16 lines
563 B
SQL
16 lines
563 B
SQL
-- migrate:up
|
|
|
|
-- Short lived state of an in-flight OIDC authorization: the csrf token is the
|
|
-- key the provider hands back, `data` holds the pkce verifier and the nonce.
|
|
-- A row is consumed by the callback (deleted on read), so a state can never be
|
|
-- replayed, and `created_at` lets the stale ones be swept.
|
|
CREATE TABLE oidc_states (
|
|
key TEXT PRIMARY KEY,
|
|
data TEXT NOT NULL,
|
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
|
);
|
|
|
|
CREATE INDEX oidc_states_created_at_idx ON oidc_states (created_at);
|
|
|
|
-- migrate:down
|
|
DROP TABLE IF EXISTS oidc_states;
|