Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Fine-grained personal tokens, workspace token rules and approvals in identity | 1 | -- Fine-grained personal access tokens, and each workspace's rules for the |
| 2 | -- tokens that reach it. This reverses 0023, which retired a token's reach | |
| 3 | -- to some workspaces or repositories: the owner chose GitHub's model, with | |
| 4 | -- classic tokens (reaching whatever their owner can, narrowed by scopes) | |
| 5 | -- and fine-grained ones (one resource owner, some of its repositories, a | |
| 6 | -- level for each permission) side by side. See src/token_reach.rs. | |
| 7 | -- | |
| 8 | -- Nothing existing changes: every column is null on today's tokens, which | |
| 9 | -- read as classic (personal) or as a workspace's token with Write. | |
| 10 | ||
| 11 | -- `fine_grained` for a fine-grained token; null for a classic one, a | |
| 12 | -- workspace's own token, a job's token and an agent's. | |
| 13 | ALTER TABLE access_tokens ADD COLUMN kind TEXT; | |
| 14 | -- A fine-grained token's resource owner: a workspace's id, or null for the | |
| 15 | -- person's own account. | |
| 16 | ALTER TABLE access_tokens ADD COLUMN owner_workspace_id TEXT; | |
| 17 | -- all | selected | public, for a fine-grained token. | |
| 18 | ALTER TABLE access_tokens ADD COLUMN repository_selection TEXT; | |
| 19 | -- A fine-grained token's permissions as JSON, `{"contents": "write"}`. | |
| 20 | -- Its `scopes` are what they map to, and are what every check reads. | |
| 21 | ALTER TABLE access_tokens ADD COLUMN permissions TEXT; | |
| 22 | -- What it is for, as its owner wrote it. | |
| 23 | ALTER TABLE access_tokens ADD COLUMN description TEXT; | |
| 24 | -- A fine-grained token aimed at a workspace that asks for approval: | |
| 25 | -- pending until an owner approves it, then active; denied or revoked by an | |
| 26 | -- owner. Null is active. Only an active one reaches the workspace. | |
| 27 | ALTER TABLE access_tokens ADD COLUMN status TEXT; | |
| 28 | -- Who reviewed or revoked it, when, and why. | |
| 29 | ALTER TABLE access_tokens ADD COLUMN reviewed_by TEXT; | |
| 30 | ALTER TABLE access_tokens ADD COLUMN reviewed_at TEXT; | |
| 31 | ALTER TABLE access_tokens ADD COLUMN review_reason TEXT; | |
| 32 | -- 1 on a workspace's own token an owner gave Admin when making it. Every | |
| 33 | -- other workspace token has Write on the workspace's repositories. | |
| 34 | ALTER TABLE access_tokens ADD COLUMN admin INTEGER; | |
| 35 | CREATE INDEX access_tokens_owner_workspace ON access_tokens (owner_workspace_id) WHERE owner_workspace_id IS NOT NULL; | |
| 36 | ||
| 37 | -- The repositories a fine-grained token with `selected` reaches, by id, so | |
| 38 | -- renames and transfers within the workspace keep them. | |
| 39 | CREATE TABLE token_repositories ( | |
| 40 | token_id TEXT NOT NULL, | |
| 41 | repo_id TEXT NOT NULL, | |
| 42 | PRIMARY KEY (token_id, repo_id) | |
| 43 | ); | |
| 44 | ||
| 45 | -- A workspace's rules for personal access tokens. No row: the defaults | |
| 46 | -- (both kinds allowed, fine-grained tokens need an owner's approval, no | |
| 47 | -- lifetime limit beyond a fine-grained token's 366 days). | |
| 48 | CREATE TABLE token_policies ( | |
| 49 | workspace_id TEXT PRIMARY KEY, | |
| 50 | -- Whether classic tokens reach the workspace: 1 or 0. | |
| 51 | allow_classic INTEGER NOT NULL DEFAULT 1, | |
| 52 | -- Whether fine-grained tokens may name it as their resource owner. | |
| 53 | allow_fine_grained INTEGER NOT NULL DEFAULT 1, | |
| 54 | -- Whether a fine-grained token naming it waits for an owner's approval. | |
| 55 | require_approval INTEGER NOT NULL DEFAULT 1, | |
| 56 | -- The longest a token reaching it may last, in days; null: no limit. | |
| 57 | max_lifetime_days INTEGER, | |
| 58 | -- 1: a token that never expires does not reach it. | |
| 59 | forbid_no_expiry INTEGER NOT NULL DEFAULT 0, | |
| 60 | updated_by TEXT, | |
| 61 | updated_at TEXT | |
| 62 | ); | |
| 63 | ||
| 64 | -- A classic token an owner took out of their workspace: it keeps working | |
| 65 | -- elsewhere, and never reaches this workspace again. | |
| 66 | CREATE TABLE token_workspace_revocations ( | |
| 67 | token_id TEXT NOT NULL, | |
| 68 | workspace_id TEXT NOT NULL, | |
| 69 | revoked_by TEXT, | |
| 70 | revoked_at TEXT NOT NULL, | |
| 71 | reason TEXT, | |
| 72 | PRIMARY KEY (token_id, workspace_id) | |
| 73 | ); |