"""DDL for synapse_targets — per-user secrets of Synapse s2s delivery targets.

Each user registers their own Synapse target (create it in the Synapse admin
panel / MCP `target_create` with the given token_ref, pointing at this navi's
POST /webhooks/synapse) and pastes the secret here. The gateway collects the
secrets of all active targets to verify incoming deliveries.
"""

_DDL = """
CREATE TABLE IF NOT EXISTS synapse_targets (
    id          SERIAL PRIMARY KEY,
    user_id     TEXT NOT NULL REFERENCES navi_users(id) ON DELETE CASCADE,
    token_ref   TEXT NOT NULL,
    secret_enc  TEXT NOT NULL,
    created_at  TIMESTAMPTZ NOT NULL,
    revoked_at  TIMESTAMPTZ
);

CREATE INDEX IF NOT EXISTS idx_synapse_targets_user_id ON synapse_targets (user_id);
"""


async def ensure_tables(pool) -> None:
    await pool.execute(_DDL)