Expiring credentials cannot mint lasting ones; credentials record the token that created them.
- Migration 0060:
api_tokensandssh_keysgaincreated_by_token(ON DELETE SET NULL). Command.MintsCredentialmarks token create, keys add, repo deploy-key add, admin invite, web login, repo runner add, admin user create, email verify and admin email verify;Dispatchrefuses them (exit 4) when the request's credential has an expiry.TestMintingCommandsMarkedpins the set.- The creator recorded is always the authenticated request's own token.
token createdefaults to--scope read.token revoke <name>lists what the token created;--createdrevokes all of it at any depth, and keys removed that way cut their connections.- e2e over
POST /api/v1/cmd: an expiring token is refused, a full token's creations are recorded and revoked with it. - API, Threat-Model, Parity and Architecture pages; #257 leaves Known-Gaps.
Upgrade note. Scripts that relied on token create defaulting to full scope must pass --scope full.
Stacked on !480 (revoke-closes-connections); merge that first. 4b94fa9 alone does not build (the store signature change lands before its callers in 89dd0a3).
Closes #257