g1t/crates/contracts/src/identity.rs

1,331 lines45,072 bytesCodeBlame
1//! The identity service: accounts, credentials and sessions.
2//!
3//! Each `*Args` struct is the argument of the method of the same name,
4//! served at `POST /rpc/<method>`.
5
6use serde::{Deserialize, Serialize};
7
8use crate::User;
9
10#[derive(Clone, Debug, Serialize, Deserialize)]
11#[serde(rename_all = "camelCase")]
12pub struct SshKey {
13 pub id: String,
14 pub title: String,
15 pub fingerprint: String,
16 /// RFC 3339.
17 pub created_at: String,
18}
19
20#[derive(Clone, Debug, Serialize, Deserialize)]
21#[serde(rename_all = "camelCase")]
22pub struct AccessToken {
23 pub id: String,
24 pub name: String,
25 /// RFC 3339.
26 pub created_at: String,
27 /// RFC 3339, to within a few minutes. Null until it is first used.
28 pub last_used_at: Option<String>,
29 /// For a workspace's token, the username of the member who made it.
30 /// Null once that account is gone, and on personal tokens.
31 pub created_by: Option<String>,
32 /// Its scopes, as `resource:level`. Null: full access.
33 #[serde(default)]
34 pub scopes: Option<Vec<String>>,
35 /// Made before tokens had scopes: full access until someone narrows it.
36 #[serde(default)]
37 pub legacy: bool,
38 /// RFC 3339. Null: it does not expire.
39 #[serde(default)]
40 pub expires_at: Option<String>,
41}
42
43/// `sign_in`: verifies a username, or any confirmed email address of the
44/// account, and its password, for website sign-in. Wrong passwords are
45/// counted against the account and `client`, and past a limit nothing is
46/// checked for a while (see identity's `throttle.rs`).
47/// Returns `Outcome<SignedIn>`.
48#[derive(Debug, Serialize, Deserialize)]
49pub struct SignInArgs {
50 pub username: String,
51 pub password: String,
52 /// Who is asking, such as the visitor's IP address, for rate limits.
53 #[serde(default)]
54 pub client: Option<String>,
55}
56
57#[derive(Debug, Serialize, Deserialize)]
58#[serde(rename_all = "camelCase")]
59pub struct SignedIn {
60 pub user: User,
61 pub session_token: String,
62}
63
64/// `sign_out` and `user_for_session`.
65#[derive(Debug, Serialize, Deserialize)]
66#[serde(rename_all = "camelCase")]
67pub struct SessionArgs {
68 pub session_token: String,
69}
70
71/// `user_for_git_credentials`: the account password or an access token.
72#[derive(Debug, Serialize, Deserialize)]
73pub struct GitCredentialsArgs {
74 pub username: String,
75 pub secret: String,
76}
77
78/// `user_for_access_token`.
79#[derive(Debug, Serialize, Deserialize)]
80pub struct TokenArgs {
81 pub token: String,
82}
83
84/// `user_for_ssh_key`.
85#[derive(Debug, Serialize, Deserialize)]
86pub struct FingerprintArgs {
87 pub fingerprint: String,
88}
89
90/// `user_by_username`.
91#[derive(Debug, Serialize, Deserialize)]
92pub struct UsernameArgs {
93 pub username: String,
94}
95
96/// `usernames`: the names behind account and workspace ids, as events and
97/// other records store them. Returns a map from id to name; ids it does
98/// not know are left out.
99#[derive(Debug, Serialize, Deserialize)]
100pub struct UsernamesArgs {
101 pub ids: Vec<String>,
102}
103
104/// `list_ssh_keys` and `list_access_tokens`.
105#[derive(Debug, Serialize, Deserialize)]
106pub struct UserArgs {
107 pub user: User,
108}
109
110/// `add_ssh_key`: `public_key` is one line in OpenSSH format.
111/// Returns `Outcome<SshKey>`.
112#[derive(Debug, Serialize, Deserialize)]
113#[serde(rename_all = "camelCase")]
114pub struct AddSshKeyArgs {
115 pub user: User,
116 pub title: String,
117 pub public_key: String,
118}
119
120/// `remove_ssh_key` and `remove_access_token`.
121#[derive(Debug, Serialize, Deserialize)]
122pub struct RemoveArgs {
123 pub user: User,
124 pub id: String,
125}
126
127/// `create_access_token`: a token that acts as `user`. For a workspace
128/// acting through a token of its own, the new token belongs to that
129/// workspace too.
130#[derive(Debug, Serialize, Deserialize)]
131#[serde(rename_all = "camelCase")]
132pub struct CreateAccessTokenArgs {
133 pub user: User,
134 pub name: String,
135 /// When set, the token stops working after this many seconds and is
136 /// left out of the user's token list, unless `listed`. Used for hosted
137 /// attempts.
138 #[serde(default)]
139 pub ttl_seconds: Option<u64>,
140 /// Its scopes, as `resource:level`; unknown names are left out. Null:
141 /// full access.
142 #[serde(default)]
143 pub scopes: Option<Vec<String>>,
144 /// Listed with the person's tokens although it expires: one they made
145 /// themselves, with an expiry.
146 #[serde(default)]
147 pub listed: bool,
148}
149
150/// `update_access_token`: changes what one of a person's tokens may do.
151/// The token itself is unchanged. Returns `Outcome<AccessToken>`.
152#[derive(Debug, Serialize, Deserialize)]
153pub struct UpdateAccessTokenArgs {
154 pub user: User,
155 pub id: String,
156 /// Null: full access.
157 #[serde(default)]
158 pub scopes: Option<Vec<String>>,
159}
160
161/// The plaintext token is returned once and never stored.
162#[derive(Debug, Serialize, Deserialize)]
163pub struct CreatedAccessToken {
164 pub token: String,
165 pub info: AccessToken,
166}
167
168/// `register`: creates an account and signs it in.
169/// Returns `Outcome<SignedIn>`.
170///
171/// While registration is invite-only (`REGISTRATION_MODE=invite`), every
172/// new account needs `invite_code`: an unused, unexpired invite, and, when
173/// the invite names an email, that address. See [`CreateInviteArgs`].
174#[derive(Debug, Serialize, Deserialize)]
175pub struct RegisterArgs {
176 pub username: String,
177 pub email: String,
178 pub password: String,
179 /// An invite code such as `g1t-k7m2-q9xd-4hpw-…`. Ignored while
180 /// registration is open.
