feat: bot API token management page

The account page pointed users at a "bot-token list" that didn't exist: there
was no GET endpoint, no UI route, and the client type lacked expiry. Add
GET /v1/auth/tokens (caller-scoped, token_hash never serialised), extend the
auth client with listTokens/expires_at and createToken expiry, and add a
/profile/tokens page to list, create (revealing the raw bearer once), and
revoke tokens. Link the account-page copy to it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-11 14:55:24 +02:00
parent 32d0a7e13b
commit 1ed1a134ea
13 changed files with 561 additions and 8 deletions

View File

@@ -224,8 +224,8 @@
<h2>Change password</h2>
<p class="hint">
Changing your password signs out every other device using this account.
Bot API tokens keep working — revoke them individually from the bot-token
list if you want to invalidate them too.
Bot API tokens keep working — revoke them individually from the
<a href="/profile/tokens">API tokens</a> page if you want to invalidate them too.
</p>
{@render passwordForm()}
</section>