g1t/crates/contracts/src/identity.rs

1,268 lines42,622 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
RFC 3339 timestamps in identity and repos16 /// RFC 3339.
17 pub created_at: String,
API and MCP server, Rust identity service, registration, site redesign18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
RFC 3339 timestamps in identity and repos25 /// RFC 3339.
26 pub created_at: String,
Agents as a team: lifecycle, merge queue, billing and a new shell27 /// RFC 3339, to within a few minutes. Null until it is first used.
28 pub last_used_at: Option<String>,
29 /// For a workspace's token, the username of the member who made it.
30 /// Null once that account is gone, and on personal tokens.
31 pub created_by: Option<String>,
API and MCP server, Rust identity service, registration, site redesign32}
33
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look34/// `sign_in`: verifies a username, or any confirmed email address of the
35/// account, and its password, for website sign-in. Wrong passwords are
36/// counted against the account and `client`, and past a limit nothing is
37/// checked for a while (see identity's `throttle.rs`).
API and MCP server, Rust identity service, registration, site redesign38/// Returns `Outcome<SignedIn>`.
39#[derive(Debug, Serialize, Deserialize)]
40pub struct SignInArgs {
41 pub username: String,
42 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look43 /// Who is asking, such as the visitor's IP address, for rate limits.
44 #[serde(default)]
45 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign46}
47
48#[derive(Debug, Serialize, Deserialize)]
49#[serde(rename_all = "camelCase")]
50pub struct SignedIn {
51 pub user: User,
52 pub session_token: String,
53}
54
55/// `sign_out` and `user_for_session`.
56#[derive(Debug, Serialize, Deserialize)]
57#[serde(rename_all = "camelCase")]
58pub struct SessionArgs {
59 pub session_token: String,
60}
61
62/// `user_for_git_credentials`: the account password or an access token.
63#[derive(Debug, Serialize, Deserialize)]
64pub struct GitCredentialsArgs {
65 pub username: String,
66 pub secret: String,
67}
68
69/// `user_for_access_token`.
70#[derive(Debug, Serialize, Deserialize)]
71pub struct TokenArgs {
72 pub token: String,
73}
74
75/// `user_for_ssh_key`.
76#[derive(Debug, Serialize, Deserialize)]
77pub struct FingerprintArgs {
78 pub fingerprint: String,
79}
80
81/// `user_by_username`.
82#[derive(Debug, Serialize, Deserialize)]
83pub struct UsernameArgs {
84 pub username: String,
85}
86
What happened across an outcome, as a feed beside its graph87/// `usernames`: the names behind account and workspace ids, as events and
88/// other records store them. Returns a map from id to name; ids it does
89/// not know are left out.
90#[derive(Debug, Serialize, Deserialize)]
91pub struct UsernamesArgs {
92 pub ids: Vec<String>,
93}
94
API and MCP server, Rust identity service, registration, site redesign95/// `list_ssh_keys` and `list_access_tokens`.
96#[derive(Debug, Serialize, Deserialize)]
97pub struct UserArgs {
98 pub user: User,
99}
100
101/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
102/// Returns `Outcome<SshKey>`.
103#[derive(Debug, Serialize, Deserialize)]
104#[serde(rename_all = "camelCase")]
105pub struct AddSshKeyArgs {
106 pub user: User,
107 pub title: String,
108 pub public_key: String,
109}
110
111/// `remove_ssh_key` and `remove_access_token`.
112#[derive(Debug, Serialize, Deserialize)]
113pub struct RemoveArgs {
114 pub user: User,
115 pub id: String,
116}
117
Agents as a team: lifecycle, merge queue, billing and a new shell118/// `create_access_token`: a token that acts as `user`. For a workspace
119/// acting through a token of its own, the new token belongs to that
120/// workspace too.
API and MCP server, Rust identity service, registration, site redesign121#[derive(Debug, Serialize, Deserialize)]
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)122#[serde(rename_all = "camelCase")]
API and MCP server, Rust identity service, registration, site redesign123pub struct CreateAccessTokenArgs {
124 pub user: User,
125 pub name: String,
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)126 /// When set, the token stops working after this many seconds and is
127 /// left out of the user's token list. Used for hosted attempts.
128 #[serde(default)]
129 pub ttl_seconds: Option<u64>,
API and MCP server, Rust identity service, registration, site redesign130}
131
132/// The plaintext token is returned once and never stored.
133#[derive(Debug, Serialize, Deserialize)]
134pub struct CreatedAccessToken {
135 pub token: String,
136 pub info: AccessToken,
137}
138
139/// `register`: creates an account and signs it in.
140/// Returns `Outcome<SignedIn>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look141///
142/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
143/// new account needs `invite_code`: an unused, unexpired invite, and, when
144/// the invite names an email, that address. See [`CreateInviteArgs`].
API and MCP server, Rust identity service, registration, site redesign145#[derive(Debug, Serialize, Deserialize)]
146pub struct RegisterArgs {
147 pub username: String,
148 pub email: String,
149 pub password: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look150 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
151 /// registration is open.
152 #[serde(default)]
153 pub invite_code: Option<String>,
154 /// Who is asking, such as the visitor's IP address, for rate limits.
155 #[serde(default)]
156 pub client: Option<String>,
API and MCP server, Rust identity service, registration, site redesign157}
Email verification, password reset, and Git for AI scale positioning158
159/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
160#[derive(Debug, Serialize, Deserialize)]
161pub struct EmailTokenArgs {
162 pub token: String,
163}
164
165/// `request_password_reset`. Always succeeds, so it cannot be used to find
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look166/// out which addresses have accounts. Any confirmed address of an account
167/// works: the link goes to the address given, and the primary (and the
168/// backup) are told a reset was asked for. A few requests an hour per
169/// address and per `client`; past that, nothing is sent.
