Skip to content
1,753 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
RFC 3339 timestamps in identity and repos16 /// RFC 3339.
17 pub created_at: String,
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca18 /// When it was last used to sign in over SSH, RFC 3339, to within 5
19 /// minutes; null when it never was.
20 #[serde(default)]
21 pub last_used_at: Option<String>,
API and MCP server, Rust identity service, registration, site redesign22}
23
Fine-grained personal tokens, workspace token rules and approvals in identity24#[derive(Clone, Debug, Default, Serialize, Deserialize)]
API and MCP server, Rust identity service, registration, site redesign25#[serde(rename_all = "camelCase")]
26pub struct AccessToken {
27 pub id: String,
28 pub name: String,
RFC 3339 timestamps in identity and repos29 /// RFC 3339.
30 pub created_at: String,
Agents as a team: lifecycle, merge queue, billing and a new shell31 /// RFC 3339, to within a few minutes. Null until it is first used.
32 pub last_used_at: Option<String>,
33 /// For a workspace's token, the username of the member who made it.
34 /// Null once that account is gone, and on personal tokens.
35 pub created_by: Option<String>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step36 /// Its scopes, as `resource:level`. Null: full access.
37 #[serde(default)]
38 pub scopes: Option<Vec<String>>,
39 /// Made before tokens had scopes: full access until someone narrows it.
40 #[serde(default)]
41 pub legacy: bool,
42 /// RFC 3339. Null: it does not expire.
43 #[serde(default)]
44 pub expires_at: Option<String>,
Fine-grained personal tokens, workspace token rules and approvals in identity45 /// Classic, fine-grained, or a workspace's own.
46 #[serde(default)]
47 pub kind: crate::tokens::TokenKind,
48 /// What it is for, as its owner wrote it.
49 #[serde(default, skip_serializing_if = "Option::is_none")]
50 pub description: Option<String>,
51 /// A fine-grained token's resource owner, repositories, permissions and
52 /// status.
53 #[serde(default, skip_serializing_if = "Option::is_none")]
54 pub fine_grained: Option<crate::tokens::FineGrainedDetails>,
55 /// A workspace's own token an owner gave Admin when making it.
56 #[serde(default, skip_serializing_if = "std::ops::Not::not")]
57 pub admin: bool,
API and MCP server, Rust identity service, registration, site redesign58}
59
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look60/// `sign_in`: verifies a username, or any confirmed email address of the
61/// account, and its password, for website sign-in. Wrong passwords are
62/// counted against the account and `client`, and past a limit nothing is
63/// checked for a while (see identity's `throttle.rs`).
API and MCP server, Rust identity service, registration, site redesign64/// Returns `Outcome<SignedIn>`.
65#[derive(Debug, Serialize, Deserialize)]
66pub struct SignInArgs {
67 pub username: String,
68 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look69 /// Who is asking, such as the visitor's IP address, for rate limits.
70 #[serde(default)]
71 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign72}
73
74#[derive(Debug, Serialize, Deserialize)]
75#[serde(rename_all = "camelCase")]
76pub struct SignedIn {
77 pub user: User,
Merge main (membership, two-factor, GitHub repo roles) into tokens78 /// Empty while `two_factor_challenge` is set: no session is made until
79 /// the code is given.
API and MCP server, Rust identity service, registration, site redesign80 pub session_token: String,
Merge main (membership, two-factor, GitHub repo roles) into tokens81 /// Set when the account has two-factor authentication on: the token to
82 /// pass to `two_factor_sign_in` with a code. Valid for
83 /// `accounts::TWO_FACTOR_CHALLENGE_SECONDS`.
84 #[serde(default, skip_serializing_if = "Option::is_none")]
85 pub two_factor_challenge: Option<String>,
API and MCP server, Rust identity service, registration, site redesign86}
87
88/// `sign_out` and `user_for_session`.
89#[derive(Debug, Serialize, Deserialize)]
90#[serde(rename_all = "camelCase")]
91pub struct SessionArgs {
92 pub session_token: String,
93}
94
95/// `user_for_git_credentials`: the account password or an access token.
96#[derive(Debug, Serialize, Deserialize)]
97pub struct GitCredentialsArgs {
98 pub username: String,
99 pub secret: String,
100}
101
102/// `user_for_access_token`.
103#[derive(Debug, Serialize, Deserialize)]
104pub struct TokenArgs {
105 pub token: String,
106}
107
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca108/// `user_for_ssh_key`, and `principal_for_ssh_key` (see [`crate::deploy_keys`]).
API and MCP server, Rust identity service, registration, site redesign109#[derive(Debug, Serialize, Deserialize)]
110pub struct FingerprintArgs {
111 pub fingerprint: String,
112}
113
114/// `user_by_username`.
115#[derive(Debug, Serialize, Deserialize)]
116pub struct UsernameArgs {
117 pub username: String,
118}
119
What happened across an outcome, as a feed beside its graph120/// `usernames`: the names behind account and workspace ids, as events and
121/// other records store them. Returns a map from id to name; ids it does
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97122/// not know are left out. Also `accounts`: the accounts behind user ids,
123/// each with its username and avatar (`HashMap<String, accounts::EmailOwner>`).
What happened across an outcome, as a feed beside its graph124#[derive(Debug, Serialize, Deserialize)]
125pub struct UsernamesArgs {
126 pub ids: Vec<String>,
127}
128
API and MCP server, Rust identity service, registration, site redesign129/// `list_ssh_keys` and `list_access_tokens`.
130#[derive(Debug, Serialize, Deserialize)]
131pub struct UserArgs {
132 pub user: User,
133}
134
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge135/// `ssh_key_owners`: services only. The account (user id) that registered
136/// each key, by fingerprint (`SHA256:…`, as `ssh-keygen -lf` prints it),
137/// for verifying commits signed with SSH keys. Returns a map of the
138/// fingerprints found to user ids.
139#[derive(Debug, Serialize, Deserialize)]
140pub struct SshKeyOwnersArgs {
141 pub fingerprints: Vec<String>,
142}
143
API and MCP server, Rust identity service, registration, site redesign144/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
145/// Returns `Outcome<SshKey>`.
146#[derive(Debug, Serialize, Deserialize)]
147#[serde(rename_all = "camelCase")]
148pub struct AddSshKeyArgs {
149 pub user: User,
150 pub title: String,
151 pub public_key: String,
152}
153
154/// `remove_ssh_key` and `remove_access_token`.
155#[derive(Debug, Serialize, Deserialize)]
156pub struct RemoveArgs {
157 pub user: User,
158 pub id: String,
159}
160
Agents as a team: lifecycle, merge queue, billing and a new shell161/// `create_access_token`: a token that acts as `user`. For a workspace
162/// acting through a token of its own, the new token belongs to that
163/// workspace too.
API and MCP server, Rust identity service, registration, site redesign164#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)165#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign166pub struct CreateAccessTokenArgs {
167 pub user: User,
168 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)169 /// When set, the token stops working after this many seconds and is
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step170 /// left out of the user's token list, unless `listed`. Used for hosted
171 /// attempts.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)172 #[serde(default)]
173 pub ttl_seconds: Option<u64>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step174 /// Its scopes, as `resource:level`; unknown names are left out. Null:
175 /// full access.
176 #[serde(default)]
177 pub scopes: Option<Vec<String>>,
178 /// Listed with the person's tokens although it expires: one they made
179 /// themselves, with an expiry.
180 #[serde(default)]
181 pub listed: bool,
182}
183
Merge branch 'worktree-agent-a3abfcce648e87dca'184/// `create_job_token`: a workflow job's `G1T_TOKEN`. It acts as the
185/// repository's workspace, reaches that repository only, holds `scopes`
186/// (from the job's `permissions`), and is never listed. The actions service
187/// revokes it when the job ends (`revoke_job_tokens`); `ttl_seconds` is a
188/// backstop. Returns `CreatedAccessToken`.
189#[derive(Debug, Serialize, Deserialize)]
190#[serde(rename_all = "camelCase")]
191pub struct CreateJobTokenArgs {
192 /// The workspace the repository belongs to, as its own principal.
193 pub workspace: User,
194 pub repo: crate::repos::RepoPath,
195 pub run_id: String,
196 pub job_id: String,
197 /// What the token is listed as in logs: `G1T_TOKEN for acme/web run 4`.
198 pub name: String,
199 pub ttl_seconds: u64,
200 /// As `resource:level`; unknown names are left out.
201 pub scopes: Vec<String>,
202 /// Whether it may open and approve pull requests (`JobToken::pull_requests`).
203 #[serde(default)]
204 pub pull_requests: bool,
205}
206
207/// `revoke_job_tokens`: ends a workflow job's tokens at once, when the job
208/// finishes or is cancelled. Only job tokens are touched. Returns `bool`.
