flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/actions/src/settings.rs

551 lines24,754 bytesCodeBlame
1//! Secrets and variables, a repository's or its workspace's: one list for
2//! every reader, shaped like Vercel's environment variables. Each row is a
3//! key, its type (a secret, or a variable shown as Config), the
4//! environments it applies to and who reads it: workflows, deployments, or
5//! both. A key may have one row per environment, so production and
6//! previews can hold different values; a key's rows never overlap.
7//!
8//! A reader asking for an environment gets the row naming it, else the
9//! key's row for every environment. A project's row overrides its
10//! workspace's of the same key.
11//!
12//! A repository's rows belong to its project (its primary one, when it
13//! carries several): asked for by repository, as GitHub's API does, they
14//! are the project's. Rows from before projects move over the first time
15//! they are touched. Names are upper-cased, as GitHub treats
16//! them without regard to case. Agents never read any.
17
18use g1t_contracts::actions::{
19 CONSUMERS, DeleteSettingArgs, ResolveSettingsArgs, ResolvedSettings, SetSettingArgs, Setting, SettingsArgs,
20 SettingsOwner,
21};
22use g1t_contracts::projects::{ByRepoArgs, ProjectRef};
23use g1t_contracts::time::rfc3339;
24use g1t_contracts::{FailureCode, Outcome, PrincipalKind, Role, User, new_id};
25use g1t_kit::now_ms;
26use serde::Deserialize;
27use serde_json::{Map, Value};
28use worker::Result;
29use worker::wasm_bindgen::JsValue;
30
31use crate::{Actions, check, fail};
32
33/// The largest value, as on GitHub.
34const MAX_VALUE_BYTES: usize = 48 * 1024;
35const MAX_PER_OWNER: u32 = 200;
36const MAX_NOTE: usize = 500;
37
38#[derive(Deserialize)]
39struct SettingRow {
40 id: String,
41 scope: String,
42 kind: String,
43 name: String,
44 value: String,
45 updated_at: String,
46 available_to: String,
47 environments: String,
48 repositories: Option<String>,
49 note: Option<String>,
50 updated_by: Option<String>,
51}
52
53/// A name GitHub would accept: letters, digits and `_`, not starting with
54/// a digit, `GITHUB_` or `G1T_`, which are g1t's own (`G1T_TOKEN` and its
55/// alias `GITHUB_TOKEN`).
56fn valid_name(name: &str) -> Result<String, String> {
57 let upper = name.trim().to_ascii_uppercase();
58 if upper.is_empty() || upper.len() > 100 {
59 return Err("A name is 1 to 100 characters.".to_owned());
60 }
61 if !upper.chars().all(|c| c.is_ascii_alphanumeric() || c == '_') {
62 return Err("A name has only letters, digits and underscores.".to_owned());
63 }
64 if upper.starts_with(|c: char| c.is_ascii_digit()) {
65 return Err("A name cannot start with a digit.".to_owned());
66 }
67 if upper.starts_with("GITHUB_") || upper.starts_with("G1T_") {
68 return Err("Names starting with G1T_ or GITHUB_ are kept for g1t's own, such as G1T_TOKEN.".to_owned());
69 }
70 Ok(upper)
71}
72
73/// Environments' names: lowercase letters, digits, `-` and `_`, each once.
74fn valid_environments(list: &[String]) -> Result<Vec<String>, String> {
75 let mut out: Vec<String> = Vec::new();
76 for name in list {
77 let lower = name.trim().to_ascii_lowercase();
78 if lower.is_empty() {
79 continue;
80 }
81 if lower.len() > 40 || !lower.chars().all(|c| c.is_ascii_alphanumeric() || c == '-' || c == '_') {
82 return Err(format!("`{name}` is not an environment's name: up to 40 letters, digits, - and _."));
83 }
84 if !out.contains(&lower) {
85 out.push(lower);
86 }
87 }
88 out.sort();
89 Ok(out)
90}
91
92fn consumers(list: &[String]) -> Result<Vec<String>, String> {
93 let mut out: Vec<String> = Vec::new();
94 for item in list {
95 let item = item.trim().to_ascii_lowercase();
96 if !CONSUMERS.contains(&item.as_str()) {
97 return Err(format!("`{item}` is not a reader: use workflows or deployments."));
98 }
99 if !out.contains(&item) {
100 out.push(item);
101 }
102 }
103 if out.is_empty() {
104 return Err("Choose who reads it: workflows, deployments, or both.".to_owned());
105 }
106 Ok(out)
107}
108
109fn split(list: &str) -> Vec<String> {
110 list.split(',').filter(|s| !s.is_empty()).map(str::to_owned).collect()
111}
112
113impl SettingRow {
114 fn environments(&self) -> Vec<String> {
115 split(&self.environments)
116 }
117
118 /// A workspace's row: the projects it reaches. The column predates
119 /// projects; it holds their slugs.
