db

package
v0.149.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Index

Constants

View Source
const DefaultSchema = "profiles"

DefaultSchema is AuthKit's default PostgreSQL namespace.

Variables

This section is empty.

Functions

func ValidSchemaName added in v0.26.0

func ValidSchemaName(s string) bool

ValidSchemaName reports whether s is a safe PostgreSQL schema identifier.

Types

type APIKeyByLookupIDParams added in v0.148.0

type APIKeyByLookupIDParams struct {
	KeyID  string
	Issuer string
}

type APIKeyByLookupIDRow added in v0.147.0

type APIKeyByLookupIDRow struct {
	ID             string
	SecretHash     []byte
	Role           string
	ExpiresAt      *time.Time
	RevokedAt      *time.Time
	CreatorLive    bool
	GroupID        string
	Persona        string
	GroupCreatedAt time.Time
}

type APIKeyForRevokeParams added in v0.147.0

type APIKeyForRevokeParams struct {
	ID      string
	GroupID string
}

type APIKeyForRevokeRow added in v0.147.0

type APIKeyForRevokeRow struct {
	Role      string
	RevokedAt *time.Time
}

type APIKeyInsertParams added in v0.41.0

type APIKeyInsertParams struct {
	GroupID       string
	KeyID         string
	SecretHash    []byte
	Name          string
	Role          string
	CreatedBy     *string
	ExpiresAt     *time.Time
	CatalogIssuer string
}

type APIKeyInsertRow added in v0.41.0

type APIKeyInsertRow struct {
	ID        string
	CreatedAt time.Time
}

type APIKeyRoleCountsRow added in v0.147.0

type APIKeyRoleCountsRow struct {
	Persona string
	Role    string
	N       int64
}

type APIKeysByGroupParams added in v0.147.0

type APIKeysByGroupParams struct {
	GroupID   string
	After     *string
	PageLimit int64
}

type APIKeysByGroupRow added in v0.147.0

type APIKeysByGroupRow struct {
	ID                string
	PermissionGroupID string
	KeyID             string
	Name              string
	Role              string
	CreatedBy         string
	CreatedAt         time.Time
	LastUsedAt        *time.Time
	ExpiresAt         *time.Time
	RevokedAt         *time.Time
}

type APIKeysDeleteExpiredBatchParams added in v0.147.0

type APIKeysDeleteExpiredBatchParams struct {
	Cutoff    time.Time
	BatchSize int64
}

type AccountDeletion added in v0.147.0

type AccountDeletion struct {
	ID         string
	UserID     string
	DeletedAt  time.Time
	PurgeAt    time.Time
	State      string
	Recipients []string
	RestoredAt *time.Time
	PurgedAt   *time.Time
	// The user who deleted the account; NULL = the operator.
	DeletedBy *string
}

type AccountDeletionDeliveryEarlierPendingParams added in v0.147.0

type AccountDeletionDeliveryEarlierPendingParams struct {
	UserID string
	Issuer string
	ID     int64
}

type AccountDeletionDeliveryInsertParams added in v0.147.0

type AccountDeletionDeliveryInsertParams struct {
	DeletionID string
	UserID     string
	Issuer     string
	Stage      string
}

type AccountDeletionDeliveryRow added in v0.147.0

type AccountDeletionDeliveryRow struct {
	AccountDeletion AccountDeletion
	Issuer          string
	Stage           string
	CompletedAt     *time.Time
}

type AccountDeletionInsertParams added in v0.147.0

type AccountDeletionInsertParams struct {
	Recipients []string
	DeletedBy  *string
	UserID     string
}

type AccountDeletionPurgeNowRow added in v0.147.0

type AccountDeletionPurgeNowRow struct {
	ID        string
	UserID    string
	DeletedAt time.Time
	PurgeAt   time.Time
}

type AccountDeletionPurgeWindowParams added in v0.147.0

type AccountDeletionPurgeWindowParams struct {
	ID     string
	UserID string
}

type AccountDeletionPurgeWindowRow added in v0.147.0

type AccountDeletionPurgeWindowRow struct {
	Now     time.Time
	PurgeAt time.Time
}

type AccountDeletionRecoverableParams added in v0.147.0

type AccountDeletionRecoverableParams struct {
	UserID    string
	DeletedAt time.Time
}

type AccountDeletionSetDeletedByParams added in v0.147.0

type AccountDeletionSetDeletedByParams struct {
	DeletedBy *string
	UserID    string
}

type AccountDeletionsDeleteTerminalBatchParams added in v0.147.0

type AccountDeletionsDeleteTerminalBatchParams struct {
	Cutoff    time.Time
	BatchSize int64
}

type AccountDeliveryFleetInsertParams added in v0.147.0

type AccountDeliveryFleetInsertParams struct {
	Issuer      string
	RiverSchema string
}

type AccountDeliveryFleetSetEventsParams added in v0.147.0

type AccountDeliveryFleetSetEventsParams struct {
	Events bool
	Issuer string
}

type AccountDeliveryFleetSetSchemaParams added in v0.147.0

type AccountDeliveryFleetSetSchemaParams struct {
	RiverSchema string
	Issuer      string
}

type AccountEvent added in v0.147.0

type AccountEvent struct {
	ID            int64
	Issuer        string
	Subject       string
	EventID       string
	Kind          string
	OccurredAt    time.Time
	ActorKind     string
	ActorID       string
	UserID        *string
	GroupID       *string
	Persona       string
	ApplicationID *string
	PreviousValue string
	CurrentValue  string
	Reason        string
	Until         *time.Time
	Attempts      int32
	RetryAt       *time.Time
}

type AccountEventEarlierPendingParams added in v0.147.0

type AccountEventEarlierPendingParams struct {
	Issuer  string
	Subject string
	ID      int64
}

type AccountEventEarlierPendingRow added in v0.147.0

type AccountEventEarlierPendingRow struct {
	Blocked bool
	Wait    float64
}

type AccountEventFleetsForShareRow added in v0.147.0

type AccountEventFleetsForShareRow struct {
	Issuer      string
	RiverSchema string
}

type AccountEventInsertParams added in v0.147.0

type AccountEventInsertParams struct {
	Issuer        string
	Subject       string
	EventID       string
	Kind          string
	ActorKind     string
	ActorID       string
	UserID        *string
	GroupID       *string
	Persona       string
	ApplicationID *string
	PreviousValue string
	CurrentValue  string
	Reason        string
	Until         *time.Time
}

type AccountEventRetryParams added in v0.147.0

type AccountEventRetryParams struct {
	DelaySeconds float64
	ID           int64
}

type AccountInviteByCodeForUpdateParams added in v0.147.0

type AccountInviteByCodeForUpdateParams struct {
	UserID   string
	CodeHash string
	GroupID  string
}

type AccountInviteByCodeForUpdateRow added in v0.147.0

type AccountInviteByCodeForUpdateRow struct {
	ID         string
	GroupID    string
	Persona    string
	Role       string
	ConsumedAt *time.Time
	ExpiresAt  time.Time
	RevokedAt  *time.Time
	IssuerLive bool
	Addressed  bool
}

type AccountInviteConsumeParams added in v0.147.0

type AccountInviteConsumeParams struct {
	UserID string
	ID     string
}

type AccountInviteForRevokeParams added in v0.147.0

type AccountInviteForRevokeParams struct {
	ID      string
	GroupID string
	Root    bool
}

type AccountInviteForRevokeRow added in v0.147.0

type AccountInviteForRevokeRow struct {
	Role       string
	RevokedAt  *time.Time
	ConsumedAt *time.Time
}

type AccountInviteForUpdateParams added in v0.147.0

type AccountInviteForUpdateParams struct {
	CodeHash string
	GroupID  *string
}

type AccountInviteForUpdateRow added in v0.147.0

type AccountInviteForUpdateRow struct {
	ID                string
	PermissionGroupID *string
	Role              *string
	Persona           *string
}

type AccountInviteInsertParams added in v0.147.0

type AccountInviteInsertParams struct {
	Email         string
	InvitedBy     *string
	CodeHash      string
	ExpiresAt     time.Time
	GroupID       *string
	Role          *string
	CatalogIssuer string
}

type AccountInviteInsertRow added in v0.147.0

type AccountInviteInsertRow struct {
	ID        string
	CreatedAt time.Time
}

type AccountInvitesDeleteExpiredBatchParams added in v0.147.0

type AccountInvitesDeleteExpiredBatchParams struct {
	Cutoff    time.Time
	BatchSize int64
}

type AuthorityAPIKeyRoleParams added in v0.148.0

type AuthorityAPIKeyRoleParams struct {
	ID     string
	Issuer string
}

type AuthorityAPIKeyRoleRow added in v0.147.0

type AuthorityAPIKeyRoleRow struct {
	PermissionGroupID string
	Role              string
}

type AuthorityApplicationOwnsGroupParams added in v0.147.0

type AuthorityApplicationOwnsGroupParams struct {
	GroupID       string
	ApplicationID string
}

type AuthorityApplicationOwnsGroupRow added in v0.147.0

type AuthorityApplicationOwnsGroupRow struct {
	Controls bool
	Persona  string
}

type AuthorityUncoveredCredentialsParams added in v0.147.0

type AuthorityUncoveredCredentialsParams struct {
	GroupID string
	UserID  string
	Issuer  string
}

type AuthorityUncoveredCredentialsRow added in v0.147.0

type AuthorityUncoveredCredentialsRow struct {
	Kind         string
	ID           string
	GroupID      string
	Persona      string
	Role         string
	Creator      string
	NeedsCreator bool
}

type AuthorityUserGroupsParams added in v0.147.0

type AuthorityUserGroupsParams struct {
	UserID string
	RootID string
}

type BootstrapAccountByCanonicalNameForUpdateRow added in v0.147.0

type BootstrapAccountByCanonicalNameForUpdateRow struct {
	ID      string
	Deleted bool
}

type BootstrapAccountByEmailForUpdateRow added in v0.147.0

type BootstrapAccountByEmailForUpdateRow struct {
	ID       string
	Verified bool
	Deleted  bool
}

type BootstrapAccountByIDForUpdateRow added in v0.147.0

type BootstrapAccountByIDForUpdateRow struct {
	ID       string
	Verified bool
	Deleted  bool
}

type BootstrapAccountByPhoneForUpdateRow added in v0.147.0

type BootstrapAccountByPhoneForUpdateRow struct {
	ID       string
	Verified bool
	Deleted  bool
}

type BootstrapApplyStateRow added in v0.147.0

type BootstrapApplyStateRow struct {
	NameClaimed bool
	AnyClaimed  bool
	GraphEmpty  bool
}

type ContactStateForUpdateRow added in v0.147.0

type ContactStateForUpdateRow struct {
	Unproven   bool
	Identifier string
	Channel    string
}

type ContactStateRow added in v0.147.0

type ContactStateRow struct {
	Unproven   bool
	Identifier string
	Channel    string
}

type CredentialSweepFleetsForShareRow added in v0.147.0

type CredentialSweepFleetsForShareRow struct {
	Issuer      string
	RiverSchema string
}

type DBTX

type DBTX interface {
	Exec(context.Context, string, ...interface{}) (pgconn.CommandTag, error)
	Query(context.Context, string, ...interface{}) (pgx.Rows, error)
	QueryRow(context.Context, string, ...interface{}) pgx.Row
}

type DeviceKeyEnrollUserInsertParams added in v0.147.0

type DeviceKeyEnrollUserInsertParams struct {
	ID    string
	Email string
}

type DeviceKeyInsertParams added in v0.147.0

type DeviceKeyInsertParams struct {
	UserID    string
	PublicKey []byte
	Label     *string
	MfaProven bool
}

type DeviceKeyIsActiveForUpdateParams added in v0.147.0

type DeviceKeyIsActiveForUpdateParams struct {
	ID     string
	UserID string
}

type DeviceKeyIsActiveParams added in v0.147.0

type DeviceKeyIsActiveParams struct {
	ID     string
	UserID string
}

type DeviceKeyRelabelParams added in v0.149.0

type DeviceKeyRelabelParams struct {
	Label  *string
	ID     string
	UserID string
}

type DeviceKeyRevokeParams added in v0.147.0

type DeviceKeyRevokeParams struct {
	ID     string
	UserID string
}

type DeviceKeyTouchParams added in v0.147.0

type DeviceKeyTouchParams struct {
	ID     string
	UserID string
}

type DeviceKeysRevokeAllExceptParams added in v0.147.0

type DeviceKeysRevokeAllExceptParams struct {
	UserID string
	KeepID *string
}

type EphemeralCompareAndConsumeParams added in v0.141.0

type EphemeralCompareAndConsumeParams struct {
	Key      string
	Expected []byte
}

type EphemeralIncrParams added in v0.141.0

type EphemeralIncrParams struct {
	Key   string
	TtlUs int64
}

type EphemeralSetParams added in v0.141.0

type EphemeralSetParams struct {
	Key   string
	Value []byte
	TtlUs int64
}

type GroupApplicationAssignmentsForGroupsParams added in v0.147.0

type GroupApplicationAssignmentsForGroupsParams struct {
	SubjectID string
	GroupIds  []string
}

type GroupApplicationAssignmentsForGroupsRow added in v0.147.0

type GroupApplicationAssignmentsForGroupsRow struct {
	Target  string
	GroupID string
	Persona string
	Role    string
}