209#[derive(Debug, Default, Serialize, Deserialize)]
210#[serde(rename_all = "camelCase")]
211pub struct RevokeJobTokensArgs {
212 pub job_id: String,
213}
214
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step215/// `update_access_token`: changes what one of a person's tokens may do.
216/// The token itself is unchanged. Returns `Outcome<AccessToken>`.
217#[derive(Debug, Serialize, Deserialize)]
218pub struct UpdateAccessTokenArgs {
219 pub user: User,
220 pub id: String,
221 /// Null: full access.
222 #[serde(default)]
223 pub scopes: Option<Vec<String>>,
API and MCP server, Rust identity service, registration, site redesign224}
225
226/// The plaintext token is returned once and never stored.
227#[derive(Debug, Serialize, Deserialize)]
228pub struct CreatedAccessToken {
229 pub token: String,
230 pub info: AccessToken,
231}
232
233/// `register`: creates an account and signs it in.
234/// Returns `Outcome<SignedIn>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look235///
236/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
237/// new account needs `invite_code`: an unused, unexpired invite, and, when
238/// the invite names an email, that address. See [`CreateInviteArgs`].
API and MCP server, Rust identity service, registration, site redesign239#[derive(Debug, Serialize, Deserialize)]
240pub struct RegisterArgs {
241 pub username: String,
242 pub email: String,
243 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look244 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
245 /// registration is open.
246 #[serde(default)]
247 pub invite_code: Option<String>,
Merge invite emails that confirm the address: the emailed link carries a proof only that email has, so signing up from it needs no code; shared links and typed codes still confirm248 /// The `proof` from the invite email's link. When it is the invite's
249 /// own and `email` is the address the invite was sent to, the account
250 /// starts with that address confirmed; otherwise it is ignored.
251 #[serde(default)]
252 pub email_proof: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look253 /// Who is asking, such as the visitor's IP address, for rate limits.
254 #[serde(default)]
255 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign256}
Email verification, password reset, and Git for AI scale positioning257
258/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
259#[derive(Debug, Serialize, Deserialize)]
260pub struct EmailTokenArgs {
261 pub token: String,
262}
263
264/// `request_password_reset`. Always succeeds, so it cannot be used to find
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look265/// out which addresses have accounts. Any confirmed address of an account
266/// works: the link goes to the address given, and the primary (and the
267/// backup) are told a reset was asked for. A few requests an hour per
268/// address and per `client`; past that, nothing is sent.
Email verification, password reset, and Git for AI scale positioning269#[derive(Debug, Serialize, Deserialize)]
270pub struct EmailArgs {
271 pub email: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look272 /// Who is asking, such as the visitor's IP address, for rate limits.
273 #[serde(default)]
274 pub client: Option<String>,
Email verification, password reset, and Git for AI scale positioning275}
276
277/// `reset_password`: sets a new password and ends every session.
278/// Returns `Outcome<User>`.
279#[derive(Debug, Serialize, Deserialize)]
280pub struct ResetPasswordArgs {
281 pub token: String,
282 pub password: String,
283}
Device sign-in replaces registering and minting tokens over the API284
285/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
286#[derive(Debug, Serialize, Deserialize)]
287#[serde(rename_all = "camelCase")]
288pub struct DeviceStartArgs {
289 /// What is asking, shown to the person approving, e.g. "Claude Code".
290 pub client_name: String,
291}
292
293#[derive(Debug, Serialize, Deserialize)]
294#[serde(rename_all = "camelCase")]
295pub struct DeviceStart {
296 /// Secret held by the tool and exchanged for a token once approved.
297 pub device_code: String,
298 /// Short code shown to the person, e.g. `WDJB-MJHT`.
299 pub user_code: String,
300 /// Seconds until both codes stop working.
301 pub expires_in: u32,
302 /// Seconds the tool should wait between polls.
303 pub interval: u32,
304}
305
306/// `device_lookup`: what a user code is asking for, or null if it is not
307/// valid. Returns `Option<DeviceRequest>`.
308#[derive(Debug, Serialize, Deserialize)]
309#[serde(rename_all = "camelCase")]
310pub struct DeviceLookupArgs {
311 pub user_code: String,
312}
313
314#[derive(Debug, Serialize, Deserialize)]
315#[serde(rename_all = "camelCase")]
316pub struct DeviceRequest {
317 pub user_code: String,
318 pub client_name: String,
319}
320
321/// `device_resolve`: the signed-in person approves or denies a request.
322/// Returns `Outcome<bool>`.
323#[derive(Debug, Serialize, Deserialize)]
324#[serde(rename_all = "camelCase")]
325pub struct DeviceResolveArgs {
326 pub user_code: String,
327 pub user: User,
328 pub approve: bool,
329}
330
331/// `device_claim`: the tool asks whether its request was approved.
332#[derive(Debug, Serialize, Deserialize)]
333#[serde(rename_all = "camelCase")]
334pub struct DeviceClaimArgs {
335 pub device_code: String,
336}
337
338/// The answer to a `device_claim`.
339#[derive(Debug, Serialize, Deserialize)]
340#[serde(tag = "status", rename_all = "snake_case")]
341pub enum DeviceClaim {
342 /// Nobody has approved or denied it yet; ask again after the interval.
343 Pending,
344 Denied,
345 /// The code was never issued, has expired, or was already used.
346 Expired,
347 /// The access token, returned once.
348 Approved {
349 token: String,
350 user: User,
351 },
352}
Workspaces own repositories353
354/// A workspace: the owner of repositories, and the first segment of their
355/// URLs. A person's own space and a team's are the same thing.
356#[derive(Clone, Debug, Serialize, Deserialize)]
357#[serde(rename_all = "camelCase")]
358pub struct Workspace {
359 pub id: String,
360 pub slug: String,
361 pub name: String,
Agents as a team: lifecycle, merge queue, billing and a new shell362 /// One line saying what the workspace is for.
363 pub description: Option<String>,
Workspaces own repositories364 /// RFC 3339.
365 pub created_at: String,
366 pub member_count: u32,
Workspace names and icons, and a component kit for every control367 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
368 /// `/avatars/<avatar>`. Null means the generated letter avatar.
369 #[serde(default)]
370 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look371 /// What every member gets on each of its repositories; owners have
372 /// Admin. See [`crate::access`].
373 #[serde(default)]
374 pub base_permission: crate::access::BasePermission,
Merge branch 'worktree-agent-ad7c6d88d93adc817'375 /// Who may create its teams. See [`crate::teams::TeamCreation`].
376 #[serde(default)]
377 pub team_creation: crate::teams::TeamCreation,
Merge main (membership, two-factor, GitHub repo roles) into tokens378 /// What members may do, by GitHub's names for each
379 /// (`members_can_create_public_repositories`...), at the top level as
380 /// GitHub's organization has them. See [`crate::MemberPrivileges`].
381 #[serde(flatten)]
382 pub privileges: crate::MemberPrivileges,
383 /// Whether members and outside collaborators need two-factor
384 /// authentication to use it.
385 #[serde(default)]
386 pub two_factor_requirement_enabled: bool,
Workspaces own repositories387}
388
389#[derive(Clone, Debug, Serialize, Deserialize)]
390pub struct Member {
391 pub username: String,
392 pub role: crate::Role,
Merge main (membership, two-factor, GitHub repo roles) into tokens393 /// The roles they hold besides `role`.
394 #[serde(default)]
395 pub org_roles: Vec<crate::OrgRole>,
396 /// Whether they have two-factor authentication on. Shown to owners
397 /// only; null for anyone else.
398 #[serde(default)]
399 pub two_factor: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look400 /// Their display name, when they set one.
401 #[serde(default)]
402 pub name: Option<String>,
403 /// Their uploaded avatar: the SHA-256 of its bytes, served at
404 /// `/avatars/<avatar>`. None means the generated letter avatar.
405 #[serde(default)]
406 pub avatar: Option<String>,
Workspaces own repositories407}
408
Merge branch 'worktree-agent-a2013627e5ea4ab13'409/// Where a workspace keeps its repositories' git data: anywhere g1t
410/// stores it (the default), or in the EU only. It applies to repositories
411/// made after it is set; the repos service reads it when it places a new
412/// one (`storage_options` says whether the EU can be chosen).
413#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
414#[serde(rename_all = "lowercase")]
415pub enum DataResidency {
416 #[default]
417 Anywhere,
418 Eu,
419}
420
421impl DataResidency {
422 pub fn as_str(self) -> &'static str {
423 match self {
424 DataResidency::Anywhere => "anywhere",
425 DataResidency::Eu => "eu",
426 }
427 }
428
429 pub fn parse(text: &str) -> Option<Self> {
430 match text.trim().to_ascii_lowercase().as_str() {
431 "anywhere" => Some(DataResidency::Anywhere),
432 "eu" => Some(DataResidency::Eu),
433 _ => None,
434 }
435 }
436}
437
438/// `workspace_residency` takes [`SlugArgs`] and returns
439/// `Option<DataResidency>` (null when there is no such workspace).
440/// `set_workspace_residency`: owners only. Returns `Outcome<DataResidency>`.
441#[derive(Debug, Serialize, Deserialize)]
442pub struct SetResidencyArgs {
443 pub actor: User,
444 pub slug: String,
445 pub residency: DataResidency,
446}
447
Workspaces own repositories448/// `create_workspace`. Returns `Outcome<Workspace>`.
449#[derive(Debug, Serialize, Deserialize)]
450pub struct CreateWorkspaceArgs {
451 pub user: User,
452 pub slug: String,
453 #[serde(default)]
454 pub name: String,
455}
456
457/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
458#[derive(Debug, Serialize, Deserialize)]
459pub struct SlugArgs {
460 pub slug: String,
461}
462
Merge main (membership, two-factor, GitHub repo roles) into tokens463/// `list_members`: members only. Owners also see each member's
464/// `two_factor`. Returns `Outcome<Vec<Member>>`.
Workspaces own repositories465#[derive(Debug, Serialize, Deserialize)]
466pub struct ListMembersArgs {
467 pub slug: String,
468 pub viewer: crate::Viewer,
469}
470
Merge main (membership, two-factor, GitHub repo roles) into tokens471/// `add_member` and `remove_member`: owners only. Removing yourself is
472/// leaving (`members::LeaveWorkspaceArgs`); removing an owner is refused
473/// when they are the last. Each returns `Outcome<bool>`.
Workspaces own repositories474#[derive(Debug, Serialize, Deserialize)]
475pub struct MemberArgs {
476 pub actor: User,
477 pub slug: String,
478 pub username: String,
Merge main (membership, two-factor, GitHub repo roles) into tokens479 #[serde(default)]
480 pub surface: Option<crate::audit::Surface>,
Workspaces own repositories481}
OAuth 2.1 sign-in for MCP clients and other applications482
Agents as a team: lifecycle, merge queue, billing and a new shell483/// `update_workspace`: owners only. An empty name falls back to the slug;
484/// an empty description clears it. Returns `Outcome<Workspace>`.
485#[derive(Debug, Serialize, Deserialize)]
486pub struct UpdateWorkspaceArgs {
487 pub actor: User,
488 pub slug: String,
489 pub name: String,
490 pub description: String,
491}
492
Agents and memory, checks and conflicts, profiles, slug renames, custom domains493/// `rename_workspace`: owners only. Changes the workspace's slug, the first
494/// segment of its URLs, to `new_slug`; the display name is untouched. The
495/// old slug redirects to the new one, and is held for this workspace, for
496/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
497/// `Outcome<Workspace>`.
498///
499/// `check_workspace_rename` takes the same arguments and answers whether
500/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
501#[derive(Debug, Serialize, Deserialize)]
502#[serde(rename_all = "camelCase")]
503pub struct RenameWorkspaceArgs {
504 pub actor: User,
505 pub slug: String,
506 pub new_slug: String,
507}
508
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look509/// `delete_workspace`: owners only, and only a person. `confirm` must be
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member510/// the workspace's slug, typed out. Refused for a protected workspace
511/// ([`protected_names`]), whoever asks, and while billing cannot settle it
512/// (`close_workspace`). Everything in it goes with it at once: nobody can
513/// reach it, its tokens stop working, its pages are not found, and its
514/// repositories, projects and apps are deleted with it. It is kept for
515/// [`WORKSPACE_RESTORE_DAYS`] so g1t's staff can restore it, then purged:
516/// its memberships, access tokens and old-slug redirects go, and billing's
517/// ledger and the audit log keep its history. The slug is never given to
518/// another workspace; the person whose username it is may make a workspace
519/// of that name again once it is purged. Publishes `workspace.deleting`,
520/// and `workspace.deleted` at the purge. Returns `Outcome<bool>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look521///
522/// `check_workspace_deletion` takes the same arguments (with `confirm`
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member523/// ignored) and says what would go and whether anything stands in the way,
524/// changing nothing. Returns `Outcome<WorkspaceDeletion>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look525#[derive(Debug, Serialize, Deserialize)]
526pub struct DeleteWorkspaceArgs {
527 pub actor: User,
528 pub slug: String,
529 #[serde(default)]
530 pub confirm: String,
531 /// Where the request came in, for the audit log; g1t.sh when absent.
532 #[serde(default)]
533 pub surface: Option<crate::audit::Surface>,
534}
535
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member536/// What deleting a workspace takes with it, and what stands in the way.
537/// Nothing does when `billing` is null and it is not `protected`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look538#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
539pub struct WorkspaceDeletion {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member540 /// Its live repositories, which are deleted with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look541 pub repositories: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member542 /// Its projects, hidden with it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look543 pub projects: u32,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member544 #[serde(default)]
545 pub members: u32,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look546 /// Why billing cannot close the workspace yet, in words for its owner.
547 pub billing: Option<String>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member548 /// It can never be deleted, by anyone ([`protected_names`]).
549 #[serde(default)]
550 pub protected: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look551}
552
553impl WorkspaceDeletion {
554 pub fn blocked(&self) -> bool {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member555 self.protected || self.billing.is_some()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look556 }
557
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member558 /// Why the workspace cannot be deleted, as one sentence, or `None`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look559 pub fn reason(&self, slug: &str) -> Option<String> {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member560 if self.protected {
561 return Some(protected_refusal(slug));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look562 }
563 self.billing.clone()
564 }
565}
566
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member567/// How long a deleted workspace is kept, for staff to restore, before it is
568/// purged.
569pub const WORKSPACE_RESTORE_DAYS: u64 = 30;
570
571/// Workspaces nobody can delete, whatever identity's `PROTECTED_WORKSPACES`
572/// says: Flagon's, which runs g1t.
573pub const ALWAYS_PROTECTED: &[&str] = &["flagon-io"];
574
575/// The protected workspaces: `configured` (comma-separated slugs or
576/// workspace ids, as identity's `PROTECTED_WORKSPACES` holds them), and
577/// [`ALWAYS_PROTECTED`] whatever it says, so an empty or missing variable
578/// still protects them. Lowercased, without duplicates.
579pub fn protected_names(configured: Option<&str>) -> Vec<String> {
580 let mut names: Vec<String> = Vec::new();
581 let given = configured.unwrap_or_default().split(',');
582 for name in ALWAYS_PROTECTED.iter().copied().chain(given) {
583 let name = name.trim().to_lowercase();
584 if !name.is_empty() && !names.contains(&name) {
585 names.push(name);
586 }
587 }
588 names
589}
590
591/// Why a protected workspace is not deleted, purged or acted on.
592pub fn protected_refusal(slug: &str) -> String {
593 format!("{slug} is protected and can never be deleted.")
594}
595
596/// `admin_deleted_workspaces` takes no arguments (`{}`) and returns
597/// `Vec<DeletedWorkspace>`, newest first. Staff only.
598///
599/// A workspace an owner deleted, kept until `purge_after` for staff to
600/// restore.
601#[derive(Clone, Debug, Serialize, Deserialize)]
602#[serde(rename_all = "camelCase")]
603pub struct DeletedWorkspace {
604 pub workspace_id: String,
605 pub slug: String,
606 pub name: String,
607 /// RFC 3339.
608 pub deleted_at: String,
Merge sudo: delete an account with the workspaces it alone owns, purge each609 /// The username of the owner who deleted it, or the staff member (by
610 /// email) who deleted it with the account that was its only owner.
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member611 pub deleted_by: String,
612 /// RFC 3339: when it is purged unless restored first.
613 pub purge_after: String,
614 /// What went with it, counted when it was deleted.
615 pub went: WorkspaceDeletion,
616 /// Whether staff can still restore it.
617 pub restorable: bool,
618}
619
620/// `admin_restore_workspace` and `admin_purge_workspace`: staff restore a
621/// deleted workspace within [`WORKSPACE_RESTORE_DAYS`], or purge it now.
622/// `staff` is who, for the audit logs. Purging needs `confirm`, the slug
623/// typed out, and is refused for a protected workspace. Restoring publishes
624/// `workspace.restored`; purging, `workspace.deleted`. Both return
625/// `Outcome<bool>`.
