| 1 | -- Membership as GitHub has it (crates/contracts/src/members.rs). Identity |
| 2 | -- 0030 is taken by another change; this starts at 0031. |
| 3 | -- |
| 4 | -- Wrangler applies it once; each ALTER must run once, like 0019's. |
| 5 | |
| 6 | -- Roles that add to a member: a billing manager manages billing as an |
| 7 | -- owner does; a security manager reads every repository and manages its |
| 8 | -- security. 1 for yes. Owners have both whatever these say. |
| 9 | ALTER TABLE workspace_members ADD COLUMN billing_manager INTEGER NOT NULL DEFAULT 0; |
| 10 | ALTER TABLE workspace_members ADD COLUMN security_manager INTEGER NOT NULL DEFAULT 0; |
| 11 | |
| 12 | -- What the workspace lets its members do, as JSON |
| 13 | -- (g1t_contracts::MemberPrivileges); NULL, or a field left out, is its |
| 14 | -- default. Set by an owner on Settings -> Member privileges. |
| 15 | ALTER TABLE workspaces ADD COLUMN member_privileges TEXT; |
| 16 | |
| 17 | -- 1 when members and outside collaborators need two-factor |
| 18 | -- authentication to use the workspace (security.rs). Off for every |
| 19 | -- workspace until an owner turns it on. |
| 20 | ALTER TABLE workspaces ADD COLUMN require_two_factor INTEGER NOT NULL DEFAULT 0; |
| 21 | |
| 22 | -- The base permission. A new workspace now starts at 'read' (as on |
| 23 | -- GitHub); create_workspace writes it. Every existing workspace keeps the |
| 24 | -- value it has: the column has been NOT NULL DEFAULT 'write' since 0020, |
| 25 | -- so each row already says; this only makes sure none is blank. |
| 26 | UPDATE workspaces SET base_permission = 'write' WHERE base_permission IS NULL OR trim(base_permission) = ''; |