Skip to content
289 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Record your own agent's sessions automatically1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb977pub mod about;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look8pub mod access;
Merge account deletion: soft delete for 30 days, staff restore and purge, ghost for what remains (identity 0037)9pub mod account_deletion;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look10pub mod accounts;
GitHub Actions on g1t, part two: running workflows11pub mod actions;
Agents and memory, checks and conflicts, profiles, slug renames, custom domains12pub mod agents;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API13pub mod audit;
Merge branch 'worktree-agent-ac5b181a013e54348'14pub mod backups;
Record your own agent's sessions automatically15pub mod billing;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API16pub mod capture;
Merge checks: statuses and check runs on every commit17pub mod checks;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar18pub mod codeowners;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API19pub mod credentials;
Artifacts contracts: folios, their four kinds, dashboard datasets, folio events and the artifacts scopes are typed and validated the same in TypeScript and Rust, with nothing using them yet20pub mod datasets;
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca21pub mod deploy_keys;
Record your own agent's sessions automatically22pub mod events;
Artifacts contracts: folios, their four kinds, dashboard datasets, folio events and the artifacts scopes are typed and validated the same in TypeScript and Rust, with nothing using them yet23pub mod folios;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look24pub mod github;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API25pub mod guardrails;
Record your own agent's sessions automatically26pub mod identity;
Inbox: the events service tells people what needs them as events arrive27pub mod inbox;
Integrations: your own model provider, alerts that open issues, tickets agents read28pub mod integrations;
Merge main (membership, two-factor, GitHub repo roles) into tokens29pub mod members;
Record your own agent's sessions automatically30mod ids;
31mod names;
32mod outcome;
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member33pub mod packages;
Projects: what a workspace builds and runs, first on every page34pub mod projects;
Record your own agent's sessions automatically35pub mod repos;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge36pub mod rules;
Fast pages, required checks on the branch, self-hosted runners, honest incidents37pub mod runners;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step38pub mod scopes;
Search across all of g1t, Explore, and a command palette39pub mod search;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API40pub mod security;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar41pub mod teams;
42pub mod security_suite;
Merge branch 'worktree-agent-ad8a36dfcd4176015' into spend-guardrails43pub mod subscribers;
Record your own agent's sessions automatically44pub mod time;
Fine-grained personal tokens, workspace token rules and approvals in identity45pub mod tokens;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar46pub mod updates;
Webhooks: every event, to your own addresses, signed and retried47pub mod webhooks;
Record your own agent's sessions automatically48pub mod work;
49
50pub use ids::new_id;
Merge branch 'worktree-agent-a8385d293d42c913a'51pub use names::{
One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers52 Username, aliasable_name, claimable_namespace, claimable_username, is_namespace_shaped, is_reserved_name, is_route_name,
53 is_valid_namespace, is_valid_repo_name,
Merge branch 'worktree-agent-a8385d293d42c913a'54};
Record your own agent's sessions automatically55pub use outcome::{Failure, FailureCode, Outcome};
56
57use serde::{Deserialize, Serialize};
58
Merge main (membership, two-factor, GitHub repo roles) into tokens59/// What a member may do in a workspace. A member may also hold
60/// [`members::OrgRole`]s, which add to it.
Record your own agent's sessions automatically61#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
62#[serde(rename_all = "lowercase")]
63pub enum Role {
Merge main (membership, two-factor, GitHub repo roles) into tokens64 /// Everything: Admin on every repository, the workspace's members,
65 /// settings, billing and security.
Record your own agent's sessions automatically66 Owner,
Merge main (membership, two-factor, GitHub repo roles) into tokens67 /// The workspace's base permission on each repository, and what its
68 /// member privileges allow (see [`members::MemberPrivileges`]).
Record your own agent's sessions automatically69 Member,
70}
71
Merge main (membership, two-factor, GitHub repo roles) into tokens72pub use members::{MemberPrivileges, OrgRole};
73
Record your own agent's sessions automatically74/// One workspace a user belongs to.
75#[derive(Clone, Debug, Serialize, Deserialize)]
76pub struct Membership {
77 /// The workspace's name in URLs: `g1t.sh/<slug>`.
78 pub slug: String,
79 pub role: Role,
Workspace names and icons, and a component kit for every control80 /// The workspace's display name, for showing it to people. Set when a
81 /// user is resolved from credentials; absent on principals made up by
82 /// a service.
83 #[serde(default, skip_serializing_if = "Option::is_none")]
84 pub name: Option<String>,
85 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
86 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
87 #[serde(default, skip_serializing_if = "Option::is_none")]
88 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look89 /// What a member gets on each of the workspace's repositories: the
90 /// workspace's base permission. Set when a user is resolved from
91 /// credentials; absent means the default, Write. Owners have Admin
92 /// whatever it says. See [`access`].
