| 1 | // A repository's deploy keys: SSH keys that reach that one repository, |
| 2 | // read-only unless whoever added one allowed write access. Mirrors |
| 3 | // crates/contracts/src/deploy_keys.rs; identity answers in snake_case. |
| 4 | |
| 5 | import type { Result } from "./result"; |
| 6 | import type { User } from "./identity"; |
| 7 | |
| 8 | /** One deploy key, as identity and the API show it. */ |
| 9 | export type DeployKey = { |
| 10 | /** `dk_…`. */ |
| 11 | id: string; |
| 12 | title: string; |
| 13 | /** The public key, `<type> <base64>`, without its comment. */ |
| 14 | key: string; |
| 15 | /** `SHA256:…`, as `ssh-keygen -lf` prints it. */ |
| 16 | fingerprint: string; |
| 17 | /** False when it may push. */ |
| 18 | read_only: boolean; |
| 19 | /** RFC 3339. */ |
| 20 | created_at: string; |
| 21 | /** Who added it; null once that account is gone. */ |
| 22 | created_by: string | null; |
| 23 | /** RFC 3339, to within 5 minutes; null when it never signed in. */ |
| 24 | last_used_at: string | null; |
| 25 | }; |
| 26 | |
| 27 | /** The most deploy keys one repository may have. */ |
| 28 | export const MAX_DEPLOY_KEYS = 100; |
| 29 | |
| 30 | /** Identity's deploy key methods, by repository path. Admins of the repository only. */ |
| 31 | export interface DeployKeysClient { |
| 32 | listDeployKeys(viewer: User | null, owner: string, name: string): Promise<Result<DeployKey[]>>; |
| 33 | /** `readOnly` is true unless said otherwise. */ |
| 34 | addDeployKey( |
| 35 | actor: User, |
| 36 | owner: string, |
| 37 | name: string, |
| 38 | key: { title: string; key: string; readOnly: boolean }, |
| 39 | ): Promise<Result<DeployKey>>; |
| 40 | removeDeployKey(actor: User, owner: string, name: string, id: string): Promise<Result<boolean>>; |
| 41 | } |