Skip to content

g1t/crates/contracts/src/lib.rs

196 lines7,087 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod access;
8pub mod accounts;
9pub mod actions;
10pub mod agents;
11pub mod audit;
12pub mod backups;
13pub mod billing;
14pub mod capture;
15pub mod credentials;
16pub mod events;
17pub mod github;
18pub mod guardrails;
19pub mod identity;
20pub mod inbox;
21pub mod integrations;
22mod ids;
23mod names;
24mod outcome;
25pub mod packages;
26pub mod projects;
27pub mod repos;
28pub mod runners;
29pub mod scopes;
30pub mod search;
31pub mod security;
32pub mod time;
33pub mod webhooks;
34pub mod work;
35
36pub use ids::new_id;
37pub use names::{claimable_namespace, is_reserved_name, is_valid_namespace, is_valid_repo_name};
38pub use outcome::{Failure, FailureCode, Outcome};
39
40use serde::{Deserialize, Serialize};
41
42/// What a member may do in a workspace.
43#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
44#[serde(rename_all = "lowercase")]
45pub enum Role {
46 /// Everything a member can, plus managing members.
47 Owner,
48 /// Create repositories, push, manage issues and merge pull requests.
49 Member,
50}
51
52/// One workspace a user belongs to.
53#[derive(Clone, Debug, Serialize, Deserialize)]
54pub struct Membership {
55 /// The workspace's name in URLs: `g1t.sh/<slug>`.
56 pub slug: String,
57 pub role: Role,
58 /// The workspace's display name, for showing it to people. Set when a
59 /// user is resolved from credentials; absent on principals made up by
60 /// a service.
61 #[serde(default, skip_serializing_if = "Option::is_none")]
62 pub name: Option<String>,
63 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
64 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
65 #[serde(default, skip_serializing_if = "Option::is_none")]
66 pub avatar: Option<String>,
67 /// What a member gets on each of the workspace's repositories: the
68 /// workspace's base permission. Set when a user is resolved from
69 /// credentials; absent means the default, Write. Owners have Admin
70 /// whatever it says. See [`access`].
71 #[serde(default, skip_serializing_if = "Option::is_none")]
72 pub base_permission: Option<access::BasePermission>,
73}
74
75impl Membership {
76 /// A plain member of `slug`, as services act inside one workspace.
77 pub fn member(slug: impl Into<String>) -> Self {
78 Membership {
79 slug: slug.into(),
80 role: Role::Member,
81 name: None,
82 avatar: None,
83 base_permission: None,
84 }
85 }
86}
87
88/// What a set of credentials resolved to.
89#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
90#[serde(rename_all = "lowercase")]
91pub enum PrincipalKind {
92 /// A person's account.
93 #[default]
94 User,
95 /// A workspace, acting through one of its own access tokens. Its `id`
96 /// is the workspace's, its `username` the workspace's slug, and it is a
97 /// member of that workspace and no other.
98 Workspace,
99 /// A g1t agent at work in a sandbox, acting through a token that lives
100 /// as long as its run and can do only what that token's scope lists, in
101 /// one repository. Its `username` is `g1t`.
102 Agent,
103 /// g1t itself: the platform acting on its own, as when it opens a
104 /// pull request to upgrade a vulnerable dependency or merges from the
105 /// queue. Never resolved from credentials: only services make one,
106 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
107 /// register.
108 System,
109}
110
111/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
112pub mod system {
113 /// Its id wherever an author or actor id is stored.
114 pub const ID: &str = "g1t";
115 /// Its name, shown as the author of what it does.
116 pub const USERNAME: &str = "g1t";
117 /// The address on the commits it makes, which no mailbox receives.
118 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
119 /// Ids that earlier versions stored for g1t's own actions, such as a
120 /// merge its settings made. Read as g1t too.
121 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
122
123 /// Whether `id` is g1t's own.
124 pub fn is_system_id(id: &str) -> bool {
125 id == ID || LEGACY_IDS.contains(&id)
126 }
127}
128
129#[derive(Clone, Debug, Default, Serialize, Deserialize)]
130pub struct User {
131 pub id: String,
132 pub username: String,
133 #[serde(default)]
134 pub kind: PrincipalKind,
135 /// Whether the account's email address has been confirmed. Unverified
136 /// accounts can sign in but cannot create or change anything.
137 #[serde(default)]
138 pub verified: bool,
139 /// The workspaces this user belongs to. Filled in when a user is
140 /// resolved from credentials, so any service can authorize from it.
141 #[serde(default)]
142 pub workspaces: Vec<Membership>,
143 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
144 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
145 #[serde(default, skip_serializing_if = "Option::is_none")]
146 pub avatar: Option<String>,
147 /// Set on an agent resolved from its token: who it acts for, with which
148 /// credential, and what it may do. See [`credentials`].
149 #[serde(default, skip_serializing_if = "Option::is_none")]
150 pub acting: Option<Box<credentials::Acting>>,
151 /// The repositories this user has been given a role on directly,
152 /// whether or not they belong to its workspace. Filled in with
153 /// `workspaces`; see [`access`].
154 #[serde(default, skip_serializing_if = "Vec::is_empty")]
155 pub grants: Vec<access::RepoGrant>,
156 /// Set on a user resolved from an access token: its scopes and the
157 /// workspaces or repositories it is limited to. Absent on a signed-in
158 /// session and on an agent (whose `acting` scope applies instead).
159 /// See [`scopes`].
160 #[serde(default, skip_serializing_if = "Option::is_none")]
161 pub token: Option<Box<scopes::TokenAccess>>,
162}
163
164impl User {
165 /// g1t itself, acting in `workspace`: what the platform's own work,
166 /// such as security updates, is done and recorded as.
167 pub fn system(workspace: &str) -> User {
168 User {
169 id: system::ID.to_owned(),
170 username: system::USERNAME.to_owned(),
171 kind: PrincipalKind::System,
172 verified: true,
173 workspaces: vec![Membership::member(workspace.to_lowercase())],
174 ..User::default()
175 }
176 }
177
178 /// Whether this is g1t itself.
179 pub fn is_system(&self) -> bool {
180 self.kind == PrincipalKind::System
181 }
182
183 pub fn role_in(&self, slug: &str) -> Option<Role> {
184 self.workspaces
185 .iter()
186 .find(|membership| membership.slug == slug)
187 .map(|membership| membership.role)
188 }
189
190 pub fn is_member(&self, slug: &str) -> bool {
191 self.role_in(slug).is_some()
192 }
193}
194
195/// Who is asking. Every read and write in every service takes one.
196pub type Viewer = Option<User>;