Documentation
¶
Index ¶
- Constants
- func ValidSchemaName(s string) bool
- type APIKeyByLookupIDRow
- type APIKeyForRevokeParams
- type APIKeyForRevokeRow
- type APIKeyInsertParams
- type APIKeyInsertRow
- type APIKeyRoleCountsRow
- type APIKeysByGroupParams
- type APIKeysByGroupRow
- type APIKeysDeleteExpiredBatchParams
- type AccountDeletion
- type AccountDeletionDeliveryEarlierPendingParams
- type AccountDeletionDeliveryInsertParams
- type AccountDeletionDeliveryRow
- type AccountDeletionInsertParams
- type AccountDeletionPurgeNowRow
- type AccountDeletionPurgeWindowParams
- type AccountDeletionPurgeWindowRow
- type AccountDeletionRecoverableParams
- type AccountDeletionSetDeletedByParams
- type AccountDeletionsDeleteTerminalBatchParams
- type AccountDeliveryFleetInsertParams
- type AccountDeliveryFleetSetEventsParams
- type AccountDeliveryFleetSetSchemaParams
- type AccountEvent
- type AccountEventEarlierPendingParams
- type AccountEventEarlierPendingRow
- type AccountEventFleetsForShareRow
- type AccountEventInsertParams
- type AccountEventRetryParams
- type AccountInviteByCodeForUpdateParams
- type AccountInviteByCodeForUpdateRow
- type AccountInviteConsumeParams
- type AccountInviteForRevokeParams
- type AccountInviteForRevokeRow
- type AccountInviteForUpdateParams
- type AccountInviteForUpdateRow
- type AccountInviteInsertParams
- type AccountInviteInsertRow
- type AccountInvitesDeleteExpiredBatchParams
- type AuthorityAPIKeyRoleRow
- type AuthorityApplicationOwnsGroupParams
- type AuthorityApplicationOwnsGroupRow
- type AuthorityUncoveredCredentialsParams
- type AuthorityUncoveredCredentialsRow
- type AuthorityUserGroupsParams
- type BootstrapAccountByCanonicalNameForUpdateRow
- type BootstrapAccountByEmailForUpdateRow
- type BootstrapAccountByIDForUpdateRow
- type BootstrapAccountByPhoneForUpdateRow
- type BootstrapApplyStateRow
- type ContactStateForUpdateRow
- type ContactStateRow
- type CredentialSweepFleetsForShareRow
- type DBTX
- type DeviceKeyEnrollUserInsertParams
- type DeviceKeyInsertParams
- type DeviceKeyIsActiveForUpdateParams
- type DeviceKeyIsActiveParams
- type DeviceKeyRevokeParams
- type DeviceKeyTouchParams
- type DeviceKeysRevokeAllExceptParams
- type EphemeralCompareAndConsumeParams
- type EphemeralIncrParams
- type EphemeralSetParams
- type GroupApplicationAssignmentsForGroupsParams
- type GroupApplicationAssignmentsForGroupsRow
- type GroupApplicationRoleDeleteParams
- type GroupApplicationRoleDeleteRow
- type GroupApplicationRoleNameParams
- type GroupApplicationRoleUpsertParams
- type GroupHasOtherUsableOwnerParams
- type GroupMembersPageParams
- type GroupMembersPageRow
- type GroupRolesForSubjectsParams
- type GroupRolesForSubjectsRow
- type GroupUserAssignmentsForGroupsParams
- type GroupUserAssignmentsForGroupsRow
- type GroupUserHasRoleParams
- type GroupUserRoleCountsRow
- type GroupUserRoleDeleteParams
- type GroupUserRoleDeleteRow
- type GroupUserRoleNameParams
- type GroupUserRoleUpsertParams
- type GroupUserRolesForUsersParams
- type GroupUserRolesForUsersRow
- type GroupsOfApplicationPageParams
- type GroupsOfApplicationPageRow
- type GroupsOfUserPageParams
- type GroupsOfUserPageRow
- type IdentityPublicUsersByIDsRow
- type ImportHeldProvidersParams
- type ImportHeldProvidersRow
- type ImportHitsByEmailRow
- type ImportHitsByIDRow
- type ImportHitsByNameParams
- type ImportHitsByNameRow
- type ImportHitsByPhoneRow
- type ImportInsertPasswordsParams
- type ImportInsertProvidersParams
- type ImportMergePasswordParams
- type ImportMergeUserParams
- type ImportReleaseAliasesParams
- type ImportSetBannedByParams
- type InvitationsByGroupParams
- type InvitationsByGroupRow
- type InviteLinkByCodeForUpdateParams
- type InviteLinkByCodeForUpdateRow
- type InviteLinkForRevokeParams
- type InviteLinkForRevokeRow
- type InviteLinkInsertParams
- type InviteLinkInsertRow
- type InviteLinksDeleteExpiredBatchParams
- type MFAConsumeBackupCodeParams
- type MFAConsumeFactorTOTPStepParams
- type MFADeleteFactorParams
- type MFAInsertFactorParams
- type MFASetBackupCodesParams
- type MFASetDefaultFactorParams
- type MFASetEmailFactorAddressParams
- type MFAUpsertSettingsParams
- type MfaFactor
- type MfaSetting
- type NameClaimAliasesByUserParams
- type NameClaimAliasesByUserRow
- type NameClaimCanonicalParams
- type NameClaimDeleteOwnedParams
- type NameClaimRetireParams
- type NameClaimTakenParams
- type PasskeyDeleteParams
- type PasskeyExistsForRPParams
- type PasskeyHandleUpsertParams
- type PasskeyInsertParams
- type PasskeyLiveForUpdateParams
- type PasskeyRecordUseParams
- type PasskeyRenameParams
- type PasskeysByUserParams
- type PermissionGroup
- type PermissionGroupInsertWithIDParams
- type PermissionGroupSoftDeleteParams
- type PermissionGroupsPageParams
- type ProviderLinkByIssuerAnyParams
- type ProviderLinkByIssuerAnyRow
- type ProviderLinkByIssuerParams
- type ProviderLinkByIssuerRow
- type Queries
- func (q *Queries) APIKeyByLookupID(ctx context.Context, keyID string) (APIKeyByLookupIDRow, error)
- func (q *Queries) APIKeyForRevoke(ctx context.Context, arg APIKeyForRevokeParams) (APIKeyForRevokeRow, error)
- func (q *Queries) APIKeyInsert(ctx context.Context, arg APIKeyInsertParams) (APIKeyInsertRow, error)
- func (q *Queries) APIKeyRetire(ctx context.Context, id string) error
- func (q *Queries) APIKeyRoleCounts(ctx context.Context, issuer string) ([]APIKeyRoleCountsRow, error)
- func (q *Queries) APIKeyTouch(ctx context.Context, id string) error
- func (q *Queries) APIKeysByGroup(ctx context.Context, arg APIKeysByGroupParams) ([]APIKeysByGroupRow, error)
- func (q *Queries) APIKeysDeleteExpiredBatch(ctx context.Context, arg APIKeysDeleteExpiredBatchParams) error
- func (q *Queries) APIKeysRevokeCreatedBy(ctx context.Context, userID string) error
- func (q *Queries) AccountDeletionDelivery(ctx context.Context, id int64) (AccountDeletionDeliveryRow, error)
- func (q *Queries) AccountDeletionDeliveryComplete(ctx context.Context, id int64) (int64, error)
- func (q *Queries) AccountDeletionDeliveryEarlierPending(ctx context.Context, arg AccountDeletionDeliveryEarlierPendingParams) (bool, error)
- func (q *Queries) AccountDeletionDeliveryInsert(ctx context.Context, arg AccountDeletionDeliveryInsertParams) (int64, error)
- func (q *Queries) AccountDeletionDeliveryUser(ctx context.Context, id int64) (string, error)
- func (q *Queries) AccountDeletionForUpdate(ctx context.Context, id string) (AccountDeletion, error)
- func (q *Queries) AccountDeletionHardDeliveriesPending(ctx context.Context, deletionID string) (bool, error)
- func (q *Queries) AccountDeletionInsert(ctx context.Context, arg AccountDeletionInsertParams) (AccountDeletion, error)
- func (q *Queries) AccountDeletionOpenForUser(ctx context.Context, userID string) (string, error)
- func (q *Queries) AccountDeletionPurgeNow(ctx context.Context, userID string) (AccountDeletionPurgeNowRow, error)
- func (q *Queries) AccountDeletionPurgeWindow(ctx context.Context, arg AccountDeletionPurgeWindowParams) (AccountDeletionPurgeWindowRow, error)
- func (q *Queries) AccountDeletionRecoverable(ctx context.Context, arg AccountDeletionRecoverableParams) (AccountDeletion, error)
- func (q *Queries) AccountDeletionSetDeletedBy(ctx context.Context, arg AccountDeletionSetDeletedByParams) error
- func (q *Queries) AccountDeletionSetFinalizing(ctx context.Context, id string) error
- func (q *Queries) AccountDeletionSetPurged(ctx context.Context, id string) error
- func (q *Queries) AccountDeletionSetRestored(ctx context.Context, id string) error
- func (q *Queries) AccountDeletionStateForUpdate(ctx context.Context, id string) (string, error)
- func (q *Queries) AccountDeletionUser(ctx context.Context, id string) (string, error)
- func (q *Queries) AccountDeletionsDeleteTerminalBatch(ctx context.Context, arg AccountDeletionsDeleteTerminalBatchParams) (int64, error)
- func (q *Queries) AccountDeliveryFleetBusy(ctx context.Context, issuer string) (bool, error)
- func (q *Queries) AccountDeliveryFleetInsert(ctx context.Context, arg AccountDeliveryFleetInsertParams) error
- func (q *Queries) AccountDeliveryFleetSchemaForShare(ctx context.Context, issuer string) (string, error)
- func (q *Queries) AccountDeliveryFleetSchemaForUpdate(ctx context.Context, issuer string) (string, error)
- func (q *Queries) AccountDeliveryFleetSetEvents(ctx context.Context, arg AccountDeliveryFleetSetEventsParams) error
- func (q *Queries) AccountDeliveryFleetSetSchema(ctx context.Context, arg AccountDeliveryFleetSetSchemaParams) error
- func (q *Queries) AccountDeliveryFleetsUnbound(ctx context.Context, issuers []string) ([]string, error)
- func (q *Queries) AccountEventByID(ctx context.Context, id int64) (AccountEvent, error)
- func (q *Queries) AccountEventDelete(ctx context.Context, id int64) error
- func (q *Queries) AccountEventEarlierPending(ctx context.Context, arg AccountEventEarlierPendingParams) (AccountEventEarlierPendingRow, error)
- func (q *Queries) AccountEventFleetsForShare(ctx context.Context, issuers []string) ([]AccountEventFleetsForShareRow, error)
- func (q *Queries) AccountEventInsert(ctx context.Context, arg AccountEventInsertParams) (int64, error)
- func (q *Queries) AccountEventRetry(ctx context.Context, arg AccountEventRetryParams) error
- func (q *Queries) AccountInviteByCodeForUpdate(ctx context.Context, arg AccountInviteByCodeForUpdateParams) (AccountInviteByCodeForUpdateRow, error)
- func (q *Queries) AccountInviteConsume(ctx context.Context, arg AccountInviteConsumeParams) error
- func (q *Queries) AccountInviteForRevoke(ctx context.Context, arg AccountInviteForRevokeParams) (AccountInviteForRevokeRow, error)
- func (q *Queries) AccountInviteForUpdate(ctx context.Context, arg AccountInviteForUpdateParams) (AccountInviteForUpdateRow, error)
- func (q *Queries) AccountInviteGroupByCode(ctx context.Context, codeHash string) (string, error)
- func (q *Queries) AccountInviteGroupLive(ctx context.Context, codeHash string) (*string, error)
- func (q *Queries) AccountInviteInsert(ctx context.Context, arg AccountInviteInsertParams) (AccountInviteInsertRow, error)
- func (q *Queries) AccountInviteRetire(ctx context.Context, id string) error
- func (q *Queries) AccountInviteValid(ctx context.Context, codeHash string) (bool, error)
- func (q *Queries) AccountInvitesDeleteExpiredBatch(ctx context.Context, arg AccountInvitesDeleteExpiredBatchParams) error
- func (q *Queries) AccountInvitesRevokeInvitedBy(ctx context.Context, userID string) error
- func (q *Queries) AdvisoryLock(ctx context.Context, key string) error
- func (q *Queries) AdvisoryXactLock(ctx context.Context, key string) error
- func (q *Queries) AuthorityAPIKeyRole(ctx context.Context, id string) (AuthorityAPIKeyRoleRow, error)
- func (q *Queries) AuthorityApplicationGroup(ctx context.Context, id string) (string, error)
- func (q *Queries) AuthorityApplicationOwnsGroup(ctx context.Context, arg AuthorityApplicationOwnsGroupParams) (AuthorityApplicationOwnsGroupRow, error)
- func (q *Queries) AuthorityGroup(ctx context.Context, id string) (PermissionGroup, error)
- func (q *Queries) AuthorityGroupState(ctx context.Context, id string) (PermissionGroup, error)
- func (q *Queries) AuthorityOutsideApplicationOwnerGroups(ctx context.Context, groupID string) ([]string, error)
- func (q *Queries) AuthorityUncoveredCredentials(ctx context.Context, arg AuthorityUncoveredCredentialsParams) ([]AuthorityUncoveredCredentialsRow, error)
- func (q *Queries) AuthorityUserGroups(ctx context.Context, arg AuthorityUserGroupsParams) ([]PermissionGroup, error)
- func (q *Queries) BootstrapAccountByCanonicalNameForUpdate(ctx context.Context, username string) (BootstrapAccountByCanonicalNameForUpdateRow, error)
- func (q *Queries) BootstrapAccountByEmailForUpdate(ctx context.Context, email string) (BootstrapAccountByEmailForUpdateRow, error)
- func (q *Queries) BootstrapAccountByIDForUpdate(ctx context.Context, id string) (BootstrapAccountByIDForUpdateRow, error)
- func (q *Queries) BootstrapAccountByPhoneForUpdate(ctx context.Context, phone string) (BootstrapAccountByPhoneForUpdateRow, error)
- func (q *Queries) BootstrapApplyInsert(ctx context.Context, name string) error
- func (q *Queries) BootstrapApplyState(ctx context.Context, name string) (BootstrapApplyStateRow, error)
- func (q *Queries) ContactState(ctx context.Context, id string) (ContactStateRow, error)
- func (q *Queries) ContactStateForUpdate(ctx context.Context, id string) (ContactStateForUpdateRow, error)
- func (q *Queries) CredentialSweepFleetsForShare(ctx context.Context, issuers []string) ([]CredentialSweepFleetsForShareRow, error)
- func (q *Queries) CurrentDatabase(ctx context.Context) (string, error)
- func (q *Queries) DeviceKeyActive(ctx context.Context, id string) (UserDeviceKey, error)
