Skip to content
214 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb977pub mod about;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look8pub mod access;
9pub mod accounts;
GitHub Actions on g1t, part two: running workflows10pub mod actions;
Agents and memory, checks and conflicts, profiles, slug renames, custom domains11pub mod agents;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API12pub mod audit;
Merge branch 'worktree-agent-ac5b181a013e54348'13pub mod backups;
Agents as a team: lifecycle, merge queue, billing and a new shell14pub mod billing;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API15pub mod capture;
Merge checks: statuses and check runs on every commit16pub mod checks;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar17pub mod codeowners;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API18pub mod credentials;
Rust repos service with shipping; pull requests kept in the model19pub mod events;
Workflow files need workflow_files:write from a token; fine-grained permission table20pub mod fine_grained;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look21pub mod github;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API22pub mod guardrails;
API and MCP server, Rust identity service, registration, site redesign23pub mod identity;
Inbox: the events service tells people what needs them as events arrive24pub mod inbox;
Integrations: your own model provider, alerts that open issues, tickets agents read25pub mod integrations;
API and MCP server, Rust identity service, registration, site redesign26mod ids;
27mod names;
28mod outcome;
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member29pub mod packages;
Projects: what a workspace builds and runs, first on every page30pub mod projects;
Rust repos service with shipping; pull requests kept in the model31pub mod repos;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge32pub mod rules;
Fast pages, required checks on the branch, self-hosted runners, honest incidents33pub mod runners;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step34pub mod scopes;
Search across all of g1t, Explore, and a command palette35pub mod search;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API36pub mod security;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar37pub mod teams;
38pub mod security_suite;
RFC 3339 timestamps in identity and repos39pub mod time;
Fine-grained personal tokens, workspace token rules and approvals in identity40pub mod tokens;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar41pub mod updates;
Webhooks: every event, to your own addresses, signed and retried42pub mod webhooks;
Work service in Rust, with RFC 3339 timestamps43pub mod work;
API and MCP server, Rust identity service, registration, site redesign44
45pub use ids::new_id;
Merge branch 'worktree-agent-a8385d293d42c913a'46pub use names::{
47 aliasable_name, claimable_namespace, is_namespace_shaped, is_reserved_name, is_route_name, is_valid_namespace,
48 is_valid_repo_name,
49};
API and MCP server, Rust identity service, registration, site redesign50pub use outcome::{Failure, FailureCode, Outcome};
51
52use serde::{Deserialize, Serialize};
53
Workspaces own repositories54/// What a member may do in a workspace.
55#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
56#[serde(rename_all = "lowercase")]
57pub enum Role {
58 /// Everything a member can, plus managing members.
59 Owner,
Issues and pull requests replace intents and attempts60 /// Create repositories, push, manage issues and merge pull requests.
Workspaces own repositories61 Member,
62}
63
64/// One workspace a user belongs to.
API and MCP server, Rust identity service, registration, site redesign65#[derive(Clone, Debug, Serialize, Deserialize)]
Workspaces own repositories66pub struct Membership {
67 /// The workspace's name in URLs: `g1t.sh/<slug>`.
68 pub slug: String,
69 pub role: Role,
Workspace names and icons, and a component kit for every control70 /// The workspace's display name, for showing it to people. Set when a
71 /// user is resolved from credentials; absent on principals made up by
72 /// a service.
73 #[serde(default, skip_serializing_if = "Option::is_none")]
74 pub name: Option<String>,
75 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
76 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
77 #[serde(default, skip_serializing_if = "Option::is_none")]
78 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look79 /// What a member gets on each of the workspace's repositories: the
80 /// workspace's base permission. Set when a user is resolved from
81 /// credentials; absent means the default, Write. Owners have Admin
82 /// whatever it says. See [`access`].
83 #[serde(default, skip_serializing_if = "Option::is_none")]
84 pub base_permission: Option<access::BasePermission>,
Merge branch 'worktree-agent-ad7c6d88d93adc817'85 /// Who may create the workspace's teams. Set when a user is resolved
86 /// from credentials; absent means the default, any member. See
87 /// [`teams::TeamCreation`].
88 #[serde(default, skip_serializing_if = "Option::is_none")]
89 pub team_creation: Option<teams::TeamCreation>,
Workspaces own repositories90}
91
Workspace names and icons, and a component kit for every control92impl Membership {
93 /// A plain member of `slug`, as services act inside one workspace.
94 pub fn member(slug: impl Into<String>) -> Self {
95 Membership {
96 slug: slug.into(),
97 role: Role::Member,
98 name: None,
99 avatar: None,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look100 base_permission: None,
Merge branch 'worktree-agent-ad7c6d88d93adc817'101 team_creation: None,
Workspace names and icons, and a component kit for every control102 }
103 }
104}
105
Agents as a team: lifecycle, merge queue, billing and a new shell106/// What a set of credentials resolved to.
