials::RunBinding>,
Agents as a team: lifecycle, merge queue, billing and a new shell809}
810
811/// `create_agent_token`: a token for a g1t agent working on someone's
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent812/// behalf. It acts as `g1t`, a member of the repository's workspace,
Agents as a team: lifecycle, merge queue, billing and a new shell813/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
814#[derive(Debug, Serialize, Deserialize)]
815#[serde(rename_all = "camelCase")]
816pub struct CreateAgentTokenArgs {
817 /// The person the agent works for; the token is recorded as theirs.
818 pub on_behalf_of: User,
819 pub scope: AgentScope,
820 pub ttl_seconds: u64,
821}
822
823// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
824// agent's token may do, or null for any other token.
825
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent826/// The id g1t's agent acts under. Only ever stored, never shown: it keeps
827/// the agent's work apart from g1t's own ([`crate::system::ID`]) where
828/// that matters, such as whether its approval counts.
Agents as a team: lifecycle, merge queue, billing and a new shell829pub const AGENT_ID: &str = "usr_g1t_agent";
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent830/// The name g1t's agent is shown by: g1t's own, [`crate::system::USERNAME`].
831/// Everything it does, people see g1t do.
832pub const AGENT_NAME: &str = crate::system::USERNAME;
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace833
834// --- Staff ---------------------------------------------------------------
835//
836// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
837// membership: only sudo calls them, over its service binding, after it has
838// verified a Cloudflare Access sign-in and its staff list. Nothing a
839// customer can reach should ever forward to them.
840
841/// `notify_owners`: emails a short notice, with one link, to each owner of
842/// a workspace with a confirmed address. Called by other services (billing
843/// warns owners near their usage limit), never on a person's behalf.
844/// Returns how many were sent.
845#[derive(Clone, Debug, Serialize, Deserialize)]
846pub struct NotifyOwnersArgs {
847 pub workspace: String,
848 pub subject: String,
849 /// One or two sentences: what happened and what it means.
850 pub intro: String,
851 /// The button's words, such as `Open billing`.
852 pub action: String,
853 /// Where the button goes; must be on g1t.sh.
854 pub link: String,
855 /// Small print: why they got it.
856 pub footer: String,
857}
858
859/// `admin_workspaces`: every workspace, newest first, at most
860/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
861/// an owner's username or email contains `query`. Returns
862/// `Vec<AdminWorkspace>`. Staff only.
863#[derive(Debug, Default, Serialize, Deserialize)]
864pub struct AdminWorkspacesArgs {
865 #[serde(default)]
866 pub query: Option<String>,
867}
868
869/// The most workspaces one `admin_workspaces` call returns.
870pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
871
872/// An owner of a workspace, as staff see them.
873#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
874pub struct AdminOwner {
875 pub username: String,
876 pub email: Option<String>,
877}
878
879/// A workspace as staff see it: who owns it and how many belong to it.
880#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
881#[serde(rename_all = "camelCase")]
882pub struct AdminWorkspace {
883 pub slug: String,
884 pub name: String,
885 /// RFC 3339.
886 pub created_at: String,
887 pub owners: Vec<AdminOwner>,
888 pub member_count: u32,
889}
890
891/// `admin_workspace`: one workspace with every member, or null. Takes
892/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
893#[derive(Clone, Debug, Serialize, Deserialize)]
894#[serde(rename_all = "camelCase")]
895pub struct AdminWorkspaceDetail {
896 pub slug: String,
897 pub name: String,
898 pub description: Option<String>,
899 /// RFC 3339.
900 pub created_at: String,
901 /// Owners first, then by username.
902 pub members: Vec<AdminMember>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member903 /// It can never be deleted ([`protected_names`]).
904 #[serde(default)]
905 pub protected: bool,
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace906}
907
908/// A member of a workspace, as staff see them.
909#[derive(Clone, Debug, Serialize, Deserialize)]
910pub struct AdminMember {
911 pub username: String,
912 pub email: Option<String>,
913 pub role: crate::Role,
914 /// When they joined the workspace. RFC 3339.
915 pub joined: String,
916}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains917
918// --- Profiles ------------------------------------------------------------
919//
920// A person's public page at `g1t.sh/u/<username>`. Everything in a
921// `Profile` is shown to anyone, signed in or not; an email address never is.
922
923/// The most characters each profile field takes.