- func (q *Queries) DeviceKeyByPublicKey(ctx context.Context, publicKey []byte) (UserDeviceKey, error)
- func (q *Queries) DeviceKeyEnrollUserInsert(ctx context.Context, arg DeviceKeyEnrollUserInsertParams) (int64, error)
- func (q *Queries) DeviceKeyInsert(ctx context.Context, arg DeviceKeyInsertParams) (UserDeviceKey, error)
- func (q *Queries) DeviceKeyIsActive(ctx context.Context, arg DeviceKeyIsActiveParams) (bool, error)
- func (q *Queries) DeviceKeyIsActiveForUpdate(ctx context.Context, arg DeviceKeyIsActiveForUpdateParams) (bool, error)
- func (q *Queries) DeviceKeyMarkMFAProven(ctx context.Context, id string) error
- func (q *Queries) DeviceKeyRevoke(ctx context.Context, arg DeviceKeyRevokeParams) (int64, error)
- func (q *Queries) DeviceKeyTouch(ctx context.Context, arg DeviceKeyTouchParams) (UserDeviceKey, error)
- func (q *Queries) DeviceKeysByUser(ctx context.Context, userID string) ([]UserDeviceKey, error)
- func (q *Queries) DeviceKeysRevokeAllExcept(ctx context.Context, arg DeviceKeysRevokeAllExceptParams) (int64, error)
- func (q *Queries) EphemeralCompareAndConsume(ctx context.Context, arg EphemeralCompareAndConsumeParams) (int64, error)
- func (q *Queries) EphemeralConsume(ctx context.Context, key string) ([]byte, error)
- func (q *Queries) EphemeralDelete(ctx context.Context, key string) error
- func (q *Queries) EphemeralDeleteExpired(ctx context.Context, batchSize int64) (int64, error)
- func (q *Queries) EphemeralGet(ctx context.Context, key string) ([]byte, error)
- func (q *Queries) EphemeralIncr(ctx context.Context, arg EphemeralIncrParams) (int64, error)
- func (q *Queries) EphemeralSet(ctx context.Context, arg EphemeralSetParams) error
- func (q *Queries) GroupApplicationAssignmentsForGroups(ctx context.Context, arg GroupApplicationAssignmentsForGroupsParams) ([]GroupApplicationAssignmentsForGroupsRow, error)
- func (q *Queries) GroupApplicationRoleDelete(ctx context.Context, arg GroupApplicationRoleDeleteParams) (GroupApplicationRoleDeleteRow, error)
- func (q *Queries) GroupApplicationRoleName(ctx context.Context, arg GroupApplicationRoleNameParams) (string, error)
- func (q *Queries) GroupApplicationRoleUpsert(ctx context.Context, arg GroupApplicationRoleUpsertParams) error
- func (q *Queries) GroupHasOtherUsableOwner(ctx context.Context, arg GroupHasOtherUsableOwnerParams) (bool, error)
- func (q *Queries) GroupMembersPage(ctx context.Context, arg GroupMembersPageParams) ([]GroupMembersPageRow, error)
- func (q *Queries) GroupRolesForSubjects(ctx context.Context, arg GroupRolesForSubjectsParams) ([]GroupRolesForSubjectsRow, error)
- func (q *Queries) GroupUserAssignmentsForGroups(ctx context.Context, arg GroupUserAssignmentsForGroupsParams) ([]GroupUserAssignmentsForGroupsRow, error)
- func (q *Queries) GroupUserHasRole(ctx context.Context, arg GroupUserHasRoleParams) (bool, error)
- func (q *Queries) GroupUserRoleCounts(ctx context.Context) ([]GroupUserRoleCountsRow, error)
- func (q *Queries) GroupUserRoleDelete(ctx context.Context, arg GroupUserRoleDeleteParams) (GroupUserRoleDeleteRow, error)
- func (q *Queries) GroupUserRoleName(ctx context.Context, arg GroupUserRoleNameParams) (string, error)
- func (q *Queries) GroupUserRoleUpsert(ctx context.Context, arg GroupUserRoleUpsertParams) error
- func (q *Queries) GroupUserRolesForUsers(ctx context.Context, arg GroupUserRolesForUsersParams) ([]GroupUserRolesForUsersRow, error)
- func (q *Queries) GroupsOfApplicationPage(ctx context.Context, arg GroupsOfApplicationPageParams) ([]GroupsOfApplicationPageRow, error)
- func (q *Queries) GroupsOfUserPage(ctx context.Context, arg GroupsOfUserPageParams) ([]GroupsOfUserPageRow, error)
- func (q *Queries) GroupsOwnedByApplication(ctx context.Context, remoteApplicationID string) ([]string, error)
- func (q *Queries) GroupsOwnedByUser(ctx context.Context, userID string) ([]string, error)
- func (q *Queries) IdentityPublicUsersByIDs(ctx context.Context, ids []string) ([]IdentityPublicUsersByIDsRow, error)
- func (q *Queries) ImportHeldProviders(ctx context.Context, arg ImportHeldProvidersParams) ([]ImportHeldProvidersRow, error)
- func (q *Queries) ImportHitsByEmail(ctx context.Context, emails []string) ([]ImportHitsByEmailRow, error)
- func (q *Queries) ImportHitsByID(ctx context.Context, ids []string) ([]ImportHitsByIDRow, error)
- func (q *Queries) ImportHitsByName(ctx context.Context, arg ImportHitsByNameParams) ([]ImportHitsByNameRow, error)
- func (q *Queries) ImportHitsByPhone(ctx context.Context, phones []string) ([]ImportHitsByPhoneRow, error)
- func (q *Queries) ImportInsertPasswords(ctx context.Context, arg ImportInsertPasswordsParams) error
- func (q *Queries) ImportInsertProviders(ctx context.Context, arg ImportInsertProvidersParams) (int64, error)
- func (q *Queries) ImportInsertUsers(ctx context.Context, users []byte) ([]string, error)
- func (q *Queries) ImportMergePassword(ctx context.Context, arg ImportMergePasswordParams) error
- func (q *Queries) ImportMergeUser(ctx context.Context, arg ImportMergeUserParams) error
- func (q *Queries) ImportReleaseAliases(ctx context.Context, arg ImportReleaseAliasesParams) error
- func (q *Queries) ImportSetBannedBy(ctx context.Context, arg ImportSetBannedByParams) error
- func (q *Queries) InvitationsByGroup(ctx context.Context, arg InvitationsByGroupParams) ([]InvitationsByGroupRow, error)
- func (q *Queries) InviteLinkByCodeForUpdate(ctx context.Context, arg InviteLinkByCodeForUpdateParams) (InviteLinkByCodeForUpdateRow, error)
- func (q *Queries) InviteLinkForRevoke(ctx context.Context, arg InviteLinkForRevokeParams) (InviteLinkForRevokeRow, error)
- func (q *Queries) InviteLinkGroupByCode(ctx context.Context, codeHash string) (string, error)
- func (q *Queries) InviteLinkInsert(ctx context.Context, arg InviteLinkInsertParams) (InviteLinkInsertRow, error)
- func (q *Queries) InviteLinkRedeem(ctx context.Context, id string) error
- func (q *Queries) InviteLinkRetire(ctx context.Context, id string) error
- func (q *Queries) InviteLinksDeleteExpiredBatch(ctx context.Context, arg InviteLinksDeleteExpiredBatchParams) error
- func (q *Queries) InviteLinksRevokeInvitedBy(ctx context.Context, userID string) error
- func (q *Queries) MFAClearDefaultFactors(ctx context.Context, userID string) error
- func (q *Queries) MFAConsumeBackupCode(ctx context.Context, arg MFAConsumeBackupCodeParams) (int64, error)
- func (q *Queries) MFAConsumeFactorTOTPStep(ctx context.Context, arg MFAConsumeFactorTOTPStepParams) (int64, error)
- func (q *Queries) MFADeleteAllFactors(ctx context.Context, userID string) error
- func (q *Queries) MFADeleteFactor(ctx context.Context, arg MFADeleteFactorParams) (int64, error)
- func (q *Queries) MFADisable(ctx context.Context, userID string) error
- func (q *Queries) MFAInsertFactor(ctx context.Context, arg MFAInsertFactorParams) (MfaFactor, error)
- func (q *Queries) MFAListFactorsByUser(ctx context.Context, userID string) ([]MfaFactor, error)
- func (q *Queries) MFALockUser(ctx context.Context, id string) (string, error)
- func (q *Queries) MFAResetSettings(ctx context.Context, userID string) error
- func (q *Queries) MFASetBackupCodes(ctx context.Context, arg MFASetBackupCodesParams) error
- func (q *Queries) MFASetDefaultFactor(ctx context.Context, arg MFASetDefaultFactorParams) (int64, error)
- func (q *Queries) MFASetEmailFactorAddress(ctx context.Context, arg MFASetEmailFactorAddressParams) error
- func (q *Queries) MFASettingsByUser(ctx context.Context, userID string) (MfaSetting, error)
- func (q *Queries) MFASettingsDelete(ctx context.Context, userID string) error
- func (q *Queries) MFAUpsertSettings(ctx context.Context, arg MFAUpsertSettingsParams) error
- func (q *Queries) MFAUsable(ctx context.Context, userID string) (bool, error)
- func (q *Queries) MigrationSchemaHasUsers(ctx context.Context, schemaName string) (bool, error)
- func (q *Queries) NameClaimAliasesByUser(ctx context.Context, arg NameClaimAliasesByUserParams) ([]NameClaimAliasesByUserRow, error)
- func (q *Queries) NameClaimCanonical(ctx context.Context, arg NameClaimCanonicalParams) error
- func (q *Queries) NameClaimDeleteOwned(ctx context.Context, arg NameClaimDeleteOwnedParams) error
- func (q *Queries) NameClaimRetire(ctx context.Context, arg NameClaimRetireParams) error
- func (q *Queries) NameClaimTaken(ctx context.Context, arg NameClaimTakenParams) (bool, error)
- func (q *Queries) NameClaimsDeleteExpired(ctx context.Context, atTime time.Time) (int64, error)
- func (q *Queries) NameClaimsLock(ctx context.Context, names []string) error
- func (q *Queries) PasskeyDelete(ctx context.Context, arg PasskeyDeleteParams) (int64, error)
- func (q *Queries) PasskeyExistsForRP(ctx context.Context, arg PasskeyExistsForRPParams) (bool, error)
- func (q *Queries) PasskeyHandleByUser(ctx context.Context, userID string) ([]byte, error)
- func (q *Queries) PasskeyHandleUpsert(ctx context.Context, arg PasskeyHandleUpsertParams) ([]byte, error)
- func (q *Queries) PasskeyHandleUser(ctx context.Context, userHandle []byte) (string, error)
- func (q *Queries) PasskeyInsert(ctx context.Context, arg PasskeyInsertParams) (UserPasskey, error)
- func (q *Queries) PasskeyLiveForUpdate(ctx context.Context, arg PasskeyLiveForUpdateParams) (string, error)
- func (q *Queries) PasskeyRecordUse(ctx context.Context, arg PasskeyRecordUseParams) (string, error)
- func (q *Queries) PasskeyRename(ctx context.Context, arg PasskeyRenameParams) (int64, error)
- func (q *Queries) PasskeysByUser(ctx context.Context, arg PasskeysByUserParams) ([]UserPasskey, error)
- func (q *Queries) PasskeysDeleteByUser(ctx context.Context, userID string) error
- func (q *Queries) PermissionGroupDelete(ctx context.Context, id string) error
- func (q *Queries) PermissionGroupEnsureRoot(ctx context.Context) (string, error)
- func (q *Queries) PermissionGroupForUpdate(ctx context.Context, id string) (PermissionGroup, error)
- func (q *Queries) PermissionGroupInsert(ctx context.Context, persona string) (string, error)
- func (q *Queries) PermissionGroupInsertWithID(ctx context.Context, arg PermissionGroupInsertWithIDParams) error
- func (q *Queries) PermissionGroupLiveForUpdate(ctx context.Context, id string) (PermissionGroup, error)
- func (q *Queries) PermissionGroupOwnerCount(ctx context.Context, groupID string) (int64, error)
- func (q *Queries) PermissionGroupRootID(ctx context.Context) (string, error)
- func (q *Queries) PermissionGroupSoftDelete(ctx context.Context, arg PermissionGroupSoftDeleteParams) error
- func (q *Queries) PermissionGroupsByIDs(ctx context.Context, ids []string) ([]PermissionGroup, error)
- func (q *Queries) PermissionGroupsPage(ctx context.Context, arg PermissionGroupsPageParams) ([]PermissionGroup, error)
- func (q *Queries) ProviderLinkByIssuer(ctx context.Context, arg ProviderLinkByIssuerParams) (ProviderLinkByIssuerRow, error)
- func (q *Queries) ProviderLinkByIssuerAny(ctx context.Context, arg ProviderLinkByIssuerAnyParams) (ProviderLinkByIssuerAnyRow, error)
- func (q *Queries) RemoteApplicationAuthority(ctx context.Context, id string) (RemoteApplicationAuthorityRow, error)
- func (q *Queries) RemoteApplicationByID(ctx context.Context, id string) (RemoteApplication, error)
- func (q *Queries) RemoteApplicationByIDForUpdate(ctx context.Context, id string) (RemoteApplication, error)
- func (q *Queries) RemoteApplicationByIssuer(ctx context.Context, issuer string) (RemoteApplication, error)
- func (q *Queries) RemoteApplicationControlRoles(ctx context.Context, remoteApplicationID string) ([]RemoteApplicationControlRolesRow, error)
- func (q *Queries) RemoteApplicationDelete(ctx context.Context, issuer string) (int64, error)
- func (q *Queries) RemoteApplicationEnabledInGroup(ctx context.Context, arg RemoteApplicationEnabledInGroupParams) (bool, error)
- func (q *Queries) RemoteApplicationSetRegistrar(ctx context.Context, arg RemoteApplicationSetRegistrarParams) error
- func (q *Queries) RemoteApplicationSetTrustRoot(ctx context.Context, arg RemoteApplicationSetTrustRootParams) error
- func (q *Queries) RemoteApplicationUpsert(ctx context.Context, arg RemoteApplicationUpsertParams) (RemoteApplication, error)
- func (q *Queries) RemoteApplicationUsable(ctx context.Context, id string) (bool, error)
- func (q *Queries) RemoteApplicationsByGroup(ctx context.Context, arg RemoteApplicationsByGroupParams) ([]RemoteApplication, error)
- func (q *Queries) RemoteApplicationsClearRegistrar(ctx context.Context, userID string) error
- func (q *Queries) RemoteApplicationsEnabled(ctx context.Context) ([]RemoteApplication, error)
- func (q *Queries) ResolveUsername(ctx context.Context, arg ResolveUsernameParams) (ResolveUsernameRow, error)
- func (q *Queries) RiverIdentityProbeLock(ctx context.Context, arg RiverIdentityProbeLockParams) (RiverIdentityProbeLockRow, error)
