777926487b
initial QEMU slice, backed by imported contracts for majors 6–9. - Implement durable handlers for access/auth, cluster, LXC, storage, HA, firewall, Ceph, SDN, ACME, notifications, pools, mapping, and node ops - Serve an interactive Web UI with catalog browsing, demo seed controls, and OpenAPI/help surfaces - Bundle PVE 6.4-15, 7.4-16, and 8.4.5 contract revisions alongside 9.2.3 - Support in-memory runtime contract Apply (POST /ui/api/contract/apply) so /version and /api2 routes follow the selected major until restart - Expand seed profiles (including demo-cluster), migrations 007–008, TLS gateway config, Compose/Makefile tooling, and compatibility evidence - Tighten .gitignore for macOS, hidden directories (.*/), and local secrets
24 lines
890 B
SQL
24 lines
890 B
SQL
CREATE TABLE tfa_entries (
|
|
principal_id uuid NOT NULL REFERENCES principals(id) ON DELETE CASCADE,
|
|
entry_id text NOT NULL,
|
|
tfa_type text NOT NULL CHECK (tfa_type IN ('totp', 'u2f', 'webauthn', 'recovery', 'yubico')),
|
|
description text,
|
|
enable boolean NOT NULL DEFAULT true,
|
|
created_at timestamptz NOT NULL DEFAULT now(),
|
|
secret text,
|
|
metadata jsonb NOT NULL DEFAULT '{}'::jsonb,
|
|
PRIMARY KEY (principal_id, entry_id)
|
|
);
|
|
CREATE INDEX tfa_entries_principal_idx ON tfa_entries(principal_id);
|
|
|
|
ALTER TABLE principals
|
|
ADD COLUMN IF NOT EXISTS tfa_locked_until timestamptz,
|
|
ADD COLUMN IF NOT EXISTS totp_locked boolean NOT NULL DEFAULT false;
|
|
|
|
CREATE TABLE openid_pending (
|
|
state text PRIMARY KEY,
|
|
realm text NOT NULL REFERENCES realms(name) ON DELETE CASCADE,
|
|
redirect_url text NOT NULL,
|
|
created_at timestamptz NOT NULL DEFAULT now()
|
|
);
|