fix: Move the API keys page off the /api prefix

/api-keys shares a raw string prefix with /api, and the proxies in front
of this app do not all match by path segment. Nginx Proxy Manager routes
/api straight to the Go server with a prefix location, so /api-keys never
reached Next at all — it reached a control plane with no such route and
came back as a JSON 404. Traefik's PathPrefix has the same shape of
matcher, which puts the Helm ingress at risk whenever ingress.api.enabled
is on.

The page is /tokens now, which cannot collide with anything, and which
matches the /api/tokens the REST API already publishes. The sidebar still
says API Keys — the label is for the reader, the path is for the router.

A permanent redirect covers anyone who bookmarked the old path today.
Fixing the proxy config instead would have left the trap set for the next
deployment, and for whatever sits in front of it.
This commit is contained in:
2026-08-13 09:26:34 +00:00
parent 18495dba68
commit 7e767ecb4f
5 changed files with 19 additions and 5 deletions
+2 -2
View File
@@ -297,7 +297,7 @@ export default function SettingsPage() {
</SectionCard>
{/* The cap lives here rather than on /api-keys because it is
{/* The cap lives here rather than on /tokens because it is
instance policy, not one person's credentials — which is
also what lets that page be reachable at every role. */}
<SectionCard
@@ -313,7 +313,7 @@ export default function SettingsPage() {
</Field>
<p className="mt-4 text-sm text-text-secondary">
Keys themselves are managed on{" "}
<Link href="/api-keys" className="text-accent hover:underline">
<Link href="/tokens" className="text-accent hover:underline">
API Keys
</Link>
, which every member can reach.