Add delete token UI for info page
This commit is contained in:
@@ -141,7 +141,7 @@ file is accepted.
|
||||
| Route | |
|
||||
|---|---|
|
||||
| `GET /d/{id}` | the file, as an attachment; supports resuming |
|
||||
| `GET /i/{id}` | a page showing name, size, expiry and digest |
|
||||
| `GET /i/{id}` | a page showing name, size, expiry, digest — and where a delete token is used |
|
||||
| `POST /api/d/{id}/delete` | delete, with `token=` in the form or `Authorization: Bearer` |
|
||||
| `POST /api/forget` | clear a remembered token |
|
||||
| `GET /admin` | administration page; admin tokens only |
|
||||
@@ -149,6 +149,15 @@ file is accepted.
|
||||
Deleting accepts the object's delete token, the token that uploaded it, or any
|
||||
admin token.
|
||||
|
||||
The delete token is shown once, when the file is uploaded. To use it later,
|
||||
open the file's info page and expand **Remove this file** — that page is the
|
||||
link worth keeping, since it holds everything about the file including the way
|
||||
to withdraw it. Anyone whose own token already owns the file, or who is an
|
||||
admin, gets a plain button there instead of a field. A wrong token returns to
|
||||
the same page with the reason rather than to a generic error, and repeated
|
||||
failures are throttled per address; a correct token is never delayed by
|
||||
someone else's guessing.
|
||||
|
||||
## Administration
|
||||
|
||||
An admin token adds a page at `/admin`, linked from the header whenever the
|
||||
|
||||
Reference in New Issue
Block a user