120 fn projects(&self) -> Vec<String> {
121 self.repositories.as_deref().and_then(|json| serde_json::from_str(json).ok()).unwrap_or_default()
122 }
123
124 fn reaches(&self, project: &str) -> bool {
125 let list = self.projects();
126 list.is_empty() || list.iter().any(|p| p.eq_ignore_ascii_case(project))
127 }
128
129 /// Whether it and rows for `environments` would both apply somewhere.
130 fn overlaps(&self, environments: &[String]) -> bool {
131 let mine = self.environments();
132 mine.is_empty() == environments.is_empty() && (mine.is_empty() || mine.iter().any(|e| environments.contains(e)))
133 }
134
135 fn describe(self) -> Setting {
136 Setting {
137 available_to: split(&self.available_to),
138 environments: self.environments(),
139 projects: self.projects(),
140 value: (self.kind == "variable").then_some(self.value),
141 id: self.id,
142 name: self.name,
143 kind: self.kind,
144 scope: self.scope,
145 updated_at: self.updated_at,
146 note: self.note,
147 updated_by: self.updated_by,
148 }
149 }
150}
151
152/// Where settings live: `(scope, owner)` with the owner a project id or a
153/// workspace slug.
154struct Place {
155 scope: &'static str,
156 owner: String,
157 namespace: String,
158 /// The project's slug, for a project's place.
159 slug: String,
160}
161
162impl Actions {
163 async fn place(&self, actor: &User, owner: &SettingsOwner, changing: bool) -> Result<Outcome<Place>> {
164 if actor.kind == PrincipalKind::Agent {
165 return Ok(fail(FailureCode::Forbidden, "Agents cannot read or change secrets and variables."));
166 }
167 // A workspace's tokens, G1T_TOKEN among them, read the names but
168 // never change them: a workflow must not rewrite what it runs with.
169 if changing && actor.kind == PrincipalKind::Workspace {
170 return Ok(fail(
171 FailureCode::Forbidden,
172 "A workspace's tokens, G1T_TOKEN included, cannot change secrets and variables. Use a person's token or the site.",
173 ));
174 }
175 match (&owner.repo, &owner.workspace) {
176 (Some(path), _) => {
177 if !actor.is_member(&path.namespace.to_lowercase()) {
178 return Ok(fail(FailureCode::Forbidden, format!("Only members of {} can see its secrets and variables.", path.namespace)));
179 }
180 let Some(repo) = self.visible_repo(path, &Some(actor.clone())).await? else {
181 return Ok(fail(FailureCode::NotFound, "There is no such repository."));
182 };
183 let Some(project) = self.project_of(&repo.id).await? else {
184 return Ok(fail(FailureCode::NotFound, "The repository has no project."));
185 };
186 Ok(Outcome::Ok(Place { scope: "project", owner: project.id, namespace: repo.namespace, slug: project.slug }))
187 }
188 (None, Some(slug)) => {
189 let slug = slug.to_lowercase();
190 let role = actor.workspaces.iter().find(|m| m.slug.eq_ignore_ascii_case(&slug)).map(|m| m.role);
191 match role {
192 None => Ok(fail(FailureCode::Forbidden, format!("Only members of {slug} can see its secrets and variables."))),
193 Some(Role::Member) if changing => Ok(fail(FailureCode::Forbidden, format!("Only owners of {slug} can change its secrets and variables."))),
194 Some(_) => Ok(Outcome::Ok(Place { scope: "workspace", owner: slug.clone(), namespace: slug, slug: String::new() })),
195 }
196 }
197 (None, None) => Ok(fail(FailureCode::Invalid, "Give `repo` or `workspace`.")),
198 }
199 }
200
201 /// A repository's primary project, with the rows kept under the
202 /// repository before projects moved to it.
