Documentation
¶
Overview ¶
Package githubapp defines the Workbench GitHub App control-plane API.
Index ¶
- Constants
- Variables
- func NewHandler(options HandlerOptions) http.Handler
- func ProjectionKey(scope Scope, id string) string
- func ValidateProjectionDocument(document ProjectionDocument) error
- func ValidatePublicEligibility(evidence PublicEligibility) error
- type Access
- type AuthoritativeProjectionReader
- type AuthoritativeReader
- type Dashboard
- type DeliveryStore
- type DocumentProjectionDeliveryStore
- func (store DocumentProjectionDeliveryStore) ClaimDelivery(ctx context.Context, id string) (bool, error)
- func (store DocumentProjectionDeliveryStore) CommitDeliveryAndWakeup(ctx context.Context, id string, wakeup Wakeup) (bool, error)
- func (store DocumentProjectionDeliveryStore) HasDelivery(ctx context.Context, id string) (bool, error)
- func (store DocumentProjectionDeliveryStore) ReleaseDelivery(ctx context.Context, id string) error
- type DocumentProjectionStore
- func (store DocumentProjectionStore) GetLeaderboard(ctx context.Context, metric string) (LeaderboardDocument, error)
- func (store DocumentProjectionStore) GetProjection(ctx context.Context, scope Scope, id string) (ProjectionDocument, error)
- func (store DocumentProjectionStore) ListProjections(ctx context.Context, scope Scope) ([]ProjectionDocument, error)
- func (store DocumentProjectionStore) ListPublicLatestMerges(ctx context.Context, limit int) (PublicLatestMerges, error)
- func (store DocumentProjectionStore) ListSeries(ctx context.Context, scope Scope, id, metric string) (SeriesDocument, error)
- type DocumentProjectionWriter
- func (writer DocumentProjectionWriter) WriteLatestMerges(ctx context.Context, deliveryID string, batch RepositoryLatestMerges) error
- func (writer DocumentProjectionWriter) WriteOrganizations(ctx context.Context, deliveryID string, records []ProjectionDocument) error
- func (writer DocumentProjectionWriter) WriteRepositories(ctx context.Context, deliveryID string, records []ProjectionDocument) error
- type DocumentStore
- type DocumentTransaction
- type Event
- type EventFilter
- type EventSource
- type EventType
- type GitHubRESTProjectionReader
- func (reader GitHubRESTProjectionReader) Refresh(ctx context.Context, delivery WebhookDelivery) error
- func (reader GitHubRESTProjectionReader) RefreshAuthoritativeProjection(ctx context.Context, delivery WebhookDelivery) (ProjectionSnapshot, error)
- func (reader GitHubRESTProjectionReader) RefreshProjection(ctx context.Context, delivery WebhookDelivery) (ProjectionSnapshot, error)
- type GitHubTokenSource
- type HTTPDoer
- type HandlerOptions
- type InstallationTokenSource
- type LatestMerge
- type Leaderboard
- type LeaderboardDocument
- type LeaderboardEntry
- type Link
- type MachineAccessResolver
- type MachinePublisher
- type MachinePublisherResolver
- type MachineSnapshotService
- type MembershipResolver
- type ProjectionDeliveryStore
- type ProjectionDocument
- type ProjectionEngine
- type ProjectionReader
- type ProjectionSnapshot
- type ProjectionStore
- type ProjectionWriter
- type PublicEligibility
- type PublicLatestMerges
- type ReadModel
- type RemoteStateWorktreeReadModel
- type RepositoryLatestMerges
- type Scope
- type Series
- type SeriesDocument
- type SeriesPoint
- type Service
- func (service Service) Dashboard(ctx context.Context, viewer Viewer) (Dashboard, error)
- func (service Service) EventStream(ctx context.Context, viewer Viewer, filter EventFilter) ([]Event, <-chan Event, error)
- func (service Service) LatestMerges(ctx context.Context, viewer Viewer, limit int) ([]LatestMerge, error)
- func (service Service) Leaderboard(ctx context.Context, viewer Viewer, metric string) (Leaderboard, error)
- func (service Service) ProcessWebhook(ctx context.Context, delivery WebhookDelivery, signature string) (bool, error)
- func (service Service) Series(ctx context.Context, viewer Viewer, scope Scope, id, metric string) (Series, error)
- func (service Service) Stats(ctx context.Context, viewer Viewer, scope Scope, id string) (Stat, error)
- func (service Service) WorktreeTable(ctx context.Context, viewer Viewer, filter WorktreeFilter) (WorktreeTable, error)
