- A browser session runs the 22 commands marked
NeedsRecentSignInonly if it signed in within 15 minutes (control.ReauthWindow): every credential mint (keys, deploy keys, runner keys, tokens, email verification, login links, admin user create/invite) and every grant of lasting access (repo access grant, org members and teams, org members-role, repo transfer, admin promote/enable, webhook add, repo secret set, repo mirror add, notification devices, PGP keys). The set is pinned by a registry test. - The sign-in time is
web_sessions.created_at, which idle renewal never moves. The gate keys onSource == control.SourceWeband the user's sign-in time, so a web request without one is refused. SSH, API tokens and host commands are unaffected. Refusals are audited. - The forms show the message and a Sign in again link; after the emailed login the user returns to the page (
gitbay_next, set server-side). The return path also refuses a leading/\. - Threat-Model, Architecture and Users pages; #297 leaves Known-Gaps; CHANGELOG.
Stacked on !512.
Closes #297