Email verification, password reset, and Git for AI scale positioning170#[derive(Debug, Serialize, Deserialize)]
171pub struct EmailArgs {
172 pub email: String,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look173 /// Who is asking, such as the visitor's IP address, for rate limits.
174 #[serde(default)]
175 pub client: Option<String>,
Email verification, password reset, and Git for AI scale positioning176}
177
178/// `reset_password`: sets a new password and ends every session.
179/// Returns `Outcome<User>`.
180#[derive(Debug, Serialize, Deserialize)]
181pub struct ResetPasswordArgs {
182 pub token: String,
183 pub password: String,
184}
Device sign-in replaces registering and minting tokens over the API185
186/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
187#[derive(Debug, Serialize, Deserialize)]
188#[serde(rename_all = "camelCase")]
189pub struct DeviceStartArgs {
190 /// What is asking, shown to the person approving, e.g. "Claude Code".
191 pub client_name: String,
192}
193
194#[derive(Debug, Serialize, Deserialize)]
195#[serde(rename_all = "camelCase")]
196pub struct DeviceStart {
197 /// Secret held by the tool and exchanged for a token once approved.
198 pub device_code: String,
199 /// Short code shown to the person, e.g. `WDJB-MJHT`.
200 pub user_code: String,
201 /// Seconds until both codes stop working.
202 pub expires_in: u32,
203 /// Seconds the tool should wait between polls.
204 pub interval: u32,
205}
206
207/// `device_lookup`: what a user code is asking for, or null if it is not
208/// valid. Returns `Option<DeviceRequest>`.
209#[derive(Debug, Serialize, Deserialize)]
210#[serde(rename_all = "camelCase")]
211pub struct DeviceLookupArgs {
212 pub user_code: String,
213}
214
215#[derive(Debug, Serialize, Deserialize)]
216#[serde(rename_all = "camelCase")]
217pub struct DeviceRequest {
218 pub user_code: String,
219 pub client_name: String,
220}
221
222/// `device_resolve`: the signed-in person approves or denies a request.
223/// Returns `Outcome<bool>`.
224#[derive(Debug, Serialize, Deserialize)]
225#[serde(rename_all = "camelCase")]
226pub struct DeviceResolveArgs {
227 pub user_code: String,
228 pub user: User,
229 pub approve: bool,
230}
231
232/// `device_claim`: the tool asks whether its request was approved.
233#[derive(Debug, Serialize, Deserialize)]
234#[serde(rename_all = "camelCase")]
235pub struct DeviceClaimArgs {
236 pub device_code: String,
237}
238
239/// The answer to a `device_claim`.
240#[derive(Debug, Serialize, Deserialize)]
241#[serde(tag = "status", rename_all = "snake_case")]
242pub enum DeviceClaim {
243 /// Nobody has approved or denied it yet; ask again after the interval.
244 Pending,
245 Denied,
246 /// The code was never issued, has expired, or was already used.
247 Expired,
248 /// The access token, returned once.
249 Approved {
250 token: String,
251 user: User,
252 },
253}
Workspaces own repositories254
255/// A workspace: the owner of repositories, and the first segment of their
256/// URLs. A person's own space and a team's are the same thing.
257#[derive(Clone, Debug, Serialize, Deserialize)]
258#[serde(rename_all = "camelCase")]
259pub struct Workspace {
260 pub id: String,
261 pub slug: String,
262 pub name: String,
Agents as a team: lifecycle, merge queue, billing and a new shell263 /// One line saying what the workspace is for.
264 pub description: Option<String>,
Workspaces own repositories265 /// RFC 3339.
266 pub created_at: String,
267 pub member_count: u32,
Workspace names and icons, and a component kit for every control268 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
269 /// `/avatars/<avatar>`. Null means the generated letter avatar.
270 #[serde(default)]
271 pub avatar: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look272 /// What every member gets on each of its repositories; owners have
273 /// Admin. See [`crate::access`].
274 #[serde(default)]
275 pub base_permission: crate::access::BasePermission,
Workspaces own repositories276}
277
278#[derive(Clone, Debug, Serialize, Deserialize)]
279pub struct Member {
280 pub username: String,
281 pub role: crate::Role,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look282 /// Their display name, when they set one.
283 #[serde(default)]
284 pub name: Option<String>,
285 /// Their uploaded avatar: the SHA-256 of its bytes, served at
286 /// `/avatars/<avatar>`. None means the generated letter avatar.
287 #[serde(default)]
288 pub avatar: Option<String>,
Workspaces own repositories289}
290
291/// `create_workspace`. Returns `Outcome<Workspace>`.
292#[derive(Debug, Serialize, Deserialize)]
293pub struct CreateWorkspaceArgs {
294 pub user: User,
295 pub slug: String,
296 #[serde(default)]
297 pub name: String,
298}
299
300/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
301#[derive(Debug, Serialize, Deserialize)]
302pub struct SlugArgs {
303 pub slug: String,
304}
305
306/// `list_members`: members only. Returns `Outcome<Vec<Member>>`.
307#[derive(Debug, Serialize, Deserialize)]
308pub struct ListMembersArgs {
309 pub slug: String,
310 pub viewer: crate::Viewer,
311}
312
313/// `add_member` and `remove_member`: owners only.
314/// Each returns `Outcome<bool>`.