- type Stat
- type StoreReadModel
- func (model StoreReadModel) Dashboard(ctx context.Context, viewer Viewer) (Access[Dashboard], error)
- func (model StoreReadModel) LatestMerges(ctx context.Context, viewer Viewer, limit int) (Access[[]LatestMerge], error)
- func (model StoreReadModel) Leaderboard(ctx context.Context, viewer Viewer, metric string) (Access[Leaderboard], error)
- func (model StoreReadModel) Series(ctx context.Context, viewer Viewer, scope Scope, id, metric string) (Access[Series], error)
- func (model StoreReadModel) Stats(ctx context.Context, viewer Viewer, scope Scope, id string) (Access[Stat], error)
- type Summary
- type Viewer
- type ViewerResolver
- type Visibility
- type Wakeup
- type WebhookDelivery
- type WorktreeFilter
- type WorktreeReadModel
- type WorktreeRow
- type WorktreeTable
Constants ¶
const ( // ControlPlaneOrigin is the dedicated machine API origin. ControlPlaneOrigin = "https://wb-github-app.sneat.dev" // ControlPlaneHost is the host-only form used by the Cloud Run adapter. ControlPlaneHost = "wb-github-app.sneat.dev" // UIOrigin is the browser origin permitted to call the control-plane API. UIOrigin = "https://sneat.work" // APIPrefix is mounted by the host application. APIPrefix = "/v0/workbench" )
const ( ProjectionCollection = "workbench_projections" SeriesCollection = "workbench_series" LeaderboardCollection = "workbench_leaderboards" MergeCollection = "workbench_latest_merges" )
const DefaultMachineStaleAfter = 24 * time.Hour
DefaultMachineStaleAfter matches WB's ordinary remote-machine freshness window. Hosted views keep stale rows visible; this threshold only labels their last published observation.
Variables ¶
var ( ErrPublisherIdentity = errors.New("machine publisher identity is unavailable") ErrPublisherMismatch = errors.New("published login or machine does not match the authenticated publisher") )
var ( ErrNoProjector = errors.New("workbench projection engine is not configured") ErrInvalidProjection = errors.New("invalid workbench projection snapshot") )
var ( ErrPrivateData = errors.New("private Workbench data requires membership") ErrNoReadModel = errors.New("workbench read model is not configured") ErrNoWebhook = errors.New("workbench webhook processor is not configured") )
var ErrProjectionNotFound = errors.New("workbench projection not found")
Functions ¶
func NewHandler ¶
func NewHandler(options HandlerOptions) http.Handler
NewHandler returns the Workbench GitHub App API under APIPrefix. It permits the Sneat Workbench browser origin only; GitHub webhooks have no CORS need.
func ProjectionKey ¶ added in v0.100.0
ProjectionKey is the stable document key: scope plus a SHA-256 digest of the canonical subject ID. The digest prevents slashes in github.com/org/repo IDs from changing collection hierarchy while preserving the original ID in the document body for audit and display.
func ValidateProjectionDocument ¶ added in v0.100.0
func ValidateProjectionDocument(document ProjectionDocument) error
func ValidatePublicEligibility ¶ added in v0.102.0
func ValidatePublicEligibility(evidence PublicEligibility) error
ValidatePublicEligibility rejects incomplete or non-canonical durable evidence. It intentionally verifies the identity and URL shape only; the authoritative reader verifies the README contents before it records this evidence with a projection.
Types ¶
type Access ¶
type Access[T any] struct { Visibility Visibility Value T }
Access wraps a read-model result with its disclosure class.
type AuthoritativeProjectionReader ¶ added in v0.103.0
type AuthoritativeProjectionReader interface {
RefreshAuthoritativeProjection(context.Context, WebhookDelivery) (ProjectionSnapshot, error)
}
AuthoritativeProjectionReader combines the freshness barrier and projection read for readers that can carry one request-scoped GitHub snapshot across the provider boundary. This avoids issuing the same REST reads twice.
type AuthoritativeReader ¶
type AuthoritativeReader interface {
Refresh(context.Context, WebhookDelivery) error
}
AuthoritativeReader refreshes the GitHub App's authoritative view before an action is queued. A cache hit alone must never satisfy this call.