181 #[serde(default)]
182 pub invite_code: Option<String>,
183 /// Who is asking, such as the visitor's IP address, for rate limits.
184 #[serde(default)]
185 pub client: Option<String>,
186}
187
188/// `verify_email`: the token from the emailed link. Returns `Outcome<User>`.
189#[derive(Debug, Serialize, Deserialize)]
190pub struct EmailTokenArgs {
191 pub token: String,
192}
193
194/// `request_password_reset`. Always succeeds, so it cannot be used to find
195/// out which addresses have accounts. Any confirmed address of an account
196/// works: the link goes to the address given, and the primary (and the
197/// backup) are told a reset was asked for. A few requests an hour per
198/// address and per `client`; past that, nothing is sent.
199#[derive(Debug, Serialize, Deserialize)]
200pub struct EmailArgs {
201 pub email: String,
202 /// Who is asking, such as the visitor's IP address, for rate limits.
203 #[serde(default)]
204 pub client: Option<String>,
205}
206
207/// `reset_password`: sets a new password and ends every session.
208/// Returns `Outcome<User>`.
209#[derive(Debug, Serialize, Deserialize)]
210pub struct ResetPasswordArgs {
211 pub token: String,
212 pub password: String,
213}
214
215/// `device_start`: begins a device sign-in. Returns `DeviceStart`.
216#[derive(Debug, Serialize, Deserialize)]
217#[serde(rename_all = "camelCase")]
218pub struct DeviceStartArgs {
219 /// What is asking, shown to the person approving, e.g. "Claude Code".
220 pub client_name: String,
221}
222
223#[derive(Debug, Serialize, Deserialize)]
224#[serde(rename_all = "camelCase")]
225pub struct DeviceStart {
226 /// Secret held by the tool and exchanged for a token once approved.
227 pub device_code: String,
228 /// Short code shown to the person, e.g. `WDJB-MJHT`.
229 pub user_code: String,
230 /// Seconds until both codes stop working.
231 pub expires_in: u32,
232 /// Seconds the tool should wait between polls.
233 pub interval: u32,
234}
235
236/// `device_lookup`: what a user code is asking for, or null if it is not
237/// valid. Returns `Option<DeviceRequest>`.
238#[derive(Debug, Serialize, Deserialize)]
239#[serde(rename_all = "camelCase")]
240pub struct DeviceLookupArgs {
241 pub user_code: String,
242}
243
244#[derive(Debug, Serialize, Deserialize)]
245#[serde(rename_all = "camelCase")]
246pub struct DeviceRequest {
247 pub user_code: String,
248 pub client_name: String,
249}
250
251/// `device_resolve`: the signed-in person approves or denies a request.
252/// Returns `Outcome<bool>`.
253#[derive(Debug, Serialize, Deserialize)]
254#[serde(rename_all = "camelCase")]
255pub struct DeviceResolveArgs {
256 pub user_code: String,
257 pub user: User,
258 pub approve: bool,
259}
260
261/// `device_claim`: the tool asks whether its request was approved.
262#[derive(Debug, Serialize, Deserialize)]
263#[serde(rename_all = "camelCase")]
264pub struct DeviceClaimArgs {
265 pub device_code: String,
266}
267
268/// The answer to a `device_claim`.
269#[derive(Debug, Serialize, Deserialize)]
270#[serde(tag = "status", rename_all = "snake_case")]
271pub enum DeviceClaim {
272 /// Nobody has approved or denied it yet; ask again after the interval.
273 Pending,
274 Denied,
275 /// The code was never issued, has expired, or was already used.
276 Expired,
277 /// The access token, returned once.
278 Approved {
279 token: String,
280 user: User,
281 },
282}
283
284/// A workspace: the owner of repositories, and the first segment of their
285/// URLs. A person's own space and a team's are the same thing.
286#[derive(Clone, Debug, Serialize, Deserialize)]
287#[serde(rename_all = "camelCase")]
288pub struct Workspace {
289 pub id: String,
290 pub slug: String,
291 pub name: String,
292 /// One line saying what the workspace is for.
293 pub description: Option<String>,
294 /// RFC 3339.
295 pub created_at: String,
296 pub member_count: u32,
297 /// The workspace's uploaded icon: the SHA-256 of its bytes, served at
298 /// `/avatars/<avatar>`. Null means the generated letter avatar.
299 #[serde(default)]
300 pub avatar: Option<String>,
301 /// What every member gets on each of its repositories; owners have
302 /// Admin. See [`crate::access`].
303 #[serde(default)]
304 pub base_permission: crate::access::BasePermission,
305}
306
307#[derive(Clone, Debug, Serialize, Deserialize)]
308pub struct Member {
309 pub username: String,
310 pub role: crate::Role,
311 /// Their display name, when they set one.
312 #[serde(default)]
313 pub name: Option<String>,
314 /// Their uploaded avatar: the SHA-256 of its bytes, served at
315 /// `/avatars/<avatar>`. None means the generated letter avatar.
316 #[serde(default)]
317 pub avatar: Option<String>,
318}
319
320/// `create_workspace`. Returns `Outcome<Workspace>`.
321#[derive(Debug, Serialize, Deserialize)]
322pub struct CreateWorkspaceArgs {
323 pub user: User,
324 pub slug: String,
325 #[serde(default)]
326 pub name: String,
327}
328
329/// `get_workspace`: public details, or null. Returns `Option<Workspace>`.
330#[derive(Debug, Serialize, Deserialize)]
331pub struct SlugArgs {
332 pub slug: String,
333}
334
335/// `list_members`: members only. Returns `Outcome<Vec<Member>>`.
336#[derive(Debug, Serialize, Deserialize)]
337pub struct ListMembersArgs {
338 pub slug: String,
339 pub viewer: crate::Viewer,
340}
341
342/// `add_member` and `remove_member`: owners only.
343/// Each returns `Outcome<bool>`.
344#[derive(Debug, Serialize, Deserialize)]
345pub struct MemberArgs {
346 pub actor: User,
347 pub slug: String,
348 pub username: String,
349}
350
351/// `update_workspace`: owners only. An empty name falls back to the slug;
352/// an empty description clears it. Returns `Outcome<Workspace>`.
