Skip to content

g1t/services/identity/migrations/0031_membership.sql

26 lines1,467 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA1-- Membership as GitHub has it (crates/contracts/src/members.rs). Identity
2-- 0030 is taken by another change; this starts at 0031.
3--
4-- Wrangler applies it once; each ALTER must run once, like 0019's.
5
6-- Roles that add to a member: a billing manager manages billing as an
7-- owner does; a security manager reads every repository and manages its
8-- security. 1 for yes. Owners have both whatever these say.
9ALTER TABLE workspace_members ADD COLUMN billing_manager INTEGER NOT NULL DEFAULT 0;
10ALTER TABLE workspace_members ADD COLUMN security_manager INTEGER NOT NULL DEFAULT 0;
11
12-- What the workspace lets its members do, as JSON
13-- (g1t_contracts::MemberPrivileges); NULL, or a field left out, is its
14-- default. Set by an owner on Settings -> Member privileges.
15ALTER TABLE workspaces ADD COLUMN member_privileges TEXT;
16
17-- 1 when members and outside collaborators need two-factor
18-- authentication to use the workspace (security.rs). Off for every
19-- workspace until an owner turns it on.
20ALTER TABLE workspaces ADD COLUMN require_two_factor INTEGER NOT NULL DEFAULT 0;
21
22-- The base permission. A new workspace now starts at 'read' (as on
23-- GitHub); create_workspace writes it. Every existing workspace keeps the
24-- value it has: the column has been NOT NULL DEFAULT 'write' since 0020,
25-- so each row already says; this only makes sure none is blank.
26UPDATE workspaces SET base_permission = 'write' WHERE base_permission IS NULL OR trim(base_permission) = '';

This file's history is long; its oldest lines are credited to the oldest commit read.