g1t/packages/contracts/src/identity.ts

91 lines3,690 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Initial g1t: services, event bus, intents and attempts1import type { Result } from "./result";
2
Email verification, password reset, and Git for AI scale positioning3export type User = {
4 id: string;
5 username: string;
6 /**
7 * Whether the account's email address is confirmed. Only set on users
8 * resolved from credentials; unverified accounts cannot change anything.
9 */
10 verified?: boolean;
11};
Initial g1t: services, event bus, intents and attempts12
13/** Who is asking. Every read and write in every service takes one. */
14export type Viewer = User | null;
15
16export type SshKey = {
17 id: string;
18 title: string;
19 fingerprint: string;
20 createdAt: number;
21};
22
23export type AccessToken = { id: string; name: string; createdAt: number };
24
Device sign-in replaces registering and minting tokens over the API25export type DeviceStart = {
26 /** Secret held by the tool and exchanged for a token once approved. */
27 deviceCode: string;
28 /** Short code shown to the person, e.g. `WDJB-MJHT`. */
29 userCode: string;
30 /** Seconds until both codes stop working. */
31 expiresIn: number;
32 /** Seconds the tool should wait between polls. */
33 interval: number;
34};
35
36export type DeviceRequest = { userCode: string; clientName: string };
37
38export type DeviceClaim =
39 | { status: "pending" | "denied" | "expired" }
40 | { status: "approved"; token: string; user: User };
41
Initial g1t: services, event bus, intents and attempts42/** Accounts, credentials and sessions. */
43export interface IdentityApi {
API and MCP server, Rust identity service, registration, site redesign44 /** Creates an account and signs it in. */
45 register(username: string, email: string, password: string): Promise<Result<{ user: User; sessionToken: string }>>;
Initial g1t: services, event bus, intents and attempts46 /** Verifies a username and password for website sign-in. */
47 signIn(username: string, password: string): Promise<Result<{ user: User; sessionToken: string }>>;
48 signOut(sessionToken: string): Promise<void>;
Email verification, password reset, and Git for AI scale positioning49
50 /** Sends the confirmation email again. */
51 resendVerification(user: User): Promise<Result<boolean>>;
52 /** Confirms the address the emailed token was sent to. */
53 verifyEmail(token: string): Promise<Result<User>>;
54 /** Emails a reset link if the address has an account. Always resolves. */
55 requestPasswordReset(email: string): Promise<boolean>;
56 /** Sets a new password from an emailed token and ends every session. */
57 resetPassword(token: string, password: string): Promise<Result<User>>;
58
Device sign-in replaces registering and minting tokens over the API59 /**
60 * Device sign-in (RFC 8628). A tool starts a request, a person approves
61 * its short code in a browser, and the tool claims an access token.
62 */
63 deviceStart(clientName: string): Promise<DeviceStart>;
64 /** What a user code is asking for, or null if it is not valid. */
65 deviceLookup(userCode: string): Promise<DeviceRequest | null>;
66 deviceResolve(userCode: string, user: User, approve: boolean): Promise<Result<boolean>>;
67 deviceClaim(deviceCode: string): Promise<DeviceClaim>;
68
Initial g1t: services, event bus, intents and attempts69 userForSession(sessionToken: string): Promise<Viewer>;
70
71 /** Verifies git credentials: the account password or an access token. */
72 userForGitCredentials(username: string, secret: string): Promise<Viewer>;
API and MCP server, Rust identity service, registration, site redesign73 /** Resolves a `g1t_…` access token, as sent to the API and MCP server. */
74 userForAccessToken(token: string): Promise<Viewer>;
Initial g1t: services, event bus, intents and attempts75 userForSshKey(fingerprint: string): Promise<Viewer>;
76 userByUsername(username: string): Promise<Viewer>;
77
78 listSshKeys(user: User): Promise<SshKey[]>;
79 /** Takes one line in OpenSSH public key format. */
80 addSshKey(user: User, title: string, publicKey: string): Promise<Result<SshKey>>;
81 removeSshKey(user: User, id: string): Promise<void>;
82
83 listAccessTokens(user: User): Promise<AccessToken[]>;
84 /** The plaintext token is returned once and never stored. */
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)85 /**
86 * With `ttlSeconds` the token expires and is left out of the user's list;
87 * that form is used for hosted attempts.
88 */
89 createAccessToken(user: User, name: string, ttlSeconds?: number): Promise<{ token: string; info: AccessToken }>;
Initial g1t: services, event bus, intents and attempts90 removeAccessToken(user: User, id: string): Promise<void>;
91}