mirror of
https://github.com/saltbo/zpan.git
synced 2026-08-28 15:51:29 +08:00
d22227ed2f
* feat: add delegated agent oauth provider Agent-Profile: https://agent-kanban.dev/agents/e0a1ce35687e48ef * test(auth): cover delegated OAuth configuration * fix(auth): route OAuth metadata through worker * fix(auth): advertise canonical OAuth issuer * test: cover agent oauth provider integration Agent-Profile: https://agent-kanban.dev/agents/e0a1ce35687e48ef * test(auth): cover managed OAuth consent flow --------- Co-authored-by: Ravi Shah <ravi-shah@mails.agent-kanban.dev> Co-authored-by: saltbo <saltbo@foxmail.com>
411 lines
15 KiB
TypeScript
411 lines
15 KiB
TypeScript
import { relations, sql } from 'drizzle-orm'
|
|
import { index, integer, sqliteTable, text } from 'drizzle-orm/sqlite-core'
|
|
|
|
export const user = sqliteTable(
|
|
'user',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
name: text('name').notNull(),
|
|
email: text('email').notNull().unique(),
|
|
emailVerified: integer('email_verified', { mode: 'boolean' }).default(false).notNull(),
|
|
image: text('image'),
|
|
role: text('role'),
|
|
banned: integer('banned', { mode: 'boolean' }).default(false),
|
|
banReason: text('ban_reason'),
|
|
banExpires: integer('ban_expires', { mode: 'timestamp_ms' }),
|
|
username: text('username').unique(),
|
|
displayUsername: text('display_username'),
|
|
lastActiveAt: integer('last_active_at', { mode: 'timestamp_ms' }),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
},
|
|
(table) => [index('user_created_idx').on(table.createdAt), index('user_lastActiveAt_idx').on(table.lastActiveAt)],
|
|
)
|
|
|
|
export const session = sqliteTable(
|
|
'session',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }).notNull(),
|
|
token: text('token').notNull().unique(),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
ipAddress: text('ip_address'),
|
|
userAgent: text('user_agent'),
|
|
userId: text('user_id')
|
|
.notNull()
|
|
.references(() => user.id, { onDelete: 'cascade' }),
|
|
impersonatedBy: text('impersonated_by'),
|
|
activeOrganizationId: text('active_organization_id'),
|
|
},
|
|
(table) => [index('session_userId_idx').on(table.userId), index('session_created_idx').on(table.createdAt)],
|
|
)
|
|
|
|
export const account = sqliteTable(
|
|
'account',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
accountId: text('account_id').notNull(),
|
|
providerId: text('provider_id').notNull(),
|
|
userId: text('user_id')
|
|
.notNull()
|
|
.references(() => user.id, { onDelete: 'cascade' }),
|
|
accessToken: text('access_token'),
|
|
refreshToken: text('refresh_token'),
|
|
idToken: text('id_token'),
|
|
accessTokenExpiresAt: integer('access_token_expires_at', {
|
|
mode: 'timestamp_ms',
|
|
}),
|
|
refreshTokenExpiresAt: integer('refresh_token_expires_at', {
|
|
mode: 'timestamp_ms',
|
|
}),
|
|
scope: text('scope'),
|
|
password: text('password'),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
},
|
|
(table) => [index('account_userId_idx').on(table.userId)],
|
|
)
|
|
|
|
export const verification = sqliteTable(
|
|
'verification',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
identifier: text('identifier').notNull(),
|
|
value: text('value').notNull(),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }).notNull(),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
},
|
|
(table) => [index('verification_identifier_idx').on(table.identifier)],
|
|
)
|
|
|
|
export const organization = sqliteTable('organization', {
|
|
id: text('id').primaryKey(),
|
|
name: text('name').notNull(),
|
|
slug: text('slug').notNull().unique(),
|
|
logo: text('logo'),
|
|
metadata: text('metadata'),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.$onUpdate(() => /* @__PURE__ */ new Date()),
|
|
})
|
|
|
|
export const member = sqliteTable(
|
|
'member',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
organizationId: text('organization_id')
|
|
.notNull()
|
|
.references(() => organization.id, { onDelete: 'cascade' }),
|
|
userId: text('user_id')
|
|
.notNull()
|
|
.references(() => user.id, { onDelete: 'cascade' }),
|
|
role: text('role').notNull().default('member'),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
},
|
|
(table) => [index('member_organizationId_idx').on(table.organizationId), index('member_userId_idx').on(table.userId)],
|
|
)
|
|
|
|
export const invitation = sqliteTable(
|
|
'invitation',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
organizationId: text('organization_id')
|
|
.notNull()
|
|
.references(() => organization.id, { onDelete: 'cascade' }),
|
|
email: text('email').notNull(),
|
|
role: text('role').notNull(),
|
|
status: text('status').notNull().default('pending'),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
