LeoVasanko
2cf8799c75
Missing new component.
2025-12-04 10:03:33 +00:00
LeoVasanko
e102b8383b
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
2025-12-04 09:19:40 +00:00
LeoVasanko
3d5b0aa4bf
Fix view switching of restricted app.
2025-12-04 07:46:36 +00:00
LeoVasanko
29df169a67
Make restricted app use simple fetch that doesn't do API authentication (recursively).
2025-12-04 06:20:14 +00:00
LeoVasanko
4d4b290cc8
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
2025-12-04 06:01:47 +00:00
LeoVasanko
0e1b9f529b
Log authentication options on the client.
2025-12-04 05:07:44 +00:00
LeoVasanko
0c3e0d3fa5
Improved dialog layout with separate mobile portrait mode.
2025-12-04 04:06:32 +00:00
LeoVasanko
1782547b9e
Fix infinitely nested login iframes when the restricted app notices it needs login.
2025-12-04 03:56:17 +00:00
LeoVasanko
9976e05696
Various fixes and cleanup, regressions from prior commits.
2025-12-04 03:40:59 +00:00
LeoVasanko
b9b1c995f9
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
2025-12-04 01:58:18 +00:00
LeoVasanko
4482a601f3
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
2025-12-04 01:35:44 +00:00
LeoVasanko
aa4b1bfd42
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-04 01:21:52 +00:00
LeoVasanko
2ecf8433a1
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-04 01:00:24 +00:00
LeoVasanko
db892365dc
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-04 00:29:42 +00:00
LeoVasanko
8d02c0f615
Formatting, tidy up, transparent auth dialog background.
2025-12-03 23:31:35 +00:00
LeoVasanko
469d606ce5
Improved apiFetch and jsonFetch functions.
2025-12-03 23:26:38 +00:00
LeoVasanko
547a6cd923
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 23:17:02 +00:00
LeoVasanko
2dac0be77a
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
2025-12-03 01:32:05 +00:00
LeoVasanko
f63c62d9ff
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
LeoVasanko
768a4391cf
Improved profile view layout.
2025-12-03 01:03:25 +00:00
LeoVasanko
f64876e73b
Improved profile view layout.
2025-12-03 00:52:52 +00:00
LeoVasanko
fd9a5afc1c
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00
LeoVasanko
adbab88c86
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
LeoVasanko
5d9d2b794d
Refactor restricted app paths and naming.
2025-12-02 19:10:13 +00:00
LeoVasanko
eedbd4aaa4
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
LeoVasanko
643d9bafab
Fix the back buttons (navigate back if you can but close if it was a new window).
2025-12-02 18:02:02 +00:00
LeoVasanko
2699aaa472
Implement Forbidden view for API calls, cleanup and better UX.
2025-12-02 17:36:37 +00:00
LeoVasanko
5422845192
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
LeoVasanko
c1ccb048f0
Update admin app authentication in API mode too, reusing components between it and the main app.
2025-12-02 15:42:55 +00:00
LeoVasanko
3030122807
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
2025-12-02 15:25:31 +00:00
LeoVasanko
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
LeoVasanko
af2834b4c0
Reset dialog UX improved.
2025-10-05 06:25:40 +00:00
LeoVasanko
ef66baff20
Harmonise ProfileView and HostApp.
2025-10-05 06:14:17 +00:00
LeoVasanko
08d4607d65
Tuning the host app.
2025-10-05 06:03:28 +00:00
LeoVasanko
1ca9e3ef58
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-05 05:55:08 +00:00
LeoVasanko
eaa16abe2a
Better UX for profile view logout buttons.
2025-10-05 04:22:16 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
f24aaa295d
More consistent shared styling between credential and session cards.
2025-10-04 20:32:27 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
2f77753354
Make the login/reset/forbidden dialogs look better.
2025-10-01 05:03:51 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
c3e4c18d5c
Remove duplicate message from permission denied page.
2025-10-01 00:56:41 +00:00
LeoVasanko
a7c23b31e7
Admin app divided to separate components.
2025-10-01 00:54:18 +00:00
LeoVasanko
3f45024396
Massive style redesign, WIP.
2025-09-30 09:02:49 +00:00
LeoVasanko
e130bc5c0a
Clear sessionStorage on logout.
2025-09-29 07:45:37 +00:00
LeoVasanko
5ad3ccb5ae
Implement breadcrumb navigation.
2025-09-28 08:47:45 +00:00
LeoVasanko
f28e69a9ce
Cleaner logout.
2025-09-03 07:11:25 +00:00
LeoVasanko
09b9894407
Cleaned up login/logout flows.
2025-09-03 07:08:16 +00:00