315#[derive(Debug, Serialize, Deserialize)]
316pub struct MemberArgs {
317 pub actor: User,
318 pub slug: String,
319 pub username: String,
320}
OAuth 2.1 sign-in for MCP clients and other applications321
Agents as a team: lifecycle, merge queue, billing and a new shell322/// `update_workspace`: owners only. An empty name falls back to the slug;
323/// an empty description clears it. Returns `Outcome<Workspace>`.
324#[derive(Debug, Serialize, Deserialize)]
325pub struct UpdateWorkspaceArgs {
326 pub actor: User,
327 pub slug: String,
328 pub name: String,
329 pub description: String,
330}
331
Agents and memory, checks and conflicts, profiles, slug renames, custom domains332/// `rename_workspace`: owners only. Changes the workspace's slug, the first
333/// segment of its URLs, to `new_slug`; the display name is untouched. The
334/// old slug redirects to the new one, and is held for this workspace, for
335/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
336/// `Outcome<Workspace>`.
337///
338/// `check_workspace_rename` takes the same arguments and answers whether
339/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
340#[derive(Debug, Serialize, Deserialize)]
341#[serde(rename_all = "camelCase")]
342pub struct RenameWorkspaceArgs {
343 pub actor: User,
344 pub slug: String,
345 pub new_slug: String,
346}
347
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look348/// `delete_workspace`: owners only, and only a person. `confirm` must be
349/// the workspace's slug, typed out. Refused while the workspace still
350/// holds repositories or projects, or while billing cannot settle it
351/// (`close_workspace`). Removes its memberships, its access tokens and its
352/// old-slug redirects; billing's ledger and the audit log keep its
353/// history. The slug is never given to another workspace; the person
354/// whose username it is may make a workspace of that name again.
355/// Publishes `workspace.deleted`. Returns `Outcome<bool>`.
356///
357/// `check_workspace_deletion` takes the same arguments (with `confirm`
358/// ignored) and says what stands in the way, changing nothing. Returns
359/// `Outcome<WorkspaceDeletion>`.
360#[derive(Debug, Serialize, Deserialize)]
361pub struct DeleteWorkspaceArgs {
362 pub actor: User,
363 pub slug: String,
364 #[serde(default)]
365 pub confirm: String,
366 /// Where the request came in, for the audit log; g1t.sh when absent.
367 #[serde(default)]
368 pub surface: Option<crate::audit::Surface>,
369}
370
371/// What stands between a workspace and its deletion. Nothing does when
372/// both counts are zero and `billing` is null.
373#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
374pub struct WorkspaceDeletion {
375 pub repositories: u32,
376 pub projects: u32,
377 /// Why billing cannot close the workspace yet, in words for its owner.
378 pub billing: Option<String>,
379}
380
381impl WorkspaceDeletion {
382 pub fn blocked(&self) -> bool {
383 self.repositories > 0 || self.projects > 0 || self.billing.is_some()
384 }
385
386 /// Why the workspace cannot be deleted yet, as one sentence, or `None`.
387 pub fn reason(&self, slug: &str) -> Option<String> {
388 let plural = |n: u32, one: &str, many: &str| {
389 format!("{n} {}", if n == 1 { one } else { many })
390 };
391 let mut held = Vec::new();
392 if self.repositories > 0 {
393 held.push(plural(self.repositories, "repository", "repositories"));
394 }
395 if self.projects > 0 {
396 held.push(plural(self.projects, "project", "projects"));
397 }
398 if !held.is_empty() {
399 return Some(format!(
400 "{slug} still holds {}. Transfer them to another workspace first.",
401 held.join(" and ")
402 ));
403 }
404 self.billing.clone()
405 }
406}
407
408/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
409/// tokens of agents at work on it are kept pointing at it. For repos'
410/// `transfer`. Returns `bool`.
411#[derive(Debug, Serialize, Deserialize)]
412pub struct TransferRepoScopesArgs {
413 pub from: crate::repos::RepoPath,
414 pub to: crate::repos::RepoPath,
415}
416
Agents and memory, checks and conflicts, profiles, slug renames, custom domains417/// How long a workspace's old slug keeps redirecting to it, and stays
418/// reserved for it, after a rename.
419pub const SLUG_HOLD_DAYS: u64 = 90;
420
421/// How long a workspace must wait between renames.
422pub const RENAME_COOLDOWN_HOURS: u64 = 24;
423
424// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
425// workspace's current slug when `slug` is one it was renamed from within
426// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
427// is in use).
428
Workspace names and icons, and a component kit for every control429/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
430/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
431/// the icon. Returns `Outcome<Workspace>`.
432#[derive(Debug, Serialize, Deserialize)]
433pub struct SetWorkspaceAvatarArgs {
434 pub actor: User,
435 pub slug: String,
436 pub image: Option<String>,
437}
438
439/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
440/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
441#[derive(Debug, Serialize, Deserialize)]
442pub struct SetUserAvatarArgs {
443 pub user: User,
444 pub image: Option<String>,
445}
446
447/// The largest avatar that can be uploaded, in bytes.
448pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
449
Agents as a team: lifecycle, merge queue, billing and a new shell450/// `list_workspace_tokens`: members only. Returns
451/// `Outcome<Vec<AccessToken>>`.
452#[derive(Debug, Serialize, Deserialize)]
453pub struct WorkspaceTokensArgs {
454 pub slug: String,
455 pub viewer: crate::Viewer,
456}
457
458/// `create_workspace_token`: owners only. The token belongs to the
459/// workspace, acts as it, and keeps working when the member who made it
460/// leaves. Returns `Outcome<CreatedAccessToken>`.
