Skip to content

g1t/services/identity/migrations/0030_job_tokens.sql

16 lines965 bytesCodeBlameRaw
1-- Workflow jobs' tokens (G1T_TOKEN, and GITHUB_TOKEN as its alias): each
2-- belongs to the repository's workspace, reaches one repository only, and
3-- carries the scopes the job's `permissions:` give it. The actions service
4-- revokes a job's tokens when the job ends. See src/job_tokens.rs.
5--
6-- `repo` is `owner/name`: a token with one is refused everywhere else.
7-- `job_id` and `job_run_id` name the job and its run, which the audit log
8-- records against what the token does. All three are null on every other
9-- token, so nothing existing changes.
10ALTER TABLE access_tokens ADD COLUMN repo TEXT;
11ALTER TABLE access_tokens ADD COLUMN job_id TEXT;
12ALTER TABLE access_tokens ADD COLUMN job_run_id TEXT;
13-- 1 when the job may open and approve pull requests (its repository and
14-- workspace allow it); 0 or null otherwise.
15ALTER TABLE access_tokens ADD COLUMN job_pulls INTEGER;
16CREATE INDEX access_tokens_job ON access_tokens (job_id) WHERE job_id IS NOT NULL;