LeoVasanko
84985501f5
MultiSite: one instance serves authentication across many domains ( #4 )
...
- Serve multiple domains (RP IDs) from one instance: host-based dispatch,
per-domain credentials and sessions, domains managed at runtime in the
admin UI — previously one RP per instance
- Cross-domain sign-in via Related Origin Requests: per-domain related-origins
list with a served .well-known/webauthn document
- Explicit per-domain origin lists with shell-glob wildcards (**. for apex +
any subdomain depth, *. for one level), editable in the admin UI with
validation and self-lockout guards
- Per-domain auth hosts: the account/admin UI can live on a different host
per domain, no longer confined to subdomains of a single RP
- CLI: 'paskia init <rp-id [rp-name]' initializes or adds a domain to an
existing database; 'paskia migrate' converts legacy databases
BREAKING CHANGES (v2.0):
- Database schema: config is now per-domain and credentials/sessions carry
an rp_id — existing databases must be converted with 'paskia migrate'
- Origins are now explicit: main implicitly allowed every subdomain of the
RP; configure '**.' origins to reproduce that behavior
- CLI: the flat '--rp-id/--rp-name/--origin/--auth/--save' flags are
replaced by the 'init' and 'migrate' subcommandsReviewed-on: #4
2026-09-07 22:14:42 +00:00
LeoVasanko
95c163e37a
Add profile picture support
...
- backend avatar storage and OIDC picture claims
- profile and admin UI components
- admin org cards, tests, and docs
2026-05-21 23:57:48 +00:00
LeoVasanko
232d0e1ae0
Added configurable timeout settings to paskia-js, used in our frontend as well. The default fetch timeout has been changed to 10s from prior 1s, but we maintain 1s for auth endpoints in internal use.
2026-04-29 20:23:38 +00:00
LeoVasanko
6257071efe
Cleaned Org Admin styling.
2026-02-19 00:37:44 +00:00
LeoVasanko
f26ac8f33b
Simplified My Profile authentication flows, fixed some UX issues with reauth cancelled/accepted leading to incorrect states.
2026-02-18 19:04:02 +00:00
LeoVasanko
880ced3b8c
Always load user's theme from API if available, and update the localStorage cache. Previously in various situations the old cached value was being used instead, leading to inconsistent theming or wrong themeselector readout.
2026-02-18 18:35:41 +00:00
LeoVasanko
fa1e69d58b
Imports to top of file.
2026-02-18 17:47:57 +00:00
LeoVasanko
49119fac81
Fix HostProfile user properties access.
2026-02-18 03:47:08 +00:00
LeoVasanko
68dccc1378
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko
f830d7d0ec
More minimalistic light theme. UI hint for org admin user/role management.
2026-02-14 18:36:20 +00:00
LeoVasanko
c1f8020f6b
API cleanup, using msgspec structs rather than raw responses. Admin app cleanup, better breadcrumbs.
2026-02-13 20:09:41 +00:00
LeoVasanko
fc0541762e
Add version indication and link to our site on profile page (bottom right corner).
2026-02-11 01:36:58 +00:00
LeoVasanko
cebaa2a757
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
2026-02-11 01:24:15 +00:00
LeoVasanko
4ebe5ae968
Style overhaul.
2026-02-11 01:18:19 +00:00
LeoVasanko
70c682b539
Improved client IP and UA handling.
2026-02-05 17:33:08 +00:00
LeoVasanko
8444d0399e
Improved theme picker
2026-02-05 16:19:06 +00:00
LeoVasanko
291a665e21
Improved UI feedback on registration link creation.
2026-02-05 14:26:11 +00:00
LeoVasanko
1800dc12ae
Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins).
2026-01-30 23:31:06 +00:00
LeoVasanko
7e49ef296a
Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced).
2026-01-29 19:46:26 +00:00
LeoVasanko
433844cf08
Refactor to separate paskia lib functionality generally useful for various apps.
2026-01-29 16:55:46 +00:00
LeoVasanko
c9ea1c8948
Consistent and stronger session revalidation checks in Auth profile and Admin App. Fix missing handling of link generation network errors.
2026-01-29 16:02:29 +00:00
LeoVasanko
cb84a81a06
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
LeoVasanko
7e568dbd10
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
LeoVasanko
c13044c085
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
851b17f45c
Adopt <dialog> for our modals to tap into browser built-in functionality.
2025-12-10 19:41:55 +00:00
LeoVasanko
720d875eb5
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
LeoVasanko
9930608359
Improved breadcrumbs on auth host.
2025-12-10 18:20:37 +00:00
LeoVasanko
3f0de04a49
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
LeoVasanko
cff62a1904
Fix mobile browser code word autocomplete (on space that wasn't detected correctly).
2025-12-10 16:40:58 +00:00
LeoVasanko
8bb00f01c4
Simplify responsive layouts. Remove button vertical stacking and always fit them on the same row.
2025-12-10 16:11:43 +00:00
LeoVasanko
ca73febe2f
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
2025-12-10 15:43:40 +00:00
LeoVasanko
f6c315d0dc
Improved session group (per site) styling and UX.
2025-12-10 01:11:43 +00:00
LeoVasanko
504e1d0fc5
Consistent use of red X only for deletion, and using only it for deletion rather than trashbin, while using non-red X for window close button.
2025-12-10 00:06:34 +00:00
LeoVasanko
a8269df0b4
Cleaner up registration link creation. Don't show the dialog until when there is a valid link. Implement a global blur backdrop with nicer effect and proper scrollbar handling (avoiding layout shifting a bit). Use the global backdrop to ensure consistent visuals between authentication and the modal being shown, along with in/out transitions.
2025-12-09 23:58:04 +00:00
LeoVasanko
d58a88c43a
Code word input overhaul, more accurate cursor and selection processing. New styling for the widget that conforms with browser default style (focus outline).
2025-12-09 23:07:15 +00:00
LeoVasanko
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
LeoVasanko
9b491164fd
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
LeoVasanko
bb34e52997
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
LeoVasanko
b9897b62b8
Remove trash bin icons from tab order. Instead, implement Delete key support (Backspace accepted on Apple devices).
2025-12-09 16:54:46 +00:00
LeoVasanko
8a21edf367
Process IPv6 display into short format including only the network prefix, and sharing the same code also for comparisons where needed.
2025-12-09 16:33:16 +00:00
LeoVasanko
03368b1b84
Rename base64 functions such that imports don't need renaming.
2025-12-09 15:55:03 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
2cf8799c75
Missing new component.
2025-12-04 10:03:33 +00:00
LeoVasanko
3d5b0aa4bf
Fix view switching of restricted app.
2025-12-04 07:46:36 +00:00
LeoVasanko
29df169a67
Make restricted app use simple fetch that doesn't do API authentication (recursively).
2025-12-04 06:20:14 +00:00
LeoVasanko
9976e05696
Various fixes and cleanup, regressions from prior commits.
2025-12-04 03:40:59 +00:00
LeoVasanko
aa4b1bfd42
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-04 01:21:52 +00:00
LeoVasanko
2ecf8433a1
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-04 01:00:24 +00:00
LeoVasanko
db892365dc
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-04 00:29:42 +00:00