Files
gitea/models/auth/token_cache.go
T
7857c5f843 feat(user): Personal access tokens can be regenerated (#38907)
Lets users regenerate a personal access token's value in place, keeping
its name and scopes, instead of deleting and recreating it. Useful when
a token was shared with a third party (e.g. an AI agent) and needs to
be invalidated immediately without redoing scope selection.

Follows the same pattern already used for OAuth2 application client
secrets (`GenerateClientSecret`/`RegenerateSecret`).

**Testing**: added a model unit test and a web integration test;
manually
verified in the running dev server that the old token stops
authenticating
and the new one works immediately after regenerating.

<img width="1040" height="245" alt="image"
src="https://github.com/user-attachments/assets/4de0d8b4-1fc4-49cf-a859-95e24d0b2c0a"
/>

Fixes #38683.

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-08-17 18:17:16 +00:00

24 lines
497 B
Go

// Copyright 2026 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package auth
import (
"sync"
"gitea.dev/modules/setting"
lru "github.com/hashicorp/golang-lru/v2"
)
type TokenCacheItem struct {
TokenID int64
TokenHash string
}
var TokenCache = sync.OnceValue(func() *lru.Cache[string, *TokenCacheItem] {
cacheSize := max(setting.SuccessfulTokensCacheSize, 20)
c, _ := lru.New[string, *TokenCacheItem](cacheSize) // it only fails when size <= 0
return c
})