924pub const MAX_PROFILE_NAME: usize = 80;
925pub const MAX_PROFILE_BIO: usize = 160;
926pub const MAX_PROFILE_LOCATION: usize = 80;
927pub const MAX_PROFILE_WEBSITE: usize = 200;
928pub const MAX_PROFILE_PRONOUNS: usize = 40;
929
930/// What anyone may see about a person.
931#[derive(Clone, Debug, Default, Serialize, Deserialize)]
932#[serde(rename_all = "camelCase")]
933pub struct Profile {
934 pub username: String,
935 /// The name they go by, if they gave one.
936 pub name: Option<String>,
937 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
938 pub bio: Option<String>,
939 pub location: Option<String>,
940 /// An `https://` address.
941 pub website: Option<String>,
942 pub pronouns: Option<String>,
943 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
944 pub avatar: Option<String>,
945 /// When the account was made. RFC 3339.
946 pub created_at: String,
947}
948
949// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
950// an account that does not exist.
951
952/// `update_profile`: a person changes their own profile. Every field is
953/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
954#[derive(Debug, Default, Serialize, Deserialize)]
955#[serde(rename_all = "camelCase")]
956pub struct UpdateProfileArgs {
957 pub actor: User,
958 #[serde(default)]
959 pub name: String,
960 #[serde(default)]
961 pub bio: String,
962 #[serde(default)]
963 pub location: String,
964 #[serde(default)]
965 pub website: String,
966 #[serde(default)]
967 pub pronouns: String,
968}
969
970/// `profile_workspaces`: the workspaces shown on a person's profile, as
971/// `viewer` may see them. A membership is shown only when it is no secret
972/// from the viewer: a workspace the viewer belongs to as well, or one of
973/// `public`, the workspaces the caller found the person has made a public
974/// project in (whose page shows that already). Returns
975/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
976#[derive(Debug, Serialize, Deserialize)]
977pub struct ProfileWorkspacesArgs {
978 pub username: String,
979 pub viewer: crate::Viewer,
980 #[serde(default)]
981 pub public: Vec<String>,
982}
983
984/// A workspace on a person's profile.
985#[derive(Clone, Debug, Serialize, Deserialize)]
986pub struct ProfileWorkspace {
987 pub slug: String,
988 pub name: String,
989 pub avatar: Option<String>,
990}
Search across all of g1t, Explore, and a command palette991
992/// `directory`: every account or every workspace, as their public pages
993/// show them, a page at a time in name order. For services that index
994/// them, such as search; nothing private is in it. Returns
995/// `DirectoryPage`.
996#[derive(Debug, Default, Serialize, Deserialize)]
997pub struct DirectoryArgs {
998 /// `user` or `workspace`.
999 pub kind: String,
1000 /// Names after this one.
1001 #[serde(default)]
1002 pub after: Option<String>,
1003 pub limit: u32,
1004}
1005
1006/// One account or workspace in the directory.
1007#[derive(Clone, Debug, Serialize, Deserialize)]
1008#[serde(rename_all = "camelCase")]
1009pub struct DirectoryEntry {
1010 /// The account's or workspace's id.
1011 pub id: String,
1012 /// A username or a workspace's slug.
1013 pub slug: String,
1014 /// A person's display name or a workspace's name.
1015 pub name: Option<String>,
1016 /// A person's bio or a workspace's description.
1017 pub bio: Option<String>,
1018 pub avatar: Option<String>,
1019 /// RFC 3339.
1020 pub created_at: String,
1021}
1022
1023#[derive(Clone, Debug, Default, Serialize, Deserialize)]
1024pub struct DirectoryPage {
1025 pub entries: Vec<DirectoryEntry>,
1026 /// Where the next page starts; null on the last.
1027 pub next: Option<String>,
1028}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1029
1030// --- Invites ---------------------------------------------------------------
1031//
1032// While registration is invite-only, every new account (with a password or
1033// through GitHub) needs an invite code. Each person may have
1034// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
1035// to a workspace, whose owners share them. Inviting an email with no
1036// account into a workspace makes an invite bound to that address, which
1037// registers and joins in one step. See services/identity/src/invites.rs.
1038
1039/// Whether anyone may make an account, or only someone with an invite. Set
1040/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
1041/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
1042#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1043#[serde(rename_all = "snake_case")]
1044pub enum RegistrationMode {
1045 #[default]
1046 Invite,
1047 Open,
1048}
1049
1050impl RegistrationMode {
1051 pub fn parse(text: Option<&str>) -> RegistrationMode {
1052 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
1053 Some("open") => RegistrationMode::Open,
1054 _ => RegistrationMode::Invite,
1055 }
1056 }
1057}
1058
1059/// How many invites a person may have out at once, unless identity's
1060/// `INVITES_PER_USER` var says otherwise.
