Skip to content
62 linesCodeBlameRaw
1-- One kind of access token. Classic tokens (scopes, reaching whatever
2-- their owner can) and fine-grained ones (a resource owner, repositories
3-- and named permissions, 0034) become the same thing: permissions,
4-- a level for each resource, stored as scopes (the highest of each
5-- resource), and a reach. See src/token_reach.rs and
6-- crates/contracts/src/tokens.rs.
7--
8-- Nothing a token can do changes. Every check already read `scopes`, and
9-- a token's reach is read from the columns it already has:
10-- owner_workspace_id set made for that workspace
11-- owner_workspace_id null, selection
12-- 'public' made for no workspace: its owner's
13-- account and public repositories
14-- anything else made for every workspace its
15-- owner belongs to (a classic token)
16-- A workspace's own token reaches its workspace, as before.
17--
18-- Running this twice changes nothing the second time.
19
20-- Full access, set out as permissions. A person's tokens made on purpose
21-- (listed, or never expiring: settings and `g1t login`) whose scopes are
22-- `*`, or null (made before scopes, full access), get every resource at
23-- its highest level. Applications' and agents' credentials keep theirs.
24UPDATE access_tokens
25SET scopes = 'repo:admin code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write account:write notifications:write workspace:admin billing:write access:admin webhooks:admin secrets:admin runners:admin models:write'
26WHERE (scopes IS NULL OR scopes = '*')
27 AND user_id IS NOT NULL AND workspace_id IS NULL
28 AND agent_scope IS NULL AND job_id IS NULL
29 AND (expires_at IS NULL OR listed = 1);
30
31-- A workspace's own tokens with full access: every resource but a
32-- person's account. One an owner gave Admin keeps Repositories: admin;
33-- one without has Repositories: write and Who has access: read, all its
34-- Write role ever let it use.
35UPDATE access_tokens
36SET scopes = 'repo:admin code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write workspace:admin billing:write access:admin webhooks:admin secrets:admin runners:admin models:write'
37WHERE (scopes IS NULL OR scopes = '*')
38 AND workspace_id IS NOT NULL AND agent_scope IS NULL AND job_id IS NULL
39 AND COALESCE(admin, 0) = 1;
40UPDATE access_tokens
41SET scopes = 'repo:write code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write workspace:admin billing:write access:read webhooks:admin secrets:admin runners:admin models:write'
42WHERE (scopes IS NULL OR scopes = '*')
43 AND workspace_id IS NOT NULL AND agent_scope IS NULL AND job_id IS NULL
44 AND COALESCE(admin, 0) = 0;
45
46-- A token made for every workspace says so, rather than by a null.
47UPDATE access_tokens SET repository_selection = 'all'
48WHERE repository_selection IS NULL AND owner_workspace_id IS NULL
49 AND agent_scope IS NULL AND job_id IS NULL
50 AND (expires_at IS NULL OR listed = 1);
51
52-- `kind` and the old named `permissions` are retired: the scopes those
53-- permissions gave are what the token holds, and nothing reads either
54-- column any more. They are left as they are, not cleared, so the identity
55-- worker from before this change still reads every token correctly in the
56-- moments between this migration and its deploy; D1 cannot drop them in
57-- place.
58
59-- token_policies keeps its columns: `allow_classic` is now "tokens made
60-- for every workspace of their owner may reach this one", and
61-- `allow_fine_grained` "tokens may be made for this workspace alone". Their
62-- meaning for every existing token is the same as before.