trackslash
TRACK-79 P3

Remove revoked API tokens from the Tokens page list

0
All issues

Description

Problem

When you revoke an API token on the Tokens page, it stays in the list for good with a "revoked" badge (tokens.html:31). A revoked token can't be used or restored, so these rows are just clutter, and they bury the tokens that are still live.

Expected behavior

Once a token is revoked, it no longer appears in the API tokens list from the next page load onwards. The revoke action already redirects back to /tokens, so in practice the row disappears straight after you revoke it.

Acceptance criteria

  • uiPartitionAuthTokens (internal/server/ui_account_pages.go:276) drops API tokens that have RevokedAt set, so they are never rendered.
  • The "revoked" badge and the {{if not .RevokedAt}} guard around the Revoke button in tokens.html are no longer reachable, so remove them.
  • When no live tokens are left, the empty state is shown. Its copy still makes sense when tokens have been revoked (e.g. "No active API tokens" rather than "No API tokens yet").
  • Revoked tokens stay in auth_tokens. This only changes the page, not the data: no hard delete.
  • Tests: a revoked token is not rendered on the Tokens page, and an unrevoked one still is.

Open questions

  • Should expired API tokens be hidden as well? They are just as unusable as revoked ones.
  • The MCP/API token listing (track_list_my_tokens) still returns revoked tokens. Suggest leaving it unchanged, since API callers may want the full history.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/track-slash-app/pull/169 (merged as c874f37).

  • uiPartitionAuthTokens now keeps only unrevoked API tokens, so a revoked token leaves the Tokens page list as soon as the revoke redirects back to /tokens.
  • The row stays in auth_tokens. The API and MCP token listings are unchanged.
  • The "revoked" badge is gone, and the empty state now reads "No active API tokens."
  • Open question left as is: expired API tokens still show, with their expiry date.