LeoVasanko
1062b5d6c8
Fix background task still running twice, and add a check to prevent that happening again (double expiry).
2026-01-27 23:51:13 +00:00
LeoVasanko
3d49cbf2d6
Disable API docs that display very much broken due to missing request/response typing.
2026-01-27 23:27:42 +00:00
LeoVasanko
13c49aebfd
Remove unnecessary use of async now that db access doesn't need awaiting.
2026-01-27 23:16:17 +00:00
LeoVasanko
9b505ff553
DB background worker cleanup, avoid issue with double cleanup. Faster write to disk.
2026-01-27 22:21:33 +00:00
LeoVasanko
cf1124c251
DB transactions cleanup, better actor/user data. Simplified admin API. Use UUID to refer to a specific permission in admin API. Other cleanup.
2026-01-27 21:48:21 +00:00
LeoVasanko
7504aaf7e0
Move imports to top of file.
2026-01-27 20:16:32 +00:00
LeoVasanko
e8247a2c7f
Remove most remaining DB getters. Add ws auth chat helper function to avoid repetition, along with the existing register chat in wschat.py.
2026-01-27 20:01:17 +00:00
LeoVasanko
968964c4c9
Remove db.get_session.
2026-01-27 18:28:32 +00:00
LeoVasanko
6aa1a08e39
Remove list_sessions_for_user, inline db access at call sites.
2026-01-27 18:25:29 +00:00
LeoVasanko
31f40d874c
DB cleanup: removed get_permission_organizations and build_org. Using db.data() for read access at call sites.
2026-01-27 18:23:17 +00:00
LeoVasanko
8f862fb4d1
Consistently use UUID type in APIs instead of UUID str as option.
2026-01-27 16:24:02 +00:00
LeoVasanko
cfb917da46
DB getter refactoring. Documented call sites. Added separate function for by-scope permission lookup.
2026-01-27 15:54:28 +00:00
LeoVasanko
86966526c4
Finalize database API class merge.
2026-01-27 03:00:18 +00:00
LeoVasanko
3196aa7688
Refactor API to match database, no _uuid postfixes.
2026-01-27 02:32:46 +00:00
LeoVasanko
cb84a81a06
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
LeoVasanko
9bdca1f43a
Finish the database key-in-object refactoring.
2026-01-27 02:11:09 +00:00
LeoVasanko
0f29544bdb
Database cleanup, better UUID passing and construction (User model).
2026-01-27 01:25:52 +00:00
LeoVasanko
4ddaa9fdf4
Cleanup and bugfixes on Bootstrap and JSONL handling.
2026-01-26 23:54:03 +00:00
LeoVasanko
7e568dbd10
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
LeoVasanko
fbc6108b7a
Fix frontend-build location. Cleanup.
2026-01-25 03:26:22 +00:00
LeoVasanko
5ee7443801
Use fastapi-vue-setup, merging its template scripts to old Paskia entry point and devserver. Simplified CLI, no longer uses serve subcommand. Fixed the URL displayed on banner to show to actual frontend/caddy server even in devmode.
2026-01-25 03:15:50 +00:00
LeoVasanko
2100a7e14f
Logging cleanup, linter.
2026-01-24 01:08:00 +00:00
LeoVasanko
aae33e60ce
Fix errors where permission scopes were still expected for indexing.
2026-01-24 00:58:18 +00:00
LeoVasanko
cebef8adfc
Large refactoring for better JSONL context. Switched back the urlsafe for session tokens that need to be passed in URLs. Other minor fixes.
2026-01-24 00:40:32 +00:00
LeoVasanko
a9ef20969e
Refer permissions by UUID rather than scope.
2026-01-24 00:06:08 +00:00
LeoVasanko
2ec6314264
Simplify session and reset token formats; removes the token utility functions entirely.
2026-01-23 20:53:03 +00:00
LeoVasanko
ae4c982a30
Fix actor fields and transactions for API operations as they are recorded to DB.
2026-01-23 20:19:33 +00:00
LeoVasanko
d4ebc1bf99
Record user UUID as actor for API access.
2026-01-23 19:55:54 +00:00
LeoVasanko
f9d23a196c
Database refactor to separate modules.
2026-01-23 18:27:12 +00:00
LeoVasanko
c13044c085
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
LeoVasanko
2c783498a4
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
236d52aa55
Replace session.renewed with .expiry for consistency with other expiring items. Fix migration script.
2026-01-23 01:39:59 +00:00
LeoVasanko
02e04da2c4
Database cleanup: make it synchronous because we work with in-memory data. Defer writes to disk and cleanup to background task. Tests passing.
2026-01-23 01:22:47 +00:00
LeoVasanko
7f3763b46d
Replace SQL database with JSONL based solution that keeps history.
2026-01-23 00:54:37 +00:00
LeoVasanko
000501b718
Add missing max-age argument to validate endpoint.
2025-12-19 18:34:01 +00:00
LeoVasanko
a8ffd629ff
Fix devserver script misprocessing in some situations where auth-host was being used. Deduplicate origins on server end.
2025-12-10 17:39:09 +00:00
LeoVasanko
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
LeoVasanko
bfc5b11cc2
Fix missing credential_uuid in admin user detail API that was causing linkage between sessions and their passkeys not show up.
2025-12-09 15:34:05 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
83419d1845
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
2025-12-06 04:45:26 +00:00
LeoVasanko
a1b73711e6
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
2025-12-06 03:39:05 +00:00
LeoVasanko
8937905c9c
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
2025-12-06 00:51:18 +00:00
LeoVasanko
127e06179b
More robust server startup, startup logo and info screen, renewed devmode script.
2025-12-05 19:06:42 +00:00
LeoVasanko
208115ebc3
Project renamed to Paskia.
2025-12-05 13:17:52 +00:00