1061pub const INVITES_PER_USER: u32 = 5;
1062
1063/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
1064/// otherwise.
1065pub const INVITE_TTL_DAYS: u64 = 30;
1066
1067/// Where an invite stands. Only a pending invite can be used or revoked.
1068/// An expired or revoked invite that was never used gives its inviter the
1069/// invite back.
1070#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1071#[serde(rename_all = "snake_case")]
1072pub enum InviteStatus {
1073 Pending,
1074 Redeemed,
1075 Expired,
1076 Revoked,
1077}
1078
1079/// What using an invite does.
1080#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1081#[serde(rename_all = "snake_case")]
1082pub enum InviteKind {
1083 /// Makes a new account, and joins `workspace` when one is set.
1084 Account,
1085 /// An existing account joins `workspace`. Never makes an account.
1086 Workspace,
1087}
1088
1089/// Whose allowance an invite uses.
1090#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1091#[serde(rename_all = "snake_case")]
1092pub enum InviteCharge {
1093 /// Its inviter's own.
1094 User,
1095 /// The workspace's, granted by staff and shared by its owners.
1096 Workspace,
1097 /// Nobody's: staff minted it, or it invites an existing account.
1098 None,
1099}
1100
1101/// One invite, as the person who made it sees it.
1102#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1103#[serde(rename_all = "camelCase")]
1104pub struct Invite {
1105 pub id: String,
1106 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
1107 /// is made, and afterwards to whoever made it while it is pending.
1108 /// Null otherwise.
1109 pub code: Option<String>,
1110 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
1111 pub hint: String,
1112 /// Only an account with this address can use it. Null: anyone with
1113 /// the code.
1114 pub email: Option<String>,
1115 pub kind: InviteKind,
1116 /// The workspace it joins, by slug.
1117 pub workspace: Option<String>,
1118 pub status: InviteStatus,
1119 pub charged_to: InviteCharge,
1120 /// Who made it, by username. Null when g1t staff did.
1121 pub invited_by: Option<String>,
1122 /// The account that used it, by username.
1123 pub redeemed_by: Option<String>,
1124 /// RFC 3339.
1125 pub created_at: String,
1126 /// RFC 3339.
1127 pub expires_at: String,
1128 /// RFC 3339.
1129 pub redeemed_at: Option<String>,
1130 /// RFC 3339.
1131 pub revoked_at: Option<String>,
1132 /// The staff member who minted it. Only in staff views.
1133 #[serde(default, skip_serializing_if = "Option::is_none")]
1134 pub staff: Option<String>,
1135}
1136
1137/// How many invites someone may have out, and how many they have.
1138#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1139pub struct Allowance {
1140 /// Null: no limit.
1141 pub limit: Option<u32>,
1142 /// Pending and used invites; revoked and expired ones are not counted.
1143 pub used: u32,
1144 /// Null: no limit.
1145 pub remaining: Option<u32>,
1146}
1147
1148impl Allowance {
1149 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
1150 Allowance {
1151 limit,
1152 used,
1153 remaining: limit.map(|limit| limit.saturating_sub(used)),
1154 }
1155 }
1156
1157 pub fn exhausted(&self) -> bool {
1158 self.remaining == Some(0)
1159 }
1160}
1161
1162/// A workspace's shared invites, for one of its owners.
1163#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
1164pub struct WorkspaceAllowance {
1165 pub slug: String,
1166 pub allowance: Allowance,
1167}
1168
1169/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
1170/// and what they have left. Returns `InvitesOverview`.
1171#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1172pub struct InvitesOverview {
1173 pub mode: RegistrationMode,
1174 pub allowance: Allowance,
1175 /// Workspaces the person owns that staff granted invites to.
1176 pub workspaces: Vec<WorkspaceAllowance>,
1177 pub invites: Vec<Invite>,
1178}
1179
1180/// `create_invite`: a person makes an invite, optionally for one email
1181/// address. People only; never an agent or a workspace's token, and not
1182/// before their email is confirmed. Uses one of the person's invites, or,
1183/// with `workspace`, one of the invites staff granted that workspace (its
1184/// owners only). Emails the address when one is given. Returns
1185/// `Outcome<Invite>`, with the code.
