Skip to content
272 linesCodeBlameRaw
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod about;
8pub mod access;
9pub mod accounts;
10pub mod actions;
11pub mod agents;
12pub mod audit;
13pub mod backups;
14pub mod billing;
15pub mod capture;
16pub mod checks;
17pub mod codeowners;
18pub mod credentials;
19pub mod deploy_keys;
20pub mod events;
21pub mod fine_grained;
22pub mod github;
23pub mod guardrails;
24pub mod identity;
25pub mod inbox;
26pub mod integrations;
27pub mod members;
28mod ids;
29mod names;
30mod outcome;
31pub mod packages;
32pub mod projects;
33pub mod repos;
34pub mod rules;
35pub mod runners;
36pub mod scopes;
37pub mod search;
38pub mod security;
39pub mod teams;
40pub mod security_suite;
41pub mod time;
42pub mod tokens;
43pub mod updates;
44pub mod webhooks;
45pub mod work;
46
47pub use ids::new_id;
48pub use names::{
49 aliasable_name, claimable_namespace, is_namespace_shaped, is_reserved_name, is_route_name, is_valid_namespace,
50 is_valid_repo_name,
51};
52pub use outcome::{Failure, FailureCode, Outcome};
53
54use serde::{Deserialize, Serialize};
55
56/// What a member may do in a workspace. A member may also hold
57/// [`members::OrgRole`]s, which add to it.
58#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
59#[serde(rename_all = "lowercase")]
60pub enum Role {
61 /// Everything: Admin on every repository, the workspace's members,
62 /// settings, billing and security.
63 Owner,
64 /// The workspace's base permission on each repository, and what its
65 /// member privileges allow (see [`members::MemberPrivileges`]).
66 Member,
67}
68
69pub use members::{MemberPrivileges, OrgRole};
70
71/// One workspace a user belongs to.
72#[derive(Clone, Debug, Serialize, Deserialize)]
73pub struct Membership {
74 /// The workspace's name in URLs: `g1t.sh/<slug>`.
75 pub slug: String,
76 pub role: Role,
77 /// The workspace's display name, for showing it to people. Set when a
78 /// user is resolved from credentials; absent on principals made up by
79 /// a service.
80 #[serde(default, skip_serializing_if = "Option::is_none")]
81 pub name: Option<String>,
82 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
83 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
84 #[serde(default, skip_serializing_if = "Option::is_none")]
85 pub avatar: Option<String>,
86 /// What a member gets on each of the workspace's repositories: the
87 /// workspace's base permission. Set when a user is resolved from
88 /// credentials; absent means the default, Write. Owners have Admin
89 /// whatever it says. See [`access`].
90 #[serde(default, skip_serializing_if = "Option::is_none")]
91 pub base_permission: Option<access::BasePermission>,
92 /// Who may create the workspace's teams. Set when a user is resolved
93 /// from credentials; absent means the default, any member. See
94 /// [`teams::TeamCreation`].
95 #[serde(default, skip_serializing_if = "Option::is_none")]
96 pub team_creation: Option<teams::TeamCreation>,
97 /// The roles the member holds besides `role`: billing manager,
98 /// security manager. Set when a user is resolved from credentials.
99 #[serde(default, skip_serializing_if = "Vec::is_empty")]
100 pub org_roles: Vec<OrgRole>,
101 /// What the workspace lets members (and repository admins) do. Set
102 /// when a user is resolved from credentials; absent means the
103 /// defaults. See [`members::MemberPrivileges`].
104 #[serde(default, skip_serializing_if = "Option::is_none")]
105 pub privileges: Option<MemberPrivileges>,
106}
107
108impl Membership {
109 /// A plain member of `slug`, as services act inside one workspace.
110 pub fn member(slug: impl Into<String>) -> Self {
111 Membership {
112 slug: slug.into(),
113 role: Role::Member,
114 name: None,
115 avatar: None,
116 base_permission: None,
117 team_creation: None,
118 org_roles: Vec::new(),
119 privileges: None,
120 }
121 }
122
123 /// Whether the member holds `role` besides owner or member.
124 pub fn has(&self, role: OrgRole) -> bool {
125 self.org_roles.contains(&role)
126 }
127}
128
129/// What a set of credentials resolved to.
130#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
131#[serde(rename_all = "lowercase")]
132pub enum PrincipalKind {
133 /// A person's account.
134 #[default]
135 User,
136 /// A workspace, acting through one of its own access tokens. Its `id`
137 /// is the workspace's, its `username` the workspace's slug, and it is a
138 /// member of that workspace and no other.
139 Workspace,
140 /// A g1t agent at work in a sandbox, acting through a token that lives
141 /// as long as its run and can do only what that token's scope lists, in
142 /// one repository. Its `username` is `g1t`.
143 Agent,
144 /// g1t itself: the platform acting on its own, as when it opens a
145 /// pull request to upgrade a vulnerable dependency or merges from the
146 /// queue. Never resolved from credentials: only services make one,
147 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
148 /// register.
