From 7780ef1e54dbed89d645a5a85ca1f1953755eb24 Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Thu, 8 Oct 2026 17:17:18 -0500 Subject: [PATCH] docs: runbook token listing reads the items envelope (sage) Darkwing's correction, checked against the 2.7.0 OpenAPI: GET /tokens returns PaginatedAPIToken, with items possibly null. Co-Authored-By: Claude Opus 5.5 --- docs/guides/slice-1-identities.md | 2 +- docs/plans/2026-09-26_lead-decisions.md | 5 +++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/docs/guides/slice-1-identities.md b/docs/guides/slice-1-identities.md index 4877d2ce..a4cdc738 100644 --- a/docs/guides/slice-1-identities.md +++ b/docs/guides/slice-1-identities.md @@ -357,7 +357,7 @@ role. The stack never writes this file. `svc -X DELETE "$VK/api/v2/tokens/"`. A revoke hits that one token, and it gets 401 on its next request. `mint` printed the old id. If you didn't keep it, list the bot's tokens as `svc-$BIZ`: - `svc "$VK/api/v2/tokens?owner_id=" | jq -c '.[] | {id, title, expires_at}'`. + `svc "$VK/api/v2/tokens?owner_id=" | jq -c '.items[]? | {id, title, expires_at}'`. A plain `GET /tokens` lists only svc's own tokens, which is none, and the owner's account gets 403 on the revoke. Then finish with section 4's `rm -f`, which deletes the header. The broker refuses to diff --git a/docs/plans/2026-09-26_lead-decisions.md b/docs/plans/2026-09-26_lead-decisions.md index 2f1489c0..86281a4b 100644 --- a/docs/plans/2026-09-26_lead-decisions.md +++ b/docs/plans/2026-09-26_lead-decisions.md @@ -1246,3 +1246,8 @@ which stay with him. Each item names who decided it and what happened. names `GET /tokens?owner_id=` as svc for finding an old id. The async update lag has an upper bound of 5 s under load, inside S3's 60 s overlap window (section U). + - Correction (Darkwing, same day): `GET /tokens` answers with the + paginated `{items, ...}` envelope (`PaginatedAPIToken` in the + 2.7.0 OpenAPI), not a bare array. The probe's `items ?? body` + read hid it. The runbook's listing line now reads `.items[]?`, + which also covers a null `items`.