- FastAPI backend with SQLModel, Alembic migrations, AgentScope agents - Next.js 15 frontend with React 19, Tailwind, Zustand, React Flow - Multi-provider AI system (DashScope, Kling, MiniMax, Volcengine, OpenAI, etc.) - All HTTP clients migrated from sync requests to async httpx - Admin-managed API keys via environment variables - SSRF vulnerability fixed in ensure_url()
55 lines
2.5 KiB
Python
55 lines
2.5 KiB
Python
"""add user_sessions table
|
|
|
|
Revision ID: add_user_sessions
|
|
Revises: b546dbb9df98
|
|
Create Date: 2026-03-09
|
|
|
|
"""
|
|
from typing import Sequence, Union
|
|
|
|
from alembic import op
|
|
import sqlalchemy as sa
|
|
|
|
|
|
revision: str = 'add_user_sessions'
|
|
down_revision: Union[str, Sequence[str], None] = 'b546dbb9df98'
|
|
branch_labels: Union[str, Sequence[str], None] = None
|
|
depends_on: Union[str, Sequence[str], None] = None
|
|
|
|
|
|
def upgrade() -> None:
|
|
op.create_table(
|
|
'user_sessions',
|
|
sa.Column('id', sa.String(), nullable=False),
|
|
sa.Column('user_id', sa.String(), nullable=False),
|
|
sa.Column('session_family_id', sa.String(), nullable=False),
|
|
sa.Column('refresh_token_hash', sa.String(), nullable=False),
|
|
sa.Column('status', sa.String(), nullable=False, server_default='active'),
|
|
sa.Column('created_at', sa.Float(), nullable=False),
|
|
sa.Column('updated_at', sa.Float(), nullable=False),
|
|
sa.Column('expires_at', sa.Float(), nullable=False),
|
|
sa.Column('last_used_at', sa.Float(), nullable=True),
|
|
sa.Column('revoked_at', sa.Float(), nullable=True),
|
|
sa.Column('revoked_reason', sa.String(), nullable=True),
|
|
sa.Column('replaced_by_session_id', sa.String(), nullable=True),
|
|
sa.Column('ip_address', sa.String(), nullable=True),
|
|
sa.Column('user_agent', sa.Text(), nullable=True),
|
|
sa.Column('device_name', sa.String(), nullable=True),
|
|
sa.ForeignKeyConstraint(['user_id'], ['users.id'], ondelete='CASCADE'),
|
|
sa.PrimaryKeyConstraint('id'),
|
|
)
|
|
op.create_index(op.f('ix_user_sessions_user_id'), 'user_sessions', ['user_id'], unique=False)
|
|
op.create_index(op.f('ix_user_sessions_session_family_id'), 'user_sessions', ['session_family_id'], unique=False)
|
|
op.create_index(op.f('ix_user_sessions_refresh_token_hash'), 'user_sessions', ['refresh_token_hash'], unique=False)
|
|
op.create_index(op.f('ix_user_sessions_status'), 'user_sessions', ['status'], unique=False)
|
|
op.create_index(op.f('ix_user_sessions_revoked_at'), 'user_sessions', ['revoked_at'], unique=False)
|
|
|
|
|
|
def downgrade() -> None:
|
|
op.drop_index(op.f('ix_user_sessions_revoked_at'), table_name='user_sessions')
|
|
op.drop_index(op.f('ix_user_sessions_status'), table_name='user_sessions')
|
|
op.drop_index(op.f('ix_user_sessions_refresh_token_hash'), table_name='user_sessions')
|
|
op.drop_index(op.f('ix_user_sessions_session_family_id'), table_name='user_sessions')
|
|
op.drop_index(op.f('ix_user_sessions_user_id'), table_name='user_sessions')
|
|
op.drop_table('user_sessions')
|