Commit Graph
6 Commits
Author SHA1 Message Date
LeoVasanko e979dd6312 Devserver and proxy configs for multi-realm
- devserver bootstraps via one-shot 'paskia init' when no database
  exists (multi --rp-id, --rp-name/--auth-host/--origin apply to the
  default realm), then runs plain 'paskia' serve which reads all realm
  configuration from the database; legacy *.paskiadb is adopted by
  serve without init.
- Caddy origins iterate all bootstrap rp-ids.
- vite.config.js accepts a comma-separated PASKIA_AUTH_HOST list and
  proxies /.well-known/webauthn to the backend so ROR works in dev.
- caddy/auth/setup forwards /.well-known/openid-configuration and
  /.well-known/webauthn to paskia (they must not be swallowed by a
  static /.well-known/* file handler); Caddyfile.dev updated to match
  the generated dev config.
2026-09-06 14:49:27 +00:00
LeoVasanko 383c9f472e Add public access mode (public=1) to forward auth
/auth/api/forward?public=1 passes requests through with a Remote-Public
header (anonymous/forbidden/authenticated) instead of 401/403, so routes
can allow anonymous visitors while still identifying logged-in users.
Reauth (max_age) still requires the auth flow. Documented in Headers.md,
api/forward.md, Integration.md and all proxy guides.
2026-09-05 16:06:32 +00:00
LeoVasanko 2d2e4e899d Simplified Caddy snippets (removed auth/all). 2025-09-29 08:00:19 +00:00
LeoVasanko fc673c8d8e Support auth request for WebSocket connections (using plain HTTP for auth). Use keep-alive for better performance. 2025-09-27 03:00:56 +00:00
LeoVasanko ffbe8a6b18 Minor tuning of Caddy configuration and improved documentation. 2025-09-26 07:12:11 +00:00
LeoVasanko 39ba032450 Provide user info in Remote-* headers. Caddy configuration improved. 2025-09-26 06:12:40 +00:00