Skip to content
215 linesCodeBlameRaw
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod about;
8pub mod access;
9pub mod accounts;
10pub mod actions;
11pub mod agents;
12pub mod audit;
13pub mod backups;
14pub mod billing;
15pub mod capture;
16pub mod checks;
17pub mod codeowners;
18pub mod credentials;
19pub mod deploy_keys;
20pub mod events;
21pub mod fine_grained;
22pub mod github;
23pub mod guardrails;
24pub mod identity;
25pub mod inbox;
26pub mod integrations;
27mod ids;
28mod names;
29mod outcome;
30pub mod packages;
31pub mod projects;
32pub mod repos;
33pub mod rules;
34pub mod runners;
35pub mod scopes;
36pub mod search;
37pub mod security;
38pub mod teams;
39pub mod security_suite;
40pub mod time;
41pub mod tokens;
42pub mod updates;
43pub mod webhooks;
44pub mod work;
45
46pub use ids::new_id;
47pub use names::{
48 aliasable_name, claimable_namespace, is_namespace_shaped, is_reserved_name, is_route_name, is_valid_namespace,
49 is_valid_repo_name,
50};
51pub use outcome::{Failure, FailureCode, Outcome};
52
53use serde::{Deserialize, Serialize};
54
55/// What a member may do in a workspace.
56#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
57#[serde(rename_all = "lowercase")]
58pub enum Role {
59 /// Everything a member can, plus managing members.
60 Owner,
61 /// Create repositories, push, manage issues and merge pull requests.
62 Member,
63}
64
65/// One workspace a user belongs to.
66#[derive(Clone, Debug, Serialize, Deserialize)]
67pub struct Membership {
68 /// The workspace's name in URLs: `g1t.sh/<slug>`.
69 pub slug: String,
70 pub role: Role,
71 /// The workspace's display name, for showing it to people. Set when a
72 /// user is resolved from credentials; absent on principals made up by
73 /// a service.
74 #[serde(default, skip_serializing_if = "Option::is_none")]
75 pub name: Option<String>,
76 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
77 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
78 #[serde(default, skip_serializing_if = "Option::is_none")]
79 pub avatar: Option<String>,
80 /// What a member gets on each of the workspace's repositories: the
81 /// workspace's base permission. Set when a user is resolved from
82 /// credentials; absent means the default, Write. Owners have Admin
83 /// whatever it says. See [`access`].
84 #[serde(default, skip_serializing_if = "Option::is_none")]
85 pub base_permission: Option<access::BasePermission>,
86 /// Who may create the workspace's teams. Set when a user is resolved
87 /// from credentials; absent means the default, any member. See
88 /// [`teams::TeamCreation`].
89 #[serde(default, skip_serializing_if = "Option::is_none")]
90 pub team_creation: Option<teams::TeamCreation>,
91}
92
93impl Membership {
94 /// A plain member of `slug`, as services act inside one workspace.
95 pub fn member(slug: impl Into<String>) -> Self {
96 Membership {
97 slug: slug.into(),
98 role: Role::Member,
99 name: None,
100 avatar: None,
101 base_permission: None,
102 team_creation: None,
103 }
104 }
105}
106
107/// What a set of credentials resolved to.
108#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
109#[serde(rename_all = "lowercase")]
110pub enum PrincipalKind {
111 /// A person's account.
112 #[default]
113 User,
114 /// A workspace, acting through one of its own access tokens. Its `id`
115 /// is the workspace's, its `username` the workspace's slug, and it is a
116 /// member of that workspace and no other.
117 Workspace,
118 /// A g1t agent at work in a sandbox, acting through a token that lives
119 /// as long as its run and can do only what that token's scope lists, in
120 /// one repository. Its `username` is `g1t`.
121 Agent,
122 /// g1t itself: the platform acting on its own, as when it opens a
123 /// pull request to upgrade a vulnerable dependency or merges from the
124 /// queue. Never resolved from credentials: only services make one,
125 /// with [`User::system`]. Its `username` is `g1t`, which nobody can
126 /// register.
127 System,
128}
129
130/// g1t's own identity, as [`PrincipalKind::System`] work is recorded.
131pub mod system {
132 /// Its id wherever an author or actor id is stored.
133 pub const ID: &str = "g1t";
134 /// Its name, shown as the author of what it does.
135 pub const USERNAME: &str = "g1t";
136 /// The address on the commits it makes, which no mailbox receives.
137 pub const EMAIL: &str = "g1t@users.noreply.g1t.sh";
138 /// Ids that earlier versions stored for g1t's own actions, such as a
139 /// merge its settings made. Read as g1t too.
140 pub const LEGACY_IDS: [&str; 3] = ["g1t_policy", "svc_runner", "g1t_runner"];
141
142 /// Whether `id` is g1t's own.
143 pub fn is_system_id(id: &str) -> bool {
144 id == ID || LEGACY_IDS.contains(&id)
145 }
146}
147
148#[derive(Clone, Debug, Default, Serialize, Deserialize)]
149pub struct User {
150 pub id: String,
151 pub username: String,
152 #[serde(default)]
153 pub kind: PrincipalKind,
154 /// Whether the account's email address has been confirmed. Unverified
155 /// accounts can sign in but cannot create or change anything.
156 #[serde(default)]
157 pub verified: bool,
158 /// The workspaces this user belongs to. Filled in when a user is
159 /// resolved from credentials, so any service can authorize from it.
160 #[serde(default)]
161 pub workspaces: Vec<Membership>,
162 /// The person's uploaded avatar: the SHA-256 of its bytes, served at
163 /// `/avatars/<avatar>`. Absent means the generated letter avatar.
164 #[serde(default, skip_serializing_if = "Option::is_none")]
165 pub avatar: Option<String>,
166 /// Set on an agent resolved from its token: who it acts for, with which
167 /// credential, and what it may do. See [`credentials`].
168 #[serde(default, skip_serializing_if = "Option::is_none")]
169 pub acting: Option<Box<credentials::Acting>>,
170 /// The repositories this user has been given a role on directly,
171 /// whether or not they belong to its workspace. Filled in with
172 /// `workspaces`; see [`access`].
173 #[serde(default, skip_serializing_if = "Vec::is_empty")]
174 pub grants: Vec<access::RepoGrant>,
175 /// Set on a user resolved from an access token: its scopes and the
176 /// workspaces or repositories it is limited to. Absent on a signed-in
177 /// session and on an agent (whose `acting` scope applies instead).
178 /// See [`scopes`].
179 #[serde(default, skip_serializing_if = "Option::is_none")]
180 pub token: Option<Box<scopes::TokenAccess>>,
181}
182
183impl User {
184 /// g1t itself, acting in `workspace`: what the platform's own work,
185 /// such as security updates, is done and recorded as.
186 pub fn system(workspace: &str) -> User {
187 User {
188 id: system::ID.to_owned(),
189 username: system::USERNAME.to_owned(),
190 kind: PrincipalKind::System,
191 verified: true,
192 workspaces: vec![Membership::member(workspace.to_lowercase())],
193 ..User::default()
194 }
195 }
196
197 /// Whether this is g1t itself.
198 pub fn is_system(&self) -> bool {
199 self.kind == PrincipalKind::System
200 }
201
202 pub fn role_in(&self, slug: &str) -> Option<Role> {
203 self.workspaces
204 .iter()
205 .find(|membership| membership.slug == slug)
206 .map(|membership| membership.role)
207 }
208
209 pub fn is_member(&self, slug: &str) -> bool {
210 self.role_in(slug).is_some()
211 }
212}
213
214/// Who is asking. Every read and write in every service takes one.
215pub type Viewer = Option<User>;