Leo Vasanko
7a09dbc040
Simplified user info update APIs, DB and frontend to remove separate update functions for each property. Automatically choose preferred username for users as they register, based on display name.
2026-02-17 18:16:32 +00:00
Leo Vasanko
8128d40202
New user basic info card and improved layout, telephone number and other contact details shown.
2026-02-17 17:33:06 +00:00
Leo Vasanko
d526b2a98d
Group OIDC sessions correctly in profile view.
2026-02-17 12:27:57 +00:00
Leo Vasanko
7523a49543
Add preferred username and email to user data.
2026-02-17 12:07:25 +00:00
Leo Vasanko
a9cf518296
Add version indication and link to our site on profile page (bottom right corner).
2026-02-11 01:36:58 +00:00
Leo Vasanko
0af7d4b939
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
2026-02-11 01:24:23 +00:00
Leo Vasanko
419f69cef5
Style overhaul.
2026-02-11 01:18:19 +00:00
Leo Vasanko
e1f6c85ced
Improved theme picker
2026-02-05 16:19:06 +00:00
Leo Vasanko
cc439aaf12
Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins).
2026-01-30 23:31:06 +00:00
Leo Vasanko
5fc5226480
Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced).
2026-01-29 19:46:26 +00:00
Leo Vasanko
d8743d9f90
Refactor to separate paskia lib functionality generally useful for various apps.
2026-01-29 16:55:46 +00:00
Leo Vasanko
2413a32bda
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
Leo Vasanko
f6e995184f
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
Leo Vasanko
c6dadd283d
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
Leo Vasanko
253387be97
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
Leo Vasanko
727db38bc7
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
Leo Vasanko
8310d9f0b5
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
LeoVasanko
2487759628
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
...
Reviewed-on: #2
2025-12-10 15:43:40 +00:00
Leo Vasanko
48a8f575ec
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
Leo Vasanko
bf8c734bf7
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
LeoVasanko
c605926c30
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
Leo Vasanko
219dd70665
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-03 13:21:52 -06:00
Leo Vasanko
4306323c44
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-03 13:00:24 -06:00
Leo Vasanko
ceb99de738
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-03 12:30:23 -06:00
Leo Vasanko
1f75e0a305
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 11:17:02 -06:00
Leo Vasanko
7ace4dcb4b
Fix the back buttons (navigate back if you can but close if it was a new window).
2025-12-02 18:13:23 +00:00
Leo Vasanko
d1a7a53c19
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
2025-12-02 15:25:31 +00:00
Leo Vasanko
cb26c61d5f
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
Leo Vasanko
59e7e40128
Harmonise ProfileView and HostApp.
2025-10-04 18:14:17 -06:00
Leo Vasanko
29be642dbe
Better UX for profile view logout buttons.
2025-10-04 16:22:16 -06:00
Leo Vasanko
bfb11cc20f
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko
389e05730b
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 08:59:51 -06:00
Leo Vasanko
591ea626bf
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-03 18:31:54 -06:00
Leo Vasanko
5d8304bbd9
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko
ed7d3ee0fc
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-09-30 16:38:14 -06:00
Leo Vasanko
d46d50b91a
Massive style redesign, WIP.
2025-09-29 21:02:49 -06:00
Leo Vasanko
6439437e8b
Implement breadcrumb navigation.
2025-09-27 20:47:45 -06:00
Leo Vasanko
b324276173
Cleaned up login/logout flows.
2025-09-02 19:08:16 -06:00
Leo Vasanko
312d23b79a
Refactor API under /auth/api
2025-09-02 14:32:19 -06:00
Leo Vasanko
fd11cac4bc
Unify user info across admin app and profile view.
2025-09-01 19:56:18 -06:00
Leo Vasanko
357eb2b761
User name editing UI (hopefully fixed)
2025-09-01 18:59:39 -06:00
Leo Vasanko
6d6c4ee35d
User rename fixes.
2025-09-01 18:20:32 -06:00
Leo Vasanko
37eaffff3f
Renaming of users in registration, profile and admin app.
2025-09-01 18:13:01 -06:00
Leo Vasanko
efdfa77fc9
Basic navigation between auth and user pages.
2025-08-29 20:50:37 -06:00
Leo Vasanko
407994548a
Almost complete org/permission handling. Much cleanup, bootstrap works.
2025-08-07 13:58:12 -06:00
Leo Vasanko
f96668b135
Cleaner error message on aborted Passkey operations.
2025-08-06 12:00:23 -06:00
Leo Vasanko
3c6c9b29f6
Frontend component selection logic simplified.
2025-08-06 11:33:34 -06:00
Leo Vasanko
74ba443d3d
Avoid loading user info twice to show profile.
2025-08-06 10:57:41 -06:00
Leo Vasanko
8882d0672b
Frontend adjusted for the new API.
2025-08-01 13:16:10 -06:00
Leo Vasanko
19bcddca30
Refactor to get user info from a single endpoint
2025-07-14 12:30:10 -06:00