DocslothSecurity
checking session

Security

Security displays real server state with a next action, not placeholder statistics.

Surface contract

Primary object: the signed-in identity’s live sessions, the scoped service tokens for this workspace, and the deployment’s identity-provider configuration.

Actions

  • Revoke sessionSends DELETE /v1/me/sessions, which revokes every registered session except this one through the per-user epoch; the server’s own confirmation is shown.
  • Create scoped tokenOpens the API tokens surface: POST /v1/tokens mints a dst_ token bound to this organization with read/author/admin scopes, shown once and revoked by DELETE /v1/tokens/{id}.
  • Configure OIDCDeployment operatorSign-in providers are configured by the deployment operator through OIDC_ISSUER_URL, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET and OIDC_REDIRECT_URI (or the Google/GitHub login credentials). This build has no in-app OIDC form, so it states the variables instead of offering a control that cannot save.
Required states and how this surface reaches them
loading
the session probe and each list show Loading… until the control plane answers.
ready
the server’s own records render as returned; the primary object is named before its details.
empty
no second session is registered; the direct action is signing in elsewhere, which the server then lists here.
error
the control plane’s status and detail are shown; no placeholder row replaces them.
offline
no control plane is reachable; nothing is rendered rather than invented.
permission_denied
a 401 returns to sign-in; the session list cannot be read without a session.
not_configured
identity-provider settings missing from the deployment are stated as environment facts; unconfigured providers are shown disabled.
budget_paused
a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
requires_approval
mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.

Scope: workspace membership. Sessions are the caller’s own records (the server never shows another user’s session); token scopes are checked server-side per request, and this page never grants a scope or revokes one in the client.

Active sessions

Browser sessions registered by the control plane. Revocation bumps the per-user epoch, so a revoked cookie dies on every API instance.

Loading…

Identity provider

Sign-in is configured by the deployment operator; this build has no in-app OIDC form.

Loading…

Revoke all sessions

DELETE /v1/me/sessions?all=true revokes every session for this identity and bumps its epoch, including this one. Nothing is sent until you confirm.