LeoVasanko
2d0d17c307
fix remote auth: create session for requesting device host
v1.4.1
2026-04-30 21:47:47 +00:00
LeoVasanko
10980ad39b
fix type hints: update_session and set_session_host key type
2026-04-30 21:47:46 +00:00
LeoVasanko
42b54cf645
Release 1.4.0
v1.4.0
2026-04-29 20:48:12 +00:00
LeoVasanko
232d0e1ae0
Added configurable timeout settings to paskia-js, used in our frontend as well. The default fetch timeout has been changed to 10s from prior 1s, but we maintain 1s for auth endpoints in internal use.
2026-04-29 20:23:38 +00:00
LeoVasanko
e97a2b3291
Improved color compatibility across terminals that may have very different ideas of yellow shades.
2026-04-29 16:23:34 +00:00
LeoVasanko
cde709e252
Print original METHOD /path on auth/api/forward access log entries. Previously the method was not printed, and nothing was printed for 401 without a session.
v1.3.7
2026-04-29 15:47:37 +00:00
LeoVasanko
72d76df35d
Log session id from handlers on selected auth routes. Adds request.state.log_extra for handlers to print access log extra.
v1.3.6
2026-04-29 03:02:30 +00:00
LeoVasanko
1a742fc0e7
Cleaner websocket access log.
2026-04-29 02:45:20 +00:00
LeoVasanko
0b29654d6f
Log original path on forward endpoint. Added logging extra argument for such additions on access logs.
2026-04-29 02:16:48 +00:00
LeoVasanko
76f24a755b
Add GET /auth/api/check endpoint for unauthenticated user permission checks
...
Checks permissions for a user given by ?user=<UUID> query arg without
requiring a session cookie. No cookie is read or written, no DB writes.
- perm= query arg supported (same wildcard semantics as validate/forward)
- Returns valid bool + minimal ctx (user/org/role/permissions)
- Permissions are host-scoped via domain filtering, same as session_ctx
- 404 if UUID not found; valid=false if perm check fails (no 403)
- Add ApiCheckUserResponse struct to apistructs
- Add has_all_scopes() helper to permutil for scope-set-based checks
v1.3.5
2026-04-26 05:45:59 +00:00
LeoVasanko
5c452f325a
Better error messages on database loading errors.
v1.3.4
2026-02-19 21:52:33 +00:00
LeoVasanko
e9b6bc7a3d
Implement migration for old format listen field in database (re: commit f746085)
v1.3.3
2026-02-19 21:26:12 +00:00
LeoVasanko
f5545b48f0
Remove dead code.
2026-02-19 21:10:16 +00:00
LeoVasanko
c1b2bcf76c
Correct alphabetical sort of names in Org Admin panel. Supports Last, First and First Last + variatioons.
v1.3.2
2026-02-19 20:54:52 +00:00
LeoVasanko
1806bcab5c
A bit more color for light theme; cleaner user badges in admin app.
2026-02-19 20:40:21 +00:00
LeoVasanko
be177cbafc
Add default value for a(ction) field in change records to keep support for very old versions.
2026-02-19 20:16:16 +00:00
LeoVasanko
f5ccc204be
Fix adminapp reference after refactoring.
v1.3.1
2026-02-19 20:03:58 +00:00
LeoVasanko
dd2031eef5
Fix runtime config update by Server Options panel.
v1.3.0
2026-02-19 19:57:12 +00:00
LeoVasanko
3cb24bfee9
Refactor to separate admin app modules to subapps, required trailing slashes and plural changes on some of the URLs.
2026-02-19 19:49:13 +00:00
LeoVasanko
3f51d06f13
Admin Server Options panel added for configuring rp-name, auth-host and origins.
2026-02-19 18:53:53 +00:00
LeoVasanko
528a728eb8
README
2026-02-19 18:44:06 +00:00
LeoVasanko
727625ef4f
Avoid storing IP and User Agent on OpenID Connect token renewals; preserves the user's information from authentication.
v1.2.4
2026-02-19 16:34:44 +00:00
LeoVasanko
5f7a5ed9b1
Added database snapshots, cleanup, better error messages.
v1.2.3
2026-02-19 16:29:23 +00:00
LeoVasanko
d64e63527b
CLI main and RuntimeConfig cleanup. Added a session_ctx wrapper function for easier access and avoiding hostutil import in db.
