* fix(security): harden auth and credential handling (HH-444) * fix(security): address HH-444 review blockers * fix(security): close remaining HH-444 review blockers --------- Co-authored-by: Rogee <rogee@ipao.vip>
42 lines
1.9 KiB
Go
42 lines
1.9 KiB
Go
package model
|
|
|
|
import (
|
|
"time"
|
|
|
|
"gorm.io/gorm"
|
|
)
|
|
|
|
// AccessToken represents a personal API access token with polymorphic ownership.
|
|
// Reference: Chatwoot AccessToken model + AccessTokenable concern + P2B M12 spec
|
|
//
|
|
// AccessTokens can belong to either a User (personal API tokens) or a PlatformApp
|
|
// (agent bot / integration tokens). The polymorphic ownership is modeled via
|
|
// OwnerType + OwnerID, matching Chatwoot's AccessTokenable concern pattern.
|
|
//
|
|
// OwnerType values: "User" (personal tokens), "PlatformApp" (bot/integration tokens).
|
|
type AccessToken struct {
|
|
ID uint `gorm:"primaryKey;autoIncrement" json:"id"`
|
|
OwnerType string `gorm:"size:100;not null;index" json:"owner_type"` // User, PlatformApp
|
|
OwnerID uint `gorm:"not null;index" json:"owner_id"`
|
|
Token string `gorm:"size:255;not null;uniqueIndex" json:"-"` // stores SHA-256 hash
|
|
TokenPrefix string `gorm:"size:20;not null;index" json:"token_prefix"` // first 8 chars for fast lookup
|
|
Name string `gorm:"size:255" json:"name"`
|
|
ExpiresAt *time.Time `json:"expires_at,omitempty"`
|
|
LastUsedAt *time.Time `json:"last_used_at,omitempty"`
|
|
CreatedAt time.Time `gorm:"autoCreateTime" json:"created_at"`
|
|
UpdatedAt time.Time `gorm:"autoUpdateTime" json:"updated_at"`
|
|
DeletedAt gorm.DeletedAt `gorm:"index" json:"deleted_at,omitempty"`
|
|
|
|
// Relations (polymorphic — loaded based on OwnerType)
|
|
User User `gorm:"foreignKey:OwnerID;conditions:owner_type='User'" json:"user,omitempty"`
|
|
PlatformApp PlatformApp `gorm:"foreignKey:OwnerID;conditions:owner_type='PlatformApp'" json:"platform_app,omitempty"`
|
|
}
|
|
|
|
func (AccessToken) TableName() string { return "access_tokens" }
|
|
|
|
// AccessTokenOwnerType constants — valid polymorphic owner types.
|
|
const (
|
|
AccessTokenOwnerTypeUser = "User"
|
|
AccessTokenOwnerTypePlatformApp = "PlatformApp"
|
|
)
|