Token creation returns 200 instead of redirecting, so a reload creates a duplicate token
Description
POST /tokens answers 200 with the rendered page instead of following Post/Redirect/Get, so a browser reload re-submits the form and silently creates a second token.
internal/server/ui_account_pages.go:122 — uiCreateToken ends with s.renderUITokens(w, r, "", created.RawToken), a 200.
Its neighbour uiRevokeToken (ui_account_pages.go:140) does the right thing: http.Redirect(w, r, "/tokens", http.StatusSeeOther).
Steps to reproduce
- Go to Tokens, create a token named
ci. - Press browser reload and confirm the resubmission prompt.
Actual
A second token named ci is created. Repeating the reload keeps creating more.
Expected
Reload re-renders the tokens list without creating anything.
Fix
Redirect after a successful create. The wrinkle is that the raw token is shown exactly once and cannot be recovered after a redirect — carry it via a one-shot flash (session value or signed short-lived cookie) read and cleared by the subsequent GET /tokens, rather than rendering it inline from the POST. Keep the current inline render for the validation-error paths (:112, :117, :127), which correctly re-render without creating anything.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.