Adds bearer-token authenticated REST API at /api/v1 covering every action a non-admin user can perform on the website: contact + beacon submission, beacon-monitor management, propagation queries, profile read/update, and self-service API token issuance/revocation. Security: SHA-256-hashed bearer tokens (mwp_ prefix, plaintext shown once at creation), RFC 9457 problem+json error responses, RFC 9651 RateLimit-* headers backed by an ETS bucket (600/min per token, 60/min per anonymous IP, 30/min on /auth/tokens), private-contact filtering by viewer. Docs at docs/api/README.md (prose reference) and docs/api/openapi.yaml (OpenAPI 3.1 spec covering every endpoint, response, and schema). Tests: 124 new tests across schema, plug, error renderer, rate limiter, fallback, and every controller. 16/17 API modules at 100% line coverage; FallbackController at 87.5% (one defmodule line, an Erlang-cover artifact for action_fallback-only modules).
20 lines
659 B
Elixir
20 lines
659 B
Elixir
defmodule Microwaveprop.Repo.Migrations.CreateUsersApiTokens do
|
|
use Ecto.Migration
|
|
|
|
def change do
|
|
create table(:users_api_tokens, primary_key: false) do
|
|
add :id, :binary_id, primary_key: true
|
|
add :user_id, references(:users, type: :binary_id, on_delete: :delete_all), null: false
|
|
add :name, :string, null: false
|
|
add :token_hash, :binary, null: false
|
|
add :last_used_at, :utc_datetime
|
|
add :expires_at, :utc_datetime
|
|
add :revoked_at, :utc_datetime
|
|
|
|
timestamps(type: :utc_datetime)
|
|
end
|
|
|
|
create index(:users_api_tokens, [:user_id])
|
|
create unique_index(:users_api_tokens, [:token_hash])
|
|
end
|
|
end
|