| 1 | -- One kind of access token. Classic tokens (scopes, reaching whatever |
| 2 | -- their owner can) and fine-grained ones (a resource owner, repositories |
| 3 | -- and named permissions, 0034) become the same thing: permissions, |
| 4 | -- a level for each resource, stored as scopes (the highest of each |
| 5 | -- resource), and a reach. See src/token_reach.rs and |
| 6 | -- crates/contracts/src/tokens.rs. |
| 7 | -- |
| 8 | -- Nothing a token can do changes. Every check already read `scopes`, and |
| 9 | -- a token's reach is read from the columns it already has: |
| 10 | -- owner_workspace_id set made for that workspace |
| 11 | -- owner_workspace_id null, selection |
| 12 | -- 'public' made for no workspace: its owner's |
| 13 | -- account and public repositories |
| 14 | -- anything else made for every workspace its |
| 15 | -- owner belongs to (a classic token) |
| 16 | -- A workspace's own token reaches its workspace, as before. |
| 17 | -- |
| 18 | -- Running this twice changes nothing the second time. |
| 19 | |
| 20 | -- Full access, set out as permissions. A person's tokens made on purpose |
| 21 | -- (listed, or never expiring: settings and `g1t login`) whose scopes are |
| 22 | -- `*`, or null (made before scopes, full access), get every resource at |
| 23 | -- its highest level. Applications' and agents' credentials keep theirs. |
| 24 | UPDATE access_tokens |
| 25 | SET scopes = 'repo:admin code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write account:write notifications:write workspace:admin billing:write access:admin webhooks:admin secrets:admin runners:admin models:write' |
| 26 | WHERE (scopes IS NULL OR scopes = '*') |
| 27 | AND user_id IS NOT NULL AND workspace_id IS NULL |
| 28 | AND agent_scope IS NULL AND job_id IS NULL |
| 29 | AND (expires_at IS NULL OR listed = 1); |
| 30 | |
| 31 | -- A workspace's own tokens with full access: every resource but a |
| 32 | -- person's account. One an owner gave Admin keeps Repositories: admin; |
| 33 | -- one without has Repositories: write and Who has access: read, all its |
| 34 | -- Write role ever let it use. |
| 35 | UPDATE access_tokens |
| 36 | SET scopes = 'repo:admin code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write workspace:admin billing:write access:admin webhooks:admin secrets:admin runners:admin models:write' |
| 37 | WHERE (scopes IS NULL OR scopes = '*') |
| 38 | AND workspace_id IS NOT NULL AND agent_scope IS NULL AND job_id IS NULL |
| 39 | AND COALESCE(admin, 0) = 1; |
| 40 | UPDATE access_tokens |
| 41 | SET scopes = 'repo:write code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write workspace:admin billing:write access:read webhooks:admin secrets:admin runners:admin models:write' |
| 42 | WHERE (scopes IS NULL OR scopes = '*') |
| 43 | AND workspace_id IS NOT NULL AND agent_scope IS NULL AND job_id IS NULL |
| 44 | AND COALESCE(admin, 0) = 0; |
| 45 | |
| 46 | -- A token made for every workspace says so, rather than by a null. |
| 47 | UPDATE access_tokens SET repository_selection = 'all' |
| 48 | WHERE repository_selection IS NULL AND owner_workspace_id IS NULL |
| 49 | AND agent_scope IS NULL AND job_id IS NULL |
| 50 | AND (expires_at IS NULL OR listed = 1); |
| 51 | |
| 52 | -- `kind` and the old named `permissions` are retired: the scopes those |
| 53 | -- permissions gave are what the token holds, and nothing reads either |
| 54 | -- column any more. They are left as they are, not cleared, so the identity |
| 55 | -- worker from before this change still reads every token correctly in the |
| 56 | -- moments between this migration and its deploy; D1 cannot drop them in |
| 57 | -- place. |
| 58 | |
| 59 | -- token_policies keeps its columns: `allow_classic` is now "tokens made |
| 60 | -- for every workspace of their owner may reach this one", and |
| 61 | -- `allow_fine_grained` "tokens may be made for this workspace alone". Their |
| 62 | -- meaning for every existing token is the same as before. |