353#[derive(Debug, Serialize, Deserialize)]
354pub struct UpdateWorkspaceArgs {
355 pub actor: User,
356 pub slug: String,
357 pub name: String,
358 pub description: String,
359}
360
361/// `rename_workspace`: owners only. Changes the workspace's slug, the first
362/// segment of its URLs, to `new_slug`; the display name is untouched. The
363/// old slug redirects to the new one, and is held for this workspace, for
364/// [`SLUG_HOLD_DAYS`]. Publishes `workspace.renamed`. Returns
365/// `Outcome<Workspace>`.
366///
367/// `check_workspace_rename` takes the same arguments and answers whether
368/// the rename would be allowed, changing nothing. Returns `Outcome<bool>`.
369#[derive(Debug, Serialize, Deserialize)]
370#[serde(rename_all = "camelCase")]
371pub struct RenameWorkspaceArgs {
372 pub actor: User,
373 pub slug: String,
374 pub new_slug: String,
375}
376
377/// `delete_workspace`: owners only, and only a person. `confirm` must be
378/// the workspace's slug, typed out. Refused while the workspace still
379/// holds repositories or projects, or while billing cannot settle it
380/// (`close_workspace`). Removes its memberships, its access tokens and its
381/// old-slug redirects; billing's ledger and the audit log keep its
382/// history. The slug is never given to another workspace; the person
383/// whose username it is may make a workspace of that name again.
384/// Publishes `workspace.deleted`. Returns `Outcome<bool>`.
385///
386/// `check_workspace_deletion` takes the same arguments (with `confirm`
387/// ignored) and says what stands in the way, changing nothing. Returns
388/// `Outcome<WorkspaceDeletion>`.
389#[derive(Debug, Serialize, Deserialize)]
390pub struct DeleteWorkspaceArgs {
391 pub actor: User,
392 pub slug: String,
393 #[serde(default)]
394 pub confirm: String,
395 /// Where the request came in, for the audit log; g1t.sh when absent.
396 #[serde(default)]
397 pub surface: Option<crate::audit::Surface>,
398}
399
400/// What stands between a workspace and its deletion. Nothing does when
401/// both counts are zero and `billing` is null.
402#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
403pub struct WorkspaceDeletion {
404 pub repositories: u32,
405 pub projects: u32,
406 /// Why billing cannot close the workspace yet, in words for its owner.
407 pub billing: Option<String>,
408}
409
410impl WorkspaceDeletion {
411 pub fn blocked(&self) -> bool {
412 self.repositories > 0 || self.projects > 0 || self.billing.is_some()
413 }
414
415 /// Why the workspace cannot be deleted yet, as one sentence, or `None`.
416 pub fn reason(&self, slug: &str) -> Option<String> {
417 let plural = |n: u32, one: &str, many: &str| {
418 format!("{n} {}", if n == 1 { one } else { many })
419 };
420 let mut held = Vec::new();
421 if self.repositories > 0 {
422 held.push(plural(self.repositories, "repository", "repositories"));
423 }
424 if self.projects > 0 {
425 held.push(plural(self.projects, "project", "projects"));
426 }
427 if !held.is_empty() {
428 return Some(format!(
429 "{slug} still holds {}. Transfer them to another workspace first.",
430 held.join(" and ")
431 ));
432 }
433 self.billing.clone()
434 }
435}
436
437/// `transfer_repo_scopes`: a repository moved from `from` to `to`; the
438/// tokens of agents at work on it are kept pointing at it. For repos'
439/// `transfer`. Returns `bool`.
440#[derive(Debug, Serialize, Deserialize)]
441pub struct TransferRepoScopesArgs {
442 pub from: crate::repos::RepoPath,
443 pub to: crate::repos::RepoPath,
444}
445
446/// How long a workspace's old slug keeps redirecting to it, and stays
447/// reserved for it, after a rename.
448pub const SLUG_HOLD_DAYS: u64 = 90;
449
450/// How long a workspace must wait between renames.
451pub const RENAME_COOLDOWN_HOURS: u64 = 24;
452
453// `resolve_slug` takes `SlugArgs` and returns `Option<String>`: the
454// workspace's current slug when `slug` is one it was renamed from within
455// the last `SLUG_HOLD_DAYS`, and null otherwise (including for a slug that
456// is in use).
457
458/// `set_workspace_avatar`: owners only. `image` is the file's bytes in
459/// base64: PNG, JPEG, WebP or GIF, at most `MAX_AVATAR_BYTES`. Null removes
460/// the icon. Returns `Outcome<Workspace>`.
461#[derive(Debug, Serialize, Deserialize)]
462pub struct SetWorkspaceAvatarArgs {
463 pub actor: User,
464 pub slug: String,
465 pub image: Option<String>,
466}
467
468/// `set_user_avatar`: a person's own avatar, as `SetWorkspaceAvatarArgs`.
469/// Returns `Outcome<Option<String>>`: the new avatar, or null once removed.
470#[derive(Debug, Serialize, Deserialize)]
471pub struct SetUserAvatarArgs {
472 pub user: User,
473 pub image: Option<String>,
474}
475
476/// The largest avatar that can be uploaded, in bytes.
477pub const MAX_AVATAR_BYTES: usize = 1024 * 1024;
478
479/// `list_workspace_tokens`: members only. Returns
480/// `Outcome<Vec<AccessToken>>`.
481#[derive(Debug, Serialize, Deserialize)]
482pub struct WorkspaceTokensArgs {
483 pub slug: String,
484 pub viewer: crate::Viewer,
485}
486
487/// `create_workspace_token`: owners only. The token belongs to the
488/// workspace, acts as it, and keeps working when the member who made it
489/// leaves. Returns `Outcome<CreatedAccessToken>`.
490#[derive(Debug, Serialize, Deserialize)]
491pub struct CreateWorkspaceTokenArgs {
492 pub actor: User,
493 pub slug: String,
494 pub name: String,
495 /// Its scopes; null for full access.
496 #[serde(default)]
497 pub scopes: Option<Vec<String>>,
498 /// When set, the token stops working after this many seconds. It is
499 /// listed with the workspace's tokens either way. Null: no expiry.
500 #[serde(default)]
501 pub ttl_seconds: Option<u64>,
502}
503
504/// `remove_workspace_token`: owners only. Returns `Outcome<bool>`.
