| 1 | /** |
| 2 | * Who may see and who may change a workspace's agents. Pure, so it is |
| 3 | * tested on its own. |
| 4 | * |
| 5 | * Any member sees them: agents are members too, and people need to know |
| 6 | * who they can talk to. Only owners create, change or archive them, since |
| 7 | * an agent spends the workspace's money and acts in its name. A |
| 8 | * workspace's own access token, acting as the workspace, counts as an |
| 9 | * owner, as it does for the workspace's other settings. |
| 10 | */ |
| 11 | import type { User } from "@g1t/contracts"; |
| 12 | |
| 13 | type Viewer = Pick<User, "kind" | "username" | "workspaces" | "verified"> | null | undefined; |
| 14 | |
| 15 | export function canSee(viewer: Viewer, workspace: string): boolean { |
| 16 | const slug = workspace.toLowerCase(); |
| 17 | if (!viewer) return false; |
| 18 | if (viewer.kind === "workspace") return viewer.username.toLowerCase() === slug; |
| 19 | return !!viewer.workspaces?.some((m) => m.slug.toLowerCase() === slug); |
| 20 | } |
| 21 | |
| 22 | export function canManage(viewer: Viewer, workspace: string): boolean { |
| 23 | const slug = workspace.toLowerCase(); |
| 24 | if (!viewer) return false; |
| 25 | if (viewer.kind === "workspace") return viewer.username.toLowerCase() === slug; |
| 26 | return !!viewer.workspaces?.some((m) => m.slug.toLowerCase() === slug && m.role === "owner"); |
| 27 | } |
| 28 | |
| 29 | export const MANAGE_REFUSAL = "Only the workspace's owners can create, change or archive its agents."; |