93 #[serde(default, skip_serializing_if = "Option::is_none")]
94 pub base_permission: Option<access::BasePermission>,
Merge branch 'worktree-agent-ad7c6d88d93adc817'95 /// Who may create the workspace's teams. Set when a user is resolved
96 /// from credentials; absent means the default, any member. See
97 /// [`teams::TeamCreation`].
98 #[serde(default, skip_serializing_if = "Option::is_none")]
99 pub team_creation: Option<teams::TeamCreation>,
Merge main (membership, two-factor, GitHub repo roles) into tokens100 /// The roles the member holds besides `role`: billing manager,
101 /// security manager. Set when a user is resolved from credentials.
102 #[serde(default, skip_serializing_if = "Vec::is_empty")]
103 pub org_roles: Vec<OrgRole>,
104 /// What the workspace lets members (and repository admins) do. Set
105 /// when a user is resolved from credentials; absent means the
106 /// defaults. See [`members::MemberPrivileges`].
107 #[serde(default, skip_serializing_if = "Option::is_none")]
108 pub privileges: Option<MemberPrivileges>,
Record your own agent's sessions automatically109}
110
Workspace names and icons, and a component kit for every control111impl Membership {
112 /// A plain member of `slug`, as services act inside one workspace.
113 pub fn member(slug: impl Into<String>) -> Self {
114 Membership {
115 slug: slug.into(),
116 role: Role::Member,
117 name: None,
118 avatar: None,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look119 base_permission: None,
Merge branch 'worktree-agent-ad7c6d88d93adc817'120 team_creation: None,
Merge main (membership, two-factor, GitHub repo roles) into tokens121 org_roles: Vec::new(),
122 privileges: None,
Workspace names and icons, and a component kit for every control123 }
124 }
Merge main (membership, two-factor, GitHub repo roles) into tokens125
126 /// Whether the member holds `role` besides owner or member.
127 pub fn has(&self, role: OrgRole) -> bool {
128 self.org_roles.contains(&role)
129 }
Workspace names and icons, and a component kit for every control130}
131
Record your own agent's sessions automatically132/// What a set of credentials resolved to.
133#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
134#[serde(rename_all = "lowercase")]
135pub enum PrincipalKind {
136 /// A person's account.
137 #[default]
138 User,
139 /// A workspace, acting through one of its own access tokens. Its `id`
140 /// is the workspace's, its `username` the workspace's slug, and it is a
141 /// member of that workspace and no other.
142 Workspace,
143 /// A g1t agent at work in a sandbox, acting through a token that lives
144 /// as long as its run and can do only what that token's scope lists, in
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent145 /// one repository. Its `username` is `g1t`.
Record your own agent's sessions automatically146 Agent,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily147 /// g1t itself: the platform acting on its own, as when it opens a
148 /// pull request to upgrade a vulnerable dependency or merges from the
149 /// queue. Never resolved from credentials: only services make one,
150 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
151 /// register.
152 System,
153}
154
155/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
156pub mod system {
157 /// Its id wherever an author or actor id is stored.
158 pub const ID: &str = "g1t";
159 /// Its name, shown as the author of what it does.
160 pub const USERNAME: &str = "g1t";
161 /// The address on the commits it makes, which no mailbox receives.
162 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
163 /// Ids that earlier versions stored for g1t's own actions, such as a
164 /// merge its settings made. Read as g1t too.
165 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
166
167 /// Whether `id` is g1t's own.
168 pub fn is_system_id(id: &str) -> bool {
169 id == ID || LEGACY_IDS.contains(&id)
170 }
Record your own agent's sessions automatically171}
172
173#[derive(Clone, Debug, Default, Serialize, Deserialize)]
174pub struct User {
175 pub id: String,
One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers176 /// Lowercased: what the person is found, linked and mentioned by.
Record your own agent's sessions automatically177 pub username: String,
One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers178 /// The username as its owner wrote it (`Ana`), when that differs from
179 /// `username`: what pages show. Set on the signed-in person and on
180 /// people looked up by name; absent elsewhere, where `username` is shown.
181 #[serde(default, skip_serializing_if = "Option::is_none")]
182 pub display_username: Option<String>,
Record your own agent's sessions automatically183 #[serde(default)]
184 pub kind: PrincipalKind,
185 /// Whether the account's email address has been confirmed. Unverified
186 /// accounts can sign in but cannot create or change anything.
