pr_01m47d15m3e54sn21z27rpy5n9/services/projects/src/index.ts

338 lines12,776 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Projects: what a workspace builds and runs, first on every page1/**
2 * The projects service: what a workspace builds and runs.
3 *
4 * A project has one source, where its code lives: today a repository hosted
5 * on g1t and a root directory in it. Everything about running it
6 * (deployments, environments, domains, secrets and variables) hangs off the
7 * project; other services key their data by its id. Every repository gets
8 * a project of its own name: when it is created (from `repo.created`), and
9 * for repositories made before projects existed, the first time their
10 * workspace's projects are asked for.
11 *
12 * Reached through service bindings: `POST /rpc/<method>`.
13 */
14
15import {
16 fail,
17 identityClient,
18 newId,
19 ok,
20 reposClient,
21 type G1tEvent,
22 type NewProject,
23 type Project,
24 type Repo,
25 type Result,
26 type ServiceBinding,
27 type User,
28 type Viewer,
29} from "@g1t/contracts";
30
31type Env = {
32 DB: D1Database;
33 REPOS: ServiceBinding;
34 IDENTITY: ServiceBinding;
35};
36
37type Row = {
38 id: string;
39 workspace: string;
40 slug: string;
41 name: string;
42 description: string | null;
43 source_kind: string;
44 repo_id: string;
45 repo_namespace: string;
46 repo_name: string;
47 repo_private: number;
48 default_branch: string;
49 root_dir: string;
50 is_primary: number;
51 created_by: string;
52 created_at: string;
53 updated_at: string;
54};
55
56const now = () => new Date().toISOString();
57
58function toProject(row: Row): Project {
59 return {
60 id: row.id,
61 workspace: row.workspace,
62 slug: row.slug,
63 name: row.name,
64 description: row.description,
65 source: {
66 kind: "hosted",
67 repoId: row.repo_id,
68 repo: { namespace: row.repo_namespace, name: row.repo_name },
69 rootDir: row.root_dir,
70 defaultBranch: row.default_branch,
71 },
72 private: !!row.repo_private,
73 primary: !!row.is_primary,
74 createdBy: row.created_by,
75 createdAt: row.created_at,
76 updatedAt: row.updated_at,
77 };
78}
79
80/** A name as an address: lowercase letters, digits, `-`, `_` and `.`. */
81function slugOf(name: string): string {
82 return name
83 .trim()
84 .toLowerCase()
85 .replace(/[^a-z0-9._-]+/g, "-")
86 .replace(/^[-.]+|[-.]+$/g, "")
87 .slice(0, 100);
88}
89
90function isMember(viewer: Viewer, workspace: string): boolean {
91 return !!viewer?.workspaces?.some((m) => m.slug === workspace.toLowerCase());
92}
93
94class Projects {
95 constructor(private readonly env: Env) {}
96
97 private get db() {
98 return this.env.DB;
99 }
100
101 private async workspaceActor(slug: string): Promise<User | null> {
102 const workspace = await identityClient(this.env.IDENTITY).getWorkspace(slug);
103 if (!workspace) return null;
104 return {
105 id: workspace.id,
106 username: workspace.slug,
107 kind: "workspace",
108 verified: true,
109 workspaces: [{ slug: workspace.slug, role: "member" }],
110 };
111 }
112
113 /** A free slug for `wanted` in the workspace. */
114 private async freeSlug(workspace: string, wanted: string): Promise<string> {
115 const base = slugOf(wanted) || "project";
116 for (let n = 1; n < 100; n++) {
117 const slug = n === 1 ? base : `${base}-${n}`;
118 const taken = await this.db
119 .prepare("SELECT 1 FROM projects WHERE workspace = ? AND slug = ?")
120 .bind(workspace, slug)
121 .first();
122 if (!taken) return slug;
123 }
124 return `${base}-${crypto.randomUUID().slice(0, 6)}`;
125 }
126
127 /** Gives a repository its own project, unless it has one. */
128 private async ensureFor(repo: Repo, createdBy: string): Promise<void> {
129 if (repo.forkOf) return;
130 const existing = await this.db.prepare("SELECT id FROM projects WHERE repo_id = ?").bind(repo.id).first();
131 if (existing) {
132 await this.db
133 .prepare("UPDATE projects SET repo_private = ?, default_branch = ?, repo_name = ? WHERE repo_id = ?")
