Leo Vasanko
|
7523a49543
|
Add preferred username and email to user data.
|
2026-02-17 12:07:25 +00:00 |
|
Leo Vasanko
|
627912fae5
|
Fix tests for earlier changes.
|
2026-02-17 01:35:11 +00:00 |
|
Leo Vasanko
|
f8c213c7dc
|
Implement backchannel logout to client.
|
2026-02-17 01:31:45 +00:00 |
|
Leo Vasanko
|
b5e308d5df
|
OIDC authentication works, remove debug.
|
2026-02-17 01:09:16 +00:00 |
|
Leo Vasanko
|
ba3695cf88
|
Aud problem debug.
|
2026-02-17 00:20:53 +00:00 |
|
Leo Vasanko
|
2e8439f876
|
Issuer problem debug.
|
2026-02-17 00:19:04 +00:00 |
|
Leo Vasanko
|
d0abd224f4
|
Issuer problem debug.
|
2026-02-17 00:17:47 +00:00 |
|
Leo Vasanko
|
5bc92ce983
|
Issuer problem debug.
|
2026-02-17 00:16:10 +00:00 |
|
Leo Vasanko
|
5019cd13fe
|
Fix again, didn't work
|
2026-02-17 00:07:26 +00:00 |
|
Leo Vasanko
|
72307fb7c3
|
Fix again, didn't work
|
2026-02-17 00:05:22 +00:00 |
|
Leo Vasanko
|
21d1e123f5
|
Fix FastAPI token grant_type validation error when missing and form was sent by client.
|
2026-02-17 00:00:51 +00:00 |
|
Leo Vasanko
|
fee833b908
|
Made PKCE and nonce optional, only when client wants them.
|
2026-02-16 23:55:42 +00:00 |
|
Leo Vasanko
|
ce68af5be3
|
Correct OIDC mode handling in restricted app.
|
2026-02-16 23:38:23 +00:00 |
|
Leo Vasanko
|
bcecb390e1
|
Fix registration broken from earlier hardening. Streamline authentication and registration to avoid duplication of this.
|
2026-02-16 21:26:24 +00:00 |
|
Leo Vasanko
|
2a318adab4
|
Add back missing ResetToken.delete() lost on earlier refactoring.
|
2026-02-16 20:53:07 +00:00 |
|
Leo Vasanko
|
30aeb9a310
|
Admin OIDC Client editing moved to its own page.
|
2026-02-16 20:32:55 +00:00 |
|
Leo Vasanko
|
09049d3094
|
Implement redirect URL autodiscovery (Trust On First Use - if none are manually defined).
|
2026-02-16 20:32:11 +00:00 |
|
Leo Vasanko
|
0081cc835b
|
[paskia-js] Inject styles when backdrop is needed for non-auth dialogs.
|
2026-02-16 19:16:09 +00:00 |
|
Leo Vasanko
|
e7e0097fba
|
User friendly admin app OIDC Client dialog. Permissions domain scoping to OIDC Clients.
|
2026-02-16 17:43:52 +00:00 |
|
Leo Vasanko
|
b73b2d6fe9
|
Renamed OIDC permissions claim to more commonly used groups. Move jwtk to a more convenient location. Draft admin app OIDC client configuratioon.
|
2026-02-16 16:54:53 +00:00 |
|
Leo Vasanko
|
eece6d4a21
|
Remove some confusion between exchange and set-session endpoints, all using set-session now with a bearer code. Using codes in remote auth as well. Full separation of cookie and OIDC codes.
|
2026-02-16 14:26:20 +00:00 |
|
Leo Vasanko
|
ebf5f6db2c
|
Route our new restricted endpoints correctly on vite dev.
|
2026-02-16 14:23:07 +00:00 |
|
Leo Vasanko
|
d653a1db35
|
Database migration to add OIDC and convert to hardened sessions.
|
2026-02-15 21:12:29 +00:00 |
|
Leo Vasanko
|
feeea30cb6
|
Hardening OIDC verification.
|
2026-02-15 20:49:13 +00:00 |
|
Leo Vasanko
|
e59852b44c
|
Session keys hardened (namespaced hashes of tokens). Various cleanup.