type GroupApplicationRoleDeleteParams added in v0.147.0

type GroupApplicationRoleDeleteParams struct {
	GroupID       string
	ApplicationID string
	Role          *string
}

type GroupApplicationRoleDeleteRow added in v0.147.0

type GroupApplicationRoleDeleteRow struct {
	Persona string
	Role    string
}

type GroupApplicationRoleNameParams added in v0.147.0

type GroupApplicationRoleNameParams struct {
	GroupID       string
	ApplicationID string
}

type GroupApplicationRoleUpsertParams added in v0.147.0

type GroupApplicationRoleUpsertParams struct {
	GroupID       string
	ApplicationID string
	Role          string
}

type GroupHasOtherUsableOwnerParams added in v0.147.0

type GroupHasOtherUsableOwnerParams struct {
	GroupID       string
	ExcludingKind string
	ExcludingID   *string
	NeedsMfa      bool
}

type GroupMembersPageParams added in v0.147.0

type GroupMembersPageParams struct {
	GroupID   string
	Kinds     []string
	Roles     []string
	AfterKind string
	AfterID   string
	LiveOnly  bool
	PageLimit int64
}

type GroupMembersPageRow added in v0.147.0

type GroupMembersPageRow struct {
	Kind string
	ID   string
	Role string
}

type GroupRolesForSubjectsParams added in v0.147.0

type GroupRolesForSubjectsParams struct {
	GroupID        string
	UserIds        []string
	ApplicationIds []string
}

type GroupRolesForSubjectsRow added in v0.147.0

type GroupRolesForSubjectsRow struct {
	Kind      string
	SubjectID string
	Role      string
}

type GroupUserAssignmentsForGroupsParams added in v0.147.0

type GroupUserAssignmentsForGroupsParams struct {
	SubjectID string
	GroupIds  []string
}

type GroupUserAssignmentsForGroupsRow added in v0.147.0

type GroupUserAssignmentsForGroupsRow struct {
	Target  string
	GroupID string
	Persona string
	Role    string
}

type GroupUserHasRoleParams added in v0.147.0

type GroupUserHasRoleParams struct {
	GroupID string
	UserID  string
	Role    string
}

type GroupUserRoleCountsRow added in v0.147.0

type GroupUserRoleCountsRow struct {
	Persona string
	Role    string
	N       int64
}

type GroupUserRoleDeleteParams added in v0.147.0

type GroupUserRoleDeleteParams struct {
	GroupID string
	UserID  string
	Role    *string
}

type GroupUserRoleDeleteRow added in v0.147.0

type GroupUserRoleDeleteRow struct {
	Persona string
	Role    string
}

type GroupUserRoleNameParams added in v0.147.0

type GroupUserRoleNameParams struct {
	GroupID string
	UserID  string
}

type GroupUserRoleUpsertParams added in v0.147.0

type GroupUserRoleUpsertParams struct {
	GroupID string
	UserID  string
	Role    string
}

type GroupUserRolesForUsersParams added in v0.147.0

type GroupUserRolesForUsersParams struct {
	GroupID string
	UserIds []string
}

type GroupUserRolesForUsersRow added in v0.147.0

type GroupUserRolesForUsersRow struct {
	UserID string
	Role   string
}

type GroupsOfApplicationPageParams added in v0.147.0

type GroupsOfApplicationPageParams struct {
	SubjectID    string
	AfterPersona string
	AfterID      string
	PageLimit    int64
}

type GroupsOfApplicationPageRow added in v0.147.0

type GroupsOfApplicationPageRow struct {
	PermissionGroup PermissionGroup
	Role            string
}

type GroupsOfUserPageParams added in v0.147.0

type GroupsOfUserPageParams struct {
	SubjectID    string
	AfterPersona string
	AfterID      string
	PageLimit    int64
}

type GroupsOfUserPageRow added in v0.147.0

type GroupsOfUserPageRow struct {
	PermissionGroup PermissionGroup
	Role            string
}

type IdentityPublicUsersByIDsRow added in v0.92.0

type IdentityPublicUsersByIDsRow struct {
	ID        string
	Username  *string
	AvatarURL *string
	CreatedAt time.Time
	DeletedAt *time.Time
	Metadata  []byte
}

type ImportHeldProvidersParams added in v0.147.0

type ImportHeldProvidersParams struct {
	Issuers  []string
	Subjects []string
}

type ImportHeldProvidersRow added in v0.147.0

type ImportHeldProvidersRow struct {
	Issuer  string
	Subject string
}

type ImportHitsByEmailRow added in v0.147.0

type ImportHitsByEmailRow struct {
	Key      string
	UserID   string
	Deleted  bool
	Verified bool
	Missing  bool
}

type ImportHitsByIDRow added in v0.147.0

type ImportHitsByIDRow struct {
	Key      string
	UserID   string
	Deleted  bool
	Verified bool
	Missing  bool
}

type ImportHitsByNameParams added in v0.147.0

type ImportHitsByNameParams struct {
	Names []string
	Now   time.Time
}

type ImportHitsByNameRow added in v0.147.0

type ImportHitsByNameRow struct {
	Key      string
	UserID   string
	Deleted  bool
	Verified bool
	Missing  bool
}

type ImportHitsByPhoneRow added in v0.147.0

type ImportHitsByPhoneRow struct {
	Key      string
	UserID   string
	Deleted  bool
	Verified bool
	Missing  bool
}

type ImportInsertPasswordsParams added in v0.147.0

type ImportInsertPasswordsParams struct {
	UserIds        []string
	PasswordHashes []string
	HashAlgos      []string
}

type ImportInsertProvidersParams added in v0.147.0

type ImportInsertProvidersParams struct {
	UserIds          []string
	Issuers          []string
	ProviderSlugs    []string
	Subjects         []string
	EmailsAtProvider []string
}

type ImportMergePasswordParams added in v0.147.0

type ImportMergePasswordParams struct {
	UserID       string
	PasswordHash string
	HashAlgo     string
}

type ImportMergeUserParams added in v0.147.0

type ImportMergeUserParams struct {
	Metadata          []byte
	CreatedAt         time.Time
	LastLogin         *time.Time
	PreferredLanguage *string
	AvatarURL         *string
	ID                string
}

type ImportReleaseAliasesParams added in v0.147.0

type ImportReleaseAliasesParams struct {
	Names []string
	Now   time.Time
}

type ImportSetBannedByParams added in v0.147.0

type ImportSetBannedByParams struct {
	UserIds  []string
	BannedBy []string
}

type InvitationsByGroupParams added in v0.147.0

type InvitationsByGroupParams struct {
	GroupID   string
	Root      bool
	After     *string
	PageLimit int64
}

type InvitationsByGroupRow added in v0.147.0

type InvitationsByGroupRow struct {
	ID         string
	Role       string
	Email      string
	CreatedBy  string
	CreatedAt  time.Time
	ExpiresAt  *time.Time
	RedeemedAt *time.Time
	RevokedAt  *time.Time
}

type InviteLinkByCodeForUpdateParams added in v0.147.0

type InviteLinkByCodeForUpdateParams struct {
	CodeHash string
	GroupID  string
}

type InviteLinkByCodeForUpdateRow added in v0.147.0

type InviteLinkByCodeForUpdateRow struct {
	ID         string
	GroupID    string
	Persona    string
	Role       string
	RedeemedAt *time.Time
	ExpiresAt  *time.Time
	RevokedAt  *time.Time
	IssuerLive bool
}

type InviteLinkForRevokeParams added in v0.147.0

type InviteLinkForRevokeParams struct {
	ID      string
	GroupID string
}

type InviteLinkForRevokeRow added in v0.147.0

type InviteLinkForRevokeRow struct {
	Role       string
	RevokedAt  *time.Time
	RedeemedAt *time.Time
}

type InviteLinkInsertParams added in v0.147.0

type InviteLinkInsertParams struct {
	GroupID       string
	Role          string
	InvitedBy     *string
	CodeHash      string
	ExpiresAt     time.Time
	CatalogIssuer string
}

type InviteLinkInsertRow added in v0.147.0

type InviteLinkInsertRow struct {
	ID        string
	CreatedAt time.Time
}

type InviteLinksDeleteExpiredBatchParams added in v0.147.0

type InviteLinksDeleteExpiredBatchParams struct {
	Cutoff    time.Time
	BatchSize int64
}

type MFAConsumeBackupCodeParams added in v0.63.0

type MFAConsumeBackupCodeParams struct {
	CodeHash string
	UserID   string
}

type MFAConsumeFactorTOTPStepParams added in v0.56.0

type MFAConsumeFactorTOTPStepParams struct {
	Step   *int64
	ID     string
	UserID string
}

type MFADeleteFactorParams added in v0.56.0

type MFADeleteFactorParams struct {
	UserID string
	ID     string
}

type MFAInsertFactorParams added in v0.98.0

type MFAInsertFactorParams struct {
	UserID       string
	Method       string
	PhoneNumber  *string
	TotpSecret   []byte
	LastTotpStep *int64
	IsDefault    bool
	Email        *string
}

type MFASetBackupCodesParams added in v0.56.0

type MFASetBackupCodesParams struct {
	BackupCodes []string
	UserID      string
}

type MFASetDefaultFactorParams added in v0.56.0

type MFASetDefaultFactorParams struct {
	UserID string
	ID     string
}

type MFASetEmailFactorAddressParams added in v0.147.0

type MFASetEmailFactorAddressParams struct {
	Email  string
	UserID string
}

type MFAUpsertSettingsParams added in v0.56.0

type MFAUpsertSettingsParams struct {
	UserID      string
	BackupCodes []string
}

type MfaFactor added in v0.105.0

type MfaFactor struct {
	ID           string
	UserID       string
	Method       string
	PhoneNumber  *string
	TotpSecret   []byte
	LastTotpStep *int64
	// Default factor AuthKit challenges first when 2FA is required
	IsDefault bool
	CreatedAt time.Time
	UpdatedAt time.Time
	Email     *string
}

Enrolled 2FA factors per user (hard-deleted on removal); backup codes remain user-scoped on mfa_settings

type MfaSetting added in v0.105.0

type MfaSetting struct {
	UserID  string
	Enabled bool
	// Hashed backup codes for account recovery
	BackupCodes []string
	CreatedAt   time.Time
	UpdatedAt   time.Time
}

Account-level 2FA gate + backup codes per user. enabled=true ⇒ 2FA required at login. Per-factor data lives in mfa_factors.

type NameClaimAliasesByUserParams added in v0.147.0

type NameClaimAliasesByUserParams struct {
	OwnerID string
	AtTime  time.Time
}

type NameClaimAliasesByUserRow added in v0.147.0

type NameClaimAliasesByUserRow struct {
	Name      string
	ExpiresAt *time.Time
}

type NameClaimCanonicalParams added in v0.147.0

type NameClaimCanonicalParams struct {
	Name    string
	OwnerID string
	AtTime  time.Time
}

type NameClaimDeleteOwnedParams added in v0.147.0

type NameClaimDeleteOwnedParams struct {
	Name    string
	OwnerID string
}

type NameClaimRetireParams added in v0.147.0

type NameClaimRetireParams struct {
	ExpiresAt *time.Time
	Name      string
	OwnerID   string
}

type NameClaimTakenParams added in v0.147.0

type NameClaimTakenParams struct {
	Name   string
	AtTime time.Time
}

type PasskeyDeleteParams added in v0.147.0

type PasskeyDeleteParams struct {
	ID     string
	UserID string
}

type PasskeyExistsForRPParams added in v0.147.0

type PasskeyExistsForRPParams struct {
	UserID string
	Rpid   string
}

type PasskeyHandleUpsertParams added in v0.147.0

type PasskeyHandleUpsertParams struct {
	UserID     string
	UserHandle []byte
}

type PasskeyInsertParams added in v0.147.0

type PasskeyInsertParams struct {
	UserID                  string
	Rpid                    string
	CredentialID            []byte
	PublicKey               []byte
	SignCount               int64
	CloneWarning            bool
	Aaguid                  []byte
	Transports              []string
	AuthenticatorAttachment string
	Flags                   []byte
	AttestationType         string
	AttestationFmt          string
	Label                   *string
}

type PasskeyLiveForUpdateParams added in v0.147.0

type PasskeyLiveForUpdateParams struct {
	ID     string
	UserID string
}

type PasskeyRecordUseParams added in v0.147.0

type PasskeyRecordUseParams struct {
	SignCount    int64
	CloneWarning bool
	Flags        []byte
	UserID       string
	Rpid         string
	CredentialID []byte
}

type PasskeyRenameParams added in v0.147.0

type PasskeyRenameParams struct {
	Label  *string
	ID     string
	UserID string
}

type PasskeysByUserParams added in v0.147.0

type PasskeysByUserParams struct {
	UserID string
	Rpid   string
}

type PermissionGroup added in v0.147.0

type PermissionGroup struct {
	ID        string
	Persona   string
	CreatedAt time.Time
	// Retained inactive group state; the trusted host owns retention and purge.
	DeletedAt *time.Time
}

type PermissionGroupInsertWithIDParams added in v0.147.0

type PermissionGroupInsertWithIDParams struct {
	ID      string
	Persona string
}

type PermissionGroupSoftDeleteParams added in v0.147.0

type PermissionGroupSoftDeleteParams struct {
	DeletedAt time.Time
	ID        string
}

type PermissionGroupsPageParams added in v0.147.0

type PermissionGroupsPageParams struct {
	Persona        string
	IncludeDeleted bool
	Ownerless      bool
	After          string
	MfaPersonas    []string
	PageLimit      int64
}

type ProviderLinkByIssuerAnyParams added in v0.97.1

type ProviderLinkByIssuerAnyParams struct {
	Issuer  string
	Subject string
}

type ProviderLinkByIssuerAnyRow added in v0.97.1

type ProviderLinkByIssuerAnyRow struct {
	UserID          string
	EmailAtProvider *string
	VerifiedAt      *time.Time
}

type ProviderLinkByIssuerParams

type ProviderLinkByIssuerParams struct {
	Issuer  string
	Subject string
}

type ProviderLinkByIssuerRow

type ProviderLinkByIssuerRow struct {
	UserID          string
	EmailAtProvider *string
}

type Queries

type Queries struct {
	// contains filtered or unexported fields
}

func New

func New(db DBTX) *Queries

func (*Queries) APIKeyByLookupID added in v0.147.0

func (q *Queries) APIKeyByLookupID(ctx context.Context, arg APIKeyByLookupIDParams) (APIKeyByLookupIDRow, error)

