web: mints and grants need a sign-in from the last 15 minutes !513

merged merged by cmc on 2026-09-29 02:25 UTC · krz/gitbay:web-mint-reauth into main

Discussion

cmc
  • A browser session runs the 22 commands marked NeedsRecentSignIn only if it signed in within 15 minutes (control.ReauthWindow): every credential mint (keys, deploy keys, runner keys, tokens, email verification, login links, admin user create/invite) and every grant of lasting access (repo access grant, org members and teams, org members-role, repo transfer, admin promote/enable, webhook add, repo secret set, repo mirror add, notification devices, PGP keys). The set is pinned by a registry test.
  • The sign-in time is web_sessions.created_at, which idle renewal never moves. The gate keys on Source == control.SourceWeb and the user's sign-in time, so a web request without one is refused. SSH, API tokens and host commands are unaffected. Refusals are audited.
  • The forms show the message and a Sign in again link; after the emailed login the user returns to the page (gitbay_next, set server-side). The return path also refuses a leading /\.
  • Threat-Model, Architecture and Users pages; #297 leaves Known-Gaps; CHANGELOG.

Stacked on !512.

Closes #297