-- migrate:up -- Short lived state of an in-flight OIDC authorization: the csrf token is the -- key the provider hands back, `data` holds the pkce verifier and the nonce. -- A row is consumed by the callback (deleted on read), so a state can never be -- replayed, and `created_at` lets the stale ones be swept. CREATE TABLE oidc_states ( key TEXT PRIMARY KEY, data TEXT NOT NULL, created_at TIMESTAMPTZ NOT NULL DEFAULT now() ); CREATE INDEX oidc_states_created_at_idx ON oidc_states (created_at); -- migrate:down DROP TABLE IF EXISTS oidc_states;