203 pub(crate) async fn project_of(&self, repo_id: &str) -> Result<Option<ProjectRef>> {
204 let projects: Vec<ProjectRef> =
205 g1t_kit::call(&self.projects, "by_repo", &ByRepoArgs { repo_id: repo_id.to_owned() }).await?;
206 let Some(project) = projects.into_iter().find(|p| p.primary) else {
207 return Ok(None);
208 };
209 self.db
210 .prepare("UPDATE settings SET owner = ?, scope = 'project' WHERE owner = ?")
211 .bind(&[project.id.as_str().into(), repo_id.into()])?
212 .run()
213 .await?;
214 Ok(Some(project))
215 }
216
217 /// `secret`, `variable`, or `None` for both.
218 fn kind(kind: &str) -> Outcome<Option<&'static str>> {
219 match kind {
220 "secret" | "secrets" => Outcome::Ok(Some("secret")),
221 "variable" | "variables" | "config" => Outcome::Ok(Some("variable")),
222 "" | "all" => Outcome::Ok(None),
223 _ => fail(FailureCode::Invalid, "`kind` is `secret` or `variable`."),
224 }
225 }
226
227 async fn rows(&self, owner: &str) -> Result<Vec<SettingRow>> {
228 self.db
229 .prepare("SELECT * FROM settings WHERE owner = ? ORDER BY name, environments")
230 .bind(&[owner.into()])?
231 .all()
232 .await?
233 .results::<SettingRow>()
234 }
235
236 pub async fn settings(&self, a: SettingsArgs) -> Result<Outcome<Vec<Setting>>> {
237 let kind = check!(Self::kind(&a.kind));
238 let place = check!(self.place(&a.actor, &a.owner, false).await?);
239 let mut out: Vec<Setting> = Vec::new();
240 // A project's list shows the workspace's rows that reach it, but for
241 // keys it sets itself.
242 if place.scope == "project" {
243 let own: Vec<String> = self.rows(&place.owner).await?.into_iter().map(|row| row.name).collect();
244 for row in self.rows(&place.namespace.to_lowercase()).await? {
245 if row.reaches(&place.slug) && !own.contains(&row.name) {
246 out.push(row.describe());
247 }
248 }
249 }
250 out.extend(self.rows(&place.owner).await?.into_iter().map(SettingRow::describe));
251 out.retain(|setting| kind.is_none_or(|kind| setting.kind == kind));
252 out.sort_by(|a, b| a.name.cmp(&b.name).then(a.environments.cmp(&b.environments)));
253 Ok(Outcome::Ok(out))
254 }
255
256 fn seal(&self, value: &str, id: &str) -> Outcome<String> {
257 match &self.sealer {
258 Some(sealer) => Outcome::Ok(sealer.seal(value, id)),
259 None => fail(FailureCode::Conflict, "Secrets cannot be saved yet: g1t's key for them is not set."),
260 }
261 }
262
263 pub async fn set_setting(&self, a: SetSettingArgs) -> Result<Outcome<Setting>> {
264 let Some(kind) = check!(Self::kind(&a.kind)) else {
265 return Ok(fail(FailureCode::Invalid, "`kind` is `secret` or `variable`."));
266 };
267 let name = match valid_name(&a.name) {
268 Ok(name) => name,
269 Err(problem) => return Ok(fail(FailureCode::Invalid, problem)),
270 };
271 if a.value.as_ref().is_some_and(|v| v.len() > MAX_VALUE_BYTES) {
272 return Ok(fail(FailureCode::Invalid, "A value is at most 48 KB."));
273 }
274 if a.note.as_ref().is_some_and(|n| n.len() > MAX_NOTE) {
275 return Ok(fail(FailureCode::Invalid, "A note is at most 500 characters."));
276 }
277 let readers = match a.available_to.as_deref().map(consumers).transpose() {
278 Ok(readers) => readers,
279 Err(problem) => return Ok(fail(FailureCode::Invalid, problem)),
280 };
281 let environments = match a.environments.as_deref().map(valid_environments).transpose() {
282 Ok(environments) => environments,
283 Err(problem) => return Ok(fail(FailureCode::Invalid, problem)),
284 };
285 let place = check!(self.place(&a.actor, &a.owner, true).await?);
286 if a.projects.as_ref().is_some_and(|r| !r.is_empty()) && place.scope != "workspace" {
287 return Ok(fail(FailureCode::Invalid, "Only a workspace's rows choose projects."));
288 }
289 let rows = self.rows(&place.owner).await?;
290 // A secret and a variable may share a key, as on GitHub, where
291 // workflows read them apart (`secrets.X`, `vars.X`).
