token: expiring credentials cannot mint; record creator; default read !483

merged merged by cmc on 2026-09-28 21:48 UTC · krz/gitbay:token-delegation into main

Discussion

cmc

Expiring credentials cannot mint lasting ones; credentials record the token that created them.

  • Migration 0060: api_tokens and ssh_keys gain created_by_token (ON DELETE SET NULL).
  • Command.MintsCredential marks token create, keys add, repo deploy-key add, admin invite, web login, repo runner add, admin user create, email verify and admin email verify; Dispatch refuses them (exit 4) when the request's credential has an expiry. TestMintingCommandsMarked pins the set.
  • The creator recorded is always the authenticated request's own token.
  • token create defaults to --scope read.
  • token revoke <name> lists what the token created; --created revokes all of it at any depth, and keys removed that way cut their connections.
  • e2e over POST /api/v1/cmd: an expiring token is refused, a full token's creations are recorded and revoked with it.
  • API, Threat-Model, Parity and Architecture pages; #257 leaves Known-Gaps.

Upgrade note. Scripts that relied on token create defaulting to full scope must pass --scope full.

Stacked on !480 (revoke-closes-connections); merge that first. 4b94fa9 alone does not build (the store signature change lands before its callers in 89dd0a3).

Closes #257