Range-diff !488

back to !488 web login over SSH applies the login-link limit

 -:  ------- >  1:  9f77ab1 store: announce key revocations; LiveSSHKeys
 -:  ------- >  2:  bf64c30 gitutil: Transport takes a cancel channel and kills its process group
 -:  ------- >  3:  c096948 sshd: re-read the key per exec; revocation cuts its connections
 -:  ------- >  4:  2b84081 e2e: removing a key cuts its multiplexed connection and a push in flight
 -:  ------- >  5:  4bbf4f8 wiki: revocation closes open connections
 -:  ------- >  6:  4b94fa9 store: tokens and keys record the token that created them; chained revoke
 -:  ------- >  7:  89dd0a3 control: expiring credentials cannot run credential-minting commands
 -:  ------- >  8:  dd36248 token: default --scope read; record the creating token; revoke --created
 -:  ------- >  9:  ed682bb e2e: expiring tokens refused on minting; revoke --created
 -:  ------- > 10:  0787c7c wiki: token delegation, read default; release note
 -:  ------- > 11:  e2a32d5 wiki: delegation bound covers tokens and keys, not web sessions
 1:  2240cff = 12:  cab50f5 store: ssh_keys.expires_at; expired keys are not live
 2:  f10d090 = 13:  7f5c45d sshd: refuse expired keys at auth and per exec; expiring keys cannot mint
 3:  5fea0e6 = 14:  44e5fb3 keys: --ttl on keys add and repo deploy-key add; lists show last use and expiry
 4:  e54f028 ! 15:  1ed9fb9 wiki: key expiry
    @@ .gitbay/wiki/Architecture/09-Controls.org: chapter names of OWASP ASVS 4.0 where
     -| Credential expiry                           | partial  | API tokens optional; SSH and deploy keys none (#277)                    |
     +| Credential expiry                           | in place | optional =--ttl= on API tokens, SSH and deploy keys; checked at auth and per exec |
      | Revocation takes effect immediately         | in place | removing a key or disabling an account closes its connections; every exec re-reads its key (=internal/sshd/sshd.go=) |
    - | Delegation bounded by the delegating credential | in place | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=) |
    + | Delegation bounded by the delegating credential | partial | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=); a web session can still mint credentials that outlive it (#297) |
      
     
      ## .gitbay/wiki/Architecture/10-Known-Gaps.org ##
    @@ .gitbay/wiki/Users.org: A key's label is the comment on its =authorized_keys= li
     
      ## CHANGELOG.org ##
     @@ CHANGELOG.org: must add =--scope full=. Existing tokens keep their scope.
    -   those too.
    +   those too (#257).
      - Removing an SSH key, a deploy key, or disabling an account closes the
        connections the key opened, a push in flight included (#256).
     +- =keys add= and =repo deploy-key add= take =--ttl=; an expired key is
 5:  498c90d = 16:  03040d2 control: keys add refuses --ttl 0h and negative
 6:  3a83e2a = 17:  2ddf238 control: token list uses expiresText, not relAge, for expiry
 -:  ------- > 18:  32a5f76 control: key lists fit 60 columns; headers clip with their column
 -:  ------- > 19:  a8ba660 sshd: an expired key counts against the auth limiter
 -:  ------- > 20:  253e1a2 token: create refuses a zero or negative --ttl
 7:  bed7020 = 21:  a6f7827 store: web sessions lapse after 12 hours idle, under the absolute cap
 8:  acc63bd ! 22:  0ff41e5 web: sessions list shows last use; docs for the idle timeout
    @@ .gitbay/wiki/Architecture/09-Controls.org: chapter names of OWASP ASVS 4.0 where
     +| Session lifetime                            | in place | 12 hours idle, 7 days absolute (=internal/store/sessions.go=)            |
      | Credential expiry                           | in place | optional =--ttl= on API tokens, SSH and deploy keys; checked at auth and per exec |
      | Revocation takes effect immediately         | in place | removing a key or disabling an account closes its connections; every exec re-reads its key (=internal/sshd/sshd.go=) |
    - | Delegation bounded by the delegating credential | in place | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=) |
    + | Delegation bounded by the delegating credential | partial | expiring tokens refused on =MintsCredential= commands; credentials record their creating token (=internal/control/control.go=); a web session can still mint credentials that outlive it (#297) |
     
      ## .gitbay/wiki/Architecture/10-Known-Gaps.org ##
     @@ .gitbay/wiki/Architecture/10-Known-Gaps.org: what the 2026-09-27 review found; remove a row when its issue closes.
    @@ .gitbay/wiki/Users.org: and deletes through the commands above.
     
      ## CHANGELOG.org ##
     @@ CHANGELOG.org: must add =--scope full=. Existing tokens keep their scope.
    -   15 seconds. An expiring key cannot create credentials, like an
    -   expiring token. =keys list= and =repo deploy-key list= gain =USED= and
        =EXPIRES= columns, after the label (#277).
    + - =token list= at a terminal shows a future expiry as a time, not
    +   "just now" (#286).
     +- Browser sessions end after twelve hours without a request, and after
     +  seven days as before. Sessions open at upgrade get a fresh twelve
     +  hours. =web sessions list= shows when each was last used (#276).
 -:  ------- > 23:  08a7e44 changelog: the unreleased lead names the session idle timeout
 9:  dc058e2 = 24:  6f553fe web: login over SSH applies the login-link limit