-- A manager, and the refresh token it holds -- sealed to that node, the way every credential is. -- -- novox/hq ADR 0050. The consolidated schema (0001) creates the `manager` and `manager_module` -- columns and the `refresh_grant` table in its final shape; this migration carries an existing -- database the same distance, so a database that predates the carve-out gains exactly what a fresh -- one is created with. -- -- **Idempotent, and it converges rather than assumes.** An early cut of this carve-out kept the -- refresh token as a bespoke at-rest envelope (`token` + `wrapped_key`) so the manager MODULE could -- open it with the node's private key. That was retired before release: a module is never given a -- node's private sealing key, so the refresh token now rides the ordinary sealed-delivery path -- -- one anonymous sealed box to the manager node's public key, unsealed by the HOST. This migration -- therefore also drops those columns and adds `sealed` for any database that ran the earlier shape, -- so both a pristine database and one carried through the early cut end at the same schema. alter table licence add column if not exists manager text; alter table licence add column if not exists manager_module text; create table if not exists refresh_grant ( licence text primary key references licence(name) on delete cascade, sealed text not null, manager_key text not null, updated_at timestamptz not null default now() ); -- Converge a database that created refresh_grant in the retired at-rest shape. There is nothing to -- preserve: an unreleased carve-out held no production refresh tokens, and a refresh token cannot be -- re-derived from a wrapped envelope this migration cannot open. The manager re-adopts. alter table refresh_grant add column if not exists sealed text; alter table refresh_grant drop column if exists token; alter table refresh_grant drop column if exists wrapped_key; update refresh_grant set sealed = '' where sealed is null; alter table refresh_grant alter column sealed set not null;