APIKeyByLookupID reads a key of a live group issued through issuer's app, or before per-app catalogs. creator_live: the key's creator is the system (NULL) or a usable account.

func (*Queries) APIKeyForRevoke added in v0.147.0

func (q *Queries) APIKeyForRevoke(ctx context.Context, arg APIKeyForRevokeParams) (APIKeyForRevokeRow, error)

func (*Queries) APIKeyInsert added in v0.41.0

func (q *Queries) APIKeyInsert(ctx context.Context, arg APIKeyInsertParams) (APIKeyInsertRow, error)

func (*Queries) APIKeyRetire added in v0.147.0

func (q *Queries) APIKeyRetire(ctx context.Context, id string) error

func (*Queries) APIKeyRoleCounts added in v0.147.0

func (q *Queries) APIKeyRoleCounts(ctx context.Context, issuer string) ([]APIKeyRoleCountsRow, error)

The live keys issued through issuer's app, or before per-app catalogs.

func (*Queries) APIKeyTouch added in v0.147.0

func (q *Queries) APIKeyTouch(ctx context.Context, id string) error

APIKeyTouch records a use at most once per 5 minutes per key.

func (*Queries) APIKeysByGroup added in v0.147.0

func (q *Queries) APIKeysByGroup(ctx context.Context, arg APIKeysByGroupParams) ([]APIKeysByGroupRow, error)

APIKeysByGroup lists a group's keys newest first, never the secret hash.

func (*Queries) APIKeysDeleteExpiredBatch added in v0.147.0

func (q *Queries) APIKeysDeleteExpiredBatch(ctx context.Context, arg APIKeysDeleteExpiredBatchParams) error

func (*Queries) APIKeysRevokeCreatedBy added in v0.147.0

func (q *Queries) APIKeysRevokeCreatedBy(ctx context.Context, userID string) error

API key queries.

func (*Queries) AccountDeletionDelivery added in v0.147.0

func (q *Queries) AccountDeletionDelivery(ctx context.Context, id int64) (AccountDeletionDeliveryRow, error)

func (*Queries) AccountDeletionDeliveryComplete added in v0.147.0

func (q *Queries) AccountDeletionDeliveryComplete(ctx context.Context, id int64) (int64, error)

func (*Queries) AccountDeletionDeliveryEarlierPending added in v0.147.0

func (q *Queries) AccountDeletionDeliveryEarlierPending(ctx context.Context, arg AccountDeletionDeliveryEarlierPendingParams) (bool, error)

func (*Queries) AccountDeletionDeliveryInsert added in v0.147.0

func (q *Queries) AccountDeletionDeliveryInsert(ctx context.Context, arg AccountDeletionDeliveryInsertParams) (int64, error)

No row (pgx.ErrNoRows) when the receipt already exists.

func (*Queries) AccountDeletionDeliveryUser added in v0.147.0

func (q *Queries) AccountDeletionDeliveryUser(ctx context.Context, id int64) (string, error)

func (*Queries) AccountDeletionForUpdate added in v0.147.0

func (q *Queries) AccountDeletionForUpdate(ctx context.Context, id string) (AccountDeletion, error)

func (*Queries) AccountDeletionHardDeliveriesPending added in v0.147.0

func (q *Queries) AccountDeletionHardDeliveriesPending(ctx context.Context, deletionID string) (bool, error)

func (*Queries) AccountDeletionInsert added in v0.147.0

func (q *Queries) AccountDeletionInsert(ctx context.Context, arg AccountDeletionInsertParams) (AccountDeletion, error)

Starts the recovery window from the account's own deleted_at.

func (*Queries) AccountDeletionOpenForUser added in v0.147.0

func (q *Queries) AccountDeletionOpenForUser(ctx context.Context, userID string) (string, error)

func (*Queries) AccountDeletionPurgeNow added in v0.147.0

func (q *Queries) AccountDeletionPurgeNow(ctx context.Context, userID string) (AccountDeletionPurgeNowRow, error)

Closes the recovery window of a deleted account now.

func (*Queries) AccountDeletionPurgeWindow added in v0.147.0

func (*Queries) AccountDeletionRecoverable added in v0.147.0

func (q *Queries) AccountDeletionRecoverable(ctx context.Context, arg AccountDeletionRecoverableParams) (AccountDeletion, error)

The account's current deletion while it can still be undone.

func (*Queries) AccountDeletionSetDeletedBy added in v0.147.0

func (q *Queries) AccountDeletionSetDeletedBy(ctx context.Context, arg AccountDeletionSetDeletedByParams) error

Records who deleted an account that is already deleted.

func (*Queries) AccountDeletionSetFinalizing added in v0.147.0

func (q *Queries) AccountDeletionSetFinalizing(ctx context.Context, id string) error

func (*Queries) AccountDeletionSetPurged added in v0.147.0

func (q *Queries) AccountDeletionSetPurged(ctx context.Context, id string) error

func (*Queries) AccountDeletionSetRestored added in v0.147.0

func (q *Queries) AccountDeletionSetRestored(ctx context.Context, id string) error

func (*Queries) AccountDeletionStateForUpdate added in v0.147.0

func (q *Queries) AccountDeletionStateForUpdate(ctx context.Context, id string) (string, error)

func (*Queries) AccountDeletionUser added in v0.147.0

func (q *Queries) AccountDeletionUser(ctx context.Context, id string) (string, error)

func (*Queries) AccountDeletionsDeleteTerminalBatch added in v0.147.0

func (q *Queries) AccountDeletionsDeleteTerminalBatch(ctx context.Context, arg AccountDeletionsDeleteTerminalBatchParams) (int64, error)

One bounded batch of restored/purged deletions past cutoff with no pending receipt; completed receipts go with them (FK cascade).

func (*Queries) AccountDeliveryFleetBusy added in v0.147.0

func (q *Queries) AccountDeliveryFleetBusy(ctx context.Context, issuer string) (bool, error)

Whether the issuer still has lifecycle work in its current fleet.

func (*Queries) AccountDeliveryFleetInsert added in v0.147.0

func (q *Queries) AccountDeliveryFleetInsert(ctx context.Context, arg AccountDeliveryFleetInsertParams) error

func (*Queries) AccountDeliveryFleetSchemaForShare added in v0.147.0

func (q *Queries) AccountDeliveryFleetSchemaForShare(ctx context.Context, issuer string) (string, error)

func (*Queries) AccountDeliveryFleetSchemaForUpdate added in v0.147.0

func (q *Queries) AccountDeliveryFleetSchemaForUpdate(ctx context.Context, issuer string) (string, error)

func (*Queries) AccountDeliveryFleetSetEvents added in v0.147.0

func (q *Queries) AccountDeliveryFleetSetEvents(ctx context.Context, arg AccountDeliveryFleetSetEventsParams) error

func (*Queries) AccountDeliveryFleetSetSchema added in v0.147.0

func (q *Queries) AccountDeliveryFleetSetSchema(ctx context.Context, arg AccountDeliveryFleetSetSchemaParams) error

func (*Queries) AccountDeliveryFleetsUnbound added in v0.147.0

func (q *Queries) AccountDeliveryFleetsUnbound(ctx context.Context, issuers []string) ([]string, error)

The issuers, sorted, with no fleet bound yet.

func (*Queries) AccountEventByID added in v0.147.0

func (q *Queries) AccountEventByID(ctx context.Context, id int64) (AccountEvent, error)

func (*Queries) AccountEventDelete added in v0.147.0

func (q *Queries) AccountEventDelete(ctx context.Context, id int64) error

func (*Queries) AccountEventEarlierPending added in v0.147.0

Whether an earlier event of the subject is still pending, and the seconds until the latest of their retries.

func (*Queries) AccountEventFleetsForShare added in v0.147.0

func (q *Queries) AccountEventFleetsForShare(ctx context.Context, issuers []string) ([]AccountEventFleetsForShareRow, error)

Durable account and group events (Deps.OnEvent): one account_events row per subscribed issuer, recorded in the change's transaction, deleted on delivery. The subscribed issuers' fleets, key-share locked until the change commits.

func (*Queries) AccountEventInsert added in v0.147.0

func (q *Queries) AccountEventInsert(ctx context.Context, arg AccountEventInsertParams) (int64, error)

func (*Queries) AccountEventRetry added in v0.147.0

func (q *Queries) AccountEventRetry(ctx context.Context, arg AccountEventRetryParams) error

func (*Queries) AccountInviteByCodeForUpdate added in v0.147.0

AccountInviteByCodeForUpdate: addressed is whether user_id has verified the invited address.

func (*Queries) AccountInviteConsume added in v0.147.0

func (q *Queries) AccountInviteConsume(ctx context.Context, arg AccountInviteConsumeParams) error

func (*Queries) AccountInviteForRevoke added in v0.147.0

func (q *Queries) AccountInviteForRevoke(ctx context.Context, arg AccountInviteForRevokeParams) (AccountInviteForRevokeRow, error)

func (*Queries) AccountInviteForUpdate added in v0.147.0

func (q *Queries) AccountInviteForUpdate(ctx context.Context, arg AccountInviteForUpdateParams) (AccountInviteForUpdateRow, error)

func (*Queries) AccountInviteGroupByCode added in v0.147.0

func (q *Queries) AccountInviteGroupByCode(ctx context.Context, codeHash string) (string, error)

func (*Queries) AccountInviteGroupLive added in v0.147.0

func (q *Queries) AccountInviteGroupLive(ctx context.Context, codeHash string) (*string, error)

func (*Queries) AccountInviteInsert added in v0.147.0

func (q *Queries) AccountInviteInsert(ctx context.Context, arg AccountInviteInsertParams) (AccountInviteInsertRow, error)

func (*Queries) AccountInviteRetire added in v0.147.0

func (q *Queries) AccountInviteRetire(ctx context.Context, id string) error

func (*Queries) AccountInviteValid added in v0.147.0

func (q *Queries) AccountInviteValid(ctx context.Context, codeHash string) (bool, error)

AccountInviteValid: code_hash names a live registration invite.

func (*Queries) AccountInvitesDeleteExpiredBatch added in v0.147.0

func (q *Queries) AccountInvitesDeleteExpiredBatch(ctx context.Context, arg AccountInvitesDeleteExpiredBatchParams) error

func (*Queries) AccountInvitesRevokeInvitedBy added in v0.147.0

func (q *Queries) AccountInvitesRevokeInvitedBy(ctx context.Context, userID string) error

func (*Queries) AdvisoryLock added in v0.147.0

func (q *Queries) AdvisoryLock(ctx context.Context, key string) error

Session-scoped advisory lock on key in this database: hold it on one dedicated connection, whose close releases it.

func (*Queries) AdvisoryXactLock added in v0.147.0

func (q *Queries) AdvisoryXactLock(ctx context.Context, key string) error

Transaction-scoped advisory lock on key, released when the transaction ends.

func (*Queries) AuthorityAPIKeyRole added in v0.147.0

func (q *Queries) AuthorityAPIKeyRole(ctx context.Context, arg AuthorityAPIKeyRoleParams) (AuthorityAPIKeyRoleRow, error)

The group and role of a live key in a live group whose creator is the system (NULL) or usable, issued through issuer's app or before per-app catalogs.

func (*Queries) AuthorityApplicationGroup added in v0.147.0

func (q *Queries) AuthorityApplicationGroup(ctx context.Context, id string) (string, error)

The controlling group of an enabled application in a live group whose registrar is usable.

func (*Queries) AuthorityApplicationOwnsGroup added in v0.147.0

Whether group_id controls the application, and the group's persona.

func (*Queries) AuthorityGroup added in v0.147.0

func (q *Queries) AuthorityGroup(ctx context.Context, id string) (PermissionGroup, error)

func (*Queries) AuthorityGroupState added in v0.147.0

func (q *Queries) AuthorityGroupState(ctx context.Context, id string) (PermissionGroup, error)

func (*Queries) AuthorityOutsideApplicationOwnerGroups added in v0.147.0

func (q *Queries) AuthorityOutsideApplicationOwnerGroups(ctx context.Context, groupID string) ([]string, error)