505#[derive(Debug, Serialize, Deserialize)]
506pub struct RemoveWorkspaceTokenArgs {
507 pub actor: User,
508 pub slug: String,
509 pub id: String,
510}
511
512/// `oauth_authorize`: the signed-in person approved an application. The
513/// caller has checked the client and that it may be redirected to
514/// `redirect_uri`. Returns `OAuthCode`.
515#[derive(Debug, Serialize, Deserialize)]
516#[serde(rename_all = "camelCase")]
517pub struct OAuthAuthorizeArgs {
518 pub user: User,
519 pub client_id: String,
520 /// Shown wherever the application's access is listed.
521 pub client_name: String,
522 pub redirect_uri: String,
523 /// PKCE challenge, method S256.
524 pub code_challenge: String,
525 /// What the person granted, as `resource:level`. Null: full access.
526 #[serde(default)]
527 pub scopes: Option<Vec<String>>,
528}
529
530#[derive(Debug, Serialize, Deserialize)]
531pub struct OAuthCode {
532 pub code: String,
533}
534
535/// `oauth_exchange`: redeems an authorization code.
536/// Returns `Outcome<OAuthTokens>`.
537#[derive(Debug, Serialize, Deserialize)]
538#[serde(rename_all = "camelCase")]
539pub struct OAuthExchangeArgs {
540 pub code: String,
541 pub code_verifier: String,
542 pub client_id: String,
543 pub redirect_uri: String,
544}
545
546/// `oauth_refresh`: trades a refresh token for new tokens.
547/// Returns `Outcome<OAuthTokens>`.
548#[derive(Debug, Serialize, Deserialize)]
549#[serde(rename_all = "camelCase")]
550pub struct OAuthRefreshArgs {
551 pub refresh_token: String,
552 pub client_id: String,
553}
554
555#[derive(Debug, Serialize, Deserialize)]
556#[serde(rename_all = "camelCase")]
557pub struct OAuthTokens {
558 pub access_token: String,
559 /// Works once; using it returns the next one.
560 pub refresh_token: String,
561 /// Seconds until the access token stops working.
562 pub expires_in: u64,
563 /// The scopes granted, space-separated, or `*` for full access.
564 #[serde(default)]
565 pub scope: Option<String>,
566}
567
568/// An application a person has signed in to. Listed by `list_oauth_grants`
569/// and ended by `revoke_oauth_grant`.
570#[derive(Debug, Serialize, Deserialize)]
571#[serde(rename_all = "camelCase")]
572pub struct OAuthGrant {
573 pub id: String,
574 pub client_name: String,
575 /// RFC 3339.
576 pub created_at: String,
577 /// RFC 3339.
578 pub last_used_at: String,
579 /// What the person granted. Null: full access.
580 #[serde(default)]
581 pub scopes: Option<Vec<String>>,
582 /// Signed in before applications were given scopes: full access until
583 /// someone narrows it.
584 #[serde(default)]
585 pub legacy: bool,
586}
587
588/// `update_oauth_grant`: changes what an application the person signed in
589/// to may do, at once and when it refreshes. Returns `Outcome<OAuthGrant>`.
590#[derive(Debug, Serialize, Deserialize)]
591pub struct UpdateOAuthGrantArgs {
592 pub user: User,
593 pub id: String,
594 #[serde(default)]
595 pub scopes: Option<Vec<String>>,
596}
597
598
599/// What an agent's token may do: these operations, in this repository.
600#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
601pub struct AgentScope {
602 pub repo: crate::repos::RepoPath,
603 /// API and MCP operation names, such as `create_issue`.
604 pub operations: Vec<String>,
605 /// Set on a run credential: the run it belongs to, and what it may do
606 /// with git. See [`crate::credentials`].
607 #[serde(default, skip_serializing_if = "Option::is_none")]
608 pub run: Option<crate::credentials::RunBinding>,
609}
610
611/// `create_agent_token`: a token for a g1t agent working on someone's
612/// behalf. It acts as `g1t`, a member of the repository's workspace,
613/// and only for the operations in `scope`. Returns `CreatedAccessToken`.
614#[derive(Debug, Serialize, Deserialize)]
615#[serde(rename_all = "camelCase")]
616pub struct CreateAgentTokenArgs {
617 /// The person the agent works for; the token is recorded as theirs.
618 pub on_behalf_of: User,
619 pub scope: AgentScope,
620 pub ttl_seconds: u64,
621}
622
623// `agent_scope` takes `TokenArgs` and returns `Option<AgentScope>`: what an
624// agent's token may do, or null for any other token.
625
626/// The id g1t's agent acts under. Only ever stored, never shown: it keeps
627/// the agent's work apart from g1t's own ([`crate::system::ID`]) where
628/// that matters, such as whether its approval counts.
629pub const AGENT_ID: &str = "usr_g1t_agent";
630/// The name g1t's agent is shown by: g1t's own, [`crate::system::USERNAME`].
631/// Everything it does, people see g1t do.
632pub const AGENT_NAME: &str = crate::system::USERNAME;
633
634// --- Staff ---------------------------------------------------------------
635//
636// Staff-only methods, for sudo.g1t.sh. They take no viewer and check no
637// membership: only sudo calls them, over its service binding, after it has
638// verified a Cloudflare Access sign-in and its staff list. Nothing a
639// customer can reach should ever forward to them.
640
641/// `notify_owners`: emails a short notice, with one link, to each owner of
642/// a workspace with a confirmed address. Called by other services (billing
643/// warns owners near their usage limit), never on a person's behalf.
644/// Returns how many were sent.
645#[derive(Clone, Debug, Serialize, Deserialize)]
646pub struct NotifyOwnersArgs {
647 pub workspace: String,
648 pub subject: String,
649 /// One or two sentences: what happened and what it means.
650 pub intro: String,
651 /// The button's words, such as `Open billing`.
652 pub action: String,
653 /// Where the button goes; must be on g1t.sh.
654 pub link: String,
655 /// Small print: why they got it.
656 pub footer: String,
657}
658
659/// `admin_workspaces`: every workspace, newest first, at most
660/// [`ADMIN_WORKSPACES_LIMIT`], optionally only those whose slug, name or
661/// an owner's username or email contains `query`. Returns
662/// `Vec<AdminWorkspace>`. Staff only.
