LeoVasanko
575d3cb1fb
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-05 05:26:03 +00:00
LeoVasanko
a4ac19f54c
WebSockets must use origin for finding the host calling them.
2025-10-05 05:16:51 +00:00
LeoVasanko
11887d15b2
Correction on restricted path checking (auth-host).
2025-10-05 04:59:05 +00:00
LeoVasanko
cefb9c3d92
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-05 04:49:23 +00:00
LeoVasanko
5b9a3fc27f
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-05 04:35:55 +00:00
LeoVasanko
19a6c32cf2
Fix deletion of session cookie on host logout.
2025-10-05 04:26:36 +00:00
LeoVasanko
eaa16abe2a
Better UX for profile view logout buttons.
2025-10-05 04:22:16 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
f24aaa295d
More consistent shared styling between credential and session cards.
2025-10-04 20:32:27 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
24692fcfec
Use git tag versioning for the Python project.
2025-10-03 04:07:11 +00:00
LeoVasanko
43850c218f
Fix reset link logic to include /auth when no configured auth-host.
2025-10-03 03:57:20 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
b4871c671f
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-03 00:22:02 +00:00
LeoVasanko
095768e07c
Version 0.2.0
2025-10-01 05:04:53 +00:00
LeoVasanko
2f77753354
Make the login/reset/forbidden dialogs look better.
2025-10-01 05:03:51 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
c3e4c18d5c
Remove duplicate message from permission denied page.
2025-10-01 00:56:41 +00:00
LeoVasanko
a7c23b31e7
Admin app divided to separate components.
2025-10-01 00:54:18 +00:00
LeoVasanko
3f45024396
Massive style redesign, WIP.
2025-09-30 09:02:49 +00:00
LeoVasanko
2d2e4e899d
Simplified Caddy snippets (removed auth/all).
2025-09-29 08:00:19 +00:00
LeoVasanko
48f718191f
Version 0.1.2
2025-09-29 07:46:49 +00:00
LeoVasanko
e130bc5c0a
Clear sessionStorage on logout.
2025-09-29 07:45:37 +00:00
LeoVasanko
2df444b80f
chore: bump version to 0.1.1
2025-09-28 08:51:46 +00:00
LeoVasanko
5ad3ccb5ae
Implement breadcrumb navigation.
2025-09-28 08:47:45 +00:00
LeoVasanko
ec098b862c
Implement credential reset via CLI.
2025-09-27 05:18:33 +00:00
LeoVasanko
bd5a920a56
Update documentation.
2025-09-27 04:59:18 +00:00
LeoVasanko
88275beb0f
Make the /auth/api/validate endpoint renew sessions if needed.
2025-09-27 04:59:11 +00:00
LeoVasanko
d897f9c217
Updated example Caddyfile
2025-09-27 04:58:36 +00:00
LeoVasanko
fc673c8d8e
Support auth request for WebSocket connections (using plain HTTP for auth). Use keep-alive for better performance.
2025-09-27 03:00:56 +00:00
LeoVasanko
4315584589
Cleanup
2025-09-27 03:00:17 +00:00
LeoVasanko
ffbe8a6b18
Minor tuning of Caddy configuration and improved documentation.
2025-09-26 07:12:11 +00:00
LeoVasanko
39ba032450
Provide user info in Remote-* headers. Caddy configuration improved.
2025-09-26 06:12:40 +00:00
LeoVasanko
f28e69a9ce
Cleaner logout.
2025-09-03 07:11:25 +00:00
LeoVasanko
09b9894407
Cleaned up login/logout flows.
2025-09-03 07:08:16 +00:00
LeoVasanko
4052122d40
Fix url_for query arg on reset link redirect.
2025-09-03 06:32:56 +00:00
LeoVasanko
f0ff3cf977
Fix matching bug
2025-09-03 06:22:21 +00:00
LeoVasanko
07212ee1de
Major refactoring of admin API (permissions, paths)
2025-09-03 06:08:06 +00:00
LeoVasanko
340888a178
Refactoring permissions checks.
2025-09-03 05:28:26 +00:00
LeoVasanko
53f1745ebd
Utility module for accessing frontend in backend code.
2025-09-03 04:05:20 +00:00
LeoVasanko
42e0266cd6
Move forward auth under /admin/api/forward
2025-09-03 03:03:39 +00:00
LeoVasanko
982937572a
New lint option path in pyproject
2025-09-03 03:03:02 +00:00
LeoVasanko
5c5da10c8b
Moved exception handlers to sub apps.
2025-09-03 02:57:06 +00:00
LeoVasanko
0d725f85a5
Rename variable to silence linter
2025-09-03 02:45:23 +00:00
LeoVasanko
6e5ea9eac0
Refactor API under /auth/api
2025-09-03 02:32:19 +00:00
LeoVasanko
5281432c96
Restructure admin app separate of user api.
2025-09-03 02:04:52 +00:00
LeoVasanko
ed2b0f6f3c
Remove icon, prefer automatic use of /favicon.ico of the host site.
2025-09-02 22:17:40 +00:00
LeoVasanko
cf4835ff83
Redux
2025-09-02 08:21:20 +00:00
LeoVasanko
01251a4769
Support WS connections on older browsers.
2025-09-02 08:15:14 +00:00
LeoVasanko
aed9835098
Better navigation on admin app.
2025-09-02 08:04:56 +00:00
LeoVasanko
54a0d84cb5
Smarter user info
2025-09-02 08:02:52 +00:00
LeoVasanko
70a7bc791f
Fix previous
2025-09-02 07:58:48 +00:00
LeoVasanko
a84556509a
Unify user info across admin app and profile view.
2025-09-02 07:56:18 +00:00
LeoVasanko
3547144313
Use bun --bun consistently, avoid devmode origin override if specified by args rp-id and/or origin.
2025-09-02 07:47:46 +00:00
LeoVasanko
2769d8c7f0
User name editing UI (hopefully fixed)
2025-09-02 06:59:39 +00:00
LeoVasanko
a526344842
Use rp-name for frontend branding
2025-09-02 06:48:59 +00:00
LeoVasanko
93d722c4d2
Count registration also as a login.
2025-09-02 06:40:05 +00:00
LeoVasanko
b39eb59961
Linter
2025-09-02 06:29:38 +00:00
LeoVasanko
a1d5270dd7
User rename fixes.
2025-09-02 06:20:32 +00:00
LeoVasanko
e1e933c756
Renaming of users in registration, profile and admin app.
2025-09-02 06:13:01 +00:00
LeoVasanko
b9c1fe059c
Crude dialog rather than prompt() for input fields. (needs cleanup)
2025-09-02 05:34:45 +00:00
LeoVasanko
2b371c70db
Updated frontend build script
2025-09-02 05:16:48 +00:00
LeoVasanko
db19ff61f6
Only allow safe characters in permission IDs
2025-08-31 07:10:00 +00:00
LeoVasanko
0e4e4f4cfa
Make default permissions use only : as separator.
2025-08-31 06:43:49 +00:00
LeoVasanko
24404738ab
Formatting
2025-08-31 06:43:27 +00:00
LeoVasanko
3a52966fc1
Extended demo Caddyfile
2025-08-31 06:41:28 +00:00
LeoVasanko
d7735675b7
Implement Permission Denied handling.
2025-08-31 06:38:48 +00:00
LeoVasanko
c06b7ddf26
Allow specifying multiple permissions.
2025-08-31 04:47:38 +00:00
LeoVasanko
c67a83abdc
Add permission check on forward-auth and validate.
2025-08-31 04:13:54 +00:00
LeoVasanko
ad4bde5d0d
Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site).
2025-08-31 03:54:17 +00:00
LeoVasanko
54cef0f9d6
Fixing cascade.
2025-08-31 02:07:32 +00:00
LeoVasanko
d229ed267c
Actually usable admin panel
2025-08-30 10:38:22 +00:00
LeoVasanko
9402aae829
Almost usable admin panel
2025-08-30 09:54:51 +00:00
LeoVasanko
75bcdb8b18
Basic navigation between auth and user pages.
2025-08-30 08:50:37 +00:00
LeoVasanko
6c6e62cd5b
Fix proxying so that Vite dev mode autoreloads.
2025-08-30 08:49:26 +00:00
LeoVasanko
395ecdbd19
Major changes to server startup. Admin page tuning.
2025-08-30 08:41:38 +00:00
LeoVasanko
6840f319eb
Instruct type checker
2025-08-30 07:03:14 +00:00
LeoVasanko
ff9bb1558d
Drafting admin app (frontend)
2025-08-13 03:24:27 +00:00
LeoVasanko
ee3708105b
Support for adding permissions on roles and orgs.
2025-08-13 03:13:35 +00:00
LeoVasanko
37640ab42b
Add permissions to orgs and roles (in DB-agnostic API).
2025-08-13 01:21:37 +00:00
LeoVasanko
c69b09ceec
Cleaner formatting
2025-08-13 01:21:05 +00:00
LeoVasanko
7e45bba612
Almost complete org/permission handling. Much cleanup, bootstrap works.
2025-08-08 01:58:12 +00:00
LeoVasanko
2505f96dde
Users always belong to one Org. Implement a DB function to fetch all data relevant to a session.
2025-08-07 22:42:49 +00:00
LeoVasanko
6a7edbb055
Bootstrapping cleanup, avoid double operations.
2025-08-07 12:45:12 +00:00
LeoVasanko
2c951f6be1
Bootstrap cleanup
2025-08-07 11:56:13 +00:00
LeoVasanko
62cf384cfa
Bootstrap code cleanup.
2025-08-07 02:39:44 +00:00
LeoVasanko
df377c4a14
Globals restructured to their own module. Origin and RP definition.
2025-08-07 01:23:35 +00:00
LeoVasanko
0578706bdf
Initial bootstrap to add admin user
2025-08-07 00:16:37 +00:00
LeoVasanko
039613a8b3
Cleaner error message on aborted Passkey operations.
2025-08-07 00:00:23 +00:00
LeoVasanko
04953c7903
Frontend component selection logic simplified.
2025-08-06 23:33:34 +00:00
LeoVasanko
764bbd1115
Avoid loading user info twice to show profile.
2025-08-06 22:57:41 +00:00
LeoVasanko
82150be650
Error handling cleanup for WS too.
2025-08-06 22:53:13 +00:00
LeoVasanko
5a55417dad
Centralised error handling & convenience.
2025-08-06 22:44:57 +00:00
LeoVasanko
4ca6eb9994
Add New Passkey and Add New Device flows fixed.
2025-08-06 22:14:04 +00:00
LeoVasanko
b255362946
Refactor to not use status: success, but HTTP codes, and renamed the error key to detail to match FastAPI's own.
2025-08-06 22:09:55 +00:00
LeoVasanko
c8bb2ab12e
Checkpoint, fixing reset token handling broken in earlier edits.
2025-08-06 21:55:14 +00:00
LeoVasanko
1440727955
Add organisations on DB
2025-08-06 00:16:02 +00:00
LeoVasanko
54056c7851
gitignore
2025-08-06 00:15:48 +00:00
LeoVasanko
e035067ffb
Change filename to passkey-auth.sqlite
2025-08-05 21:24:38 +00:00