1ba5738d52
- OAuth Callback to Use Gatehouse UI to login instead of Backend Served dull ui - Setup Autoregister of user + org, on oauth - Microsoft Oauth Support - OIDCRefreshToken.access_token_id had a narrow Column increased to VAR(255) and remove FK to sessions.id which had no use - client_id and client.id mismatch ,backup-code consumption
125 lines
7.0 KiB
Python
125 lines
7.0 KiB
Python
"""totp
|
|
|
|
Revision ID: d2fd4f159054
|
|
Revises: 004
|
|
Create Date: 2026-02-23 13:21:54.136904
|
|
|
|
"""
|
|
from alembic import op
|
|
import sqlalchemy as sa
|
|
|
|
|
|
# revision identifiers, used by Alembic.
|
|
revision = 'd2fd4f159054'
|
|
down_revision = '004'
|
|
branch_labels = None
|
|
depends_on = None
|
|
|
|
|
|
def upgrade():
|
|
# ### commands auto generated by Alembic - please adjust! ###
|
|
op.create_table('application_provider_configs',
|
|
sa.Column('provider_type', sa.String(length=50), nullable=False),
|
|
sa.Column('client_id', sa.String(length=255), nullable=False),
|
|
sa.Column('client_secret_encrypted', sa.String(length=512), nullable=True),
|
|
sa.Column('is_enabled', sa.Boolean(), nullable=False),
|
|
sa.Column('default_redirect_url', sa.String(length=2048), nullable=True),
|
|
sa.Column('additional_config', sa.JSON(), nullable=True),
|
|
sa.Column('id', sa.String(length=36), nullable=False),
|
|
sa.Column('created_at', sa.DateTime(), nullable=False),
|
|
sa.Column('updated_at', sa.DateTime(), nullable=False),
|
|
sa.Column('deleted_at', sa.DateTime(), nullable=True),
|
|
sa.PrimaryKeyConstraint('id'),
|
|
sa.UniqueConstraint('id')
|
|
)
|
|
op.create_index(op.f('ix_application_provider_configs_provider_type'), 'application_provider_configs', ['provider_type'], unique=True)
|
|
op.create_table('external_provider_configs',
|
|
sa.Column('organization_id', sa.String(length=36), nullable=False),
|
|
sa.Column('provider_type', sa.String(length=50), nullable=False),
|
|
sa.Column('client_id', sa.String(length=255), nullable=False),
|
|
sa.Column('client_secret_encrypted', sa.String(length=512), nullable=True),
|
|
sa.Column('auth_url', sa.String(length=2048), nullable=False),
|
|
sa.Column('token_url', sa.String(length=2048), nullable=False),
|
|
sa.Column('userinfo_url', sa.String(length=2048), nullable=True),
|
|
sa.Column('jwks_url', sa.String(length=2048), nullable=True),
|
|
sa.Column('scopes', sa.JSON(), nullable=False),
|
|
sa.Column('redirect_uris', sa.JSON(), nullable=False),
|
|
sa.Column('settings', sa.JSON(), nullable=True),
|
|
sa.Column('is_active', sa.Boolean(), nullable=False),
|
|
sa.Column('id', sa.String(length=36), nullable=False),
|
|
sa.Column('created_at', sa.DateTime(), nullable=False),
|
|
sa.Column('updated_at', sa.DateTime(), nullable=False),
|
|
sa.Column('deleted_at', sa.DateTime(), nullable=True),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.PrimaryKeyConstraint('id'),
|
|
sa.UniqueConstraint('id'),
|
|
sa.UniqueConstraint('organization_id', 'provider_type', name='uix_org_provider_type')
|
|
)
|
|
op.create_index('idx_provider_config_org', 'external_provider_configs', ['organization_id', 'provider_type'], unique=False)
|
|
op.create_index(op.f('ix_external_provider_configs_organization_id'), 'external_provider_configs', ['organization_id'], unique=False)
|
|
op.create_index(op.f('ix_external_provider_configs_provider_type'), 'external_provider_configs', ['provider_type'], unique=False)
|
|
op.create_table('oauth_states',
|
|
sa.Column('state', sa.String(length=64), nullable=False),
|
|
sa.Column('flow_type', sa.String(length=50), nullable=False),
|
|
sa.Column('provider_type', sa.String(length=50), nullable=False),
|
|
sa.Column('user_id', sa.String(length=36), nullable=True),
|
|
sa.Column('organization_id', sa.String(length=36), nullable=True),
|
|
