Most of this shipped in #139 (aggregate row, bulk revoke, confirmation, htmx redirect). The remaining gap was the count itself.
Bug: sessions get a 7-day expiry (TRACK_SLASH_SESSION_TTL), but the sweep in 0040_session_token_expiry.sql only revokes sessions older than three years. uiPartitionAuthTokens counted anything unrevoked, so expired-but-unswept sessions were reported as active. Signing in from a new browser weekly builds up to ~150 "active web sessions" when exactly one still authenticates.
Fix (#147):
AuthToken.Live(now)names the predicateAuthenticateTokenalready applies in SQL — unrevoked and unexpired — so the listing and the auth path cannot drift.uiPartitionAuthTokenscounts sessions with that predicate.- Zero case reads "No active web sessions" rather than "0 active web sessions"; that is what an API-token-only account sees.
Coverage: AuthToken.Live and uiPartitionAuthTokens at 100%. New tests for the expiry boundary, aggregation, an expired session being ignored, and the empty state. Successful bulk revoke and the htmx path were already covered.
Full ./internal/... suite passes against Postgres.