trackslash
TRACK-58 P3

Group web sessions on the tokens page behind a single revoke-all action

0
All issues

Description

The tokens page lists every token individually, including session tokens. Web sessions are hard to track — they are numerous, short-lived, and their names carry little meaning — so listing them one by one is noise that buries the API tokens people actually manage.

Proposed change

On the tokens page (internal/server/templates/tokens.html), split the list by token kind:

  • API tokens — keep the current per-row listing with individual revoke, since these are named, long-lived, and managed deliberately.
  • Web sessions — collapse into a single row showing a count (e.g. "4 active web sessions") with one Revoke all web sessions action. Do not render them individually.

The current session must survive or be handled explicitly: revoking all sessions logs the user out. Either exclude the current session from the bulk action, or clear the cookie and redirect to /login, matching what uiRevokeToken already does when you revoke your own session (internal/server/ui_account_pages.go:136-139).

Implementation notes

  • Token kinds already exist as model.AuthTokenKindAPI / the session kind, so the split is a partition of the existing ListAuthTokens result in renderUITokens (ui_account_pages.go:143).
  • Needs a new store method to revoke all session tokens for a user (optionally excluding one ID) in a single statement, plus a route and handler alongside uiRevokeToken.
  • Follow the existing card and list patterns per COMPONENTS.md; no new visual language.

Related

Pairs with the session auto-expiry ticket, which reduces how many sessions accumulate in the first place.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.