461#[derive(Debug, Serialize, Deserialize)]
462pub struct CreateWorkspaceTokenArgs {
463 pub actor: User,
464 pub slug: String,
465 pub name: String,
466}
467
468/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
469#[derive(Debug, Serialize, Deserialize)]
470pub struct RemoveWorkspaceTokenArgs {
471 pub actor: User,
472 pub slug: String,
473 pub id: String,
474}
475
OAuth 2.1 sign-in for MCP clients and other applications476/// `oauth_authorize`: the signed-in person approved an application. The
477/// caller has checked the client and that it may be redirected to
478/// `redirect_uri`. Returns `OAuthCode`.
479#[derive(Debug, Serialize, Deserialize)]
480#[serde(rename_all = "camelCase")]
481pub struct OAuthAuthorizeArgs {
482 pub user: User,
483 pub client_id: String,
484 /// Shown wherever the application's access is listed.
485 pub client_name: String,
486 pub redirect_uri: String,
487 /// PKCE challenge, method S256.
488 pub code_challenge: String,
489}
490
491#[derive(Debug, Serialize, Deserialize)]
492pub struct OAuthCode {
493 pub code: String,
494}
495
496/// `oauth_exchange`: redeems an authorization code.
497/// Returns `Outcome<OAuthTokens>`.
498#[derive(Debug, Serialize, Deserialize)]
499#[serde(rename_all = "camelCase")]
500pub struct OAuthExchangeArgs {
501 pub code: String,
502 pub code_verifier: String,
503 pub client_id: String,
504 pub redirect_uri: String,
505}
506
507/// `oauth_refresh`: trades a refresh token for new tokens.
508/// Returns `Outcome<OAuthTokens>`.
509#[derive(Debug, Serialize, Deserialize)]
510#[serde(rename_all = "camelCase")]
511pub struct OAuthRefreshArgs {
512 pub refresh_token: String,
513 pub client_id: String,
514}
515
516#[derive(Debug, Serialize, Deserialize)]
517#[serde(rename_all = "camelCase")]
518pub struct OAuthTokens {
519 pub access_token: String,
520 /// Works once; using it returns the next one.
521 pub refresh_token: String,
522 /// Seconds until the access token stops working.
523 pub expires_in: u64,
524}
525
526/// An application a person has signed in to. Listed by `list_oauth_grants`
527/// and ended by `revoke_oauth_grant`.
528#[derive(Debug, Serialize, Deserialize)]
529#[serde(rename_all = "camelCase")]
530pub struct OAuthGrant {
531 pub id: String,
532 pub client_name: String,
533 /// RFC 3339.
534 pub created_at: String,
535 /// RFC 3339.
536 pub last_used_at: String,
537}
Agents as a team: lifecycle, merge queue, billing and a new shell538
539
540/// What an agent's token may do: these operations, in this repository.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API541#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
Agents as a team: lifecycle, merge queue, billing and a new shell542pub struct AgentScope {
543 pub repo: crate::repos::RepoPath,
544 /// API and MCP operation names, such as `create_issue`.
545 pub operations: Vec<String>,
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API546 /// Set on a run credential: the run it belongs to, and what it may do
547 /// with git. See [`crate::credentials`].
548 #[serde(default, skip_serializing_if = "Option::is_none")]
549 pub run: Option<crate::credentials::RunBinding>,
Agents as a team: lifecycle, merge queue, billing and a new shell550}
551
552/// `create_agent_token`: a token for a g1t agent working on someone's
553/// behalf. It acts as `g1t-agent`, a member of the repository's workspace,
554/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
555#[derive(Debug, Serialize, Deserialize)]
556#[serde(rename_all = "camelCase")]
557pub struct CreateAgentTokenArgs {
558 /// The person the agent works for; the token is recorded as theirs.
559 pub on_behalf_of: User,
560 pub scope: AgentScope,
561 pub ttl_seconds: u64,
562}
563
564// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
565// agent's token may do, or null for any other token.
566
567/// The id and name g1t's agents act under.
568pub const AGENT_ID: &str = "usr_g1t_agent";
569pub const AGENT_NAME: &str = "g1t-agent";
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace570
571// --- Staff ---------------------------------------------------------------
572//
573// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
574// membership: only sudo calls them, over its service binding, after it has
575// verified a Cloudflare Access sign-in and its staff list. Nothing a
576// customer can reach should ever forward to them.
577
578/// `notify_owners`: emails a short notice, with one link, to each owner of
579/// a workspace with a confirmed address. Called by other services (billing
580/// warns owners near their usage limit), never on a person's behalf.
581/// Returns how many were sent.
582#[derive(Clone, Debug, Serialize, Deserialize)]
583pub struct NotifyOwnersArgs {
584 pub workspace: String,
585 pub subject: String,
586 /// One or two sentences: what happened and what it means.
587 pub intro: String,
588 /// The button's words, such as `Open billing`.
589 pub action: String,
590 /// Where the button goes; must be on g1t.sh.
591 pub link: String,
592 /// Small print: why they got it.
593 pub footer: String,
594}
595
596/// `admin_workspaces`: every workspace, newest first, at most
597/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
598/// an owner's username or email contains `query`. Returns
599/// `Vec<AdminWorkspace>`. Staff only.
600#[derive(Debug, Default, Serialize, Deserialize)]
601pub struct AdminWorkspacesArgs {
602 #[serde(default)]
603 pub query: Option<String>,
604}
605
606/// The most workspaces one `admin_workspaces` call returns.
607pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
608
609/// An owner of a workspace, as staff see them.
