g1t/services/identity/migrations/0022_token_scopes.sql
| 1 | -- Scopes for access tokens and applications signed in with OAuth: what each |
| 2 | -- may do, and which workspaces or repositories it reaches. See |
| 3 | -- crates/contracts/src/scopes.rs and src/tokens.rs. |
| 4 | -- |
| 5 | -- `scopes` is the scopes, space-separated (`repo:read issues:write`), or |
| 6 | -- `*` for full access. Null marks a token or grant made before scopes: |
| 7 | -- it keeps full access, so nothing that uses one breaks, and settings |
| 8 | -- show it as legacy with a way to narrow it. No existing row is changed. |
| 9 | -- |
| 10 | -- `resources` is JSON: {"kind":"all"}, {"kind":"workspaces","workspaces": |
| 11 | -- [<workspace ids>]} or {"kind":"repositories","repositories": |
| 12 | -- ["owner/name"]}. Null means all. |
| 13 | ALTER TABLE access_tokens ADD COLUMN scopes TEXT; |
| 14 | ALTER TABLE access_tokens ADD COLUMN resources TEXT; |
| 15 | -- A token a person made with an expiry is still theirs to see and delete; |
| 16 | -- tokens issued to applications and agents, which expire too, are not |
| 17 | -- listed. |
| 18 | ALTER TABLE access_tokens ADD COLUMN listed INTEGER NOT NULL DEFAULT 0; |
| 19 | |
| 20 | ALTER TABLE oauth_codes ADD COLUMN scopes TEXT; |
| 21 | ALTER TABLE oauth_codes ADD COLUMN resources TEXT; |
| 22 | ALTER TABLE oauth_grants ADD COLUMN scopes TEXT; |
| 23 | ALTER TABLE oauth_grants ADD COLUMN resources TEXT; |