LeoVasanko
2da1ce777a
Multi-site plan v4: combined paskia.kantadb, bootstrap-only CLI, runtime realm management
2026-09-06 03:19:42 +00:00
LeoVasanko
383c9f472e
Add public access mode (public=1) to forward auth
...
/auth/api/forward?public=1 passes requests through with a Remote-Public
header (anonymous/forbidden/authenticated) instead of 401/403, so routes
can allow anonymous visitors while still identifying logged-in users.
Reauth (max_age) still requires the auth flow. Documented in Headers.md,
api/forward.md, Integration.md and all proxy guides.
2026-09-05 16:06:32 +00:00
LeoVasanko
8c2809a879
Update fastapi-vue-setup, make use of its access logging facility.
2026-09-05 14:36:25 +00:00
LeoVasanko
3912b5473e
Fix Caddyfile indentation
2026-08-15 05:54:28 +00:00
LeoVasanko
223429d51c
Add renew=0 query arg on validate, useful when only a permission check is required.
v1.5.6
2026-08-11 01:46:56 +00:00
LeoVasanko
2456730f70
Check max-age only after checking permissions: if neither is passing, we want a 403 error; simply authenticating again won't fix it so don't bother reauth flow. After forbidden flow e.g. account change we are already good with max-age too.
v1.5.5
2026-08-11 00:56:01 +00:00
LeoVasanko
f74bf3ebe6
Require Python 3.14, ruff formatting for simpler typing.
2026-08-11 00:46:45 +00:00
LeoVasanko
79074dd4f1
OR semantics in perm query arg, strict parsing, segment-aware wildcards
...
perm=a|b+c now means (a or b) and c; repeated perm args remain ANDed.
Out-of-spec values (empty alternatives, chars outside the scope charset,
stray %2B) are rejected with 400 instead of being silently misparsed;
extra spaces between groups are tolerated. Forward endpoint 400/500
details name /auth/api/forward as origin without echoing query args.
Wildcards are now filename-like: * stays within a :- or /-separated
segment, ** spans segments, partial segments allowed. Slash added to
allowed scope characters for path-based permissions.
2026-08-11 00:44:58 +00:00
LeoVasanko
00ef0ae2e7
Update API and proxy docs
2026-08-10 21:35:46 +00:00
LeoVasanko
6f5287e070
Avoid clearing session.user_agent if a validation request lack this header. Backend-initiated session validations may not have the data.
2026-08-10 14:09:42 +00:00
LeoVasanko
051e1bbb41
Replace paskia.db.logging with kanta's built-in logging (kanta 0.7.0)
...
The vendored db/logging module duplicated what kanta now provides:
diff formatting, UUID-to-label resolution via logfmt callbacks, unsafe
character filtering and value truncation. Censoring of oidc.key material
moves into the format_log_uuid logfmt callback in db.lifecycle, taking
care to hide only the value, not the 'key' path component itself.
v1.5.4
2026-08-09 23:25:16 +00:00
LeoVasanko
4b156b712c
Proper handling of auth site runtime change done via web interface, making the change immediately effective. Kept in origins list that is still also visible on the same dialog, where it can be removed if needed.
2026-08-09 23:00:22 +00:00
LeoVasanko
df8a7c0026
Cleanup of admin user panel where incorrect toast messages were issued after changes.
2026-08-09 21:45:23 +00:00
LeoVasanko
9b28250391
Upgrade to kanta 0.4.0:
...
- Make use of its new features and cleanup our interfacing and init/shutdown processes and migrations
- Clean up circular deps, simplify app init
- Add specific pytest for CLI main to cover the changes
v1.5.3
2026-06-13 21:59:18 +00:00
LeoVasanko
b9aec6bb58
Remove built-in database, replace with kanta package. No disk format changes.
v1.5.2
2026-06-12 19:39:30 +00:00
LeoVasanko
c79cb497ee
Fix profile image path on OIDC.
v1.5.1
2026-05-22 02:45:12 +00:00
LeoVasanko
9f50c8c20d
Missing file
v1.5.0
2026-05-22 01:40:53 +00:00
LeoVasanko
816c7a681e
Update E2E tests for new database folder.
2026-05-22 01:40:09 +00:00
LeoVasanko
d31c09084e
Make rpid.paskiadb a folder containing the database and the files in one. Migrates existing old format rpid.paskiadb file to main.db.
2026-05-22 01:22:35 +00:00
LeoVasanko
cc938dd306
Fix a call to loadOrgs when renaming a role, missed in earlier refactoring where we use loadAdminData() for refreshing.
2026-05-22 00:31:06 +00:00
LeoVasanko
36db1e7e56
Fix showing of admin reset link also in devserver where the logging configuration was eating the message.
2026-05-22 00:22:04 +00:00
LeoVasanko
95c163e37a
Add profile picture support
...
