g1t/services/identity/migrations/0006_device_codes.sql
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Device sign-in replaces registering and minting tokens over the API | 1 | -- Sign-in for agents and command-line tools (RFC 8628). The tool shows a |
| 2 | -- person a short code; the person approves it in a browser; the tool then | |
| 3 | -- collects an access token. | |
| 4 | -- | |
| 5 | -- Timestamps are RFC 3339 UTC text, which sorts and compares as text. | |
| 6 | CREATE TABLE device_codes ( | |
| 7 | -- SHA-256 of the device code the tool holds. | |
| 8 | id TEXT PRIMARY KEY, | |
| 9 | -- What the person types or sees, e.g. WDJB-MJHT. | |
| 10 | user_code TEXT NOT NULL UNIQUE, | |
| 11 | client_name TEXT NOT NULL, | |
| 12 | -- 'pending', 'approved' or 'denied' | |
| 13 | status TEXT NOT NULL DEFAULT 'pending', | |
| 14 | user_id TEXT REFERENCES users (id) ON DELETE CASCADE, | |
| 15 | expires_at TEXT NOT NULL | |
| 16 | ); |