flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/crates/contracts/src/lib.rs

118 lines3,863 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod actions;
8pub mod agents;
9pub mod billing;
10pub mod events;
11pub mod identity;
12pub mod integrations;
13mod ids;
14mod names;
15mod outcome;
16pub mod projects;
17pub mod repos;
18pub mod time;
19pub mod webhooks;
20pub mod work;
21
22pub use ids::new_id;
23pub use names::{is_valid_namespace, is_valid_repo_name};
24pub use outcome::{Failure, FailureCode, Outcome};
25
26use serde::{Deserialize, Serialize};
27
28/// What a member may do in a workspace.
29#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
30#[serde(rename_all = "lowercase")]
31pub enum Role {
32 /// Everything a member can, plus managing members.
33 Owner,
34 /// Create repositories, push, manage issues and merge pull requests.
35 Member,
36}
37
38/// One workspace a user belongs to.
39#[derive(Clone, Debug, Serialize, Deserialize)]
40pub struct Membership {
41 /// The workspace's name in URLs: `g1t.sh/<slug>`.
42 pub slug: String,
43 pub role: Role,
44 /// The workspace's display name, for showing it to people. Set when a
45 /// user is resolved from credentials; absent on principals made up by
46 /// a service.
47 #[serde(default, skip_serializing_if = "Option::is_none")]
48 pub name: Option<String>,
49 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
50 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
51 #[serde(default, skip_serializing_if = "Option::is_none")]
52 pub avatar: Option<String>,
53}
54
55impl Membership {
56 /// A plain member of `slug`, as services act inside one workspace.
57 pub fn member(slug: impl Into<String>) -> Self {
58 Membership {
59 slug: slug.into(),
60 role: Role::Member,
61 name: None,
62 avatar: None,
63 }
64 }
65}
66
67/// What a set of credentials resolved to.
68#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
69#[serde(rename_all = "lowercase")]
70pub enum PrincipalKind {
71 /// A person's account.
72 #[default]
73 User,
74 /// A workspace, acting through one of its own access tokens. Its `id`
75 /// is the workspace's, its `username` the workspace's slug, and it is a
76 /// member of that workspace and no other.
77 Workspace,
78 /// A g1t agent at work in a sandbox, acting through a token that lives
79 /// as long as its run and can do only what that token's scope lists, in
80 /// one repository. Its `username` is `g1t-agent`.
81 Agent,
82}
83
84#[derive(Clone, Debug, Default, Serialize, Deserialize)]
85pub struct User {
86 pub id: String,
87 pub username: String,
88 #[serde(default)]
89 pub kind: PrincipalKind,
90 /// Whether the account's email address has been confirmed. Unverified
91 /// accounts can sign in but cannot create or change anything.
92 #[serde(default)]
93 pub verified: bool,
94 /// The workspaces this user belongs to. Filled in when a user is
95 /// resolved from credentials, so any service can authorize from it.
96 #[serde(default)]
97 pub workspaces: Vec<Membership>,
98 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
99 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
100 #[serde(default, skip_serializing_if = "Option::is_none")]
101 pub avatar: Option<String>,
102}
103
104impl User {
105 pub fn role_in(&self, slug: &str) -> Option<Role> {
106 self.workspaces
107 .iter()
108 .find(|membership| membership.slug == slug)
109 .map(|membership| membership.role)
110 }
111
112 pub fn is_member(&self, slug: &str) -> bool {
113 self.role_in(slug).is_some()
114 }
115}
116
117/// Who is asking. Every read and write in every service takes one.
118pub type Viewer = Option<User>;