610#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
611pub struct AdminOwner {
612 pub username: String,
613 pub email: Option<String>,
614}
615
616/// A workspace as staff see it: who owns it and how many belong to it.
617#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
618#[serde(rename_all = "camelCase")]
619pub struct AdminWorkspace {
620 pub slug: String,
621 pub name: String,
622 /// RFC 3339.
623 pub created_at: String,
624 pub owners: Vec<AdminOwner>,
625 pub member_count: u32,
626}
627
628/// `admin_workspace`: one workspace with every member, or null. Takes
629/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
630#[derive(Clone, Debug, Serialize, Deserialize)]
631#[serde(rename_all = "camelCase")]
632pub struct AdminWorkspaceDetail {
633 pub slug: String,
634 pub name: String,
635 pub description: Option<String>,
636 /// RFC 3339.
637 pub created_at: String,
638 /// Owners first, then by username.
639 pub members: Vec<AdminMember>,
640}
641
642/// A member of a workspace, as staff see them.
643#[derive(Clone, Debug, Serialize, Deserialize)]
644pub struct AdminMember {
645 pub username: String,
646 pub email: Option<String>,
647 pub role: crate::Role,
648 /// When they joined the workspace. RFC 3339.
649 pub joined: String,
650}
Agents and memory, checks and conflicts, profiles, slug renames, custom domains651
652// --- Profiles ------------------------------------------------------------
653//
654// A person's public page at `g1t.sh/u/<username>`. Everything in a
655// `Profile` is shown to anyone, signed in or not; an email address never is.
656
657/// The most characters each profile field takes.
658pub const MAX_PROFILE_NAME: usize = 80;
659pub const MAX_PROFILE_BIO: usize = 160;
660pub const MAX_PROFILE_LOCATION: usize = 80;
661pub const MAX_PROFILE_WEBSITE: usize = 200;
662pub const MAX_PROFILE_PRONOUNS: usize = 40;
663
664/// What anyone may see about a person.
665#[derive(Clone, Debug, Default, Serialize, Deserialize)]
666#[serde(rename_all = "camelCase")]
667pub struct Profile {
668 pub username: String,
669 /// The name they go by, if they gave one.
670 pub name: Option<String>,
671 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
672 pub bio: Option<String>,
673 pub location: Option<String>,
674 /// An `https://` address.
675 pub website: Option<String>,
676 pub pronouns: Option<String>,
677 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
678 pub avatar: Option<String>,
679 /// When the account was made. RFC 3339.
680 pub created_at: String,
681}
682
683// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
684// an account that does not exist.
685
686/// `update_profile`: a person changes their own profile. Every field is
687/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
688#[derive(Debug, Default, Serialize, Deserialize)]
689#[serde(rename_all = "camelCase")]
690pub struct UpdateProfileArgs {
691 pub actor: User,
692 #[serde(default)]
693 pub name: String,
694 #[serde(default)]
695 pub bio: String,
696 #[serde(default)]
697 pub location: String,
698 #[serde(default)]
699 pub website: String,
700 #[serde(default)]
701 pub pronouns: String,
702}
703
704/// `profile_workspaces`: the workspaces shown on a person's profile, as
705/// `viewer` may see them. A membership is shown only when it is no secret
706/// from the viewer: a workspace the viewer belongs to as well, or one of
707/// `public`, the workspaces the caller found the person has made a public
708/// project in (whose page shows that already). Returns
709/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
710#[derive(Debug, Serialize, Deserialize)]
711pub struct ProfileWorkspacesArgs {
712 pub username: String,
713 pub viewer: crate::Viewer,
714 #[serde(default)]
715 pub public: Vec<String>,
716}
717
718/// A workspace on a person's profile.
719#[derive(Clone, Debug, Serialize, Deserialize)]
720pub struct ProfileWorkspace {
721 pub slug: String,
722 pub name: String,
723 pub avatar: Option<String>,
724}
Search across all of g1t, Explore, and a command palette725
726/// `directory`: every account or every workspace, as their public pages
727/// show them, a page at a time in name order. For services that index
728/// them, such as search; nothing private is in it. Returns
729/// `DirectoryPage`.
730#[derive(Debug, Default, Serialize, Deserialize)]
731pub struct DirectoryArgs {
732 /// `user` or `workspace`.
733 pub kind: String,
734 /// Names after this one.
735 #[serde(default)]
736 pub after: Option<String>,
737 pub limit: u32,
738}
739
740/// One account or workspace in the directory.
741#[derive(Clone, Debug, Serialize, Deserialize)]
742#[serde(rename_all = "camelCase")]
743pub struct DirectoryEntry {
744 /// The account's or workspace's id.
745 pub id: String,
746 /// A username or a workspace's slug.
747 pub slug: String,
748 /// A person's display name or a workspace's name.
749 pub name: Option<String>,
750 /// A person's bio or a workspace's description.
751 pub bio: Option<String>,
752 pub avatar: Option<String>,
753 /// RFC 3339.
754 pub created_at: String,
755}
756
757#[derive(Clone, Debug, Default, Serialize, Deserialize)]
758pub struct DirectoryPage {
759 pub entries: Vec<DirectoryEntry>,
760 /// Where the next page starts; null on the last.
761 pub next: Option<String>,
762}
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look763
764// --- Invites ---------------------------------------------------------------
765//
766// While registration is invite-only, every new account (with a password or
767// through GitHub) needs an invite code. Each person may have
768// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
769// to a workspace, whose owners share them. Inviting an email with no
770// account into a workspace makes an invite bound to that address, which
771// registers and joins in one step. See services/identity/src/invites.rs.