- func (q *Queries) RiverIdentityProbeSeen(ctx context.Context, arg RiverIdentityProbeSeenParams) (bool, error)
- func (q *Queries) RoleCatalogFingerprint(ctx context.Context, issuer string) (string, error)
- func (q *Queries) RoleCatalogSet(ctx context.Context, arg RoleCatalogSetParams) error
- func (q *Queries) RoleCatalogsDeclaredRoles(ctx context.Context, issuers []string) ([]string, error)
- func (q *Queries) RuntimeAccessLock(ctx context.Context) error
- func (q *Queries) RuntimeIdentity(ctx context.Context) (RuntimeIdentityRow, error)
- func (q *Queries) SessionByCurrentTokenHash(ctx context.Context, arg SessionByCurrentTokenHashParams) (SessionByCurrentTokenHashRow, error)
- func (q *Queries) SessionByHistoricalTokenHash(ctx context.Context, arg SessionByHistoricalTokenHashParams) (SessionByHistoricalTokenHashRow, error)
- func (q *Queries) SessionEventInsert(ctx context.Context, arg SessionEventInsertParams) error
- func (q *Queries) SessionEventsByUser(ctx context.Context, arg SessionEventsByUserParams) ([]SessionEvent, error)
- func (q *Queries) SessionEventsPruneBatch(ctx context.Context, arg SessionEventsPruneBatchParams) (int64, error)
- func (q *Queries) SessionFreshSince(ctx context.Context, arg SessionFreshSinceParams) (SessionFreshSinceRow, error)
- func (q *Queries) SessionFreshSinceForUpdate(ctx context.Context, arg SessionFreshSinceForUpdateParams) (SessionFreshSinceForUpdateRow, error)
- func (q *Queries) SessionInsert(ctx context.Context, arg SessionInsertParams) (SessionInsertRow, error)
- func (q *Queries) SessionMarkAuthenticated(ctx context.Context, arg SessionMarkAuthenticatedParams) (int64, error)
- func (q *Queries) SessionProvedPassword(ctx context.Context, arg SessionProvedPasswordParams) (bool, error)
- func (q *Queries) SessionRevokeByIDForUser(ctx context.Context, arg SessionRevokeByIDForUserParams) (string, error)
- func (q *Queries) SessionRotate(ctx context.Context, arg SessionRotateParams) (int64, error)
- func (q *Queries) SessionsCountActive(ctx context.Context, arg SessionsCountActiveParams) (int64, error)
- func (q *Queries) SessionsCountActiveOutsideIssuers(ctx context.Context, arg SessionsCountActiveOutsideIssuersParams) (int64, error)
- func (q *Queries) SessionsDeleteRevokedOrExpiredBatch(ctx context.Context, batchSize int64) (int64, error)
- func (q *Queries) SessionsEvictOldest(ctx context.Context, arg SessionsEvictOldestParams) ([]string, error)
- func (q *Queries) SessionsListByUser(ctx context.Context, arg SessionsListByUserParams) ([]SessionsListByUserRow, error)
- func (q *Queries) SessionsRevokeAll(ctx context.Context, arg SessionsRevokeAllParams) ([]SessionsRevokeAllRow, error)
- func (q *Queries) SessionsRevokeFamily(ctx context.Context, familyID string) ([]SessionsRevokeFamilyRow, error)
- func (q *Queries) SetSearchPath(ctx context.Context, arg SetSearchPathParams) error
- func (q *Queries) StatementTimestamp(ctx context.Context) (time.Time, error)
- func (q *Queries) TransactionSettings(ctx context.Context) (TransactionSettingsRow, error)
- func (q *Queries) UserAdvanceCredentialVersion(ctx context.Context, id string) error
- func (q *Queries) UserApplyEmailChange(ctx context.Context, arg UserApplyEmailChangeParams) error
- func (q *Queries) UserApplyPhoneChange(ctx context.Context, arg UserApplyPhoneChangeParams) error
- func (q *Queries) UserBan(ctx context.Context, arg UserBanParams) error
- func (q *Queries) UserBanInForce(ctx context.Context, id string) (bool, error)
- func (q *Queries) UserByEmail(ctx context.Context, email string) (User, error)
- func (q *Queries) UserByID(ctx context.Context, id string) (User, error)
- func (q *Queries) UserByPhone(ctx context.Context, phoneNumber *string) (User, error)
- func (q *Queries) UserByUsername(ctx context.Context, username string) (User, error)
- func (q *Queries) UserClearBan(ctx context.Context, id string) error
- func (q *Queries) UserCredentialVersion(ctx context.Context, id string) (UserCredentialVersionRow, error)
- func (q *Queries) UserCredentialVersionForUpdate(ctx context.Context, id string) (UserCredentialVersionForUpdateRow, error)
- func (q *Queries) UserDeleteHard(ctx context.Context, id string) error
- func (q *Queries) UserEmailOrUsernameTaken(ctx context.Context, arg UserEmailOrUsernameTakenParams) (UserEmailOrUsernameTakenRow, error)
- func (q *Queries) UserExists(ctx context.Context, id string) (bool, error)
- func (q *Queries) UserGroupRoles(ctx context.Context, userID string) ([]UserGroupRolesRow, error)
- func (q *Queries) UserHasPassword(ctx context.Context, userID string) (bool, error)
- func (q *Queries) UserImportInsert(ctx context.Context, arg UserImportInsertParams) error
- func (q *Queries) UserImportUpdate(ctx context.Context, arg UserImportUpdateParams) (string, error)
- func (q *Queries) UserInsert(ctx context.Context, arg UserInsertParams) (User, error)
- func (q *Queries) UserIsReserved(ctx context.Context, id string) (bool, error)
- func (q *Queries) UserLastRenamedAt(ctx context.Context, id string) (*time.Time, error)
- func (q *Queries) UserMetadata(ctx context.Context, id string) ([]byte, error)
- func (q *Queries) UserNameForUpdate(ctx context.Context, id string) (UserNameForUpdateRow, error)
- func (q *Queries) UserNotDeleted(ctx context.Context, id string) (bool, error)
- func (q *Queries) UserPasswordDelete(ctx context.Context, userID string) error
- func (q *Queries) UserPasswordInsert(ctx context.Context, arg UserPasswordInsertParams) error
- func (q *Queries) UserPasswordRehash(ctx context.Context, arg UserPasswordRehashParams) error
- func (q *Queries) UserPasswordRow(ctx context.Context, userID string) (UserPasswordRowRow, error)
- func (q *Queries) UserPasswordUpsert(ctx context.Context, arg UserPasswordUpsertParams) error
- func (q *Queries) UserPatchMetadata(ctx context.Context, arg UserPatchMetadataParams) error
- func (q *Queries) UserPhoneOrUsernameTaken(ctx context.Context, arg UserPhoneOrUsernameTakenParams) (UserPhoneOrUsernameTakenRow, error)
- func (q *Queries) UserPreferredLanguage(ctx context.Context, id string) (string, error)
- func (q *Queries) UserProviderByIssuerAny(ctx context.Context, arg UserProviderByIssuerAnyParams) (UserProviderByIssuerAnyRow, error)
- func (q *Queries) UserProviderCountForUpdate(ctx context.Context, userID string) (int32, error)
- func (q *Queries) UserProviderDeleteBySlug(ctx context.Context, arg UserProviderDeleteBySlugParams) error
- func (q *Queries) UserProviderImportUnverified(ctx context.Context, arg UserProviderImportUnverifiedParams) (UserProviderImportUnverifiedRow, error)
- func (q *Queries) UserProviderLinkExists(ctx context.Context, arg UserProviderLinkExistsParams) (bool, error)
- func (q *Queries) UserProviderMergeProfile(ctx context.Context, arg UserProviderMergeProfileParams) error
- func (q *Queries) UserProviderProofSource(ctx context.Context, arg UserProviderProofSourceParams) (string, error)
- func (q *Queries) UserProviderSetUsername(ctx context.Context, arg UserProviderSetUsernameParams) error
- func (q *Queries) UserProviderSlugsDistinct(ctx context.Context, userID string) ([]string, error)
- func (q *Queries) UserProviderSubjectProfileByIssuer(ctx context.Context, arg UserProviderSubjectProfileByIssuerParams) (UserProviderSubjectProfileByIssuerRow, error)
- func (q *Queries) UserProviderUnverifiedForUpdate(ctx context.Context, arg UserProviderUnverifiedForUpdateParams) (string, error)
- func (q *Queries) UserProviderUpsertByIssuer(ctx context.Context, arg UserProviderUpsertByIssuerParams) (UserProviderUpsertByIssuerRow, error)
- func (q *Queries) UserProviderVerifiedLink(ctx context.Context, arg UserProviderVerifiedLinkParams) (UserProviderVerifiedLinkRow, error)
- func (q *Queries) UserProviderVerifyImported(ctx context.Context, arg UserProviderVerifyImportedParams) (*time.Time, error)
- func (q *Queries) UserProvidersDeleteByUser(ctx context.Context, userID string) error
- func (q *Queries) UserRename(ctx context.Context, arg UserRenameParams) error
- func (q *Queries) UserRestore(ctx context.Context, id string) error
- func (q *Queries) UserSessionLive(ctx context.Context, arg UserSessionLiveParams) (UserSessionLiveRow, error)
- func (q *Queries) UserSetAvatarURL(ctx context.Context, arg UserSetAvatarURLParams) error
- func (q *Queries) UserSetEmail(ctx context.Context, arg UserSetEmailParams) error
- func (q *Queries) UserSetEmailVerified(ctx context.Context, arg UserSetEmailVerifiedParams) error
- func (q *Queries) UserSetEmailVerifiedIfPresent(ctx context.Context, arg UserSetEmailVerifiedIfPresentParams) (int64, error)
- func (q *Queries) UserSetLastLogin(ctx context.Context, arg UserSetLastLoginParams) error
- func (q *Queries) UserSetPhone(ctx context.Context, arg UserSetPhoneParams) error
- func (q *Queries) UserSetPhoneVerifiedByIDAndPhone(ctx context.Context, arg UserSetPhoneVerifiedByIDAndPhoneParams) error
- func (q *Queries) UserSetPhoneVerifiedIfPresent(ctx context.Context, arg UserSetPhoneVerifiedIfPresentParams) (int64, error)
- func (q *Queries) UserSetPreferredLanguage(ctx context.Context, arg UserSetPreferredLanguageParams) error
- func (q *Queries) UserSetUsernameSpelling(ctx context.Context, arg UserSetUsernameSpellingParams) error
- func (q *Queries) UserSoftDelete(ctx context.Context, id string) error
- func (q *Queries) UserUsable(ctx context.Context, id string) (bool, error)
- func (q *Queries) UsersByIDs(ctx context.Context, ids []string) ([]User, error)
- func (q *Queries) WithTx(tx pgx.Tx) *Queries
- type RemoteApplication
- type RemoteApplicationAuthorityRow
- type RemoteApplicationControlRolesRow
- type RemoteApplicationEnabledInGroupParams
- type RemoteApplicationSetRegistrarParams
- type RemoteApplicationSetTrustRootParams
- type RemoteApplicationUpsertParams
- type RemoteApplicationsByGroupParams
- type ResolveUsernameParams
- type ResolveUsernameRow
- type RiverIdentityProbeLockParams
- type RiverIdentityProbeLockRow
- type RiverIdentityProbeSeenParams
- type RoleCatalogSetParams
- type RuntimeIdentityRow
- type SessionByCurrentTokenHashParams
- type SessionByCurrentTokenHashRow
- type SessionByHistoricalTokenHashParams
- type SessionByHistoricalTokenHashRow
- type SessionEvent
- type SessionEventInsertParams
- type SessionEventsByUserParams
- type SessionEventsPruneBatchParams
- type SessionFreshSinceForUpdateParams
- type SessionFreshSinceForUpdateRow
- type SessionFreshSinceParams
- type SessionFreshSinceRow
- type SessionInsertParams
- type SessionInsertRow
- type SessionMarkAuthenticatedParams
- type SessionProvedPasswordParams
- type SessionRevokeByIDForUserParams
- type SessionRotateParams
- type SessionsCountActiveOutsideIssuersParams
- type SessionsCountActiveParams
- type SessionsEvictOldestParams
- type SessionsListByUserParams
- type SessionsListByUserRow
- type SessionsRevokeAllParams
- type SessionsRevokeAllRow
- type SessionsRevokeFamilyRow
- type SetSearchPathParams
- type TransactionSettingsRow
- type User
- type UserApplyEmailChangeParams
- type UserApplyPhoneChangeParams
- type UserBanParams
- type UserCredentialVersionForUpdateRow
- type UserCredentialVersionRow
- type UserDeviceKey
- type UserEmailOrUsernameTakenParams
- type UserEmailOrUsernameTakenRow
- type UserGroupRolesRow
- type UserImportInsertParams
- type UserImportUpdateParams
- type UserInsertParams
- type UserNameForUpdateRow
- type UserPasskey
- type UserPasswordInsertParams
- type UserPasswordRehashParams
- type UserPasswordRowRow
- type UserPasswordUpsertParams
- type UserPatchMetadataParams
- type UserPhoneOrUsernameTakenParams
- type UserPhoneOrUsernameTakenRow
- type UserProviderByIssuerAnyParams
- type UserProviderByIssuerAnyRow
- type UserProviderDeleteBySlugParams
- type UserProviderImportUnverifiedParams
- type UserProviderImportUnverifiedRow
- type UserProviderLinkExistsParams
- type UserProviderMergeProfileParams
- type UserProviderProofSourceParams
- type UserProviderSetUsernameParams
- type UserProviderSubjectProfileByIssuerParams
- type UserProviderSubjectProfileByIssuerRow
- type UserProviderUnverifiedForUpdateParams
- type UserProviderUpsertByIssuerParams
- type UserProviderUpsertByIssuerRow
- type UserProviderVerifiedLinkParams
- type UserProviderVerifiedLinkRow
- type UserProviderVerifyImportedParams
- type UserRenameParams
- type UserSessionLiveParams
- type UserSessionLiveRow
- type UserSetAvatarURLParams
- type UserSetEmailParams
- type UserSetEmailVerifiedIfPresentParams
- type UserSetEmailVerifiedParams
- type UserSetLastLoginParams
- type UserSetPhoneParams
- type UserSetPhoneVerifiedByIDAndPhoneParams
- type UserSetPhoneVerifiedIfPresentParams
- type UserSetPreferredLanguageParams
- type UserSetUsernameSpellingParams
Constants ¶
const DefaultSchema = "profiles"
DefaultSchema is AuthKit's default PostgreSQL namespace.
