Leo Vasanko
8a6540aa91
Fix background task still running twice, and add a check to prevent that happening again (double expiry).
2026-01-27 23:51:13 +00:00
Leo Vasanko
2413a32bda
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
Leo Vasanko
f6e995184f
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
Leo Vasanko
2227a9bf6f
Refer permissions by UUID rather than scope.
2026-01-24 00:06:08 +00:00
Leo Vasanko
4c1db37c73
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
Leo Vasanko
253387be97
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
Leo Vasanko
727db38bc7
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
Leo Vasanko
8310d9f0b5
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
Leo Vasanko
b9b6c9356f
Change input placeholder that was improperly triggering Bitwarden to complete username in it. BW does not respect autocomplete at all.
2025-12-10 16:56:19 +00:00
LeoVasanko
2487759628
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
...
Reviewed-on: #2
2025-12-10 15:43:40 +00:00
LeoVasanko
c605926c30
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
Leo Vasanko
219dd70665
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-03 13:21:52 -06:00
Leo Vasanko
4306323c44
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-03 13:00:24 -06:00
Leo Vasanko
1f75e0a305
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 11:17:02 -06:00
Leo Vasanko
bd13dbd1a0
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
Leo Vasanko
ca8d65ad25
Improved profile view layout.
2025-12-03 01:04:07 +00:00
Leo Vasanko
c83450dace
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
Leo Vasanko
2a5f06d707
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
Leo Vasanko
6f9f4aefc1
Implement Forbidden view for API calls, cleanup and better UX.
2025-12-02 17:36:37 +00:00
Leo Vasanko
a05d4aec81
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
Leo Vasanko
77d8e97dc9
Update admin app authentication in API mode too, reusing components between it and the main app.
2025-12-02 15:42:55 +00:00
Leo Vasanko
cb26c61d5f
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
Leo Vasanko
bfb11cc20f
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko
591ea626bf
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-03 18:31:54 -06:00
Leo Vasanko
5d8304bbd9
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko
ed7d3ee0fc
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-09-30 16:38:14 -06:00
Leo Vasanko
89b40cd080
Admin app divided to separate components.
2025-09-30 12:54:18 -06:00
Leo Vasanko
d46d50b91a
Massive style redesign, WIP.
2025-09-29 21:02:49 -06:00
Leo Vasanko
6439437e8b
Implement breadcrumb navigation.
2025-09-27 20:47:45 -06:00
Leo Vasanko
c9f9b28bf4
Major refactoring of admin API (permissions, paths)
2025-09-02 18:08:06 -06:00
Leo Vasanko
312d23b79a
Refactor API under /auth/api
2025-09-02 14:32:19 -06:00
Leo Vasanko
70551cebb7
Better navigation on admin app.
2025-09-01 20:04:56 -06:00
Leo Vasanko
5a9bee9a1d
Smarter user info
2025-09-01 20:02:52 -06:00
Leo Vasanko
fd11cac4bc
Unify user info across admin app and profile view.
2025-09-01 19:56:18 -06:00
Leo Vasanko
7036338b33
Use rp-name for frontend branding
2025-09-01 18:48:59 -06:00
Leo Vasanko
6d6c4ee35d
User rename fixes.
2025-09-01 18:20:32 -06:00
Leo Vasanko
37eaffff3f
Renaming of users in registration, profile and admin app.
2025-09-01 18:13:01 -06:00
Leo Vasanko
bc87f76d11
Crude dialog rather than prompt() for input fields. (needs cleanup)
2025-09-01 17:34:45 -06:00
Leo Vasanko
2b03fa74cd
Only allow safe characters in permission IDs
2025-08-30 19:10:00 -06:00
Leo Vasanko
4f094a7016
Fixing cascade.
2025-08-30 14:07:32 -06:00
Leo Vasanko
f3e3679b6d
Actually usable admin panel
2025-08-29 22:38:22 -06:00
Leo Vasanko
4db7f2e9a6
Almost usable admin panel
2025-08-29 21:54:51 -06:00
Leo Vasanko
efdfa77fc9
Basic navigation between auth and user pages.
2025-08-29 20:50:37 -06:00
Leo Vasanko
7380f09458
Major changes to server startup. Admin page tuning.
2025-08-29 20:41:38 -06:00
Leo Vasanko
e0717f005a
Drafting admin app (frontend)
2025-08-12 13:24:27 -07:00