663#[derive(Debug, Default, Serialize, Deserialize)]
664pub struct AdminWorkspacesArgs {
665 #[serde(default)]
666 pub query: Option<String>,
667}
668
669/// The most workspaces one `admin_workspaces` call returns.
670pub const ADMIN_WORKSPACES_LIMIT: usize = 500;
671
672/// An owner of a workspace, as staff see them.
673#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
674pub struct AdminOwner {
675 pub username: String,
676 pub email: Option<String>,
677}
678
679/// A workspace as staff see it: who owns it and how many belong to it.
680#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
681#[serde(rename_all = "camelCase")]
682pub struct AdminWorkspace {
683 pub slug: String,
684 pub name: String,
685 /// RFC 3339.
686 pub created_at: String,
687 pub owners: Vec<AdminOwner>,
688 pub member_count: u32,
689}
690
691/// `admin_workspace`: one workspace with every member, or null. Takes
692/// `SlugArgs`; returns `Option<AdminWorkspaceDetail>`. Staff only.
693#[derive(Clone, Debug, Serialize, Deserialize)]
694#[serde(rename_all = "camelCase")]
695pub struct AdminWorkspaceDetail {
696 pub slug: String,
697 pub name: String,
698 pub description: Option<String>,
699 /// RFC 3339.
700 pub created_at: String,
701 /// Owners first, then by username.
702 pub members: Vec<AdminMember>,
703}
704
705/// A member of a workspace, as staff see them.
706#[derive(Clone, Debug, Serialize, Deserialize)]
707pub struct AdminMember {
708 pub username: String,
709 pub email: Option<String>,
710 pub role: crate::Role,
711 /// When they joined the workspace. RFC 3339.
712 pub joined: String,
713}
714
715// --- Profiles ------------------------------------------------------------
716//
717// A person's public page at `g1t.sh/u/<username>`. Everything in a
718// `Profile` is shown to anyone, signed in or not; an email address never is.
719
720/// The most characters each profile field takes.
721pub const MAX_PROFILE_NAME: usize = 80;
722pub const MAX_PROFILE_BIO: usize = 160;
723pub const MAX_PROFILE_LOCATION: usize = 80;
724pub const MAX_PROFILE_WEBSITE: usize = 200;
725pub const MAX_PROFILE_PRONOUNS: usize = 40;
726
727/// What anyone may see about a person.
728#[derive(Clone, Debug, Default, Serialize, Deserialize)]
729#[serde(rename_all = "camelCase")]
730pub struct Profile {
731 pub username: String,
732 /// The name they go by, if they gave one.
733 pub name: Option<String>,
734 /// One or two lines about them, at most [`MAX_PROFILE_BIO`] characters.
735 pub bio: Option<String>,
736 pub location: Option<String>,
737 /// An `https://` address.
738 pub website: Option<String>,
739 pub pronouns: Option<String>,
740 /// The uploaded avatar's hash, served at `/avatars/<avatar>`.
741 pub avatar: Option<String>,
742 /// When the account was made. RFC 3339.
743 pub created_at: String,
744}
745
746// `profile` takes `UsernameArgs` and returns `Option<Profile>`: null for
747// an account that does not exist.
748
749/// `update_profile`: a person changes their own profile. Every field is
750/// replaced; an empty one is cleared. Returns `Outcome<Profile>`.
751#[derive(Debug, Default, Serialize, Deserialize)]
752#[serde(rename_all = "camelCase")]
753pub struct UpdateProfileArgs {
754 pub actor: User,
755 #[serde(default)]
756 pub name: String,
757 #[serde(default)]
758 pub bio: String,
759 #[serde(default)]
760 pub location: String,
761 #[serde(default)]
762 pub website: String,
763 #[serde(default)]
764 pub pronouns: String,
765}
766
767/// `profile_workspaces`: the workspaces shown on a person's profile, as
768/// `viewer` may see them. A membership is shown only when it is no secret
769/// from the viewer: a workspace the viewer belongs to as well, or one of
770/// `public`, the workspaces the caller found the person has made a public
771/// project in (whose page shows that already). Returns
772/// `Vec<ProfileWorkspace>`; empty for an account that does not exist.
773#[derive(Debug, Serialize, Deserialize)]
774pub struct ProfileWorkspacesArgs {
775 pub username: String,
776 pub viewer: crate::Viewer,
777 #[serde(default)]
778 pub public: Vec<String>,
779}
780
781/// A workspace on a person's profile.
782#[derive(Clone, Debug, Serialize, Deserialize)]
783pub struct ProfileWorkspace {
784 pub slug: String,
785 pub name: String,
786 pub avatar: Option<String>,
787}
788
789/// `directory`: every account or every workspace, as their public pages
790/// show them, a page at a time in name order. For services that index
791/// them, such as search; nothing private is in it. Returns
792/// `DirectoryPage`.
793#[derive(Debug, Default, Serialize, Deserialize)]
794pub struct DirectoryArgs {
795 /// `user` or `workspace`.
796 pub kind: String,
797 /// Names after this one.
798 #[serde(default)]
799 pub after: Option<String>,
800 pub limit: u32,
801}
802
803/// One account or workspace in the directory.
804#[derive(Clone, Debug, Serialize, Deserialize)]
805#[serde(rename_all = "camelCase")]
806pub struct DirectoryEntry {
807 /// The account's or workspace's id.
808 pub id: String,
809 /// A username or a workspace's slug.
810 pub slug: String,
811 /// A person's display name or a workspace's name.
812 pub name: Option<String>,
813 /// A person's bio or a workspace's description.
814 pub bio: Option<String>,
815 pub avatar: Option<String>,
816 /// RFC 3339.
817 pub created_at: String,
818}
819
820#[derive(Clone, Debug, Default, Serialize, Deserialize)]
821pub struct DirectoryPage {
822 pub entries: Vec<DirectoryEntry>,
823 /// Where the next page starts; null on the last.
824 pub next: Option<String>,
825}
826
827// --- Invites ---------------------------------------------------------------
828//
829// While registration is invite-only, every new account (with a password or
830// through GitHub) needs an invite code. Each person may have
831// `INVITES_PER_USER` invites out at a time; staff grant more to a person or
832// to a workspace, whose owners share them. Inviting an email with no
833// account into a workspace makes an invite bound to that address, which
834// registers and joins in one step. See services/identity/src/invites.rs.