sa.Column('nonce', sa.String(length=128), nullable=True),
|
|
sa.Column('code_verifier', sa.String(length=128), nullable=True),
|
|
sa.Column('code_challenge', sa.String(length=128), nullable=True),
|
|
sa.Column('redirect_uri', sa.String(length=2048), nullable=True),
|
|
sa.Column('return_url', sa.String(length=2048), nullable=True),
|
|
sa.Column('extra_data', sa.JSON(), nullable=True),
|
|
sa.Column('expires_at', sa.DateTime(), nullable=False),
|
|
sa.Column('used', sa.Boolean(), nullable=False),
|
|
sa.Column('id', sa.String(length=36), nullable=False),
|
|
sa.Column('created_at', sa.DateTime(), nullable=False),
|
|
sa.Column('updated_at', sa.DateTime(), nullable=False),
|
|
sa.Column('deleted_at', sa.DateTime(), nullable=True),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.ForeignKeyConstraint(['user_id'], ['users.id'], ),
|
|
sa.PrimaryKeyConstraint('id'),
|
|
sa.UniqueConstraint('id')
|
|
)
|
|
op.create_index(op.f('ix_oauth_states_expires_at'), 'oauth_states', ['expires_at'], unique=False)
|
|
op.create_index(op.f('ix_oauth_states_organization_id'), 'oauth_states', ['organization_id'], unique=False)
|
|
op.create_index(op.f('ix_oauth_states_state'), 'oauth_states', ['state'], unique=True)
|
|
op.create_table('organization_provider_overrides',
|
|
sa.Column('organization_id', sa.String(length=36), nullable=False),
|
|
sa.Column('provider_type', sa.String(length=50), nullable=False),
|
|
sa.Column('client_id', sa.String(length=255), nullable=True),
|
|
sa.Column('client_secret_encrypted', sa.String(length=512), nullable=True),
|
|
sa.Column('is_enabled', sa.Boolean(), nullable=False),
|
|
sa.Column('redirect_url_override', sa.String(length=2048), nullable=True),
|
|
sa.Column('additional_config', sa.JSON(), nullable=True),
|
|
sa.Column('id', sa.String(length=36), nullable=False),
|
|
sa.Column('created_at', sa.DateTime(), nullable=False),
|
|
sa.Column('updated_at', sa.DateTime(), nullable=False),
|
|
sa.Column('deleted_at', sa.DateTime(), nullable=True),
|
|
sa.ForeignKeyConstraint(['organization_id'], ['organizations.id'], ),
|
|
sa.PrimaryKeyConstraint('id'),
|
|
sa.UniqueConstraint('id'),
|
|
sa.UniqueConstraint('organization_id', 'provider_type', name='uix_org_provider_override_type')
|
|
)
|
|
op.create_index(op.f('ix_organization_provider_overrides_organization_id'), 'organization_provider_overrides', ['organization_id'], unique=False)
|
|
op.create_index(op.f('ix_organization_provider_overrides_provider_type'), 'organization_provider_overrides', ['provider_type'], unique=False)
|
|
# ### end Alembic commands ###
|
|
|
|
|
|
def downgrade():
|
|
# ### commands auto generated by Alembic - please adjust! ###
|
|
op.drop_index(op.f('ix_organization_provider_overrides_provider_type'), table_name='organization_provider_overrides')
|
|
op.drop_index(op.f('ix_organization_provider_overrides_organization_id'), table_name='organization_provider_overrides')
|
|
op.drop_table('organization_provider_overrides')
|
|
op.drop_index(op.f('ix_oauth_states_state'), table_name='oauth_states')
|
|
op.drop_index(op.f('ix_oauth_states_organization_id'), table_name='oauth_states')
|
|
op.drop_index(op.f('ix_oauth_states_expires_at'), table_name='oauth_states')
|
|
op.drop_table('oauth_states')
|
|
op.drop_index(op.f('ix_external_provider_configs_provider_type'), table_name='external_provider_configs')
|
|
op.drop_index(op.f('ix_external_provider_configs_organization_id'), table_name='external_provider_configs')
|
|
op.drop_index('idx_provider_config_org', table_name='external_provider_configs')
|
|
op.drop_table('external_provider_configs')
|
|
op.drop_index(op.f('ix_application_provider_configs_provider_type'), table_name='application_provider_configs')
|
|
op.drop_table('application_provider_configs')
|
|
# ### end Alembic commands ###
|