Sign-in: link to the web token page; explain full scope #18

closed cmc opened this on 2026-09-28 03:18 UTC · sign-in ux

Discussion

cmc 2026-09-28 03:18 UTC

Sign-in assumes the CLI.

SignInView.swift:34,46,49 asks for a pasted token and hints gitbay auth token create --name iphone --scope full --ttl 90d. Only the CLI can mint one today, so a user who signed up on the web cannot get in. The web token page is filed in krz/gitbay.

Decided: the app needs write, so the hint stays --scope full.

  • Link to the web token page as the first option once it exists.
  • Keep --scope full explicit (krz/gitbay#257 changes the CLI default to read) and keep --ttl.
  • Say what full scope allows: comment and merge, and on an admin account, administering the instance.
  • AccountView.swift:3-4 says tokens are minted over SSH "only, by design"; since krz/gitbay#234 that is no longer the rule. Reword it.

closed by cmc in commit 1b9856d2d1: Sign-in: link to the web token page; say what full scope allows (!136)

2026-09-30 02:12 UTC