187 #[serde(default)]
188 pub verified: bool,
189 /// The workspaces this user belongs to. Filled in when a user is
190 /// resolved from credentials, so any service can authorize from it.
191 #[serde(default)]
192 pub workspaces: Vec<Membership>,
Workspace names and icons, and a component kit for every control193 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
194 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
195 #[serde(default, skip_serializing_if = "Option::is_none")]
196 pub avatar: Option<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API197 /// Set on an agent resolved from its token: who it acts for, with which
198 /// credential, and what it may do. See [`credentials`].
199 #[serde(default, skip_serializing_if = "Option::is_none")]
200 pub acting: Option<Box<credentials::Acting>>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look201 /// The repositories this user has been given a role on directly,
202 /// whether or not they belong to its workspace. Filled in with
203 /// `workspaces`; see [`access`].
204 #[serde(default, skip_serializing_if = "Vec::is_empty")]
205 pub grants: Vec<access::RepoGrant>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step206 /// Set on a user resolved from an access token: its scopes and the
207 /// workspaces or repositories it is limited to. Absent on a signed-in
208 /// session and on an agent (whose `acting` scope applies instead).
209 /// See [`scopes`].
210 #[serde(default, skip_serializing_if = "Option::is_none")]
211 pub token: Option<Box<scopes::TokenAccess>>,
Merge main (membership, two-factor, GitHub repo roles) into tokens212 /// The workspaces this person belongs to but cannot use until they
213 /// meet its policy, such as turning on two-factor authentication.
214 /// They are left out of `workspaces` and `grants` meanwhile. Set when
215 /// a person is resolved from a session.
216 #[serde(default, skip_serializing_if = "Vec::is_empty")]
217 pub held: Vec<members::PolicyHold>,
Record your own agent's sessions automatically218}
219
220impl User {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily221 /// g1t itself, acting in `workspace`: what the platform's own work,
222 /// such as security updates, is done and recorded as.
223 pub fn system(workspace: &str) -> User {
224 User {
225 id: system::ID.to_owned(),
226 username: system::USERNAME.to_owned(),
227 kind: PrincipalKind::System,
228 verified: true,
229 workspaces: vec![Membership::member(workspace.to_lowercase())],
230 ..User::default()
231 }
232 }
233
234 /// Whether this is g1t itself.
235 pub fn is_system(&self) -> bool {
236 self.kind == PrincipalKind::System
237 }
238
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)239 /// Whether this is a person whose account has not confirmed its email
240 /// address. Such an account can only confirm it (or change it, or sign
241 /// out): the site, the API, MCP and git refuse it everything else
242 /// ([`accounts::confirm_email_first`]).
243 pub fn awaits_confirmation(&self) -> bool {
244 self.kind == PrincipalKind::User && !self.verified
245 }
246
Record your own agent's sessions automatically247 pub fn role_in(&self, slug: &str) -> Option<Role> {
248 self.workspaces
249 .iter()
250 .find(|membership| membership.slug == slug)
251 .map(|membership| membership.role)
252 }
253
254 pub fn is_member(&self, slug: &str) -> bool {
255 self.role_in(slug).is_some()
256 }
Merge main (membership, two-factor, GitHub repo roles) into tokens257
258 /// The membership in `slug`, if any.
259 pub fn membership(&self, slug: &str) -> Option<&Membership> {
260 self.workspaces.iter().find(|membership| membership.slug.eq_ignore_ascii_case(slug))
261 }
262
263 /// Whether this is a person who owns `slug`, or holds `role` in it.
264 pub fn owns_or_has(&self, slug: &str, role: OrgRole) -> bool {
265 self.membership(slug)
266 .is_some_and(|membership| membership.role == Role::Owner || membership.has(role))
267 }
268
269 /// Whether the user may manage `slug`'s billing: an owner or a billing
270 /// manager.
271 pub fn manages_billing(&self, slug: &str) -> bool {
272 self.owns_or_has(slug, OrgRole::BillingManager)
273 }
274
275 /// Whether the user may see and manage security across `slug`: an
276 /// owner or a security manager.
277 pub fn manages_security(&self, slug: &str) -> bool {
278 self.owns_or_has(slug, OrgRole::SecurityManager)
279 }
280
281 /// The workspace's member privileges as this user sees them: the
282 /// defaults when the membership does not say.
283 pub fn privileges_in(&self, slug: &str) -> MemberPrivileges {
284 self.membership(slug).and_then(|membership| membership.privileges).unwrap_or_default()
285 }
Record your own agent's sessions automatically286}
287
288/// Who is asking. Every read and write in every service takes one.
289pub type Viewer = Option<User>;

This file's history is long; its oldest lines are credited to the oldest commit read.