772
773/// Whether anyone may make an account, or only someone with an invite. Set
774/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
775/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
776#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
777#[serde(rename_all = "snake_case")]
778pub enum RegistrationMode {
779 #[default]
780 Invite,
781 Open,
782}
783
784impl RegistrationMode {
785 pub fn parse(text: Option<&str>) -> RegistrationMode {
786 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
787 Some("open") => RegistrationMode::Open,
788 _ => RegistrationMode::Invite,
789 }
790 }
791}
792
793/// How many invites a person may have out at once, unless identity's
794/// `INVITES_PER_USER` var says otherwise.
795pub const INVITES_PER_USER: u32 = 5;
796
797/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
798/// otherwise.
799pub const INVITE_TTL_DAYS: u64 = 30;
800
801/// Where an invite stands. Only a pending invite can be used or revoked.
802/// An expired or revoked invite that was never used gives its inviter the
803/// invite back.
804#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
805#[serde(rename_all = "snake_case")]
806pub enum InviteStatus {
807 Pending,
808 Redeemed,
809 Expired,
810 Revoked,
811}
812
813/// What using an invite does.
814#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
815#[serde(rename_all = "snake_case")]
816pub enum InviteKind {
817 /// Makes a new account, and joins `workspace` when one is set.
818 Account,
819 /// An existing account joins `workspace`. Never makes an account.
820 Workspace,
821}
822
823/// Whose allowance an invite uses.
824#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
825#[serde(rename_all = "snake_case")]
826pub enum InviteCharge {
827 /// Its inviter's own.
828 User,
829 /// The workspace's, granted by staff and shared by its owners.
830 Workspace,
831 /// Nobody's: staff minted it, or it invites an existing account.
832 None,
833}
834
835/// One invite, as the person who made it sees it.
836#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
837#[serde(rename_all = "camelCase")]
838pub struct Invite {
839 pub id: String,
840 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
841 /// is made, and afterwards to whoever made it while it is pending.
842 /// Null otherwise.
843 pub code: Option<String>,
844 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
845 pub hint: String,
846 /// Only an account with this address can use it. Null: anyone with
847 /// the code.
848 pub email: Option<String>,
849 pub kind: InviteKind,
850 /// The workspace it joins, by slug.
851 pub workspace: Option<String>,
852 pub status: InviteStatus,
853 pub charged_to: InviteCharge,
854 /// Who made it, by username. Null when g1t staff did.
855 pub invited_by: Option<String>,
856 /// The account that used it, by username.
857 pub redeemed_by: Option<String>,
858 /// RFC 3339.
859 pub created_at: String,
860 /// RFC 3339.
861 pub expires_at: String,
862 /// RFC 3339.
863 pub redeemed_at: Option<String>,
864 /// RFC 3339.
865 pub revoked_at: Option<String>,
866 /// The staff member who minted it. Only in staff views.
867 #[serde(default, skip_serializing_if = "Option::is_none")]
868 pub staff: Option<String>,
869}
870
871/// How many invites someone may have out, and how many they have.
872#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
873pub struct Allowance {
874 /// Null: no limit.
875 pub limit: Option<u32>,
876 /// Pending and used invites; revoked and expired ones are not counted.
877 pub used: u32,
878 /// Null: no limit.
879 pub remaining: Option<u32>,
880}
881
882impl Allowance {
883 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
884 Allowance {
885 limit,
886 used,
887 remaining: limit.map(|limit| limit.saturating_sub(used)),
888 }
889 }
890
891 pub fn exhausted(&self) -> bool {
892 self.remaining == Some(0)
893 }
894}
895
896/// A workspace's shared invites, for one of its owners.
897#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
898pub struct WorkspaceAllowance {
899 pub slug: String,
900 pub allowance: Allowance,
901}
902
903/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
904/// and what they have left. Returns `InvitesOverview`.
905#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
906pub struct InvitesOverview {
907 pub mode: RegistrationMode,
908 pub allowance: Allowance,
909 /// Workspaces the person owns that staff granted invites to.
910 pub workspaces: Vec<WorkspaceAllowance>,
911 pub invites: Vec<Invite>,
912}
913
914/// `create_invite`: a person makes an invite, optionally for one email
915/// address. People only; never an agent or a workspace's token, and not
916/// before their email is confirmed. Uses one of the person's invites, or,
917/// with `workspace`, one of the invites staff granted that workspace (its
918/// owners only). Emails the address when one is given. Returns
919/// `Outcome<Invite>`, with the code.
920///
921/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
922/// invite; a workspace's owners may revoke one made for the workspace.
923/// The invite comes back to whoever it was charged to. Returns
924/// `Outcome<Invite>`.
925#[derive(Debug, Serialize, Deserialize)]
926pub struct CreateInviteArgs {
927 pub user: User,
928 #[serde(default)]
929 pub email: Option<String>,
930 /// Use this workspace's granted invites, by slug.
931 #[serde(default)]
932 pub workspace: Option<String>,
933 /// Where the request came in, for the audit log; g1t.sh when absent.
934 #[serde(default)]
935 pub surface: Option<crate::audit::Surface>,
936}
937
938/// `check_invite`: what an invite code is for, before using it. Returns
939/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas940/// expired gets the same answer, so codes cannot be probed. With
941/// `any_status`, a real code that can no longer be used is described
942/// instead (its `status` says why), so the page can say whom to ask for a
943/// new one; an unknown code still gets the one answer.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look944#[derive(Debug, Serialize, Deserialize)]
945pub struct InviteCodeArgs {
946 pub code: String,
947 /// Who is asking, such as the visitor's IP address, for rate limits.
