LeoVasanko
10af29f92d
MultiSite: one instance serves authentication across many domains ( #4 )
...
- Serve multiple domains (RP IDs) from one instance: host-based dispatch,
per-domain credentials and sessions, domains managed at runtime in the
admin UI — previously one RP per instance
- Cross-domain sign-in via Related Origin Requests: per-domain related-origins
list with a served .well-known/webauthn document
- Explicit per-domain origin lists with shell-glob wildcards (**. for apex +
any subdomain depth, *. for one level), editable in the admin UI with
validation and self-lockout guards
- Per-domain auth hosts: the account/admin UI can live on a different host
per domain, no longer confined to subdomains of a single RP
- CLI: 'paskia init <rp-id [rp-name]' initializes or adds a domain to an
existing database; 'paskia migrate' converts legacy databases
BREAKING CHANGES (v2.0):
- Database schema: config is now per-domain and credentials/sessions carry
an rp_id — existing databases must be converted with 'paskia migrate'
- Origins are now explicit: main implicitly allowed every subdomain of the
RP; configure '**.' origins to reproduce that behavior
- CLI: the flat '--rp-id/--rp-name/--origin/--auth/--save' flags are
replaced by the 'init' and 'migrate' subcommandsReviewed-on: #4
2026-09-07 22:02:06 +00:00
LeoVasanko
df8a7c0026
Cleanup of admin user panel where incorrect toast messages were issued after changes.
2026-08-09 21:45:23 +00:00
LeoVasanko
cc938dd306
Fix a call to loadOrgs when renaming a role, missed in earlier refactoring where we use loadAdminData() for refreshing.
2026-05-22 00:31:06 +00:00
LeoVasanko
95c163e37a
Add profile picture support
...
- backend avatar storage and OIDC picture claims
- profile and admin UI components
- admin org cards, tests, and docs
2026-05-21 23:57:48 +00:00
LeoVasanko
232d0e1ae0
Added configurable timeout settings to paskia-js, used in our frontend as well. The default fetch timeout has been changed to 10s from prior 1s, but we maintain 1s for auth endpoints in internal use.
2026-04-29 20:23:38 +00:00
LeoVasanko
f5545b48f0
Remove dead code.
2026-02-19 21:10:16 +00:00
LeoVasanko
c1b2bcf76c
Correct alphabetical sort of names in Org Admin panel. Supports Last, First and First Last + variatioons.
2026-02-19 20:54:52 +00:00
LeoVasanko
1806bcab5c
A bit more color for light theme; cleaner user badges in admin app.
2026-02-19 20:40:21 +00:00
LeoVasanko
3f51d06f13
Admin Server Options panel added for configuring rp-name, auth-host and origins.
2026-02-19 18:53:53 +00:00
LeoVasanko
6257071efe
Cleaned Org Admin styling.
2026-02-19 00:37:44 +00:00
LeoVasanko
f26ac8f33b
Simplified My Profile authentication flows, fixed some UX issues with reauth cancelled/accepted leading to incorrect states.
2026-02-18 19:04:02 +00:00
LeoVasanko
880ced3b8c
Always load user's theme from API if available, and update the localStorage cache. Previously in various situations the old cached value was being used instead, leading to inconsistent theming or wrong themeselector readout.
2026-02-18 18:35:41 +00:00
LeoVasanko
af80b5eefc
Make ResetApp Registration layout match the other dialog apps (centered).
2026-02-18 18:01:17 +00:00
LeoVasanko
fa1e69d58b
Imports to top of file.
2026-02-18 17:47:57 +00:00
LeoVasanko
49119fac81
Fix HostProfile user properties access.
2026-02-18 03:47:08 +00:00
LeoVasanko
68dccc1378
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko
557ffaa0cd
Add theme toggles that were missing from forward and reset apps.
2026-02-17 18:36:12 +00:00
LeoVasanko
f830d7d0ec
More minimalistic light theme. UI hint for org admin user/role management.
2026-02-14 18:36:20 +00:00
LeoVasanko
c1f8020f6b
API cleanup, using msgspec structs rather than raw responses. Admin app cleanup, better breadcrumbs.