|
2026-02-15 20:14:48 +00:00 |
|
Leo Vasanko
|
18722f0e01
|
Implement stateful OIDC as Session objects. Add refresh tokens and backchannel logout.
|
2026-02-15 03:48:10 +00:00 |
|
Leo Vasanko
|
8132189a04
|
Rename /auth/restricted/ to auth/restricted/{iframe,oidc} for clarity and separation.
|
2026-02-15 03:05:11 +00:00 |
|
Leo Vasanko
|
701b0810bd
|
Stricter security. Moved to /auth/oidc/
|
2026-02-15 02:57:23 +00:00 |
|
Leo Vasanko
|
b5a5f2707a
|
Draft OpenID Connect support.
|
2026-02-14 23:01:13 +00:00 |
|
Leo Vasanko
|
f195818f07
|
Upgrade fastapi-vue-setup 1.0.2
|
2026-02-11 21:33:21 +00:00 |
|
Leo Vasanko
|
e16c027b53
|
Remove unused CLI bootstrap entry point.
|
2026-02-11 20:29:12 +00:00 |
|
Leo Vasanko
|
a9cf518296
|
Add version indication and link to our site on profile page (bottom right corner).
|
2026-02-11 01:36:58 +00:00 |
|
Leo Vasanko
|
0af7d4b939
|
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
|
2026-02-11 01:24:23 +00:00 |
|
Leo Vasanko
|
419f69cef5
|
Style overhaul.
|
2026-02-11 01:18:19 +00:00 |
|
Leo Vasanko
|
b1731e5abf
|
Inline get_config, rewrite update_config, DB init Config and rp_id defaults changed.
|
2026-02-10 23:17:28 +00:00 |
|
Leo Vasanko
|
9332eb63ab
|
ResetToken.hash(phrase) added avoiding code duplication.
|
2026-02-10 22:56:49 +00:00 |
|
Leo Vasanko
|
310a4e9a87
|
Remove remaining DB getter functions, inline at call site and add ResetToken.by_passphrase().
|
2026-02-10 22:48:31 +00:00 |
|
Leo Vasanko
|
6961a82f3f
|
Remove unnecessary odd getter from db.operations.
|
2026-02-10 22:37:57 +00:00 |
|
Leo Vasanko
|
f7d9d03765
|
Refactor DB lifecycle functions init and cleanup to separate db.lifecycle module.
|
2026-02-10 22:28:38 +00:00 |
|
Leo Vasanko
|
2f2934db6b
|
CRUD store and delete on the DB classes directly.
|
2026-02-10 22:19:02 +00:00 |
|
Leo Vasanko
|
f0d360758c
|
Db operations: bootstrap separated to its own module.
|
2026-02-10 22:09:07 +00:00 |
|
Leo Vasanko
|
12715ee405
|
Use strictly same now timestamp over a transaction, even for UUIDv7s generated.
|
2026-02-10 21:45:09 +00:00 |
|
Leo Vasanko
|
2105040661
|
Calculate session expiry times in operations, using a common now timestamp for everything.
|
2026-02-10 21:35:56 +00:00 |
|
Leo Vasanko
|
4fcfee78c7
|
Set last seen and increment visits during registration, not only on authentication.
|
2026-02-10 21:25:20 +00:00 |
|
Leo Vasanko
|
859a76a029
|
README
|
2026-02-09 19:22:05 +00:00 |
|
Leo Vasanko
|
441f920736
|
README
|
2026-02-09 18:52:53 +00:00 |
|
Leo Vasanko
|
9716b06399
|
README
|
2026-02-09 18:46:03 +00:00 |
|
Leo Vasanko
|
abdca4f648
|
Make config part of bootstrap.
|
2026-02-09 18:33:29 +00:00 |
|
Leo Vasanko
|
eb2a003f24
|
Improved CLI logging of DB transactions.
|
2026-02-09 18:28:24 +00:00 |
|
Leo Vasanko
|
e4efc1c442
|
Fix save config running before bootstrap for new databases.
|
2026-02-09 18:07:51 +00:00 |
|