948 #[serde(default)]
949 pub client: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas950 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
951 #[serde(default)]
952 pub viewer: Option<User>,
953 #[serde(default)]
954 pub any_status: bool,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look955}
956
957/// Someone shown on an invite.
958#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
959pub struct InviteFrom {
960 pub username: String,
961 pub name: Option<String>,
962 pub avatar: Option<String>,
963}
964
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas965/// A repository an invite code was sent with: using the code accepts the
966/// invitation to collaborate on it.
967#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
968pub struct InviteRepository {
969 /// `workspace/repo`.
970 pub name: String,
971 /// The role it gives, such as `write`.
972 pub role: String,
973}
974
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look975/// What a valid invite code is for.
976#[derive(Clone, Debug, Serialize, Deserialize)]
977#[serde(rename_all = "camelCase")]
978pub struct InvitePreview {
979 pub kind: InviteKind,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas980 /// Pending, unless `any_status` asked about a code that is spent.
981 pub status: InviteStatus,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look982 /// Null when g1t staff sent it.
983 pub invited_by: Option<InviteFrom>,
984 pub workspace: Option<ProfileWorkspace>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas985 /// The repository it accepts an invitation to, if it was sent with one.
986 pub repository: Option<InviteRepository>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look987 /// The address it is for, partly hidden, such as `a•••@example.com`.
988 pub email: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas989 /// The address in full, while it is pending: whoever holds the code
990 /// was sent it there. Fills in and locks the sign-up form.
991 pub address: Option<String>,
992 /// Whether the address it is for has a g1t account already, so the
993 /// page asks them to sign in rather than sign up.
994 pub has_account: bool,
995 /// With a viewer: whether the invite is theirs (it is for one of their
996 /// confirmed addresses, or they used it). Null without a viewer or,
997 /// for a pending invite, when it is for anyone with the code.
998 pub for_viewer: Option<bool>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look999 /// RFC 3339.
1000 pub expires_at: String,
1001}
1002
1003/// `accept_invite`: a signed-in person uses a workspace invite made for
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1004/// their confirmed address, and joins the workspace, or an invite sent with
1005/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1006/// workspace's slug, or `workspace/repo`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1007#[derive(Debug, Serialize, Deserialize)]
1008pub struct AcceptInviteArgs {
1009 pub user: User,
1010 pub code: String,
1011}
1012
1013/// `invite_member`: an owner invites an email address into a workspace.
1014/// It always makes an invite bound to that address and emails it, so the
1015/// answer never says whether the address has an account. Without one, the
1016/// invite registers and joins in one step, and uses one of the workspace's
1017/// granted invites or else one of the owner's own. With one, it costs
1018/// nothing. Returns `Outcome<Invite>`, with the code.
1019#[derive(Debug, Serialize, Deserialize)]
1020pub struct InviteMemberArgs {
1021 pub actor: User,
1022 pub slug: String,
1023 pub email: String,
1024 /// Where the request came in, for the audit log; g1t.sh when absent.
1025 #[serde(default)]
1026 pub surface: Option<crate::audit::Surface>,
1027}
1028
1029/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1030/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1031///
1032/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1033#[derive(Debug, Serialize, Deserialize)]
1034pub struct WorkspaceInviteArgs {
1035 pub actor: User,
1036 pub slug: String,
1037 pub id: String,
1038}
1039
1040/// `request_access`: someone without an invite asks for one. Kept on the
1041/// waitlist, one entry per address. Answers the same way whether or not
1042/// the address is already on it. Returns `Outcome<bool>`.
1043#[derive(Debug, Default, Serialize, Deserialize)]
1044pub struct RequestAccessArgs {
1045 pub email: String,
1046 /// What they will build, if they said.
1047 #[serde(default)]
1048 pub about: String,
1049 /// Who is asking, such as the visitor's IP address, for rate limits.
1050 #[serde(default)]
1051 pub client: Option<String>,
1052}
1053
1054/// The most characters `RequestAccessArgs::about` keeps.
1055pub const MAX_WAITLIST_ABOUT: usize = 1000;
1056
1057// `registration` takes `{}` and returns `RegistrationMode`.
1058
1059// --- Invites, staff only ---
1060
1061#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1062#[serde(rename_all = "snake_case")]
1063pub enum WaitlistStatus {
1064 Waiting,
1065 Invited,
1066 Dismissed,
1067}
1068
1069impl WaitlistStatus {
1070 pub fn as_str(self) -> &'static str {
1071 match self {
1072 WaitlistStatus::Waiting => "waiting",
1073 WaitlistStatus::Invited => "invited",
1074 WaitlistStatus::Dismissed => "dismissed",
1075 }
1076 }
1077}
1078
1079/// Someone who asked for access.
1080#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1081#[serde(rename_all = "camelCase")]
1082pub struct WaitlistEntry {
1083 pub id: String,
1084 pub email: String,
1085 pub about: Option<String>,
1086 pub status: WaitlistStatus,
1087 pub invite_id: Option<String>,
1088 pub decided_by: Option<String>,
1089 /// RFC 3339.
1090 pub decided_at: Option<String>,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1091 /// What staff wrote when approving; it went in the invite email.
1092 #[serde(default)]
1093 pub note: Option<String>,
1094 /// The account made with the invite, once it was used.
1095 #[serde(default)]
1096 pub joined_as: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1097 /// When they first asked. RFC 3339.
1098 pub created_at: String,
1099 /// When they last asked. RFC 3339.
