-- One row per browser session. The id is an opaque random value the cookie -- carries verbatim; a request is authenticated by looking the row up, and -- deleting the row is how a session is revoked. Expired rows are removed -- lazily on lookup and swept by the next login, so nothing runs a background -- cleanup. CREATE TABLE sessions ( id text PRIMARY KEY, reader_id bigint NOT NULL REFERENCES readers (id) ON DELETE CASCADE, created_at timestamptz NOT NULL DEFAULT now(), expires_at timestamptz NOT NULL );