-- Group image-generation permission is part of the API-key auth snapshot. -- Extend the existing durable invalidation trigger without changing migration 184. CREATE OR REPLACE FUNCTION enqueue_group_auth_cache_invalidation() RETURNS TRIGGER LANGUAGE plpgsql AS $$ DECLARE target_group_id BIGINT; BEGIN target_group_id := OLD.id; IF TG_OP = 'UPDATE' AND OLD.status IS NOT DISTINCT FROM NEW.status AND OLD.is_exclusive IS NOT DISTINCT FROM NEW.is_exclusive AND OLD.allow_image_generation IS NOT DISTINCT FROM NEW.allow_image_generation AND OLD.deleted_at IS NOT DISTINCT FROM NEW.deleted_at THEN RETURN NEW; END IF; INSERT INTO auth_cache_invalidation_outbox (cache_key) SELECT encode(sha256(convert_to(k.key, 'UTF8')), 'hex') FROM api_keys AS k WHERE k.group_id = target_group_id AND k.deleted_at IS NULL AND k.key <> ''; IF TG_OP = 'DELETE' THEN RETURN OLD; END IF; RETURN NEW; END; $$;