g1t/crates/contracts/src/lib.rs

88 lines2,733 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod billing;
8pub mod events;
9pub mod identity;
10mod ids;
11mod names;
12mod outcome;
13pub mod repos;
14pub mod time;
15pub mod work;
16
17pub use ids::new_id;
18pub use names::{is_valid_namespace, is_valid_repo_name};
19pub use outcome::{Failure, FailureCode, Outcome};
20
21use serde::{Deserialize, Serialize};
22
23/// What a member may do in a workspace.
24#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
25#[serde(rename_all = "lowercase")]
26pub enum Role {
27 /// Everything a member can, plus managing members.
28 Owner,
29 /// Create repositories, push, manage issues and merge pull requests.
30 Member,
31}
32
33/// One workspace a user belongs to.
34#[derive(Clone, Debug, Serialize, Deserialize)]
35pub struct Membership {
36 /// The workspace's name in URLs: `g1t.sh/<slug>`.
37 pub slug: String,
38 pub role: Role,
39}
40
41/// What a set of credentials resolved to.
42#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
43#[serde(rename_all = "lowercase")]
44pub enum PrincipalKind {
45 /// A person's account.
46 #[default]
47 User,
48 /// A workspace, acting through one of its own access tokens. Its `id`
49 /// is the workspace's, its `username` the workspace's slug, and it is a
50 /// member of that workspace and no other.
51 Workspace,
52 /// A g1t agent at work in a sandbox, acting through a token that lives
53 /// as long as its run and can do only what that token's scope lists, in
54 /// one repository. Its `username` is `g1t-agent`.
55 Agent,
56}
57
58#[derive(Clone, Debug, Default, Serialize, Deserialize)]
59pub struct User {
60 pub id: String,
61 pub username: String,
62 #[serde(default)]
63 pub kind: PrincipalKind,
64 /// Whether the account's email address has been confirmed. Unverified
65 /// accounts can sign in but cannot create or change anything.
66 #[serde(default)]
67 pub verified: bool,
68 /// The workspaces this user belongs to. Filled in when a user is
69 /// resolved from credentials, so any service can authorize from it.
70 #[serde(default)]
71 pub workspaces: Vec<Membership>,
72}
73
74impl User {
75 pub fn role_in(&self, slug: &str) -> Option<Role> {
76 self.workspaces
77 .iter()
78 .find(|membership| membership.slug == slug)
79 .map(|membership| membership.role)
80 }
81
82 pub fn is_member(&self, slug: &str) -> bool {
83 self.role_in(slug).is_some()
84 }
85}
86
87/// Who is asking. Every read and write in every service takes one.
88pub type Viewer = Option<User>;