-- Kernel-owned web-push subscriptions. A subscription is always scoped to the -- structure that registered it, and send-time fanout re-checks structure -- visibility before delivery. CREATE TABLE notification_subscriptions ( id INTEGER PRIMARY KEY AUTOINCREMENT, structure_id INTEGER NOT NULL, user_id INTEGER NOT NULL, endpoint TEXT NOT NULL, client_id TEXT, subscription TEXT NOT NULL, content_encoding TEXT, created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP, updated_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP, FOREIGN KEY(structure_id) REFERENCES structures(id), FOREIGN KEY(user_id) REFERENCES users(id), UNIQUE(structure_id, endpoint) ); CREATE INDEX idx_notification_subscriptions_structure ON notification_subscriptions (structure_id, user_id);