| 1 | -- A person's access token may be let use the website (g1t.sh) as them, |
| 2 | -- sent as `Authorization: Bearer`, so automation driving a browser can |
| 3 | -- work there without signing in. Off unless its owner turns it on when |
| 4 | -- making or changing the token. It is not a scope: full access and every |
| 5 | -- existing token stay off. See src/tokens.rs and apps/web's |
| 6 | -- app/lib/website-token.ts. |
| 7 | ALTER TABLE access_tokens ADD COLUMN website INTEGER NOT NULL DEFAULT 0; |