LeoVasanko
2fadaea19c
Update E2E tests with changes since a while back.
2026-01-27 02:24:09 +00:00
LeoVasanko
cb84a81a06
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
LeoVasanko
9bdca1f43a
Finish the database key-in-object refactoring.
2026-01-27 02:11:09 +00:00
LeoVasanko
0f29544bdb
Database cleanup, better UUID passing and construction (User model).
2026-01-27 01:25:52 +00:00
LeoVasanko
4ddaa9fdf4
Cleanup and bugfixes on Bootstrap and JSONL handling.
2026-01-26 23:54:03 +00:00
LeoVasanko
7e568dbd10
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
LeoVasanko
fbc6108b7a
Fix frontend-build location. Cleanup.
2026-01-25 03:26:22 +00:00
LeoVasanko
6e649f1f07
Fix test expected HTTP code.
2026-01-25 03:20:28 +00:00
LeoVasanko
8d68e5d237
Add missing set_session_host on dunder all.
2026-01-25 03:17:32 +00:00
LeoVasanko
5ee7443801
Use fastapi-vue-setup, merging its template scripts to old Paskia entry point and devserver. Simplified CLI, no longer uses serve subcommand. Fixed the URL displayed on banner to show to actual frontend/caddy server even in devmode.
2026-01-25 03:15:50 +00:00
LeoVasanko
2100a7e14f
Logging cleanup, linter.
2026-01-24 01:08:00 +00:00
LeoVasanko
aae33e60ce
Fix errors where permission scopes were still expected for indexing.
2026-01-24 00:58:18 +00:00
LeoVasanko
cebef8adfc
Large refactoring for better JSONL context. Switched back the urlsafe for session tokens that need to be passed in URLs. Other minor fixes.
2026-01-24 00:40:32 +00:00
LeoVasanko
57a9c60557
Don't load existing JSONL on migrate.
2026-01-24 00:08:21 +00:00
LeoVasanko
a9ef20969e
Refer permissions by UUID rather than scope.
2026-01-24 00:06:08 +00:00
LeoVasanko
57748876cb
Debug JSONL updates.
2026-01-23 23:49:11 +00:00
LeoVasanko
ba552e24cd
Debug JSONL updates.
2026-01-23 23:41:47 +00:00
LeoVasanko
dbe4149b63
Debug JSONL updates.
2026-01-23 23:35:00 +00:00
LeoVasanko
3d5f82c3df
Debug JSONL updates.
2026-01-23 23:29:47 +00:00
LeoVasanko
2a005692ee
Fixes to JSONL management, starting from empty state rather than default DB.
2026-01-23 21:31:54 +00:00
LeoVasanko
2ec6314264
Simplify session and reset token formats; removes the token utility functions entirely.
2026-01-23 20:53:03 +00:00
LeoVasanko
ae4c982a30
Fix actor fields and transactions for API operations as they are recorded to DB.
2026-01-23 20:19:33 +00:00
LeoVasanko
c2933d60c2
Update migrate script with the latest database changes.
2026-01-23 19:56:44 +00:00
LeoVasanko
d4ebc1bf99
Record user UUID as actor for API access.
2026-01-23 19:55:54 +00:00
LeoVasanko
0f857ffb78
Cleanup, add database versioning.
2026-01-23 19:22:23 +00:00
LeoVasanko
b7ebe68665
Refactor to use UUID and bytes rather than str keys in msgspec structs because the module can automatically convert these.
2026-01-23 18:47:56 +00:00
LeoVasanko
f9d23a196c
Database refactor to separate modules.
2026-01-23 18:27:12 +00:00
LeoVasanko
2c6a5c72d9
Updated database to use async background worker, making changes lock-free synchronous ops.
2026-01-23 15:57:16 +00:00
LeoVasanko
c13044c085
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
LeoVasanko
2c783498a4
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
236d52aa55
Replace session.renewed with .expiry for consistency with other expiring items. Fix migration script.
2026-01-23 01:39:59 +00:00
LeoVasanko
02e04da2c4
Database cleanup: make it synchronous because we work with in-memory data. Defer writes to disk and cleanup to background task. Tests passing.
2026-01-23 01:22:47 +00:00
LeoVasanko
7f3763b46d
Replace SQL database with JSONL based solution that keeps history.
