g1t/services/identity/migrations/0030_job_tokens.sql
| 1 | -- Workflow jobs' tokens (G1T_TOKEN, and GITHUB_TOKEN as its alias): each |
| 2 | -- belongs to the repository's workspace, reaches one repository only, and |
| 3 | -- carries the scopes the job's `permissions:` give it. The actions service |
| 4 | -- revokes a job's tokens when the job ends. See src/job_tokens.rs. |
| 5 | -- |
| 6 | -- `repo` is `owner/name`: a token with one is refused everywhere else. |
| 7 | -- `job_id` and `job_run_id` name the job and its run, which the audit log |
| 8 | -- records against what the token does. All three are null on every other |
| 9 | -- token, so nothing existing changes. |
| 10 | ALTER TABLE access_tokens ADD COLUMN repo TEXT; |
| 11 | ALTER TABLE access_tokens ADD COLUMN job_id TEXT; |
| 12 | ALTER TABLE access_tokens ADD COLUMN job_run_id TEXT; |
| 13 | -- 1 when the job may open and approve pull requests (its repository and |
| 14 | -- workspace allow it); 0 or null otherwise. |
| 15 | ALTER TABLE access_tokens ADD COLUMN job_pulls INTEGER; |
| 16 | CREATE INDEX access_tokens_job ON access_tokens (job_id) WHERE job_id IS NOT NULL; |