835
836/// Whether anyone may make an account, or only someone with an invite. Set
837/// by identity's `REGISTRATION_MODE` var; anything but `open`, including
838/// leaving it unset, is `invite`, so a missing setting never opens sign-up.
839#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
840#[serde(rename_all = "snake_case")]
841pub enum RegistrationMode {
842 #[default]
843 Invite,
844 Open,
845}
846
847impl RegistrationMode {
848 pub fn parse(text: Option<&str>) -> RegistrationMode {
849 match text.map(|text| text.trim().to_ascii_lowercase()).as_deref() {
850 Some("open") => RegistrationMode::Open,
851 _ => RegistrationMode::Invite,
852 }
853 }
854}
855
856/// How many invites a person may have out at once, unless identity's
857/// `INVITES_PER_USER` var says otherwise.
858pub const INVITES_PER_USER: u32 = 5;
859
860/// How long an invite works, unless identity's `INVITE_TTL_DAYS` var says
861/// otherwise.
862pub const INVITE_TTL_DAYS: u64 = 30;
863
864/// Where an invite stands. Only a pending invite can be used or revoked.
865/// An expired or revoked invite that was never used gives its inviter the
866/// invite back.
867#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
868#[serde(rename_all = "snake_case")]
869pub enum InviteStatus {
870 Pending,
871 Redeemed,
872 Expired,
873 Revoked,
874}
875
876/// What using an invite does.
877#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
878#[serde(rename_all = "snake_case")]
879pub enum InviteKind {
880 /// Makes a new account, and joins `workspace` when one is set.
881 Account,
882 /// An existing account joins `workspace`. Never makes an account.
883 Workspace,
884}
885
886/// Whose allowance an invite uses.
887#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
888#[serde(rename_all = "snake_case")]
889pub enum InviteCharge {
890 /// Its inviter's own.
891 User,
892 /// The workspace's, granted by staff and shared by its owners.
893 Workspace,
894 /// Nobody's: staff minted it, or it invites an existing account.
895 None,
896}
897
898/// One invite, as the person who made it sees it.
899#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
900#[serde(rename_all = "camelCase")]
901pub struct Invite {
902 pub id: String,
903 /// The code, such as `g1t-k7m2-q9xd-…`: returned once when the invite
904 /// is made, and afterwards to whoever made it while it is pending.
905 /// Null otherwise.
906 pub code: Option<String>,
907 /// The code's first group, such as `g1t-k7m2`, to recognise it by.
908 pub hint: String,
909 /// Only an account with this address can use it. Null: anyone with
910 /// the code.
911 pub email: Option<String>,
912 pub kind: InviteKind,
913 /// The workspace it joins, by slug.
914 pub workspace: Option<String>,
915 pub status: InviteStatus,
916 pub charged_to: InviteCharge,
917 /// Who made it, by username. Null when g1t staff did.
918 pub invited_by: Option<String>,
919 /// The account that used it, by username.
920 pub redeemed_by: Option<String>,
921 /// RFC 3339.
922 pub created_at: String,
923 /// RFC 3339.
924 pub expires_at: String,
925 /// RFC 3339.
926 pub redeemed_at: Option<String>,
927 /// RFC 3339.
928 pub revoked_at: Option<String>,
929 /// The staff member who minted it. Only in staff views.
930 #[serde(default, skip_serializing_if = "Option::is_none")]
931 pub staff: Option<String>,
932}
933
934/// How many invites someone may have out, and how many they have.
935#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
936pub struct Allowance {
937 /// Null: no limit.
938 pub limit: Option<u32>,
939 /// Pending and used invites; revoked and expired ones are not counted.
940 pub used: u32,
941 /// Null: no limit.
942 pub remaining: Option<u32>,
943}
944
945impl Allowance {
946 pub fn new(limit: Option<u32>, used: u32) -> Allowance {
947 Allowance {
948 limit,
949 used,
950 remaining: limit.map(|limit| limit.saturating_sub(used)),
951 }
952 }
953
954 pub fn exhausted(&self) -> bool {
955 self.remaining == Some(0)
956 }
957}
958
959/// A workspace's shared invites, for one of its owners.
960#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
961pub struct WorkspaceAllowance {
962 pub slug: String,
963 pub allowance: Allowance,
964}
965
966/// `list_invites` (takes `UserArgs`): a person's invites, newest first,
967/// and what they have left. Returns `InvitesOverview`.
968#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
969pub struct InvitesOverview {
970 pub mode: RegistrationMode,
971 pub allowance: Allowance,
972 /// Workspaces the person owns that staff granted invites to.
973 pub workspaces: Vec<WorkspaceAllowance>,
974 pub invites: Vec<Invite>,
975}
976
977/// `create_invite`: a person makes an invite, optionally for one email
978/// address. People only; never an agent or a workspace's token, and not
979/// before their email is confirmed. Uses one of the person's invites, or,
980/// with `workspace`, one of the invites staff granted that workspace (its
981/// owners only). Emails the address when one is given. Returns
982/// `Outcome<Invite>`, with the code.
983///
984/// `revoke_invite` (takes `RemoveArgs`): its maker revokes a pending
985/// invite; a workspace's owners may revoke one made for the workspace.
986/// The invite comes back to whoever it was charged to. Returns
987/// `Outcome<Invite>`.
988#[derive(Debug, Serialize, Deserialize)]
989pub struct CreateInviteArgs {
990 pub user: User,
991 #[serde(default)]
992 pub email: Option<String>,
993 /// Use this workspace's granted invites, by slug.
994 #[serde(default)]
995 pub workspace: Option<String>,
996 /// Where the request came in, for the audit log; g1t.sh when absent.
997 #[serde(default)]
998 pub surface: Option<crate::audit::Surface>,
999}
1000
1001/// `check_invite`: what an invite code is for, before using it. Returns
1002/// `Outcome<InvitePreview>`; a code that is unknown, used, revoked or
1003/// expired gets the same answer, so codes cannot be probed. With
1004/// `any_status`, a real code that can no longer be used is described
1005/// instead (its `status` says why), so the page can say whom to ask for a
1006/// new one; an unknown code still gets the one answer.
