LeoVasanko
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
LeoVasanko
9b491164fd
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
LeoVasanko
bb34e52997
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
LeoVasanko
b9897b62b8
Remove trash bin icons from tab order. Instead, implement Delete key support (Backspace accepted on Apple devices).
2025-12-09 16:54:46 +00:00
LeoVasanko
8a21edf367
Process IPv6 display into short format including only the network prefix, and sharing the same code also for comparisons where needed.
2025-12-09 16:33:16 +00:00
LeoVasanko
03368b1b84
Rename base64 functions such that imports don't need renaming.
2025-12-09 15:55:03 +00:00
LeoVasanko
bfc5b11cc2
Fix missing credential_uuid in admin user detail API that was causing linkage between sessions and their passkeys not show up.
2025-12-09 15:34:05 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
83419d1845
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
2025-12-06 04:45:26 +00:00
LeoVasanko
a2fe0b6f1a
Added E2E restricted API flow tests and fixed earlier failing tests. All passing. Coverage 51% backend, 74% frontend.
2025-12-06 03:43:28 +00:00
LeoVasanko
a1b73711e6
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
2025-12-06 03:39:05 +00:00
LeoVasanko
df5c176bcd
Fixed and updated E2E test suite. Added user credential registration tests. Coverage for backend and frontend.
2025-12-06 00:52:35 +00:00
LeoVasanko
8937905c9c
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
2025-12-06 00:51:18 +00:00
LeoVasanko
127e06179b
More robust server startup, startup logo and info screen, renewed devmode script.
2025-12-05 19:06:42 +00:00
LeoVasanko
c1204ca020
Updated documentation.
2025-12-05 16:15:50 +00:00
LeoVasanko
208115ebc3
Project renamed to Paskia.
2025-12-05 13:17:52 +00:00
LeoVasanko
8609f2fe69
Refactor dev mode into a source repo script (remove dev subcommand from package).
2025-12-05 18:36:13 +00:00
LeoVasanko
0355c55fc0
Updated E2E tests.
2025-12-04 04:44:58 +00:00
LeoVasanko
ea1ddbbe6f
Make dev mode run without static files, only serving assets in production.
2025-12-04 10:15:26 +00:00
LeoVasanko
b091744665
Cleanup old hostapp files (finished, working).
2025-12-04 10:06:54 +00:00
LeoVasanko
2cf8799c75
Missing new component.
2025-12-04 10:03:33 +00:00
LeoVasanko
a72349077c
Integrate host app to main app (WIP).
2025-12-04 10:00:47 +00:00
LeoVasanko
e102b8383b
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
2025-12-04 09:19:40 +00:00
LeoVasanko
5aa8d021e6
Brought examples directly to front page.
2025-12-04 08:19:32 +00:00
LeoVasanko
3d5b0aa4bf
Fix view switching of restricted app.
2025-12-04 07:46:36 +00:00
LeoVasanko
29df169a67
Make restricted app use simple fetch that doesn't do API authentication (recursively).
2025-12-04 06:20:14 +00:00
LeoVasanko
97dc459bfb
Fixed and simplified examples.
2025-12-04 06:08:52 +00:00
LeoVasanko
4d4b290cc8
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
2025-12-04 06:01:47 +00:00
LeoVasanko
0e1b9f529b
Log authentication options on the client.
2025-12-04 05:07:44 +00:00
LeoVasanko
0c3e0d3fa5
Improved dialog layout with separate mobile portrait mode.
2025-12-04 04:06:32 +00:00
LeoVasanko
1782547b9e
Fix infinitely nested login iframes when the restricted app notices it needs login.
2025-12-04 03:56:17 +00:00
LeoVasanko
9976e05696
Various fixes and cleanup, regressions from prior commits.
2025-12-04 03:40:59 +00:00
LeoVasanko
6124fa6c01
Fix syntax error in reset app created by earlier commit.
2025-12-04 02:31:13 +00:00
LeoVasanko
a6591a1fbb
Better static files handling on backend, when in dev mode: fetch from vite.
2025-12-04 02:30:02 +00:00
LeoVasanko
b9b1c995f9
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
2025-12-04 01:58:18 +00:00
LeoVasanko
4482a601f3
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
2025-12-04 01:35:44 +00:00
LeoVasanko
aa4b1bfd42
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-04 01:21:52 +00:00
LeoVasanko
2ecf8433a1
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-04 01:00:24 +00:00
LeoVasanko
db892365dc
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-04 00:29:42 +00:00
LeoVasanko
8d02c0f615
Formatting, tidy up, transparent auth dialog background.
2025-12-03 23:31:35 +00:00
LeoVasanko
469d606ce5
Improved apiFetch and jsonFetch functions.
2025-12-03 23:26:38 +00:00
LeoVasanko
547a6cd923
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 23:17:02 +00:00
LeoVasanko
deabee3b5c
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
2025-12-03 22:58:48 +00:00
LeoVasanko
fd1aa11409
Add E2E tests to register and verify passkey.
2025-12-03 02:52:39 +00:00
LeoVasanko
ca1ea9d90b
Always use timezone aware UTC time.
