Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers | 1 | -- One kind of access token. Classic tokens (scopes, reaching whatever |
| 2 | -- their owner can) and fine-grained ones (a resource owner, repositories | |
| 3 | -- and named permissions, 0034) become the same thing: permissions, | |
| 4 | -- a level for each resource, stored as scopes (the highest of each | |
| 5 | -- resource), and a reach. See src/token_reach.rs and | |
| 6 | -- crates/contracts/src/tokens.rs. | |
| 7 | -- | |
| 8 | -- Nothing a token can do changes. Every check already read `scopes`, and | |
| 9 | -- a token's reach is read from the columns it already has: | |
| 10 | -- owner_workspace_id set made for that workspace | |
| 11 | -- owner_workspace_id null, selection | |
| 12 | -- 'public' made for no workspace: its owner's | |
| 13 | -- account and public repositories | |
| 14 | -- anything else made for every workspace its | |
| 15 | -- owner belongs to (a classic token) | |
| 16 | -- A workspace's own token reaches its workspace, as before. | |
| 17 | -- | |
| 18 | -- Running this twice changes nothing the second time. | |
| 19 | ||
| 20 | -- Full access, set out as permissions. A person's tokens made on purpose | |
| 21 | -- (listed, or never expiring: settings and `g1t login`) whose scopes are | |
| 22 | -- `*`, or null (made before scopes, full access), get every resource at | |
| 23 | -- its highest level. Applications' and agents' credentials keep theirs. | |
| 24 | UPDATE access_tokens | |
| 25 | SET scopes = 'repo:admin code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write account:write notifications:write workspace:admin billing:write access:admin webhooks:admin secrets:admin runners:admin models:write' | |
| 26 | WHERE (scopes IS NULL OR scopes = '*') | |
| 27 | AND user_id IS NOT NULL AND workspace_id IS NULL | |
| 28 | AND agent_scope IS NULL AND job_id IS NULL | |
| 29 | AND (expires_at IS NULL OR listed = 1); | |
| 30 | ||
| 31 | -- A workspace's own tokens with full access: every resource but a | |
| 32 | -- person's account. One an owner gave Admin keeps Repositories: admin; | |
| 33 | -- one without has Repositories: write and Who has access: read, all its | |
| 34 | -- Write role ever let it use. | |
| 35 | UPDATE access_tokens | |
| 36 | SET scopes = 'repo:admin code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write workspace:admin billing:write access:admin webhooks:admin secrets:admin runners:admin models:write' | |
| 37 | WHERE (scopes IS NULL OR scopes = '*') | |
| 38 | AND workspace_id IS NOT NULL AND agent_scope IS NULL AND job_id IS NULL | |
| 39 | AND COALESCE(admin, 0) = 1; | |
| 40 | UPDATE access_tokens | |
| 41 | SET scopes = 'repo:write code:write security:write packages:delete issues:write pull_requests:write agents:run workflows:write workflow_files:write checks:write deployments:write memory:write workspace:admin billing:write access:read webhooks:admin secrets:admin runners:admin models:write' | |
| 42 | WHERE (scopes IS NULL OR scopes = '*') | |
| 43 | AND workspace_id IS NOT NULL AND agent_scope IS NULL AND job_id IS NULL | |
| 44 | AND COALESCE(admin, 0) = 0; | |
| 45 | ||
| 46 | -- A token made for every workspace says so, rather than by a null. | |
| 47 | UPDATE access_tokens SET repository_selection = 'all' | |
| 48 | WHERE repository_selection IS NULL AND owner_workspace_id IS NULL | |
| 49 | AND agent_scope IS NULL AND job_id IS NULL | |
| 50 | AND (expires_at IS NULL OR listed = 1); | |
| 51 | ||
| 52 | -- `kind` and the old named `permissions` are retired: the scopes those | |
| 53 | -- permissions gave are what the token holds, and nothing reads either | |
| 54 | -- column any more. They are left as they are, not cleared, so the identity | |
| 55 | -- worker from before this change still reads every token correctly in the | |
| 56 | -- moments between this migration and its deploy; D1 cannot drop them in | |
| 57 | -- place. | |
| 58 | ||
| 59 | -- token_policies keeps its columns: `allow_classic` is now "tokens made | |
| 60 | -- for every workspace of their owner may reach this one", and | |
| 61 | -- `allow_fine_grained` "tokens may be made for this workspace alone". Their | |
| 62 | -- meaning for every existing token is the same as before. |