The other groups owned by enabled applications that group_id controls.

func (*Queries) AuthorityUncoveredCredentials added in v0.147.0

func (q *Queries) AuthorityUncoveredCredentials(ctx context.Context, arg AuthorityUncoveredCredentialsParams) ([]AuthorityUncoveredCredentialsRow, error)

Live credentials in the scope of a grant change to group_id (root: every live group) issued by user_id (” = anyone) through issuer's app, or before per-app catalogs: invite links, account invitations (one without a group belongs to root), API keys and the roles of applications (needs_creator: a group registration, which confers nothing without its registrar).

func (*Queries) AuthorityUserGroups added in v0.147.0

func (q *Queries) AuthorityUserGroups(ctx context.Context, arg AuthorityUserGroupsParams) ([]PermissionGroup, error)

The live groups other than root where the user holds a role.

func (*Queries) BootstrapAccountByCanonicalNameForUpdate added in v0.147.0

func (q *Queries) BootstrapAccountByCanonicalNameForUpdate(ctx context.Context, username string) (BootstrapAccountByCanonicalNameForUpdateRow, error)

A canonical username only; an alias is never followed.

func (*Queries) BootstrapAccountByEmailForUpdate added in v0.147.0

func (q *Queries) BootstrapAccountByEmailForUpdate(ctx context.Context, email string) (BootstrapAccountByEmailForUpdateRow, error)

func (*Queries) BootstrapAccountByIDForUpdate added in v0.147.0

func (q *Queries) BootstrapAccountByIDForUpdate(ctx context.Context, id string) (BootstrapAccountByIDForUpdateRow, error)

Bootstrap manifests and EnsureUserRole: find and lock the account a manifest user or a UserRef names. verified reports whether the key proves who holds the account (the id itself, or a verified contact).

func (*Queries) BootstrapAccountByPhoneForUpdate added in v0.147.0

func (q *Queries) BootstrapAccountByPhoneForUpdate(ctx context.Context, phone string) (BootstrapAccountByPhoneForUpdateRow, error)

func (*Queries) BootstrapApplyInsert added in v0.147.0

func (q *Queries) BootstrapApplyInsert(ctx context.Context, name string) error

func (*Queries) BootstrapApplyState added in v0.147.0

func (q *Queries) BootstrapApplyState(ctx context.Context, name string) (BootstrapApplyStateRow, error)

func (*Queries) ContactState added in v0.147.0

func (q *Queries) ContactState(ctx context.Context, id string) (ContactStateRow, error)

An account is unproven when it has an address and none is verified.

func (*Queries) ContactStateForUpdate added in v0.147.0

func (q *Queries) ContactStateForUpdate(ctx context.Context, id string) (ContactStateForUpdateRow, error)

func (*Queries) CredentialSweepFleetsForShare added in v0.147.0

func (q *Queries) CredentialSweepFleetsForShare(ctx context.Context, issuers []string) ([]CredentialSweepFleetsForShareRow, error)

The fleets of issuers, key-share locked until the change commits.

func (*Queries) CurrentDatabase added in v0.147.0

func (q *Queries) CurrentDatabase(ctx context.Context) (string, error)

func (*Queries) DeviceKeyActive added in v0.147.0

func (q *Queries) DeviceKeyActive(ctx context.Context, id string) (UserDeviceKey, error)

func (*Queries) DeviceKeyByPublicKey added in v0.147.0

func (q *Queries) DeviceKeyByPublicKey(ctx context.Context, publicKey []byte) (UserDeviceKey, error)

Device key queries. A key read returns db.UserDeviceKey.

func (*Queries) DeviceKeyEnrollUserInsert added in v0.147.0

func (q *Queries) DeviceKeyEnrollUserInsert(ctx context.Context, arg DeviceKeyEnrollUserInsertParams) (int64, error)

The account a device-key enrollment creates; the emailed code proved its address.

func (*Queries) DeviceKeyInsert added in v0.147.0

func (q *Queries) DeviceKeyInsert(ctx context.Context, arg DeviceKeyInsertParams) (UserDeviceKey, error)

func (*Queries) DeviceKeyIsActive added in v0.147.0

func (q *Queries) DeviceKeyIsActive(ctx context.Context, arg DeviceKeyIsActiveParams) (bool, error)

func (*Queries) DeviceKeyIsActiveForUpdate added in v0.147.0

func (q *Queries) DeviceKeyIsActiveForUpdate(ctx context.Context, arg DeviceKeyIsActiveForUpdateParams) (bool, error)

func (*Queries) DeviceKeyMarkMFAProven added in v0.147.0

func (q *Queries) DeviceKeyMarkMFAProven(ctx context.Context, id string) error

func (*Queries) DeviceKeyRelabel added in v0.149.0

func (q *Queries) DeviceKeyRelabel(ctx context.Context, arg DeviceKeyRelabelParams) (UserDeviceKey, error)

func (*Queries) DeviceKeyRevoke added in v0.147.0

func (q *Queries) DeviceKeyRevoke(ctx context.Context, arg DeviceKeyRevokeParams) (int64, error)

func (*Queries) DeviceKeyTouch added in v0.147.0

func (q *Queries) DeviceKeyTouch(ctx context.Context, arg DeviceKeyTouchParams) (UserDeviceKey, error)

func (*Queries) DeviceKeysByUser added in v0.147.0

func (q *Queries) DeviceKeysByUser(ctx context.Context, userID string) ([]UserDeviceKey, error)

func (*Queries) DeviceKeysRevokeAllExcept added in v0.147.0

func (q *Queries) DeviceKeysRevokeAllExcept(ctx context.Context, arg DeviceKeysRevokeAllExceptParams) (int64, error)

Ends every live device key of the account but keep_id (optional), e.g. the one presenting a credential change.

func (*Queries) EphemeralCompareAndConsume added in v0.141.0

func (q *Queries) EphemeralCompareAndConsume(ctx context.Context, arg EphemeralCompareAndConsumeParams) (int64, error)

func (*Queries) EphemeralConsume added in v0.141.0

func (q *Queries) EphemeralConsume(ctx context.Context, key string) ([]byte, error)

func (*Queries) EphemeralDelete added in v0.141.0

func (q *Queries) EphemeralDelete(ctx context.Context, key string) error

func (*Queries) EphemeralDeleteExpired added in v0.141.0

func (q *Queries) EphemeralDeleteExpired(ctx context.Context, batchSize int64) (int64, error)

func (*Queries) EphemeralGet added in v0.141.0

func (q *Queries) EphemeralGet(ctx context.Context, key string) ([]byte, error)

Each operation is one statement. Expiry always uses the database clock, so replicas with skewed clocks agree on what is live.

func (*Queries) EphemeralIncr added in v0.141.0

func (q *Queries) EphemeralIncr(ctx context.Context, arg EphemeralIncrParams) (int64, error)

The TTL is set when the counter starts and never extended; an expired counter restarts at 1.

func (*Queries) EphemeralSet added in v0.141.0

func (q *Queries) EphemeralSet(ctx context.Context, arg EphemeralSetParams) error

func (*Queries) GroupApplicationAssignmentsForGroups added in v0.147.0

func (*Queries) GroupApplicationRoleDelete added in v0.147.0

func (*Queries) GroupApplicationRoleName added in v0.147.0

func (q *Queries) GroupApplicationRoleName(ctx context.Context, arg GroupApplicationRoleNameParams) (string, error)

func (*Queries) GroupApplicationRoleUpsert added in v0.147.0

func (q *Queries) GroupApplicationRoleUpsert(ctx context.Context, arg GroupApplicationRoleUpsertParams) error

func (*Queries) GroupHasOtherUsableOwner added in v0.147.0

func (q *Queries) GroupHasOtherUsableOwner(ctx context.Context, arg GroupHasOtherUsableOwnerParams) (bool, error)

Whether the group has an owner that counts, other than the subject (excluding_kind, excluding_id): a usable user, MFA-enrolled when needs_mfa, or, when owners need no MFA, an enabled application of the group itself whose registrar is usable. An application a departing user registered never stands in for that user: its authority ends with theirs (R1).

func (*Queries) GroupMembersPage added in v0.147.0

func (q *Queries) GroupMembersPage(ctx context.Context, arg GroupMembersPageParams) ([]GroupMembersPageRow, error)

GroupMembersPage lists the subjects holding a role in a group, by kind then id. live: a usable user, or an enabled application with a live control group.

func (*Queries) GroupRolesForSubjects added in v0.147.0

func (q *Queries) GroupRolesForSubjects(ctx context.Context, arg GroupRolesForSubjectsParams) ([]GroupRolesForSubjectsRow, error)

func (*Queries) GroupUserAssignmentsForGroups added in v0.147.0

func (q *Queries) GroupUserAssignmentsForGroups(ctx context.Context, arg GroupUserAssignmentsForGroupsParams) ([]GroupUserAssignmentsForGroupsRow, error)

GroupUserAssignmentsForGroups and GroupApplicationAssignmentsForGroups read, for every live target group, the subject's assignments on it and on root. An application's assignments count only while it is enabled and its control group is live.

func (*Queries) GroupUserHasRole added in v0.147.0

func (q *Queries) GroupUserHasRole(ctx context.Context, arg GroupUserHasRoleParams) (bool, error)

func (*Queries) GroupUserRoleCounts added in v0.147.0

func (q *Queries) GroupUserRoleCounts(ctx context.Context) ([]GroupUserRoleCountsRow, error)

func (*Queries) GroupUserRoleDelete added in v0.147.0

func (q *Queries) GroupUserRoleDelete(ctx context.Context, arg GroupUserRoleDeleteParams) (GroupUserRoleDeleteRow, error)

GroupUserRoleDelete and GroupApplicationRoleDelete delete the subject's assignment in a group; role, when set, must match.

func (*Queries) GroupUserRoleName added in v0.147.0

func (q *Queries) GroupUserRoleName(ctx context.Context, arg GroupUserRoleNameParams) (string, error)

func (*Queries) GroupUserRoleUpsert added in v0.147.0

func (q *Queries) GroupUserRoleUpsert(ctx context.Context, arg GroupUserRoleUpsertParams) error

func (*Queries) GroupUserRolesForUsers added in v0.147.0

func (q *Queries) GroupUserRolesForUsers(ctx context.Context, arg GroupUserRolesForUsersParams) ([]GroupUserRolesForUsersRow, error)

func (*Queries) GroupsOfApplicationPage added in v0.147.0

func (q *Queries) GroupsOfApplicationPage(ctx context.Context, arg GroupsOfApplicationPageParams) ([]GroupsOfApplicationPageRow, error)

func (*Queries) GroupsOfUserPage added in v0.147.0

func (q *Queries) GroupsOfUserPage(ctx context.Context, arg GroupsOfUserPageParams) ([]GroupsOfUserPageRow, error)

GroupsOfUserPage and GroupsOfApplicationPage list the live groups a subject holds a role in, by persona then id.

func (*Queries) GroupsOwnedByApplication added in v0.147.0

func (q *Queries) GroupsOwnedByApplication(ctx context.Context, remoteApplicationID string) ([]string, error)

func (*Queries) GroupsOwnedByUser added in v0.147.0

func (q *Queries) GroupsOwnedByUser(ctx context.Context, userID string) ([]string, error)

func (*Queries) IdentityPublicUsersByIDs added in v0.92.0

func (q *Queries) IdentityPublicUsersByIDs(ctx context.Context, ids []string) ([]IdentityPublicUsersByIDsRow, error)

The PUBLIC-safe display projection (#268): no email column is selected, so a caller cannot leak one by forgetting a tag. Soft-deleted rows ARE returned — the Go layer tombstones them — so a reference to a deleted author resolves to a stable placeholder instead of silently vanishing.

func (*Queries) ImportHeldProviders added in v0.147.0

func (q *Queries) ImportHeldProviders(ctx context.Context, arg ImportHeldProvidersParams) ([]ImportHeldProvidersRow, error)

The identities some account holds, verified or not.

func (*Queries) ImportHitsByEmail added in v0.147.0

func (q *Queries) ImportHitsByEmail(ctx context.Context, emails []string) ([]ImportHitsByEmailRow, error)

func (*Queries) ImportHitsByID added in v0.147.0

func (q *Queries) ImportHitsByID(ctx context.Context, ids []string) ([]ImportHitsByIDRow, error)

The ImportHits* reads share one row shape: the matched key, the account, and whether it is deleted, the key verified on it, or a name reserved for a purged account.

func (*Queries) ImportHitsByName added in v0.147.0

func (q *Queries) ImportHitsByName(ctx context.Context, arg ImportHitsByNameParams) ([]ImportHitsByNameRow, error)

A canonical name or a live alias.

func (*Queries) ImportHitsByPhone added in v0.147.0

func (q *Queries) ImportHitsByPhone(ctx context.Context, phones []string) ([]ImportHitsByPhoneRow, error)

func (*Queries) ImportInsertPasswords added in v0.147.0

func (q *Queries) ImportInsertPasswords(ctx context.Context, arg ImportInsertPasswordsParams) error

func (*Queries) ImportInsertProviders added in v0.147.0

func (q *Queries) ImportInsertProviders(ctx context.Context, arg ImportInsertProvidersParams) (int64, error)

An empty provider slug or provider email is stored as NULL.

