Skip to content

g1t/crates/contracts/src/lib.rs

212 lines7,595 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod about;
8pub mod access;
9pub mod accounts;
10pub mod actions;
11pub mod agents;
12pub mod audit;
13pub mod backups;
14pub mod billing;
15pub mod capture;
16pub mod checks;
17pub mod codeowners;
18pub mod credentials;
19pub mod events;
20pub mod github;
21pub mod guardrails;
22pub mod identity;
23pub mod inbox;
24pub mod integrations;
25mod ids;
26mod names;
27mod outcome;
28pub mod packages;
29pub mod projects;
30pub mod repos;
31pub mod rules;
32pub mod runners;
33pub mod scopes;
34pub mod search;
35pub mod security;
36pub mod teams;
37pub mod security_suite;
38pub mod time;
39pub mod updates;
40pub mod webhooks;
41pub mod work;
42
43pub use ids::new_id;
44pub use names::{
45 aliasable_name, claimable_namespace, is_namespace_shaped, is_reserved_name, is_route_name, is_valid_namespace,
46 is_valid_repo_name,
47};
48pub use outcome::{Failure, FailureCode, Outcome};
49
50use serde::{Deserialize, Serialize};
51
52/// What a member may do in a workspace.
53#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
54#[serde(rename_all = "lowercase")]
55pub enum Role {
56 /// Everything a member can, plus managing members.
57 Owner,
58 /// Create repositories, push, manage issues and merge pull requests.
59 Member,
60}
61
62/// One workspace a user belongs to.
63#[derive(Clone, Debug, Serialize, Deserialize)]
64pub struct Membership {
65 /// The workspace's name in URLs: `g1t.sh/<slug>`.
66 pub slug: String,
67 pub role: Role,
68 /// The workspace's display name, for showing it to people. Set when a
69 /// user is resolved from credentials; absent on principals made up by
70 /// a service.
71 #[serde(default, skip_serializing_if = "Option::is_none")]
72 pub name: Option<String>,
73 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
74 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
75 #[serde(default, skip_serializing_if = "Option::is_none")]
76 pub avatar: Option<String>,
77 /// What a member gets on each of the workspace's repositories: the
78 /// workspace's base permission. Set when a user is resolved from
79 /// credentials; absent means the default, Write. Owners have Admin
80 /// whatever it says. See [`access`].
81 #[serde(default, skip_serializing_if = "Option::is_none")]
82 pub base_permission: Option<access::BasePermission>,
83 /// Who may create the workspace's teams. Set when a user is resolved
84 /// from credentials; absent means the default, any member. See
85 /// [`teams::TeamCreation`].
86 #[serde(default, skip_serializing_if = "Option::is_none")]
87 pub team_creation: Option<teams::TeamCreation>,
88}
89
90impl Membership {
91 /// A plain member of `slug`, as services act inside one workspace.
92 pub fn member(slug: impl Into<String>) -> Self {
93 Membership {
94 slug: slug.into(),
95 role: Role::Member,
96 name: None,
97 avatar: None,
98 base_permission: None,
99 team_creation: None,
100 }
101 }
102}
103
104/// What a set of credentials resolved to.
105#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
106#[serde(rename_all = "lowercase")]
107pub enum PrincipalKind {
108 /// A person's account.
109 #[default]
110 User,
111 /// A workspace, acting through one of its own access tokens. Its `id`
112 /// is the workspace's, its `username` the workspace's slug, and it is a
113 /// member of that workspace and no other.
114 Workspace,
115 /// A g1t agent at work in a sandbox, acting through a token that lives
116 /// as long as its run and can do only what that token's scope lists, in
117 /// one repository. Its `username` is `g1t`.
118 Agent,
119 /// g1t itself: the platform acting on its own, as when it opens a
120 /// pull request to upgrade a vulnerable dependency or merges from the
121 /// queue. Never resolved from credentials: only services make one,
122 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
123 /// register.
124 System,
125}
126
127/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
128pub mod system {
129 /// Its id wherever an author or actor id is stored.
130 pub const ID: &str = "g1t";
131 /// Its name, shown as the author of what it does.
132 pub const USERNAME: &str = "g1t";
133 /// The address on the commits it makes, which no mailbox receives.
134 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
135 /// Ids that earlier versions stored for g1t's own actions, such as a
136 /// merge its settings made. Read as g1t too.
137 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
138
139 /// Whether `id` is g1t's own.
140 pub fn is_system_id(id: &str) -> bool {
141 id == ID || LEGACY_IDS.contains(&id)
142 }
143}
144
145#[derive(Clone, Debug, Default, Serialize, Deserialize)]
146pub struct User {
147 pub id: String,
148 pub username: String,
149 #[serde(default)]
150 pub kind: PrincipalKind,
151 /// Whether the account's email address has been confirmed. Unverified
152 /// accounts can sign in but cannot create or change anything.
153 #[serde(default)]
154 pub verified: bool,
155 /// The workspaces this user belongs to. Filled in when a user is
156 /// resolved from credentials, so any service can authorize from it.
157 #[serde(default)]
158 pub workspaces: Vec<Membership>,
159 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
160 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
161 #[serde(default, skip_serializing_if = "Option::is_none")]
162 pub avatar: Option<String>,
163 /// Set on an agent resolved from its token: who it acts for, with which
164 /// credential, and what it may do. See [`credentials`].
165 #[serde(default, skip_serializing_if = "Option::is_none")]
166 pub acting: Option<Box<credentials::Acting>>,
167 /// The repositories this user has been given a role on directly,
168 /// whether or not they belong to its workspace. Filled in with
169 /// `workspaces`; see [`access`].
170 #[serde(default, skip_serializing_if = "Vec::is_empty")]
171 pub grants: Vec<access::RepoGrant>,
172 /// Set on a user resolved from an access token: its scopes and the
173 /// workspaces or repositories it is limited to. Absent on a signed-in
174 /// session and on an agent (whose `acting` scope applies instead).
175 /// See [`scopes`].
176 #[serde(default, skip_serializing_if = "Option::is_none")]
177 pub token: Option<Box<scopes::TokenAccess>>,
178}
179
180impl User {
181 /// g1t itself, acting in `workspace`: what the platform's own work,
182 /// such as security updates, is done and recorded as.
183 pub fn system(workspace: &str) -> User {
184 User {
185 id: system::ID.to_owned(),
186 username: system::USERNAME.to_owned(),
187 kind: PrincipalKind::System,
188 verified: true,
189 workspaces: vec![Membership::member(workspace.to_lowercase())],
190 ..User::default()
191 }
192 }
193
194 /// Whether this is g1t itself.
195 pub fn is_system(&self) -> bool {
196 self.kind == PrincipalKind::System
197 }
198
199 pub fn role_in(&self, slug: &str) -> Option<Role> {
200 self.workspaces
201 .iter()
202 .find(|membership| membership.slug == slug)
203 .map(|membership| membership.role)
204 }
205
206 pub fn is_member(&self, slug: &str) -> bool {
207 self.role_in(slug).is_some()
208 }
209}
210
211/// Who is asking. Every read and write in every service takes one.
212pub type Viewer = Option<User>;