1007#[derive(Debug, Serialize, Deserialize)]
1008pub struct InviteCodeArgs {
1009 pub code: String,
1010 /// Who is asking, such as the visitor's IP address, for rate limits.
1011 #[serde(default)]
1012 pub client: Option<String>,
1013 /// Who is looking, if signed in: sets `InvitePreview::for_viewer`.
1014 #[serde(default)]
1015 pub viewer: Option<User>,
1016 #[serde(default)]
1017 pub any_status: bool,
1018}
1019
1020/// Someone shown on an invite.
1021#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1022pub struct InviteFrom {
1023 pub username: String,
1024 pub name: Option<String>,
1025 pub avatar: Option<String>,
1026}
1027
1028/// A repository an invite code was sent with: using the code accepts the
1029/// invitation to collaborate on it.
1030#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1031pub struct InviteRepository {
1032 /// `workspace/repo`.
1033 pub name: String,
1034 /// The role it gives, such as `write`.
1035 pub role: String,
1036}
1037
1038/// What a valid invite code is for.
1039#[derive(Clone, Debug, Serialize, Deserialize)]
1040#[serde(rename_all = "camelCase")]
1041pub struct InvitePreview {
1042 pub kind: InviteKind,
1043 /// Pending, unless `any_status` asked about a code that is spent.
1044 pub status: InviteStatus,
1045 /// Null when g1t staff sent it.
1046 pub invited_by: Option<InviteFrom>,
1047 pub workspace: Option<ProfileWorkspace>,
1048 /// The repository it accepts an invitation to, if it was sent with one.
1049 pub repository: Option<InviteRepository>,
1050 /// The address it is for, partly hidden, such as `a•••@example.com`.
1051 pub email: Option<String>,
1052 /// The address in full, while it is pending: whoever holds the code
1053 /// was sent it there. Fills in and locks the sign-up form.
1054 pub address: Option<String>,
1055 /// Whether the address it is for has a g1t account already, so the
1056 /// page asks them to sign in rather than sign up.
1057 pub has_account: bool,
1058 /// With a viewer: whether the invite is theirs (it is for one of their
1059 /// confirmed addresses, or they used it). Null without a viewer or,
1060 /// for a pending invite, when it is for anyone with the code.
1061 pub for_viewer: Option<bool>,
1062 /// RFC 3339.
1063 pub expires_at: String,
1064}
1065
1066/// `accept_invite`: a signed-in person uses a workspace invite made for
1067/// their confirmed address, and joins the workspace, or an invite sent with
1068/// a repository invitation, and accepts it. Returns `Outcome<String>`: the
1069/// workspace's slug, or `workspace/repo`.
1070#[derive(Debug, Serialize, Deserialize)]
1071pub struct AcceptInviteArgs {
1072 pub user: User,
1073 pub code: String,
1074}
1075
1076/// `invite_member`: an owner invites an email address into a workspace.
1077/// It always makes an invite bound to that address and emails it, so the
1078/// answer never says whether the address has an account. Without one, the
1079/// invite registers and joins in one step, and uses one of the workspace's
1080/// granted invites or else one of the owner's own. With one, it costs
1081/// nothing. Returns `Outcome<Invite>`, with the code.
1082#[derive(Debug, Serialize, Deserialize)]
1083pub struct InviteMemberArgs {
1084 pub actor: User,
1085 pub slug: String,
1086 pub email: String,
1087 /// Where the request came in, for the audit log; g1t.sh when absent.
1088 #[serde(default)]
1089 pub surface: Option<crate::audit::Surface>,
1090}
1091
1092/// `workspace_invites` (takes `ListMembersArgs`): a workspace's invites,
1093/// newest first. Owners only. Returns `Outcome<Vec<Invite>>`.
1094///
1095/// `revoke_workspace_invite`: owners only. Returns `Outcome<Invite>`.
1096#[derive(Debug, Serialize, Deserialize)]
1097pub struct WorkspaceInviteArgs {
1098 pub actor: User,
1099 pub slug: String,
1100 pub id: String,
1101}
1102
1103/// `request_access`: someone without an invite asks for one. Kept on the
1104/// waitlist, one entry per address. Answers the same way whether or not
1105/// the address is already on it. Returns `Outcome<bool>`.
1106#[derive(Debug, Default, Serialize, Deserialize)]
1107pub struct RequestAccessArgs {
1108 pub email: String,
1109 /// What they will build, if they said.
1110 #[serde(default)]
1111 pub about: String,
1112 /// Who is asking, such as the visitor's IP address, for rate limits.
1113 #[serde(default)]
1114 pub client: Option<String>,
1115}
1116
1117/// The most characters `RequestAccessArgs::about` keeps.
1118pub const MAX_WAITLIST_ABOUT: usize = 1000;
1119
1120// `registration` takes `{}` and returns `RegistrationMode`.
1121
1122// --- Invites, staff only ---
1123
1124#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1125#[serde(rename_all = "snake_case")]
1126pub enum WaitlistStatus {
1127 Waiting,
1128 Invited,
1129 Dismissed,
1130}
1131
1132impl WaitlistStatus {
1133 pub fn as_str(self) -> &'static str {
1134 match self {
1135 WaitlistStatus::Waiting => "waiting",
1136 WaitlistStatus::Invited => "invited",
1137 WaitlistStatus::Dismissed => "dismissed",
1138 }
1139 }
1140}
1141
1142/// Someone who asked for access.
1143#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1144#[serde(rename_all = "camelCase")]
1145pub struct WaitlistEntry {
1146 pub id: String,
1147 pub email: String,
1148 pub about: Option<String>,
1149 pub status: WaitlistStatus,
1150 pub invite_id: Option<String>,
1151 pub decided_by: Option<String>,
1152 /// RFC 3339.
1153 pub decided_at: Option<String>,
1154 /// What staff wrote when approving; it went in the invite email.
1155 #[serde(default)]
1156 pub note: Option<String>,
1157 /// The account made with the invite, once it was used.
1158 #[serde(default)]
1159 pub joined_as: Option<String>,
1160 /// When they first asked. RFC 3339.
1161 pub created_at: String,
1162 /// When they last asked. RFC 3339.
1163 pub updated_at: String,
1164}
1165
1166/// `admin_waitlist`: the waitlist, newest first, at most
1167/// [`ADMIN_INVITES_LIMIT`]. Returns `Vec<WaitlistEntry>`.