- backend avatar storage and OIDC picture claims
- profile and admin UI components
- admin org cards, tests, and docs
2026-05-21 23:57:48 +00:00
LeoVasanko
2d0d17c307
fix remote auth: create session for requesting device host
v1.4.1
2026-04-30 21:47:47 +00:00
LeoVasanko
10980ad39b
fix type hints: update_session and set_session_host key type
2026-04-30 21:47:46 +00:00
LeoVasanko
42b54cf645
Release 1.4.0
v1.4.0
2026-04-29 20:48:12 +00:00
LeoVasanko
232d0e1ae0
Added configurable timeout settings to paskia-js, used in our frontend as well. The default fetch timeout has been changed to 10s from prior 1s, but we maintain 1s for auth endpoints in internal use.
2026-04-29 20:23:38 +00:00
LeoVasanko
e97a2b3291
Improved color compatibility across terminals that may have very different ideas of yellow shades.
2026-04-29 16:23:34 +00:00
LeoVasanko
cde709e252
Print original METHOD /path on auth/api/forward access log entries. Previously the method was not printed, and nothing was printed for 401 without a session.
v1.3.7
2026-04-29 15:47:37 +00:00
LeoVasanko
72d76df35d
Log session id from handlers on selected auth routes. Adds request.state.log_extra for handlers to print access log extra.
v1.3.6
2026-04-29 03:02:30 +00:00
LeoVasanko
1a742fc0e7
Cleaner websocket access log.
2026-04-29 02:45:20 +00:00
LeoVasanko
0b29654d6f
Log original path on forward endpoint. Added logging extra argument for such additions on access logs.
2026-04-29 02:16:48 +00:00
LeoVasanko
76f24a755b
Add GET /auth/api/check endpoint for unauthenticated user permission checks
...
Checks permissions for a user given by ?user=<UUID> query arg without
requiring a session cookie. No cookie is read or written, no DB writes.
- perm= query arg supported (same wildcard semantics as validate/forward)
- Returns valid bool + minimal ctx (user/org/role/permissions)
- Permissions are host-scoped via domain filtering, same as session_ctx
- 404 if UUID not found; valid=false if perm check fails (no 403)
- Add ApiCheckUserResponse struct to apistructs
- Add has_all_scopes() helper to permutil for scope-set-based checks
v1.3.5
2026-04-26 05:45:59 +00:00
LeoVasanko
5c452f325a
Better error messages on database loading errors.
v1.3.4
2026-02-19 21:52:33 +00:00
LeoVasanko
e9b6bc7a3d
Implement migration for old format listen field in database (re: commit f746085)
v1.3.3
2026-02-19 21:26:12 +00:00
LeoVasanko
f5545b48f0
Remove dead code.
2026-02-19 21:10:16 +00:00
LeoVasanko
c1b2bcf76c
Correct alphabetical sort of names in Org Admin panel. Supports Last, First and First Last + variatioons.
v1.3.2
2026-02-19 20:54:52 +00:00
LeoVasanko
1806bcab5c
A bit more color for light theme; cleaner user badges in admin app.
2026-02-19 20:40:21 +00:00
LeoVasanko
be177cbafc
Add default value for a(ction) field in change records to keep support for very old versions.
2026-02-19 20:16:16 +00:00
LeoVasanko
f5ccc204be
Fix adminapp reference after refactoring.
v1.3.1
2026-02-19 20:03:58 +00:00
LeoVasanko
dd2031eef5
Fix runtime config update by Server Options panel.
v1.3.0
2026-02-19 19:57:12 +00:00
LeoVasanko
3cb24bfee9
Refactor to separate admin app modules to subapps, required trailing slashes and plural changes on some of the URLs.
2026-02-19 19:49:13 +00:00
LeoVasanko
3f51d06f13
Admin Server Options panel added for configuring rp-name, auth-host and origins.
2026-02-19 18:53:53 +00:00
LeoVasanko
528a728eb8
README
2026-02-19 18:44:06 +00:00
LeoVasanko
727625ef4f
Avoid storing IP and User Agent on OpenID Connect token renewals; preserves the user's information from authentication.
v1.2.4
2026-02-19 16:34:44 +00:00
LeoVasanko
5f7a5ed9b1
Added database snapshots, cleanup, better error messages.
v1.2.3
2026-02-19 16:29:23 +00:00
LeoVasanko
d64e63527b
CLI main and RuntimeConfig cleanup. Added a session_ctx wrapper function for easier access and avoiding hostutil import in db.
2026-02-19 14:24:16 +00:00
LeoVasanko
733439b446
Logging cleanup, better color compatibility for Mac Terminal and consistent across DB and FastAPI access logs.
2026-02-19 14:19:54 +00:00
LeoVasanko
4e6f63e9ef
Fix auth-host being added to origins even when no origins were wanted.
v1.2.2
2026-02-19 01:00:13 +00:00
LeoVasanko
d431c75297
Fix request header removal that was causing zstd compressed response when we wanted plain text.
v1.2.1
2026-02-19 00:51:11 +00:00
LeoVasanko
6257071efe
Cleaned Org Admin styling.
v1.2.0
2026-02-19 00:37:44 +00:00