flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/identity/migrations/0023_retire_token_reach.sql

21 lines1,247 bytesCodeBlame
1-- Tokens are classic: a token reaches whatever its owner can (a person's
2-- token, their workspaces and repositories; a workspace's token, that
3-- workspace), and only its scopes narrow that. The per-token limit to some
4-- workspaces or repositories that 0022 stored in `resources` is retired.
5--
6-- The `resources` columns stay, since D1 cannot drop a column in place
7-- safely; nothing reads or writes them any more.
8--
9-- A token or application that was limited would otherwise widen silently
10-- to everything its owner can reach. Instead it fails closed: its scopes
11-- are emptied, so it can only say who it is (and read public code) until
12-- its owner gives it scopes again under Settings, Access tokens or
13-- Applications. Then the limits are cleared. Running this twice changes
14-- nothing the second time.
15UPDATE access_tokens SET scopes = '' WHERE resources IS NOT NULL;
16UPDATE oauth_grants SET scopes = '' WHERE resources IS NOT NULL;
17UPDATE access_tokens SET resources = NULL WHERE resources IS NOT NULL;
18UPDATE oauth_grants SET resources = NULL WHERE resources IS NOT NULL;
19-- A code still waiting to be exchanged (they last five minutes) is dropped;
20-- the application asks again.
21DELETE FROM oauth_codes WHERE resources IS NOT NULL;