292 let same_key: Vec<&SettingRow> = rows.iter().filter(|row| row.name == name).collect();
293 // The row being changed: by id, else the key's row for every
294 // environment (GitHub's API names a secret by its key alone).
295 let existing = match &a.id {
296 Some(id) => match rows.iter().find(|row| &row.id == id) {
297 Some(row) => Some(row),
298 None => return Ok(fail(FailureCode::NotFound, "There is no such row.")),
299 },
300 None if a.environments.is_none() => same_key.iter().copied().find(|row| row.environments.is_empty() && row.kind == kind),
301 None => None,
302 };
303 if existing.is_some_and(|row| row.kind == "secret" && kind == "variable") {
304 return Ok(fail(FailureCode::Invalid, "A secret cannot become config: its value is sealed. Add a config row and remove the secret."));
305 }
306 let environments = environments.unwrap_or_else(|| existing.map(SettingRow::environments).unwrap_or_default());
307 // A key's rows never apply to the same environment twice.
308 if let Some(clash) = same_key
309 .iter()
310 .find(|row| row.kind == kind && existing.is_none_or(|e| e.id != row.id) && row.overlaps(&environments))
311 {
312 let at = if clash.environments.is_empty() { "all environments".to_owned() } else { clash.environments.replace(',', ", ") };
313 let what = if kind == "secret" { "secret" } else { "config" };
314 return Ok(fail(
315 FailureCode::Conflict,
316 format!("{name} already has a {what} row for {at}. Edit that row, or choose other environments."),
317 ));
318 }
319 if existing.is_none() && rows.len() as u32 >= MAX_PER_OWNER {
320 return Ok(fail(FailureCode::Invalid, format!("There can be at most {MAX_PER_OWNER} secrets and variables here.")));
321 }
322 let id = existing.map(|row| row.id.clone()).unwrap_or_else(|| new_id("set", now_ms()));
323 let value = match (&a.value, existing) {
324 (Some(value), _) if kind == "secret" => check!(self.seal(value, &id)),
325 (Some(value), _) => value.clone(),
326 // Config becoming a secret: its value is sealed now.
327 (None, Some(row)) if row.kind == "variable" && kind == "secret" => check!(self.seal(&row.value, &id)),
328 (None, Some(row)) => row.value.clone(),
329 (None, None) => return Ok(fail(FailureCode::Invalid, "A new row needs a `value`.")),
330 };
331 let available_to = readers
332 .map(|r| r.join(","))
333 .or_else(|| existing.map(|row| row.available_to.clone()))
334 .unwrap_or_else(|| CONSUMERS.join(","));
335 let repositories: Option<String> = match &a.projects {
336 Some(list) if list.is_empty() => None,
337 Some(list) => Some(serde_json::to_string(list).unwrap_or_default()),
338 None => existing.and_then(|row| row.repositories.clone()),
339 };
340 let note = match &a.note {
341 Some(note) if note.trim().is_empty() => None,
342 Some(note) => Some(note.trim().to_owned()),
343 None => existing.and_then(|row| row.note.clone()),
344 };
345 let at = rfc3339(now_ms());
346 let optional = |v: Option<&str>| v.map_or(JsValue::NULL, JsValue::from);
347 self.db
348 .prepare(
349 "INSERT INTO settings (id, scope, owner, kind, name, value, updated_at, available_to, environments, repositories, note, updated_by)
350 VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
351 ON CONFLICT (id) DO UPDATE SET kind = excluded.kind, value = excluded.value, updated_at = excluded.updated_at,
352 available_to = excluded.available_to, environments = excluded.environments,
353 repositories = excluded.repositories, note = excluded.note, updated_by = excluded.updated_by",
354 )
355 .bind(&[
356 id.as_str().into(),
357 place.scope.into(),
358 place.owner.as_str().into(),
359 kind.into(),
360 name.as_str().into(),
361 value.into(),
362 at.as_str().into(),
363 available_to.as_str().into(),
364 environments.join(",").into(),
365 optional(repositories.as_deref()),
366 optional(note.as_deref()),
367 a.actor.username.as_str().into(),
368 ])?