inviterId: text('inviter_id')
|
|
.notNull()
|
|
.references(() => user.id, { onDelete: 'cascade' }),
|
|
},
|
|
(table) => [
|
|
index('invitation_organizationId_idx').on(table.organizationId),
|
|
index('invitation_email_idx').on(table.email),
|
|
],
|
|
)
|
|
|
|
// apikey table — managed by @better-auth/api-key plugin
|
|
export const apikey = sqliteTable(
|
|
'apikey',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
configId: text('config_id').notNull().default('default'),
|
|
name: text('name'),
|
|
start: text('start'),
|
|
referenceId: text('reference_id').notNull(), // userId; workspace scope lives in metadata
|
|
prefix: text('prefix'),
|
|
key: text('key').notNull(),
|
|
refillInterval: integer('refill_interval'),
|
|
refillAmount: integer('refill_amount'),
|
|
lastRefillAt: integer('last_refill_at', { mode: 'timestamp_ms' }),
|
|
enabled: integer('enabled', { mode: 'boolean' }).notNull().default(true),
|
|
rateLimitEnabled: integer('rate_limit_enabled', { mode: 'boolean' }).notNull().default(true),
|
|
rateLimitTimeWindow: integer('rate_limit_time_window'),
|
|
rateLimitMax: integer('rate_limit_max'),
|
|
requestCount: integer('request_count').notNull().default(0),
|
|
remaining: integer('remaining'),
|
|
lastRequest: integer('last_request', { mode: 'timestamp_ms' }),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' }).notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' }).notNull(),
|
|
permissions: text('permissions'), // JSON-serialized Statements
|
|
metadata: text('metadata'), // JSON string
|
|
},
|
|
(table) => [
|
|
index('apikey_config_id_idx').on(table.configId),
|
|
index('apikey_reference_id_idx').on(table.referenceId),
|
|
index('apikey_key_idx').on(table.key),
|
|
],
|
|
)
|
|
|
|
export const deviceCode = sqliteTable(
|
|
'deviceCode',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
deviceCode: text('device_code').notNull(),
|
|
userCode: text('user_code').notNull(),
|
|
userId: text('user_id'),
|
|
clientId: text('client_id'),
|
|
scope: text('scope'),
|
|
status: text('status').notNull(),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }).notNull(),
|
|
lastPolledAt: integer('last_polled_at', { mode: 'timestamp_ms' }),
|
|
pollingInterval: integer('polling_interval'),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
},
|
|
(table) => [
|
|
index('deviceCode_device_code_idx').on(table.deviceCode),
|
|
index('deviceCode_user_code_idx').on(table.userCode),
|
|
index('deviceCode_status_idx').on(table.status),
|
|
],
|
|
)
|
|
|
|
export const oauthClient = sqliteTable(
|
|
'oauthClient',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
clientId: text('client_id').notNull().unique(),
|
|
clientSecret: text('client_secret'),
|
|
disabled: integer('disabled', { mode: 'boolean' }).default(false),
|
|
skipConsent: integer('skip_consent', { mode: 'boolean' }),
|
|
enableEndSession: integer('enable_end_session', { mode: 'boolean' }),
|
|
subjectType: text('subject_type'),
|
|
scopes: text('scopes'), // JSON-serialized string[]
|
|
userId: text('user_id').references(() => user.id, { onDelete: 'cascade' }),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
name: text('name'),
|
|
uri: text('uri'),
|
|
icon: text('icon'),
|
|
contacts: text('contacts'), // JSON-serialized string[]
|
|
tos: text('tos'),
|
|
policy: text('policy'),
|
|
softwareId: text('software_id'),
|
|
softwareVersion: text('software_version'),
|
|
softwareStatement: text('software_statement'),
|
|
redirectUris: text('redirect_uris').notNull(), // JSON-serialized string[]
|
|
postLogoutRedirectUris: text('post_logout_redirect_uris'), // JSON-serialized string[]
|
|
tokenEndpointAuthMethod: text('token_endpoint_auth_method'),
|
|
grantTypes: text('grant_types'), // JSON-serialized string[]
|
|
responseTypes: text('response_types'), // JSON-serialized string[]
|
|
public: integer('public', { mode: 'boolean' }),
|
|
type: text('type'),
|
|
requirePKCE: integer('require_pkce', { mode: 'boolean' }),
|
|
referenceId: text('reference_id'),
|
|
metadata: text('metadata'),
|
|
},
|
|
(table) => [index('oauthClient_client_id_idx').on(table.clientId), index('oauthClient_user_id_idx').on(table.userId)],
|
|
)
|
|
|
|
export const oauthRefreshToken = sqliteTable(
|
|
'oauthRefreshToken',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
token: text('token').notNull().unique(),
|
|
clientId: text('client_id')
|
|
.notNull()
|
|
.references(() => oauthClient.clientId, { onDelete: 'cascade' }),
|
|
sessionId: text('session_id').references(() => session.id, { onDelete: 'set null' }),
|
|
userId: text('user_id')
|
|
.notNull()
|
|
.references(() => user.id, { onDelete: 'cascade' }),
|
|