func (*Queries) ImportInsertUsers added in v0.147.0

func (q *Queries) ImportInsertUsers(ctx context.Context, users []byte) ([]string, error)

users is a JSON array of users rows (column-named keys; a missing key is NULL). A row losing a uniqueness race to another writer is not returned.

func (*Queries) ImportMergePassword added in v0.147.0

func (q *Queries) ImportMergePassword(ctx context.Context, arg ImportMergePasswordParams) error

func (*Queries) ImportMergeUser added in v0.147.0

func (q *Queries) ImportMergeUser(ctx context.Context, arg ImportMergeUserParams) error

func (*Queries) ImportReleaseAliases added in v0.147.0

func (q *Queries) ImportReleaseAliases(ctx context.Context, arg ImportReleaseAliasesParams) error

ImportUsers: bulk account import, one chunk per transaction. Expired aliases of the chunk's names neither match nor block.

func (*Queries) ImportSetBannedBy added in v0.147.0

func (q *Queries) ImportSetBannedBy(ctx context.Context, arg ImportSetBannedByParams) error

Records who banned imported accounts; a banner that is no account leaves banned_by NULL.

func (*Queries) InvitationsByGroup added in v0.147.0

func (q *Queries) InvitationsByGroup(ctx context.Context, arg InvitationsByGroupParams) ([]InvitationsByGroupRow, error)

InvitationsByGroup lists a group's invite links and email invitations, newest first, never a code hash. In the root group (root) it includes the plain registration invites, which have no group.

func (*Queries) InviteLinkByCodeForUpdate added in v0.147.0

func (*Queries) InviteLinkForRevoke added in v0.147.0

func (q *Queries) InviteLinkForRevoke(ctx context.Context, arg InviteLinkForRevokeParams) (InviteLinkForRevokeRow, error)

func (*Queries) InviteLinkGroupByCode added in v0.147.0

func (q *Queries) InviteLinkGroupByCode(ctx context.Context, codeHash string) (string, error)

func (*Queries) InviteLinkInsert added in v0.147.0

func (q *Queries) InviteLinkInsert(ctx context.Context, arg InviteLinkInsertParams) (InviteLinkInsertRow, error)

An issuer is the system (NULL) or a usable account: a credential never outlives its issuer's authority.

func (*Queries) InviteLinkRedeem added in v0.147.0

func (q *Queries) InviteLinkRedeem(ctx context.Context, id string) error

func (*Queries) InviteLinkRetire added in v0.147.0

func (q *Queries) InviteLinkRetire(ctx context.Context, id string) error

func (*Queries) InviteLinksDeleteExpiredBatch added in v0.147.0

func (q *Queries) InviteLinksDeleteExpiredBatch(ctx context.Context, arg InviteLinksDeleteExpiredBatchParams) error

Maintenance sweep of terminal credentials, retained for inspection until cutoff. Each call deletes one bounded batch, locking only that batch (SKIP LOCKED) so concurrent sweeps make progress.

func (*Queries) InviteLinksRevokeInvitedBy added in v0.147.0

func (q *Queries) InviteLinksRevokeInvitedBy(ctx context.Context, userID string) error

Group invite links and account registration invites.

func (*Queries) MFAClearDefaultFactors added in v0.56.0

func (q *Queries) MFAClearDefaultFactors(ctx context.Context, userID string) error

func (*Queries) MFAConsumeBackupCode added in v0.63.0

func (q *Queries) MFAConsumeBackupCode(ctx context.Context, arg MFAConsumeBackupCodeParams) (int64, error)

Atomic single-use consume: removes the hashed code and reports rows affected. 1 = this caller consumed it; 0 = code absent / already used / 2FA disabled. The `= ANY(...)` guard makes the test-and-remove a single statement so concurrent submissions of the same code cannot both succeed.

func (*Queries) MFAConsumeFactorTOTPStep added in v0.56.0

func (q *Queries) MFAConsumeFactorTOTPStep(ctx context.Context, arg MFAConsumeFactorTOTPStepParams) (int64, error)

func (*Queries) MFADeleteAllFactors added in v0.56.0

func (q *Queries) MFADeleteAllFactors(ctx context.Context, userID string) error

func (*Queries) MFADeleteFactor added in v0.56.0

func (q *Queries) MFADeleteFactor(ctx context.Context, arg MFADeleteFactorParams) (int64, error)

func (*Queries) MFADisable added in v0.56.0

func (q *Queries) MFADisable(ctx context.Context, userID string) error

Two-factor queries.

#125: factors are hard-deleted (no per-factor `enabled` flag). mfa_settings holds only the account-level gate (`enabled`) + `backup_codes`; per-factor data (method/phone/totp_secret/last_totp_step) lives ONLY on mfa_factors.

func (*Queries) MFAInsertFactor added in v0.98.0

func (q *Queries) MFAInsertFactor(ctx context.Context, arg MFAInsertFactorParams) (MfaFactor, error)

func (*Queries) MFAListFactorsByUser added in v0.56.0

func (q *Queries) MFAListFactorsByUser(ctx context.Context, userID string) ([]MfaFactor, error)

func (*Queries) MFALockUser added in v0.98.0

func (q *Queries) MFALockUser(ctx context.Context, id string) (string, error)

func (*Queries) MFAResetSettings added in v0.147.0

func (q *Queries) MFAResetSettings(ctx context.Context, userID string) error

Disables 2FA and drops the backup codes.

func (*Queries) MFASetBackupCodes added in v0.56.0

func (q *Queries) MFASetBackupCodes(ctx context.Context, arg MFASetBackupCodesParams) error

func (*Queries) MFASetDefaultFactor added in v0.56.0

func (q *Queries) MFASetDefaultFactor(ctx context.Context, arg MFASetDefaultFactorParams) (int64, error)

func (*Queries) MFASetEmailFactorAddress added in v0.147.0

func (q *Queries) MFASetEmailFactorAddress(ctx context.Context, arg MFASetEmailFactorAddressParams) error

func (*Queries) MFASettingsByUser added in v0.56.0

func (q *Queries) MFASettingsByUser(ctx context.Context, userID string) (MfaSetting, error)

func (*Queries) MFASettingsDelete added in v0.147.0

func (q *Queries) MFASettingsDelete(ctx context.Context, userID string) error

func (*Queries) MFAUpsertSettings added in v0.56.0

func (q *Queries) MFAUpsertSettings(ctx context.Context, arg MFAUpsertSettingsParams) error

func (*Queries) MFAUsable added in v0.147.0

func (q *Queries) MFAUsable(ctx context.Context, userID string) (bool, error)

2FA is enabled and has a factor.

func (*Queries) MigrationSchemaHasUsers added in v0.147.0

func (q *Queries) MigrationSchemaHasUsers(ctx context.Context, schemaName string) (bool, error)

func (*Queries) NameClaimAliasesByUser added in v0.147.0

func (q *Queries) NameClaimAliasesByUser(ctx context.Context, arg NameClaimAliasesByUserParams) ([]NameClaimAliasesByUserRow, error)

func (*Queries) NameClaimCanonical added in v0.147.0

func (q *Queries) NameClaimCanonical(ctx context.Context, arg NameClaimCanonicalParams) error

func (*Queries) NameClaimDeleteOwned added in v0.147.0

func (q *Queries) NameClaimDeleteOwned(ctx context.Context, arg NameClaimDeleteOwnedParams) error

func (*Queries) NameClaimRetire added in v0.147.0

func (q *Queries) NameClaimRetire(ctx context.Context, arg NameClaimRetireParams) error

The canonical name becomes an alias until expires_at (NULL: kept for good).

func (*Queries) NameClaimTaken added in v0.147.0

func (q *Queries) NameClaimTaken(ctx context.Context, arg NameClaimTakenParams) (bool, error)

func (*Queries) NameClaimsDeleteExpired added in v0.98.0

func (q *Queries) NameClaimsDeleteExpired(ctx context.Context, atTime time.Time) (int64, error)

func (*Queries) NameClaimsLock added in v0.147.0

func (q *Queries) NameClaimsLock(ctx context.Context, names []string) error

Takes the names' stripe locks in stripe order, so opposite renames cannot deadlock.

func (*Queries) PasskeyDelete added in v0.147.0

func (q *Queries) PasskeyDelete(ctx context.Context, arg PasskeyDeleteParams) (int64, error)

A deleted passkey stays deleted; no row changes only for another account's or no passkey.

func (*Queries) PasskeyExistsForRP added in v0.147.0

func (q *Queries) PasskeyExistsForRP(ctx context.Context, arg PasskeyExistsForRPParams) (bool, error)

func (*Queries) PasskeyHandleByUser added in v0.147.0

func (q *Queries) PasskeyHandleByUser(ctx context.Context, userID string) ([]byte, error)

func (*Queries) PasskeyHandleUpsert added in v0.147.0

func (q *Queries) PasskeyHandleUpsert(ctx context.Context, arg PasskeyHandleUpsertParams) ([]byte, error)

A concurrent first registration keeps the handle already stored.

func (*Queries) PasskeyHandleUser added in v0.147.0

func (q *Queries) PasskeyHandleUser(ctx context.Context, userHandle []byte) (string, error)

func (*Queries) PasskeyInsert added in v0.147.0

func (q *Queries) PasskeyInsert(ctx context.Context, arg PasskeyInsertParams) (UserPasskey, error)

func (*Queries) PasskeyLiveForUpdate added in v0.147.0

func (q *Queries) PasskeyLiveForUpdate(ctx context.Context, arg PasskeyLiveForUpdateParams) (string, error)

func (*Queries) PasskeyRecordUse added in v0.147.0

func (q *Queries) PasskeyRecordUse(ctx context.Context, arg PasskeyRecordUseParams) (string, error)

func (*Queries) PasskeyRename added in v0.147.0

func (q *Queries) PasskeyRename(ctx context.Context, arg PasskeyRenameParams) (int64, error)

func (*Queries) PasskeysByUser added in v0.147.0

func (q *Queries) PasskeysByUser(ctx context.Context, arg PasskeysByUserParams) ([]UserPasskey, error)

The user's live passkeys for one relying party.

func (*Queries) PasskeysDeleteByUser added in v0.147.0

func (q *Queries) PasskeysDeleteByUser(ctx context.Context, userID string) error

Passkey queries.

func (*Queries) PermissionGroupDelete added in v0.147.0

func (q *Queries) PermissionGroupDelete(ctx context.Context, id string) error

func (*Queries) PermissionGroupEnsureRoot added in v0.147.0

func (q *Queries) PermissionGroupEnsureRoot(ctx context.Context) (string, error)

DO NOTHING keeps a concurrent singleton insert from aborting the caller's transaction; no row means another transaction created root.

func (*Queries) PermissionGroupForUpdate added in v0.147.0

func (q *Queries) PermissionGroupForUpdate(ctx context.Context, id string) (PermissionGroup, error)

func (*Queries) PermissionGroupInsert added in v0.147.0

func (q *Queries) PermissionGroupInsert(ctx context.Context, persona string) (string, error)

Permission groups and their role assignments. A group read selects the whole row, so every group read returns db.PermissionGroup. Role tables are one per subject kind, so every assignment statement has a user and an application variant.

func (*Queries) PermissionGroupInsertWithID added in v0.147.0

func (q *Queries) PermissionGroupInsertWithID(ctx context.Context, arg PermissionGroupInsertWithIDParams) error

func (*Queries) PermissionGroupLiveForUpdate added in v0.147.0

func (q *Queries) PermissionGroupLiveForUpdate(ctx context.Context, id string) (PermissionGroup, error)

PermissionGroupLiveForUpdate is the shared lifecycle lock of a live group.

func (*Queries) PermissionGroupOwnerCount added in v0.147.0

func (q *Queries) PermissionGroupOwnerCount(ctx context.Context, groupID string) (int64, error)

PermissionGroupOwnerCount counts usable user owners and enabled application owners of the group itself.

func (*Queries) PermissionGroupRootID added in v0.147.0

func (q *Queries) PermissionGroupRootID(ctx context.Context) (string, error)

func (*Queries) PermissionGroupSoftDelete added in v0.147.0

func (q *Queries) PermissionGroupSoftDelete(ctx context.Context, arg PermissionGroupSoftDeleteParams) error

func (*Queries) PermissionGroupsByIDs added in v0.147.0

func (q *Queries) PermissionGroupsByIDs(ctx context.Context, ids []string) ([]PermissionGroup, error)

func (*Queries) PermissionGroupsPage added in v0.147.0

func (q *Queries) PermissionGroupsPage(ctx context.Context, arg PermissionGroupsPageParams) ([]PermissionGroup, error)

PermissionGroupsPage lists non-root groups oldest first. ownerless keeps live groups no owner counts for under the last-owner rule: a usable user (MFA-enrolled in an mfa_personas group), or, where owners need no MFA, an enabled application of the group itself whose registrar is usable.

func (*Queries) ProviderLinkByIssuer

func (q *Queries) ProviderLinkByIssuer(ctx context.Context, arg ProviderLinkByIssuerParams) (ProviderLinkByIssuerRow, error)

func (*Queries) ProviderLinkByIssuerAny added in v0.97.1

func (q *Queries) ProviderLinkByIssuerAny(ctx context.Context, arg ProviderLinkByIssuerAnyParams) (ProviderLinkByIssuerAnyRow, error)

func (*Queries) RemoteApplicationAuthority added in v0.147.0

func (q *Queries) RemoteApplicationAuthority(ctx context.Context, id string) (RemoteApplicationAuthorityRow, error)