626#[derive(Debug, Serialize, Deserialize)]
627#[serde(rename_all = "camelCase")]
628pub struct AdminDeletedWorkspaceArgs {
629 pub workspace_id: String,
630 pub staff: String,
631 #[serde(default)]
632 pub confirm: String,
633}
634
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look635/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
636/// tokens of agents at work on it are kept pointing at it. For repos'
637/// `transfer`. Returns `bool`.
638#[derive(Debug, Serialize, Deserialize)]
639pub struct TransferRepoScopesArgs {
640 pub from: crate::repos::RepoPath,
641 pub to: crate::repos::RepoPath,
642}
643
Agents and memory, checks and conflicts, profiles, slug renames, custom domains644/// How long a workspace's old slug keeps redirecting to it, and stays
645/// reserved for it, after a rename.
646pub const SLUG_HOLD_DAYS: u64 = 90;
647
648/// How long a workspace must wait between renames.
649pub const RENAME_COOLDOWN_HOURS: u64 = 24;
650
651// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
652// workspace's current slug when `slug` is one it was renamed from within
653// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
Merge branch 'worktree-agent-a8385d293d42c913a'654// is in use), or the workspace's slug when `slug` is one of its aliases.
655
656// `resolve_alias` takes `SlugArgs` and returns `Option<String>`: the slug
657// now of the workspace `slug` is an alias of, and null when it is none.
658// Aliases are set by g1t's staff only: `g1t` is Flagon, Inc.'s `flagon-io`.
659// An alias follows its workspace through renames.
660
661/// `admin_aliases` takes no arguments (`{}`) and returns
662/// `Vec<WorkspaceAlias>`, by alias. Staff only.
663///
664/// A name staff point at a workspace, so that its addresses (pages, git,
665/// the API, packages) lead to the workspace under its own name.
666#[derive(Clone, Debug, Serialize, Deserialize)]
667#[serde(rename_all = "camelCase")]
668pub struct WorkspaceAlias {
669 pub alias: String,
670 pub workspace_id: String,
671 /// The workspace's slug and name now.
672 pub workspace: String,
673 pub workspace_name: String,
674 /// Why it exists, as staff wrote it.
675 pub note: String,
676 /// The staff member who set it, or `migration`.
677 pub created_by: String,
678 /// RFC 3339.
679 pub created_at: String,
680}
681
682/// `admin_set_alias`: points `alias` at the workspace whose slug is
683/// `workspace`. The alias must have a namespace's shape, must not be one of
684/// the site's routes, and must not be anyone's username, a workspace's slug
685/// (deleted, or held after a rename) or another alias. `note` is required:
686/// it is the reason, kept with the alias and in sudo's audit log. Staff
687/// only. Returns `Outcome<WorkspaceAlias>`.
688#[derive(Debug, Serialize, Deserialize)]
689#[serde(rename_all = "camelCase")]
690pub struct AdminSetAliasArgs {
691 pub alias: String,
692 pub workspace: String,
693 pub note: String,
694 pub staff: String,
695}
696
697/// `admin_remove_alias`: the alias stops leading anywhere, and the name is
698/// nobody's again unless it is reserved. `reason` goes in sudo's audit log.
699/// Staff only. Returns `Outcome<bool>`.
700#[derive(Debug, Serialize, Deserialize)]
701#[serde(rename_all = "camelCase")]
702pub struct AdminRemoveAliasArgs {
703 pub alias: String,
704 pub reason: String,
705 pub staff: String,
706}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains707
Workspace names and icons, and a component kit for every control708/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
709/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
710/// the icon. Returns `Outcome<Workspace>`.
711#[derive(Debug, Serialize, Deserialize)]
712pub struct SetWorkspaceAvatarArgs {
713 pub actor: User,
714 pub slug: String,
715 pub image: Option<String>,
716}
717
718/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
719/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
720#[derive(Debug, Serialize, Deserialize)]
721pub struct SetUserAvatarArgs {
722 pub user: User,
723 pub image: Option<String>,
724}
725
726/// The largest avatar that can be uploaded, in bytes.
727pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
728
Agents as a team: lifecycle, merge queue, billing and a new shell729/// `list_workspace_tokens`: members only. Returns
730/// `Outcome<Vec<AccessToken>>`.
731#[derive(Debug, Serialize, Deserialize)]
732pub struct WorkspaceTokensArgs {
733 pub slug: String,
734 pub viewer: crate::Viewer,
735}
736
737/// `create_workspace_token`: owners only. The token belongs to the
738/// workspace, acts as it, and keeps working when the member who made it
739/// leaves. Returns `Outcome<CreatedAccessToken>`.
740#[derive(Debug, Serialize, Deserialize)]
741pub struct CreateWorkspaceTokenArgs {
742 pub actor: User,
743 pub slug: String,
744 pub name: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step745 /// Its scopes; null for full access.
746 #[serde(default)]
747 pub scopes: Option<Vec<String>>,
748 /// When set, the token stops working after this many seconds. It is
749 /// listed with the workspace's tokens either way. Null: no expiry.
750 #[serde(default)]
751 pub ttl_seconds: Option<u64>,
Fine-grained personal tokens, workspace token rules and approvals in identity752 /// Admin on the workspace's repositories, rather than Write: given by
753 /// the owner on purpose, when making it.
754 #[serde(default)]
755 pub admin: bool,
Agents as a team: lifecycle, merge queue, billing and a new shell756}
757
758/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
759#[derive(Debug, Serialize, Deserialize)]
760pub struct RemoveWorkspaceTokenArgs {
761 pub actor: User,
762 pub slug: String,
763 pub id: String,
764}
765
OAuth 2.1 sign-in for MCP clients and other applications766/// `oauth_authorize`: the signed-in person approved an application. The
767/// caller has checked the client and that it may be redirected to
768/// `redirect_uri`. Returns `OAuthCode`.
769#[derive(Debug, Serialize, Deserialize)]
770#[serde(rename_all = "camelCase")]
771pub struct OAuthAuthorizeArgs {
772 pub user: User,
773 pub client_id: String,
774 /// Shown wherever the application's access is listed.
775 pub client_name: String,
776 pub redirect_uri: String,
777 /// PKCE challenge, method S256.
778 pub code_challenge: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step779 /// What the person granted, as `resource:level`. Null: full access.
780 #[serde(default)]
781 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications782}
783
784#[derive(Debug, Serialize, Deserialize)]
785pub struct OAuthCode {
786 pub code: String,
787}
788
789/// `oauth_exchange`: redeems an authorization code.
790/// Returns `Outcome<OAuthTokens>`.
791#[derive(Debug, Serialize, Deserialize)]
792#[serde(rename_all = "camelCase")]
793pub struct OAuthExchangeArgs {
794 pub code: String,
795 pub code_verifier: String,
796 pub client_id: String,
797 pub redirect_uri: String,
798}
799
800/// `oauth_refresh`: trades a refresh token for new tokens.
801/// Returns `Outcome<OAuthTokens>`.
802#[derive(Debug, Serialize, Deserialize)]
803#[serde(rename_all = "camelCase")]
804pub struct OAuthRefreshArgs {
805 pub refresh_token: String,
806 pub client_id: String,
807}
808
809#[derive(Debug, Serialize, Deserialize)]
810#[serde(rename_all = "camelCase")]
811pub struct OAuthTokens {
812 pub access_token: String,
813 /// Works once; using it returns the next one.
814 pub refresh_token: String,
815 /// Seconds until the access token stops working.
816 pub expires_in: u64,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step817 /// The scopes granted, space-separated, or `*` for full access.
818 #[serde(default)]
819 pub scope: Option<String>,
OAuth 2.1 sign-in for MCP clients and other applications820}
821
822/// An application a person has signed in to. Listed by `list_oauth_grants`
823/// and ended by `revoke_oauth_grant`.
824#[derive(Debug, Serialize, Deserialize)]
825#[serde(rename_all = "camelCase")]
826pub struct OAuthGrant {
827 pub id: String,
828 pub client_name: String,
829 /// RFC 3339.
830 pub created_at: String,
831 /// RFC 3339.
832 pub last_used_at: String,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step833 /// What the person granted. Null: full access.
834 #[serde(default)]
835 pub scopes: Option<Vec<String>>,
836 /// Signed in before applications were given scopes: full access until
837 /// someone narrows it.
838 #[serde(default)]
839 pub legacy: bool,
840}
841
842/// `update_oauth_grant`: changes what an application the person signed in
843/// to may do, at once and when it refreshes. Returns `Outcome<OAuthGrant>`.