type Dashboard ¶
type Dashboard struct {
GeneratedAt time.Time `json:"generated_at"`
Summary Summary `json:"summary"`
Links []Link `json:"links,omitempty"`
}
Dashboard is the top-level dashboard response.
type DeliveryStore ¶
type DeliveryStore interface {
HasDelivery(context.Context, string) (bool, error)
CommitDeliveryAndWakeup(context.Context, string, Wakeup) (bool, error)
}
DeliveryStore must be backed by durable storage. HasDelivery is a cheap preflight that avoids repeating an authoritative GitHub read for a redelivery. CommitDeliveryAndWakeup atomically records the delivery ID and persists a wakeup coalesced by its scope key. It returns false when a concurrent request committed the same delivery first.
type DocumentProjectionDeliveryStore ¶ added in v0.124.4
type DocumentProjectionDeliveryStore struct {
Backend DocumentStore
Now func() time.Time
Lease time.Duration
}
DocumentProjectionDeliveryStore provides the atomic claim and coalesced wakeup used by ProjectionEngine. An expired claim is recoverable.
func (DocumentProjectionDeliveryStore) ClaimDelivery ¶ added in v0.124.4
func (DocumentProjectionDeliveryStore) CommitDeliveryAndWakeup ¶ added in v0.124.4
func (DocumentProjectionDeliveryStore) HasDelivery ¶ added in v0.124.4
func (DocumentProjectionDeliveryStore) ReleaseDelivery ¶ added in v0.124.4
func (store DocumentProjectionDeliveryStore) ReleaseDelivery(ctx context.Context, id string) error
type DocumentProjectionStore ¶ added in v0.124.4
type DocumentProjectionStore struct{ Backend DocumentStore }
DocumentProjectionStore maps the documented Workbench collections to the host's document store. The adapter contains no cloud.google.com imports, keeping the provider portable and letting the host supply its configured engine.
func (DocumentProjectionStore) GetLeaderboard ¶ added in v0.124.4
func (store DocumentProjectionStore) GetLeaderboard(ctx context.Context, metric string) (LeaderboardDocument, error)
func (DocumentProjectionStore) GetProjection ¶ added in v0.124.4
func (store DocumentProjectionStore) GetProjection(ctx context.Context, scope Scope, id string) (ProjectionDocument, error)
func (DocumentProjectionStore) ListProjections ¶ added in v0.124.4
func (store DocumentProjectionStore) ListProjections(ctx context.Context, scope Scope) ([]ProjectionDocument, error)
func (DocumentProjectionStore) ListPublicLatestMerges ¶ added in v0.124.4
func (store DocumentProjectionStore) ListPublicLatestMerges(ctx context.Context, limit int) (PublicLatestMerges, error)
func (DocumentProjectionStore) ListSeries ¶ added in v0.124.4
func (store DocumentProjectionStore) ListSeries(ctx context.Context, scope Scope, id, metric string) (SeriesDocument, error)
type DocumentProjectionWriter ¶ added in v0.124.4
type DocumentProjectionWriter struct{ Backend DocumentStore }
DocumentProjectionWriter applies complete batches by stable document key. Set is intentionally idempotent, so a retry after a crash cannot duplicate projections or public merges.
func (DocumentProjectionWriter) WriteLatestMerges ¶ added in v0.124.4
func (writer DocumentProjectionWriter) WriteLatestMerges(ctx context.Context, deliveryID string, batch RepositoryLatestMerges) error
func (DocumentProjectionWriter) WriteOrganizations ¶ added in v0.124.4
func (writer DocumentProjectionWriter) WriteOrganizations(ctx context.Context, deliveryID string, records []ProjectionDocument) error
func (DocumentProjectionWriter) WriteRepositories ¶ added in v0.124.4
func (writer DocumentProjectionWriter) WriteRepositories(ctx context.Context, deliveryID string, records []ProjectionDocument) error
type DocumentStore ¶ added in v0.124.4
type DocumentStore interface {
Get(context.Context, string, string, any) (bool, error)
Query(context.Context, string, map[string]any, int, any) error
Set(context.Context, string, string, any) error
UpdateAtomic(context.Context, func(DocumentTransaction) error) error
}
DocumentStore is the deliberately small seam over a hierarchical document database. A collection is addressed by its slash-joined path ("installations/42/chunks"), a document by its id within it. Values are decoded into out by the store. Query takes equality filters only (a nil or empty map is an unfiltered scan) and a limit, where 0 means unbounded; out is a pointer to a slice of the document type. UpdateAtomic must provide serializable transaction semantics and may invoke its callback more than once when the storage engine retries a conflict.