134 .bind(repo.isPrivate ? 1 : 0, repo.defaultBranch, repo.name, repo.id)
135 .run();
136 return;
137 }
138 const at = now();
139 await this.db
140 .prepare(
141 `INSERT INTO projects (id, workspace, slug, name, description, repo_id, repo_namespace, repo_name, repo_private,
142 default_branch, root_dir, is_primary, created_by, created_at, updated_at)
143 VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, '', 1, ?, ?, ?)
144 ON CONFLICT (workspace, slug) DO NOTHING`,
145 )
146 .bind(
147 newId("prj"),
148 repo.namespace.toLowerCase(),
149 await this.freeSlug(repo.namespace.toLowerCase(), repo.name),
150 repo.name,
151 repo.description,
152 repo.id,
153 repo.namespace,
154 repo.name,
155 repo.isPrivate ? 1 : 0,
156 repo.defaultBranch,
157 createdBy,
158 at,
159 at,
160 )
161 .run();
162 }
163
164 /** Projects for a workspace's repositories made before projects existed. Once. */
165 private async backfill(workspace: string): Promise<void> {
166 const done = await this.db.prepare("SELECT 1 FROM backfilled WHERE workspace = ?").bind(workspace).first();
167 if (done) return;
168 const actor = await this.workspaceActor(workspace);
169 if (!actor) return;
170 const list = await reposClient(this.env.REPOS).list(actor, { namespace: workspace });
171 for (const repo of list) {
172 if (repo.namespace.toLowerCase() === workspace) await this.ensureFor(repo, "g1t");
173 }
174 await this.db.prepare("INSERT OR REPLACE INTO backfilled (workspace, at) VALUES (?, ?)").bind(workspace, now()).run();
175 }
176
177 private visible(row: Row, viewer: Viewer): boolean {
178 return !row.repo_private || isMember(viewer, row.workspace);
179 }
180
181 async list(a: { workspace: string; viewer: Viewer }): Promise<Result<Project[]>> {
182 const workspace = a.workspace.toLowerCase();
183 await this.backfill(workspace);
184 const rows = await this.db
185 .prepare("SELECT * FROM projects WHERE workspace = ? ORDER BY name COLLATE NOCASE")
186 .bind(workspace)
187 .all<Row>();
188 return ok(rows.results.filter((row) => this.visible(row, a.viewer)).map(toProject));
189 }
190
191 async get(a: { workspace: string; slug: string; viewer: Viewer }): Promise<Result<Project>> {
192 const workspace = a.workspace.toLowerCase();
193 await this.backfill(workspace);
194 const row = await this.db
195 .prepare("SELECT * FROM projects WHERE workspace = ? AND slug = ?")
196 .bind(workspace, a.slug.toLowerCase())
197 .first<Row>();
198 if (!row || !this.visible(row, a.viewer)) return fail("not_found", "There is no such project.");
199 return ok(toProject(row));
200 }
201
202 async byRepo(a: { repoId: string }): Promise<Project[]> {
203 const rows = await this.db
204 .prepare("SELECT * FROM projects WHERE repo_id = ? ORDER BY is_primary DESC, created_at")
205 .bind(a.repoId)
206 .all<Row>();
207 if (rows.results.length > 0) return rows.results.map(toProject);
208 // A repository from before projects: give it its own now.
209 const path = await this.env.REPOS.fetch("https://repos/rpc/path_by_id", {
210 method: "POST",
211 headers: { "content-type": "application/json" },
212 body: JSON.stringify({ id: a.repoId }),
213 });
214 const repoPath = path.ok ? ((await path.json()) as { namespace: string; name: string } | null) : null;
215 if (!repoPath) return [];
216 const actor = await this.workspaceActor(repoPath.namespace);
217 const repo = actor ? await reposClient(this.env.REPOS).get(repoPath, actor) : null;
218 if (!repo?.ok) return [];
219 await this.ensureFor(repo.value, "g1t");
220 const again = await this.db.prepare("SELECT * FROM projects WHERE repo_id = ?").bind(a.repoId).all<Row>();
221 return again.results.map(toProject);
222 }
223
224 async create(a: { actor: User; workspace: string; input: NewProject }): Promise<Result<Project>> {
225 const workspace = a.workspace.toLowerCase();
226 if (!isMember(a.actor, workspace)) return fail("forbidden", "Only members can add projects to a workspace.");
227 if (a.input.repo.namespace.toLowerCase() !== workspace) {
228 return fail("invalid", "A project builds from one of its own workspace's repositories.");
229 }
230 const repo = await reposClient(this.env.REPOS).get(a.input.repo, a.actor);
231 if (!repo.ok) return repo;
232 if (repo.value.forkOf) return fail("invalid", "A pull request's working copy cannot be a project's source.");
233 const name = a.input.name.trim();
234 if (!name || name.length > 100) return fail("invalid", "A project's name is 1 to 100 characters.");