2026-01-23 00:54:37 +00:00
LeoVasanko
0fe55b2b62
Update docs/Caddy.md
2025-12-19 22:53:10 +00:00
LeoVasanko
ccf71bf0a3
Docs updates.
2025-12-19 21:09:56 +00:00
LeoVasanko
cdaeecb179
Docs updates.
2025-12-19 21:08:40 +00:00
LeoVasanko
82cdee51e4
Docs updates.
2025-12-19 21:07:20 +00:00
LeoVasanko
851e0793a6
Docs updates.
2025-12-19 21:06:27 +00:00
LeoVasanko
cd681a0599
Docs updates.
2025-12-19 21:01:05 +00:00
LeoVasanko
71cb01cfda
Docs updates.
2025-12-19 21:00:16 +00:00
LeoVasanko
535ac8558d
Docs updates.
2025-12-19 20:59:16 +00:00
LeoVasanko
c64554aeda
Docs updates.
2025-12-19 20:56:47 +00:00
LeoVasanko
0bc1bae26c
Docs updates.
2025-12-19 20:54:44 +00:00
LeoVasanko
156231b142
Docs updates.
2025-12-19 20:52:38 +00:00
LeoVasanko
daf397b3b5
Docs updates.
2025-12-19 20:38:49 +00:00
LeoVasanko
a1a5ad8520
Docs updates.
2025-12-19 20:37:25 +00:00
LeoVasanko
d25124d30b
Docs updates.
2025-12-19 20:23:49 +00:00
LeoVasanko
0bfb035f76
Docs updates.
2025-12-19 18:34:12 +00:00
LeoVasanko
000501b718
Add missing max-age argument to validate endpoint.
2025-12-19 18:34:01 +00:00
LeoVasanko
5a57e78814
Docs updates.
2025-12-19 18:17:28 +00:00
LeoVasanko
e5b84dd28c
Docs updates.
2025-12-19 17:34:09 +00:00
LeoVasanko
4b01fd9e7a
Docs updates.
2025-12-19 17:28:54 +00:00
LeoVasanko
431c48f1dd
Docs updates.
2025-12-19 16:06:51 +00:00
LeoVasanko
03c966919f
README formatting and links.
2025-12-19 14:59:22 +00:00
LeoVasanko
2795b1061f
Info fields for PyPI
2025-12-18 14:13:05 +00:00
LeoVasanko
9230344eb5
Remove layout max width.
2025-12-10 20:53:59 +00:00
LeoVasanko
8992cff473
Fix dialog patterns in admin app: dialog must close before doing API calls to avoid conflict with authentication dialogs.
2025-12-10 20:42:12 +00:00
LeoVasanko
1e91b84d3d
Cleanup on Admin app, better delete confirmations.
2025-12-10 20:16:57 +00:00
LeoVasanko
851b17f45c
Adopt <dialog> for our modals to tap into browser built-in functionality.
2025-12-10 19:41:55 +00:00
LeoVasanko
cdb9691b59
Revised light color scheme for a more professional look.
2025-12-10 19:40:59 +00:00
LeoVasanko
720d875eb5
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
LeoVasanko
ac560172ff
Fix regression from adding color-scheme: light dark improperly at :root (html) rather than at body.
2025-12-10 18:47:56 +00:00
LeoVasanko
091f20a666
Use absolute paths for resources so that the links work when Vite is serving these at root instead of /auth/
2025-12-10 18:30:45 +00:00
LeoVasanko
9930608359
Improved breadcrumbs on auth host.
2025-12-10 18:20:37 +00:00
LeoVasanko
4a753ca29b
Vite devserver configuration that behaves correctly for auth-host, serving the profile view at site root and /admin/ instead of under /auth/.
2025-12-10 18:18:14 +00:00
LeoVasanko
2d797454de
Fix button row layout problem from the responsive layout cleanup before, that was causing them display stretched to full window width. Now they only shrink.
2025-12-10 17:43:10 +00:00
LeoVasanko
a8ffd629ff
Fix devserver script misprocessing in some situations where auth-host was being used. Deduplicate origins on server end.