dalgostore.New implements it on DALgo, so the hosted instance runs on dalgo2firestore and a self-hoster picks any DALgo engine. See spec/decisions/0002-bench-open-source-and-self-hosting.md.
type DocumentTransaction ¶ added in v0.124.4
type DocumentTransaction interface {
Get(context.Context, string, string, any) (bool, error)
Set(context.Context, string, string, any) error
// Delete removes one document inside the same atomic update. Provider-owned
// stores need it to consume a pending installation state once it has been
// transitioned or completed, and to drop acknowledged pending event
// references, so that a replay cannot observe state that was already spent.
Delete(context.Context, string, string) error
}
type Event ¶
type Event struct {
ID uint64 `json:"id"`
Type EventType `json:"type"`
Visibility Visibility `json:"visibility"`
At time.Time `json:"at"`
Repository string `json:"repository,omitempty"`
Task string `json:"task,omitempty"`
Operation string `json:"operation,omitempty"`
Session string `json:"session,omitempty"`
Severity string `json:"severity,omitempty"`
Payload json.RawMessage `json:"payload"`
}
Event is an SSE record. ID is a durable monotonic cursor, not a timestamp. Payload is only serialized after the viewer passes its visibility check.
type EventFilter ¶
type EventFilter struct {
After uint64
Since time.Time
Repository string
Task string
Operation string
Session string
Severity string
}
EventFilter selects one resumable daemon/direct-WB event sequence. Work Logs remain immutable per-task evidence; this filter is transient monitoring only.
type EventSource ¶
type EventSource interface {
Replay(context.Context, EventFilter) ([]Event, error)
Subscribe(context.Context, EventFilter) (<-chan Event, error)
}
EventSource durably replays events strictly after a cursor, then exposes a live subscription. Implementations must retain enough history for reconnects and issue globally monotonic IDs across daemon generations.
type EventType ¶
type EventType string
EventType classifies a live Workbench daemon update. WebSocket is reserved for later bidirectional controls such as cancel and reprioritize.
type GitHubRESTProjectionReader ¶ added in v0.103.0
type GitHubRESTProjectionReader struct {
HTTP HTTPDoer
Tokens GitHubTokenSource
APIBase string
Now func() time.Time
}
GitHubRESTProjectionReader builds one delivery snapshot from GitHub's REST API. APIBase is injectable for a host proxy and tests; the default is the public GitHub API.
func (GitHubRESTProjectionReader) Refresh ¶ added in v0.103.0
func (reader GitHubRESTProjectionReader) Refresh(ctx context.Context, delivery WebhookDelivery) error
func (GitHubRESTProjectionReader) RefreshAuthoritativeProjection ¶ added in v0.103.0
func (reader GitHubRESTProjectionReader) RefreshAuthoritativeProjection(ctx context.Context, delivery WebhookDelivery) (ProjectionSnapshot, error)
func (GitHubRESTProjectionReader) RefreshProjection ¶ added in v0.103.0
func (reader GitHubRESTProjectionReader) RefreshProjection(ctx context.Context, delivery WebhookDelivery) (ProjectionSnapshot, error)
type GitHubTokenSource ¶ added in v0.103.0
type GitHubTokenSource interface {
Token(context.Context, WebhookDelivery) (string, error)
}
type HTTPDoer ¶ added in v0.103.0
HTTPDoer and GitHubTokenSource keep credentials and transport in the host. The reader never imports a GitHub SDK or accepts identity from a webhook payload beyond its repository/install identity.
type HandlerOptions ¶
type HandlerOptions struct {
Service Service
ViewerResolver ViewerResolver
PublisherResolver MachinePublisherResolver
MachineSnapshots *MachineSnapshotService
AllowedOrigin string
}
HandlerOptions supplies the narrow host bindings for the public API.
