LeoVasanko
8d02c0f615
Formatting, tidy up, transparent auth dialog background.
2025-12-03 23:31:35 +00:00
LeoVasanko
547a6cd923
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 23:17:02 +00:00
LeoVasanko
deabee3b5c
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
2025-12-03 22:58:48 +00:00
LeoVasanko
ca1ea9d90b
Always use timezone aware UTC time.
2025-12-03 01:36:15 +00:00
LeoVasanko
f63c62d9ff
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
LeoVasanko
768a4391cf
Improved profile view layout.
2025-12-03 01:03:25 +00:00
LeoVasanko
fd9a5afc1c
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00
LeoVasanko
8714fe9319
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
2025-12-02 22:41:12 +00:00
LeoVasanko
adbab88c86
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
LeoVasanko
5d9d2b794d
Refactor restricted app paths and naming.
2025-12-02 19:10:13 +00:00
LeoVasanko
eedbd4aaa4
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
LeoVasanko
15916047fa
Remove backend access control, now that the profile and admin apps handle that via API.
2025-12-02 18:25:58 +00:00
LeoVasanko
5422845192
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
LeoVasanko
d4f8e97469
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
2025-12-02 14:30:31 +00:00
LeoVasanko
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
LeoVasanko
2dca6b1eec
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/ .
2025-12-01 20:07:26 +00:00
LeoVasanko
c218ddad61
Centralise all cookie handling to session.py.
2025-10-05 06:48:24 +00:00
LeoVasanko
7247f7c584
Refactor /api/user/* to its own module.
2025-10-05 06:41:14 +00:00
LeoVasanko
af2834b4c0
Reset dialog UX improved.
2025-10-05 06:25:40 +00:00
LeoVasanko
1ca9e3ef58
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-05 05:55:08 +00:00
LeoVasanko
575d3cb1fb
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-05 05:26:03 +00:00
LeoVasanko
a4ac19f54c
WebSockets must use origin for finding the host calling them.
2025-10-05 05:16:51 +00:00
LeoVasanko
11887d15b2
Correction on restricted path checking (auth-host).
2025-10-05 04:59:05 +00:00
LeoVasanko
cefb9c3d92
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-05 04:49:23 +00:00
LeoVasanko
5b9a3fc27f
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-05 04:35:55 +00:00
LeoVasanko
19a6c32cf2
Fix deletion of session cookie on host logout.
2025-10-05 04:26:36 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
43850c218f
Fix reset link logic to include /auth when no configured auth-host.
2025-10-03 03:57:20 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
b4871c671f
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-03 00:22:02 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
ec098b862c
Implement credential reset via CLI.
2025-09-27 05:18:33 +00:00
LeoVasanko
88275beb0f
Make the /auth/api/validate endpoint renew sessions if needed.
2025-09-27 04:59:11 +00:00
LeoVasanko
4315584589
Cleanup
2025-09-27 03:00:17 +00:00
LeoVasanko
ffbe8a6b18
Minor tuning of Caddy configuration and improved documentation.
2025-09-26 07:12:11 +00:00
LeoVasanko
39ba032450
Provide user info in Remote-* headers. Caddy configuration improved.
2025-09-26 06:12:40 +00:00
LeoVasanko
09b9894407
Cleaned up login/logout flows.
2025-09-03 07:08:16 +00:00
LeoVasanko
4052122d40
Fix url_for query arg on reset link redirect.
2025-09-03 06:32:56 +00:00
LeoVasanko
f0ff3cf977
Fix matching bug
2025-09-03 06:22:21 +00:00
LeoVasanko
07212ee1de
Major refactoring of admin API (permissions, paths)
2025-09-03 06:08:06 +00:00
LeoVasanko
340888a178
Refactoring permissions checks.
2025-09-03 05:28:26 +00:00
LeoVasanko
53f1745ebd
Utility module for accessing frontend in backend code.
2025-09-03 04:05:20 +00:00
LeoVasanko
42e0266cd6
Move forward auth under /admin/api/forward
2025-09-03 03:03:39 +00:00
LeoVasanko
5c5da10c8b
Moved exception handlers to sub apps.
2025-09-03 02:57:06 +00:00
LeoVasanko
0d725f85a5
Rename variable to silence linter
2025-09-03 02:45:23 +00:00
LeoVasanko
6e5ea9eac0
Refactor API under /auth/api
2025-09-03 02:32:19 +00:00
LeoVasanko
5281432c96
Restructure admin app separate of user api.
2025-09-03 02:04:52 +00:00
LeoVasanko
3547144313
Use bun --bun consistently, avoid devmode origin override if specified by args rp-id and/or origin.
2025-09-02 07:47:46 +00:00