107#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
108#[serde(rename_all = "lowercase")]
109pub enum PrincipalKind {
110 /// A person's account.
111 #[default]
112 User,
113 /// A workspace, acting through one of its own access tokens. Its `id`
114 /// is the workspace's, its `username` the workspace's slug, and it is a
115 /// member of that workspace and no other.
116 Workspace,
117 /// A g1t agent at work in a sandbox, acting through a token that lives
118 /// as long as its run and can do only what that token's scope lists, in
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent119 /// one repository. Its `username` is `g1t`.
Agents as a team: lifecycle, merge queue, billing and a new shell120 Agent,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily121 /// g1t itself: the platform acting on its own, as when it opens a
122 /// pull request to upgrade a vulnerable dependency or merges from the
123 /// queue. Never resolved from credentials: only services make one,
124 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
125 /// register.
126 System,
127}
128
129/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
130pub mod system {
131 /// Its id wherever an author or actor id is stored.
132 pub const ID: &str = "g1t";
133 /// Its name, shown as the author of what it does.
134 pub const USERNAME: &str = "g1t";
135 /// The address on the commits it makes, which no mailbox receives.
136 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
137 /// Ids that earlier versions stored for g1t's own actions, such as a
138 /// merge its settings made. Read as g1t too.
139 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
140
141 /// Whether `id` is g1t's own.
142 pub fn is_system_id(id: &str) -> bool {
143 id == ID || LEGACY_IDS.contains(&id)
144 }
Agents as a team: lifecycle, merge queue, billing and a new shell145}
146
Workspaces own repositories147#[derive(Clone, Debug, Default, Serialize, Deserialize)]
API and MCP server, Rust identity service, registration, site redesign148pub struct User {
149 pub id: String,
150 pub username: String,
Agents as a team: lifecycle, merge queue, billing and a new shell151 #[serde(default)]
152 pub kind: PrincipalKind,
Email verification, password reset, and Git for AI scale positioning153 /// Whether the account's email address has been confirmed. Unverified
154 /// accounts can sign in but cannot create or change anything.
155 #[serde(default)]
156 pub verified: bool,
Workspaces own repositories157 /// The workspaces this user belongs to. Filled in when a user is
158 /// resolved from credentials, so any service can authorize from it.
159 #[serde(default)]
160 pub workspaces: Vec<Membership>,
Workspace names and icons, and a component kit for every control161 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
162 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
163 #[serde(default, skip_serializing_if = "Option::is_none")]
164 pub avatar: Option<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API165 /// Set on an agent resolved from its token: who it acts for, with which
166 /// credential, and what it may do. See [`credentials`].
167 #[serde(default, skip_serializing_if = "Option::is_none")]
168 pub acting: Option<Box<credentials::Acting>>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look169 /// The repositories this user has been given a role on directly,
170 /// whether or not they belong to its workspace. Filled in with
171 /// `workspaces`; see [`access`].
172 #[serde(default, skip_serializing_if = "Vec::is_empty")]
173 pub grants: Vec<access::RepoGrant>,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step174 /// Set on a user resolved from an access token: its scopes and the
175 /// workspaces or repositories it is limited to. Absent on a signed-in
176 /// session and on an agent (whose `acting` scope applies instead).
177 /// See [`scopes`].
178 #[serde(default, skip_serializing_if = "Option::is_none")]
179 pub token: Option<Box<scopes::TokenAccess>>,
Workspaces own repositories180}
181
182impl User {
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily183 /// g1t itself, acting in `workspace`: what the platform's own work,
184 /// such as security updates, is done and recorded as.
185 pub fn system(workspace: &str) -> User {
186 User {
187 id: system::ID.to_owned(),
188 username: system::USERNAME.to_owned(),
189 kind: PrincipalKind::System,
190 verified: true,
191 workspaces: vec![Membership::member(workspace.to_lowercase())],
192 ..User::default()
193 }
194 }
195
196 /// Whether this is g1t itself.
197 pub fn is_system(&self) -> bool {
198 self.kind == PrincipalKind::System
199 }
200
Workspaces own repositories201 pub fn role_in(&self, slug: &str) -> Option<Role> {
202 self.workspaces
203 .iter()
204 .find(|membership| membership.slug == slug)
205 .map(|membership| membership.role)
206 }
207
208 pub fn is_member(&self, slug: &str) -> bool {
209 self.role_in(slug).is_some()
210 }
API and MCP server, Rust identity service, registration, site redesign211}
212
213/// Who is asking. Every read and write in every service takes one.
214pub type Viewer = Option<User>;

This file's history is long; its oldest lines are credited to the oldest commit read.