Files
Felis/internal/store/migrations/0005_account_link_auth_source.sql
flyemoji 1f8b9bb5d0 feat(api): record account-link auth source (mojang|thirdparty)
Capture which Yggdrasil authenticated an in-game UUID when a link code is
minted (spec §10 dual-Yggdrasil) and copy it onto the durable account_links
row at verify. The value originates in-game — the web verify side never sees
the authentication — so it threads through account_link_codes, mirroring how
mc_uuid (not user_id) lives on a code.

- migration 0005: add link_auth_source enum + auth_source column on both
  account_link_codes and account_links; DEFAULT 'mojang' backfills existing
  rows and sets the Mojang-priority default for a mint that omits the field
- mint validates an explicit auth_source (unknown value -> 400); verify
  surfaces it in the 200 body and refreshes it on idempotent re-verify
2026-06-27 13:01:19 +09:00

18 lines
1.0 KiB
SQL

-- Player onboarding (spec §10, dual-Yggdrasil): record HOW the in-game identity
-- authenticated when a link code was minted — 'mojang' (Mojang/official Yggdrasil,
-- the priority source) or 'thirdparty' (a configured alternate Yggdrasil). The
-- value is known only in-game at the moment online-mode auth established the UUID,
-- so it is captured on the code at mint time and copied onto the durable link at
-- verify. The web verify side never sees the authentication and cannot originate
-- it — the same constraint that puts mc_uuid (not user_id) on a code.
--
-- DEFAULT 'mojang' backfills any code/link rows that predate this column and gives
-- a Mojang-priority default for a mint that omits the field; the mint path supplies
-- it explicitly going forward.
CREATE TYPE link_auth_source AS ENUM ('mojang','thirdparty');
ALTER TABLE account_link_codes
ADD COLUMN auth_source link_auth_source NOT NULL DEFAULT 'mojang';
ALTER TABLE account_links
ADD COLUMN auth_source link_auth_source NOT NULL DEFAULT 'mojang';