feat: backend support for creating and storing service accounts (#22698)

Add is_service_account column to users table with CHECK constraints
enforcing login_type='none' and empty email for service accounts.
Update user creation API to validate service account constraints.

Related to:
https://linear.app/codercom/issue/PLAT-27/feat-backend-support-for-creating-and-storing-service-accounts
This commit is contained in:
George K
2026-03-11 10:19:08 -07:00
committed by GitHub
parent e96cd5cbb2
commit e5c19d0af4
28 changed files with 522 additions and 87 deletions
+1
View File
@@ -160,6 +160,7 @@ var auditableResourcesTypes = map[any]map[string]Action{
"hashed_one_time_passcode": ActionIgnore,
"one_time_passcode_expires_at": ActionTrack,
"is_system": ActionTrack, // Should never change, but track it anyway.
"is_service_account": ActionTrack, // Should never change, but track it anyway.
},
&database.WorkspaceTable{}: {
"id": ActionTrack,
+2
View File
@@ -4577,6 +4577,7 @@ func TestWorkspacesSharedWith(t *testing.T) {
// Update a shared with user to have a name and avatar
_, err := db.UpdateUserProfile(dbauthz.AsSystemRestricted(ctx), database.UpdateUserProfileParams{
ID: sharedWithUser.ID,
Email: sharedWithUser.Email,
Username: sharedWithUser.Username,
Name: "Shared User Name",
AvatarURL: "/emojis/1fae1.png",
@@ -4664,6 +4665,7 @@ func TestWorkspacesSharedWith(t *testing.T) {
// Update a shared with user to have a name and avatar
_, err := db.UpdateUserProfile(dbauthz.AsSystemRestricted(ctx), database.UpdateUserProfileParams{
ID: sharedWithUser.ID,
Email: sharedWithUser.Email,
Username: sharedWithUser.Username,
Name: "Shared User Name",
AvatarURL: "/emojis/1fae1.png",