flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/crates/contracts/src/lib.rs

128 lines4,221 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
GitHub Actions on g1t, part two: running workflows7pub mod actions;
Agents and memory, checks and conflicts, profiles, slug renames, custom domains8pub mod agents;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API9pub mod audit;
Agents as a team: lifecycle, merge queue, billing and a new shell10pub mod billing;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API11pub mod capture;
12pub mod credentials;
Rust repos service with shipping; pull requests kept in the model13pub mod events;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API14pub mod guardrails;
API and MCP server, Rust identity service, registration, site redesign15pub mod identity;
Integrations: your own model provider, alerts that open issues, tickets agents read16pub mod integrations;
API and MCP server, Rust identity service, registration, site redesign17mod ids;
18mod names;
19mod outcome;
Projects: what a workspace builds and runs, first on every page20pub mod projects;
Rust repos service with shipping; pull requests kept in the model21pub mod repos;
Search across all of g1t, Explore, and a command palette22pub mod search;
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API23pub mod security;
RFC 3339 timestamps in identity and repos24pub mod time;
Webhooks: every event, to your own addresses, signed and retried25pub mod webhooks;
Work service in Rust, with RFC 3339 timestamps26pub mod work;
API and MCP server, Rust identity service, registration, site redesign27
28pub use ids::new_id;
29pub use names::{is_valid_namespace, is_valid_repo_name};
30pub use outcome::{Failure, FailureCode, Outcome};
31
32use serde::{Deserialize, Serialize};
33
Workspaces own repositories34/// What a member may do in a workspace.
35#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
36#[serde(rename_all = "lowercase")]
37pub enum Role {
38 /// Everything a member can, plus managing members.
39 Owner,
Issues and pull requests replace intents and attempts40 /// Create repositories, push, manage issues and merge pull requests.
Workspaces own repositories41 Member,
42}
43
44/// One workspace a user belongs to.
API and MCP server, Rust identity service, registration, site redesign45#[derive(Clone, Debug, Serialize, Deserialize)]
Workspaces own repositories46pub struct Membership {
47 /// The workspace's name in URLs: `g1t.sh/<slug>`.
48 pub slug: String,
49 pub role: Role,
Workspace names and icons, and a component kit for every control50 /// The workspace's display name, for showing it to people. Set when a
51 /// user is resolved from credentials; absent on principals made up by
52 /// a service.
53 #[serde(default, skip_serializing_if = "Option::is_none")]
54 pub name: Option<String>,
55 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
56 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
57 #[serde(default, skip_serializing_if = "Option::is_none")]
58 pub avatar: Option<String>,
Workspaces own repositories59}
60
Workspace names and icons, and a component kit for every control61impl Membership {
62 /// A plain member of `slug`, as services act inside one workspace.
63 pub fn member(slug: impl Into<String>) -> Self {
64 Membership {
65 slug: slug.into(),
66 role: Role::Member,
67 name: None,
68 avatar: None,
69 }
70 }
71}
72
Agents as a team: lifecycle, merge queue, billing and a new shell73/// What a set of credentials resolved to.
74#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
75#[serde(rename_all = "lowercase")]
76pub enum PrincipalKind {
77 /// A person's account.
78 #[default]
79 User,
80 /// A workspace, acting through one of its own access tokens. Its `id`
81 /// is the workspace's, its `username` the workspace's slug, and it is a
82 /// member of that workspace and no other.
83 Workspace,
84 /// A g1t agent at work in a sandbox, acting through a token that lives
85 /// as long as its run and can do only what that token's scope lists, in
86 /// one repository. Its `username` is `g1t-agent`.
87 Agent,
88}
89
Workspaces own repositories90#[derive(Clone, Debug, Default, Serialize, Deserialize)]
API and MCP server, Rust identity service, registration, site redesign91pub struct User {
92 pub id: String,
93 pub username: String,
Agents as a team: lifecycle, merge queue, billing and a new shell94 #[serde(default)]
95 pub kind: PrincipalKind,
Email verification, password reset, and Git for AI scale positioning96 /// Whether the account's email address has been confirmed. Unverified
97 /// accounts can sign in but cannot create or change anything.
98 #[serde(default)]
99 pub verified: bool,
Workspaces own repositories100 /// The workspaces this user belongs to. Filled in when a user is
101 /// resolved from credentials, so any service can authorize from it.
102 #[serde(default)]
103 pub workspaces: Vec<Membership>,
Workspace names and icons, and a component kit for every control104 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
105 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
106 #[serde(default, skip_serializing_if = "Option::is_none")]
107 pub avatar: Option<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API108 /// Set on an agent resolved from its token: who it acts for, with which
109 /// credential, and what it may do. See [`credentials`].
110 #[serde(default, skip_serializing_if = "Option::is_none")]
111 pub acting: Option<Box<credentials::Acting>>,
Workspaces own repositories112}
113
114impl User {
115 pub fn role_in(&self, slug: &str) -> Option<Role> {
116 self.workspaces
117 .iter()
118 .find(|membership| membership.slug == slug)
119 .map(|membership| membership.role)
120 }
121
122 pub fn is_member(&self, slug: &str) -> bool {
123 self.role_in(slug).is_some()
124 }
API and MCP server, Rust identity service, registration, site redesign125}
126
127/// Who is asking. Every read and write in every service takes one.
128pub type Viewer = Option<User>;