pr_01m47d24b0e6n91zwymwxg0vpx/crates/contracts/src/lib.rs

91 lines2,790 bytesCodeBlame
1//! Types and service interfaces shared by every g1t service.
2//!
3//! Each service has a module here holding the data it exchanges and the
4//! arguments of each of its methods. Services and their callers depend on
5//! this crate, never on each other's code.
6
7pub mod actions;
8pub mod billing;
9pub mod events;
10pub mod identity;
11pub mod integrations;
12mod ids;
13mod names;
14mod outcome;
15pub mod repos;
16pub mod time;
17pub mod webhooks;
18pub mod work;
19
20pub use ids::new_id;
21pub use names::{is_valid_namespace, is_valid_repo_name};
22pub use outcome::{Failure, FailureCode, Outcome};
23
24use serde::{Deserialize, Serialize};
25
26/// What a member may do in a workspace.
27#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
28#[serde(rename_all = "lowercase")]
29pub enum Role {
30 /// Everything a member can, plus managing members.
31 Owner,
32 /// Create repositories, push, manage issues and merge pull requests.
33 Member,
34}
35
36/// One workspace a user belongs to.
37#[derive(Clone, Debug, Serialize, Deserialize)]
38pub struct Membership {
39 /// The workspace's name in URLs: `g1t.sh/<slug>`.
40 pub slug: String,
41 pub role: Role,
42}
43
44/// What a set of credentials resolved to.
45#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
46#[serde(rename_all = "lowercase")]
47pub enum PrincipalKind {
48 /// A person's account.
49 #[default]
50 User,
51 /// A workspace, acting through one of its own access tokens. Its `id`
52 /// is the workspace's, its `username` the workspace's slug, and it is a
53 /// member of that workspace and no other.
54 Workspace,
55 /// A g1t agent at work in a sandbox, acting through a token that lives
56 /// as long as its run and can do only what that token's scope lists, in
57 /// one repository. Its `username` is `g1t-agent`.
58 Agent,
59}
60
61#[derive(Clone, Debug, Default, Serialize, Deserialize)]
62pub struct User {
63 pub id: String,
64 pub username: String,
65 #[serde(default)]
66 pub kind: PrincipalKind,
67 /// Whether the account's email address has been confirmed. Unverified
68 /// accounts can sign in but cannot create or change anything.
69 #[serde(default)]
70 pub verified: bool,
71 /// The workspaces this user belongs to. Filled in when a user is
72 /// resolved from credentials, so any service can authorize from it.
73 #[serde(default)]
74 pub workspaces: Vec<Membership>,
75}
76
77impl User {
78 pub fn role_in(&self, slug: &str) -> Option<Role> {
79 self.workspaces
80 .iter()
81 .find(|membership| membership.slug == slug)
82 .map(|membership| membership.role)
83 }
84
85 pub fn is_member(&self, slug: &str) -> bool {
86 self.role_in(slug).is_some()
87 }
88}
89
90/// Who is asking. Every read and write in every service takes one.
91pub type Viewer = Option<User>;