-- One row per browser session. The id is an opaque random value the cookie -- carries verbatim; a request is authenticated by looking the row up, and -- deleting the row is how a session is revoked. Expired rows are removed -- lazily on lookup, so nothing sweeps them. CREATE TABLE sessions ( id text PRIMARY KEY, reader_id bigint NOT NULL REFERENCES readers (id) ON DELETE CASCADE, created_at timestamptz NOT NULL DEFAULT now(), expires_at timestamptz NOT NULL );