Commit Graph
35 Commits
Author SHA1 Message Date
LeoVasanko 68dccc1378 OAuth2 OpenID Connect provider support, API and DB refactoring (#3)
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko c1f8020f6b API cleanup, using msgspec structs rather than raw responses. Admin app cleanup, better breadcrumbs. 2026-02-13 20:09:41 +00:00
LeoVasanko 1800dc12ae Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins). 2026-01-30 23:31:06 +00:00
LeoVasanko 7e49ef296a Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced). 2026-01-29 19:46:26 +00:00
LeoVasanko 433844cf08 Refactor to separate paskia lib functionality generally useful for various apps. 2026-01-29 16:55:46 +00:00
LeoVasanko 2c783498a4 Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements. 2026-01-23 15:11:01 +00:00
LeoVasanko 9976e05696 Various fixes and cleanup, regressions from prior commits. 2025-12-04 03:40:59 +00:00
LeoVasanko 2ecf8433a1 Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication). 2025-12-04 01:00:24 +00:00
LeoVasanko 547a6cd923 Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata. 2025-12-03 23:17:02 +00:00
LeoVasanko 5422845192 Better error messages from backend, avoid bad toasts, cleanup of session validation. 2025-12-02 16:37:27 +00:00
LeoVasanko 3030122807 Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages. 2025-12-02 15:25:31 +00:00
LeoVasanko eaa16abe2a Better UX for profile view logout buttons. 2025-10-05 04:22:16 +00:00
LeoVasanko 01bc39a0e8 A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko fa513940c7 Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 20:59:51 +00:00
LeoVasanko 0af7aad28c Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-04 06:31:54 +00:00
LeoVasanko 2f1578c4bc Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko e130bc5c0a Clear sessionStorage on logout. 2025-09-29 07:45:37 +00:00
LeoVasanko f28e69a9ce Cleaner logout. 2025-09-03 07:11:25 +00:00
LeoVasanko 09b9894407 Cleaned up login/logout flows. 2025-09-03 07:08:16 +00:00
LeoVasanko 6e5ea9eac0 Refactor API under /auth/api 2025-09-03 02:32:19 +00:00
LeoVasanko a526344842 Use rp-name for frontend branding 2025-09-02 06:48:59 +00:00
LeoVasanko 24404738ab Formatting 2025-08-31 06:43:27 +00:00
LeoVasanko ad4bde5d0d Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site). 2025-08-31 03:54:17 +00:00
LeoVasanko 7e45bba612 Almost complete org/permission handling. Much cleanup, bootstrap works. 2025-08-08 01:58:12 +00:00
LeoVasanko 039613a8b3 Cleaner error message on aborted Passkey operations. 2025-08-07 00:00:23 +00:00
LeoVasanko 04953c7903 Frontend component selection logic simplified. 2025-08-06 23:33:34 +00:00
LeoVasanko b255362946 Refactor to not use status: success, but HTTP codes, and renamed the error key to detail to match FastAPI's own. 2025-08-06 22:09:55 +00:00
LeoVasanko c8bb2ab12e Checkpoint, fixing reset token handling broken in earlier edits. 2025-08-06 21:55:14 +00:00
LeoVasanko 71db80c7ea Everything works. Minor adjustments on frontend and backend for the new API. 2025-08-02 19:41:42 +00:00
LeoVasanko f1ef7e43cc Frontend adjusted for the new API. 2025-08-02 01:16:10 +00:00
LeoVasanko 9b82f77729 Major cleanup and refactoring of the backend (frontend not fully updated). 2025-08-02 00:32:27 +00:00
LeoVasanko 6a2c6f7ed0 Refactoring reset and session tokens, currently broken. 2025-07-15 04:10:02 +00:00
LeoVasanko 158115f172 Refactor to get user info from a single endpoint 2025-07-15 00:30:10 +00:00
LeoVasanko 1850f9b27f Move the whole app under /auth/, fix static build. 2025-07-14 02:03:15 +00:00
LeoVasanko 611f1ddd40 Rewritten frontend with Vue 2025-07-14 00:41:08 +00:00