web: API tokens on the settings page; web UX final-review fixes !507

merged merged by cmc on 2026-09-28 23:23 UTC · krz/gitbay:web-api-tokens into main

Discussion

cmc

API tokens on the settings page, and the web UX plan's final-review fixes.

  • Settings → API tokens lists each token (scope, created, expires, last used), creates one with a chosen scope (read by default) and an optional expiry, and revokes one after its name is typed back. Both dispatch token create / token revoke --; the new token is shown once, in the response to the POST that made it, with Cache-Control: no-store, and never again. token revoke --created stays CLI only.
  • The registered page's next steps are a numbered list.
  • Final-review fixes for the plan:
    • A reader who owns a writable fork gets New merge request on the MR list and compare pages again.
    • The new-issue form keeps milestone and assignee on preview and shows a refused create's message on the form with the draft kept.
    • Issues, milestones, org milestones and releases empty states quote no CLI commands.
    • The range-diff page shows a bad revision's message instead of a 404.
    • Parity rows for range-diff and token list/revoke, privacy and settings wording, two e2e assertions that could not fail.
  • CHANGELOG.

A browser session can create tokens here that outlive it; that is #297, already open for keys and deploy keys.

Stacked on !506 (pack-limit).

Closes #264