844#[derive(Debug, Serialize, Deserialize)]
845pub struct UpdateOAuthGrantArgs {
846 pub user: User,
847 pub id: String,
848 #[serde(default)]
849 pub scopes: Option<Vec<String>>,
OAuth 2.1 sign-in for MCP clients and other applications850}
Agents as a team: lifecycle, merge queue, billing and a new shell851
852
853/// What an agent's token may do: these operations, in this repository.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API854#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
Agents as a team: lifecycle, merge queue, billing and a new shell855pub struct AgentScope {
856 pub repo: crate::repos::RepoPath,
857 /// API and MCP operation names, such as `create_issue`.
858 pub operations: Vec<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API859 /// Set on a run credential: the run it belongs to, and what it may do
860 /// with git. See [`crate::credentials`].
861 #[serde(default, skip_serializing_if = "Option::is_none")]
862 pub run: Option<crate::credentials::RunBinding>,
Agents as a team: lifecycle, merge queue, billing and a new shell863}
864
865/// `create_agent_token`: a token for a g1t agent working on someone's
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent866/// behalf. It acts as `g1t`, a member of the repository's workspace,
Agents as a team: lifecycle, merge queue, billing and a new shell867/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
868#[derive(Debug, Serialize, Deserialize)]
869#[serde(rename_all = "camelCase")]
870pub struct CreateAgentTokenArgs {
871 /// The person the agent works for; the token is recorded as theirs.
872 pub on_behalf_of: User,
873 pub scope: AgentScope,
874 pub ttl_seconds: u64,
875}
876
877// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
878// agent's token may do, or null for any other token.
879
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent880/// The id g1t's agent acts under. Only ever stored, never shown: it keeps
881/// the agent's work apart from g1t's own ([`crate::system::ID`]) where
882/// that matters, such as whether its approval counts.
Agents as a team: lifecycle, merge queue, billing and a new shell883pub const AGENT_ID: &str = "usr_g1t_agent";
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent884/// The name g1t's agent is shown by: g1t's own, [`crate::system::USERNAME`].
885/// Everything it does, people see g1t do.
886pub const AGENT_NAME: &str = crate::system::USERNAME;
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace887
888// --- Staff ---------------------------------------------------------------
889//
890// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
891// membership: only sudo calls them, over its service binding, after it has
892// verified a Cloudflare Access sign-in and its staff list. Nothing a
893// customer can reach should ever forward to them.
894
895/// `notify_owners`: emails a short notice, with one link, to each owner of
896/// a workspace with a confirmed address. Called by other services (billing
897/// warns owners near their usage limit), never on a person's behalf.
898/// Returns how many were sent.
899#[derive(Clone, Debug, Serialize, Deserialize)]
900pub struct NotifyOwnersArgs {
901 pub workspace: String,
902 pub subject: String,
903 /// One or two sentences: what happened and what it means.
904 pub intro: String,
905 /// The button's words, such as `Open billing`.
906 pub action: String,
907 /// Where the button goes; must be on g1t.sh.
908 pub link: String,
909 /// Small print: why they got it.
910 pub footer: String,
911}
912
913/// `admin_workspaces`: every workspace, newest first, at most
914/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
915/// an owner's username or email contains `query`. Returns
916/// `Vec<AdminWorkspace>`. Staff only.
917#[derive(Debug, Default, Serialize, Deserialize)]
918pub struct AdminWorkspacesArgs {
919 #[serde(default)]
920 pub query: Option<String>,
921}
922
923/// The most workspaces one `admin_workspaces` call returns.
924pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
925
926/// An owner of a workspace, as staff see them.
927#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
928pub struct AdminOwner {
929 pub username: String,
930 pub email: Option<String>,
931}
932
933/// A workspace as staff see it: who owns it and how many belong to it.
934#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
935#[serde(rename_all = "camelCase")]
936pub struct AdminWorkspace {
937 pub slug: String,
938 pub name: String,
939 /// RFC 3339.
940 pub created_at: String,
941 pub owners: Vec<AdminOwner>,
942 pub member_count: u32,
943}
944
945/// `admin_workspace`: one workspace with every member, or null. Takes
946/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
947#[derive(Clone, Debug, Serialize, Deserialize)]
948#[serde(rename_all = "camelCase")]
949pub struct AdminWorkspaceDetail {
950 pub slug: String,
951 pub name: String,
952 pub description: Option<String>,
953 /// RFC 3339.
954 pub created_at: String,
955 /// Owners first, then by username.
956 pub members: Vec<AdminMember>,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member957 /// It can never be deleted ([`protected_names`]).
958 #[serde(default)]
959 pub protected: bool,
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace960}
961
962/// A member of a workspace, as staff see them.
963#[derive(Clone, Debug, Serialize, Deserialize)]
964pub struct AdminMember {
965 pub username: String,
966 pub email: Option<String>,
967 pub role: crate::Role,
968 /// When they joined the workspace. RFC 3339.
969 pub joined: String,
970}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains971
972// --- Profiles ------------------------------------------------------------
973//
974// A person's public page at `g1t.sh/u/<username>`. Everything in a
975// `Profile` is shown to anyone, signed in or not; an email address never is.
976
977/// The most characters each profile field takes.
978pub const MAX_PROFILE_NAME: usize = 80;
979pub const MAX_PROFILE_BIO: usize = 160;
980pub const MAX_PROFILE_LOCATION: usize = 80;
981pub const MAX_PROFILE_WEBSITE: usize = 200;
982pub const MAX_PROFILE_PRONOUNS: usize = 40;
Merge leftovers: plan activity filtered in the query, pushes counted by account, ghost during the deletion window, profile time zones (identity 0039)983pub const MAX_PROFILE_TIMEZONE: usize = 64;
Agents and memory, checks and conflicts, profiles, slug renames, custom domains984
985/// What anyone may see about a person.
986#[derive(Clone, Debug, Default, Serialize, Deserialize)]
987#[serde(rename_all = "camelCase")]
988pub struct Profile {
989 pub username: String,
990 /// The name they go by, if they gave one.
991 pub name: Option<String>,
992 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
993 pub bio: Option<String>,
994 pub location: Option<String>,
995 /// An `https://` address.
996 pub website: Option<String>,
997 pub pronouns: Option<String>,
Merge leftovers: plan activity filtered in the query, pushes counted by account, ghost during the deletion window, profile time zones (identity 0039)998 /// The time zone they are in, an IANA name such as `America/Denver`.
999 #[serde(default)]
1000 pub timezone: Option<String>,
Agents and memory, checks and conflicts, profiles, slug renames, custom domains1001 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
1002 pub avatar: Option<String>,
1003 /// When the account was made. RFC 3339.
1004 pub created_at: String,
1005}
1006
1007// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
1008// an account that does not exist.
1009
1010/// `update_profile`: a person changes their own profile. Every field is
1011/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
1012#[derive(Debug, Default, Serialize, Deserialize)]
1013#[serde(rename_all = "camelCase")]
1014pub struct UpdateProfileArgs {
1015 pub actor: User,
1016 #[serde(default)]
1017 pub name: String,
1018 #[serde(default)]
1019 pub bio: String,
1020 #[serde(default)]
1021 pub location: String,
1022 #[serde(default)]
1023 pub website: String,
1024 #[serde(default)]
1025 pub pronouns: String,
Merge leftovers: plan activity filtered in the query, pushes counted by account, ghost during the deletion window, profile time zones (identity 0039)1026 /// An IANA time zone name, such as `America/Denver`.
1027 #[serde(default)]
1028 pub timezone: String,
Agents and memory, checks and conflicts, profiles, slug renames, custom domains1029}
1030
1031/// `profile_workspaces`: the workspaces shown on a person's profile, as
1032/// `viewer` may see them. A membership is shown only when it is no secret
1033/// from the viewer: a workspace the viewer belongs to as well, or one of
1034/// `public`, the workspaces the caller found the person has made a public
1035/// project in (whose page shows that already). Returns
1036/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
1037#[derive(Debug, Serialize, Deserialize)]
1038pub struct ProfileWorkspacesArgs {
1039 pub username: String,
1040 pub viewer: crate::Viewer,
1041 #[serde(default)]
1042 pub public: Vec<String>,
1043}
1044
1045/// A workspace on a person's profile.
1046#[derive(Clone, Debug, Serialize, Deserialize)]
1047pub struct ProfileWorkspace {
1048 pub slug: String,
1049 pub name: String,
1050 pub avatar: Option<String>,
1051}
Search across all of g1t, Explore, and a command palette1052
1053/// `directory`: every account or every workspace, as their public pages
1054/// show them, a page at a time in name order. For services that index
1055/// them, such as search; nothing private is in it. Returns
1056/// `DirectoryPage`.
1057#[derive(Debug, Default, Serialize, Deserialize)]
1058pub struct DirectoryArgs {
1059 /// `user` or `workspace`.
1060 pub kind: String,
1061 /// Names after this one.