Variables ¶
This section is empty.
Functions ¶
func ValidSchemaName ¶ added in v0.26.0
ValidSchemaName reports whether s is a safe PostgreSQL schema identifier.
Types ¶
type APIKeyByLookupIDRow ¶ added in v0.147.0
type APIKeyForRevokeParams ¶ added in v0.147.0
type APIKeyForRevokeRow ¶ added in v0.147.0
type APIKeyInsertParams ¶ added in v0.41.0
type APIKeyInsertRow ¶ added in v0.41.0
type APIKeyRoleCountsRow ¶ added in v0.147.0
type APIKeysByGroupParams ¶ added in v0.147.0
type APIKeysByGroupRow ¶ added in v0.147.0
type APIKeysDeleteExpiredBatchParams ¶ added in v0.147.0
type AccountDeletion ¶ added in v0.147.0
type AccountDeletionDeliveryEarlierPendingParams ¶ added in v0.147.0
type AccountDeletionDeliveryInsertParams ¶ added in v0.147.0
type AccountDeletionDeliveryRow ¶ added in v0.147.0
type AccountDeletionDeliveryRow struct {
AccountDeletion AccountDeletion
Issuer string
Stage string
CompletedAt *time.Time
}
type AccountDeletionInsertParams ¶ added in v0.147.0
type AccountDeletionPurgeNowRow ¶ added in v0.147.0
type AccountDeletionPurgeWindowParams ¶ added in v0.147.0
type AccountDeletionPurgeWindowRow ¶ added in v0.147.0
type AccountDeletionRecoverableParams ¶ added in v0.147.0
type AccountDeletionSetDeletedByParams ¶ added in v0.147.0
type AccountDeletionsDeleteTerminalBatchParams ¶ added in v0.147.0
type AccountDeliveryFleetInsertParams ¶ added in v0.147.0
type AccountDeliveryFleetSetEventsParams ¶ added in v0.147.0
type AccountDeliveryFleetSetSchemaParams ¶ added in v0.147.0
type AccountEvent ¶ added in v0.147.0
type AccountEvent struct {
ID int64
Issuer string
Subject string
EventID string
Kind string
OccurredAt time.Time
ActorKind string
ActorID string
UserID *string
GroupID *string
Persona string
ApplicationID *string
PreviousValue string
CurrentValue string
Reason string
Until *time.Time
Attempts int32
RetryAt *time.Time
}
type AccountEventEarlierPendingParams ¶ added in v0.147.0
type AccountEventEarlierPendingRow ¶ added in v0.147.0
type AccountEventFleetsForShareRow ¶ added in v0.147.0
type AccountEventFleetsForShareRow struct {
}
type AccountEventInsertParams ¶ added in v0.147.0
type AccountEventRetryParams ¶ added in v0.147.0
type AccountInviteByCodeForUpdateParams ¶ added in v0.147.0
type AccountInviteByCodeForUpdateRow ¶ added in v0.147.0
type AccountInviteConsumeParams ¶ added in v0.147.0
type AccountInviteForRevokeParams ¶ added in v0.147.0
type AccountInviteForRevokeRow ¶ added in v0.147.0
type AccountInviteForUpdateParams ¶ added in v0.147.0
type AccountInviteForUpdateRow ¶ added in v0.147.0
type AccountInviteInsertParams ¶ added in v0.147.0
type AccountInviteInsertRow ¶ added in v0.147.0
type AccountInvitesDeleteExpiredBatchParams ¶ added in v0.147.0
type AuthorityAPIKeyRoleRow ¶ added in v0.147.0
type AuthorityApplicationOwnsGroupParams ¶ added in v0.147.0
type AuthorityApplicationOwnsGroupRow ¶ added in v0.147.0
type AuthorityUncoveredCredentialsParams ¶ added in v0.147.0
type AuthorityUncoveredCredentialsRow ¶ added in v0.147.0
type AuthorityUserGroupsParams ¶ added in v0.147.0
type BootstrapAccountByCanonicalNameForUpdateRow ¶ added in v0.147.0
type BootstrapAccountByEmailForUpdateRow ¶ added in v0.147.0
type BootstrapAccountByIDForUpdateRow ¶ added in v0.147.0
type BootstrapAccountByPhoneForUpdateRow ¶ added in v0.147.0
type BootstrapApplyStateRow ¶ added in v0.147.0
type ContactStateForUpdateRow ¶ added in v0.147.0
type ContactStateRow ¶ added in v0.147.0
type CredentialSweepFleetsForShareRow ¶ added in v0.147.0
type CredentialSweepFleetsForShareRow struct {
}
type DeviceKeyEnrollUserInsertParams ¶ added in v0.147.0
type DeviceKeyInsertParams ¶ added in v0.147.0
type DeviceKeyIsActiveForUpdateParams ¶ added in v0.147.0
type DeviceKeyIsActiveParams ¶ added in v0.147.0
type DeviceKeyRevokeParams ¶ added in v0.147.0
type DeviceKeyTouchParams ¶ added in v0.147.0
type DeviceKeysRevokeAllExceptParams ¶ added in v0.147.0
type EphemeralCompareAndConsumeParams ¶ added in v0.141.0
type EphemeralIncrParams ¶ added in v0.141.0
type EphemeralSetParams ¶ added in v0.141.0
type GroupApplicationAssignmentsForGroupsParams ¶ added in v0.147.0
type GroupApplicationAssignmentsForGroupsRow ¶ added in v0.147.0
type GroupApplicationRoleDeleteParams ¶ added in v0.147.0
type GroupApplicationRoleDeleteRow ¶ added in v0.147.0
type GroupApplicationRoleNameParams ¶ added in v0.147.0
type GroupApplicationRoleUpsertParams ¶ added in v0.147.0
type GroupHasOtherUsableOwnerParams ¶ added in v0.147.0
type GroupMembersPageParams ¶ added in v0.147.0
type GroupMembersPageRow ¶ added in v0.147.0
type GroupRolesForSubjectsParams ¶ added in v0.147.0
type GroupRolesForSubjectsRow ¶ added in v0.147.0
type GroupUserAssignmentsForGroupsParams ¶ added in v0.147.0
type GroupUserAssignmentsForGroupsRow ¶ added in v0.147.0
type GroupUserHasRoleParams ¶ added in v0.147.0
type GroupUserRoleCountsRow ¶ added in v0.147.0
type GroupUserRoleDeleteParams ¶ added in v0.147.0
type GroupUserRoleDeleteRow ¶ added in v0.147.0
type GroupUserRoleNameParams ¶ added in v0.147.0
type GroupUserRoleUpsertParams ¶ added in v0.147.0
type GroupUserRolesForUsersParams ¶ added in v0.147.0
type GroupUserRolesForUsersRow ¶ added in v0.147.0
type GroupsOfApplicationPageParams ¶ added in v0.147.0
type GroupsOfApplicationPageRow ¶ added in v0.147.0
type GroupsOfApplicationPageRow struct {
PermissionGroup PermissionGroup
Role string
}
type GroupsOfUserPageParams ¶ added in v0.147.0
type GroupsOfUserPageRow ¶ added in v0.147.0
type GroupsOfUserPageRow struct {
PermissionGroup PermissionGroup
Role string
}
type IdentityPublicUsersByIDsRow ¶ added in v0.92.0
type ImportHeldProvidersParams ¶ added in v0.147.0
type ImportHeldProvidersRow ¶ added in v0.147.0
type ImportHitsByEmailRow ¶ added in v0.147.0
type ImportHitsByIDRow ¶ added in v0.147.0
type ImportHitsByNameParams ¶ added in v0.147.0
type ImportHitsByNameRow ¶ added in v0.147.0
type ImportHitsByPhoneRow ¶ added in v0.147.0
type ImportInsertPasswordsParams ¶ added in v0.147.0
type ImportInsertProvidersParams ¶ added in v0.147.0
type ImportMergePasswordParams ¶ added in v0.147.0
type ImportMergeUserParams ¶ added in v0.147.0
type ImportReleaseAliasesParams ¶ added in v0.147.0
type ImportSetBannedByParams ¶ added in v0.147.0
type InvitationsByGroupParams ¶ added in v0.147.0
type InvitationsByGroupRow ¶ added in v0.147.0
type InviteLinkByCodeForUpdateParams ¶ added in v0.147.0
type InviteLinkByCodeForUpdateRow ¶ added in v0.147.0
type InviteLinkForRevokeParams ¶ added in v0.147.0
type InviteLinkForRevokeRow ¶ added in v0.147.0
type InviteLinkInsertParams ¶ added in v0.147.0
type InviteLinkInsertRow ¶ added in v0.147.0
type InviteLinksDeleteExpiredBatchParams ¶ added in v0.147.0
type MFAConsumeBackupCodeParams ¶ added in v0.63.0
type MFAConsumeFactorTOTPStepParams ¶ added in v0.56.0
type MFADeleteFactorParams ¶ added in v0.56.0
type MFAInsertFactorParams ¶ added in v0.98.0
type MFASetBackupCodesParams ¶ added in v0.56.0
type MFASetDefaultFactorParams ¶ added in v0.56.0
type MFASetEmailFactorAddressParams ¶ added in v0.147.0
type MFAUpsertSettingsParams ¶ added in v0.56.0
type MfaFactor ¶ added in v0.105.0
type MfaFactor struct {
ID string
UserID string
Method string
PhoneNumber *string
TotpSecret []byte
LastTotpStep *int64
// Default factor AuthKit challenges first when 2FA is required
IsDefault bool
CreatedAt time.Time
UpdatedAt time.Time
Email *string
}
Enrolled 2FA factors per user (hard-deleted on removal); backup codes remain user-scoped on mfa_settings
type MfaSetting ¶ added in v0.105.0
type MfaSetting struct {
UserID string
Enabled bool
// Hashed backup codes for account recovery
BackupCodes []string
CreatedAt time.Time
UpdatedAt time.Time
}
Account-level 2FA gate + backup codes per user. enabled=true ⇒ 2FA required at login. Per-factor data lives in mfa_factors.
type NameClaimAliasesByUserParams ¶ added in v0.147.0
type NameClaimAliasesByUserRow ¶ added in v0.147.0
type NameClaimCanonicalParams ¶ added in v0.147.0
type NameClaimDeleteOwnedParams ¶ added in v0.147.0
type NameClaimRetireParams ¶ added in v0.147.0
type NameClaimTakenParams ¶ added in v0.147.0
type PasskeyDeleteParams ¶ added in v0.147.0
type PasskeyExistsForRPParams ¶ added in v0.147.0
type PasskeyHandleUpsertParams ¶ added in v0.147.0
type PasskeyInsertParams ¶ added in v0.147.0
type PasskeyLiveForUpdateParams ¶ added in v0.147.0
type PasskeyRecordUseParams ¶ added in v0.147.0
type PasskeyRenameParams ¶ added in v0.147.0
type PasskeysByUserParams ¶ added in v0.147.0
type PermissionGroup ¶ added in v0.147.0
type PermissionGroupInsertWithIDParams ¶ added in v0.147.0
type PermissionGroupSoftDeleteParams ¶ added in v0.147.0
type PermissionGroupsPageParams ¶ added in v0.147.0
type ProviderLinkByIssuerAnyParams ¶ added in v0.97.1
type ProviderLinkByIssuerAnyRow ¶ added in v0.97.1
type ProviderLinkByIssuerRow ¶
type Queries ¶
type Queries struct {
// contains filtered or unexported fields
}
func (*Queries) APIKeyByLookupID ¶ added in v0.147.0
APIKeyByLookupID reads a key of a live group. creator_live: the key's creator is the system (NULL) or a usable account.
func (*Queries) APIKeyForRevoke ¶ added in v0.147.0
func (q *Queries) APIKeyForRevoke(ctx context.Context, arg APIKeyForRevokeParams) (APIKeyForRevokeRow, error)
func (*Queries) APIKeyInsert ¶ added in v0.41.0
func (q *Queries) APIKeyInsert(ctx context.Context, arg APIKeyInsertParams) (APIKeyInsertRow, error)
func (*Queries) APIKeyRetire ¶ added in v0.147.0
func (*Queries) APIKeyRoleCounts ¶ added in v0.147.0
func (q *Queries) APIKeyRoleCounts(ctx context.Context, issuer string) ([]APIKeyRoleCountsRow, error)
The live keys issued through issuer's app, or before per-app catalogs.
