-- AUDIT-6 (2026-05-23): hash heartbeat tokens at rest.
--
-- Additive column. The application starts dual-writing immediately
-- after the PR lands: new heartbeat-type monitors get BOTH a raw
-- heartbeatToken (used by the UI to render the URL) AND a sha256
-- hash. The /api/heartbeat/[token] route hashes the URL parameter
-- before looking up the monitor, so the at-rest column an attacker
-- sees on a DB leak is no longer a forgeable bearer.
--
-- Existing rows have heartbeatTokenHash = NULL until the operator runs
--   npx tsx scripts/maint/backfill-heartbeat-token-hash.ts --apply
-- which computes the hash from the existing raw token.
--
-- A follow-up PR drops the heartbeatToken column once all live rows
-- have been backfilled.

ALTER TABLE `Monitor`
  ADD COLUMN `heartbeatTokenHash` VARCHAR(191) NULL,
  ADD UNIQUE INDEX `Monitor_heartbeatTokenHash_key` (`heartbeatTokenHash`);
