Commit 25279b4b49
25279b4b49d17f0ab01273fe21fdaa140619cb33
parent: 132441b6f5
Verified · cmc
cmc <hello@cleberg.net> · 2026-09-29 02:29 UTC
control: repo settings visibility needs a sign-in from the last 15 minutes
Ref #297
Layout: unified · split
.gitbay/wiki/Architecture/05-Identity-and-Access.org
+2 −1
| @@ -121,7 +121,8 @@ button and the displayed status (=internal/control/mr.go=): |
| 121 | - Commands that create a credential (SSH, deploy and runner keys, API |
121 | - Commands that create a credential (SSH, deploy and runner keys, API |
| 122 | tokens, email verification, login links, PGP keys, device tokens) or |
122 | tokens, email verification, login links, PGP keys, device tokens) or |
| 123 | grant access (repository and organization roles, teams, transfers, |
123 | grant access (repository and organization roles, teams, transfers, |
| 124 | admin promote and enable, webhooks, secrets, mirrors) are refused |
124 | repository visibility, admin promote and enable, webhooks, secrets, |
| |
125 | mirrors) are refused |
| 125 | from a browser session that signed in more than 15 minutes ago |
126 | from a browser session that signed in more than 15 minutes ago |
| 126 | (=control.ReauthWindow=, =Command.NeedsRecentSignIn=). The sign-in |
127 | (=control.ReauthWindow=, =Command.NeedsRecentSignIn=). The sign-in |
| 127 | time is =web_sessions.created_at=, which idle renewal does not move; |
128 | time is =web_sessions.created_at=, which idle renewal does not move; |
.gitbay/wiki/Users.org
+2 −1
| @@ -702,7 +702,8 @@ or =--all= ends them from the terminal, which is where a lost laptop is |
| 702 | handled. |
702 | handled. |
| 703 | |
703 | |
| 704 | Actions that create a credential or grant access (adding a key, token |
704 | Actions that create a credential or grant access (adding a key, token |
| 705 | or email, org and repository roles, transfers) ask you to sign in again |
705 | or email, org and repository roles, transfers, a repository's |
| |
706 | visibility) ask you to sign in again |
| 706 | when your web sign-in is older than 15 minutes. The form shows a "Sign |
707 | when your web sign-in is older than 15 minutes. The form shows a "Sign |
| 707 | in again" link and the login returns to the page. Idle renewal does not |
708 | in again" link and the login returns to the page. Idle renewal does not |
| 708 | extend this window. |
709 | extend this window. |
CHANGELOG.org
+4 −4
| @@ -24,10 +24,10 @@ anything beyond "replace the binary and restart" is needed. |
| 24 | first sync (#298). |
24 | first sync (#298). |
| 25 | - A browser session creates credentials and grants access — keys, PGP |
25 | - A browser session creates credentials and grants access — keys, PGP |
| 26 | keys, tokens, verified addresses, org and repository roles, transfers, |
26 | keys, tokens, verified addresses, org and repository roles, transfers, |
| 27 | webhooks, secrets, mirrors, and the admin promote/enable actions — |
27 | repository visibility, webhooks, secrets, mirrors, and the admin |
| 28 | only within 15 minutes of signing in. An older session gets the form |
28 | promote/enable actions — only within 15 minutes of signing in. An |
| 29 | back with a "Sign in again" link, and the login returns to it. SSH and |
29 | older session gets the form back with a "Sign in again" link, and the |
| 30 | API tokens are unaffected (#297). |
30 | login returns to it. SSH and API tokens are unaffected (#297). |
| 31 | - The builds page's status badge section gives an org-mode snippet |
31 | - The builds page's status badge section gives an org-mode snippet |
| 32 | beside the Markdown one, for a README.org (#299). |
32 | beside the Markdown one, for a README.org (#299). |
| 33 | - API tokens on the settings page: create with a scope and optional |
33 | - API tokens on the settings page: create with a scope and optional |
internal/control/reauth_test.go
+1
| @@ -125,6 +125,7 @@ func TestNeedsRecentSignInSet(t *testing.T) { |
| 125 | "repo mirror add", |
125 | "repo mirror add", |
| 126 | "repo runner add", |
126 | "repo runner add", |
| 127 | "repo secret set", |
127 | "repo secret set", |
| |
128 | "repo settings visibility", |
| 128 | "repo transfer", |
129 | "repo transfer", |
| 129 | "token create", |
130 | "token create", |
| 130 | "web login", |
131 | "web login", |
internal/control/repo.go
+3 −1
| @@ -118,7 +118,9 @@ func init() { |
| 118 | Summary: "set repository visibility", |
118 | Summary: "set repository visibility", |
| 119 | Usage: "repo settings visibility <owner/name> public|private", |
119 | Usage: "repo settings visibility <owner/name> public|private", |
| 120 | Examples: []string{"repo settings visibility krz/gitbay public"}, |
120 | Examples: []string{"repo settings visibility krz/gitbay public"}, |
| 121 | Run: runSetVisibility}) |
121 | // Making a repository public shows it to everyone. |
| |
122 | NeedsRecentSignIn: true, |
| |
123 | Run: runSetVisibility}) |
| 122 | register(Command{Path: []string{"repo", "settings", "website"}, |
124 | register(Command{Path: []string{"repo", "settings", "website"}, |
| 123 | Summary: "set the repository website", |
125 | Summary: "set the repository website", |
| 124 | Usage: "repo settings website <owner/name> <url> ('' clears)", |
126 | Usage: "repo settings website <owner/name> <url> ('' clears)", |