func (*Queries) APIKeyTouch ¶ added in v0.147.0
APIKeyTouch records a use at most once per 5 minutes per key.
func (*Queries) APIKeysByGroup ¶ added in v0.147.0
func (q *Queries) APIKeysByGroup(ctx context.Context, arg APIKeysByGroupParams) ([]APIKeysByGroupRow, error)
APIKeysByGroup lists a group's keys newest first, never the secret hash.
func (*Queries) APIKeysDeleteExpiredBatch ¶ added in v0.147.0
func (q *Queries) APIKeysDeleteExpiredBatch(ctx context.Context, arg APIKeysDeleteExpiredBatchParams) error
func (*Queries) APIKeysRevokeCreatedBy ¶ added in v0.147.0
API key queries.
func (*Queries) AccountDeletionDelivery ¶ added in v0.147.0
func (*Queries) AccountDeletionDeliveryComplete ¶ added in v0.147.0
func (*Queries) AccountDeletionDeliveryEarlierPending ¶ added in v0.147.0
func (*Queries) AccountDeletionDeliveryInsert ¶ added in v0.147.0
func (q *Queries) AccountDeletionDeliveryInsert(ctx context.Context, arg AccountDeletionDeliveryInsertParams) (int64, error)
No row (pgx.ErrNoRows) when the receipt already exists.
func (*Queries) AccountDeletionDeliveryUser ¶ added in v0.147.0
func (*Queries) AccountDeletionForUpdate ¶ added in v0.147.0
func (*Queries) AccountDeletionHardDeliveriesPending ¶ added in v0.147.0
func (*Queries) AccountDeletionInsert ¶ added in v0.147.0
func (q *Queries) AccountDeletionInsert(ctx context.Context, arg AccountDeletionInsertParams) (AccountDeletion, error)
Starts the recovery window from the account's own deleted_at.
func (*Queries) AccountDeletionOpenForUser ¶ added in v0.147.0
func (*Queries) AccountDeletionPurgeNow ¶ added in v0.147.0
func (q *Queries) AccountDeletionPurgeNow(ctx context.Context, userID string) (AccountDeletionPurgeNowRow, error)
Closes the recovery window of a deleted account now.
func (*Queries) AccountDeletionPurgeWindow ¶ added in v0.147.0
func (q *Queries) AccountDeletionPurgeWindow(ctx context.Context, arg AccountDeletionPurgeWindowParams) (AccountDeletionPurgeWindowRow, error)
func (*Queries) AccountDeletionRecoverable ¶ added in v0.147.0
func (q *Queries) AccountDeletionRecoverable(ctx context.Context, arg AccountDeletionRecoverableParams) (AccountDeletion, error)
The account's current deletion while it can still be undone.
func (*Queries) AccountDeletionSetDeletedBy ¶ added in v0.147.0
func (q *Queries) AccountDeletionSetDeletedBy(ctx context.Context, arg AccountDeletionSetDeletedByParams) error
Records who deleted an account that is already deleted.
func (*Queries) AccountDeletionSetFinalizing ¶ added in v0.147.0
func (*Queries) AccountDeletionSetPurged ¶ added in v0.147.0
func (*Queries) AccountDeletionSetRestored ¶ added in v0.147.0
func (*Queries) AccountDeletionStateForUpdate ¶ added in v0.147.0
func (*Queries) AccountDeletionUser ¶ added in v0.147.0
func (*Queries) AccountDeletionsDeleteTerminalBatch ¶ added in v0.147.0
func (q *Queries) AccountDeletionsDeleteTerminalBatch(ctx context.Context, arg AccountDeletionsDeleteTerminalBatchParams) (int64, error)
One bounded batch of restored/purged deletions past cutoff with no pending receipt; completed receipts go with them (FK cascade).
func (*Queries) AccountDeliveryFleetBusy ¶ added in v0.147.0
Whether the issuer still has lifecycle work in its current fleet.
func (*Queries) AccountDeliveryFleetInsert ¶ added in v0.147.0
func (q *Queries) AccountDeliveryFleetInsert(ctx context.Context, arg AccountDeliveryFleetInsertParams) error
func (*Queries) AccountDeliveryFleetSchemaForShare ¶ added in v0.147.0
func (*Queries) AccountDeliveryFleetSchemaForUpdate ¶ added in v0.147.0
func (*Queries) AccountDeliveryFleetSetEvents ¶ added in v0.147.0
func (q *Queries) AccountDeliveryFleetSetEvents(ctx context.Context, arg AccountDeliveryFleetSetEventsParams) error
func (*Queries) AccountDeliveryFleetSetSchema ¶ added in v0.147.0
func (q *Queries) AccountDeliveryFleetSetSchema(ctx context.Context, arg AccountDeliveryFleetSetSchemaParams) error
func (*Queries) AccountDeliveryFleetsUnbound ¶ added in v0.147.0
func (q *Queries) AccountDeliveryFleetsUnbound(ctx context.Context, issuers []string) ([]string, error)
The issuers, sorted, with no fleet bound yet.
func (*Queries) AccountEventByID ¶ added in v0.147.0
func (*Queries) AccountEventDelete ¶ added in v0.147.0
func (*Queries) AccountEventEarlierPending ¶ added in v0.147.0
func (q *Queries) AccountEventEarlierPending(ctx context.Context, arg AccountEventEarlierPendingParams) (AccountEventEarlierPendingRow, error)
Whether an earlier event of the subject is still pending, and the seconds until the latest of their retries.
func (*Queries) AccountEventFleetsForShare ¶ added in v0.147.0
func (q *Queries) AccountEventFleetsForShare(ctx context.Context, issuers []string) ([]AccountEventFleetsForShareRow, error)
Durable account and group events (Deps.OnEvent): one account_events row per subscribed issuer, recorded in the change's transaction, deleted on delivery. The subscribed issuers' fleets, key-share locked until the change commits.
func (*Queries) AccountEventInsert ¶ added in v0.147.0
func (*Queries) AccountEventRetry ¶ added in v0.147.0
func (q *Queries) AccountEventRetry(ctx context.Context, arg AccountEventRetryParams) error
func (*Queries) AccountInviteByCodeForUpdate ¶ added in v0.147.0
func (q *Queries) AccountInviteByCodeForUpdate(ctx context.Context, arg AccountInviteByCodeForUpdateParams) (AccountInviteByCodeForUpdateRow, error)
AccountInviteByCodeForUpdate: addressed is whether user_id has verified the invited address.
func (*Queries) AccountInviteConsume ¶ added in v0.147.0
func (q *Queries) AccountInviteConsume(ctx context.Context, arg AccountInviteConsumeParams) error
func (*Queries) AccountInviteForRevoke ¶ added in v0.147.0
func (q *Queries) AccountInviteForRevoke(ctx context.Context, arg AccountInviteForRevokeParams) (AccountInviteForRevokeRow, error)
func (*Queries) AccountInviteForUpdate ¶ added in v0.147.0
func (q *Queries) AccountInviteForUpdate(ctx context.Context, arg AccountInviteForUpdateParams) (AccountInviteForUpdateRow, error)
func (*Queries) AccountInviteGroupByCode ¶ added in v0.147.0
func (*Queries) AccountInviteGroupLive ¶ added in v0.147.0
func (*Queries) AccountInviteInsert ¶ added in v0.147.0
func (q *Queries) AccountInviteInsert(ctx context.Context, arg AccountInviteInsertParams) (AccountInviteInsertRow, error)
func (*Queries) AccountInviteRetire ¶ added in v0.147.0
func (*Queries) AccountInviteValid ¶ added in v0.147.0
AccountInviteValid: code_hash names a live registration invite.
func (*Queries) AccountInvitesDeleteExpiredBatch ¶ added in v0.147.0
func (q *Queries) AccountInvitesDeleteExpiredBatch(ctx context.Context, arg AccountInvitesDeleteExpiredBatchParams) error
func (*Queries) AccountInvitesRevokeInvitedBy ¶ added in v0.147.0
func (*Queries) AdvisoryLock ¶ added in v0.147.0
Session-scoped advisory lock on key in this database: hold it on one dedicated connection, whose close releases it.
func (*Queries) AdvisoryXactLock ¶ added in v0.147.0
Transaction-scoped advisory lock on key, released when the transaction ends.
func (*Queries) AuthorityAPIKeyRole ¶ added in v0.147.0
func (q *Queries) AuthorityAPIKeyRole(ctx context.Context, id string) (AuthorityAPIKeyRoleRow, error)
The group and role of a live key in a live group whose creator is the system (NULL) or usable.
func (*Queries) AuthorityApplicationGroup ¶ added in v0.147.0
The controlling group of an enabled application in a live group whose registrar is usable.
func (*Queries) AuthorityApplicationOwnsGroup ¶ added in v0.147.0
func (q *Queries) AuthorityApplicationOwnsGroup(ctx context.Context, arg AuthorityApplicationOwnsGroupParams) (AuthorityApplicationOwnsGroupRow, error)
Whether group_id controls the application, and the group's persona.
func (*Queries) AuthorityGroup ¶ added in v0.147.0
func (*Queries) AuthorityGroupState ¶ added in v0.147.0
func (*Queries) AuthorityOutsideApplicationOwnerGroups ¶ added in v0.147.0
func (q *Queries) AuthorityOutsideApplicationOwnerGroups(ctx context.Context, groupID string) ([]string, error)
The other groups owned by enabled applications that group_id controls.
func (*Queries) AuthorityUncoveredCredentials ¶ added in v0.147.0
func (q *Queries) AuthorityUncoveredCredentials(ctx context.Context, arg AuthorityUncoveredCredentialsParams) ([]AuthorityUncoveredCredentialsRow, error)
Live credentials in the scope of a grant change to group_id (root: every live group) issued by user_id (” = anyone) through issuer's app, or before per-app catalogs: invite links, account invitations (one without a group belongs to root), API keys and the roles of applications (needs_creator: a group registration, which confers nothing without its registrar).
func (*Queries) AuthorityUserGroups ¶ added in v0.147.0
func (q *Queries) AuthorityUserGroups(ctx context.Context, arg AuthorityUserGroupsParams) ([]PermissionGroup, error)
The live groups other than root where the user holds a role.
func (*Queries) BootstrapAccountByCanonicalNameForUpdate ¶ added in v0.147.0
func (q *Queries) BootstrapAccountByCanonicalNameForUpdate(ctx context.Context, username string) (BootstrapAccountByCanonicalNameForUpdateRow, error)
A canonical username only; an alias is never followed.
func (*Queries) BootstrapAccountByEmailForUpdate ¶ added in v0.147.0
func (*Queries) BootstrapAccountByIDForUpdate ¶ added in v0.147.0
func (q *Queries) BootstrapAccountByIDForUpdate(ctx context.Context, id string) (BootstrapAccountByIDForUpdateRow, error)
Bootstrap manifests and EnsureUserRole: find and lock the account a manifest user or a UserRef names. verified reports whether the key proves who holds the account (the id itself, or a verified contact).
func (*Queries) BootstrapAccountByPhoneForUpdate ¶ added in v0.147.0
func (*Queries) BootstrapApplyInsert ¶ added in v0.147.0
func (*Queries) BootstrapApplyState ¶ added in v0.147.0
func (*Queries) ContactState ¶ added in v0.147.0
An account is unproven when it has an address and none is verified.
func (*Queries) ContactStateForUpdate ¶ added in v0.147.0
func (*Queries) CredentialSweepFleetsForShare ¶ added in v0.147.0
func (q *Queries) CredentialSweepFleetsForShare(ctx context.Context, issuers []string) ([]CredentialSweepFleetsForShareRow, error)
The fleets of issuers, key-share locked until the change commits.
func (*Queries) CurrentDatabase ¶ added in v0.147.0
func (*Queries) DeviceKeyActive ¶ added in v0.147.0
func (*Queries) DeviceKeyByPublicKey ¶ added in v0.147.0
func (q *Queries) DeviceKeyByPublicKey(ctx context.Context, publicKey []byte) (UserDeviceKey, error)
Device key queries. A key read returns db.UserDeviceKey.
func (*Queries) DeviceKeyEnrollUserInsert ¶ added in v0.147.0
func (q *Queries) DeviceKeyEnrollUserInsert(ctx context.Context, arg DeviceKeyEnrollUserInsertParams) (int64, error)
The account a device-key enrollment creates; the emailed code proved its address.
func (*Queries) DeviceKeyInsert ¶ added in v0.147.0
func (q *Queries) DeviceKeyInsert(ctx context.Context, arg DeviceKeyInsertParams) (UserDeviceKey, error)
func (*Queries) DeviceKeyIsActive ¶ added in v0.147.0
func (*Queries) DeviceKeyIsActiveForUpdate ¶ added in v0.147.0
func (*Queries) DeviceKeyMarkMFAProven ¶ added in v0.147.0
func (*Queries) DeviceKeyRevoke ¶ added in v0.147.0
func (*Queries) DeviceKeyTouch ¶ added in v0.147.0
func (q *Queries) DeviceKeyTouch(ctx context.Context, arg DeviceKeyTouchParams) (UserDeviceKey, error)
func (*Queries) DeviceKeysByUser ¶ added in v0.147.0
func (*Queries) DeviceKeysRevokeAllExcept ¶ added in v0.147.0
func (q *Queries) DeviceKeysRevokeAllExcept(ctx context.Context, arg DeviceKeysRevokeAllExceptParams) (int64, error)
Ends every live device key of the account but keep_id (optional), e.g. the one presenting a credential change.
func (*Queries) EphemeralCompareAndConsume ¶ added in v0.141.0
func (*Queries) EphemeralConsume ¶ added in v0.141.0
func (*Queries) EphemeralDelete ¶ added in v0.141.0
func (*Queries) EphemeralDeleteExpired ¶ added in v0.141.0
func (*Queries) EphemeralGet ¶ added in v0.141.0
Each operation is one statement. Expiry always uses the database clock, so replicas with skewed clocks agree on what is live.
