Adds instance_role + reserved email/mfa_secret columns to admin_users, creates app_members for per-app role grants, and creates api_keys for bearer-token credentials. Schema snapshot re-blessed. Reserves invites and service_accounts shapes in a trailing comment block — both land in their own migrations when those flows ship. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
218 lines
8.5 KiB
Plaintext
218 lines
8.5 KiB
Plaintext
# Schema snapshot — generated by schema_snapshot test.
|
|
# Do not edit by hand. Run with BLESS=1 to regenerate.
|
|
|
|
## tables
|
|
|
|
table: admin_sessions
|
|
token_hash: text NOT NULL
|
|
user_id: uuid NOT NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
expires_at: timestamp with time zone NOT NULL
|
|
last_used_at: timestamp with time zone NOT NULL default=now()
|
|
|
|
table: admin_users
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
username: text NOT NULL
|
|
password_hash: text NOT NULL
|
|
is_active: boolean NOT NULL default=true
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
updated_at: timestamp with time zone NOT NULL default=now()
|
|
last_login_at: timestamp with time zone NULL
|
|
instance_role: text NOT NULL default='owner'::text
|
|
email: text NULL
|
|
mfa_secret: text NULL
|
|
|
|
table: api_keys
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
user_id: uuid NOT NULL
|
|
hash: text NOT NULL
|
|
prefix: text NOT NULL
|
|
name: text NOT NULL
|
|
scopes: ARRAY NOT NULL
|
|
app_id: uuid NULL
|
|
expires_at: timestamp with time zone NULL
|
|
last_used_at: timestamp with time zone NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
|
|
table: app_domains
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
app_id: uuid NOT NULL
|
|
pattern: text NOT NULL
|
|
shape: text NOT NULL
|
|
shape_key: text NOT NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
|
|
table: app_members
|
|
app_id: uuid NOT NULL
|
|
user_id: uuid NOT NULL
|
|
role: text NOT NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
|
|
table: app_slug_history
|
|
slug: text NOT NULL
|
|
current_app_id: uuid NOT NULL
|
|
retired_at: timestamp with time zone NOT NULL default=now()
|
|
|
|
table: apps
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
slug: text NOT NULL
|
|
name: text NOT NULL
|
|
description: text NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
updated_at: timestamp with time zone NOT NULL default=now()
|
|
|
|
table: execution_logs
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
script_id: uuid NOT NULL
|
|
request_id: uuid NOT NULL
|
|
request_path: text NULL
|
|
request_headers: jsonb NOT NULL default='{}'::jsonb
|
|
request_body: jsonb NULL
|
|
response_code: integer NULL
|
|
response_body: jsonb NULL
|
|
logs: jsonb NOT NULL default='[]'::jsonb
|
|
duration_ms: integer NOT NULL default=0
|
|
status: text NOT NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
app_id: uuid NOT NULL
|
|
|
|
table: routes
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
script_id: uuid NOT NULL
|
|
host_kind: text NOT NULL
|
|
host: text NOT NULL default=''::text
|
|
host_param_name: text NULL
|
|
path_kind: text NOT NULL
|
|
path: text NOT NULL
|
|
method: text NULL
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
app_id: uuid NOT NULL
|
|
|
|
table: scripts
|
|
id: uuid NOT NULL default=gen_random_uuid()
|
|
name: text NOT NULL
|
|
description: text NULL
|
|
version: integer NOT NULL default=1
|
|
source: text NOT NULL
|
|
timeout_seconds: integer NOT NULL default=30
|
|
memory_limit_mb: integer NOT NULL default=256
|
|
created_at: timestamp with time zone NOT NULL default=now()
|
|
updated_at: timestamp with time zone NOT NULL default=now()
|
|
sandbox: jsonb NOT NULL default='{}'::jsonb
|
|
app_id: uuid NOT NULL
|
|
|
|
## indexes
|
|
|
|
indexes on admin_sessions:
|
|
admin_sessions_expiry_idx: public.admin_sessions USING btree (expires_at)
|
|
admin_sessions_pkey: public.admin_sessions USING btree (token_hash)
|
|
admin_sessions_user_idx: public.admin_sessions USING btree (user_id)
|
|
|
|
indexes on admin_users:
|
|
admin_users_email_key: public.admin_users USING btree (email)
|
|
admin_users_instance_role_idx: public.admin_users USING btree (instance_role)
|
|
admin_users_pkey: public.admin_users USING btree (id)
|
|
admin_users_username_key: public.admin_users USING btree (username)
|
|
|
|
indexes on api_keys:
|
|
api_keys_pkey: public.api_keys USING btree (id)
|
|
api_keys_prefix_idx: public.api_keys USING btree (prefix)
|
|
api_keys_user_id_idx: public.api_keys USING btree (user_id)
|
|
|
|
indexes on app_domains:
|
|
app_domains_app_id_idx: public.app_domains USING btree (app_id)
|
|
app_domains_pkey: public.app_domains USING btree (id)
|
|
app_domains_shape_key_key: public.app_domains USING btree (shape_key)
|
|
|
|
indexes on app_members:
|
|
