| 1 | -- A new account confirms its address before it can do anything on g1t, |
| 2 | -- by typing the code from its confirmation email or following the link in |
| 3 | -- the same email (src/emails.rs). |
| 4 | |
| 5 | -- The code sent with a confirmation link: an HMAC of it, never the code. |
| 6 | -- One row holds both, so using either deletes the row and ends both. |
| 7 | ALTER TABLE email_tokens ADD COLUMN code_hash TEXT; |
| 8 | |
| 9 | -- When what an invite gives was applied: the workspace it joins, and the |
| 10 | -- repository invitations sent with it. An invite used to sign up is spent |
| 11 | -- (redeemed_at) at once, but applied only when the new account confirms |
| 12 | -- its address, in the same transaction. Null on a redeemed invite means |
| 13 | -- it is waiting for that. |
| 14 | ALTER TABLE invites ADD COLUMN applied_at TEXT; |
| 15 | |
| 16 | -- Every invite used before now was applied when it was used. |
| 17 | UPDATE invites SET applied_at = redeemed_at WHERE redeemed_at IS NOT NULL; |
| 18 | |
| 19 | CREATE INDEX invites_awaiting ON invites (redeemed_by) WHERE redeemed_at IS NOT NULL AND applied_at IS NULL; |