func (*Queries) EphemeralIncr ¶ added in v0.141.0
The TTL is set when the counter starts and never extended; an expired counter restarts at 1.
func (*Queries) EphemeralSet ¶ added in v0.141.0
func (q *Queries) EphemeralSet(ctx context.Context, arg EphemeralSetParams) error
func (*Queries) GroupApplicationAssignmentsForGroups ¶ added in v0.147.0
func (q *Queries) GroupApplicationAssignmentsForGroups(ctx context.Context, arg GroupApplicationAssignmentsForGroupsParams) ([]GroupApplicationAssignmentsForGroupsRow, error)
func (*Queries) GroupApplicationRoleDelete ¶ added in v0.147.0
func (q *Queries) GroupApplicationRoleDelete(ctx context.Context, arg GroupApplicationRoleDeleteParams) (GroupApplicationRoleDeleteRow, error)
func (*Queries) GroupApplicationRoleName ¶ added in v0.147.0
func (*Queries) GroupApplicationRoleUpsert ¶ added in v0.147.0
func (q *Queries) GroupApplicationRoleUpsert(ctx context.Context, arg GroupApplicationRoleUpsertParams) error
func (*Queries) GroupHasOtherUsableOwner ¶ added in v0.147.0
func (q *Queries) GroupHasOtherUsableOwner(ctx context.Context, arg GroupHasOtherUsableOwnerParams) (bool, error)
Whether the group has an owner that counts, other than the subject (excluding_kind, excluding_id): a usable user, MFA-enrolled when needs_mfa, or, when owners need no MFA, an enabled application of the group itself whose registrar is usable. An application a departing user registered never stands in for that user: its authority ends with theirs (R1).
func (*Queries) GroupMembersPage ¶ added in v0.147.0
func (q *Queries) GroupMembersPage(ctx context.Context, arg GroupMembersPageParams) ([]GroupMembersPageRow, error)
GroupMembersPage lists the subjects holding a role in a group, by kind then id. live: a usable user, or an enabled application with a live control group.
func (*Queries) GroupRolesForSubjects ¶ added in v0.147.0
func (q *Queries) GroupRolesForSubjects(ctx context.Context, arg GroupRolesForSubjectsParams) ([]GroupRolesForSubjectsRow, error)
func (*Queries) GroupUserAssignmentsForGroups ¶ added in v0.147.0
func (q *Queries) GroupUserAssignmentsForGroups(ctx context.Context, arg GroupUserAssignmentsForGroupsParams) ([]GroupUserAssignmentsForGroupsRow, error)
GroupUserAssignmentsForGroups and GroupApplicationAssignmentsForGroups read, for every live target group, the subject's assignments on it and on root. An application's assignments count only while it is enabled and its control group is live.
func (*Queries) GroupUserHasRole ¶ added in v0.147.0
func (*Queries) GroupUserRoleCounts ¶ added in v0.147.0
func (q *Queries) GroupUserRoleCounts(ctx context.Context) ([]GroupUserRoleCountsRow, error)
func (*Queries) GroupUserRoleDelete ¶ added in v0.147.0
func (q *Queries) GroupUserRoleDelete(ctx context.Context, arg GroupUserRoleDeleteParams) (GroupUserRoleDeleteRow, error)
GroupUserRoleDelete and GroupApplicationRoleDelete delete the subject's assignment in a group; role, when set, must match.
func (*Queries) GroupUserRoleName ¶ added in v0.147.0
func (*Queries) GroupUserRoleUpsert ¶ added in v0.147.0
func (q *Queries) GroupUserRoleUpsert(ctx context.Context, arg GroupUserRoleUpsertParams) error
func (*Queries) GroupUserRolesForUsers ¶ added in v0.147.0
func (q *Queries) GroupUserRolesForUsers(ctx context.Context, arg GroupUserRolesForUsersParams) ([]GroupUserRolesForUsersRow, error)
func (*Queries) GroupsOfApplicationPage ¶ added in v0.147.0
func (q *Queries) GroupsOfApplicationPage(ctx context.Context, arg GroupsOfApplicationPageParams) ([]GroupsOfApplicationPageRow, error)
func (*Queries) GroupsOfUserPage ¶ added in v0.147.0
func (q *Queries) GroupsOfUserPage(ctx context.Context, arg GroupsOfUserPageParams) ([]GroupsOfUserPageRow, error)
GroupsOfUserPage and GroupsOfApplicationPage list the live groups a subject holds a role in, by persona then id.
func (*Queries) GroupsOwnedByApplication ¶ added in v0.147.0
func (*Queries) GroupsOwnedByUser ¶ added in v0.147.0
func (*Queries) IdentityPublicUsersByIDs ¶ added in v0.92.0
func (q *Queries) IdentityPublicUsersByIDs(ctx context.Context, ids []string) ([]IdentityPublicUsersByIDsRow, error)
The PUBLIC-safe display projection (#268): no email column is selected, so a caller cannot leak one by forgetting a tag. Soft-deleted rows ARE returned — the Go layer tombstones them — so a reference to a deleted author resolves to a stable placeholder instead of silently vanishing.
func (*Queries) ImportHeldProviders ¶ added in v0.147.0
func (q *Queries) ImportHeldProviders(ctx context.Context, arg ImportHeldProvidersParams) ([]ImportHeldProvidersRow, error)
The identities some account holds, verified or not.
func (*Queries) ImportHitsByEmail ¶ added in v0.147.0
func (*Queries) ImportHitsByID ¶ added in v0.147.0
The ImportHits* reads share one row shape: the matched key, the account, and whether it is deleted, the key verified on it, or a name reserved for a purged account.
func (*Queries) ImportHitsByName ¶ added in v0.147.0
func (q *Queries) ImportHitsByName(ctx context.Context, arg ImportHitsByNameParams) ([]ImportHitsByNameRow, error)
A canonical name or a live alias.
func (*Queries) ImportHitsByPhone ¶ added in v0.147.0
func (*Queries) ImportInsertPasswords ¶ added in v0.147.0
func (q *Queries) ImportInsertPasswords(ctx context.Context, arg ImportInsertPasswordsParams) error
func (*Queries) ImportInsertProviders ¶ added in v0.147.0
func (q *Queries) ImportInsertProviders(ctx context.Context, arg ImportInsertProvidersParams) (int64, error)
An empty provider slug or provider email is stored as NULL.
func (*Queries) ImportInsertUsers ¶ added in v0.147.0
users is a JSON array of users rows (column-named keys; a missing key is NULL). A row losing a uniqueness race to another writer is not returned.
func (*Queries) ImportMergePassword ¶ added in v0.147.0
func (q *Queries) ImportMergePassword(ctx context.Context, arg ImportMergePasswordParams) error
func (*Queries) ImportMergeUser ¶ added in v0.147.0
func (q *Queries) ImportMergeUser(ctx context.Context, arg ImportMergeUserParams) error
func (*Queries) ImportReleaseAliases ¶ added in v0.147.0
func (q *Queries) ImportReleaseAliases(ctx context.Context, arg ImportReleaseAliasesParams) error
ImportUsers: bulk account import, one chunk per transaction. Expired aliases of the chunk's names neither match nor block.
func (*Queries) ImportSetBannedBy ¶ added in v0.147.0
func (q *Queries) ImportSetBannedBy(ctx context.Context, arg ImportSetBannedByParams) error
Records who banned imported accounts; a banner that is no account leaves banned_by NULL.
func (*Queries) InvitationsByGroup ¶ added in v0.147.0
func (q *Queries) InvitationsByGroup(ctx context.Context, arg InvitationsByGroupParams) ([]InvitationsByGroupRow, error)
InvitationsByGroup lists a group's invite links and email invitations, newest first, never a code hash. In the root group (root) it includes the plain registration invites, which have no group.
func (*Queries) InviteLinkByCodeForUpdate ¶ added in v0.147.0
func (q *Queries) InviteLinkByCodeForUpdate(ctx context.Context, arg InviteLinkByCodeForUpdateParams) (InviteLinkByCodeForUpdateRow, error)
func (*Queries) InviteLinkForRevoke ¶ added in v0.147.0
func (q *Queries) InviteLinkForRevoke(ctx context.Context, arg InviteLinkForRevokeParams) (InviteLinkForRevokeRow, error)
func (*Queries) InviteLinkGroupByCode ¶ added in v0.147.0
func (*Queries) InviteLinkInsert ¶ added in v0.147.0
func (q *Queries) InviteLinkInsert(ctx context.Context, arg InviteLinkInsertParams) (InviteLinkInsertRow, error)
An issuer is the system (NULL) or a usable account: a credential never outlives its issuer's authority.
func (*Queries) InviteLinkRedeem ¶ added in v0.147.0
func (*Queries) InviteLinkRetire ¶ added in v0.147.0
func (*Queries) InviteLinksDeleteExpiredBatch ¶ added in v0.147.0
func (q *Queries) InviteLinksDeleteExpiredBatch(ctx context.Context, arg InviteLinksDeleteExpiredBatchParams) error
Maintenance sweep of terminal credentials, retained for inspection until cutoff. Each call deletes one bounded batch, locking only that batch (SKIP LOCKED) so concurrent sweeps make progress.
func (*Queries) InviteLinksRevokeInvitedBy ¶ added in v0.147.0
Group invite links and account registration invites.
func (*Queries) MFAClearDefaultFactors ¶ added in v0.56.0
func (*Queries) MFAConsumeBackupCode ¶ added in v0.63.0
func (q *Queries) MFAConsumeBackupCode(ctx context.Context, arg MFAConsumeBackupCodeParams) (int64, error)
Atomic single-use consume: removes the hashed code and reports rows affected. 1 = this caller consumed it; 0 = code absent / already used / 2FA disabled. The `= ANY(...)` guard makes the test-and-remove a single statement so concurrent submissions of the same code cannot both succeed.
func (*Queries) MFAConsumeFactorTOTPStep ¶ added in v0.56.0
func (*Queries) MFADeleteAllFactors ¶ added in v0.56.0
func (*Queries) MFADeleteFactor ¶ added in v0.56.0
func (*Queries) MFADisable ¶ added in v0.56.0
Two-factor queries.
#125: factors are hard-deleted (no per-factor `enabled` flag). mfa_settings holds only the account-level gate (`enabled`) + `backup_codes`; per-factor data (method/phone/totp_secret/last_totp_step) lives ONLY on mfa_factors.
func (*Queries) MFAInsertFactor ¶ added in v0.98.0
func (*Queries) MFAListFactorsByUser ¶ added in v0.56.0
func (*Queries) MFALockUser ¶ added in v0.98.0
func (*Queries) MFAResetSettings ¶ added in v0.147.0
Disables 2FA and drops the backup codes.
func (*Queries) MFASetBackupCodes ¶ added in v0.56.0
func (q *Queries) MFASetBackupCodes(ctx context.Context, arg MFASetBackupCodesParams) error
func (*Queries) MFASetDefaultFactor ¶ added in v0.56.0
func (*Queries) MFASetEmailFactorAddress ¶ added in v0.147.0
func (q *Queries) MFASetEmailFactorAddress(ctx context.Context, arg MFASetEmailFactorAddressParams) error
func (*Queries) MFASettingsByUser ¶ added in v0.56.0
func (*Queries) MFASettingsDelete ¶ added in v0.147.0
func (*Queries) MFAUpsertSettings ¶ added in v0.56.0
func (q *Queries) MFAUpsertSettings(ctx context.Context, arg MFAUpsertSettingsParams) error
func (*Queries) MigrationSchemaHasUsers ¶ added in v0.147.0
func (*Queries) NameClaimAliasesByUser ¶ added in v0.147.0
func (q *Queries) NameClaimAliasesByUser(ctx context.Context, arg NameClaimAliasesByUserParams) ([]NameClaimAliasesByUserRow, error)
func (*Queries) NameClaimCanonical ¶ added in v0.147.0
func (q *Queries) NameClaimCanonical(ctx context.Context, arg NameClaimCanonicalParams) error
func (*Queries) NameClaimDeleteOwned ¶ added in v0.147.0
func (q *Queries) NameClaimDeleteOwned(ctx context.Context, arg NameClaimDeleteOwnedParams) error
func (*Queries) NameClaimRetire ¶ added in v0.147.0
func (q *Queries) NameClaimRetire(ctx context.Context, arg NameClaimRetireParams) error
The canonical name becomes an alias until expires_at (NULL: kept for good).
func (*Queries) NameClaimTaken ¶ added in v0.147.0
func (*Queries) NameClaimsDeleteExpired ¶ added in v0.98.0
func (*Queries) NameClaimsLock ¶ added in v0.147.0
Takes the names' stripe locks in stripe order, so opposite renames cannot deadlock.
func (*Queries) PasskeyDelete ¶ added in v0.147.0
func (*Queries) PasskeyExistsForRP ¶ added in v0.147.0
func (*Queries) PasskeyHandleByUser ¶ added in v0.147.0
func (*Queries) PasskeyHandleUpsert ¶ added in v0.147.0
func (q *Queries) PasskeyHandleUpsert(ctx context.Context, arg PasskeyHandleUpsertParams) ([]byte, error)
A concurrent first registration keeps the handle already stored.
func (*Queries) PasskeyHandleUser ¶ added in v0.147.0
func (*Queries) PasskeyInsert ¶ added in v0.147.0
func (q *Queries) PasskeyInsert(ctx context.Context, arg PasskeyInsertParams) (UserPasskey, error)
func (*Queries) PasskeyLiveForUpdate ¶ added in v0.147.0
func (*Queries) PasskeyRecordUse ¶ added in v0.147.0
func (*Queries) PasskeyRename ¶ added in v0.147.0
func (*Queries) PasskeysByUser ¶ added in v0.147.0
func (q *Queries) PasskeysByUser(ctx context.Context, arg PasskeysByUserParams) ([]UserPasskey, error)
The user's live passkeys for one relying party.
func (*Queries) PasskeysDeleteByUser ¶ added in v0.147.0
Passkey queries.