app_members_pkey: public.app_members USING btree (app_id, user_id)
|
|
app_members_user_id_idx: public.app_members USING btree (user_id)
|
|
|
|
indexes on app_slug_history:
|
|
app_slug_history_pkey: public.app_slug_history USING btree (slug)
|
|
|
|
indexes on apps:
|
|
apps_pkey: public.apps USING btree (id)
|
|
apps_slug_key: public.apps USING btree (slug)
|
|
|
|
indexes on execution_logs:
|
|
execution_logs_app_id_created_at_idx: public.execution_logs USING btree (app_id, created_at DESC)
|
|
execution_logs_pkey: public.execution_logs USING btree (id)
|
|
execution_logs_script_id_created_at_idx: public.execution_logs USING btree (script_id, created_at DESC)
|
|
|
|
indexes on routes:
|
|
routes_app_id_idx: public.routes USING btree (app_id)
|
|
routes_lookup_idx: public.routes USING btree (host_kind, host)
|
|
routes_pkey: public.routes USING btree (id)
|
|
routes_script_id_idx: public.routes USING btree (script_id)
|
|
routes_unique_binding_idx: public.routes USING btree (app_id, host_kind, host, path_kind, path, COALESCE(method, ''::text))
|
|
|
|
indexes on scripts:
|
|
scripts_app_id_idx: public.scripts USING btree (app_id)
|
|
scripts_name_uidx: public.scripts USING btree (app_id, lower(name))
|
|
scripts_pkey: public.scripts USING btree (id)
|
|
|
|
## constraints
|
|
|
|
constraints on admin_sessions:
|
|
[FOREIGN KEY] admin_sessions_user_id_fkey: FOREIGN KEY (user_id) REFERENCES admin_users(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] admin_sessions_pkey: PRIMARY KEY (token_hash)
|
|
|
|
constraints on admin_users:
|
|
[CHECK] admin_users_instance_role_check: CHECK ((instance_role = ANY (ARRAY['owner'::text, 'admin'::text, 'member'::text])))
|
|
[PRIMARY KEY] admin_users_pkey: PRIMARY KEY (id)
|
|
[UNIQUE] admin_users_email_key: UNIQUE (email)
|
|
[UNIQUE] admin_users_username_key: UNIQUE (username)
|
|
|
|
constraints on api_keys:
|
|
[FOREIGN KEY] api_keys_app_id_fkey: FOREIGN KEY (app_id) REFERENCES apps(id) ON DELETE CASCADE
|
|
[FOREIGN KEY] api_keys_user_id_fkey: FOREIGN KEY (user_id) REFERENCES admin_users(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] api_keys_pkey: PRIMARY KEY (id)
|
|
|
|
constraints on app_domains:
|
|
[CHECK] app_domains_shape_check: CHECK ((shape = ANY (ARRAY['exact'::text, 'wildcard'::text, 'parameterized'::text])))
|
|
[FOREIGN KEY] app_domains_app_id_fkey: FOREIGN KEY (app_id) REFERENCES apps(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] app_domains_pkey: PRIMARY KEY (id)
|
|
[UNIQUE] app_domains_shape_key_key: UNIQUE (shape_key)
|
|
|
|
constraints on app_members:
|
|
[CHECK] app_members_role_check: CHECK ((role = ANY (ARRAY['app_admin'::text, 'editor'::text, 'viewer'::text])))
|
|
[FOREIGN KEY] app_members_app_id_fkey: FOREIGN KEY (app_id) REFERENCES apps(id) ON DELETE CASCADE
|
|
[FOREIGN KEY] app_members_user_id_fkey: FOREIGN KEY (user_id) REFERENCES admin_users(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] app_members_pkey: PRIMARY KEY (app_id, user_id)
|
|
|
|
constraints on app_slug_history:
|
|
[FOREIGN KEY] app_slug_history_current_app_id_fkey: FOREIGN KEY (current_app_id) REFERENCES apps(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] app_slug_history_pkey: PRIMARY KEY (slug)
|
|
|
|
constraints on apps:
|
|
[PRIMARY KEY] apps_pkey: PRIMARY KEY (id)
|
|
[UNIQUE] apps_slug_key: UNIQUE (slug)
|
|
|
|
constraints on execution_logs:
|
|
[CHECK] execution_logs_status_check: CHECK ((status = ANY (ARRAY['success'::text, 'error'::text, 'timeout'::text, 'budget_exceeded'::text])))
|
|
[FOREIGN KEY] execution_logs_app_id_fk: FOREIGN KEY (app_id) REFERENCES apps(id) ON DELETE CASCADE
|
|
[FOREIGN KEY] execution_logs_script_id_fkey: FOREIGN KEY (script_id) REFERENCES scripts(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] execution_logs_pkey: PRIMARY KEY (id)
|
|
|
|
constraints on routes:
|
|
[CHECK] routes_host_kind_check: CHECK ((host_kind = ANY (ARRAY['any'::text, 'strict'::text, 'wildcard'::text])))
|
|
[CHECK] routes_path_kind_check: CHECK ((path_kind = ANY (ARRAY['exact'::text, 'prefix'::text, 'param'::text])))
|
|
[FOREIGN KEY] routes_app_id_fk: FOREIGN KEY (app_id) REFERENCES apps(id) ON DELETE CASCADE
|
|
[FOREIGN KEY] routes_script_id_fkey: FOREIGN KEY (script_id) REFERENCES scripts(id) ON DELETE CASCADE
|
|
[PRIMARY KEY] routes_pkey: PRIMARY KEY (id)
|
|
|
|
constraints on scripts:
|
|
[CHECK] scripts_memory_limit_mb_check: CHECK (((memory_limit_mb > 0) AND (memory_limit_mb <= 2048)))
|
|
[CHECK] scripts_timeout_seconds_check: CHECK (((timeout_seconds > 0) AND (timeout_seconds <= 300)))
|
|
[FOREIGN KEY] scripts_app_id_fk: FOREIGN KEY (app_id) REFERENCES apps(id) ON DELETE RESTRICT
|
|
[PRIMARY KEY] scripts_pkey: PRIMARY KEY (id)
|
|
|
|
## applied migrations
|
|
0001: init
|
|
0002: sandbox
|
|
0003: routes
|
|
0004: admin auth
|
|
0005: apps
|
|
0006: users authz
|