flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/crates/contracts/src/lib.rs

127 lines4,205 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod actions;
8pub mod agents;
9pub mod audit;
10pub mod billing;
11pub mod capture;
12pub mod credentials;
13pub mod events;
14pub mod guardrails;
15pub mod identity;
16pub mod integrations;
17mod ids;
18mod names;
19mod outcome;
20pub mod projects;
21pub mod repos;
22pub mod security;
23pub mod time;
24pub mod webhooks;
25pub mod work;
26
27pub use ids::new_id;
28pub use names::{is_valid_namespace, is_valid_repo_name};
29pub use outcome::{Failure, FailureCode, Outcome};
30
31use serde::{Deserialize, Serialize};
32
33/// What a member may do in a workspace.
34#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
35#[serde(rename_all = "lowercase")]
36pub enum Role {
37 /// Everything a member can, plus managing members.
38 Owner,
39 /// Create repositories, push, manage issues and merge pull requests.
40 Member,
41}
42
43/// One workspace a user belongs to.
44#[derive(Clone, Debug, Serialize, Deserialize)]
45pub struct Membership {
46 /// The workspace's name in URLs: `g1t.sh/<slug>`.
47 pub slug: String,
48 pub role: Role,
49 /// The workspace's display name, for showing it to people. Set when a
50 /// user is resolved from credentials; absent on principals made up by
51 /// a service.
52 #[serde(default, skip_serializing_if = "Option::is_none")]
53 pub name: Option<String>,
54 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
55 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
56 #[serde(default, skip_serializing_if = "Option::is_none")]
57 pub avatar: Option<String>,
58}
59
60impl Membership {
61 /// A plain member of `slug`, as services act inside one workspace.
62 pub fn member(slug: impl Into<String>) -> Self {
63 Membership {
64 slug: slug.into(),
65 role: Role::Member,
66 name: None,
67 avatar: None,
68 }
69 }
70}
71
72/// What a set of credentials resolved to.
73#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
74#[serde(rename_all = "lowercase")]
75pub enum PrincipalKind {
76 /// A person's account.
77 #[default]
78 User,
79 /// A workspace, acting through one of its own access tokens. Its `id`
80 /// is the workspace's, its `username` the workspace's slug, and it is a
81 /// member of that workspace and no other.
82 Workspace,
83 /// A g1t agent at work in a sandbox, acting through a token that lives
84 /// as long as its run and can do only what that token's scope lists, in
85 /// one repository. Its `username` is `g1t-agent`.
86 Agent,
87}
88
89#[derive(Clone, Debug, Default, Serialize, Deserialize)]
90pub struct User {
91 pub id: String,
92 pub username: String,
93 #[serde(default)]
94 pub kind: PrincipalKind,
95 /// Whether the account's email address has been confirmed. Unverified
96 /// accounts can sign in but cannot create or change anything.
97 #[serde(default)]
98 pub verified: bool,
99 /// The workspaces this user belongs to. Filled in when a user is
100 /// resolved from credentials, so any service can authorize from it.
101 #[serde(default)]
102 pub workspaces: Vec<Membership>,
103 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
104 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
105 #[serde(default, skip_serializing_if = "Option::is_none")]
106 pub avatar: Option<String>,
107 /// Set on an agent resolved from its token: who it acts for, with which
108 /// credential, and what it may do. See [`credentials`].
109 #[serde(default, skip_serializing_if = "Option::is_none")]
110 pub acting: Option<Box<credentials::Acting>>,
111}
112
113impl User {
114 pub fn role_in(&self, slug: &str) -> Option<Role> {
115 self.workspaces
116 .iter()
117 .find(|membership| membership.slug == slug)
118 .map(|membership| membership.role)
119 }
120
121 pub fn is_member(&self, slug: &str) -> bool {
122 self.role_in(slug).is_some()
123 }
124}
125
126/// Who is asking. Every read and write in every service takes one.
127pub type Viewer = Option<User>;