1186///
1187/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
1188/// invite; a workspace's owners may revoke one made for the workspace.
1189/// The invite comes back to whoever it was charged to. Returns
1190/// `Outcome<Invite>`.
1191#[derive(Debug, Serialize, Deserialize)]
1192pub struct CreateInviteArgs {
1193 pub user: User,
1194 #[serde(default)]
1195 pub email: Option<String>,
1196 /// Use this workspace's granted invites, by slug.
1197 #[serde(default)]
1198 pub workspace: Option<String>,
1199 /// Where the request came in, for the audit log; g1t.sh when absent.
1200 #[serde(default)]
1201 pub surface: Option<crate::audit::Surface>,
1202}
1203
1204/// `check_invite`: what an invite code is for, before using it. Returns
1205/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1206/// expired gets the same answer, so codes cannot be probed. With
1207/// `any_status`, a real code that can no longer be used is described
1208/// instead (its `status` says why), so the page can say whom to ask for a
1209/// new one; an unknown code still gets the one answer.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1210#[derive(Debug, Serialize, Deserialize)]
1211pub struct InviteCodeArgs {
1212 pub code: String,
1213 /// Who is asking, such as the visitor's IP address, for rate limits.
1214 #[serde(default)]
1215 pub client: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1216 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
1217 #[serde(default)]
1218 pub viewer: Option<User>,
1219 #[serde(default)]
1220 pub any_status: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1221}
1222
1223/// Someone shown on an invite.
1224#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1225pub struct InviteFrom {
1226 pub username: String,
1227 pub name: Option<String>,
1228 pub avatar: Option<String>,
1229}
1230
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1231/// A repository an invite code was sent with: using the code accepts the
1232/// invitation to collaborate on it.
1233#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1234pub struct InviteRepository {
1235 /// `workspace/repo`.
1236 pub name: String,
1237 /// The role it gives, such as `write`.
1238 pub role: String,
1239}
1240
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1241/// What a valid invite code is for.
1242#[derive(Clone, Debug, Serialize, Deserialize)]
1243#[serde(rename_all = "camelCase")]
1244pub struct InvitePreview {
1245 pub kind: InviteKind,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1246 /// Pending, unless `any_status` asked about a code that is spent.
1247 pub status: InviteStatus,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1248 /// Null when g1t staff sent it.
1249 pub invited_by: Option<InviteFrom>,
1250 pub workspace: Option<ProfileWorkspace>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1251 /// The repository it accepts an invitation to, if it was sent with one.
1252 pub repository: Option<InviteRepository>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1253 /// The address it is for, partly hidden, such as `a•••@example.com`.
1254 pub email: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1255 /// The address in full, while it is pending: whoever holds the code
1256 /// was sent it there. Fills in and locks the sign-up form.
1257 pub address: Option<String>,
1258 /// Whether the address it is for has a g1t account already, so the
1259 /// page asks them to sign in rather than sign up.
1260 pub has_account: bool,
1261 /// With a viewer: whether the invite is theirs (it is for one of their
1262 /// confirmed addresses, or they used it). Null without a viewer or,
1263 /// for a pending invite, when it is for anyone with the code.
1264 pub for_viewer: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1265 /// RFC 3339.
1266 pub expires_at: String,
1267}
1268
1269/// `accept_invite`: a signed-in person uses a workspace invite made for
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1270/// their confirmed address, and joins the workspace, or an invite sent with
1271/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1272/// workspace's slug, or `workspace/repo`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1273#[derive(Debug, Serialize, Deserialize)]
1274pub struct AcceptInviteArgs {
1275 pub user: User,
1276 pub code: String,
1277}
1278
1279/// `invite_member`: an owner invites an email address into a workspace.
1280/// It always makes an invite bound to that address and emails it, so the
1281/// answer never says whether the address has an account. Without one, the
1282/// invite registers and joins in one step, and uses one of the workspace's
1283/// granted invites or else one of the owner's own. With one, it costs
1284/// nothing. Returns `Outcome<Invite>`, with the code.
1285#[derive(Debug, Serialize, Deserialize)]
1286pub struct InviteMemberArgs {
1287 pub actor: User,
1288 pub slug: String,
1289 pub email: String,
1290 /// Where the request came in, for the audit log; g1t.sh when absent.
