All checks were successful
Build and Deploy / build-and-deploy (push) Successful in 1m5s
Combines shared, blog, market, cart, events, federation, and account into a single repository. Eliminates submodule sync, sibling model copying at build time, and per-app CI orchestration. Changes: - Remove per-app .git, .gitmodules, .gitea, submodule shared/ dirs - Remove stale sibling model copies from each app - Update all 6 Dockerfiles for monorepo build context (root = .) - Add build directives to docker-compose.yml - Add single .gitea/workflows/ci.yml with change detection - Add .dockerignore for monorepo build context - Create __init__.py for federation and account (cross-app imports)
33 lines
1.6 KiB
Python
33 lines
1.6 KiB
Python
from __future__ import annotations
|
|
from datetime import datetime
|
|
from sqlalchemy import String, Integer, DateTime, ForeignKey, func, Index
|
|
from sqlalchemy.orm import Mapped, mapped_column, relationship
|
|
from shared.db.base import Base
|
|
|
|
|
|
class OAuthGrant(Base):
|
|
"""Long-lived grant tracking each client-app session authorization.
|
|
|
|
Created when the OAuth authorize endpoint issues a code. Tied to the
|
|
account session that issued it (``issuer_session``) so that logging out
|
|
on one device revokes only that device's grants.
|
|
"""
|
|
__tablename__ = "oauth_grants"
|
|
|
|
id: Mapped[int] = mapped_column(Integer, primary_key=True, autoincrement=True)
|
|
token: Mapped[str] = mapped_column(String(128), unique=True, nullable=False)
|
|
user_id: Mapped[int] = mapped_column(ForeignKey("users.id", ondelete="CASCADE"), nullable=False, index=True)
|
|
client_id: Mapped[str] = mapped_column(String(64), nullable=False)
|
|
issuer_session: Mapped[str] = mapped_column(String(128), nullable=False, index=True)
|
|
device_id: Mapped[str | None] = mapped_column(String(128), nullable=True, index=True)
|
|
created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), nullable=False, server_default=func.now())
|
|
revoked_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True), nullable=True)
|
|
|
|
user = relationship("User", backref="oauth_grants")
|
|
|
|
__table_args__ = (
|
|
Index("ix_oauth_grant_token", "token", unique=True),
|
|
Index("ix_oauth_grant_issuer", "issuer_session"),
|
|
Index("ix_oauth_grant_device", "device_id", "client_id"),
|
|
)
|