Commit Graph
72 Commits
Author SHA1 Message Date
LeoVasanko 8714fe9319 Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility. 2025-12-02 22:41:12 +00:00
LeoVasanko adbab88c86 Major refactor of frontend source tree such that paths better match where they are served. 2025-12-02 22:09:07 +00:00
LeoVasanko 5d9d2b794d Refactor restricted app paths and naming. 2025-12-02 19:10:13 +00:00
LeoVasanko eedbd4aaa4 Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app. 2025-12-02 18:34:59 +00:00
LeoVasanko 643d9bafab Fix the back buttons (navigate back if you can but close if it was a new window). 2025-12-02 18:02:02 +00:00
LeoVasanko 2699aaa472 Implement Forbidden view for API calls, cleanup and better UX. 2025-12-02 17:36:37 +00:00
LeoVasanko 5422845192 Better error messages from backend, avoid bad toasts, cleanup of session validation. 2025-12-02 16:37:27 +00:00
LeoVasanko c1ccb048f0 Update admin app authentication in API mode too, reusing components between it and the main app. 2025-12-02 15:42:55 +00:00
LeoVasanko 3030122807 Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages. 2025-12-02 15:25:31 +00:00
LeoVasanko a62e8ddf1e Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified. 2025-12-02 03:10:16 +00:00
LeoVasanko af2834b4c0 Reset dialog UX improved. 2025-10-05 06:25:40 +00:00
LeoVasanko ef66baff20 Harmonise ProfileView and HostApp. 2025-10-05 06:14:17 +00:00
LeoVasanko 08d4607d65 Tuning the host app. 2025-10-05 06:03:28 +00:00
LeoVasanko 1ca9e3ef58 Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose. 2025-10-05 05:55:08 +00:00
LeoVasanko eaa16abe2a Better UX for profile view logout buttons. 2025-10-05 04:22:16 +00:00
LeoVasanko 01bc39a0e8 A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko fa513940c7 Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 20:59:51 +00:00
LeoVasanko f24aaa295d More consistent shared styling between credential and session cards. 2025-10-04 20:32:27 +00:00
LeoVasanko 0af7aad28c Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-04 06:31:54 +00:00
LeoVasanko 2f1578c4bc Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko 2f77753354 Make the login/reset/forbidden dialogs look better. 2025-10-01 05:03:51 +00:00
LeoVasanko ea871635e0 Admin app: guard rails extended, consistent styling, also share styling with main app. 2025-10-01 04:38:14 +00:00
LeoVasanko c3e4c18d5c Remove duplicate message from permission denied page. 2025-10-01 00:56:41 +00:00
LeoVasanko a7c23b31e7 Admin app divided to separate components. 2025-10-01 00:54:18 +00:00
LeoVasanko 3f45024396 Massive style redesign, WIP. 2025-09-30 09:02:49 +00:00
LeoVasanko e130bc5c0a Clear sessionStorage on logout. 2025-09-29 07:45:37 +00:00
LeoVasanko 5ad3ccb5ae Implement breadcrumb navigation. 2025-09-28 08:47:45 +00:00
LeoVasanko f28e69a9ce Cleaner logout. 2025-09-03 07:11:25 +00:00
LeoVasanko 09b9894407 Cleaned up login/logout flows. 2025-09-03 07:08:16 +00:00
LeoVasanko 07212ee1de Major refactoring of admin API (permissions, paths) 2025-09-03 06:08:06 +00:00
LeoVasanko 6e5ea9eac0 Refactor API under /auth/api 2025-09-03 02:32:19 +00:00
LeoVasanko ed2b0f6f3c Remove icon, prefer automatic use of /favicon.ico of the host site. 2025-09-02 22:17:40 +00:00
LeoVasanko cf4835ff83 Redux 2025-09-02 08:21:20 +00:00
LeoVasanko 01251a4769 Support WS connections on older browsers. 2025-09-02 08:15:14 +00:00
LeoVasanko aed9835098 Better navigation on admin app. 2025-09-02 08:04:56 +00:00
LeoVasanko 54a0d84cb5 Smarter user info 2025-09-02 08:02:52 +00:00
LeoVasanko 70a7bc791f Fix previous 2025-09-02 07:58:48 +00:00
LeoVasanko a84556509a Unify user info across admin app and profile view. 2025-09-02 07:56:18 +00:00
LeoVasanko 2769d8c7f0 User name editing UI (hopefully fixed) 2025-09-02 06:59:39 +00:00
LeoVasanko a526344842 Use rp-name for frontend branding 2025-09-02 06:48:59 +00:00
LeoVasanko a1d5270dd7 User rename fixes. 2025-09-02 06:20:32 +00:00
LeoVasanko e1e933c756 Renaming of users in registration, profile and admin app. 2025-09-02 06:13:01 +00:00
LeoVasanko b9c1fe059c Crude dialog rather than prompt() for input fields. (needs cleanup) 2025-09-02 05:34:45 +00:00
LeoVasanko db19ff61f6 Only allow safe characters in permission IDs 2025-08-31 07:10:00 +00:00
LeoVasanko 24404738ab Formatting 2025-08-31 06:43:27 +00:00
LeoVasanko d7735675b7 Implement Permission Denied handling. 2025-08-31 06:38:48 +00:00
LeoVasanko ad4bde5d0d Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site). 2025-08-31 03:54:17 +00:00
LeoVasanko 54cef0f9d6 Fixing cascade. 2025-08-31 02:07:32 +00:00
LeoVasanko d229ed267c Actually usable admin panel 2025-08-30 10:38:22 +00:00
LeoVasanko 9402aae829 Almost usable admin panel 2025-08-30 09:54:51 +00:00