235 const rootDir = (a.input.rootDir ?? "").trim().replace(/^\/+|\/+$/g, "");
236 if (rootDir.split("/").some((part) => part === "..")) return fail("invalid", "The root directory is inside the repository.");
237 const slug = slugOf(name);
238 if (!slug) return fail("invalid", "Give the project a name with letters or digits.");
239 const taken = await this.db.prepare("SELECT 1 FROM projects WHERE workspace = ? AND slug = ?").bind(workspace, slug).first();
240 if (taken) return fail("conflict", `${workspace} already has a project called ${slug}.`);
241 const primary = !(await this.db.prepare("SELECT 1 FROM projects WHERE repo_id = ?").bind(repo.value.id).first());
242 const at = now();
243 const id = newId("prj");
244 await this.db
245 .prepare(
246 `INSERT INTO projects (id, workspace, slug, name, description, repo_id, repo_namespace, repo_name, repo_private,
247 default_branch, root_dir, is_primary, created_by, created_at, updated_at)
248 VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`,
249 )
250 .bind(
251 id,
252 workspace,
253 slug,
254 name,
255 a.input.description?.trim() || null,
256 repo.value.id,
257 repo.value.namespace,
258 repo.value.name,
259 repo.value.isPrivate ? 1 : 0,
260 repo.value.defaultBranch,
261 rootDir,
262 primary ? 1 : 0,
263 a.actor.username,
264 at,
265 at,
266 )
267 .run();
268 return ok(toProject((await this.db.prepare("SELECT * FROM projects WHERE id = ?").bind(id).first<Row>())!));
269 }
270
271 async update(a: {
272 actor: User;
273 workspace: string;
274 slug: string;
275 changes: { name?: string; description?: string | null; rootDir?: string };
276 }): Promise<Result<Project>> {
277 const workspace = a.workspace.toLowerCase();
278 if (!isMember(a.actor, workspace)) return fail("forbidden", "Only members can change a workspace's projects.");
279 const row = await this.db
280 .prepare("SELECT * FROM projects WHERE workspace = ? AND slug = ?")
281 .bind(workspace, a.slug.toLowerCase())
282 .first<Row>();
283 if (!row) return fail("not_found", "There is no such project.");
284 const name = a.changes.name?.trim() || row.name;
285 const description = a.changes.description === undefined ? row.description : a.changes.description?.trim() || null;
286 const rootDir = a.changes.rootDir === undefined ? row.root_dir : a.changes.rootDir.trim().replace(/^\/+|\/+$/g, "");
287 if (rootDir.split("/").some((part) => part === "..")) return fail("invalid", "The root directory is inside the repository.");
288 await this.db
289 .prepare("UPDATE projects SET name = ?, description = ?, root_dir = ?, updated_at = ? WHERE id = ?")
290 .bind(name.slice(0, 100), description, rootDir, now(), row.id)
291 .run();
292 return ok(toProject((await this.db.prepare("SELECT * FROM projects WHERE id = ?").bind(row.id).first<Row>())!));
293 }
294
295 async onEvent(event: G1tEvent): Promise<void> {
296 if (event.type !== "repo.created") return;
297 const actor = await this.workspaceActor(event.data.namespace);
298 if (!actor) return;
299 const repo = await reposClient(this.env.REPOS).get({ namespace: event.data.namespace, name: event.data.name }, actor);
300 if (repo.ok) await this.ensureFor(repo.value, event.actor ?? "g1t");
301 }
302}
303
304export default {
305 async fetch(request: Request, env: Env): Promise<Response> {
306 const match = new URL(request.url).pathname.match(/^\/rpc\/([a-z_]+)$/);
307 if (request.method !== "POST" || !match) return new Response("Not found\n", { status: 404 });
308 const service = new Projects(env);
309 const args = (await request.json().catch(() => ({}))) as any;
310 switch (match[1]) {
311 case "list":
312 return Response.json(await service.list(args));
313 case "get":
314 return Response.json(await service.get(args));
315 case "by_repo":
316 return Response.json(await service.byRepo(args));
317 case "create":
318 return Response.json(await service.create(args));
319 case "update":
320 return Response.json(await service.update(args));
321 default:
322 return new Response("Unknown method\n", { status: 404 });
323 }
324 },
325
326 async queue(batch: MessageBatch<G1tEvent>, env: Env): Promise<void> {
327 const service = new Projects(env);
328 for (const message of batch.messages) {
329 try {
330 await service.onEvent(message.body);
331 message.ack();
332 } catch (error) {
333 console.error("projects could not handle", message.body.type, error);
334 message.retry();
335 }
336 }
337 },
338} satisfies ExportedHandler<Env, G1tEvent>;