Description
The tokens page lists every token individually, including session tokens. Web sessions are hard to track — they are numerous, short-lived, and their names carry little meaning — so listing them one by one is noise that buries the API tokens people actually manage.
Proposed change
On the tokens page (internal/server/templates/tokens.html), split the list by token kind:
- API tokens — keep the current per-row listing with individual revoke, since these are named, long-lived, and managed deliberately.
- Web sessions — collapse into a single row showing a count (e.g. "4 active web sessions") with one Revoke all web sessions action. Do not render them individually.
The current session must survive or be handled explicitly: revoking all sessions logs the user out. Either exclude the current session from the bulk action, or clear the cookie and redirect to /login, matching what uiRevokeToken already does when you revoke your own session (internal/server/ui_account_pages.go:136-139).
Implementation notes
- Token kinds already exist as
model.AuthTokenKindAPI/ the session kind, so the split is a partition of the existingListAuthTokensresult inrenderUITokens(ui_account_pages.go:143). - Needs a new store method to revoke all session tokens for a user (optionally excluding one ID) in a single statement, plus a route and handler alongside
uiRevokeToken. - Follow the existing card and list patterns per
COMPONENTS.md; no new visual language.
Related
Pairs with the session auto-expiry ticket, which reduces how many sessions accumulate in the first place.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.