1291 #[serde(default)]
1292 pub surface: Option<crate::audit::Surface>,
1293}
1294
1295/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1296/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1297///
1298/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1299#[derive(Debug, Serialize, Deserialize)]
1300pub struct WorkspaceInviteArgs {
1301 pub actor: User,
1302 pub slug: String,
1303 pub id: String,
1304}
1305
1306/// `request_access`: someone without an invite asks for one. Kept on the
1307/// waitlist, one entry per address. Answers the same way whether or not
1308/// the address is already on it. Returns `Outcome<bool>`.
1309#[derive(Debug, Default, Serialize, Deserialize)]
1310pub struct RequestAccessArgs {
1311 pub email: String,
1312 /// What they will build, if they said.
1313 #[serde(default)]
1314 pub about: String,
1315 /// Who is asking, such as the visitor's IP address, for rate limits.
1316 #[serde(default)]
1317 pub client: Option<String>,
1318}
1319
1320/// The most characters `RequestAccessArgs::about` keeps.
1321pub const MAX_WAITLIST_ABOUT: usize = 1000;
1322
1323// `registration` takes `{}` and returns `RegistrationMode`.
1324
1325// --- Invites, staff only ---
1326
1327#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1328#[serde(rename_all = "snake_case")]
1329pub enum WaitlistStatus {
1330 Waiting,
1331 Invited,
1332 Dismissed,
1333}
1334
1335impl WaitlistStatus {
1336 pub fn as_str(self) -> &'static str {
1337 match self {
1338 WaitlistStatus::Waiting => "waiting",
1339 WaitlistStatus::Invited => "invited",
1340 WaitlistStatus::Dismissed => "dismissed",
1341 }
1342 }
1343}
1344
1345/// Someone who asked for access.
1346#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1347#[serde(rename_all = "camelCase")]
1348pub struct WaitlistEntry {
1349 pub id: String,
1350 pub email: String,
1351 pub about: Option<String>,
1352 pub status: WaitlistStatus,
1353 pub invite_id: Option<String>,
1354 pub decided_by: Option<String>,
1355 /// RFC 3339.
1356 pub decided_at: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1357 /// What staff wrote when approving; it went in the invite email.
1358 #[serde(default)]
1359 pub note: Option<String>,
1360 /// The account made with the invite, once it was used.
1361 #[serde(default)]
1362 pub joined_as: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1363 /// When they first asked. RFC 3339.
1364 pub created_at: String,
1365 /// When they last asked. RFC 3339.
1366 pub updated_at: String,
1367}
1368
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1369/// `admin_waitlist`: the waitlist, newest first, at most
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1370/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1371///
1372/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1373/// still waiting, for sudo's navigation.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1374#[derive(Debug, Default, Serialize, Deserialize)]
1375pub struct AdminWaitlistArgs {
1376 /// Part of an email address or of what they said.
1377 #[serde(default)]
1378 pub query: Option<String>,
1379 /// Null: every status.
1380 #[serde(default)]
1381 pub status: Option<WaitlistStatus>,
1382}
1383
1384/// The most rows one staff listing of invites or the waitlist returns.
1385pub const ADMIN_INVITES_LIMIT: usize = 500;
1386
1387/// `admin_decide_waitlist`: approving mints an invite bound to the
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1388/// address, charged to nobody, and emails it, with `note` if given;
1389/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1390#[derive(Debug, Serialize, Deserialize)]
1391pub struct AdminDecideWaitlistArgs {
1392 pub id: String,
1393 pub approve: bool,
1394 /// The staff member, by email.
1395 pub staff: String,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1396 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1397 #[serde(default)]
1398 pub note: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1399}
1400
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1401/// The most characters an approval's note keeps.
1402pub const MAX_WAITLIST_NOTE: usize = 500;
1403
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1404/// `admin_invites`: every invite, newest first, at most
1405/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1406/// `query`, or whose email, inviter or redeemer contains it. Returns
1407/// `Vec<Invite>`.
1408#[derive(Debug, Default, Serialize, Deserialize)]
1409pub struct AdminInvitesArgs {
1410 #[serde(default)]
1411 pub query: Option<String>,
1412}
1413
1414/// `admin_revoke_invite`: revokes any pending invite. Returns
1415/// `Outcome<Invite>`.
1416#[derive(Debug, Serialize, Deserialize)]
1417pub struct AdminRevokeInviteArgs {
1418 pub id: String,
1419 pub staff: String,
1420}
1421
1422/// `admin_mint_invite`: staff make an invite that uses nobody's
1423/// allowance, optionally bound to (and emailed to) an address. Returns
1424/// `Outcome<Invite>`, with the code.
