LeoVasanko
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
LeoVasanko
2dca6b1eec
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/ .
2025-12-01 20:07:26 +00:00
LeoVasanko
c218ddad61
Centralise all cookie handling to session.py.
2025-10-05 06:48:24 +00:00
LeoVasanko
7247f7c584
Refactor /api/user/* to its own module.
2025-10-05 06:41:14 +00:00
LeoVasanko
af2834b4c0
Reset dialog UX improved.
2025-10-05 06:25:40 +00:00
LeoVasanko
1ca9e3ef58
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-05 05:55:08 +00:00
LeoVasanko
575d3cb1fb
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-05 05:26:03 +00:00
LeoVasanko
a4ac19f54c
WebSockets must use origin for finding the host calling them.
2025-10-05 05:16:51 +00:00
LeoVasanko
11887d15b2
Correction on restricted path checking (auth-host).
2025-10-05 04:59:05 +00:00
LeoVasanko
cefb9c3d92
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-05 04:49:23 +00:00
LeoVasanko
5b9a3fc27f
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-05 04:35:55 +00:00
LeoVasanko
19a6c32cf2
Fix deletion of session cookie on host logout.
2025-10-05 04:26:36 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
43850c218f
Fix reset link logic to include /auth when no configured auth-host.
2025-10-03 03:57:20 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
b4871c671f
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-03 00:22:02 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
ec098b862c
Implement credential reset via CLI.
2025-09-27 05:18:33 +00:00
LeoVasanko
88275beb0f
Make the /auth/api/validate endpoint renew sessions if needed.
2025-09-27 04:59:11 +00:00
LeoVasanko
4315584589
Cleanup
2025-09-27 03:00:17 +00:00
LeoVasanko
ffbe8a6b18
Minor tuning of Caddy configuration and improved documentation.
2025-09-26 07:12:11 +00:00
LeoVasanko
39ba032450
Provide user info in Remote-* headers. Caddy configuration improved.
2025-09-26 06:12:40 +00:00
LeoVasanko
09b9894407
Cleaned up login/logout flows.
2025-09-03 07:08:16 +00:00
LeoVasanko
4052122d40
Fix url_for query arg on reset link redirect.
2025-09-03 06:32:56 +00:00
LeoVasanko
f0ff3cf977
Fix matching bug
2025-09-03 06:22:21 +00:00
LeoVasanko
07212ee1de
Major refactoring of admin API (permissions, paths)
2025-09-03 06:08:06 +00:00
LeoVasanko
340888a178
Refactoring permissions checks.
2025-09-03 05:28:26 +00:00
LeoVasanko
53f1745ebd
Utility module for accessing frontend in backend code.
2025-09-03 04:05:20 +00:00
LeoVasanko
42e0266cd6
Move forward auth under /admin/api/forward
2025-09-03 03:03:39 +00:00
LeoVasanko
5c5da10c8b
Moved exception handlers to sub apps.
2025-09-03 02:57:06 +00:00
LeoVasanko
0d725f85a5
Rename variable to silence linter
2025-09-03 02:45:23 +00:00
LeoVasanko
6e5ea9eac0
Refactor API under /auth/api
2025-09-03 02:32:19 +00:00
LeoVasanko
5281432c96
Restructure admin app separate of user api.
2025-09-03 02:04:52 +00:00
LeoVasanko
3547144313
Use bun --bun consistently, avoid devmode origin override if specified by args rp-id and/or origin.
2025-09-02 07:47:46 +00:00
LeoVasanko
a526344842
Use rp-name for frontend branding
2025-09-02 06:48:59 +00:00
LeoVasanko
93d722c4d2
Count registration also as a login.
2025-09-02 06:40:05 +00:00
LeoVasanko
b39eb59961
Linter
2025-09-02 06:29:38 +00:00
LeoVasanko
e1e933c756
Renaming of users in registration, profile and admin app.
2025-09-02 06:13:01 +00:00
LeoVasanko
db19ff61f6
Only allow safe characters in permission IDs
2025-08-31 07:10:00 +00:00
LeoVasanko
0e4e4f4cfa
Make default permissions use only : as separator.
2025-08-31 06:43:49 +00:00
LeoVasanko
c06b7ddf26
Allow specifying multiple permissions.
2025-08-31 04:47:38 +00:00
LeoVasanko
c67a83abdc
Add permission check on forward-auth and validate.
2025-08-31 04:13:54 +00:00
LeoVasanko
ad4bde5d0d
Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site).
2025-08-31 03:54:17 +00:00
LeoVasanko
54cef0f9d6
Fixing cascade.
2025-08-31 02:07:32 +00:00
LeoVasanko
d229ed267c
Actually usable admin panel
2025-08-30 10:38:22 +00:00
LeoVasanko
9402aae829
Almost usable admin panel
2025-08-30 09:54:51 +00:00
LeoVasanko
395ecdbd19
Major changes to server startup. Admin page tuning.
2025-08-30 08:41:38 +00:00
LeoVasanko
ff9bb1558d
Drafting admin app (frontend)
2025-08-13 03:24:27 +00:00