challenger

OAuth 2.0-based authentication service that validates user can receive messages at a certain address
Log | Files | Refs | Submodules | README | LICENSE

challenger-0006.sql (1587B)


      1 --
      2 -- This file is part of Challenger
      3 -- Copyright (C) 2026 Taler Systems SA
      4 --
      5 -- Challenger is free software; you can redistribute it and/or modify it under the
      6 -- terms of the GNU General Public License as published by the Free Software
      7 -- Foundation; either version 3, or (at your option) any later version.
      8 --
      9 -- Challenger is distributed in the hope that it will be useful, but WITHOUT ANY
     10 -- WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
     11 -- A PARTICULAR PURPOSE.  See the GNU General Public License for more details.
     12 --
     13 -- You should have received a copy of the GNU General Public License along with
     14 -- Challenger; see the file COPYING.  If not, see <http://www.gnu.org/licenses/>
     15 --
     16 
     17 -- Everything in one big transaction
     18 BEGIN;
     19 
     20 -- Check patch versioning is in place.
     21 SELECT _v.register_patch('challenger-0006', NULL, NULL);
     22 
     23 SET search_path TO challenger;
     24 
     25 ALTER TABLE validations
     26   ADD COLUMN failed BOOLEAN NOT NULL DEFAULT FALSE;
     27 COMMENT ON COLUMN validations.failed
     28   IS 'TRUE once the user exhausted every address change, TAN transmission and TAN attempt; the validation can then never succeed and is reported to the client as access_denied. Final: nothing resets it';
     29 
     30 -- Validations that are already out of options.  An address marked
     31 -- 'read_only' by the client cannot be changed, whatever
     32 -- address_attempts_left says.
     33 UPDATE validations
     34    SET failed=TRUE
     35  WHERE auth_attempts_left=0
     36    AND pin_transmissions_left=0
     37    AND ( (address_attempts_left=0)
     38       OR COALESCE(address::JSONB->'read_only' = 'true'::JSONB, FALSE) );
     39 
     40 
     41 COMMIT;