type InstallationTokenSource ¶ added in v0.104.0
type InstallationTokenSource struct {
AppID int64
PrivateKeyPEM []byte
Transport http.RoundTripper
APIBase string
Now func() time.Time
}
InstallationTokenSource exchanges a delivery's exact GitHub App installation identity for a short-lived installation access token. Hosts supply every credential, the HTTP transport, and the clock.
func (InstallationTokenSource) Token ¶ added in v0.104.0
func (source InstallationTokenSource) Token(ctx context.Context, delivery WebhookDelivery) (string, error)
Token creates a short-lived RS256 GitHub App JWT and exchanges it for the installation token identified by delivery.Payload. Errors never include the private key, JWT, installation token, or response body.
type LatestMerge ¶
type LatestMerge struct {
Repository string `json:"repository" firestore:"repository"`
PullRequest int `json:"pull_request" firestore:"pull_request"`
MergedAt time.Time `json:"merged_at" firestore:"merged_at"`
PullRequestURL string `json:"pull_request_url,omitempty" firestore:"pull_request_url,omitempty"`
IssueURL string `json:"issue_url,omitempty" firestore:"issue_url,omitempty"`
MergeCommitSHA string `json:"merge_commit_sha,omitempty" firestore:"merge_commit_sha,omitempty"`
MergeCommitURL string `json:"merge_commit_url,omitempty" firestore:"merge_commit_url,omitempty"`
ReleaseURL string `json:"release_url,omitempty" firestore:"release_url,omitempty"`
ReceiptURL string `json:"receipt_url,omitempty" firestore:"receipt_url,omitempty"`
}
LatestMerge gives the dashboard every navigable artifact around a merge.
type Leaderboard ¶
type Leaderboard struct {
Metric string `json:"metric"`
Entries []LeaderboardEntry `json:"entries"`
}
Leaderboard groups ranked values for a requested metric.
type LeaderboardDocument ¶ added in v0.100.0
type LeaderboardDocument struct {
Metric string `json:"metric" firestore:"metric"`
Entries []LeaderboardEntry `json:"entries" firestore:"entries"`
PublicOnly bool `json:"public_only" firestore:"public_only"`
}
type LeaderboardEntry ¶
type LeaderboardEntry struct {
Rank int `json:"rank" firestore:"rank"`
SubjectID string `json:"subject_id" firestore:"subject_id"`
DisplayName string `json:"display_name" firestore:"display_name"`
Value int64 `json:"value" firestore:"value"`
}
LeaderboardEntry is intentionally small so public leaderboards do not leak private repository names or private activity counts.
type MachineAccessResolver ¶ added in v0.112.0
type MachineAccessResolver interface {
CanViewMachine(context.Context, Viewer, string, string) (bool, error)
}
MachineAccessResolver proves that one viewer may inspect one exact published machine. Authentication alone is never treated as machine ownership.
type MachinePublisher ¶ added in v0.114.0
MachinePublisher is the exact identity bound to a daemon credential by the host. Neither value comes from request headers or the submitted payload.
type MachinePublisherResolver ¶ added in v0.114.0
type MachinePublisherResolver interface {
Publisher(*http.Request) (MachinePublisher, error)
}
MachinePublisherResolver binds host authentication to one exact WB machine.
type MachineSnapshotService ¶ added in v0.114.0
type MachineSnapshotService struct {
Store machinesnapshot.SnapshotStore
Now func() time.Time
}
MachineSnapshotService applies publisher identity, validation, server time, and privacy-safe persistence around a durable store.
func (MachineSnapshotService) List ¶ added in v0.114.0
func (service MachineSnapshotService) List(ctx context.Context, publisher MachinePublisher) (machinesnapshot.ListResponse, error)
List returns every durable machine for the authenticated login. Publisher credentials never grant cross-login reads.
func (MachineSnapshotService) Publish ¶ added in v0.114.0
func (service MachineSnapshotService) Publish(ctx context.Context, publisher MachinePublisher, snapshot machinesnapshot.Snapshot) (machinesnapshot.Receipt, error)
Publish validates and atomically stores the latest snapshot for one exact authenticated login/machine key.
type MembershipResolver ¶ added in v0.100.0
MembershipResolver proves GitHub installation membership for one canonical subject. A Firebase-authenticated host maps Viewer.UserID to GitHub identity; the provider never trusts browser headers or public GitHub visibility.