An enabled application in a live group, whose registrar (if a group registered it) is usable.

func (*Queries) RemoteApplicationByID added in v0.147.0

func (q *Queries) RemoteApplicationByID(ctx context.Context, id string) (RemoteApplication, error)

func (*Queries) RemoteApplicationByIDForUpdate added in v0.147.0

func (q *Queries) RemoteApplicationByIDForUpdate(ctx context.Context, id string) (RemoteApplication, error)

func (*Queries) RemoteApplicationByIssuer added in v0.27.0

func (q *Queries) RemoteApplicationByIssuer(ctx context.Context, issuer string) (RemoteApplication, error)

func (*Queries) RemoteApplicationControlRoles added in v0.147.0

func (q *Queries) RemoteApplicationControlRoles(ctx context.Context, remoteApplicationID string) ([]RemoteApplicationControlRolesRow, error)

The roles an application holds in live groups.

func (*Queries) RemoteApplicationDelete added in v0.27.0

func (q *Queries) RemoteApplicationDelete(ctx context.Context, issuer string) (int64, error)

func (*Queries) RemoteApplicationEnabledInGroup added in v0.147.0

func (q *Queries) RemoteApplicationEnabledInGroup(ctx context.Context, arg RemoteApplicationEnabledInGroupParams) (bool, error)

func (*Queries) RemoteApplicationSetRegistrar added in v0.147.0

func (q *Queries) RemoteApplicationSetRegistrar(ctx context.Context, arg RemoteApplicationSetRegistrarParams) error

The registrar's app becomes the registration's.

func (*Queries) RemoteApplicationSetTrustRoot added in v0.147.0

func (q *Queries) RemoteApplicationSetTrustRoot(ctx context.Context, arg RemoteApplicationSetTrustRootParams) error

func (*Queries) RemoteApplicationUpsert added in v0.27.0

func (q *Queries) RemoteApplicationUpsert(ctx context.Context, arg RemoteApplicationUpsertParams) (RemoteApplication, error)

Remote application registry. A remote_application is the federation PRINCIPAL: it authenticates by signing JWTs verified against its JWKS/public keys (#74).

The controlling group is addressed as permission_group_id throughout. Every read returns the whole row: db.RemoteApplication.

func (*Queries) RemoteApplicationUsable added in v0.147.0

func (q *Queries) RemoteApplicationUsable(ctx context.Context, id string) (bool, error)

func (*Queries) RemoteApplicationsByGroup added in v0.147.0

func (q *Queries) RemoteApplicationsByGroup(ctx context.Context, arg RemoteApplicationsByGroupParams) ([]RemoteApplication, error)

Newest first, keyset-paged by id.

func (*Queries) RemoteApplicationsClearRegistrar added in v0.147.0

func (q *Queries) RemoteApplicationsClearRegistrar(ctx context.Context, userID string) error

func (*Queries) RemoteApplicationsEnabled added in v0.27.0

func (q *Queries) RemoteApplicationsEnabled(ctx context.Context) ([]RemoteApplication, error)

func (*Queries) ResolveUsername added in v0.98.0

func (q *Queries) ResolveUsername(ctx context.Context, arg ResolveUsernameParams) (ResolveUsernameRow, error)

func (*Queries) RiverIdentityProbeLock added in v0.147.0

func (q *Queries) RiverIdentityProbeLock(ctx context.Context, arg RiverIdentityProbeLockParams) (RiverIdentityProbeLockRow, error)

River database identity witness (requireSameRiverDatabase): the producer pool takes two random transaction advisory locks; the worker pool must see them held by that backend in the same database.

func (*Queries) RiverIdentityProbeSeen added in v0.147.0

func (q *Queries) RiverIdentityProbeSeen(ctx context.Context, arg RiverIdentityProbeSeenParams) (bool, error)

func (*Queries) RoleCatalogFingerprint added in v0.147.0

func (q *Queries) RoleCatalogFingerprint(ctx context.Context, issuer string) (string, error)

Each app's role catalog as its credential sweep last reconciled it, and the fleets that sweep the credentials of the other apps sharing the accounts.

func (*Queries) RoleCatalogSet added in v0.147.0

func (q *Queries) RoleCatalogSet(ctx context.Context, arg RoleCatalogSetParams) error

func (*Queries) RoleCatalogsDeclaredRoles added in v0.147.0

func (q *Queries) RoleCatalogsDeclaredRoles(ctx context.Context, issuers []string) ([]string, error)

The persona:role names the catalogs of issuers declare.

func (*Queries) RuntimeAccessLock added in v0.147.0

func (q *Queries) RuntimeAccessLock(ctx context.Context) error

Shared with OpenRails: ACL writes can touch the same public objects.

func (*Queries) RuntimeIdentity added in v0.147.0

func (q *Queries) RuntimeIdentity(ctx context.Context) (RuntimeIdentityRow, error)

func (*Queries) SessionByHistoricalTokenHash added in v0.98.0

Every consumed token stays attributable for the session lifetime. Only the immediate predecessor can open the current grace seal; older hashes still identify the family for reuse detection.

func (*Queries) SessionEventInsert added in v0.81.0

func (q *Queries) SessionEventInsert(ctx context.Context, arg SessionEventInsertParams) error

Session-event history queries (#245). Best-effort append-only log: sign-ins, revocations, password changes. Retention-pruned.

func (*Queries) SessionEventsByUser added in v0.147.0

func (q *Queries) SessionEventsByUser(ctx context.Context, arg SessionEventsByUserParams) ([]SessionEvent, error)

One page of an account's history, newest first, after the (after_at, after_id) keyset cursor when after_at is set; no kinds means every kind.

func (*Queries) SessionEventsPruneBatch added in v0.81.0

func (q *Queries) SessionEventsPruneBatch(ctx context.Context, arg SessionEventsPruneBatchParams) (int64, error)

One bounded retention batch: delete up to batch_size rows older than cutoff, walking the occurred_at index. Callers loop until a short batch — never an unbounded single DELETE.

func (*Queries) SessionFreshSince

func (q *Queries) SessionFreshSince(ctx context.Context, arg SessionFreshSinceParams) (SessionFreshSinceRow, error)

func (*Queries) SessionFreshSinceForUpdate added in v0.100.0

func (*Queries) SessionInsert

func (q *Queries) SessionInsert(ctx context.Context, arg SessionInsertParams) (SessionInsertRow, error)

Refresh-session queries.

func (*Queries) SessionMarkAuthenticated

func (q *Queries) SessionMarkAuthenticated(ctx context.Context, arg SessionMarkAuthenticatedParams) (int64, error)

Re-proving identity refreshes the freshness window and UNIONS the methods just used into what the session proved, so its refresh assurance never drops. MFA freshness moves only when these methods include the second factor.

func (*Queries) SessionProvedPassword added in v0.147.0

func (q *Queries) SessionProvedPassword(ctx context.Context, arg SessionProvedPasswordParams) (bool, error)

Whether the user's live session session_id signed in with a password.

func (*Queries) SessionRevokeByIDForUser

func (q *Queries) SessionRevokeByIDForUser(ctx context.Context, arg SessionRevokeByIDForUserParams) (string, error)

func (*Queries) SessionRotate

func (q *Queries) SessionRotate(ctx context.Context, arg SessionRotateParams) (int64, error)

Record the consumed hash and rotate in one statement. The CAS admits one writer; an insertion failure rolls back the rotation, and a lost CAS inserts no history. The row's latest seal still re-delivers the same successor to concurrent holders of the immediate predecessor.

func (*Queries) SessionsCountActive

func (q *Queries) SessionsCountActive(ctx context.Context, arg SessionsCountActiveParams) (int64, error)

func (*Queries) SessionsCountActiveOutsideIssuers added in v0.102.0

func (q *Queries) SessionsCountActiveOutsideIssuers(ctx context.Context, arg SessionsCountActiveOutsideIssuersParams) (int64, error)

Live sessions an account-wide revocation could not reach: issuers missing from the configured account issuer set.

func (*Queries) SessionsDeleteRevokedOrExpiredBatch added in v0.98.0

func (q *Queries) SessionsDeleteRevokedOrExpiredBatch(ctx context.Context, batchSize int64) (int64, error)

One bounded GC batch (#325): collect up to batch_size dead sessions through the two partial indexes (revoked / expired), then delete them by tuple id so the outer step is a Tid Scan, never a table scan. Callers loop until a short batch. History rows cascade.

func (*Queries) SessionsEvictOldest

func (q *Queries) SessionsEvictOldest(ctx context.Context, arg SessionsEvictOldestParams) ([]string, error)

func (*Queries) SessionsListByUser

func (q *Queries) SessionsListByUser(ctx context.Context, arg SessionsListByUserParams) ([]SessionsListByUserRow, error)

last_authenticated_at and revoked_at are intentionally NOT selected: the session-list handler never renders them, and revoked_at is always NULL here (the WHERE clause filters to non-revoked rows), so reading them was pure over-fetch (#230).

func (*Queries) SessionsRevokeAll

func (q *Queries) SessionsRevokeAll(ctx context.Context, arg SessionsRevokeAllParams) ([]SessionsRevokeAllRow, error)

issuers is the revocation scope: this issuer alone, or every account issuer. keep_session_id (optional) survives, e.g. the session changing the password.

func (*Queries) SessionsRevokeFamily

func (q *Queries) SessionsRevokeFamily(ctx context.Context, familyID string) ([]SessionsRevokeFamilyRow, error)

func (*Queries) SetSearchPath added in v0.147.0

func (q *Queries) SetSearchPath(ctx context.Context, arg SetSearchPathParams) error

Connection setup, migrations and runtime-role provisioning. The schema identifiers in CREATE SCHEMA and the GRANTs stay inline in the engine. is_local false sets it for the session, true until the transaction (or savepoint) ends.

func (*Queries) StatementTimestamp added in v0.147.0

func (q *Queries) StatementTimestamp(ctx context.Context) (time.Time, error)

Account deletion lifecycle: the recovery window (account_deletions), the per-issuer delivery receipts River works off, and each issuer's River fleet.

func (*Queries) TransactionSettings added in v0.147.0

func (q *Queries) TransactionSettings(ctx context.Context) (TransactionSettingsRow, error)

Authority: the lock and transaction settings of authority mutations, group and actor resolution, ownership invariants and the credential sweep. A usable account is a row of usable_users; an application's registrar counts only while usable.

func (*Queries) UserAdvanceCredentialVersion added in v0.100.0

func (q *Queries) UserAdvanceCredentialVersion(ctx context.Context, id string) error

func (*Queries) UserApplyEmailChange

func (q *Queries) UserApplyEmailChange(ctx context.Context, arg UserApplyEmailChangeParams) error

func (*Queries) UserApplyPhoneChange

func (q *Queries) UserApplyPhoneChange(ctx context.Context, arg UserApplyPhoneChangeParams) error

func (*Queries) UserBan

func (q *Queries) UserBan(ctx context.Context, arg UserBanParams) error

func (*Queries) UserBanInForce added in v0.147.0

func (q *Queries) UserBanInForce(ctx context.Context, id string) (bool, error)

func (*Queries) UserByEmail

func (q *Queries) UserByEmail(ctx context.Context, email string) (User, error)

func (*Queries) UserByID

func (q *Queries) UserByID(ctx context.Context, id string) (User, error)

User-row queries. A user read selects the whole row, so every read returns db.User: the engine's one user type.

func (*Queries) UserByPhone

func (q *Queries) UserByPhone(ctx context.Context, phoneNumber *string) (User, error)

func (*Queries) UserByUsername

func (q *Queries) UserByUsername(ctx context.Context, username string) (User, error)

func (*Queries) UserClearBan

func (q *Queries) UserClearBan(ctx context.Context, id string) error

func (*Queries) UserCredentialVersion added in v0.100.0

func (q *Queries) UserCredentialVersion(ctx context.Context, id string) (UserCredentialVersionRow, error)

func (*Queries) UserCredentialVersionForUpdate added in v0.100.0

func (q *Queries) UserCredentialVersionForUpdate(ctx context.Context, id string) (UserCredentialVersionForUpdateRow, error)

All credential changes acquire this account lock before credential/session rows.

func (*Queries) UserDeleteHard

func (q *Queries) UserDeleteHard(ctx context.Context, id string) error

func (*Queries) UserEmailOrUsernameTaken

func (*Queries) UserExists added in v0.147.0

func (q *Queries) UserExists(ctx context.Context, id string) (bool, error)

func (*Queries) UserGroupRoles added in v0.147.0

func (q *Queries) UserGroupRoles(ctx context.Context, userID string) ([]UserGroupRolesRow, error)

Every role the user holds, with its group's persona.

func (*Queries) UserHasPassword

func (q *Queries) UserHasPassword(ctx context.Context, userID string) (bool, error)

func (*Queries) UserImportInsert

func (q *Queries) UserImportInsert(ctx context.Context, arg UserImportInsertParams) error

func (*Queries) UserImportUpdate

func (q *Queries) UserImportUpdate(ctx context.Context, arg UserImportUpdateParams) (string, error)

func (*Queries) UserInsert

func (q *Queries) UserInsert(ctx context.Context, arg UserInsertParams) (User, error)

func (*Queries) UserIsReserved

func (q *Queries) UserIsReserved(ctx context.Context, id string) (bool, error)

Owner-namespace queries.

