Commit Graph
64 Commits
Author SHA1 Message Date
LeoVasanko 3030122807 Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages. 2025-12-02 15:25:31 +00:00
LeoVasanko a62e8ddf1e Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified. 2025-12-02 03:10:16 +00:00
LeoVasanko af2834b4c0 Reset dialog UX improved. 2025-10-05 06:25:40 +00:00
LeoVasanko ef66baff20 Harmonise ProfileView and HostApp. 2025-10-05 06:14:17 +00:00
LeoVasanko 08d4607d65 Tuning the host app. 2025-10-05 06:03:28 +00:00
LeoVasanko 1ca9e3ef58 Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose. 2025-10-05 05:55:08 +00:00
LeoVasanko eaa16abe2a Better UX for profile view logout buttons. 2025-10-05 04:22:16 +00:00
LeoVasanko 01bc39a0e8 A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko fa513940c7 Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 20:59:51 +00:00
LeoVasanko f24aaa295d More consistent shared styling between credential and session cards. 2025-10-04 20:32:27 +00:00
LeoVasanko 0af7aad28c Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-04 06:31:54 +00:00
LeoVasanko 2f1578c4bc Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko 2f77753354 Make the login/reset/forbidden dialogs look better. 2025-10-01 05:03:51 +00:00
LeoVasanko ea871635e0 Admin app: guard rails extended, consistent styling, also share styling with main app. 2025-10-01 04:38:14 +00:00
LeoVasanko c3e4c18d5c Remove duplicate message from permission denied page. 2025-10-01 00:56:41 +00:00
LeoVasanko a7c23b31e7 Admin app divided to separate components. 2025-10-01 00:54:18 +00:00
LeoVasanko 3f45024396 Massive style redesign, WIP. 2025-09-30 09:02:49 +00:00
LeoVasanko e130bc5c0a Clear sessionStorage on logout. 2025-09-29 07:45:37 +00:00
LeoVasanko 5ad3ccb5ae Implement breadcrumb navigation. 2025-09-28 08:47:45 +00:00
LeoVasanko f28e69a9ce Cleaner logout. 2025-09-03 07:11:25 +00:00
LeoVasanko 09b9894407 Cleaned up login/logout flows. 2025-09-03 07:08:16 +00:00
LeoVasanko 07212ee1de Major refactoring of admin API (permissions, paths) 2025-09-03 06:08:06 +00:00
LeoVasanko 6e5ea9eac0 Refactor API under /auth/api 2025-09-03 02:32:19 +00:00
LeoVasanko ed2b0f6f3c Remove icon, prefer automatic use of /favicon.ico of the host site. 2025-09-02 22:17:40 +00:00
LeoVasanko cf4835ff83 Redux 2025-09-02 08:21:20 +00:00
LeoVasanko 01251a4769 Support WS connections on older browsers. 2025-09-02 08:15:14 +00:00
LeoVasanko aed9835098 Better navigation on admin app. 2025-09-02 08:04:56 +00:00
LeoVasanko 54a0d84cb5 Smarter user info 2025-09-02 08:02:52 +00:00
LeoVasanko 70a7bc791f Fix previous 2025-09-02 07:58:48 +00:00
LeoVasanko a84556509a Unify user info across admin app and profile view. 2025-09-02 07:56:18 +00:00
LeoVasanko 2769d8c7f0 User name editing UI (hopefully fixed) 2025-09-02 06:59:39 +00:00
LeoVasanko a526344842 Use rp-name for frontend branding 2025-09-02 06:48:59 +00:00
LeoVasanko a1d5270dd7 User rename fixes. 2025-09-02 06:20:32 +00:00
LeoVasanko e1e933c756 Renaming of users in registration, profile and admin app. 2025-09-02 06:13:01 +00:00
LeoVasanko b9c1fe059c Crude dialog rather than prompt() for input fields. (needs cleanup) 2025-09-02 05:34:45 +00:00
LeoVasanko db19ff61f6 Only allow safe characters in permission IDs 2025-08-31 07:10:00 +00:00
LeoVasanko 24404738ab Formatting 2025-08-31 06:43:27 +00:00
LeoVasanko d7735675b7 Implement Permission Denied handling. 2025-08-31 06:38:48 +00:00
LeoVasanko ad4bde5d0d Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site). 2025-08-31 03:54:17 +00:00
LeoVasanko 54cef0f9d6 Fixing cascade. 2025-08-31 02:07:32 +00:00
LeoVasanko d229ed267c Actually usable admin panel 2025-08-30 10:38:22 +00:00
LeoVasanko 9402aae829 Almost usable admin panel 2025-08-30 09:54:51 +00:00
LeoVasanko 75bcdb8b18 Basic navigation between auth and user pages. 2025-08-30 08:50:37 +00:00
LeoVasanko 6c6e62cd5b Fix proxying so that Vite dev mode autoreloads. 2025-08-30 08:49:26 +00:00
LeoVasanko 395ecdbd19 Major changes to server startup. Admin page tuning. 2025-08-30 08:41:38 +00:00
LeoVasanko ff9bb1558d Drafting admin app (frontend) 2025-08-13 03:24:27 +00:00
LeoVasanko 7e45bba612 Almost complete org/permission handling. Much cleanup, bootstrap works. 2025-08-08 01:58:12 +00:00
LeoVasanko 039613a8b3 Cleaner error message on aborted Passkey operations. 2025-08-07 00:00:23 +00:00
LeoVasanko 04953c7903 Frontend component selection logic simplified. 2025-08-06 23:33:34 +00:00
LeoVasanko 764bbd1115 Avoid loading user info twice to show profile. 2025-08-06 22:57:41 +00:00