Leo Vasanko
9d7ace8fb5
Refactor dev mode into a source repo script (remove dev subcommand from package).
2025-12-05 13:08:44 +00:00
Leo Vasanko
8011a0d910
Make dev mode run without static files, only serving assets in production.
2025-12-03 22:15:26 -06:00
Leo Vasanko
18eed4654f
Integrate host app to main app (WIP).
2025-12-03 22:00:47 -06:00
Leo Vasanko
afbd9606db
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
2025-12-03 18:01:47 -06:00
Leo Vasanko
7a70c933c9
Various fixes and cleanup, regressions from prior commits.
2025-12-03 15:40:59 -06:00
Leo Vasanko
ad63d3fb3a
Better static files handling on backend, when in dev mode: fetch from vite.
2025-12-03 14:30:02 -06:00
Leo Vasanko
9488f69e53
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
2025-12-03 13:58:18 -06:00
Leo Vasanko
219dd70665
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-03 13:21:52 -06:00
Leo Vasanko
ceb99de738
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-03 12:30:23 -06:00
Leo Vasanko
ad374f5dda
Formatting, tidy up, transparent auth dialog background.
2025-12-03 11:33:24 -06:00
Leo Vasanko
1f75e0a305
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 11:17:02 -06:00
Leo Vasanko
7b0a9c2a2a
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
2025-12-03 10:58:48 -06:00
Leo Vasanko
6003189da2
Always use timezone aware UTC time.
2025-12-03 01:36:15 +00:00
Leo Vasanko
bd13dbd1a0
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
Leo Vasanko
ca8d65ad25
Improved profile view layout.
2025-12-03 01:04:07 +00:00
Leo Vasanko
10ce0126b0
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00
Leo Vasanko
aed48de38e
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
2025-12-02 22:41:12 +00:00
Leo Vasanko
c83450dace
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
Leo Vasanko
123a62549b
Refactor restricted app paths and naming.
2025-12-02 19:10:13 +00:00
Leo Vasanko
2a5f06d707
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
Leo Vasanko
3441a7a2b3
Remove backend access control, now that the profile and admin apps handle that via API.
2025-12-02 18:25:58 +00:00
Leo Vasanko
a05d4aec81
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
Leo Vasanko
2c777661b8
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
2025-12-02 14:30:31 +00:00
Leo Vasanko
cb26c61d5f
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
Leo Vasanko
74a7723300
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/ .
2025-12-01 20:07:26 +00:00
Leo Vasanko
07525b47ae
Centralise all cookie handling to session.py.
2025-10-04 18:48:24 -06:00
Leo Vasanko
1ad1644b64
Refactor /api/user/* to its own module.
2025-10-04 18:41:35 -06:00
Leo Vasanko
876215f1c1
Reset dialog UX improved.
2025-10-04 18:40:46 -06:00
Leo Vasanko
94efb00e34
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-04 17:55:08 -06:00
Leo Vasanko
f9f4d59c6b
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-04 17:26:03 -06:00
Leo Vasanko
45f9870d0d
WebSockets must use origin for finding the host calling them.
2025-10-04 17:16:51 -06:00
Leo Vasanko
2a81544701
Correction on restricted path checking (auth-host).
2025-10-04 16:59:05 -06:00
Leo Vasanko
a60c1bd5f5
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-04 16:49:23 -06:00
Leo Vasanko
229f066533
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-04 16:35:55 -06:00
Leo Vasanko
97f653e116
Fix deletion of session cookie on host logout.
2025-10-04 16:26:36 -06:00
Leo Vasanko
bfb11cc20f
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko
389e05730b
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 08:59:51 -06:00
Leo Vasanko
591ea626bf
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-03 18:31:54 -06:00
Leo Vasanko
bb35e57ba4
Fix reset link logic to include /auth when no configured auth-host.
2025-10-02 15:57:20 -06:00
Leo Vasanko
5d8304bbd9
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko
fbfd0bbb47
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-02 12:30:50 -06:00
Leo Vasanko
ed7d3ee0fc
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-09-30 16:38:14 -06:00
Leo Vasanko
654618883d
Implement credential reset via CLI.
2025-09-26 17:18:49 -06:00
Leo Vasanko
8409c7726c
Make the /auth/api/validate endpoint renew sessions if needed.
2025-09-26 16:59:11 -06:00
Leo Vasanko
21a6bfd8ba
Cleanup
2025-09-26 15:00:17 -06:00
Leo Vasanko
eaca57f625
Minor tuning of Caddy configuration and improved documentation.
2025-09-25 19:12:11 -06:00
Leo Vasanko
e514ae010d
Provide user info in Remote-* headers. Caddy configuration improved.
2025-09-25 18:12:40 -06:00
Leo Vasanko
b324276173
Cleaned up login/logout flows.
2025-09-02 19:08:16 -06:00
Leo Vasanko
10e55f63b5
Fix url_for query arg on reset link redirect.
2025-09-02 18:32:56 -06:00
Leo Vasanko
074daebd14
Fix matching bug
2025-09-02 18:22:21 -06:00