Settings
Settings displays real server state with a next action, not placeholder statistics.
Surface contract
Primary object: the caller’s profile and credentials, the registered sessions, and the organization’s export and deletion records — each the server’s own answer.
Actions
- EditEdits the display name through PATCH /v1/me; locale and retention are revision-bound policy rules on the Policies surface. A refused change keeps the API detail and the typed value.
- ExportRequest tenant export builds the archive server-side (POST /v1/tenant/export, owner/admin) and the download link appears only after the server reports the archive ready, with its counts and digest.
- Delete workspaceDelete tenant purges the organization’s cloud rows after the confirmation dialog echoes its id/slug (the server requires x-docsloth-confirm); a wrong confirmation is refused with 428 and nothing is deleted.
Required states and how this surface reaches them
- loading
- the session probe and each list show Loading… until the control plane answers.
- ready
- the server’s own records render as returned; the primary object is named before its details.
- empty
- a provider-only account has no password until one is set; an organization has no export until one is requested — both are stated, not errors.
- error
- the control plane’s status and detail are shown; no placeholder row replaces them.
- offline
- no control plane is reachable; nothing is rendered rather than invented.
- permission_denied
- a 403 on export or deletion states that only an owner/admin may perform it; a 401 returns to sign-in with this path.
- not_configured
- email changes answer 503 when SMTP is unconfigured, and the page says no verification email was sent instead of claiming one.
- budget_paused
- a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
- requires_approval
- deletion requires echoing the organization slug in the confirmation header; a wrong confirmation is refused with the server’s 428 detail and nothing is purged.
Scope: workspace membership (export and deletion are owner/admin). Locale and retention are control-plane policy values on the Policies surface, not a second settings store; this page never deletes or exports anything the server did not confirm.
Profile
The display name other members see.
Loading…
Changing the address requires a verification link sent to the new address.
Loading…
Password
Set a password, or change the existing one. If this account was created with an identity provider, there is no password yet — setting one adds password sign-in.
Loading…
Active sessions
Sessions signed in to this account. The current one is marked when the API identifies it.
Loading…
Data rights
Export or delete this organization's data. Both operations go through the control plane and report its answer.
Loading…