func (*Queries) PermissionGroupDelete ¶ added in v0.147.0
func (*Queries) PermissionGroupEnsureRoot ¶ added in v0.147.0
DO NOTHING keeps a concurrent singleton insert from aborting the caller's transaction; no row means another transaction created root.
func (*Queries) PermissionGroupForUpdate ¶ added in v0.147.0
func (*Queries) PermissionGroupInsert ¶ added in v0.147.0
Permission groups and their role assignments. A group read selects the whole row, so every group read returns db.PermissionGroup. Role tables are one per subject kind, so every assignment statement has a user and an application variant.
func (*Queries) PermissionGroupInsertWithID ¶ added in v0.147.0
func (q *Queries) PermissionGroupInsertWithID(ctx context.Context, arg PermissionGroupInsertWithIDParams) error
func (*Queries) PermissionGroupLiveForUpdate ¶ added in v0.147.0
func (q *Queries) PermissionGroupLiveForUpdate(ctx context.Context, id string) (PermissionGroup, error)
PermissionGroupLiveForUpdate is the shared lifecycle lock of a live group.
func (*Queries) PermissionGroupOwnerCount ¶ added in v0.147.0
PermissionGroupOwnerCount counts usable user owners and enabled application owners of the group itself.
func (*Queries) PermissionGroupRootID ¶ added in v0.147.0
func (*Queries) PermissionGroupSoftDelete ¶ added in v0.147.0
func (q *Queries) PermissionGroupSoftDelete(ctx context.Context, arg PermissionGroupSoftDeleteParams) error
func (*Queries) PermissionGroupsByIDs ¶ added in v0.147.0
func (*Queries) PermissionGroupsPage ¶ added in v0.147.0
func (q *Queries) PermissionGroupsPage(ctx context.Context, arg PermissionGroupsPageParams) ([]PermissionGroup, error)
PermissionGroupsPage lists non-root groups oldest first. ownerless keeps live groups no owner counts for under the last-owner rule: a usable user (MFA-enrolled in an mfa_personas group), or, where owners need no MFA, an enabled application of the group itself whose registrar is usable.
func (*Queries) ProviderLinkByIssuer ¶
func (q *Queries) ProviderLinkByIssuer(ctx context.Context, arg ProviderLinkByIssuerParams) (ProviderLinkByIssuerRow, error)
func (*Queries) ProviderLinkByIssuerAny ¶ added in v0.97.1
func (q *Queries) ProviderLinkByIssuerAny(ctx context.Context, arg ProviderLinkByIssuerAnyParams) (ProviderLinkByIssuerAnyRow, error)
func (*Queries) RemoteApplicationAuthority ¶ added in v0.147.0
func (q *Queries) RemoteApplicationAuthority(ctx context.Context, id string) (RemoteApplicationAuthorityRow, error)
An enabled application in a live group, whose registrar (if a group registered it) is usable.
func (*Queries) RemoteApplicationByID ¶ added in v0.147.0
func (*Queries) RemoteApplicationByIDForUpdate ¶ added in v0.147.0
func (*Queries) RemoteApplicationByIssuer ¶ added in v0.27.0
func (*Queries) RemoteApplicationControlRoles ¶ added in v0.147.0
func (q *Queries) RemoteApplicationControlRoles(ctx context.Context, remoteApplicationID string) ([]RemoteApplicationControlRolesRow, error)
The roles an application holds in live groups.
func (*Queries) RemoteApplicationDelete ¶ added in v0.27.0
func (*Queries) RemoteApplicationEnabledInGroup ¶ added in v0.147.0
func (*Queries) RemoteApplicationSetRegistrar ¶ added in v0.147.0
func (q *Queries) RemoteApplicationSetRegistrar(ctx context.Context, arg RemoteApplicationSetRegistrarParams) error
The registrar's app becomes the registration's.
func (*Queries) RemoteApplicationSetTrustRoot ¶ added in v0.147.0
func (q *Queries) RemoteApplicationSetTrustRoot(ctx context.Context, arg RemoteApplicationSetTrustRootParams) error
func (*Queries) RemoteApplicationUpsert ¶ added in v0.27.0
func (q *Queries) RemoteApplicationUpsert(ctx context.Context, arg RemoteApplicationUpsertParams) (RemoteApplication, error)
Remote application registry. A remote_application is the federation PRINCIPAL: it authenticates by signing JWTs verified against its JWKS/public keys (#74).
The controlling group is addressed as permission_group_id throughout. Every read returns the whole row: db.RemoteApplication.
func (*Queries) RemoteApplicationUsable ¶ added in v0.147.0
func (*Queries) RemoteApplicationsByGroup ¶ added in v0.147.0
func (q *Queries) RemoteApplicationsByGroup(ctx context.Context, arg RemoteApplicationsByGroupParams) ([]RemoteApplication, error)
Newest first, keyset-paged by id.
func (*Queries) RemoteApplicationsClearRegistrar ¶ added in v0.147.0
func (*Queries) RemoteApplicationsEnabled ¶ added in v0.27.0
func (q *Queries) RemoteApplicationsEnabled(ctx context.Context) ([]RemoteApplication, error)
func (*Queries) ResolveUsername ¶ added in v0.98.0
func (q *Queries) ResolveUsername(ctx context.Context, arg ResolveUsernameParams) (ResolveUsernameRow, error)
func (*Queries) RiverIdentityProbeLock ¶ added in v0.147.0
func (q *Queries) RiverIdentityProbeLock(ctx context.Context, arg RiverIdentityProbeLockParams) (RiverIdentityProbeLockRow, error)
River database identity witness (requireSameRiverDatabase): the producer pool takes two random transaction advisory locks; the worker pool must see them held by that backend in the same database.
func (*Queries) RiverIdentityProbeSeen ¶ added in v0.147.0
func (*Queries) RoleCatalogFingerprint ¶ added in v0.147.0
Each app's role catalog as its credential sweep last reconciled it, and the fleets that sweep the credentials of the other apps sharing the accounts.
func (*Queries) RoleCatalogSet ¶ added in v0.147.0
func (q *Queries) RoleCatalogSet(ctx context.Context, arg RoleCatalogSetParams) error
func (*Queries) RoleCatalogsDeclaredRoles ¶ added in v0.147.0
func (q *Queries) RoleCatalogsDeclaredRoles(ctx context.Context, issuers []string) ([]string, error)
The persona:role names the catalogs of issuers declare.
func (*Queries) RuntimeAccessLock ¶ added in v0.147.0
Shared with OpenRails: ACL writes can touch the same public objects.
func (*Queries) RuntimeIdentity ¶ added in v0.147.0
func (q *Queries) RuntimeIdentity(ctx context.Context) (RuntimeIdentityRow, error)
func (*Queries) SessionByCurrentTokenHash ¶
func (q *Queries) SessionByCurrentTokenHash(ctx context.Context, arg SessionByCurrentTokenHashParams) (SessionByCurrentTokenHashRow, error)
func (*Queries) SessionByHistoricalTokenHash ¶ added in v0.98.0
func (q *Queries) SessionByHistoricalTokenHash(ctx context.Context, arg SessionByHistoricalTokenHashParams) (SessionByHistoricalTokenHashRow, error)
Every consumed token stays attributable for the session lifetime. Only the immediate predecessor can open the current grace seal; older hashes still identify the family for reuse detection.
func (*Queries) SessionEventInsert ¶ added in v0.81.0
func (q *Queries) SessionEventInsert(ctx context.Context, arg SessionEventInsertParams) error
Session-event history queries (#245). Best-effort append-only log: sign-ins, revocations, password changes. Retention-pruned.
func (*Queries) SessionEventsByUser ¶ added in v0.147.0
func (q *Queries) SessionEventsByUser(ctx context.Context, arg SessionEventsByUserParams) ([]SessionEvent, error)
One page of an account's history, newest first, after the (after_at, after_id) keyset cursor when after_at is set; no kinds means every kind.
func (*Queries) SessionEventsPruneBatch ¶ added in v0.81.0
func (q *Queries) SessionEventsPruneBatch(ctx context.Context, arg SessionEventsPruneBatchParams) (int64, error)
One bounded retention batch: delete up to batch_size rows older than cutoff, walking the occurred_at index. Callers loop until a short batch — never an unbounded single DELETE.
func (*Queries) SessionFreshSince ¶
func (q *Queries) SessionFreshSince(ctx context.Context, arg SessionFreshSinceParams) (SessionFreshSinceRow, error)
func (*Queries) SessionFreshSinceForUpdate ¶ added in v0.100.0
func (q *Queries) SessionFreshSinceForUpdate(ctx context.Context, arg SessionFreshSinceForUpdateParams) (SessionFreshSinceForUpdateRow, error)
func (*Queries) SessionInsert ¶
func (q *Queries) SessionInsert(ctx context.Context, arg SessionInsertParams) (SessionInsertRow, error)
Refresh-session queries.
func (*Queries) SessionMarkAuthenticated ¶
func (q *Queries) SessionMarkAuthenticated(ctx context.Context, arg SessionMarkAuthenticatedParams) (int64, error)
Re-proving identity refreshes the freshness window and UNIONS the methods just used into what the session proved, so its refresh assurance never drops. MFA freshness moves only when these methods include the second factor.
func (*Queries) SessionProvedPassword ¶ added in v0.147.0
func (q *Queries) SessionProvedPassword(ctx context.Context, arg SessionProvedPasswordParams) (bool, error)
Whether the user's live session session_id signed in with a password.
func (*Queries) SessionRevokeByIDForUser ¶
func (*Queries) SessionRotate ¶
Record the consumed hash and rotate in one statement. The CAS admits one writer; an insertion failure rolls back the rotation, and a lost CAS inserts no history. The row's latest seal still re-delivers the same successor to concurrent holders of the immediate predecessor.
func (*Queries) SessionsCountActive ¶
func (*Queries) SessionsCountActiveOutsideIssuers ¶ added in v0.102.0
func (q *Queries) SessionsCountActiveOutsideIssuers(ctx context.Context, arg SessionsCountActiveOutsideIssuersParams) (int64, error)
Live sessions an account-wide revocation could not reach: issuers missing from the configured account issuer set.
func (*Queries) SessionsDeleteRevokedOrExpiredBatch ¶ added in v0.98.0
func (q *Queries) SessionsDeleteRevokedOrExpiredBatch(ctx context.Context, batchSize int64) (int64, error)
One bounded GC batch (#325): collect up to batch_size dead sessions through the two partial indexes (revoked / expired), then delete them by tuple id so the outer step is a Tid Scan, never a table scan. Callers loop until a short batch. History rows cascade.
func (*Queries) SessionsEvictOldest ¶
func (*Queries) SessionsListByUser ¶
func (q *Queries) SessionsListByUser(ctx context.Context, arg SessionsListByUserParams) ([]SessionsListByUserRow, error)
last_authenticated_at and revoked_at are intentionally NOT selected: the session-list handler never renders them, and revoked_at is always NULL here (the WHERE clause filters to non-revoked rows), so reading them was pure over-fetch (#230).
func (*Queries) SessionsRevokeAll ¶
func (q *Queries) SessionsRevokeAll(ctx context.Context, arg SessionsRevokeAllParams) ([]SessionsRevokeAllRow, error)
issuers is the revocation scope: this issuer alone, or every account issuer. keep_session_id (optional) survives, e.g. the session changing the password.
func (*Queries) SessionsRevokeFamily ¶
func (*Queries) SetSearchPath ¶ added in v0.147.0
func (q *Queries) SetSearchPath(ctx context.Context, arg SetSearchPathParams) error
Connection setup, migrations and runtime-role provisioning. The schema identifiers in CREATE SCHEMA and the GRANTs stay inline in the engine. is_local false sets it for the session, true until the transaction (or savepoint) ends.
func (*Queries) StatementTimestamp ¶ added in v0.147.0
Account deletion lifecycle: the recovery window (account_deletions), the per-issuer delivery receipts River works off, and each issuer's River fleet.
func (*Queries) TransactionSettings ¶ added in v0.147.0
func (q *Queries) TransactionSettings(ctx context.Context) (TransactionSettingsRow, error)
Authority: the lock and transaction settings of authority mutations, group and actor resolution, ownership invariants and the credential sweep. A usable account is a row of usable_users; an application's registrar counts only while usable.
func (*Queries) UserAdvanceCredentialVersion ¶ added in v0.100.0
func (*Queries) UserApplyEmailChange ¶
func (q *Queries) UserApplyEmailChange(ctx context.Context, arg UserApplyEmailChangeParams) error
func (*Queries) UserApplyPhoneChange ¶
func (q *Queries) UserApplyPhoneChange(ctx context.Context, arg UserApplyPhoneChangeParams) error
func (*Queries) UserBanInForce ¶ added in v0.147.0
func (*Queries) UserByEmail ¶
func (*Queries) UserByID ¶
User-row queries. A user read selects the whole row, so every read returns db.User: the engine's one user type.
func (*Queries) UserByPhone ¶
func (*Queries) UserByUsername ¶
func (*Queries) UserCredentialVersion ¶ added in v0.100.0
func (*Queries) UserCredentialVersionForUpdate ¶ added in v0.100.0
func (q *Queries) UserCredentialVersionForUpdate(ctx context.Context, id string) (UserCredentialVersionForUpdateRow, error)
All credential changes acquire this account lock before credential/session rows.
func (*Queries) UserDeleteHard ¶
func (*Queries) UserEmailOrUsernameTaken ¶
func (q *Queries) UserEmailOrUsernameTaken(ctx context.Context, arg UserEmailOrUsernameTakenParams) (UserEmailOrUsernameTakenRow, error)
func (*Queries) UserExists ¶ added in v0.147.0
func (*Queries) UserGroupRoles ¶ added in v0.147.0
Every role the user holds, with its group's persona.
func (*Queries) UserHasPassword ¶
func (*Queries) UserImportInsert ¶
func (q *Queries) UserImportInsert(ctx context.Context, arg UserImportInsertParams) error
func (*Queries) UserImportUpdate ¶
func (*Queries) UserInsert ¶
func (*Queries) UserIsReserved ¶
Owner-namespace queries.