2025-12-10 17:39:09 +00:00
LeoVasanko
3f0de04a49
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
LeoVasanko
460094e4dd
Change input placeholder that was improperly triggering Bitwarden to complete username in it. BW does not respect autocomplete at all.
2025-12-10 16:56:19 +00:00
LeoVasanko
cff62a1904
Fix mobile browser code word autocomplete (on space that wasn't detected correctly).
2025-12-10 16:40:58 +00:00
LeoVasanko
ea63b7236c
Automatic light/dark mode. Fixes a cursor color issue on Huawei Browser, and is generally a good idea.
2025-12-10 16:40:54 +00:00
LeoVasanko
8bb00f01c4
Simplify responsive layouts. Remove button vertical stacking and always fit them on the same row.
2025-12-10 16:11:43 +00:00
LeoVasanko
ca73febe2f
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
2025-12-10 15:43:40 +00:00
LeoVasanko
7f47f44039
Fix scrolling behaviour when backdrop dialogs appear.
2025-12-10 12:07:43 +00:00
LeoVasanko
f6c315d0dc
Improved session group (per site) styling and UX.
2025-12-10 01:11:43 +00:00
LeoVasanko
504e1d0fc5
Consistent use of red X only for deletion, and using only it for deletion rather than trashbin, while using non-red X for window close button.
2025-12-10 00:06:34 +00:00
LeoVasanko
a8269df0b4
Cleaner up registration link creation. Don't show the dialog until when there is a valid link. Implement a global blur backdrop with nicer effect and proper scrollbar handling (avoiding layout shifting a bit). Use the global backdrop to ensure consistent visuals between authentication and the modal being shown, along with in/out transitions.
2025-12-09 23:58:04 +00:00
LeoVasanko
d58a88c43a
Code word input overhaul, more accurate cursor and selection processing. New styling for the widget that conforms with browser default style (focus outline).
2025-12-09 23:07:15 +00:00
LeoVasanko
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
LeoVasanko
9b491164fd
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
LeoVasanko
bb34e52997
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
LeoVasanko
b9897b62b8
Remove trash bin icons from tab order. Instead, implement Delete key support (Backspace accepted on Apple devices).
2025-12-09 16:54:46 +00:00
LeoVasanko
8a21edf367
Process IPv6 display into short format including only the network prefix, and sharing the same code also for comparisons where needed.
2025-12-09 16:33:16 +00:00
LeoVasanko
03368b1b84
Rename base64 functions such that imports don't need renaming.
2025-12-09 15:55:03 +00:00
LeoVasanko
bfc5b11cc2
Fix missing credential_uuid in admin user detail API that was causing linkage between sessions and their passkeys not show up.
2025-12-09 15:34:05 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
83419d1845
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
2025-12-06 04:45:26 +00:00
LeoVasanko
a2fe0b6f1a
Added E2E restricted API flow tests and fixed earlier failing tests. All passing. Coverage 51% backend, 74% frontend.
2025-12-06 03:43:28 +00:00
LeoVasanko
a1b73711e6
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
2025-12-06 03:39:05 +00:00
LeoVasanko
df5c176bcd
Fixed and updated E2E test suite. Added user credential registration tests. Coverage for backend and frontend.
2025-12-06 00:52:35 +00:00
LeoVasanko
8937905c9c
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
2025-12-06 00:51:18 +00:00
LeoVasanko
127e06179b
More robust server startup, startup logo and info screen, renewed devmode script.
2025-12-05 19:06:42 +00:00
LeoVasanko
c1204ca020
Updated documentation.
2025-12-05 16:15:50 +00:00
LeoVasanko
208115ebc3
Project renamed to Paskia.
2025-12-05 13:17:52 +00:00
LeoVasanko
8609f2fe69
Refactor dev mode into a source repo script (remove dev subcommand from package).
2025-12-05 18:36:13 +00:00
LeoVasanko
0355c55fc0
Updated E2E tests.
2025-12-04 04:44:58 +00:00
LeoVasanko
ea1ddbbe6f
Make dev mode run without static files, only serving assets in production.
2025-12-04 10:15:26 +00:00
LeoVasanko
b091744665
Cleanup old hostapp files (finished, working).
2025-12-04 10:06:54 +00:00
LeoVasanko
2cf8799c75
Missing new component.
2025-12-04 10:03:33 +00:00