1062 #[serde(default)]
1063 pub after: Option<String>,
1064 pub limit: u32,
1065}
1066
1067/// One account or workspace in the directory.
1068#[derive(Clone, Debug, Serialize, Deserialize)]
1069#[serde(rename_all = "camelCase")]
1070pub struct DirectoryEntry {
1071 /// The account's or workspace's id.
1072 pub id: String,
1073 /// A username or a workspace's slug.
1074 pub slug: String,
1075 /// A person's display name or a workspace's name.
1076 pub name: Option<String>,
1077 /// A person's bio or a workspace's description.
1078 pub bio: Option<String>,
1079 pub avatar: Option<String>,
1080 /// RFC 3339.
1081 pub created_at: String,
1082}
1083
1084#[derive(Clone, Debug, Default, Serialize, Deserialize)]
1085pub struct DirectoryPage {
1086 pub entries: Vec<DirectoryEntry>,
1087 /// Where the next page starts; null on the last.
1088 pub next: Option<String>,
1089}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1090
1091// --- Invites ---------------------------------------------------------------
1092//
1093// While registration is invite-only, every new account (with a password or
1094// through GitHub) needs an invite code. Each person may have
1095// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
1096// to a workspace, whose owners share them. Inviting an email with no
1097// account into a workspace makes an invite bound to that address, which
1098// registers and joins in one step. See services/identity/src/invites.rs.
1099
1100/// Whether anyone may make an account, or only someone with an invite. Set
1101/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
1102/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
1103#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1104#[serde(rename_all = "snake_case")]
1105pub enum RegistrationMode {
1106 #[default]
1107 Invite,
1108 Open,
1109}
1110
1111impl RegistrationMode {
1112 pub fn parse(text: Option<&str>) -> RegistrationMode {
1113 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
1114 Some("open") => RegistrationMode::Open,
1115 _ => RegistrationMode::Invite,
1116 }
1117 }
1118}
1119
1120/// How many invites a person may have out at once, unless identity's
1121/// `INVITES_PER_USER` var says otherwise.
1122pub const INVITES_PER_USER: u32 = 5;
1123
1124/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
1125/// otherwise.
1126pub const INVITE_TTL_DAYS: u64 = 30;
1127
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)1128/// Where an invite stands. Only a pending invite can be used. A pending
1129/// invite can be revoked, and so can one awaiting confirmation. An expired
1130/// or revoked invite that was never used gives its inviter the invite back.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1131#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1132#[serde(rename_all = "snake_case")]
1133pub enum InviteStatus {
1134 Pending,
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)1135 /// Used to make an account that has not confirmed its email address
1136 /// yet. The code is spent; the workspace (or repository) it gives is
1137 /// joined when the address is confirmed, unless it is revoked first.
1138 AwaitingConfirmation,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1139 Redeemed,
1140 Expired,
1141 Revoked,
1142}
1143
1144/// What using an invite does.
1145#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1146#[serde(rename_all = "snake_case")]
1147pub enum InviteKind {
1148 /// Makes a new account, and joins `workspace` when one is set.
1149 Account,
1150 /// An existing account joins `workspace`. Never makes an account.
1151 Workspace,
1152}
1153
1154/// Whose allowance an invite uses.
1155#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1156#[serde(rename_all = "snake_case")]
1157pub enum InviteCharge {
1158 /// Its inviter's own.
1159 User,
1160 /// The workspace's, granted by staff and shared by its owners.
1161 Workspace,
1162 /// Nobody's: staff minted it, or it invites an existing account.
1163 None,
1164}
1165
1166/// One invite, as the person who made it sees it.
1167#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1168#[serde(rename_all = "camelCase")]
1169pub struct Invite {
1170 pub id: String,
1171 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
1172 /// is made, and afterwards to whoever made it while it is pending.
1173 /// Null otherwise.
1174 pub code: Option<String>,
1175 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
1176 pub hint: String,
1177 /// Only an account with this address can use it. Null: anyone with
1178 /// the code.
1179 pub email: Option<String>,
1180 pub kind: InviteKind,
1181 /// The workspace it joins, by slug.
1182 pub workspace: Option<String>,
1183 pub status: InviteStatus,
1184 pub charged_to: InviteCharge,
1185 /// Who made it, by username. Null when g1t staff did.
1186 pub invited_by: Option<String>,
1187 /// The account that used it, by username.
1188 pub redeemed_by: Option<String>,
1189 /// RFC 3339.
1190 pub created_at: String,
1191 /// RFC 3339.
1192 pub expires_at: String,
1193 /// RFC 3339.
1194 pub redeemed_at: Option<String>,
1195 /// RFC 3339.
1196 pub revoked_at: Option<String>,
1197 /// The staff member who minted it. Only in staff views.
1198 #[serde(default, skip_serializing_if = "Option::is_none")]
1199 pub staff: Option<String>,
1200}
1201
1202/// How many invites someone may have out, and how many they have.
1203#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
1204pub struct Allowance {
1205 /// Null: no limit.
1206 pub limit: Option<u32>,
1207 /// Pending and used invites; revoked and expired ones are not counted.
1208 pub used: u32,
1209 /// Null: no limit.
1210 pub remaining: Option<u32>,
1211}
1212
1213impl Allowance {
1214 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
1215 Allowance {
1216 limit,
1217 used,
1218 remaining: limit.map(|limit| limit.saturating_sub(used)),
1219 }
1220 }
1221
1222 pub fn exhausted(&self) -> bool {
1223 self.remaining == Some(0)
1224 }
1225}
1226
1227/// A workspace's shared invites, for one of its owners.
1228#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
1229pub struct WorkspaceAllowance {
1230 pub slug: String,
1231 pub allowance: Allowance,
1232}
1233
1234/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
1235/// and what they have left. Returns `InvitesOverview`.
1236#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1237pub struct InvitesOverview {
1238 pub mode: RegistrationMode,
1239 pub allowance: Allowance,
1240 /// Workspaces the person owns that staff granted invites to.
1241 pub workspaces: Vec<WorkspaceAllowance>,
1242 pub invites: Vec<Invite>,
1243}
1244
1245/// `create_invite`: a person makes an invite, optionally for one email
1246/// address. People only; never an agent or a workspace's token, and not
1247/// before their email is confirmed. Uses one of the person's invites, or,
1248/// with `workspace`, one of the invites staff granted that workspace (its
1249/// owners only). Emails the address when one is given. Returns
1250/// `Outcome<Invite>`, with the code.
1251///
1252/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
1253/// invite; a workspace's owners may revoke one made for the workspace.
1254/// The invite comes back to whoever it was charged to. Returns
1255/// `Outcome<Invite>`.
1256#[derive(Debug, Serialize, Deserialize)]
1257pub struct CreateInviteArgs {
1258 pub user: User,
1259 #[serde(default)]
1260 pub email: Option<String>,
1261 /// Use this workspace's granted invites, by slug.
1262 #[serde(default)]
1263 pub workspace: Option<String>,
1264 /// Where the request came in, for the audit log; g1t.sh when absent.
1265 #[serde(default)]
1266 pub surface: Option<crate::audit::Surface>,
1267}
1268
1269/// `check_invite`: what an invite code is for, before using it. Returns
1270/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1271/// expired gets the same answer, so codes cannot be probed. With
1272/// `any_status`, a real code that can no longer be used is described
1273/// instead (its `status` says why), so the page can say whom to ask for a
1274/// new one; an unknown code still gets the one answer.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1275#[derive(Debug, Serialize, Deserialize)]
1276pub struct InviteCodeArgs {
1277 pub code: String,
1278 /// Who is asking, such as the visitor's IP address, for rate limits.
1279 #[serde(default)]
1280 pub client: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1281 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
1282 #[serde(default)]
1283 pub viewer: Option<User>,
1284 #[serde(default)]
1285 pub any_status: bool,
Merge invite emails that confirm the address: the emailed link carries a proof only that email has, so signing up from it needs no code; shared links and typed codes still confirm1286 /// The `proof` from the invite email's link, if the page was opened
1287 /// from it: sets `InvitePreview::email_proven`.
1288 #[serde(default)]
1289 pub email_proof: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1290}
1291
1292/// Someone shown on an invite.
1293#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1294pub struct InviteFrom {
1295 pub username: String,
1296 pub name: Option<String>,
1297 pub avatar: Option<String>,
1298}
1299
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1300/// A repository an invite code was sent with: using the code accepts the
1301/// invitation to collaborate on it.
1302#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1303pub struct InviteRepository {
1304 /// `workspace/repo`.
1305 pub name: String,
1306 /// The role it gives, such as `write`.
1307 pub role: String,
1308}
1309
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1310/// What a valid invite code is for.