1168///
1169/// `admin_waitlist_pending` takes `{}` and returns the number of requests
1170/// still waiting, for sudo's navigation.
1171#[derive(Debug, Default, Serialize, Deserialize)]
1172pub struct AdminWaitlistArgs {
1173 /// Part of an email address or of what they said.
1174 #[serde(default)]
1175 pub query: Option<String>,
1176 /// Null: every status.
1177 #[serde(default)]
1178 pub status: Option<WaitlistStatus>,
1179}
1180
1181/// The most rows one staff listing of invites or the waitlist returns.
1182pub const ADMIN_INVITES_LIMIT: usize = 500;
1183
1184/// `admin_decide_waitlist`: approving mints an invite bound to the
1185/// address, charged to nobody, and emails it, with `note` if given;
1186/// dismissing only marks the entry. Returns `Outcome<WaitlistEntry>`.
1187#[derive(Debug, Serialize, Deserialize)]
1188pub struct AdminDecideWaitlistArgs {
1189 pub id: String,
1190 pub approve: bool,
1191 /// The staff member, by email.
1192 pub staff: String,
1193 /// A line for the invite email, up to [`MAX_WAITLIST_NOTE`] characters.
1194 #[serde(default)]
1195 pub note: Option<String>,
1196}
1197
1198/// The most characters an approval's note keeps.
1199pub const MAX_WAITLIST_NOTE: usize = 500;
1200
1201/// `admin_invites`: every invite, newest first, at most
1202/// [`ADMIN_INVITES_LIMIT`], optionally only those whose code starts with
1203/// `query`, or whose email, inviter or redeemer contains it. Returns
1204/// `Vec<Invite>`.
1205#[derive(Debug, Default, Serialize, Deserialize)]
1206pub struct AdminInvitesArgs {
1207 #[serde(default)]
1208 pub query: Option<String>,
1209}
1210
1211/// `admin_revoke_invite`: revokes any pending invite. Returns
1212/// `Outcome<Invite>`.
1213#[derive(Debug, Serialize, Deserialize)]
1214pub struct AdminRevokeInviteArgs {
1215 pub id: String,
1216 pub staff: String,
1217}
1218
1219/// `admin_mint_invite`: staff make an invite that uses nobody's
1220/// allowance, optionally bound to (and emailed to) an address. Returns
1221/// `Outcome<Invite>`, with the code.
1222#[derive(Debug, Serialize, Deserialize)]
1223pub struct AdminMintInviteArgs {
1224 #[serde(default)]
1225 pub email: Option<String>,
1226 pub staff: String,
1227}
1228
1229/// Who staff grant invites to.
1230#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
1231#[serde(rename_all = "snake_case")]
1232pub enum GrantTarget {
1233 User,
1234 Workspace,
1235}
1236
1237impl GrantTarget {
1238 pub fn as_str(self) -> &'static str {
1239 match self {
1240 GrantTarget::User => "user",
1241 GrantTarget::Workspace => "workspace",
1242 }
1243 }
1244}
1245
1246/// `admin_grant_invites`: gives a person (by username) or a workspace (by
1247/// slug) `amount` more invites; a negative amount takes some back. Returns
1248/// `Outcome<Allowance>`: theirs afterwards.
1249#[derive(Debug, Serialize, Deserialize)]
1250pub struct AdminGrantInvitesArgs {
1251 pub target: GrantTarget,
1252 pub name: String,
1253 pub amount: i32,
1254 #[serde(default)]
1255 pub note: String,
1256 pub staff: String,
1257}
1258
1259/// The most invites one grant gives or takes back.
1260pub const MAX_INVITE_GRANT: i32 = 1000;
1261
1262/// Invites staff granted.
1263#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1264#[serde(rename_all = "camelCase")]
1265pub struct InviteGrant {
1266 pub amount: i32,
1267 pub note: Option<String>,
1268 pub granted_by: String,
1269 /// RFC 3339.
1270 pub created_at: String,
1271}
1272
1273/// Someone a person invited, and whom they invited in turn.
1274#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1275#[serde(rename_all = "camelCase")]
1276pub struct InviteTreeNode {
1277 pub username: String,
1278 /// When they used the invite. RFC 3339.
1279 pub joined_at: String,
1280 pub invited: Vec<InviteTreeNode>,
1281}
1282
1283/// `admin_invite_tree` (takes `UsernameArgs`): where a person came from
1284/// and whom they brought, for tracing abuse. Returns `Option<InviteTree>`.
1285///
1286/// `admin_workspace_invites` (takes `SlugArgs`): a workspace's granted
1287/// invites, grants and invites. Returns `Option<InviteTree>` with
1288/// `username` the slug and no `invited_by`.
1289#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1290#[serde(rename_all = "camelCase")]
1291pub struct InviteTree {
1292 pub username: String,
1293 /// Who invited them, then who invited that person, and so on. Empty
1294 /// for an account made without an invite.
1295 pub invited_by: Vec<String>,
1296 /// The staff member who minted their invite, when staff did.
1297 pub staff: Option<String>,
1298 pub allowance: Allowance,
1299 pub grants: Vec<InviteGrant>,
1300 /// Their invites, newest first.
1301 pub invites: Vec<Invite>,
1302 /// Whom they invited, three levels down.
1303 pub invited: Vec<InviteTreeNode>,
1304}
1305
1306#[cfg(test)]
1307mod deletion_tests {
1308 use super::WorkspaceDeletion;
1309
1310 #[test]
1311 fn says_what_is_left_to_move() {
1312 let clear = WorkspaceDeletion::default();
1313 assert!(!clear.blocked());
1314 assert_eq!(clear.reason("acme"), None);
1315 let held = WorkspaceDeletion {
1316 repositories: 2,
1317 projects: 1,
1318 billing: Some("Pay first.".into()),
1319 };
1320 assert!(held.blocked());
1321 assert_eq!(
1322 held.reason("acme").as_deref(),
1323 Some("acme still holds 2 repositories and 1 project. Transfer them to another workspace first.")
1324 );
1325 let owing = WorkspaceDeletion {
1326 billing: Some("Pay first.".into()),
1327 ..WorkspaceDeletion::default()
1328 };
1329 assert_eq!(owing.reason("acme").as_deref(), Some("Pay first."));
1330 }
1331}