Skip to content
42 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1/**
2 * Who may do what with a project's deployments: each method's capability
3 * on the project's repository. Seeing deployments takes Read; deploying,
4 * redeploying and taking an app down spend compute and take Write (`run`);
5 * deployment settings and domains take Admin (`manage_integrations`).
6 * Types only, so the table is tested apart from the service.
7 */
8
g1t is the stored author of what it opens; the person who asked is requested_by and keeps the author's rights9import type { Capability, Project, RepoRef, User } from "@g1t/contracts";
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look10
11export const NEEDS = {
12 settings: "read",
13 list: "read",
14 get: "read",
15 listDomains: "read",
16 redeploy: "run",
17 takeDown: "run",
18 updateSettings: "manage_integrations",
19 addDomain: "manage_integrations",
20 removeDomain: "manage_integrations",
21 refreshDomain: "manage_integrations",
22} as const satisfies Record<string, Capability>;
23
24export type Method = keyof typeof NEEDS;
25
26/** The repository a project's permission comes from. A mirrored one has none: its workspace's base permission decides. */
27export function repoRef(project: Project): RepoRef {
28 if (project.source.kind === "hosted") {
29 return { id: project.source.repoId, namespace: project.source.repo.namespace, isPrivate: project.private };
30 }
31 return { id: "", namespace: project.workspace, isPrivate: project.private };
32}
g1t is the stored author of what it opens; the person who asked is requested_by and keeps the author's rights33
34/**
35 * Whether whoever a pull request is for is trusted with a project's secrets
36 * without asking what they may do: only g1t itself, in work nobody asked it
37 * for. A change g1t made for someone is for them (`workOwner`), and they are
38 * asked about like anyone else.
39 */
40export function trustedOutright(owner: Pick<User, "kind">): boolean {
41 return owner.kind === "agent" || owner.kind === "system";
42}