72e52283516b399ecb682c7002f961ea34720100
Mint, resolve, list and revoke, with the effective role capped at the owner's and recomputed per request rather than frozen at creation. Deleting a user deletes their tokens in the same call, so offboarding is one action. Revoking somebody else's token answers not-found rather than forbidden, since a 403 confirms the credential exists. Also re-exports shared.APITokenMaxDays into server/internal/models, following the existing ValidRole wrapper pattern, since the token service needs it and it was never re-exported.
Description
No description provided
9.7 MiB
Languages
JavaScript
63.9%
Go
19.3%
TypeScript
16.6%