mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-19 20:28:34 +00:00
feat(user): Personal access tokens can be regenerated (#38907)
Lets users regenerate a personal access token's value in place, keeping its name and scopes, instead of deleting and recreating it. Useful when a token was shared with a third party (e.g. an AI agent) and needs to be invalidated immediately without redoing scope selection. Follows the same pattern already used for OAuth2 application client secrets (`GenerateClientSecret`/`RegenerateSecret`). **Testing**: added a model unit test and a web integration test; manually verified in the running dev server that the old token stops authenticating and the new one works immediately after regenerating. <img width="1040" height="245" alt="image" src="https://github.com/user-attachments/assets/4de0d8b4-1fc4-49cf-a859-95e24d0b2c0a" /> Fixes #38683. --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
@@ -854,6 +854,9 @@
|
||||
"settings.access_token_deletion_confirm_action": "Delete",
|
||||
"settings.access_token_deletion_desc": "Deleting a token will revoke access to your account for applications using it. This cannot be undone. Continue?",
|
||||
"settings.delete_token_success": "The token has been deleted. Applications using it no longer have access to your account.",
|
||||
"settings.regenerate_token": "Regenerate",
|
||||
"settings.access_token_regeneration": "Regenerate Access Token",
|
||||
"settings.access_token_regeneration_desc": "Regenerating a token immediately invalidates its old value; applications still using the old value will lose access. Its name and permissions are kept. This cannot be undone. Continue?",
|
||||
"settings.repo_and_org_access": "Repository and Organization Access",
|
||||
"settings.permissions_public_only": "Public only",
|
||||
"settings.permissions_access_all": "All (public, private, and limited)",
|
||||
|
||||
Reference in New Issue
Block a user