API tokens on the settings page, and the web UX plan's final-review fixes.
- Settings → API tokens lists each token (scope, created, expires, last used), creates one with a chosen scope (read by default) and an optional expiry, and revokes one after its name is typed back. Both dispatch
token create/token revoke --; the new token is shown once, in the response to the POST that made it, withCache-Control: no-store, and never again.token revoke --createdstays CLI only. - The registered page's next steps are a numbered list.
- Final-review fixes for the plan:
- A reader who owns a writable fork gets New merge request on the MR list and compare pages again.
- The new-issue form keeps milestone and assignee on preview and shows a refused create's message on the form with the draft kept.
- Issues, milestones, org milestones and releases empty states quote no CLI commands.
- The range-diff page shows a bad revision's message instead of a 404.
- Parity rows for range-diff and token list/revoke, privacy and settings wording, two e2e assertions that could not fail.
- CHANGELOG.
A browser session can create tokens here that outlive it; that is #297, already open for keys and deploy keys.
Stacked on !506 (pack-limit).
Closes #264