type ProjectionDeliveryStore ¶ added in v0.101.0
type ProjectionDeliveryStore interface {
DeliveryStore
ClaimDelivery(context.Context, string) (bool, error)
ReleaseDelivery(context.Context, string) error
}
ProjectionDeliveryStore extends DeliveryStore with an atomic in-flight claim. ClaimDelivery returns false for a committed or currently claimed delivery. ReleaseDelivery makes refresh/write failures retryable; the implementation must retain its append-only audit record.
type ProjectionDocument ¶ added in v0.100.0
type ProjectionDocument struct {
Scope Scope `json:"scope" firestore:"scope"`
ID string `json:"id" firestore:"id"`
DisplayName string `json:"display_name" firestore:"display_name"`
Summary Summary `json:"summary" firestore:"summary"`
UpdatedAt time.Time `json:"updated_at" firestore:"updated_at"`
PublicOptIn bool `json:"public_opt_in" firestore:"public_opt_in"`
PublicEligibility *PublicEligibility `json:"public_eligibility,omitempty" firestore:"public_eligibility,omitempty"`
}
ProjectionDocument is the durable, privacy-classified summary written by a Workbench-owned projector. Public responses require PublicOptIn; private responses require the host membership resolver below.
type ProjectionEngine ¶ added in v0.101.0
type ProjectionEngine struct {
Deliveries ProjectionDeliveryStore
Reader ProjectionReader
Writer ProjectionWriter
AuthoritativeReader AuthoritativeReader
WebhookSecret []byte
}
ProjectionEngine coordinates authoritative refresh, durable projection writes, and delivery receipt publication. It deliberately does not import GitHub, Firebase, or Firestore clients.
func (ProjectionEngine) Process ¶ added in v0.101.0
func (engine ProjectionEngine) Process(ctx context.Context, delivery WebhookDelivery, signature string) (queued bool, processErr error)
Process verifies and applies one delivery. AuthoritativeReader is retained as a required companion to ProjectionReader so hosts cannot accidentally wire a projection reader that omits the existing refresh barrier.
type ProjectionReader ¶ added in v0.101.0
type ProjectionReader interface {
RefreshProjection(context.Context, WebhookDelivery) (ProjectionSnapshot, error)
}
ProjectionReader refreshes and returns the authoritative records for a delivery. Implementations may coalesce equivalent repository refreshes, but must not satisfy a delivery from cache alone.
type ProjectionSnapshot ¶ added in v0.101.0
type ProjectionSnapshot struct {
Repositories []ProjectionDocument
Organizations []ProjectionDocument
LatestMerges *RepositoryLatestMerges
}
ProjectionSnapshot is the authoritative result of refreshing one GitHub App delivery. The reader owns GitHub access; the provider owns validation and the stable projection write order.
type ProjectionStore ¶ added in v0.100.0
type ProjectionStore interface {
ListProjections(context.Context, Scope) ([]ProjectionDocument, error)
GetProjection(context.Context, Scope, string) (ProjectionDocument, error)
ListSeries(context.Context, Scope, string, string) (SeriesDocument, error)
GetLeaderboard(context.Context, string) (LeaderboardDocument, error)
ListPublicLatestMerges(context.Context, int) (PublicLatestMerges, error)
}
ProjectionStore is the narrow durable persistence adapter supplied by the host. Implementations map these operations to Firestore or another durable store; aggregation and disclosure stay in this package.
type ProjectionWriter ¶ added in v0.101.0
type ProjectionWriter interface {
WriteRepositories(context.Context, string, []ProjectionDocument) error
WriteOrganizations(context.Context, string, []ProjectionDocument) error
WriteLatestMerges(context.Context, string, RepositoryLatestMerges) error
}
ProjectionWriter durably applies a complete authoritative snapshot. Every method is keyed by deliveryID and must be idempotent: a crash after a write and before DeliveryStore commits is safe to retry. Implementations should replace projections by ProjectionKey and replace the public merge view as a single logical operation.
type PublicEligibility ¶
type PublicEligibility struct {
Repository string `json:"repository" firestore:"repository"`
READMEURL string `json:"readme_url" firestore:"readme_url"`
VerifiedAt time.Time `json:"verified_at" firestore:"verified_at"`
}
PublicEligibility is the auditable root-README opt-in record required before a repository can appear in unauthenticated results. It is not inferred from GitHub repository visibility alone.