1311#[derive(Clone, Debug, Serialize, Deserialize)]
1312#[serde(rename_all = "camelCase")]
1313pub struct InvitePreview {
1314 pub kind: InviteKind,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1315 /// Pending, unless `any_status` asked about a code that is spent.
1316 pub status: InviteStatus,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1317 /// Null when g1t staff sent it.
1318 pub invited_by: Option<InviteFrom>,
1319 pub workspace: Option<ProfileWorkspace>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1320 /// The repository it accepts an invitation to, if it was sent with one.
1321 pub repository: Option<InviteRepository>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1322 /// The address it is for, partly hidden, such as `a•••@example.com`.
1323 pub email: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1324 /// The address in full, while it is pending: whoever holds the code
1325 /// was sent it there. Fills in and locks the sign-up form.
1326 pub address: Option<String>,
1327 /// Whether the address it is for has a g1t account already, so the
1328 /// page asks them to sign in rather than sign up.
1329 pub has_account: bool,
1330 /// With a viewer: whether the invite is theirs (it is for one of their
1331 /// confirmed addresses, or they used it). Null without a viewer or,
1332 /// for a pending invite, when it is for anyone with the code.
1333 pub for_viewer: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1334 /// RFC 3339.
1335 pub expires_at: String,
Merge shared invite links: label, uses, expiry, domains; joined through recorded (identity 0038)1336 /// For a shared invite link ([`SharedInvite`]): the group it was made
1337 /// for, such as `Cloudflare judges`. Not secret; the sign-up page shows
1338 /// it. Null for a one-person invite.
1339 #[serde(default)]
1340 pub shared_label: Option<String>,
1341 /// For a shared invite link limited to some email domains: those
1342 /// domains, such as `["cloudflare.com"]`. Empty for any address.
1343 #[serde(default)]
1344 pub shared_domains: Vec<String>,
Merge invite emails that confirm the address: the emailed link carries a proof only that email has, so signing up from it needs no code; shared links and typed codes still confirm1345 /// Whether `email_proof` was this pending invite's own, from the email
1346 /// it was sent in: the account made with it starts with `address`
1347 /// confirmed. False without a proof, with a wrong one, and for an
1348 /// invite bound to no address.
1349 #[serde(default)]
1350 pub email_proven: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1351}
1352
1353/// `accept_invite`: a signed-in person uses a workspace invite made for
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1354/// their confirmed address, and joins the workspace, or an invite sent with
1355/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1356/// workspace's slug, or `workspace/repo`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1357#[derive(Debug, Serialize, Deserialize)]
1358pub struct AcceptInviteArgs {
1359 pub user: User,
1360 pub code: String,
1361}
1362
1363/// `invite_member`: an owner invites an email address into a workspace.
1364/// It always makes an invite bound to that address and emails it, so the
1365/// answer never says whether the address has an account. Without one, the
1366/// invite registers and joins in one step, and uses one of the workspace's
1367/// granted invites or else one of the owner's own. With one, it costs
1368/// nothing. Returns `Outcome<Invite>`, with the code.
1369#[derive(Debug, Serialize, Deserialize)]
1370pub struct InviteMemberArgs {
1371 pub actor: User,
1372 pub slug: String,
1373 pub email: String,
1374 /// Where the request came in, for the audit log; g1t.sh when absent.
1375 #[serde(default)]
1376 pub surface: Option<crate::audit::Surface>,
1377}
1378
1379/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1380/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1381///
1382/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1383#[derive(Debug, Serialize, Deserialize)]
1384pub struct WorkspaceInviteArgs {
1385 pub actor: User,
1386 pub slug: String,
1387 pub id: String,
1388}
1389
1390/// `request_access`: someone without an invite asks for one. Kept on the
1391/// waitlist, one entry per address. Answers the same way whether or not
1392/// the address is already on it. Returns `Outcome<bool>`.
1393#[derive(Debug, Default, Serialize, Deserialize)]
1394pub struct RequestAccessArgs {
1395 pub email: String,
1396 /// What they will build, if they said.
1397 #[serde(default)]
1398 pub about: String,
1399 /// Who is asking, such as the visitor's IP address, for rate limits.
1400 #[serde(default)]
1401 pub client: Option<String>,
1402}
1403
1404/// The most characters `RequestAccessArgs::about` keeps.
1405pub const MAX_WAITLIST_ABOUT: usize = 1000;
1406
1407// `registration` takes `{}` and returns `RegistrationMode`.
1408
1409// --- Invites, staff only ---
1410
1411#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1412#[serde(rename_all = "snake_case")]
1413pub enum WaitlistStatus {
1414 Waiting,
1415 Invited,
1416 Dismissed,
1417}
1418
1419impl WaitlistStatus {
1420 pub fn as_str(self) -> &'static str {
1421 match self {
1422 WaitlistStatus::Waiting => "waiting",
1423 WaitlistStatus::Invited => "invited",
1424 WaitlistStatus::Dismissed => "dismissed",
1425 }
1426 }
1427}
1428
1429/// Someone who asked for access.
1430#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1431#[serde(rename_all = "camelCase")]
1432pub struct WaitlistEntry {
1433 pub id: String,
1434 pub email: String,
1435 pub about: Option<String>,
1436 pub status: WaitlistStatus,
1437 pub invite_id: Option<String>,
1438 pub decided_by: Option<String>,
1439 /// RFC 3339.
1440 pub decided_at: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1441 /// What staff wrote when approving; it went in the invite email.
1442 #[serde(default)]
1443 pub note: Option<String>,
1444 /// The account made with the invite, once it was used.
1445 #[serde(default)]
1446 pub joined_as: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1447 /// When they first asked. RFC 3339.
1448 pub created_at: String,
1449 /// When they last asked. RFC 3339.
1450 pub updated_at: String,
1451}
1452
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1453/// `admin_waitlist`: the waitlist, newest first, at most
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1454/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1455///
1456/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1457/// still waiting, for sudo's navigation.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1458#[derive(Debug, Default, Serialize, Deserialize)]
1459pub struct AdminWaitlistArgs {
1460 /// Part of an email address or of what they said.
1461 #[serde(default)]
1462 pub query: Option<String>,
1463 /// Null: every status.
1464 #[serde(default)]
1465 pub status: Option<WaitlistStatus>,
1466}
1467
1468/// The most rows one staff listing of invites or the waitlist returns.
1469pub const ADMIN_INVITES_LIMIT: usize = 500;
1470
1471/// `admin_decide_waitlist`: approving mints an invite bound to the
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1472/// address, charged to nobody, and emails it, with `note` if given;
1473/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1474#[derive(Debug, Serialize, Deserialize)]
1475pub struct AdminDecideWaitlistArgs {
1476 pub id: String,
1477 pub approve: bool,
1478 /// The staff member, by email.
1479 pub staff: String,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1480 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1481 #[serde(default)]
1482 pub note: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1483}
1484
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1485/// The most characters an approval's note keeps.
1486pub const MAX_WAITLIST_NOTE: usize = 500;
1487
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1488/// `admin_invites`: every invite, newest first, at most
1489/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1490/// `query`, or whose email, inviter or redeemer contains it. Returns
1491/// `Vec<Invite>`.
1492#[derive(Debug, Default, Serialize, Deserialize)]
1493pub struct AdminInvitesArgs {
1494 #[serde(default)]
1495 pub query: Option<String>,
1496}
1497
1498/// `admin_revoke_invite`: revokes any pending invite. Returns
1499/// `Outcome<Invite>`.
1500#[derive(Debug, Serialize, Deserialize)]
1501pub struct AdminRevokeInviteArgs {
1502 pub id: String,
1503 pub staff: String,
1504}
1505
1506/// `admin_mint_invite`: staff make an invite that uses nobody's
1507/// allowance, optionally bound to (and emailed to) an address. Returns
1508/// `Outcome<Invite>`, with the code.
1509#[derive(Debug, Serialize, Deserialize)]
1510pub struct AdminMintInviteArgs {
1511 #[serde(default)]
1512 pub email: Option<String>,
1513 pub staff: String,
1514}
1515
1516/// Who staff grant invites to.
1517#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1518#[serde(rename_all = "snake_case")]
1519pub enum GrantTarget {
1520 User,
1521 Workspace,
1522}
1523
1524impl GrantTarget {
1525 pub fn as_str(self) -> &'static str {
1526 match self {
1527 GrantTarget::User => "user",
1528 GrantTarget::Workspace => "workspace",
1529 }
1530 }
1531}
1532
1533/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1534/// slug) `amount` more invites; a negative amount takes some back. Returns
1535/// `Outcome<Allowance>`: theirs afterwards.
