pr_01m47d15m3e54sn21z27rpy5n9/packages/contracts/src/identity.ts

60 lines2,487 bytesCodeBlame
1import type { Result } from "./result";
2
3export type User = {
4 id: string;
5 username: string;
6 /**
7 * Whether the account's email address is confirmed. Only set on users
8 * resolved from credentials; unverified accounts cannot change anything.
9 */
10 verified?: boolean;
11};
12
13/** Who is asking. Every read and write in every service takes one. */
14export type Viewer = User | null;
15
16export type SshKey = {
17 id: string;
18 title: string;
19 fingerprint: string;
20 createdAt: number;
21};
22
23export type AccessToken = { id: string; name: string; createdAt: number };
24
25/** Accounts, credentials and sessions. */
26export interface IdentityApi {
27 /** Creates an account and signs it in. */
28 register(username: string, email: string, password: string): Promise<Result<{ user: User; sessionToken: string }>>;
29 /** Verifies a username and password for website sign-in. */
30 signIn(username: string, password: string): Promise<Result<{ user: User; sessionToken: string }>>;
31 signOut(sessionToken: string): Promise<void>;
32
33 /** Sends the confirmation email again. */
34 resendVerification(user: User): Promise<Result<boolean>>;
35 /** Confirms the address the emailed token was sent to. */
36 verifyEmail(token: string): Promise<Result<User>>;
37 /** Emails a reset link if the address has an account. Always resolves. */
38 requestPasswordReset(email: string): Promise<boolean>;
39 /** Sets a new password from an emailed token and ends every session. */
40 resetPassword(token: string, password: string): Promise<Result<User>>;
41
42 userForSession(sessionToken: string): Promise<Viewer>;
43
44 /** Verifies git credentials: the account password or an access token. */
45 userForGitCredentials(username: string, secret: string): Promise<Viewer>;
46 /** Resolves a `g1t_…` access token, as sent to the API and MCP server. */
47 userForAccessToken(token: string): Promise<Viewer>;
48 userForSshKey(fingerprint: string): Promise<Viewer>;
49 userByUsername(username: string): Promise<Viewer>;
50
51 listSshKeys(user: User): Promise<SshKey[]>;
52 /** Takes one line in OpenSSH public key format. */
53 addSshKey(user: User, title: string, publicKey: string): Promise<Result<SshKey>>;
54 removeSshKey(user: User, id: string): Promise<void>;
55
56 listAccessTokens(user: User): Promise<AccessToken[]>;
57 /** The plaintext token is returned once and never stored. */
58 createAccessToken(user: User, name: string): Promise<{ token: string; info: AccessToken }>;
59 removeAccessToken(user: User, id: string): Promise<void>;
60}