2025-12-03 01:36:15 +00:00
LeoVasanko
2dac0be77a
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
2025-12-03 01:32:05 +00:00
LeoVasanko
f63c62d9ff
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
LeoVasanko
768a4391cf
Improved profile view layout.
2025-12-03 01:03:25 +00:00
LeoVasanko
f64876e73b
Improved profile view layout.
2025-12-03 00:52:52 +00:00
LeoVasanko
b6a3cdd3a4
Fix examples folder serving broken a couple of commits ago.
2025-12-03 00:06:32 +00:00
LeoVasanko
fd9a5afc1c
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00
LeoVasanko
8714fe9319
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
2025-12-02 22:41:12 +00:00
LeoVasanko
adbab88c86
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
LeoVasanko
5d9d2b794d
Refactor restricted app paths and naming.
2025-12-02 19:10:13 +00:00
LeoVasanko
eedbd4aaa4
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
LeoVasanko
15916047fa
Remove backend access control, now that the profile and admin apps handle that via API.
2025-12-02 18:25:58 +00:00
LeoVasanko
643d9bafab
Fix the back buttons (navigate back if you can but close if it was a new window).
2025-12-02 18:02:02 +00:00
LeoVasanko
2699aaa472
Implement Forbidden view for API calls, cleanup and better UX.
2025-12-02 17:36:37 +00:00
LeoVasanko
5422845192
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
LeoVasanko
c1ccb048f0
Update admin app authentication in API mode too, reusing components between it and the main app.
2025-12-02 15:42:55 +00:00
LeoVasanko
3030122807
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
2025-12-02 15:25:31 +00:00
LeoVasanko
d4f8e97469
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
2025-12-02 14:30:31 +00:00
LeoVasanko
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
LeoVasanko
2dca6b1eec
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/ .
2025-12-01 20:07:26 +00:00
LeoVasanko
4f50974222
Updated build-frontend script, now uses deno, npm, bun in this order.
2025-12-01 19:25:08 +00:00
LeoVasanko
c218ddad61
Centralise all cookie handling to session.py.
2025-10-05 06:48:24 +00:00
LeoVasanko
7247f7c584
Refactor /api/user/* to its own module.
2025-10-05 06:41:14 +00:00
LeoVasanko
af2834b4c0
Reset dialog UX improved.
2025-10-05 06:25:40 +00:00
LeoVasanko
ef66baff20
Harmonise ProfileView and HostApp.
2025-10-05 06:14:17 +00:00
LeoVasanko
08d4607d65
Tuning the host app.
2025-10-05 06:03:28 +00:00
LeoVasanko
1ca9e3ef58
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-05 05:55:08 +00:00
LeoVasanko
575d3cb1fb
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-05 05:26:03 +00:00
LeoVasanko
a4ac19f54c
WebSockets must use origin for finding the host calling them.
2025-10-05 05:16:51 +00:00
LeoVasanko
11887d15b2
Correction on restricted path checking (auth-host).
2025-10-05 04:59:05 +00:00
LeoVasanko
cefb9c3d92
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-05 04:49:23 +00:00
LeoVasanko
5b9a3fc27f
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-05 04:35:55 +00:00
LeoVasanko
19a6c32cf2
Fix deletion of session cookie on host logout.
2025-10-05 04:26:36 +00:00
LeoVasanko
eaa16abe2a
Better UX for profile view logout buttons.
2025-10-05 04:22:16 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
f24aaa295d
More consistent shared styling between credential and session cards.
2025-10-04 20:32:27 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
24692fcfec
Use git tag versioning for the Python project.
2025-10-03 04:07:11 +00:00
LeoVasanko
43850c218f
Fix reset link logic to include /auth when no configured auth-host.
2025-10-03 03:57:20 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
b4871c671f
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-03 00:22:02 +00:00
LeoVasanko
095768e07c
Version 0.2.0
2025-10-01 05:04:53 +00:00
LeoVasanko
2f77753354
Make the login/reset/forbidden dialogs look better.
2025-10-01 05:03:51 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
c3e4c18d5c
Remove duplicate message from permission denied page.
2025-10-01 00:56:41 +00:00
LeoVasanko
a7c23b31e7
Admin app divided to separate components.
2025-10-01 00:54:18 +00:00
LeoVasanko
3f45024396
Massive style redesign, WIP.
2025-09-30 09:02:49 +00:00
LeoVasanko
2d2e4e899d
Simplified Caddy snippets (removed auth/all).
2025-09-29 08:00:19 +00:00
LeoVasanko
48f718191f
Version 0.1.2
2025-09-29 07:46:49 +00:00
LeoVasanko
e130bc5c0a
Clear sessionStorage on logout.
2025-09-29 07:45:37 +00:00
LeoVasanko
2df444b80f
chore: bump version to 0.1.1
2025-09-28 08:51:46 +00:00
LeoVasanko
5ad3ccb5ae
Implement breadcrumb navigation.
2025-09-28 08:47:45 +00:00
LeoVasanko
ec098b862c
Implement credential reset via CLI.
2025-09-27 05:18:33 +00:00
LeoVasanko
bd5a920a56
Update documentation.
2025-09-27 04:59:18 +00:00
LeoVasanko
88275beb0f
Make the /auth/api/validate endpoint renew sessions if needed.
2025-09-27 04:59:11 +00:00