g1t/crates/contracts/src/identity.rs

214 lines5,778 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
16 /// Milliseconds since the epoch.
17 pub created_at: u64,
18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
25 pub created_at: u64,
26}
27
28/// `sign_in`: verifies a username and password for website sign-in.
29/// Returns `Outcome<SignedIn>`.
30#[derive(Debug, Serialize, Deserialize)]
31pub struct SignInArgs {
32 pub username: String,
33 pub password: String,
34}
35
36#[derive(Debug, Serialize, Deserialize)]
37#[serde(rename_all = "camelCase")]
38pub struct SignedIn {
39 pub user: User,
40 pub session_token: String,
41}
42
43/// `sign_out` and `user_for_session`.
44#[derive(Debug, Serialize, Deserialize)]
45#[serde(rename_all = "camelCase")]
46pub struct SessionArgs {
47 pub session_token: String,
48}
49
50/// `user_for_git_credentials`: the account password or an access token.
51#[derive(Debug, Serialize, Deserialize)]
52pub struct GitCredentialsArgs {
53 pub username: String,
54 pub secret: String,
55}
56
57/// `user_for_access_token`.
58#[derive(Debug, Serialize, Deserialize)]
59pub struct TokenArgs {
60 pub token: String,
61}
62
63/// `user_for_ssh_key`.
64#[derive(Debug, Serialize, Deserialize)]
65pub struct FingerprintArgs {
66 pub fingerprint: String,
67}
68
69/// `user_by_username`.
70#[derive(Debug, Serialize, Deserialize)]
71pub struct UsernameArgs {
72 pub username: String,
73}
74
75/// `list_ssh_keys` and `list_access_tokens`.
76#[derive(Debug, Serialize, Deserialize)]
77pub struct UserArgs {
78 pub user: User,
79}
80
81/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
82/// Returns `Outcome<SshKey>`.
83#[derive(Debug, Serialize, Deserialize)]
84#[serde(rename_all = "camelCase")]
85pub struct AddSshKeyArgs {
86 pub user: User,
87 pub title: String,
88 pub public_key: String,
89}
90
91/// `remove_ssh_key` and `remove_access_token`.
92#[derive(Debug, Serialize, Deserialize)]
93pub struct RemoveArgs {
94 pub user: User,
95 pub id: String,
96}
97
98/// `create_access_token`.
99#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)100#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign101pub struct CreateAccessTokenArgs {
102 pub user: User,
103 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)104 /// When set, the token stops working after this many seconds and is
105 /// left out of the user's token list. Used for hosted attempts.
106 #[serde(default)]
107 pub ttl_seconds: Option<u64>,
API and MCP server, Rust identity service, registration, site redesign108}
109
110/// The plaintext token is returned once and never stored.
111#[derive(Debug, Serialize, Deserialize)]
112pub struct CreatedAccessToken {
113 pub token: String,
114 pub info: AccessToken,
115}
116
117/// `register`: creates an account and signs it in.
118/// Returns `Outcome<SignedIn>`.
119#[derive(Debug, Serialize, Deserialize)]
120pub struct RegisterArgs {
121 pub username: String,
122 pub email: String,
123 pub password: String,
124}
Email verification, password reset, and Git for AI scale positioning125
126/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
127#[derive(Debug, Serialize, Deserialize)]
128pub struct EmailTokenArgs {
129 pub token: String,
130}
131
132/// `request_password_reset`. Always succeeds, so it cannot be used to find
133/// out which addresses have accounts.
134#[derive(Debug, Serialize, Deserialize)]
135pub struct EmailArgs {
136 pub email: String,
137}
138
139/// `reset_password`: sets a new password and ends every session.
140/// Returns `Outcome<User>`.
141#[derive(Debug, Serialize, Deserialize)]
142pub struct ResetPasswordArgs {
143 pub token: String,
144 pub password: String,
145}
Device sign-in replaces registering and minting tokens over the API146
147/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
148#[derive(Debug, Serialize, Deserialize)]
149#[serde(rename_all = "camelCase")]
150pub struct DeviceStartArgs {
151 /// What is asking, shown to the person approving, e.g. "Claude Code".
152 pub client_name: String,
153}
154
155#[derive(Debug, Serialize, Deserialize)]
156#[serde(rename_all = "camelCase")]
157pub struct DeviceStart {
158 /// Secret held by the tool and exchanged for a token once approved.
159 pub device_code: String,
160 /// Short code shown to the person, e.g. `WDJB-MJHT`.
161 pub user_code: String,
162 /// Seconds until both codes stop working.
163 pub expires_in: u32,
164 /// Seconds the tool should wait between polls.
165 pub interval: u32,
166}
167
168/// `device_lookup`: what a user code is asking for, or null if it is not
169/// valid. Returns `Option<DeviceRequest>`.
170#[derive(Debug, Serialize, Deserialize)]
171#[serde(rename_all = "camelCase")]
172pub struct DeviceLookupArgs {
173 pub user_code: String,
174}
175
176#[derive(Debug, Serialize, Deserialize)]
177#[serde(rename_all = "camelCase")]
178pub struct DeviceRequest {
179 pub user_code: String,
180 pub client_name: String,
181}
182
183/// `device_resolve`: the signed-in person approves or denies a request.
184/// Returns `Outcome<bool>`.
185#[derive(Debug, Serialize, Deserialize)]
186#[serde(rename_all = "camelCase")]
187pub struct DeviceResolveArgs {
188 pub user_code: String,
189 pub user: User,
190 pub approve: bool,
191}
192
193/// `device_claim`: the tool asks whether its request was approved.
194#[derive(Debug, Serialize, Deserialize)]
195#[serde(rename_all = "camelCase")]
196pub struct DeviceClaimArgs {
197 pub device_code: String,
198}
199
200/// The answer to a `device_claim`.
201#[derive(Debug, Serialize, Deserialize)]
202#[serde(tag = "status", rename_all = "snake_case")]
203pub enum DeviceClaim {
204 /// Nobody has approved or denied it yet; ask again after the interval.
205 Pending,
206 Denied,
207 /// The code was never issued, has expired, or was already used.
208 Expired,
209 /// The access token, returned once.
210 Approved {
211 token: String,
212 user: User,
213 },
214}