Commit 25279b4b49

25279b4b49d17f0ab01273fe21fdaa140619cb33

parent: 132441b6f5

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-29 02:29 UTC

control: repo settings visibility needs a sign-in from the last 15 minutes

Ref #297

Layout: unified · split

.gitbay/wiki/Architecture/05-Identity-and-Access.org +2 −1
@@ -121,7 +121,8 @@ button and the displayed status (=internal/control/mr.go=):
121121- Commands that create a credential (SSH, deploy and runner keys, API
122122 tokens, email verification, login links, PGP keys, device tokens) or
123123 grant access (repository and organization roles, teams, transfers,
124 admin promote and enable, webhooks, secrets, mirrors) are refused
124 repository visibility, admin promote and enable, webhooks, secrets,
125 mirrors) are refused
125126 from a browser session that signed in more than 15 minutes ago
126127 (=control.ReauthWindow=, =Command.NeedsRecentSignIn=). The sign-in
127128 time is =web_sessions.created_at=, which idle renewal does not move;
.gitbay/wiki/Users.org +2 −1
@@ -702,7 +702,8 @@ or =--all= ends them from the terminal, which is where a lost laptop is
702702handled.
703703
704704Actions that create a credential or grant access (adding a key, token
705or email, org and repository roles, transfers) ask you to sign in again
705or email, org and repository roles, transfers, a repository's
706visibility) ask you to sign in again
706707when your web sign-in is older than 15 minutes. The form shows a "Sign
707708in again" link and the login returns to the page. Idle renewal does not
708709extend this window.
CHANGELOG.org +4 −4
@@ -24,10 +24,10 @@ anything beyond "replace the binary and restart" is needed.
2424 first sync (#298).
2525- A browser session creates credentials and grants access — keys, PGP
2626 keys, tokens, verified addresses, org and repository roles, transfers,
27 webhooks, secrets, mirrors, and the admin promote/enable actions —
28 only within 15 minutes of signing in. An older session gets the form
29 back with a "Sign in again" link, and the login returns to it. SSH and
30 API tokens are unaffected (#297).
27 repository visibility, webhooks, secrets, mirrors, and the admin
28 promote/enable actions — only within 15 minutes of signing in. An
29 older session gets the form back with a "Sign in again" link, and the
30 login returns to it. SSH and API tokens are unaffected (#297).
3131- The builds page's status badge section gives an org-mode snippet
3232 beside the Markdown one, for a README.org (#299).
3333- API tokens on the settings page: create with a scope and optional
internal/control/reauth_test.go +1
@@ -125,6 +125,7 @@ func TestNeedsRecentSignInSet(t *testing.T) {
125125 "repo mirror add",
126126 "repo runner add",
127127 "repo secret set",
128 "repo settings visibility",
128129 "repo transfer",
129130 "token create",
130131 "web login",
internal/control/repo.go +3 −1
@@ -118,7 +118,9 @@ func init() {
118118 Summary: "set repository visibility",
119119 Usage: "repo settings visibility <owner/name> public|private",
120120 Examples: []string{"repo settings visibility krz/gitbay public"},
121 Run: runSetVisibility})
121 // Making a repository public shows it to everyone.
122 NeedsRecentSignIn: true,
123 Run: runSetVisibility})
122124 register(Command{Path: []string{"repo", "settings", "website"},
123125 Summary: "set the repository website",
124126 Usage: "repo settings website <owner/name> <url> ('' clears)",