Hide newly created token after its confirmed revocation - #51
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Revoking a newly created access token on the Agents page left its one-time plaintext result visible even though authentication immediately denied it. The creation result now includes its existing nonsecret token ID, and the panel hides the credential only after the authoritative list confirms revocation of that exact token. Other tokens sharing a name/prefix, pending results and creation errors preserve their intended behavior.
Six regressions exercise real Issue/List/Revoke use cases, the actual creation action and React rendered output with controlled completed hook state. Original source: 2 failed/4 passed; patched focused run including share controls: 12 passed. Web typecheck, targeted lint and whitespace checks pass. Native dispatch/hydration/revalidation of this follow-up remain pending; earlier actual browser audit and PR50 invalid-token401 fix are documented with explicit coverage and cleanup limitations.
Updates the browser audit and release handoff documentation to verified PR50 master results: 1,851 workspace tests plus one paid live skip. AWS activation remains blocked by missing role configuration.
Note
Low Risk
Changes only when the one-time secret is shown in the UI; revocation and token issuance behavior are unchanged aside from exposing token ID in the action result.
Overview
Fixes a UX gap on the Agents page where revoking a newly created access token left the one-time plaintext visible even though the token was already denied.
createAccessTokenActionnow returnstokenId(non-secret) alongside the secret.AgentsPanelonly shows the “Copy your token now” block when creation succeeded and the refreshed token list has not marked that exact ID as revoked—so same-page revoke clears the credential, while revoking another token, a still-active token, a lagging list, or a failed create keeps or replaces the UI correctly.Adds
agents-panel-token-result.test.tswith six regressions (real issue/list/revoke use cases, the actual server action, and static render of the panel via controlleduseActionState). Docs note the follow-up, PR #50 merge evidence, and that full native dispatch/hydration for this change is still pending.Reviewed by Cursor Bugbot for commit a879103. Bugbot is set up for automated code reviews on this repo. Configure here.