149 System,
150}
151
152/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
153pub mod system {
154 /// Its id wherever an author or actor id is stored.
155 pub const ID: &str = "g1t";
156 /// Its name, shown as the author of what it does.
157 pub const USERNAME: &str = "g1t";
158 /// The address on the commits it makes, which no mailbox receives.
159 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
160 /// Ids that earlier versions stored for g1t's own actions, such as a
161 /// merge its settings made. Read as g1t too.
162 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
163
164 /// Whether `id` is g1t's own.
165 pub fn is_system_id(id: &str) -> bool {
166 id == ID || LEGACY_IDS.contains(&id)
167 }
168}
169
170#[derive(Clone, Debug, Default, Serialize, Deserialize)]
171pub struct User {
172 pub id: String,
173 pub username: String,
174 #[serde(default)]
175 pub kind: PrincipalKind,
176 /// Whether the account's email address has been confirmed. Unverified
177 /// accounts can sign in but cannot create or change anything.
178 #[serde(default)]
179 pub verified: bool,
180 /// The workspaces this user belongs to. Filled in when a user is
181 /// resolved from credentials, so any service can authorize from it.
182 #[serde(default)]
183 pub workspaces: Vec<Membership>,
184 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
185 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
186 #[serde(default, skip_serializing_if = "Option::is_none")]
187 pub avatar: Option<String>,
188 /// Set on an agent resolved from its token: who it acts for, with which
189 /// credential, and what it may do. See [`credentials`].
190 #[serde(default, skip_serializing_if = "Option::is_none")]
191 pub acting: Option<Box<credentials::Acting>>,
192 /// The repositories this user has been given a role on directly,
193 /// whether or not they belong to its workspace. Filled in with
194 /// `workspaces`; see [`access`].
195 #[serde(default, skip_serializing_if = "Vec::is_empty")]
196 pub grants: Vec<access::RepoGrant>,
197 /// Set on a user resolved from an access token: its scopes and the
198 /// workspaces or repositories it is limited to. Absent on a signed-in
199 /// session and on an agent (whose `acting` scope applies instead).
200 /// See [`scopes`].
201 #[serde(default, skip_serializing_if = "Option::is_none")]
202 pub token: Option<Box<scopes::TokenAccess>>,
203 /// The workspaces this person belongs to but cannot use until they
204 /// meet its policy, such as turning on two-factor authentication.
205 /// They are left out of `workspaces` and `grants` meanwhile. Set when
206 /// a person is resolved from a session.
207 #[serde(default, skip_serializing_if = "Vec::is_empty")]
208 pub held: Vec<members::PolicyHold>,
209}
210
211impl User {
212 /// g1t itself, acting in `workspace`: what the platform's own work,
213 /// such as security updates, is done and recorded as.
214 pub fn system(workspace: &str) -> User {
215 User {
216 id: system::ID.to_owned(),
217 username: system::USERNAME.to_owned(),
218 kind: PrincipalKind::System,
219 verified: true,
220 workspaces: vec![Membership::member(workspace.to_lowercase())],
221 ..User::default()
222 }
223 }
224
225 /// Whether this is g1t itself.
226 pub fn is_system(&self) -> bool {
227 self.kind == PrincipalKind::System
228 }
229
230 pub fn role_in(&self, slug: &str) -> Option<Role> {
231 self.workspaces
232 .iter()
233 .find(|membership| membership.slug == slug)
234 .map(|membership| membership.role)
235 }
236
237 pub fn is_member(&self, slug: &str) -> bool {
238 self.role_in(slug).is_some()
239 }
240
241 /// The membership in `slug`, if any.
242 pub fn membership(&self, slug: &str) -> Option<&Membership> {
243 self.workspaces.iter().find(|membership| membership.slug.eq_ignore_ascii_case(slug))
244 }
245
246 /// Whether this is a person who owns `slug`, or holds `role` in it.
247 pub fn owns_or_has(&self, slug: &str, role: OrgRole) -> bool {
248 self.membership(slug)
249 .is_some_and(|membership| membership.role == Role::Owner || membership.has(role))
250 }
251
252 /// Whether the user may manage `slug`'s billing: an owner or a billing
253 /// manager.
254 pub fn manages_billing(&self, slug: &str) -> bool {
255 self.owns_or_has(slug, OrgRole::BillingManager)
256 }
257
258 /// Whether the user may see and manage security across `slug`: an
259 /// owner or a security manager.
260 pub fn manages_security(&self, slug: &str) -> bool {
261 self.owns_or_has(slug, OrgRole::SecurityManager)
262 }
263
264 /// The workspace's member privileges as this user sees them: the
265 /// defaults when the membership does not say.
266 pub fn privileges_in(&self, slug: &str) -> MemberPrivileges {
267 self.membership(slug).and_then(|membership| membership.privileges).unwrap_or_default()
268 }
269}
270
271/// Who is asking. Every read and write in every service takes one.
272pub type Viewer = Option<User>;