pub(super) async fn migrate_token_expiry(services: &Services) -> Result<bool>Expand description
Adopts the access-token expiry a foreign database keeps in a column of its own, returning whether the pass is finished with that column.
That column is keyed by device while this server keeps the expiry alongside the owner in the shared token column, so a migrated session keeps authenticating while its expiry does not.
Every row names an OAuth session whose client can only recover from the expiry by refreshing against an OIDC provider here, so without one the pass waits, unfinished, rather than stranding sessions. With one it adopts once, since this server writes the same column afterward and a second pass would resurrect a replaced expiry.