flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/crates/contracts/src/lib.rs

92 lines2,808 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod actions;
8pub mod billing;
9pub mod events;
10pub mod identity;
11pub mod integrations;
12mod ids;
13mod names;
14mod outcome;
15pub mod projects;
16pub mod repos;
17pub mod time;
18pub mod webhooks;
19pub mod work;
20
21pub use ids::new_id;
22pub use names::{is_valid_namespace, is_valid_repo_name};
23pub use outcome::{Failure, FailureCode, Outcome};
24
25use serde::{Deserialize, Serialize};
26
27/// What a member may do in a workspace.
28#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
29#[serde(rename_all = "lowercase")]
30pub enum Role {
31 /// Everything a member can, plus managing members.
32 Owner,
33 /// Create repositories, push, manage issues and merge pull requests.
34 Member,
35}
36
37/// One workspace a user belongs to.
38#[derive(Clone, Debug, Serialize, Deserialize)]
39pub struct Membership {
40 /// The workspace's name in URLs: `g1t.sh/<slug>`.
41 pub slug: String,
42 pub role: Role,
43}
44
45/// What a set of credentials resolved to.
46#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
47#[serde(rename_all = "lowercase")]
48pub enum PrincipalKind {
49 /// A person's account.
50 #[default]
51 User,
52 /// A workspace, acting through one of its own access tokens. Its `id`
53 /// is the workspace's, its `username` the workspace's slug, and it is a
54 /// member of that workspace and no other.
55 Workspace,
56 /// A g1t agent at work in a sandbox, acting through a token that lives
57 /// as long as its run and can do only what that token's scope lists, in
58 /// one repository. Its `username` is `g1t-agent`.
59 Agent,
60}
61
62#[derive(Clone, Debug, Default, Serialize, Deserialize)]
63pub struct User {
64 pub id: String,
65 pub username: String,
66 #[serde(default)]
67 pub kind: PrincipalKind,
68 /// Whether the account's email address has been confirmed. Unverified
69 /// accounts can sign in but cannot create or change anything.
70 #[serde(default)]
71 pub verified: bool,
72 /// The workspaces this user belongs to. Filled in when a user is
73 /// resolved from credentials, so any service can authorize from it.
74 #[serde(default)]
75 pub workspaces: Vec<Membership>,
76}
77
78impl User {
79 pub fn role_in(&self, slug: &str) -> Option<Role> {
80 self.workspaces
81 .iter()
82 .find(|membership| membership.slug == slug)
83 .map(|membership| membership.role)
84 }
85
86 pub fn is_member(&self, slug: &str) -> bool {
87 self.role_in(slug).is_some()
88 }
89}
90
91/// Who is asking. Every read and write in every service takes one.
92pub type Viewer = Option<User>;