referenceId: text('reference_id'),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }).notNull(),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
revoked: integer('revoked', { mode: 'timestamp_ms' }),
|
|
authTime: integer('auth_time', { mode: 'timestamp_ms' }),
|
|
scopes: text('scopes').notNull(), // JSON-serialized string[]
|
|
},
|
|
(table) => [
|
|
index('oauthRefreshToken_client_id_idx').on(table.clientId),
|
|
index('oauthRefreshToken_session_id_idx').on(table.sessionId),
|
|
index('oauthRefreshToken_user_id_idx').on(table.userId),
|
|
index('oauthRefreshToken_token_idx').on(table.token),
|
|
],
|
|
)
|
|
|
|
export const oauthAccessToken = sqliteTable(
|
|
'oauthAccessToken',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
token: text('token').notNull().unique(),
|
|
clientId: text('client_id')
|
|
.notNull()
|
|
.references(() => oauthClient.clientId, { onDelete: 'cascade' }),
|
|
sessionId: text('session_id').references(() => session.id, { onDelete: 'set null' }),
|
|
userId: text('user_id').references(() => user.id, { onDelete: 'cascade' }),
|
|
referenceId: text('reference_id'),
|
|
refreshId: text('refresh_id').references(() => oauthRefreshToken.id, { onDelete: 'cascade' }),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }).notNull(),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
scopes: text('scopes').notNull(), // JSON-serialized string[]
|
|
},
|
|
(table) => [
|
|
index('oauthAccessToken_client_id_idx').on(table.clientId),
|
|
index('oauthAccessToken_session_id_idx').on(table.sessionId),
|
|
index('oauthAccessToken_user_id_idx').on(table.userId),
|
|
index('oauthAccessToken_refresh_id_idx').on(table.refreshId),
|
|
index('oauthAccessToken_token_idx').on(table.token),
|
|
],
|
|
)
|
|
|
|
export const oauthConsent = sqliteTable(
|
|
'oauthConsent',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
clientId: text('client_id')
|
|
.notNull()
|
|
.references(() => oauthClient.clientId, { onDelete: 'cascade' }),
|
|
userId: text('user_id').references(() => user.id, { onDelete: 'cascade' }),
|
|
referenceId: text('reference_id'),
|
|
scopes: text('scopes').notNull(), // JSON-serialized string[]
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
updatedAt: integer('updated_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.$onUpdate(() => /* @__PURE__ */ new Date())
|
|
.notNull(),
|
|
},
|
|
(table) => [
|
|
index('oauthConsent_client_id_idx').on(table.clientId),
|
|
index('oauthConsent_user_id_idx').on(table.userId),
|
|
],
|
|
)
|
|
|
|
export const downloaderBootstrapCredential = sqliteTable(
|
|
'downloader_bootstrap_credentials',
|
|
{
|
|
id: text('id').primaryKey(),
|
|
tokenHash: text('token_hash').notNull().unique(),
|
|
userId: text('user_id')
|
|
.notNull()
|
|
.references(() => user.id, { onDelete: 'cascade' }),
|
|
deviceCode: text('device_code').notNull(),
|
|
clientId: text('client_id').notNull(),
|
|
scope: text('scope').notNull(),
|
|
expiresAt: integer('expires_at', { mode: 'timestamp_ms' }).notNull(),
|
|
consumedAt: integer('consumed_at', { mode: 'timestamp_ms' }),
|
|
createdAt: integer('created_at', { mode: 'timestamp_ms' })
|
|
.default(sql`(cast(unixepoch('subsecond') * 1000 as integer))`)
|
|
.notNull(),
|
|
},
|
|
(table) => [
|
|
index('downloader_bootstrap_token_hash_idx').on(table.tokenHash),
|
|
index('downloader_bootstrap_user_idx').on(table.userId),
|
|
index('downloader_bootstrap_consumed_idx').on(table.consumedAt),
|
|
],
|
|
)
|
|
|
|
export const userRelations = relations(user, ({ many }) => ({
|
|
sessions: many(session),
|
|
accounts: many(account),
|
|
members: many(member),
|
|
}))
|
|
|
|
export const sessionRelations = relations(session, ({ one }) => ({
|
|
user: one(user, {
|
|
fields: [session.userId],
|
|
references: [user.id],
|
|
}),
|
|
}))
|
|
|
|
export const accountRelations = relations(account, ({ one }) => ({
|
|
user: one(user, {
|
|
fields: [account.userId],
|
|
references: [user.id],
|
|
}),
|
|
}))
|
|
|
|
export const organizationRelations = relations(organization, ({ many }) => ({
|
|
members: many(member),
|
|
invitations: many(invitation),
|
|
}))
|
|
|
|
export const memberRelations = relations(member, ({ one }) => ({
|
|
organization: one(organization, {
|
|
fields: [member.organizationId],
|
|
references: [organization.id],
|
|
}),
|
|
user: one(user, {
|
|
fields: [member.userId],
|
|
references: [user.id],
|
|
}),
|
|
}))
|
|
|
|
export const invitationRelations = relations(invitation, ({ one }) => ({
|
|
organization: one(organization, {
|
|
fields: [invitation.organizationId],
|
|
references: [organization.id],
|
|
}),
|
|
inviter: one(user, {
|
|
fields: [invitation.inviterId],
|
|
references: [user.id],
|
|
}),
|
|
}))
|