Commit Graph
65 Commits
Author SHA1 Message Date
Leo Vasanko a54d872b46 Various improvements to remote link login. PoW algorithm tuned. Added base64url and helper modules. 2025-12-07 20:12:38 +00:00
Leo Vasanko 4bb64863f9 Proper PoW, unified verification WS etc 2025-12-07 04:12:11 +00:00
Leo Vasanko 9485cbd201 Drafting autocomplete for the words. Don't check for malformed words 2025-12-07 00:37:40 +00:00
Leo Vasanko dd49907c8d Moved remote-link links to same location with reset links, avoiding vite routing issue. Realtime lookup of session when three words have been entered. 2025-12-07 00:15:56 +00:00
Leo Vasanko 4da1127976 Drafting remote auth linking. 2025-12-06 16:43:47 +00:00
Leo Vasanko 5c72777c2f Missing new component. 2025-12-03 22:03:33 -06:00
Leo Vasanko bc4254ad18 Fix view switching of restricted app. 2025-12-03 19:46:36 -06:00
Leo Vasanko d541377798 Make restricted app use simple fetch that doesn't do API authentication (recursively). 2025-12-03 18:20:14 -06:00
Leo Vasanko 7a70c933c9 Various fixes and cleanup, regressions from prior commits. 2025-12-03 15:40:59 -06:00
Leo Vasanko 219dd70665 Viewing linked passkeys/sessions (by clicking either one of them). 2025-12-03 13:21:52 -06:00
Leo Vasanko 4306323c44 Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication). 2025-12-03 13:00:24 -06:00
Leo Vasanko ceb99de738 Improved auth profile UX, consistent transparent-blur dialog background everywhere. 2025-12-03 12:30:23 -06:00
Leo Vasanko ad374f5dda Formatting, tidy up, transparent auth dialog background. 2025-12-03 11:33:24 -06:00
Leo Vasanko 1f75e0a305 Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata. 2025-12-03 11:17:02 -06:00
Leo Vasanko 2e9895443b Improved session list IP handling. Hovering sessions shows Same IP on matching sessions. 2025-12-03 01:32:05 +00:00
Leo Vasanko bd13dbd1a0 Implement session termination in admin API, for completeness. 2025-12-03 01:20:52 +00:00
Leo Vasanko 70411fa77b Improved profile view layout. 2025-12-03 00:52:52 +00:00
Leo Vasanko 10ce0126b0 Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement. 2025-12-02 23:39:31 +00:00
Leo Vasanko c83450dace Major refactor of frontend source tree such that paths better match where they are served. 2025-12-02 22:09:07 +00:00
Leo Vasanko 7ace4dcb4b Fix the back buttons (navigate back if you can but close if it was a new window). 2025-12-02 18:13:23 +00:00
Leo Vasanko 6f9f4aefc1 Implement Forbidden view for API calls, cleanup and better UX. 2025-12-02 17:36:37 +00:00
Leo Vasanko a05d4aec81 Better error messages from backend, avoid bad toasts, cleanup of session validation. 2025-12-02 16:37:27 +00:00
Leo Vasanko 77d8e97dc9 Update admin app authentication in API mode too, reusing components between it and the main app. 2025-12-02 15:42:55 +00:00
Leo Vasanko d1a7a53c19 Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages. 2025-12-02 15:25:31 +00:00
Leo Vasanko cb26c61d5f Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified. 2025-12-02 03:10:16 +00:00
Leo Vasanko 59e7e40128 Harmonise ProfileView and HostApp. 2025-10-04 18:14:17 -06:00
Leo Vasanko 29be642dbe Better UX for profile view logout buttons. 2025-10-04 16:22:16 -06:00
Leo Vasanko bfb11cc20f A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko 389e05730b Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 08:59:51 -06:00
Leo Vasanko 79b6c50a9c More consistent shared styling between credential and session cards. 2025-10-04 08:32:27 -06:00
Leo Vasanko 591ea626bf Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-03 18:31:54 -06:00
Leo Vasanko 5d8304bbd9 Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko 382341e5ee Make the login/reset/forbidden dialogs look better. 2025-09-30 17:03:51 -06:00
Leo Vasanko ed7d3ee0fc Admin app: guard rails extended, consistent styling, also share styling with main app. 2025-09-30 16:38:14 -06:00
Leo Vasanko 3dff459068 Remove duplicate message from permission denied page. 2025-09-30 12:56:41 -06:00
Leo Vasanko d46d50b91a Massive style redesign, WIP. 2025-09-29 21:02:49 -06:00
Leo Vasanko 6439437e8b Implement breadcrumb navigation. 2025-09-27 20:47:45 -06:00
Leo Vasanko b324276173 Cleaned up login/logout flows. 2025-09-02 19:08:16 -06:00
Leo Vasanko 312d23b79a Refactor API under /auth/api 2025-09-02 14:32:19 -06:00
Leo Vasanko 5a9bee9a1d Smarter user info 2025-09-01 20:02:52 -06:00
Leo Vasanko 19b5ce6464 Fix previous 2025-09-01 19:58:48 -06:00
Leo Vasanko fd11cac4bc Unify user info across admin app and profile view. 2025-09-01 19:56:18 -06:00
Leo Vasanko 357eb2b761 User name editing UI (hopefully fixed) 2025-09-01 18:59:39 -06:00
Leo Vasanko 7036338b33 Use rp-name for frontend branding 2025-09-01 18:48:59 -06:00
Leo Vasanko 6d6c4ee35d User rename fixes. 2025-09-01 18:20:32 -06:00
Leo Vasanko 37eaffff3f Renaming of users in registration, profile and admin app. 2025-09-01 18:13:01 -06:00
Leo Vasanko 4a0fbd8199 Implement Permission Denied handling. 2025-08-30 18:38:48 -06:00
Leo Vasanko 3e5c0065d5 Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site). 2025-08-30 15:54:17 -06:00
Leo Vasanko 4db7f2e9a6 Almost usable admin panel 2025-08-29 21:54:51 -06:00
Leo Vasanko efdfa77fc9 Basic navigation between auth and user pages. 2025-08-29 20:50:37 -06:00