1425#[derive(Debug, Serialize, Deserialize)]
1426pub struct AdminMintInviteArgs {
1427 #[serde(default)]
1428 pub email: Option<String>,
1429 pub staff: String,
1430}
1431
1432/// Who staff grant invites to.
1433#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1434#[serde(rename_all = "snake_case")]
1435pub enum GrantTarget {
1436 User,
1437 Workspace,
1438}
1439
1440impl GrantTarget {
1441 pub fn as_str(self) -> &'static str {
1442 match self {
1443 GrantTarget::User => "user",
1444 GrantTarget::Workspace => "workspace",
1445 }
1446 }
1447}
1448
1449/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1450/// slug) `amount` more invites; a negative amount takes some back. Returns
1451/// `Outcome<Allowance>`: theirs afterwards.
1452#[derive(Debug, Serialize, Deserialize)]
1453pub struct AdminGrantInvitesArgs {
1454 pub target: GrantTarget,
1455 pub name: String,
1456 pub amount: i32,
1457 #[serde(default)]
1458 pub note: String,
1459 pub staff: String,
1460}
1461
1462/// The most invites one grant gives or takes back.
1463pub const MAX_INVITE_GRANT: i32 = 1000;
1464
1465/// Invites staff granted.
1466#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1467#[serde(rename_all = "camelCase")]
1468pub struct InviteGrant {
1469 pub amount: i32,
1470 pub note: Option<String>,
1471 pub granted_by: String,
1472 /// RFC 3339.
1473 pub created_at: String,
1474}
1475
1476/// Someone a person invited, and whom they invited in turn.
1477#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1478#[serde(rename_all = "camelCase")]
1479pub struct InviteTreeNode {
1480 pub username: String,
1481 /// When they used the invite. RFC 3339.
1482 pub joined_at: String,
1483 pub invited: Vec<InviteTreeNode>,
1484}
1485
1486/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1487/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1488///
1489/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1490/// invites, grants and invites. Returns `Option<InviteTree>` with
1491/// `username` the slug and no `invited_by`.
1492#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1493#[serde(rename_all = "camelCase")]
1494pub struct InviteTree {
1495 pub username: String,
1496 /// Who invited them, then who invited that person, and so on. Empty
1497 /// for an account made without an invite.
1498 pub invited_by: Vec<String>,
1499 /// The staff member who minted their invite, when staff did.
1500 pub staff: Option<String>,
1501 pub allowance: Allowance,
1502 pub grants: Vec<InviteGrant>,
1503 /// Their invites, newest first.
1504 pub invites: Vec<Invite>,
1505 /// Whom they invited, three levels down.
1506 pub invited: Vec<InviteTreeNode>,
1507}
1508
1509#[cfg(test)]
1510mod deletion_tests {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1511 use super::{WorkspaceDeletion, protected_names};
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1512
1513 #[test]
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1514 fn only_billing_or_protection_stands_in_the_way() {
1515 let clear = WorkspaceDeletion {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1516 repositories: 2,
1517 projects: 1,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1518 members: 3,
1519 ..WorkspaceDeletion::default()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1520 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1521 assert!(!clear.blocked());
1522 assert_eq!(clear.reason("acme"), None);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1523 let owing = WorkspaceDeletion {
1524 billing: Some("Pay first.".into()),
1525 ..WorkspaceDeletion::default()
1526 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1527 assert!(owing.blocked());
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1528 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1529 let protected = WorkspaceDeletion {
1530 billing: Some("Pay first.".into()),
1531 protected: true,
1532 ..WorkspaceDeletion::default()
1533 };
1534 assert!(protected.blocked());
1535 assert_eq!(
1536 protected.reason("flagon-io").as_deref(),
1537 Some("flagon-io is protected and can never be deleted.")
1538 );
1539 }
1540
1541 #[test]
1542 fn flagon_is_protected_whatever_the_variable_says() {
1543 assert_eq!(protected_names(None), ["flagon-io"]);
1544 assert_eq!(protected_names(Some("")), ["flagon-io"]);
1545 assert_eq!(protected_names(Some(" , ")), ["flagon-io"]);
1546 assert_eq!(
1547 protected_names(Some("Flagon-IO, acme ,wsp_1")),
1548 ["flagon-io", "acme", "wsp_1"]
1549 );
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1550 }
1551}

This file's history is long; its oldest lines are credited to the oldest commit read.