mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-25 14:53:34 +00:00
The invitation flow is redundant — admin create user already generates a token and shows a login link. Invitations add complexity without value until email integration exists. Removed: - InvitationRecord struct and 4 UserStore trait methods - invitations table from V14 migration (postgres + both libsql schemas) - PostgreSQL Store methods (create/get/accept/list invitations) - libSQL UserStore invitation methods + row_to_invitation helper - invitations.rs handler file (212 lines) - /api/invitations routes (create, list, accept) - test_invitation_lifecycle test Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
32 lines
1.6 KiB
SQL
32 lines
1.6 KiB
SQL
-- User management tables for multi-tenant deployments.
|
|
--
|
|
-- Replaces the static GATEWAY_USER_TOKENS env var with DB-backed
|
|
-- user registration, API token management, and invitation flow.
|
|
|
|
CREATE TABLE users (
|
|
id TEXT PRIMARY KEY, -- matches existing user_id pattern (string, not UUID)
|
|
email TEXT UNIQUE, -- nullable for token-only users
|
|
display_name TEXT NOT NULL,
|
|
status TEXT NOT NULL DEFAULT 'active', -- active | suspended | deactivated
|
|
role TEXT NOT NULL DEFAULT 'member', -- admin | member
|
|
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
|
|
updated_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
|
|
last_login_at TIMESTAMPTZ,
|
|
created_by TEXT REFERENCES users(id), -- who invited this user (nullable for bootstrap)
|
|
metadata JSONB NOT NULL DEFAULT '{}' -- extensible profile data
|
|
);
|
|
|
|
CREATE TABLE api_tokens (
|
|
id UUID PRIMARY KEY,
|
|
user_id TEXT NOT NULL REFERENCES users(id) ON DELETE CASCADE,
|
|
token_hash BYTEA NOT NULL, -- SHA-256 hash (never store plaintext)
|
|
token_prefix TEXT NOT NULL, -- first 8 hex chars for display
|
|
name TEXT NOT NULL, -- human label ("my-laptop", "ci-bot")
|
|
expires_at TIMESTAMPTZ, -- nullable = never expires
|
|
last_used_at TIMESTAMPTZ,
|
|
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
|
|
revoked_at TIMESTAMPTZ -- soft-revoke: set this instead of deleting
|
|
);
|
|
CREATE INDEX idx_api_tokens_user ON api_tokens(user_id);
|
|
CREATE INDEX idx_api_tokens_hash ON api_tokens(token_hash);
|