- Domain dialog submits one origins map (in-domain + related together);
classification is derived, the submit-time split is gone
- Placeholder-row machinery deleted: an empty list now means 'nothing
allowed'; new domains get a real pre-filled '*.{rp-id}' row that
follows rp-id edits until touched
- Plain '*' is invalid; wildcards only within the domain
- Editing the domain in use: when no auth host is marked and the admin's
current page origin would no longer be allowed to run ceremonies, Save
is disabled with an explanatory error (mirrors the backend guard)
- Origin list display: single table with derived related badges; '*'
sort special case removed
- Empty-origins default shows as a '*' placeholder row that is not
persisted unless edited (open+save no longer tightens any-scheme to
https-only)
- Foreign wildcards are flagged invalid instead of being classified as
related origins; over-cap related list disables Save
- Single-label rp-ids accepted (matching backend validate_rp_id)
- Auth-host mark follows row edits; row menu state resets on dialog close
- rp-id/origin keys lowercased for classification and submit
- settings cache: stale in-flight responses no longer overwrite a forced
refresh
- Remove the dead oidc-edit dialog path and other unused code; fix stale
comments (realm→domain, '*' semantics, per-domain discovery URLs)
- DB.oidc is a single OIDC (one key, one client set); hosts are issuer
aliases. OIDCCode drops its rp_id field; client CRUD is not keyed by
domain.
- No cross-domain auth-host fallback: a domain without its own auth host
uses its own hosts; several domains may share one auth host (nested
rp-ids) with deterministic best-suffix resolution.
- '*' origin shorthand expands to '*.{rp-id}'; legacy wildcards convert
as-is; related origins may point at/inside another domain's rp-id.
- Admin UI and docs updated to match.
- 'paskia init [rp-id] [rp-name]' and 'paskia migrate [rp-id]' are now
positional; comma separation and the --rp-id/--rp-name flags are gone.
- With an existing paskia.kantadb, init adds the rp-id as a new domain
(seeding its OIDC provider) or updates an existing domain's rp-name.
- Origin allow-list semantics clarified: the bare '*' entry allows
anything within the rp-id domain on any scheme and port (also the
empty-list default and its display in the admin UI, replacing the
synthetic '*.rp-id' row); '*.x' wildcards are https-only; exact entries
match scheme, host and port. Legacy '*.rp-id' wildcards migrate to '*'
to preserve their any-scheme meaning.
Finish the realm→domain terminology removal across source, tests, e2e
and docs. The stored config drops all lists: Config.domains is keyed by
rp-id, DomainConfig.origins/related are objects keyed by host (https://
omitted), values True or OriginEntry(auth_host=True). The default/primary
domain concept is gone; ordering is display-time. Tests and e2e updated
to the new API shapes (not run). Database re-migrated from the legacy
backup into the new format.
RealmConfig.origins is again purely an allow-list of sign-in sites
within the realm's domain (unset = rp-id and all subdomains), restoring
the restriction semantics the realm rework had silently turned into an
always-open subtree. Cross-domain ROR origins move to their own
RealmConfig.related_origins field — always additive, capped, validated
to be outside the rp-id domain, and the sole source of the
/.well-known/webauthn document.
Admin API POST/PATCH accept related_origins; misfiled entries are
rejected (cross-domain in origins, in-domain in related_origins).
Admin UI: the realm dialog edits the two lists separately with
end-user-oriented explanations (allowed sign-in sites vs. related
domains + the well-known note); the Realms section intro explains the
multi-domain model, and the table shows sign-in site and related domain
counts.
- devserver bootstraps via one-shot 'paskia init' when no database
exists (multi --rp-id, --rp-name/--auth-host/--origin apply to the
default realm), then runs plain 'paskia' serve which reads all realm
configuration from the database; legacy *.paskiadb is adopted by
serve without init.
- Caddy origins iterate all bootstrap rp-ids.
- vite.config.js accepts a comma-separated PASKIA_AUTH_HOST list and
proxies /.well-known/webauthn to the backend so ROR works in dev.
- caddy/auth/setup forwards /.well-known/openid-configuration and
/.well-known/webauthn to paskia (they must not be swallowed by a
static /.well-known/* file handler); Caddyfile.dev updated to match
the generated dev config.
- Admin: replace Server Options dialog with per-realm management —
realms table on the overview, add/edit/delete realm dialog backed by
/auth/api/admin/realms/. Origins may be any well-formed origin;
non-subdomain ones are related origins (ROR, max 5) and the dialog
points at the .well-known/webauthn URL that must list them.
Connectivity checks compare against the edited realm's rp-id and
degrade to warnings instead of blocking saves.
- Host mode (limited profile) now keys off own_auth_host so realms
sharing another realm's auth host serve the full profile locally.
- Credential list shows a realm badge on passkeys registered for a
different rp-id than the current realm.
- Profile shows an enrollment prompt when the user has no passkey for
the current realm (e.g. after a cross-realm remote login).
- Remote auth permit shows the requesting realm when it differs from
the approver's own.
- settings cache can be force-refreshed after realm changes.
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout