g1t/services/identity/migrations/0022_token_scopes.sql
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 1 | -- Scopes for access tokens and applications signed in with OAuth: what each |
| 2 | -- may do, and which workspaces or repositories it reaches. See | |
| 3 | -- crates/contracts/src/scopes.rs and src/tokens.rs. | |
| 4 | -- | |
| 5 | -- `scopes` is the scopes, space-separated (`repo:read issues:write`), or | |
| 6 | -- `*` for full access. Null marks a token or grant made before scopes: | |
| 7 | -- it keeps full access, so nothing that uses one breaks, and settings | |
| 8 | -- show it as legacy with a way to narrow it. No existing row is changed. | |
| 9 | -- | |
| 10 | -- `resources` is JSON: {"kind":"all"}, {"kind":"workspaces","workspaces": | |
| 11 | -- [<workspace ids>]} or {"kind":"repositories","repositories": | |
| 12 | -- ["owner/name"]}. Null means all. | |
| 13 | ALTER TABLE access_tokens ADD COLUMN scopes TEXT; | |
| 14 | ALTER TABLE access_tokens ADD COLUMN resources TEXT; | |
| 15 | -- A token a person made with an expiry is still theirs to see and delete; | |
| 16 | -- tokens issued to applications and agents, which expire too, are not | |
| 17 | -- listed. | |
| 18 | ALTER TABLE access_tokens ADD COLUMN listed INTEGER NOT NULL DEFAULT 0; | |
| 19 | ||
| 20 | ALTER TABLE oauth_codes ADD COLUMN scopes TEXT; | |
| 21 | ALTER TABLE oauth_codes ADD COLUMN resources TEXT; | |
| 22 | ALTER TABLE oauth_grants ADD COLUMN scopes TEXT; | |
| 23 | ALTER TABLE oauth_grants ADD COLUMN resources TEXT; |