1536#[derive(Debug, Serialize, Deserialize)]
1537pub struct AdminGrantInvitesArgs {
1538 pub target: GrantTarget,
1539 pub name: String,
1540 pub amount: i32,
1541 #[serde(default)]
1542 pub note: String,
1543 pub staff: String,
1544}
1545
1546/// The most invites one grant gives or takes back.
1547pub const MAX_INVITE_GRANT: i32 = 1000;
1548
1549/// Invites staff granted.
1550#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1551#[serde(rename_all = "camelCase")]
1552pub struct InviteGrant {
1553 pub amount: i32,
1554 pub note: Option<String>,
1555 pub granted_by: String,
1556 /// RFC 3339.
1557 pub created_at: String,
1558}
1559
1560/// Someone a person invited, and whom they invited in turn.
1561#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1562#[serde(rename_all = "camelCase")]
1563pub struct InviteTreeNode {
1564 pub username: String,
1565 /// When they used the invite. RFC 3339.
1566 pub joined_at: String,
1567 pub invited: Vec<InviteTreeNode>,
1568}
1569
1570/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1571/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1572///
1573/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1574/// invites, grants and invites. Returns `Option<InviteTree>` with
1575/// `username` the slug and no `invited_by`.
1576#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1577#[serde(rename_all = "camelCase")]
1578pub struct InviteTree {
1579 pub username: String,
1580 /// Who invited them, then who invited that person, and so on. Empty
1581 /// for an account made without an invite.
1582 pub invited_by: Vec<String>,
1583 /// The staff member who minted their invite, when staff did.
1584 pub staff: Option<String>,
1585 pub allowance: Allowance,
1586 pub grants: Vec<InviteGrant>,
1587 /// Their invites, newest first.
1588 pub invites: Vec<Invite>,
1589 /// Whom they invited, three levels down.
1590 pub invited: Vec<InviteTreeNode>,
Merge shared invite links: label, uses, expiry, domains; joined through recorded (identity 0038)1591 /// The shared invite link the account was made with, if it was.
1592 #[serde(default)]
1593 pub shared: Option<SharedInviteSource>,
1594}
1595
1596// --- Shared invite links, staff only ---
1597//
1598// One link for a group (a conference's judges, a post, a community): up
1599// to `max_uses` new accounts, until it expires or staff revoke it,
1600// optionally only for addresses at some domains. Each use makes a new
1601// account, which then makes its own workspace; a shared link never joins
1602// anyone to an existing workspace, and uses nobody's allowance. Its code
1603// looks and is stored like any invite code (only a hash, and a sealed copy
1604// staff can copy again while it is live); the link is
1605// `https://g1t.sh/register?invite=<code>`. See
1606// services/identity/src/shared_invites.rs.
1607
1608/// How long a shared invite link works when staff give no date.
1609pub const SHARED_INVITE_TTL_DAYS: u64 = 14;
1610/// The furthest ahead a shared invite link's last day may be set.
1611pub const SHARED_INVITE_MAX_DAYS: u64 = 365;
1612/// The most accounts one shared invite link makes.
1613pub const MAX_SHARED_INVITE_USES: u32 = 1000;
1614/// The most characters a shared invite link's label keeps.
1615pub const MAX_SHARED_INVITE_LABEL: usize = 80;
1616/// The most email domains one shared invite link may be limited to.
1617pub const MAX_SHARED_INVITE_DOMAINS: usize = 10;
1618
1619/// Where a shared invite link stands. Only a live one makes accounts.
1620#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1621#[serde(rename_all = "snake_case")]
1622pub enum SharedInviteStatus {
1623 Live,
1624 /// Every use is taken.
1625 UsedUp,
1626 Expired,
1627 Revoked,
1628}
1629
1630/// The shared invite link an account was made with.
1631#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
1632pub struct SharedInviteSource {
1633 pub id: String,
1634 pub label: String,
1635}
1636
1637/// An account made with a shared invite link.
1638#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1639#[serde(rename_all = "camelCase")]
1640pub struct SharedInviteAccount {
1641 /// Null once the account is purged.
1642 pub username: Option<String>,
1643 /// When it was made with the link. RFC 3339.
1644 pub joined_at: String,
1645}
1646
1647/// One shared invite link, as staff see it.
1648#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1649#[serde(rename_all = "camelCase")]
1650pub struct SharedInvite {
1651 /// `sinv_…`.
1652 pub id: String,
1653 /// Whom it is for, such as `Cloudflare judges`.
1654 pub label: String,
1655 /// The code, while it is live (and IDENTITY_KEY is set).
1656 pub code: Option<String>,
1657 /// The code's first group, such as `g1t-k7m2`.
1658 pub hint: String,
1659 pub max_uses: u32,
1660 /// Accounts made with it so far.
1661 pub uses: u32,
1662 /// Only addresses at these domains may use it; empty for any.
1663 pub domains: Vec<String>,
1664 pub status: SharedInviteStatus,
1665 /// The staff member who made it, by email.
1666 pub staff: String,
1667 /// RFC 3339.
1668 pub created_at: String,
1669 /// RFC 3339.
1670 pub expires_at: String,
1671 pub revoked_at: Option<String>,
1672 pub revoked_by: Option<String>,
1673 /// The accounts made with it, oldest first.
1674 pub accounts: Vec<SharedInviteAccount>,
1675}
1676
1677/// `admin_shared_invites` takes `{}`: shared invite links, newest first,
1678/// at most 200, each with the accounts it made. Returns
1679/// `Vec<SharedInvite>`.
1680///
1681/// `admin_create_shared_invite`: staff make a shared invite link. Recorded
1682/// in sudo's audit log. Returns `Outcome<SharedInvite>`, with the code.
1683#[derive(Debug, Default, Serialize, Deserialize)]
1684pub struct AdminCreateSharedInviteArgs {
1685 /// Required, up to [`MAX_SHARED_INVITE_LABEL`] characters.
1686 pub label: String,
1687 /// 1 to [`MAX_SHARED_INVITE_USES`].
1688 pub max_uses: u32,
1689 /// The last day it works, `YYYY-MM-DD` (UTC; it works until the end of
1690 /// that day), at most [`SHARED_INVITE_MAX_DAYS`] ahead. Null for
1691 /// [`SHARED_INVITE_TTL_DAYS`] from now.
1692 #[serde(default)]
1693 pub expires_on: Option<String>,
1694 /// Email domains it is limited to, such as `cloudflare.com`; empty for
1695 /// any address. Up to [`MAX_SHARED_INVITE_DOMAINS`].
1696 #[serde(default)]
1697 pub domains: Vec<String>,
1698 /// The staff member, by email.
1699 pub staff: String,
1700}
1701
1702/// `admin_revoke_shared_invite`: stops a shared invite link making any
1703/// more accounts. Those it made stay. Recorded in sudo's audit log.
1704/// Returns `Outcome<SharedInvite>`.
1705#[derive(Debug, Serialize, Deserialize)]
1706pub struct AdminRevokeSharedInviteArgs {
1707 pub id: String,
1708 pub staff: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1709}
1710
1711#[cfg(test)]
1712mod deletion_tests {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1713 use super::{WorkspaceDeletion, protected_names};
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1714
1715 #[test]
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1716 fn only_billing_or_protection_stands_in_the_way() {
1717 let clear = WorkspaceDeletion {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1718 repositories: 2,
1719 projects: 1,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1720 members: 3,
1721 ..WorkspaceDeletion::default()
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1722 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1723 assert!(!clear.blocked());
1724 assert_eq!(clear.reason("acme"), None);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1725 let owing = WorkspaceDeletion {
1726 billing: Some("Pay first.".into()),
1727 ..WorkspaceDeletion::default()
1728 };
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1729 assert!(owing.blocked());
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1730 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1731 let protected = WorkspaceDeletion {
1732 billing: Some("Pay first.".into()),
1733 protected: true,
1734 ..WorkspaceDeletion::default()
1735 };
1736 assert!(protected.blocked());
1737 assert_eq!(
1738 protected.reason("flagon-io").as_deref(),
1739 Some("flagon-io is protected and can never be deleted.")
1740 );
1741 }
1742
1743 #[test]
1744 fn flagon_is_protected_whatever_the_variable_says() {
1745 assert_eq!(protected_names(None), ["flagon-io"]);
1746 assert_eq!(protected_names(Some("")), ["flagon-io"]);
1747 assert_eq!(protected_names(Some(" , ")), ["flagon-io"]);
1748 assert_eq!(
1749 protected_names(Some("Flagon-IO, acme ,wsp_1")),
1750 ["flagon-io", "acme", "wsp_1"]
1751 );
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1752 }
1753}

This file's history is long; its oldest lines are credited to the oldest commit read.