web: API token page, so a web-only user can sign in to the iOS app #264

closed cmc opened this on 2026-09-28 03:18 UTC · mobile ux web

Discussion

cmc 2026-09-28 03:18 UTC

No web page mints an API token, so a web-only user cannot sign in to the iOS app.

The iOS app signs in with a pasted token, and only the CLI can create one. account.html:192-196 says "No page here yet, and nothing refusing one". Parity lists token mint as web no. Someone who signs up in a browser and never installs the CLI has no way into the app.

  • Settings → Tokens: create (name, scope, TTL), shown once on the result page; list with scope, expiry, created and last used; revoke behind the confirmfield typed confirmation keys use.
  • Scope default follows #257 (read). The form says a phone app needs full scope to comment and merge, and that full scope on an admin account can administer the instance.
  • registered.html:7-10: turn the next steps into a numbered list (copy the code from the mail, sign in, paste it in Settings → Email) and add "Using the iOS app? Create a token in Settings → Tokens".
  • Update Parity.

The iOS side (linking to this page from sign-in) is filed in krz/gitbay-ios.

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

referenced in commit 7e29c13f48 by cmc: e2e: signup expects the registered page's numbered steps

2026-09-28 23:23 UTC

referenced in commit ccf54427de by cmc: tests: token and issue-form tests pass a nil pack limiter to New

2026-09-28 23:23 UTC

closed by cmc in commit abc151f56b: wiki: Parity reflects the web API-token page

2026-09-28 23:23 UTC

referenced in commit a5a27ecbe6 by cmc: web: registered page's next steps as a numbered list, with a token mention for the iOS app

2026-09-28 23:23 UTC

referenced in commit f4b0c29240 by cmc: web: Settings → API tokens: create, list, revoke

2026-09-28 23:23 UTC