Add delete token UI for info page

This commit is contained in:
2026-09-13 00:32:51 +02:00
parent ca34f1506d
commit 74bfdbfd8a
9 changed files with 293 additions and 25 deletions
+10 -1
View File
@@ -141,7 +141,7 @@ file is accepted.
| Route | |
|---|---|
| `GET /d/{id}` | the file, as an attachment; supports resuming |
| `GET /i/{id}` | a page showing name, size, expiry and digest |
| `GET /i/{id}` | a page showing name, size, expiry, digest — and where a delete token is used |
| `POST /api/d/{id}/delete` | delete, with `token=` in the form or `Authorization: Bearer` |
| `POST /api/forget` | clear a remembered token |
| `GET /admin` | administration page; admin tokens only |
@@ -149,6 +149,15 @@ file is accepted.
Deleting accepts the object's delete token, the token that uploaded it, or any
admin token.
The delete token is shown once, when the file is uploaded. To use it later,
open the file's info page and expand **Remove this file** — that page is the
link worth keeping, since it holds everything about the file including the way
to withdraw it. Anyone whose own token already owns the file, or who is an
admin, gets a plain button there instead of a field. A wrong token returns to
the same page with the reason rather than to a generic error, and repeated
failures are throttled per address; a correct token is never delayed by
someone else's guessing.
## Administration
An admin token adds a page at `/admin`, linked from the header whenever the