Permission groups own group-scoped routing now. The reserved-account guard is users.metadata->>'reserved' (UserIsReserved); rename history is not authority.

func (*Queries) UserLastRenamedAt

func (q *Queries) UserLastRenamedAt(ctx context.Context, id string) (*time.Time, error)

func (*Queries) UserMetadata

func (q *Queries) UserMetadata(ctx context.Context, id string) ([]byte, error)

Reserved-account + metadata queries.

func (*Queries) UserNameForUpdate added in v0.147.0

func (q *Queries) UserNameForUpdate(ctx context.Context, id string) (UserNameForUpdateRow, error)

func (*Queries) UserNotDeleted added in v0.147.0

func (q *Queries) UserNotDeleted(ctx context.Context, id string) (bool, error)

func (*Queries) UserPasswordDelete

func (q *Queries) UserPasswordDelete(ctx context.Context, userID string) error

func (*Queries) UserPasswordInsert

func (q *Queries) UserPasswordInsert(ctx context.Context, arg UserPasswordInsertParams) error

func (*Queries) UserPasswordRehash added in v0.100.0

func (q *Queries) UserPasswordRehash(ctx context.Context, arg UserPasswordRehashParams) error

Opportunistic rehash cannot overwrite a password changed after verification.

func (*Queries) UserPasswordRow

func (q *Queries) UserPasswordRow(ctx context.Context, userID string) (UserPasswordRowRow, error)

func (*Queries) UserPasswordUpsert

func (q *Queries) UserPasswordUpsert(ctx context.Context, arg UserPasswordUpsertParams) error

func (*Queries) UserPhoneOrUsernameTaken

func (*Queries) UserPreferredLanguage added in v0.54.0

func (q *Queries) UserPreferredLanguage(ctx context.Context, id string) (string, error)

func (*Queries) UserProviderByIssuerAny added in v0.97.1

func (q *Queries) UserProviderByIssuerAny(ctx context.Context, arg UserProviderByIssuerAnyParams) (UserProviderByIssuerAnyRow, error)

func (*Queries) UserProviderCountForUpdate added in v0.72.0

func (q *Queries) UserProviderCountForUpdate(ctx context.Context, userID string) (int32, error)

Locks the user's provider rows (FOR UPDATE in the inner query) and returns the count, so a concurrent unlink for the same user serializes behind this lock — closing the last-credential TOCTOU. Must run inside a transaction.

func (*Queries) UserProviderDeleteBySlug

func (q *Queries) UserProviderDeleteBySlug(ctx context.Context, arg UserProviderDeleteBySlugParams) error

func (*Queries) UserProviderImportUnverified added in v0.97.1

func (*Queries) UserProviderLinkExists

func (q *Queries) UserProviderLinkExists(ctx context.Context, arg UserProviderLinkExistsParams) (bool, error)

HTTP-layer provider lookups (http/step_up.go, http/user_me_get.go).

func (*Queries) UserProviderMergeProfile

func (q *Queries) UserProviderMergeProfile(ctx context.Context, arg UserProviderMergeProfileParams) error

func (*Queries) UserProviderProofSource added in v0.147.0

func (q *Queries) UserProviderProofSource(ctx context.Context, arg UserProviderProofSourceParams) (string, error)

func (*Queries) UserProviderSetUsername

func (q *Queries) UserProviderSetUsername(ctx context.Context, arg UserProviderSetUsernameParams) error

func (*Queries) UserProviderSlugsDistinct

func (q *Queries) UserProviderSlugsDistinct(ctx context.Context, userID string) ([]string, error)

func (*Queries) UserProviderUnverifiedForUpdate added in v0.97.1

func (q *Queries) UserProviderUnverifiedForUpdate(ctx context.Context, arg UserProviderUnverifiedForUpdateParams) (string, error)

What a provider sign-in proves: the account's credential version and the verified link.

func (*Queries) UserProviderVerifyImported added in v0.97.1

func (q *Queries) UserProviderVerifyImported(ctx context.Context, arg UserProviderVerifyImportedParams) (*time.Time, error)

func (*Queries) UserProvidersDeleteByUser

func (q *Queries) UserProvidersDeleteByUser(ctx context.Context, userID string) error

func (*Queries) UserProvidersLinked added in v0.149.0

func (q *Queries) UserProvidersLinked(ctx context.Context, userID string) ([]UserProvidersLinkedRow, error)

The account's verified provider links, with the email each provider reported.

func (*Queries) UserRename added in v0.147.0

func (q *Queries) UserRename(ctx context.Context, arg UserRenameParams) error

func (*Queries) UserRestore

func (q *Queries) UserRestore(ctx context.Context, id string) error

Clearing deleted_at fires the credential-version trigger, like deletion.

func (*Queries) UserSessionLive added in v0.147.0

func (q *Queries) UserSessionLive(ctx context.Context, arg UserSessionLiveParams) (UserSessionLiveRow, error)

The session check (#412): whether the account is usable, and whether the sign-in it names (session_id or device_key_id; ” = none) is still a live refresh session or device key of the account.

func (*Queries) UserSetAvatarURL added in v0.90.0

func (q *Queries) UserSetAvatarURL(ctx context.Context, arg UserSetAvatarURLParams) error

func (*Queries) UserSetEmail added in v0.147.0

func (q *Queries) UserSetEmail(ctx context.Context, arg UserSetEmailParams) error

A new address is unverified; setting the current one changes nothing.

func (*Queries) UserSetEmailVerified

func (q *Queries) UserSetEmailVerified(ctx context.Context, arg UserSetEmailVerifiedParams) error

func (*Queries) UserSetEmailVerifiedIfPresent added in v0.147.0

func (q *Queries) UserSetEmailVerifiedIfPresent(ctx context.Context, arg UserSetEmailVerifiedIfPresentParams) (int64, error)

Verifying needs an address; no row changes without one.

func (*Queries) UserSetLastLogin

func (q *Queries) UserSetLastLogin(ctx context.Context, arg UserSetLastLoginParams) error

func (*Queries) UserSetMetadata added in v0.148.0

func (q *Queries) UserSetMetadata(ctx context.Context, arg UserSetMetadataParams) error

Replaces the metadata document (PatchUserMetadata merges in Go).

func (*Queries) UserSetPhone added in v0.147.0

func (q *Queries) UserSetPhone(ctx context.Context, arg UserSetPhoneParams) error

func (*Queries) UserSetPhoneVerifiedByIDAndPhone

func (q *Queries) UserSetPhoneVerifiedByIDAndPhone(ctx context.Context, arg UserSetPhoneVerifiedByIDAndPhoneParams) error

func (*Queries) UserSetPhoneVerifiedIfPresent added in v0.147.0

func (q *Queries) UserSetPhoneVerifiedIfPresent(ctx context.Context, arg UserSetPhoneVerifiedIfPresentParams) (int64, error)

func (*Queries) UserSetPreferredLanguage added in v0.54.0

func (q *Queries) UserSetPreferredLanguage(ctx context.Context, arg UserSetPreferredLanguageParams) error

func (*Queries) UserSetUsernameSpelling added in v0.147.0

func (q *Queries) UserSetUsernameSpelling(ctx context.Context, arg UserSetUsernameSpellingParams) error

Same name, new display spelling: no name claim, alias or cooldown.

func (*Queries) UserSoftDelete

func (q *Queries) UserSoftDelete(ctx context.Context, id string) error

func (*Queries) UserUsable added in v0.147.0

func (q *Queries) UserUsable(ctx context.Context, id string) (bool, error)

func (*Queries) UsersByIDs added in v0.147.0

func (q *Queries) UsersByIDs(ctx context.Context, ids []string) ([]User, error)

func (*Queries) WithTx

func (q *Queries) WithTx(tx pgx.Tx) *Queries

type RemoteApplication added in v0.147.0

type RemoteApplication struct {
	ID         string
	Issuer     string
	JwksUri    string
	Mode       string
	PublicKeys []byte
	Enabled    bool
	CreatedAt  time.Time
	UpdatedAt  time.Time
	// Required controlling permission-group. Authority comes from group_remote_application_roles on it and on root.
	PermissionGroupID string
	// What changes the keys: manual (the system) | user (a credentials manager of the controlling group). Never the keypair alone.
	TrustRoot string
	// The user who supplied the keys of a group registration; NULL = the operator.
	RegisteredBy *string
	// The Token.Issuer of the app its registrar registered it through; only its role catalog judges the application's roles. NULL = every app does.
	CatalogIssuer *string
}

Federation principals: external systems that authenticate by signing JWTs verified against configured keys.

type RemoteApplicationAuthorityRow added in v0.147.0

type RemoteApplicationAuthorityRow struct {
	PermissionGroupID string
	Persona           string
}

type RemoteApplicationControlRolesRow added in v0.147.0

type RemoteApplicationControlRolesRow struct {
	GroupID string
	Persona string
	Role    string
}

type RemoteApplicationEnabledInGroupParams added in v0.147.0

type RemoteApplicationEnabledInGroupParams struct {
	ID      string
	GroupID string
}

type RemoteApplicationSetRegistrarParams added in v0.147.0

type RemoteApplicationSetRegistrarParams struct {
	RegisteredBy  string
	CatalogIssuer string
	ID            string
}

type RemoteApplicationSetTrustRootParams added in v0.147.0

type RemoteApplicationSetTrustRootParams struct {
	TrustRoot string
	ID        string
}

type RemoteApplicationUpsertParams added in v0.27.0

type RemoteApplicationUpsertParams struct {
	PermissionGroupID string
	Issuer            string
	JwksUri           string
	Mode              string
	PublicKeys        []byte
	Enabled           bool
	CatalogIssuer     string
}

type RemoteApplicationsByGroupParams added in v0.147.0

type RemoteApplicationsByGroupParams struct {
	PermissionGroupID string
	AfterID           *string
	MaxRows           int64
}

type ResolveUsernameParams added in v0.98.0

type ResolveUsernameParams struct {
	Name   string
	AtTime time.Time
}

type ResolveUsernameRow added in v0.98.0

type ResolveUsernameRow struct {
	ID            string
	CanonicalName string
	IsAlias       bool
	ExpiresAt     *time.Time
}

type RiverIdentityProbeLockParams added in v0.147.0

type RiverIdentityProbeLockParams struct {
	Key1 int32
	Key2 int32
	Key3 int32
	Key4 int32
}

type RiverIdentityProbeLockRow added in v0.147.0

type RiverIdentityProbeLockRow struct {
	Pid    int32
	First  bool
	Second bool
}

type RiverIdentityProbeSeenParams added in v0.147.0

type RiverIdentityProbeSeenParams struct {
	Pid    int32
	Class1 int64
	Obj1   int64
	Class2 int64
	Obj2   int64
}

type RoleCatalogSetParams added in v0.147.0

type RoleCatalogSetParams struct {
	Issuer      string
	Fingerprint string
	Roles       []string
}

type RuntimeIdentityRow added in v0.147.0

type RuntimeIdentityRow struct {
	UserName     string
	DatabaseName string
}

type SessionByCurrentTokenHashParams

type SessionByCurrentTokenHashParams struct {
	CurrentTokenHash []byte
	Issuer           string
}

type SessionByCurrentTokenHashRow

type SessionByCurrentTokenHashRow struct {
	ID          string
	UserID      string
	FamilyID    string
	AuthMethods []string
}

type SessionByHistoricalTokenHashParams added in v0.98.0

type SessionByHistoricalTokenHashParams struct {
	TokenHash []byte
	Issuer    string
}

type SessionByHistoricalTokenHashRow added in v0.98.0

type SessionByHistoricalTokenHashRow struct {
	ID                      string
	UserID                  string
	FamilyID                string
	AuthMethods             []string
	ExpiresAt               *time.Time
	CurrentTokenHash        []byte
	PreviousSuccessorSealed []byte
	PreviousRotatedAt       *time.Time
}

type SessionEvent added in v0.147.0

type SessionEvent struct {
	ID         int64
	OccurredAt time.Time
	Issuer     string
	UserID     string
	SessionID  string
	Event      string
	Method     *string
	Reason     *string
	IpAddr     *string
	UserAgent  *string
}

type SessionEventInsertParams added in v0.81.0

type SessionEventInsertParams struct {
	OccurredAt time.Time
	Issuer     string
	UserID     string
	SessionID  string
	Event      string
	Method     *string
	Reason     *string
	IpAddr     *string
	UserAgent  *string
}

type SessionEventsByUserParams added in v0.147.0

type SessionEventsByUserParams struct {
	UserID    string
	Kinds     []string
	AfterAt   *time.Time
	AfterID   int64
	PageLimit int64
}

type SessionEventsPruneBatchParams added in v0.81.0

type SessionEventsPruneBatchParams struct {
	Cutoff    time.Time
	BatchSize int64
}

type SessionFreshSinceForUpdateParams added in v0.100.0

type SessionFreshSinceForUpdateParams struct {
	SessionID string
	UserID    string
	Issuer    string
}

type SessionFreshSinceForUpdateRow added in v0.100.0

type SessionFreshSinceForUpdateRow struct {
	FreshSince         time.Time
	AuthMethods        []string
	MfaAuthenticatedAt *time.Time
}