func VerifyPublicEligibility ¶ added in v0.102.0
func VerifyPublicEligibility(repository, readmeURL, markdown string, verifiedAt time.Time) (PublicEligibility, error)
VerifyPublicEligibility returns auditable evidence only when the root README has an explicit Workbench opt-in. The caller supplies the canonical GitHub README URL it read and the verification time from its authoritative refresh.
type PublicLatestMerges ¶ added in v0.100.0
type PublicLatestMerges struct {
Entries []LatestMerge `json:"entries" firestore:"entries"`
}
type ReadModel ¶
type ReadModel interface {
Dashboard(context.Context, Viewer) (Access[Dashboard], error)
Stats(context.Context, Viewer, Scope, string) (Access[Stat], error)
Series(context.Context, Viewer, Scope, string, string) (Access[Series], error)
Leaderboard(context.Context, Viewer, string) (Access[Leaderboard], error)
LatestMerges(context.Context, Viewer, int) (Access[[]LatestMerge], error)
}
ReadModel owns persistence and GitHub data projection. It must return only subjects whose public opt-in is recorded, unless the supplied viewer is an authenticated member of the private subject.
type RemoteStateWorktreeReadModel ¶ added in v0.112.0
type RemoteStateWorktreeReadModel struct {
Store machinesnapshot.SnapshotStore
Access MachineAccessResolver
Now func() time.Time
StaleAfter time.Duration
}
RemoteStateWorktreeReadModel projects existing WB machine snapshots through a per-machine authorization boundary.
func (RemoteStateWorktreeReadModel) Worktrees ¶ added in v0.112.0
func (model RemoteStateWorktreeReadModel) Worktrees(ctx context.Context, viewer Viewer, filter WorktreeFilter) (Access[WorktreeTable], error)
type RepositoryLatestMerges ¶ added in v0.104.2
type RepositoryLatestMerges struct {
Repository string
PublicOptIn bool
Entries []LatestMerge
}
RepositoryLatestMerges is one repository's complete contribution to the anonymous latest-merge view. PublicOptIn false removes any earlier public contribution for the repository without publishing private merge details.
type Series ¶
type Series struct {
Scope Scope `json:"scope"`
ID string `json:"id"`
Metric string `json:"metric"`
Points []SeriesPoint `json:"points"`
}
Series is a named time-series for graph and table consumers.
type SeriesDocument ¶ added in v0.100.0
type SeriesDocument struct {
Scope Scope `json:"scope" firestore:"scope"`
ID string `json:"id" firestore:"id"`
Metric string `json:"metric" firestore:"metric"`
Points []SeriesPoint `json:"points" firestore:"points"`
}
type SeriesPoint ¶
type SeriesPoint struct {
At time.Time `json:"at" firestore:"at"`
Value int64 `json:"value" firestore:"value"`
}
SeriesPoint can render either a graph point or a table row.
type Service ¶
type Service struct {
// Projector is the only supported webhook processor.
Projector *ProjectionEngine
ReadModel ReadModel
Worktrees WorktreeReadModel
Events EventSource
}
Service applies disclosure policy around a Workbench read model and processes signed GitHub App webhook deliveries.
func (Service) EventStream ¶
func (service Service) EventStream(ctx context.Context, viewer Viewer, filter EventFilter) ([]Event, <-chan Event, error)
EventStream replays visible durable events after cursor and returns the filtered live channel. It validates monotonic order so a bad source cannot cause a browser to skip or regress a reconnect cursor.
func (Service) LatestMerges ¶
func (Service) Leaderboard ¶
func (Service) ProcessWebhook ¶
func (service Service) ProcessWebhook(ctx context.Context, delivery WebhookDelivery, signature string) (bool, error)
ProcessWebhook delegates webhook processing to the claim-safe projection engine. Hosts without a configured projector fail closed; the legacy fields are retained only so migrating compositions remain source-compatible.
func (Service) WorktreeTable ¶ added in v0.112.0
func (service Service) WorktreeTable(ctx context.Context, viewer Viewer, filter WorktreeFilter) (WorktreeTable, error)
WorktreeTable returns one privacy-safe row per published worktree on the machines the host authorizes for this viewer.
type Stat ¶
type Stat struct {
Scope Scope `json:"scope"`
ID string `json:"id"`
DisplayName string `json:"display_name"`
Summary Summary `json:"summary"`
UpdatedAt time.Time `json:"updated_at"`
Links []Link `json:"links,omitempty"`
}
Stat is one scoped repository, organization, or user result.
type StoreReadModel ¶ added in v0.100.0
type StoreReadModel struct {
Store ProjectionStore
Membership MembershipResolver
}
func (StoreReadModel) LatestMerges ¶ added in v0.100.0
func (model StoreReadModel) LatestMerges(ctx context.Context, viewer Viewer, limit int) (Access[[]LatestMerge], error)
func (StoreReadModel) Leaderboard ¶ added in v0.100.0
func (model StoreReadModel) Leaderboard(ctx context.Context, viewer Viewer, metric string) (Access[Leaderboard], error)
type Summary ¶
type Summary struct {
Repositories int `json:"repositories" firestore:"repositories"`
OpenPulls int `json:"open_pulls" firestore:"open_pulls"`
MergedPulls int `json:"merged_pulls" firestore:"merged_pulls"`
OpenIssues int `json:"open_issues" firestore:"open_issues"`
Releases int `json:"releases" firestore:"releases"`
}
Summary is the compact dashboard card set.
type ViewerResolver ¶
ViewerResolver binds the host authentication and membership system to the Workbench domain. The WB domain never accepts identity headers directly.
type Visibility ¶
type Visibility string
Visibility describes whether a response contains an explicitly opted-in public subject or a member-only private subject.
const ( VisibilityPublic Visibility = "public" VisibilityPrivate Visibility = "private" )
type Wakeup ¶
type Wakeup struct {
Key string `json:"key" firestore:"key"`
Repository string `json:"repository" firestore:"repository"`
Event string `json:"event" firestore:"event"`
}
Wakeup is a durable, coalescible unit of refresh work.
type WebhookDelivery ¶
WebhookDelivery is the verified, minimally parsed GitHub webhook envelope.
type WorktreeFilter ¶ added in v0.112.0
type WorktreeFilter struct {
Machine string
Repository string
Status string
Stream string
Task string
NeedsAttention *bool
}
WorktreeFilter selects rows in the consolidated development-machine table. Empty strings match every value. NeedsAttention is a pointer so false can be selected explicitly rather than being confused with an omitted filter.
type WorktreeReadModel ¶ added in v0.112.0
type WorktreeReadModel interface {
Worktrees(context.Context, Viewer, WorktreeFilter) (Access[WorktreeTable], error)
}
WorktreeReadModel supplies the private cross-machine dashboard table.
type WorktreeRow ¶ added in v0.112.0
type WorktreeRow struct {
Repository string `json:"repository"`
Task string `json:"task"`
Stream string `json:"stream,omitempty"`
Branch string `json:"branch"`
Status string `json:"status"`
Lifecycle string `json:"lifecycle"`
OwnerStatus string `json:"owner_status"`
Owner string `json:"owner,omitempty"`
PullRequest int `json:"pull_request,omitempty"`
PullRequestURL string `json:"pull_request_url,omitempty"`
Machine string `json:"machine"`
MachineSeenAt time.Time `json:"machine_seen_at"`
MachineStale bool `json:"machine_stale"`
LastActivityAt *time.Time `json:"last_activity_at,omitempty"`
PublishedAt time.Time `json:"published_at"`
NeedsAttention bool `json:"needs_attention"`
AttentionReason string `json:"attention_reason,omitempty"`
}
WorktreeRow is the privacy-safe hosted projection of a published worktree. It intentionally has no local path, projects root, commit subject, or prompt.
type WorktreeTable ¶ added in v0.112.0
type WorktreeTable struct {
GeneratedAt time.Time `json:"generated_at"`
Rows []WorktreeRow `json:"rows"`
}
WorktreeTable is one generated, filterable view across authorized machines.
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package dalgostore implements githubapp.DocumentStore on DALgo.
|
Package dalgostore implements githubapp.DocumentStore on DALgo. |
|
Package machinesnapshot defines the public, privacy-safe HTTP and durable storage contract for hosted WB machine state.
|
Package machinesnapshot defines the public, privacy-safe HTTP and durable storage contract for hosted WB machine state. |
|
Package repositoryevent defines the public, privacy-safe contract used by the Workbench GitHub App to notify enrolled WB daemons about repository changes.
|
Package repositoryevent defines the public, privacy-safe contract used by the Workbench GitHub App to notify enrolled WB daemons about repository changes. |