File
Blob: src/worker/db/d1/schema/patRepoGrants.ts
| 1 | import { sql } from "drizzle-orm"; |
| 2 | import { check, index, primaryKey, sqliteTable, text } from "drizzle-orm/sqlite-core"; |
| 3 | |
| 4 | import { type PatGrantLevel } from "./patNamespaceGrants"; |
| 5 | import { personalAccessTokens } from "./personalAccessTokens"; |
| 6 | import { repositories } from "./repositories"; |
| 7 | |
| 8 | // PAT scoped to a single repository. Reuses `PatGrantLevel` from the |
| 9 | // namespace grant module so both grant tables stay on the same canonical |
| 10 | // type and CHECK shape. |
| 11 | export const patRepoGrants = sqliteTable( |
| 12 | "pat_repo_grants", |
| 13 | { |
| 14 | patId: text("pat_id") |
| 15 | .notNull() |
| 16 | .references(() => personalAccessTokens.id, { onDelete: "cascade" }), |
| 17 | repoId: text("repo_id") |
| 18 | .notNull() |
| 19 | .references(() => repositories.id, { onDelete: "cascade" }), |
| 20 | level: text("level").$type<PatGrantLevel>().notNull(), |
| 21 | }, |
| 22 | (table) => [ |
| 23 | primaryKey({ columns: [table.patId, table.repoId] }), |
| 24 | index("idx_pat_repo_grants_repo").on(table.repoId), |
| 25 | check("chk_pat_repo_grants_level", sql`"level" IN ('pull','push')`), |
| 26 | ] |
| 27 | ); |
| 28 | |
| 29 | export type PatRepoGrantRow = typeof patRepoGrants.$inferSelect; |
| 30 | export type NewPatRepoGrantRow = typeof patRepoGrants.$inferInsert; |