Permission groups own group-scoped routing now. The reserved-account guard is users.metadata->>'reserved' (UserIsReserved); rename history is not authority.
func (*Queries) UserLastRenamedAt ¶
func (*Queries) UserMetadata ¶
Reserved-account + metadata queries.
func (*Queries) UserNameForUpdate ¶ added in v0.147.0
func (*Queries) UserNotDeleted ¶ added in v0.147.0
func (*Queries) UserPasswordDelete ¶
func (*Queries) UserPasswordInsert ¶
func (q *Queries) UserPasswordInsert(ctx context.Context, arg UserPasswordInsertParams) error
func (*Queries) UserPasswordRehash ¶ added in v0.100.0
func (q *Queries) UserPasswordRehash(ctx context.Context, arg UserPasswordRehashParams) error
Opportunistic rehash cannot overwrite a password changed after verification.
func (*Queries) UserPasswordRow ¶
func (*Queries) UserPasswordUpsert ¶
func (q *Queries) UserPasswordUpsert(ctx context.Context, arg UserPasswordUpsertParams) error
func (*Queries) UserPatchMetadata ¶ added in v0.147.0
func (q *Queries) UserPatchMetadata(ctx context.Context, arg UserPatchMetadataParams) error
Merges patch into the metadata and removes drop_keys.
func (*Queries) UserPhoneOrUsernameTaken ¶
func (q *Queries) UserPhoneOrUsernameTaken(ctx context.Context, arg UserPhoneOrUsernameTakenParams) (UserPhoneOrUsernameTakenRow, error)
func (*Queries) UserPreferredLanguage ¶ added in v0.54.0
func (*Queries) UserProviderByIssuerAny ¶ added in v0.97.1
func (q *Queries) UserProviderByIssuerAny(ctx context.Context, arg UserProviderByIssuerAnyParams) (UserProviderByIssuerAnyRow, error)
func (*Queries) UserProviderCountForUpdate ¶ added in v0.72.0
Locks the user's provider rows (FOR UPDATE in the inner query) and returns the count, so a concurrent unlink for the same user serializes behind this lock — closing the last-credential TOCTOU. Must run inside a transaction.
func (*Queries) UserProviderDeleteBySlug ¶
func (q *Queries) UserProviderDeleteBySlug(ctx context.Context, arg UserProviderDeleteBySlugParams) error
func (*Queries) UserProviderImportUnverified ¶ added in v0.97.1
func (q *Queries) UserProviderImportUnverified(ctx context.Context, arg UserProviderImportUnverifiedParams) (UserProviderImportUnverifiedRow, error)
func (*Queries) UserProviderLinkExists ¶
func (q *Queries) UserProviderLinkExists(ctx context.Context, arg UserProviderLinkExistsParams) (bool, error)
HTTP-layer provider lookups (http/step_up.go, http/user_me_get.go).
func (*Queries) UserProviderMergeProfile ¶
func (q *Queries) UserProviderMergeProfile(ctx context.Context, arg UserProviderMergeProfileParams) error
func (*Queries) UserProviderProofSource ¶ added in v0.147.0
func (*Queries) UserProviderSetUsername ¶
func (q *Queries) UserProviderSetUsername(ctx context.Context, arg UserProviderSetUsernameParams) error
func (*Queries) UserProviderSlugsDistinct ¶
func (*Queries) UserProviderSubjectProfileByIssuer ¶
func (q *Queries) UserProviderSubjectProfileByIssuer(ctx context.Context, arg UserProviderSubjectProfileByIssuerParams) (UserProviderSubjectProfileByIssuerRow, error)
func (*Queries) UserProviderUnverifiedForUpdate ¶ added in v0.97.1
func (*Queries) UserProviderUpsertByIssuer ¶
func (q *Queries) UserProviderUpsertByIssuer(ctx context.Context, arg UserProviderUpsertByIssuerParams) (UserProviderUpsertByIssuerRow, error)
func (*Queries) UserProviderVerifiedLink ¶ added in v0.147.0
func (q *Queries) UserProviderVerifiedLink(ctx context.Context, arg UserProviderVerifiedLinkParams) (UserProviderVerifiedLinkRow, error)
What a provider sign-in proves: the account's credential version and the verified link.
func (*Queries) UserProviderVerifyImported ¶ added in v0.97.1
func (*Queries) UserProvidersDeleteByUser ¶
func (*Queries) UserRename ¶ added in v0.147.0
func (q *Queries) UserRename(ctx context.Context, arg UserRenameParams) error
func (*Queries) UserRestore ¶
Clearing deleted_at fires the credential-version trigger, like deletion.
func (*Queries) UserSessionLive ¶ added in v0.147.0
func (q *Queries) UserSessionLive(ctx context.Context, arg UserSessionLiveParams) (UserSessionLiveRow, error)
The session check (#412): whether the account is usable, and whether the sign-in it names (session_id or device_key_id; ” = none) is still a live refresh session or device key of the account.
func (*Queries) UserSetAvatarURL ¶ added in v0.90.0
func (q *Queries) UserSetAvatarURL(ctx context.Context, arg UserSetAvatarURLParams) error
func (*Queries) UserSetEmail ¶ added in v0.147.0
func (q *Queries) UserSetEmail(ctx context.Context, arg UserSetEmailParams) error
A new address is unverified; setting the current one changes nothing.
func (*Queries) UserSetEmailVerified ¶
func (q *Queries) UserSetEmailVerified(ctx context.Context, arg UserSetEmailVerifiedParams) error
func (*Queries) UserSetEmailVerifiedIfPresent ¶ added in v0.147.0
func (q *Queries) UserSetEmailVerifiedIfPresent(ctx context.Context, arg UserSetEmailVerifiedIfPresentParams) (int64, error)
Verifying needs an address; no row changes without one.
func (*Queries) UserSetLastLogin ¶
func (q *Queries) UserSetLastLogin(ctx context.Context, arg UserSetLastLoginParams) error
func (*Queries) UserSetPhone ¶ added in v0.147.0
func (q *Queries) UserSetPhone(ctx context.Context, arg UserSetPhoneParams) error
func (*Queries) UserSetPhoneVerifiedByIDAndPhone ¶
func (q *Queries) UserSetPhoneVerifiedByIDAndPhone(ctx context.Context, arg UserSetPhoneVerifiedByIDAndPhoneParams) error
func (*Queries) UserSetPhoneVerifiedIfPresent ¶ added in v0.147.0
func (*Queries) UserSetPreferredLanguage ¶ added in v0.54.0
func (q *Queries) UserSetPreferredLanguage(ctx context.Context, arg UserSetPreferredLanguageParams) error
func (*Queries) UserSetUsernameSpelling ¶ added in v0.147.0
func (q *Queries) UserSetUsernameSpelling(ctx context.Context, arg UserSetUsernameSpellingParams) error
Same name, new display spelling: no name claim, alias or cooldown.
func (*Queries) UserSoftDelete ¶
func (*Queries) UserUsable ¶ added in v0.147.0
func (*Queries) UsersByIDs ¶ added in v0.147.0
type RemoteApplication ¶ added in v0.147.0
type RemoteApplication struct {
ID string
Issuer string
JwksUri string
Mode string
PublicKeys []byte
Enabled bool
CreatedAt time.Time
UpdatedAt time.Time
// Required controlling permission-group. Authority comes from group_remote_application_roles on it and on root.
PermissionGroupID string
// What changes the keys: manual (the system) | user (a credentials manager of the controlling group). Never the keypair alone.
TrustRoot string
// The user who supplied the keys of a group registration; NULL = the operator.
RegisteredBy *string
// The Token.Issuer of the app its registrar registered it through; only its role catalog judges the application's roles. NULL = every app does.
CatalogIssuer *string
}
Federation principals: external systems that authenticate by signing JWTs verified against configured keys.
type RemoteApplicationAuthorityRow ¶ added in v0.147.0
type RemoteApplicationControlRolesRow ¶ added in v0.147.0
type RemoteApplicationEnabledInGroupParams ¶ added in v0.147.0
type RemoteApplicationSetRegistrarParams ¶ added in v0.147.0
type RemoteApplicationSetTrustRootParams ¶ added in v0.147.0
type RemoteApplicationUpsertParams ¶ added in v0.27.0
type RemoteApplicationsByGroupParams ¶ added in v0.147.0
type ResolveUsernameParams ¶ added in v0.98.0
type ResolveUsernameRow ¶ added in v0.98.0
type RiverIdentityProbeLockParams ¶ added in v0.147.0
type RiverIdentityProbeLockRow ¶ added in v0.147.0
type RiverIdentityProbeSeenParams ¶ added in v0.147.0
type RoleCatalogSetParams ¶ added in v0.147.0
type RuntimeIdentityRow ¶ added in v0.147.0
type SessionByHistoricalTokenHashParams ¶ added in v0.98.0
type SessionByHistoricalTokenHashRow ¶ added in v0.98.0
type SessionEvent ¶ added in v0.147.0
type SessionEventInsertParams ¶ added in v0.81.0
type SessionEventsByUserParams ¶ added in v0.147.0
type SessionEventsPruneBatchParams ¶ added in v0.81.0
type SessionFreshSinceForUpdateParams ¶ added in v0.100.0
type SessionFreshSinceForUpdateRow ¶ added in v0.100.0
type SessionFreshSinceParams ¶
type SessionFreshSinceRow ¶ added in v0.52.0
type SessionInsertParams ¶
type SessionInsertRow ¶
type SessionProvedPasswordParams ¶ added in v0.147.0
type SessionRotateParams ¶
type SessionsCountActiveOutsideIssuersParams ¶ added in v0.102.0
type SessionsListByUserRow ¶
type SessionsRevokeAllParams ¶
type SessionsRevokeAllRow ¶ added in v0.102.0
type SessionsRevokeFamilyRow ¶
type SetSearchPathParams ¶ added in v0.147.0
type TransactionSettingsRow ¶ added in v0.147.0
type User ¶ added in v0.147.0
type User struct {
ID string
Email *string
Username *string
EmailVerified bool
// E.164 format phone number (e.g. +14155551234)
PhoneNumber *string
// Whether the phone number has been verified via SMS code
PhoneVerified bool
// When the user was banned
BannedAt *time.Time
// When a temporary ban expires (NULL for permanent)
BannedUntil *time.Time
// Reason for ban
BanReason *string
// User ID of admin who imposed ban
BannedBy *string
DeletedAt *time.Time
// Arbitrary user metadata (internal/admin flags such as reserved)
Metadata []byte
CreatedAt time.Time
UpdatedAt time.Time
LastLogin *time.Time
// User communication/auth language, e.g. en, es, de, ko, zh
PreferredLanguage *string
// Host-supplied avatar URL/key string; blob storage is host-owned
AvatarURL *string
LastRenamedAt *time.Time
CredentialVersion int64
}
type UserBanParams ¶
type UserCredentialVersionForUpdateRow ¶ added in v0.100.0
type UserCredentialVersionRow ¶ added in v0.100.0
type UserDeviceKey ¶ added in v0.147.0
type UserDeviceKey struct {
ID string
UserID string
PublicKey []byte
Label *string
CreatedAt time.Time
LastUsedAt *time.Time
RevokedAt *time.Time
MfaProvenAt *time.Time
}
Ed25519 public keys for native clients. Revoked rows remain tombstones and cannot be re-enrolled.
type UserGroupRolesRow ¶ added in v0.147.0
type UserImportInsertParams ¶
type UserImportUpdateParams ¶
type UserInsertParams ¶
type UserNameForUpdateRow ¶ added in v0.147.0
type UserPasskey ¶ added in v0.147.0
type UserPasskey struct {
ID string
UserID string
Rpid string
CredentialID []byte
PublicKey []byte
SignCount int64
CloneWarning bool
Aaguid []byte
Transports []string
AuthenticatorAttachment string
Flags []byte
AttestationType string
AttestationFmt string
Label *string
CreatedAt time.Time
LastUsedAt *time.Time
DeletedAt *time.Time
}
type UserPasswordRehashParams ¶ added in v0.100.0
type UserPasswordRowRow ¶
type UserPatchMetadataParams ¶ added in v0.147.0
type UserProviderByIssuerAnyParams ¶ added in v0.97.1
type UserProviderByIssuerAnyRow ¶ added in v0.97.1
type UserProviderImportUnverifiedParams ¶ added in v0.97.1
type UserProviderImportUnverifiedRow ¶ added in v0.97.1
type UserProviderProofSourceParams ¶ added in v0.147.0
type UserProviderUnverifiedForUpdateParams ¶ added in v0.97.1
type UserProviderUpsertByIssuerRow ¶ added in v0.72.0
type UserProviderVerifiedLinkParams ¶ added in v0.147.0
type UserProviderVerifiedLinkRow ¶ added in v0.147.0
type UserProviderVerifyImportedParams ¶ added in v0.97.1
type UserRenameParams ¶ added in v0.147.0
type UserSessionLiveParams ¶ added in v0.147.0
type UserSessionLiveRow ¶ added in v0.147.0
type UserSetAvatarURLParams ¶ added in v0.90.0
type UserSetEmailParams ¶ added in v0.147.0
type UserSetEmailVerifiedIfPresentParams ¶ added in v0.147.0
type UserSetLastLoginParams ¶
type UserSetPhoneParams ¶ added in v0.147.0
type UserSetPhoneVerifiedIfPresentParams ¶ added in v0.147.0
type UserSetPreferredLanguageParams ¶ added in v0.54.0
Source Files
¶
- account_deletions.sql.go
- api_keys.sql.go
- authority.sql.go
- bootstrap.sql.go
- cleanup.sql.go
- db.go
- device_keys.sql.go
- ephemeral.sql.go
- events.sql.go
- identity.sql.go
- import.sql.go
- invites.sql.go
- models.go
- name_claims.sql.go
- owner_namespace.sql.go
- passkeys.sql.go
- permission_groups.sql.go
- providers.sql.go
- remote_applications.sql.go
- reserved_accounts.sql.go
- river.sql.go
- role_catalog.sql.go
- runtime.sql.go
- schema.go
- session_events.sql.go
- sessions.sql.go
- twofactor.sql.go
- users.sql.go