2026-02-13 20:09:41 +00:00
LeoVasanko
fc0541762e
Add version indication and link to our site on profile page (bottom right corner).
2026-02-11 01:36:58 +00:00
LeoVasanko
cebaa2a757
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
2026-02-11 01:24:15 +00:00
LeoVasanko
4ebe5ae968
Style overhaul.
2026-02-11 01:18:19 +00:00
LeoVasanko
6a217978d6
Upgrade fastapi-vue-setup.
2026-02-09 16:29:24 +00:00
LeoVasanko
70c682b539
Improved client IP and UA handling.
2026-02-05 17:33:08 +00:00
LeoVasanko
8444d0399e
Improved theme picker
2026-02-05 16:19:06 +00:00
LeoVasanko
3c5f8694b3
Load stylesheets directly from HTML to avoid flashing wrong background color first.
2026-02-05 15:39:51 +00:00
LeoVasanko
871eb149ab
Styling updates, more robust dynamic/userpref light/dark switching. Sync with paskia-js.
2026-02-05 15:27:15 +00:00
LeoVasanko
291a665e21
Improved UI feedback on registration link creation.
2026-02-05 14:26:11 +00:00
LeoVasanko
0537b85085
Better UI for role deletions.
2026-02-05 14:05:36 +00:00
LeoVasanko
af5a48f565
API/DB cleanup for flat URLs that don't include org where users etc. are referred to. Implement user deletion in admin app and API, UI improvement. Reset token DB factory function revised to create passphrase and key internally. Removed unneeded functions and args, using update_user_role instead of a separate deleted _in_organization function.
2026-02-05 13:57:07 +00:00
LeoVasanko
a7e6eb7341
Missing theme file. Added favicon.
2026-01-31 00:25:38 +00:00
LeoVasanko
1800dc12ae
Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins).
2026-01-30 23:31:06 +00:00
LeoVasanko
cc55474e62
Light/dark override for in-app login dialogs to match app style e.g. light only
2026-01-30 22:59:52 +00:00
LeoVasanko
7e49ef296a
Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced).
2026-01-29 19:46:26 +00:00
LeoVasanko
433844cf08
Refactor to separate paskia lib functionality generally useful for various apps.
2026-01-29 16:55:46 +00:00
LeoVasanko
c9ea1c8948
Consistent and stronger session revalidation checks in Auth profile and Admin App. Fix missing handling of link generation network errors.
2026-01-29 16:02:29 +00:00
LeoVasanko
1062b5d6c8
Fix background task still running twice, and add a check to prevent that happening again (double expiry).
2026-01-27 23:51:13 +00:00
LeoVasanko
cf1124c251
DB transactions cleanup, better actor/user data. Simplified admin API. Use UUID to refer to a specific permission in admin API. Other cleanup.
2026-01-27 21:48:21 +00:00
LeoVasanko
3a8e7d1f4f
Remove credentials: 'include', a mechanism that we don't actually use.
2026-01-27 15:23:19 +00:00
LeoVasanko
cb84a81a06
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
LeoVasanko
7e568dbd10
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
LeoVasanko
5ee7443801
Use fastapi-vue-setup, merging its template scripts to old Paskia entry point and devserver. Simplified CLI, no longer uses serve subcommand. Fixed the URL displayed on banner to show to actual frontend/caddy server even in devmode.
2026-01-25 03:15:50 +00:00
LeoVasanko
a9ef20969e
Refer permissions by UUID rather than scope.
2026-01-24 00:06:08 +00:00
LeoVasanko
c13044c085
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
LeoVasanko
2c783498a4
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
9230344eb5
Remove layout max width.
2025-12-10 20:53:59 +00:00
LeoVasanko
8992cff473
Fix dialog patterns in admin app: dialog must close before doing API calls to avoid conflict with authentication dialogs.
2025-12-10 20:42:12 +00:00
LeoVasanko
1e91b84d3d
Cleanup on Admin app, better delete confirmations.
2025-12-10 20:16:57 +00:00
LeoVasanko
851b17f45c
Adopt <dialog> for our modals to tap into browser built-in functionality.
2025-12-10 19:41:55 +00:00