1cc62230ab
* Create schema and migration for organization access tokens * Add helpers for creating and authenticating OATs * Adapt the auth service to also accept OATs * Accept OATs in the whoami v2 endpoint * Enable deployments with the CLI using OATs * Avoid reading env variables directly in the token utils * Remove duplicate cli token utils * Validate ENCRYPTION_KEY length when parsing env vars * Make token utils a server-only module * Disallow revoking already revoked OATs * Simplify generics in authenticateRequest * Use 32 bytes mock encryption key in the test setup * Update dummy encryption key values in tests and templates * Add a column in the OATs table to differentiate between user and system generated * Simplify args for v3ProjectPath Co-authored-by: Matt Aitken <matt@mattaitken.com> * Add index on org id and createdAt * Avoid storing the encrypted oat token and its obfuscated version in the DB at all It is a safer approach. Also we do not need to ever read the decrypted token value after creation. * Fix prisma update condition * Add token type to the OAT table index * Accept OATs in the mcp auth flow * Simplify env auth flow around the /projects endpoints --------- Co-authored-by: Matt Aitken <matt@mattaitken.com>