type SessionFreshSinceParams

type SessionFreshSinceParams struct {
	SessionID string
	UserID    string
	Issuer    string
}

type SessionFreshSinceRow added in v0.52.0

type SessionFreshSinceRow struct {
	FreshSince         time.Time
	AuthMethods        []string
	MfaAuthenticatedAt *time.Time
}

type SessionInsertParams

type SessionInsertParams struct {
	ID               string
	FamilyID         string
	UserID           string
	Issuer           string
	CurrentTokenHash []byte
	ExpiresAt        *time.Time
	UserAgent        *string
	IpAddr           *string
	AuthMethods      []string
}

type SessionInsertRow

type SessionInsertRow struct {
	ID       string
	FamilyID string
}

type SessionMarkAuthenticatedParams

type SessionMarkAuthenticatedParams struct {
	AuthMethods []string
	SessionID   string
	UserID      string
	Issuer      string
}

type SessionProvedPasswordParams added in v0.147.0

type SessionProvedPasswordParams struct {
	SessionID string
	UserID    string
}

type SessionRevokeByIDForUserParams

type SessionRevokeByIDForUserParams struct {
	ID     string
	UserID string
	Issuer string
}

type SessionRotateParams

type SessionRotateParams struct {
	ExpectedCurrentTokenHash []byte
	NewTokenHash             []byte
	UserAgent                *string
	IpAddr                   *string
	PreviousSuccessorSealed  []byte
	ID                       string
}

type SessionsCountActiveOutsideIssuersParams added in v0.102.0

type SessionsCountActiveOutsideIssuersParams struct {
	UserID  string
	Issuers []string
}

type SessionsCountActiveParams

type SessionsCountActiveParams struct {
	UserID string
	Issuer string
}

type SessionsEvictOldestParams

type SessionsEvictOldestParams struct {
	UserID     string
	Issuer     string
	EvictCount int64
}

type SessionsListByUserParams

type SessionsListByUserParams struct {
	UserID string
	Issuer string
}

type SessionsListByUserRow

type SessionsListByUserRow struct {
	ID         string
	FamilyID   string
	CreatedAt  time.Time
	LastUsedAt time.Time
	ExpiresAt  *time.Time
	UserAgent  *string
	IpAddr     *string
}

type SessionsRevokeAllParams

type SessionsRevokeAllParams struct {
	UserID        string
	Issuers       []string
	KeepSessionID *string
}

type SessionsRevokeAllRow added in v0.102.0

type SessionsRevokeAllRow struct {
	ID     string
	Issuer string
}

type SessionsRevokeFamilyRow

type SessionsRevokeFamilyRow struct {
	ID     string
	UserID string
}

type SetSearchPathParams added in v0.147.0

type SetSearchPathParams struct {
	SearchPath string
	IsLocal    bool
}

type TransactionSettingsRow added in v0.147.0

type TransactionSettingsRow struct {
	Isolation  string
	SearchPath string
}

type User added in v0.147.0

type User struct {
	ID            string
	Email         *string
	Username      *string
	EmailVerified bool
	// E.164 format phone number (e.g. +14155551234)
	PhoneNumber *string
	// Whether the phone number has been verified via SMS code
	PhoneVerified bool
	// When the user was banned
	BannedAt *time.Time
	// When a temporary ban expires (NULL for permanent)
	BannedUntil *time.Time
	// Reason for ban
	BanReason *string
	// User ID of admin who imposed ban
	BannedBy  *string
	DeletedAt *time.Time
	// Arbitrary user metadata (internal/admin flags such as reserved)
	Metadata  []byte
	CreatedAt time.Time
	UpdatedAt time.Time
	LastLogin *time.Time
	// User communication/auth language, e.g. en, es, de, ko, zh
	PreferredLanguage *string
	// Host-supplied avatar URL/key string; blob storage is host-owned
	AvatarURL         *string
	LastRenamedAt     *time.Time
	CredentialVersion int64
}

type UserApplyEmailChangeParams

type UserApplyEmailChangeParams struct {
	ID    string
	Email string
}

type UserApplyPhoneChangeParams

type UserApplyPhoneChangeParams struct {
	ID          string
	PhoneNumber *string
}

type UserBanParams

type UserBanParams struct {
	BannedAt    *time.Time
	BannedUntil *time.Time
	BanReason   *string
	BannedBy    *string
	ID          string
}

type UserCredentialVersionForUpdateRow added in v0.100.0

type UserCredentialVersionForUpdateRow struct {
	CredentialVersion int64
	Email             *string
	PhoneNumber       *string
	DeletedAt         *time.Time
	BannedAt          *time.Time
	BannedUntil       *time.Time
}

type UserCredentialVersionRow added in v0.100.0

type UserCredentialVersionRow struct {
	CredentialVersion int64
	Email             *string
	PhoneNumber       *string
}

type UserDeviceKey added in v0.147.0

type UserDeviceKey struct {
	ID          string
	UserID      string
	PublicKey   []byte
	Label       *string
	CreatedAt   time.Time
	LastUsedAt  *time.Time
	RevokedAt   *time.Time
	MfaProvenAt *time.Time
}

Ed25519 public keys for native clients. Revoked rows remain tombstones and cannot be re-enrolled.

type UserEmailOrUsernameTakenParams

type UserEmailOrUsernameTakenParams struct {
	Email    string
	Username string
	AtTime   time.Time
}

type UserEmailOrUsernameTakenRow

type UserEmailOrUsernameTakenRow struct {
	EmailTaken    bool
	UsernameTaken bool
}

type UserGroupRolesRow added in v0.147.0

type UserGroupRolesRow struct {
	PermissionGroupID string
	Persona           string
	Role              string
}

type UserImportInsertParams

type UserImportInsertParams struct {
	ID            string
	Email         *string
	PhoneNumber   *string
	Username      *string
	EmailVerified bool
	PhoneVerified bool
	BannedAt      *time.Time
	BannedUntil   *time.Time
	BanReason     *string
	BannedBy      *string
	Metadata      []byte
	CreatedAt     time.Time
	UpdatedAt     time.Time
	AtTime        time.Time
}

type UserImportUpdateParams

type UserImportUpdateParams struct {
	Email         *string
	PhoneNumber   *string
	Username      *string
	EmailVerified bool
	PhoneVerified bool
	BannedAt      *time.Time
	BannedUntil   *time.Time
	BanReason     *string
	BannedBy      *string
	Metadata      []byte
	CreatedAt     time.Time
	UpdatedAt     time.Time
	ID            string
}

type UserInsertParams

type UserInsertParams struct {
	ID       string
	Email    string
	Username *string
	AtTime   time.Time
}

type UserNameForUpdateRow added in v0.147.0

type UserNameForUpdateRow struct {
	Username      *string
	LastRenamedAt *time.Time
}

type UserPasskey added in v0.147.0

type UserPasskey struct {
	ID                      string
	UserID                  string
	Rpid                    string
	CredentialID            []byte
	PublicKey               []byte
	SignCount               int64
	CloneWarning            bool
	Aaguid                  []byte
	Transports              []string
	AuthenticatorAttachment string
	Flags                   []byte
	AttestationType         string
	AttestationFmt          string
	Label                   *string
	CreatedAt               time.Time
	LastUsedAt              *time.Time
	DeletedAt               *time.Time
}

type UserPasswordInsertParams

type UserPasswordInsertParams struct {
	UserID       string
	PasswordHash string
}

type UserPasswordRehashParams added in v0.100.0

type UserPasswordRehashParams struct {
	NewHash string
	UserID  string
	OldHash string
}

type UserPasswordRowRow

type UserPasswordRowRow struct {
	PasswordHash string
	HashAlgo     string
}

type UserPasswordUpsertParams

type UserPasswordUpsertParams struct {
	UserID       string
	PasswordHash string
	HashAlgo     string
}

type UserPhoneOrUsernameTakenParams

type UserPhoneOrUsernameTakenParams struct {
	Phone    string
	Username string
	AtTime   time.Time
}

type UserPhoneOrUsernameTakenRow

type UserPhoneOrUsernameTakenRow struct {
	PhoneTaken    bool
	UsernameTaken bool
}

type UserProviderByIssuerAnyParams added in v0.97.1

type UserProviderByIssuerAnyParams struct {
	UserID string
	Issuer string
}

type UserProviderByIssuerAnyRow added in v0.97.1

type UserProviderByIssuerAnyRow struct {
	Subject    string
	VerifiedAt *time.Time
}

type UserProviderDeleteBySlugParams

type UserProviderDeleteBySlugParams struct {
	UserID       string
	ProviderSlug *string
}

type UserProviderImportUnverifiedParams added in v0.97.1

type UserProviderImportUnverifiedParams struct {
	ID           string
	UserID       string
	Issuer       string
	ProviderSlug *string
	Subject      string
	CreatedAt    time.Time
	Profile      []byte
}

type UserProviderImportUnverifiedRow added in v0.97.1

type UserProviderImportUnverifiedRow struct {
	ID     string
	UserID string
}

type UserProviderLinkExistsParams

type UserProviderLinkExistsParams struct {
	UserID       string
	Issuer       string
	ProviderSlug *string
}

type UserProviderMergeProfileParams

type UserProviderMergeProfileParams struct {
	UserID  string
	Issuer  string
	Subject string
	Patch   []byte
}

type UserProviderProofSourceParams added in v0.147.0

type UserProviderProofSourceParams struct {
	ID      string
	UserID  string
	Issuer  string
	Subject string
}

type UserProviderSetUsernameParams

type UserProviderSetUsernameParams struct {
	UserID   string
	Issuer   string
	Subject  string
	Username string
}

type UserProviderSubjectProfileByIssuerParams

type UserProviderSubjectProfileByIssuerParams struct {
	UserID string
	Issuer string
}

type UserProviderSubjectProfileByIssuerRow

type UserProviderSubjectProfileByIssuerRow struct {
	Subject    string
	CreatedAt  time.Time
	VerifiedAt *time.Time
	Profile    string
}

type UserProviderUnverifiedForUpdateParams added in v0.97.1

type UserProviderUnverifiedForUpdateParams struct {
	UserID       string
	ProviderSlug *string
}

type UserProviderUpsertByIssuerParams

type UserProviderUpsertByIssuerParams struct {
	ID              string
	UserID          string
	Issuer          string
	ProviderSlug    *string
	Subject         string
	EmailAtProvider *string
}

type UserProviderUpsertByIssuerRow added in v0.72.0

type UserProviderUpsertByIssuerRow struct {
	ID         string
	UserID     string
	VerifiedAt *time.Time
}

type UserProviderVerifiedLinkParams added in v0.147.0

type UserProviderVerifiedLinkParams struct {
	UserID  string
	Issuer  string
	Subject string
}

type UserProviderVerifiedLinkRow added in v0.147.0

type UserProviderVerifiedLinkRow struct {
	CredentialVersion int64
	ProviderID        string
}

type UserProviderVerifyImportedParams added in v0.97.1

type UserProviderVerifyImportedParams struct {
	UserID  string
	Issuer  string
	Subject string
}

type UserProvidersLinkedRow added in v0.149.0

type UserProvidersLinkedRow struct {
	ProviderSlug    string
	EmailAtProvider *string
	CreatedAt       time.Time
}

type UserRenameParams added in v0.147.0

type UserRenameParams struct {
	Username *string
	AtTime   time.Time
	ID       string
}

type UserSessionLiveParams added in v0.147.0

type UserSessionLiveParams struct {
	UserID      string
	SessionID   string
	DeviceKeyID string
}

type UserSessionLiveRow added in v0.147.0

type UserSessionLiveRow struct {
	Usable   bool
	SignedIn bool
}

type UserSetAvatarURLParams added in v0.90.0

type UserSetAvatarURLParams struct {
	AvatarURL *string
	ID        string
}

type UserSetEmailParams added in v0.147.0

type UserSetEmailParams struct {
	Email *string
	ID    string
}

type UserSetEmailVerifiedIfPresentParams added in v0.147.0

type UserSetEmailVerifiedIfPresentParams struct {
	Verified bool
	ID       string
}

type UserSetEmailVerifiedParams

type UserSetEmailVerifiedParams struct {
	ID            string
	EmailVerified bool
}

type UserSetLastLoginParams

type UserSetLastLoginParams struct {
	ID        string
	LastLogin *time.Time
}

type UserSetMetadataParams added in v0.148.0

type UserSetMetadataParams struct {
	Metadata []byte
	ID       string
}

type UserSetPhoneParams added in v0.147.0

type UserSetPhoneParams struct {
	PhoneNumber *string
	ID          string
}

type UserSetPhoneVerifiedByIDAndPhoneParams

type UserSetPhoneVerifiedByIDAndPhoneParams struct {
	ID          string
	PhoneNumber *string
}

type UserSetPhoneVerifiedIfPresentParams added in v0.147.0

type UserSetPhoneVerifiedIfPresentParams struct {
	Verified bool
	ID       string
}

type UserSetPreferredLanguageParams added in v0.54.0

type UserSetPreferredLanguageParams struct {
	ID                string
	PreferredLanguage *string
}

type UserSetUsernameSpellingParams added in v0.147.0

type UserSetUsernameSpellingParams struct {
	Username *string
	AtTime   time.Time
	ID       string
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL