f4f6c9c9e9
- The empty state is about an empty library, not a brand-new Reader:
listView.Fresh becomes EmptyLibrary and moves behind the tab-specific
branches, so "No favourites yet" is no longer shadowed for a Reader whose
library happens to be empty. The action key stays put — hiding it was
never asked for.
- The owner is not a revocable Reader: their row offers no button and
POST /readers/{owner}/revoke is a 404, so the one row where the control
would sign out the tapping browser cannot be reached by a hand-rolled
POST either.
- Modify isolation is asserted in both directions, and the owner's own
sign-in through the OAuth callback is pinned to the seeded row.
- CUTOVER.md and REDEPLOY.md still grepped API_TOKEN out of .env for their
smoke tests, which the last commit deleted; both now take the acting
Reader's derived credential.
- Roster type follows the machine-fact spec (500 10-11px mono, tracked),
and PRODUCT.md names the Readers panel instead of claiming there is no
owner surface at all.
30 lines
1.4 KiB
HTML
30 lines
1.4 KiB
HTML
{{/* The owner's Reader roster. Rendered only for the owner (listView.Owner),
|
|
and re-rendered whole as the response to a revocation so the session
|
|
counts cannot describe the state before the tap. Revocation is
|
|
confirm-gated: it signs someone out of every device at once. */}}
|
|
{{define "readers"}}
|
|
<details class="setup" id="readers">
|
|
<summary>Readers</summary>
|
|
<p class="setup-copy">Everyone who has signed in through Discord. Revoking
|
|
signs a Reader out of every device; their library and bookmarks are
|
|
untouched, and they can sign in again.</p>
|
|
<ul class="readerlist">
|
|
{{range .Readers}}
|
|
<li>
|
|
<span class="reader-id">{{.DiscordID}}</span>
|
|
<span class="reader-sessions">{{.Sessions}} session{{if ne .Sessions 1}}s{{end}}</span>
|
|
{{/* The owner's own row never offers Revoke: it is the one row where the
|
|
button would sign the tapping browser out, and the endpoint refuses
|
|
it anyway. Logout is the deliberate way to do that. */}}
|
|
{{if and .Sessions (ne .ID $.OwnerID)}}
|
|
<form hx-post="/readers/{{.ID}}/revoke" hx-target="#readers" hx-swap="outerHTML"
|
|
hx-confirm="Revoking signs this Reader out on every device immediately. Revoke?">
|
|
<button type="submit" class="ghost danger">Revoke sessions</button>
|
|
</form>
|
|
{{end}}
|
|
</li>
|
|
{{end}}
|
|
</ul>
|
|
</details>
|
|
{{end}}
|