2026-02-19 14:24:16 +00:00
LeoVasanko
733439b446
Logging cleanup, better color compatibility for Mac Terminal and consistent across DB and FastAPI access logs.
2026-02-19 14:19:54 +00:00
LeoVasanko
4e6f63e9ef
Fix auth-host being added to origins even when no origins were wanted.
v1.2.2
2026-02-19 01:00:13 +00:00
LeoVasanko
d431c75297
Fix request header removal that was causing zstd compressed response when we wanted plain text.
v1.2.1
2026-02-19 00:51:11 +00:00
LeoVasanko
6257071efe
Cleaned Org Admin styling.
v1.2.0
2026-02-19 00:37:44 +00:00
LeoVasanko
7958b6f365
Migrations cleanup by using a MigrationCtx object for meta.
2026-02-19 00:08:38 +00:00
LeoVasanko
b3cb540098
Implement database file locking for extra safety.
2026-02-19 00:01:49 +00:00
LeoVasanko
22ba7231b1
Implement read-only database load at startup for CLI to get its settings. Full opening only when server has started.
2026-02-18 23:46:18 +00:00
LeoVasanko
9a9979fb62
Add missing new file.
2026-02-18 23:45:22 +00:00
LeoVasanko
9b7855c0af
Faster and simplified hash_secret() that directly produces urlsafe entries.
2026-02-18 23:02:36 +00:00
LeoVasanko
dfc4c76d43
Fix static asset serving in devserver mode.
2026-02-18 22:19:18 +00:00
LeoVasanko
e1f0fdf664
Fix E2E tests
2026-02-18 22:18:31 +00:00
LeoVasanko
f26ac8f33b
Simplified My Profile authentication flows, fixed some UX issues with reauth cancelled/accepted leading to incorrect states.
2026-02-18 19:04:02 +00:00
LeoVasanko
880ced3b8c
Always load user's theme from API if available, and update the localStorage cache. Previously in various situations the old cached value was being used instead, leading to inconsistent theming or wrong themeselector readout.
2026-02-18 18:35:41 +00:00
LeoVasanko
af80b5eefc
Make ResetApp Registration layout match the other dialog apps (centered).
2026-02-18 18:01:17 +00:00
LeoVasanko
fa1e69d58b
Imports to top of file.
2026-02-18 17:47:57 +00:00
LeoVasanko
39000ef831
Remove PASKIA_SITE_URL env, use PASKIA_VITE_URL instead, moving the correct site URL determination to paskia CLI directly. This resolves devserver issues where VITE URL was reported as the external site URL instead of configured auth-host or origins. Main CLI still simplified. Bump deps versions and cleanup pyproject.toml.
2026-02-18 17:21:03 +00:00
LeoVasanko
49119fac81
Fix HostProfile user properties access.
2026-02-18 03:47:08 +00:00
LeoVasanko
14aae74b60
Bump and synchronize paskia-js version.
v1.1.0
2026-02-18 02:45:33 +00:00
LeoVasanko
68dccc1378
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko
557ffaa0cd
Add theme toggles that were missing from forward and reset apps.
2026-02-17 18:36:12 +00:00
LeoVasanko
c0aba07326
Show credential UUID in logging as they are, no prettifying.
2026-02-17 18:32:47 +00:00
LeoVasanko
f830d7d0ec
More minimalistic light theme. UI hint for org admin user/role management.
2026-02-14 18:36:20 +00:00
LeoVasanko
7f52276c23
Use samesite=strict because we don't need the cookie for page loads.
2026-02-13 20:22:05 +00:00
LeoVasanko
c1f8020f6b
API cleanup, using msgspec structs rather than raw responses. Admin app cleanup, better breadcrumbs.
2026-02-13 20:09:41 +00:00
LeoVasanko
423abb0d1b
Move CLI entry point to main module even though it runs the FastAPI app from a submodule.
2026-02-13 16:26:05 +00:00
LeoVasanko
ef7a6c8011
Upgrade fastapi-vue-setup 1.0.2
2026-02-11 21:33:21 +00:00