LeoVasanko
|
a1b73711e6
|
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
|
2025-12-06 03:39:05 +00:00 |
|
LeoVasanko
|
df5c176bcd
|
Fixed and updated E2E test suite. Added user credential registration tests. Coverage for backend and frontend.
|
2025-12-06 00:52:35 +00:00 |
|
LeoVasanko
|
8937905c9c
|
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
|
2025-12-06 00:51:18 +00:00 |
|
LeoVasanko
|
127e06179b
|
More robust server startup, startup logo and info screen, renewed devmode script.
|
2025-12-05 19:06:42 +00:00 |
|
LeoVasanko
|
c1204ca020
|
Updated documentation.
|
2025-12-05 16:15:50 +00:00 |
|
LeoVasanko
|
208115ebc3
|
Project renamed to Paskia.
|
2025-12-05 13:17:52 +00:00 |
|
LeoVasanko
|
8609f2fe69
|
Refactor dev mode into a source repo script (remove dev subcommand from package).
|
2025-12-05 18:36:13 +00:00 |
|
LeoVasanko
|
0355c55fc0
|
Updated E2E tests.
|
2025-12-04 04:44:58 +00:00 |
|
LeoVasanko
|
ea1ddbbe6f
|
Make dev mode run without static files, only serving assets in production.
v0.5.0
|
2025-12-04 10:15:26 +00:00 |
|
LeoVasanko
|
b091744665
|
Cleanup old hostapp files (finished, working).
|
2025-12-04 10:06:54 +00:00 |
|
LeoVasanko
|
2cf8799c75
|
Missing new component.
|
2025-12-04 10:03:33 +00:00 |
|
LeoVasanko
|
a72349077c
|
Integrate host app to main app (WIP).
|
2025-12-04 10:00:47 +00:00 |
|
LeoVasanko
|
e102b8383b
|
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
|
2025-12-04 09:19:40 +00:00 |
|
LeoVasanko
|
5aa8d021e6
|
Brought examples directly to front page.
|
2025-12-04 08:19:32 +00:00 |
|
LeoVasanko
|
3d5b0aa4bf
|
Fix view switching of restricted app.
|
2025-12-04 07:46:36 +00:00 |
|
LeoVasanko
|
29df169a67
|
Make restricted app use simple fetch that doesn't do API authentication (recursively).
|
2025-12-04 06:20:14 +00:00 |
|
LeoVasanko
|
97dc459bfb
|
Fixed and simplified examples.
|
2025-12-04 06:08:52 +00:00 |
|
LeoVasanko
|
4d4b290cc8
|
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
|
2025-12-04 06:01:47 +00:00 |
|
LeoVasanko
|
0e1b9f529b
|
Log authentication options on the client.
|
2025-12-04 05:07:44 +00:00 |
|
LeoVasanko
|
0c3e0d3fa5
|
Improved dialog layout with separate mobile portrait mode.
|
2025-12-04 04:06:32 +00:00 |
|
LeoVasanko
|
1782547b9e
|
Fix infinitely nested login iframes when the restricted app notices it needs login.
|
2025-12-04 03:56:17 +00:00 |
|
LeoVasanko
|
9976e05696
|
Various fixes and cleanup, regressions from prior commits.
|
2025-12-04 03:40:59 +00:00 |
|
LeoVasanko
|
6124fa6c01
|
Fix syntax error in reset app created by earlier commit.
|
2025-12-04 02:31:13 +00:00 |
|
LeoVasanko
|
a6591a1fbb
|
Better static files handling on backend, when in dev mode: fetch from vite.
|
2025-12-04 02:30:02 +00:00 |
|
LeoVasanko
|
b9b1c995f9
|
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
|
2025-12-04 01:58:18 +00:00 |
|
LeoVasanko
|
4482a601f3
|
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
|
2025-12-04 01:35:44 +00:00 |
|
LeoVasanko
|
aa4b1bfd42
|
Viewing linked passkeys/sessions (by clicking either one of them).
|
2025-12-04 01:21:52 +00:00 |
|
LeoVasanko
|
2ecf8433a1
|
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
|
2025-12-04 01:00:24 +00:00 |
|
LeoVasanko
|
db892365dc
|
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
|
2025-12-04 00:29:42 +00:00 |
|
LeoVasanko
|
8d02c0f615
|
Formatting, tidy up, transparent auth dialog background.
|
2025-12-03 23:31:35 +00:00 |
|
LeoVasanko
|
469d606ce5
|
Improved apiFetch and jsonFetch functions.
|
2025-12-03 23:26:38 +00:00 |
|
LeoVasanko
|
547a6cd923
|
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
|
2025-12-03 23:17:02 +00:00 |
|
LeoVasanko
|
deabee3b5c
|
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
|
2025-12-03 22:58:48 +00:00 |
|
LeoVasanko
|
fd1aa11409
|
Add E2E tests to register and verify passkey.
|
2025-12-03 02:52:39 +00:00 |
|
LeoVasanko
|
ca1ea9d90b
|
Always use timezone aware UTC time.
|
2025-12-03 01:36:15 +00:00 |
|
LeoVasanko
|
2dac0be77a
|
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
|
2025-12-03 01:32:05 +00:00 |
|
LeoVasanko
|
f63c62d9ff
|
Implement session termination in admin API, for completeness.
|
2025-12-03 01:20:52 +00:00 |
|
LeoVasanko
|
768a4391cf
|
Improved profile view layout.
|
2025-12-03 01:03:25 +00:00 |
|
LeoVasanko
|
f64876e73b
|
Improved profile view layout.
|
2025-12-03 00:52:52 +00:00 |
|
LeoVasanko
|
b6a3cdd3a4
|
Fix examples folder serving broken a couple of commits ago.
|
2025-12-03 00:06:32 +00:00 |
|
LeoVasanko
|
fd9a5afc1c
|
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
|
2025-12-02 23:39:31 +00:00 |
|
LeoVasanko
|
8714fe9319
|
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
|
2025-12-02 22:41:12 +00:00 |
|
LeoVasanko
|
adbab88c86
|
Major refactor of frontend source tree such that paths better match where they are served.
|
2025-12-02 22:09:07 +00:00 |
|
LeoVasanko
|
5d9d2b794d
|
Refactor restricted app paths and naming.
|
2025-12-02 19:10:13 +00:00 |
|
LeoVasanko
|
eedbd4aaa4
|
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
|
2025-12-02 18:34:59 +00:00 |
|
LeoVasanko
|
15916047fa
|
Remove backend access control, now that the profile and admin apps handle that via API.
|
2025-12-02 18:25:58 +00:00 |
|
LeoVasanko
|
643d9bafab
|
Fix the back buttons (navigate back if you can but close if it was a new window).
|
2025-12-02 18:02:02 +00:00 |
|
LeoVasanko
|
2699aaa472
|
Implement Forbidden view for API calls, cleanup and better UX.
|
2025-12-02 17:36:37 +00:00 |
|
LeoVasanko
|
5422845192
|
Better error messages from backend, avoid bad toasts, cleanup of session validation.
|
2025-12-02 16:37:27 +00:00 |
|
LeoVasanko
|
c1ccb048f0
|
Update admin app authentication in API mode too, reusing components between it and the main app.
|
2025-12-02 15:42:55 +00:00 |
|