369 .run()
370 .await?;
371 let row = self
372 .db
373 .prepare("SELECT * FROM settings WHERE id = ?")
374 .bind(&[id.as_str().into()])?
375 .first::<SettingRow>(None)
376 .await?
377 .expect("just written");
378 Ok(Outcome::Ok(row.describe()))
379 }
380
381 pub async fn delete_setting(&self, a: DeleteSettingArgs) -> Result<Outcome<bool>> {
382 let kind = check!(Self::kind(&a.kind));
383 let place = check!(self.place(&a.actor, &a.owner, true).await?);
384 let name = a.name.trim().to_ascii_uppercase();
385 let removed = match &a.id {
386 Some(id) => self
387 .db
388 .prepare("DELETE FROM settings WHERE owner = ? AND id = ? RETURNING id")
389 .bind(&[place.owner.as_str().into(), id.as_str().into()])?
390 .all()
391 .await?,
392 None => self
393 .db
394 .prepare("DELETE FROM settings WHERE owner = ? AND name = ? AND (?3 IS NULL OR kind = ?3) RETURNING id")
395 .bind(&[place.owner.as_str().into(), name.as_str().into(), kind.map_or(JsValue::NULL, JsValue::from)])?
396 .all()
397 .await?,
398 };
399 Ok(if removed.results::<Value>()?.is_empty() {
400 fail(FailureCode::NotFound, format!("There is nothing called {} here.", a.name))
401 } else {
402 Outcome::Ok(true)
403 })
404 }
405
406 /// What one reader of a repository gets: per key, the row for
407 /// `environment`, else the row for every environment; the repository's
408 /// over its workspace's. No secrets unless `trusted`.
409 #[allow(clippy::too_many_arguments)]
410 async fn resolved(
411 &self,
412 project_id: &str,
413 project_slug: &str,
414 namespace: &str,
415 kind: &str,
416 consumer: &str,
417 environment: Option<&str>,
418 trusted: bool,
419 ) -> Result<Map<String, Value>> {
420 if kind == "secret" && !trusted {
421 return Ok(Map::new());
422 }
423 let environment = environment.map(str::to_ascii_lowercase);
424 let mut out = Map::new();
425 for owner in [namespace.to_lowercase(), project_id.to_owned()] {
426 let rows: Vec<SettingRow> = self
427 .rows(&owner)
428 .await?
429 .into_iter()
430 .filter(|row| row.kind == kind)
431 .filter(|row| split(&row.available_to).iter().any(|r| r == consumer))
432 .filter(|row| row.scope != "workspace" || row.reaches(project_slug))
433 .collect();
434 let mut names: Vec<&str> = rows.iter().map(|row| row.name.as_str()).collect();
435 names.dedup();
436 for name in names {
437 let of_key: Vec<&SettingRow> = rows.iter().filter(|row| row.name == name).collect();
438 let chosen = environment
439 .as_deref()
440 .and_then(|env| of_key.iter().find(|row| row.environments().iter().any(|e| e == env)))
441 .or_else(|| of_key.iter().find(|row| row.environments.is_empty()));
442 let Some(row) = chosen else {
443 // Rows only for other environments: this reader gets
444 // none, nor the workspace's.
445 out.remove(name);
446 continue;
447 };
448 let value = if kind == "secret" {
449 match self.sealer.as_ref().and_then(|sealer| sealer.open(&row.value, &row.id)) {
450 Some(value) => value,
451 None => continue,
452 }
453 } else {
454 row.value.clone()
455 };
456 out.insert(name.to_owned(), Value::String(value));
457 }
458 }
459 Ok(out)
460 }
461
462 /// The `vars` context of a repository's runs. `environment` is the job's
463 /// `environment:`, when it has one.
464 pub async fn variables_for(&self, repo_id: &str, repo: &str, environment: Option<&str>, trusted: bool) -> Result<Map<String, Value>> {
465 let (namespace, _) = repo.split_once('/').unwrap_or((repo, ""));
466 let Some(project) = self.project_of(repo_id).await? else {
467 return Ok(Map::new());
468 };
469 self.resolved(&project.id, &project.slug, namespace, "variable", "workflows", environment, trusted).await
470 }
471
472 /// The `secrets` context of a repository's runs, opened.
473 pub async fn secrets_for(&self, repo_id: &str, repo: &str, environment: Option<&str>, trusted: bool) -> Result<Map<String, Value>> {
474 let (namespace, _) = repo.split_once('/').unwrap_or((repo, ""));
475 let Some(project) = self.project_of(repo_id).await? else {
476 return Ok(Map::new());
477 };
478 self.resolved(&project.id, &project.slug, namespace, "secret", "workflows", environment, trusted).await
479 }
480
481 /// `resolve_settings`, for the deployments service: what a deploy build
482 /// and its running app get.
483 pub async fn resolve_settings(&self, a: ResolveSettingsArgs) -> Result<ResolvedSettings> {
484 let environment = a.environment.as_deref();
485 // Rows kept under the repository from before projects move to its
486 // primary project first, however the project is named here.
487 let primary = self.project_of(&a.repo_id).await?;
488 let (project_id, slug) = match (a.project_id, a.project_slug, primary) {
489 (Some(id), Some(slug), _) => (id, slug),
490 (_, _, Some(project)) => (project.id, project.slug),
491 _ => return Ok(ResolvedSettings::default()),
492 };
493 Ok(ResolvedSettings {
494 secrets: self
495 .resolved(&project_id, &slug, &a.repo.namespace, "secret", &a.consumer, environment, a.trusted)
496 .await?,
497 variables: self
498 .resolved(&project_id, &slug, &a.repo.namespace, "variable", &a.consumer, environment, a.trusted)
499 .await?,
500 })
501 }
502}
503
504#[cfg(test)]
505mod tests {
506 use super::{SettingRow, consumers, valid_environments, valid_name};
507
508 fn row(environments: &str) -> SettingRow {
509 SettingRow {
510 id: "set_1".into(),
511 scope: "repository".into(),
512 kind: "secret".into(),
513 name: "STRIPE_KEY".into(),
514 value: String::new(),
515 updated_at: String::new(),
516 available_to: "workflows,deployments".into(),
517 environments: environments.into(),
518 repositories: None,
519 note: None,
520 updated_by: None,
521 }
522 }
523
524 #[test]
525 fn names_follow_githubs_rules_and_keep_g1ts_own() {
526 assert_eq!(valid_name("npm_token").unwrap(), "NPM_TOKEN");
527 assert!(valid_name("GITHUB_TOKEN").is_err());
528 assert!(valid_name("G1T_TOKEN").is_err());
529 assert!(valid_name("1PASSWORD").is_err());
530 assert!(valid_name("MY-TOKEN").is_err());
531 assert!(valid_name("").is_err());
532 }
533
534 #[test]
535 fn environments_and_readers_are_checked() {
536 assert_eq!(valid_environments(&["Production".into(), "preview".into(), "production".into()]).unwrap(), vec!["preview", "production"]);
537 assert!(valid_environments(&["staging env".into()]).is_err());
538 assert_eq!(consumers(&["Deployments".into(), "deployments".into()]).unwrap(), vec!["deployments"]);
539 assert!(consumers(&["agents".into()]).is_err());
540 assert!(consumers(&[]).is_err());
541 }
542
543 #[test]
544 fn a_keys_rows_cannot_share_an_environment() {
545 assert!(row("production").overlaps(&["production".into(), "preview".into()]));
546 assert!(!row("production").overlaps(&["preview".into()]));
547 // One row for every environment, and others for some, live together.
548 assert!(!row("").overlaps(&["preview".into()]));
549 assert!(row("").overlaps(&[]));
550 }
551}