Skip to content

Hide newly created token after its confirmed revocation - #51

Merged
jckail merged 1 commit into
masterfrom
codex/pointup-revoked-token-display-20261002
Oct 2, 2026
Merged

jckail merged 1 commit into
masterfrom
codex/pointup-revoked-token-display-20261002

Conversation

@jckail

@jckail jckail commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Revoking a newly created access token on the Agents page left its one-time plaintext result visible even though authentication immediately denied it. The creation result now includes its existing nonsecret token ID, and the panel hides the credential only after the authoritative list confirms revocation of that exact token. Other tokens sharing a name/prefix, pending results and creation errors preserve their intended behavior.

Six regressions exercise real Issue/List/Revoke use cases, the actual creation action and React rendered output with controlled completed hook state. Original source: 2 failed/4 passed; patched focused run including share controls: 12 passed. Web typecheck, targeted lint and whitespace checks pass. Native dispatch/hydration/revalidation of this follow-up remain pending; earlier actual browser audit and PR50 invalid-token401 fix are documented with explicit coverage and cleanup limitations.

Updates the browser audit and release handoff documentation to verified PR50 master results: 1,851 workspace tests plus one paid live skip. AWS activation remains blocked by missing role configuration.


Note

Low Risk
Changes only when the one-time secret is shown in the UI; revocation and token issuance behavior are unchanged aside from exposing token ID in the action result.

Overview
Fixes a UX gap on the Agents page where revoking a newly created access token left the one-time plaintext visible even though the token was already denied.

createAccessTokenAction now returns tokenId (non-secret) alongside the secret. AgentsPanel only shows the “Copy your token now” block when creation succeeded and the refreshed token list has not marked that exact ID as revoked—so same-page revoke clears the credential, while revoking another token, a still-active token, a lagging list, or a failed create keeps or replaces the UI correctly.

Adds agents-panel-token-result.test.ts with six regressions (real issue/list/revoke use cases, the actual server action, and static render of the panel via controlled useActionState). Docs note the follow-up, PR #50 merge evidence, and that full native dispatch/hydration for this change is still pending.

Reviewed by Cursor Bugbot for commit a879103. Bugbot is set up for automated code reviews on this repo. Configure here.

@jckail
jckail merged commit 99465f4 into master Oct 2, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant