g1t/services/projects/src/access.ts
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 1 | /** |
| 2 | * Who may do what with a project: each method's capability on the | |
| 3 | * project's repository. Seeing a project takes Read; changing it (its name, | |
| 4 | * root directory and dependencies) takes Maintain (`manage_settings`). | |
| 5 | * Types only, so the table is tested apart from the service. | |
| 6 | */ | |
| 7 | ||
| 8 | import type { Capability, RepoRef } from "@g1t/contracts"; | |
| 9 | ||
| 10 | export const NEEDS = { | |
| 11 | get: "read", | |
| 12 | create: "manage_settings", | |
| 13 | update: "manage_settings", | |
| 14 | addDependency: "manage_settings", | |
| 15 | removeDependency: "manage_settings", | |
| 16 | } as const satisfies Record<string, Capability>; | |
| 17 | ||
| 18 | /** The repository a stored project's permission comes from. */ | |
| 19 | export function repoRef(row: { repo_id: string; repo_namespace: string; repo_private: number | boolean }): RepoRef { | |
| 20 | return { id: row.repo_id, namespace: row.repo_namespace, isPrivate: !!row.repo_private }; | |
| 21 | } |