LeoVasanko
c13044c085
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
LeoVasanko
2c783498a4
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
9230344eb5
Remove layout max width.
2025-12-10 20:53:59 +00:00
LeoVasanko
851b17f45c
Adopt <dialog> for our modals to tap into browser built-in functionality.
2025-12-10 19:41:55 +00:00
LeoVasanko
cdb9691b59
Revised light color scheme for a more professional look.
2025-12-10 19:40:59 +00:00
LeoVasanko
720d875eb5
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
LeoVasanko
ac560172ff
Fix regression from adding color-scheme: light dark improperly at :root (html) rather than at body.
2025-12-10 18:47:56 +00:00
LeoVasanko
9930608359
Improved breadcrumbs on auth host.
2025-12-10 18:20:37 +00:00
LeoVasanko
2d797454de
Fix button row layout problem from the responsive layout cleanup before, that was causing them display stretched to full window width. Now they only shrink.
2025-12-10 17:43:10 +00:00
LeoVasanko
3f0de04a49
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
LeoVasanko
460094e4dd
Change input placeholder that was improperly triggering Bitwarden to complete username in it. BW does not respect autocomplete at all.
2025-12-10 16:56:19 +00:00
LeoVasanko
cff62a1904
Fix mobile browser code word autocomplete (on space that wasn't detected correctly).
2025-12-10 16:40:58 +00:00
LeoVasanko
ea63b7236c
Automatic light/dark mode. Fixes a cursor color issue on Huawei Browser, and is generally a good idea.
2025-12-10 16:40:54 +00:00
LeoVasanko
8bb00f01c4
Simplify responsive layouts. Remove button vertical stacking and always fit them on the same row.
2025-12-10 16:11:43 +00:00
LeoVasanko
ca73febe2f
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
2025-12-10 15:43:40 +00:00
LeoVasanko
7f47f44039
Fix scrolling behaviour when backdrop dialogs appear.
2025-12-10 12:07:43 +00:00
LeoVasanko
f6c315d0dc
Improved session group (per site) styling and UX.
2025-12-10 01:11:43 +00:00
LeoVasanko
504e1d0fc5
Consistent use of red X only for deletion, and using only it for deletion rather than trashbin, while using non-red X for window close button.
2025-12-10 00:06:34 +00:00
LeoVasanko
a8269df0b4
Cleaner up registration link creation. Don't show the dialog until when there is a valid link. Implement a global blur backdrop with nicer effect and proper scrollbar handling (avoiding layout shifting a bit). Use the global backdrop to ensure consistent visuals between authentication and the modal being shown, along with in/out transitions.
2025-12-09 23:58:04 +00:00
LeoVasanko
d58a88c43a
Code word input overhaul, more accurate cursor and selection processing. New styling for the widget that conforms with browser default style (focus outline).
2025-12-09 23:07:15 +00:00
LeoVasanko
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
LeoVasanko
9b491164fd
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
LeoVasanko
bb34e52997
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
LeoVasanko
b9897b62b8
Remove trash bin icons from tab order. Instead, implement Delete key support (Backspace accepted on Apple devices).
2025-12-09 16:54:46 +00:00
LeoVasanko
8a21edf367
Process IPv6 display into short format including only the network prefix, and sharing the same code also for comparisons where needed.
2025-12-09 16:33:16 +00:00
LeoVasanko
03368b1b84
Rename base64 functions such that imports don't need renaming.
2025-12-09 15:55:03 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
2cf8799c75
Missing new component.
2025-12-04 10:03:33 +00:00
LeoVasanko
e102b8383b
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
2025-12-04 09:19:40 +00:00
LeoVasanko
3d5b0aa4bf
Fix view switching of restricted app.
2025-12-04 07:46:36 +00:00
LeoVasanko
29df169a67
Make restricted app use simple fetch that doesn't do API authentication (recursively).
2025-12-04 06:20:14 +00:00
LeoVasanko
4d4b290cc8
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
2025-12-04 06:01:47 +00:00
LeoVasanko
0e1b9f529b
Log authentication options on the client.
2025-12-04 05:07:44 +00:00
LeoVasanko
0c3e0d3fa5
Improved dialog layout with separate mobile portrait mode.
2025-12-04 04:06:32 +00:00
LeoVasanko
1782547b9e
Fix infinitely nested login iframes when the restricted app notices it needs login.
2025-12-04 03:56:17 +00:00
LeoVasanko
9976e05696
Various fixes and cleanup, regressions from prior commits.
2025-12-04 03:40:59 +00:00
LeoVasanko
b9b1c995f9
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
2025-12-04 01:58:18 +00:00
LeoVasanko
4482a601f3
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
2025-12-04 01:35:44 +00:00
LeoVasanko
aa4b1bfd42
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-04 01:21:52 +00:00
LeoVasanko
2ecf8433a1
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-04 01:00:24 +00:00
LeoVasanko
db892365dc
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-04 00:29:42 +00:00
LeoVasanko
8d02c0f615
Formatting, tidy up, transparent auth dialog background.
2025-12-03 23:31:35 +00:00
LeoVasanko
469d606ce5
Improved apiFetch and jsonFetch functions.
2025-12-03 23:26:38 +00:00
LeoVasanko
547a6cd923
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 23:17:02 +00:00
LeoVasanko
2dac0be77a
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
2025-12-03 01:32:05 +00:00
LeoVasanko
f63c62d9ff
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
LeoVasanko
768a4391cf
Improved profile view layout.
2025-12-03 01:03:25 +00:00
LeoVasanko
f64876e73b
Improved profile view layout.
2025-12-03 00:52:52 +00:00
LeoVasanko
fd9a5afc1c
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00