LeoVasanko
|
e102b8383b
|
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
|
2025-12-04 09:19:40 +00:00 |
|
LeoVasanko
|
5aa8d021e6
|
Brought examples directly to front page.
|
2025-12-04 08:19:32 +00:00 |
|
LeoVasanko
|
3d5b0aa4bf
|
Fix view switching of restricted app.
|
2025-12-04 07:46:36 +00:00 |
|
LeoVasanko
|
29df169a67
|
Make restricted app use simple fetch that doesn't do API authentication (recursively).
|
2025-12-04 06:20:14 +00:00 |
|
LeoVasanko
|
97dc459bfb
|
Fixed and simplified examples.
|
2025-12-04 06:08:52 +00:00 |
|
LeoVasanko
|
4d4b290cc8
|
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
|
2025-12-04 06:01:47 +00:00 |
|
LeoVasanko
|
0e1b9f529b
|
Log authentication options on the client.
|
2025-12-04 05:07:44 +00:00 |
|
LeoVasanko
|
0c3e0d3fa5
|
Improved dialog layout with separate mobile portrait mode.
|
2025-12-04 04:06:32 +00:00 |
|
LeoVasanko
|
1782547b9e
|
Fix infinitely nested login iframes when the restricted app notices it needs login.
|
2025-12-04 03:56:17 +00:00 |
|
LeoVasanko
|
9976e05696
|
Various fixes and cleanup, regressions from prior commits.
|
2025-12-04 03:40:59 +00:00 |
|
LeoVasanko
|
6124fa6c01
|
Fix syntax error in reset app created by earlier commit.
|
2025-12-04 02:31:13 +00:00 |
|
LeoVasanko
|
a6591a1fbb
|
Better static files handling on backend, when in dev mode: fetch from vite.
|
2025-12-04 02:30:02 +00:00 |
|
LeoVasanko
|
b9b1c995f9
|
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
|
2025-12-04 01:58:18 +00:00 |
|
LeoVasanko
|
4482a601f3
|
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
|
2025-12-04 01:35:44 +00:00 |
|
LeoVasanko
|
aa4b1bfd42
|
Viewing linked passkeys/sessions (by clicking either one of them).
|
2025-12-04 01:21:52 +00:00 |
|
LeoVasanko
|
2ecf8433a1
|
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
|
2025-12-04 01:00:24 +00:00 |
|
LeoVasanko
|
db892365dc
|
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
|
2025-12-04 00:29:42 +00:00 |
|
LeoVasanko
|
8d02c0f615
|
Formatting, tidy up, transparent auth dialog background.
|
2025-12-03 23:31:35 +00:00 |
|
LeoVasanko
|
469d606ce5
|
Improved apiFetch and jsonFetch functions.
|
2025-12-03 23:26:38 +00:00 |
|
LeoVasanko
|
547a6cd923
|
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
|
2025-12-03 23:17:02 +00:00 |
|
LeoVasanko
|
deabee3b5c
|
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
|
2025-12-03 22:58:48 +00:00 |
|
LeoVasanko
|
fd1aa11409
|
Add E2E tests to register and verify passkey.
|
2025-12-03 02:52:39 +00:00 |
|
LeoVasanko
|
ca1ea9d90b
|
Always use timezone aware UTC time.
|
2025-12-03 01:36:15 +00:00 |
|
LeoVasanko
|
2dac0be77a
|
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
|
2025-12-03 01:32:05 +00:00 |
|
LeoVasanko
|
f63c62d9ff
|
Implement session termination in admin API, for completeness.
|
2025-12-03 01:20:52 +00:00 |
|
LeoVasanko
|
768a4391cf
|
Improved profile view layout.
|
2025-12-03 01:03:25 +00:00 |
|
LeoVasanko
|
f64876e73b
|
Improved profile view layout.
|
2025-12-03 00:52:52 +00:00 |
|
LeoVasanko
|
b6a3cdd3a4
|
Fix examples folder serving broken a couple of commits ago.
|
2025-12-03 00:06:32 +00:00 |
|
LeoVasanko
|
fd9a5afc1c
|
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
|
2025-12-02 23:39:31 +00:00 |
|
LeoVasanko
|
8714fe9319
|
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
|
2025-12-02 22:41:12 +00:00 |
|
LeoVasanko
|
adbab88c86
|
Major refactor of frontend source tree such that paths better match where they are served.
|
2025-12-02 22:09:07 +00:00 |
|
LeoVasanko
|
5d9d2b794d
|
Refactor restricted app paths and naming.
|
2025-12-02 19:10:13 +00:00 |
|
LeoVasanko
|
eedbd4aaa4
|
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
|
2025-12-02 18:34:59 +00:00 |
|
LeoVasanko
|
15916047fa
|
Remove backend access control, now that the profile and admin apps handle that via API.
|
2025-12-02 18:25:58 +00:00 |
|
LeoVasanko
|
643d9bafab
|
Fix the back buttons (navigate back if you can but close if it was a new window).
|
2025-12-02 18:02:02 +00:00 |
|
LeoVasanko
|
2699aaa472
|
Implement Forbidden view for API calls, cleanup and better UX.
|
2025-12-02 17:36:37 +00:00 |
|
LeoVasanko
|
5422845192
|
Better error messages from backend, avoid bad toasts, cleanup of session validation.
|
2025-12-02 16:37:27 +00:00 |
|
LeoVasanko
|
c1ccb048f0
|
Update admin app authentication in API mode too, reusing components between it and the main app.
|
2025-12-02 15:42:55 +00:00 |
|
LeoVasanko
|
3030122807
|
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
|
2025-12-02 15:25:31 +00:00 |
|
LeoVasanko
|
d4f8e97469
|
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
|
2025-12-02 14:30:31 +00:00 |
|
LeoVasanko
|
a62e8ddf1e
|
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
|
2025-12-02 03:10:16 +00:00 |
|
LeoVasanko
|
2dca6b1eec
|
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/.
|
2025-12-01 20:07:26 +00:00 |
|
LeoVasanko
|
4f50974222
|
Updated build-frontend script, now uses deno, npm, bun in this order.
|
2025-12-01 19:25:08 +00:00 |
|
LeoVasanko
|
c218ddad61
|
Centralise all cookie handling to session.py.
v0.4.0
|
2025-10-05 06:48:24 +00:00 |
|
LeoVasanko
|
7247f7c584
|
Refactor /api/user/* to its own module.
|
2025-10-05 06:41:14 +00:00 |
|
LeoVasanko
|
af2834b4c0
|
Reset dialog UX improved.
|
2025-10-05 06:25:40 +00:00 |
|
LeoVasanko
|
ef66baff20
|
Harmonise ProfileView and HostApp.
|
2025-10-05 06:14:17 +00:00 |
|
LeoVasanko
|
08d4607d65
|
Tuning the host app.
|
2025-10-05 06:03:28 +00:00 |
|
LeoVasanko
|
1ca9e3ef58
|
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
|
2025-10-05 05:55:08 +00:00 |
|
LeoVasanko
|
575d3cb1fb
|
Deny creating sessions for hosts other than rp-id subdomains.
|
2025-10-05 05:26:03 +00:00 |
|