1100 pub updated_at: String,
1101}
1102
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1103/// `admin_waitlist`: the waitlist, newest first, at most
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1104/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1105///
1106/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1107/// still waiting, for sudo's navigation.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1108#[derive(Debug, Default, Serialize, Deserialize)]
1109pub struct AdminWaitlistArgs {
1110 /// Part of an email address or of what they said.
1111 #[serde(default)]
1112 pub query: Option<String>,
1113 /// Null: every status.
1114 #[serde(default)]
1115 pub status: Option<WaitlistStatus>,
1116}
1117
1118/// The most rows one staff listing of invites or the waitlist returns.
1119pub const ADMIN_INVITES_LIMIT: usize = 500;
1120
1121/// `admin_decide_waitlist`: approving mints an invite bound to the
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1122/// address, charged to nobody, and emails it, with `note` if given;
1123/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1124#[derive(Debug, Serialize, Deserialize)]
1125pub struct AdminDecideWaitlistArgs {
1126 pub id: String,
1127 pub approve: bool,
1128 /// The staff member, by email.
1129 pub staff: String,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1130 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1131 #[serde(default)]
1132 pub note: Option<String>,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1133}
1134
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas1135/// The most characters an approval's note keeps.
1136pub const MAX_WAITLIST_NOTE: usize = 500;
1137
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1138/// `admin_invites`: every invite, newest first, at most
1139/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1140/// `query`, or whose email, inviter or redeemer contains it. Returns
1141/// `Vec<Invite>`.
1142#[derive(Debug, Default, Serialize, Deserialize)]
1143pub struct AdminInvitesArgs {
1144 #[serde(default)]
1145 pub query: Option<String>,
1146}
1147
1148/// `admin_revoke_invite`: revokes any pending invite. Returns
1149/// `Outcome<Invite>`.
1150#[derive(Debug, Serialize, Deserialize)]
1151pub struct AdminRevokeInviteArgs {
1152 pub id: String,
1153 pub staff: String,
1154}
1155
1156/// `admin_mint_invite`: staff make an invite that uses nobody's
1157/// allowance, optionally bound to (and emailed to) an address. Returns
1158/// `Outcome<Invite>`, with the code.
1159#[derive(Debug, Serialize, Deserialize)]
1160pub struct AdminMintInviteArgs {
1161 #[serde(default)]
1162 pub email: Option<String>,
1163 pub staff: String,
1164}
1165
1166/// Who staff grant invites to.
1167#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1168#[serde(rename_all = "snake_case")]
1169pub enum GrantTarget {
1170 User,
1171 Workspace,
1172}
1173
1174impl GrantTarget {
1175 pub fn as_str(self) -> &'static str {
1176 match self {
1177 GrantTarget::User => "user",
1178 GrantTarget::Workspace => "workspace",
1179 }
1180 }
1181}
1182
1183/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1184/// slug) `amount` more invites; a negative amount takes some back. Returns
1185/// `Outcome<Allowance>`: theirs afterwards.
1186#[derive(Debug, Serialize, Deserialize)]
1187pub struct AdminGrantInvitesArgs {
1188 pub target: GrantTarget,
1189 pub name: String,
1190 pub amount: i32,
1191 #[serde(default)]
1192 pub note: String,
1193 pub staff: String,
1194}
1195
1196/// The most invites one grant gives or takes back.
1197pub const MAX_INVITE_GRANT: i32 = 1000;
1198
1199/// Invites staff granted.
1200#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1201#[serde(rename_all = "camelCase")]
1202pub struct InviteGrant {
1203 pub amount: i32,
1204 pub note: Option<String>,
1205 pub granted_by: String,
1206 /// RFC 3339.
1207 pub created_at: String,
1208}
1209
1210/// Someone a person invited, and whom they invited in turn.
1211#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1212#[serde(rename_all = "camelCase")]
1213pub struct InviteTreeNode {
1214 pub username: String,
1215 /// When they used the invite. RFC 3339.
1216 pub joined_at: String,
1217 pub invited: Vec<InviteTreeNode>,
1218}
1219
1220/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1221/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1222///
1223/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1224/// invites, grants and invites. Returns `Option<InviteTree>` with
1225/// `username` the slug and no `invited_by`.
1226#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1227#[serde(rename_all = "camelCase")]
1228pub struct InviteTree {
1229 pub username: String,
1230 /// Who invited them, then who invited that person, and so on. Empty
1231 /// for an account made without an invite.
1232 pub invited_by: Vec<String>,
1233 /// The staff member who minted their invite, when staff did.
1234 pub staff: Option<String>,
1235 pub allowance: Allowance,
1236 pub grants: Vec<InviteGrant>,
1237 /// Their invites, newest first.
1238 pub invites: Vec<Invite>,
1239 /// Whom they invited, three levels down.
1240 pub invited: Vec<InviteTreeNode>,
1241}
1242
1243#[cfg(test)]
1244mod deletion_tests {
1245 use super::WorkspaceDeletion;
1246
1247 #[test]
1248 fn says_what_is_left_to_move() {
1249 let clear = WorkspaceDeletion::default();
1250 assert!(!clear.blocked());
1251 assert_eq!(clear.reason("acme"), None);
1252 let held = WorkspaceDeletion {
1253 repositories: 2,
1254 projects: 1,
1255 billing: Some("Pay first.".into()),
1256 };
1257 assert!(held.blocked());
1258 assert_eq!(
1259 held.reason("acme").as_deref(),
1260 Some("acme still holds 2 repositories and 1 project. Transfer them to another workspace first.")
1261 );
1262 let owing = WorkspaceDeletion {
1263 billing: Some("Pay first.".into()),
1264 ..WorkspaceDeletion::default()
1265 };
1266 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
1267 }
1268}