Commit Graph
50 Commits
Author SHA1 Message Date
LeoVasanko a6591a1fbb Better static files handling on backend, when in dev mode: fetch from vite. 2025-12-04 02:30:02 +00:00
LeoVasanko b9b1c995f9 Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode). 2025-12-04 01:58:18 +00:00
LeoVasanko 547a6cd923 Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata. 2025-12-03 23:17:02 +00:00
LeoVasanko ca1ea9d90b Always use timezone aware UTC time. 2025-12-03 01:36:15 +00:00
LeoVasanko fd9a5afc1c Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement. 2025-12-02 23:39:31 +00:00
LeoVasanko adbab88c86 Major refactor of frontend source tree such that paths better match where they are served. 2025-12-02 22:09:07 +00:00
LeoVasanko 5d9d2b794d Refactor restricted app paths and naming. 2025-12-02 19:10:13 +00:00
LeoVasanko eedbd4aaa4 Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app. 2025-12-02 18:34:59 +00:00
LeoVasanko d4f8e97469 Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI. 2025-12-02 14:30:31 +00:00
LeoVasanko c218ddad61 Centralise all cookie handling to session.py. 2025-10-05 06:48:24 +00:00
LeoVasanko 7247f7c584 Refactor /api/user/* to its own module. 2025-10-05 06:41:14 +00:00
LeoVasanko 19a6c32cf2 Fix deletion of session cookie on host logout. 2025-10-05 04:26:36 +00:00
LeoVasanko 01bc39a0e8 A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko fa513940c7 Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 20:59:51 +00:00
LeoVasanko 0af7aad28c Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-04 06:31:54 +00:00
LeoVasanko 43850c218f Fix reset link logic to include /auth when no configured auth-host. 2025-10-03 03:57:20 +00:00
LeoVasanko 2f1578c4bc Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko b4871c671f Create registration links on the same host (subdomain) that is being used by the one who creates it. 2025-10-03 00:22:02 +00:00
LeoVasanko ea871635e0 Admin app: guard rails extended, consistent styling, also share styling with main app. 2025-10-01 04:38:14 +00:00
LeoVasanko 88275beb0f Make the /auth/api/validate endpoint renew sessions if needed. 2025-09-27 04:59:11 +00:00
LeoVasanko 4315584589 Cleanup 2025-09-27 03:00:17 +00:00
LeoVasanko ffbe8a6b18 Minor tuning of Caddy configuration and improved documentation. 2025-09-26 07:12:11 +00:00
LeoVasanko 39ba032450 Provide user info in Remote-* headers. Caddy configuration improved. 2025-09-26 06:12:40 +00:00
LeoVasanko 340888a178 Refactoring permissions checks. 2025-09-03 05:28:26 +00:00
LeoVasanko 42e0266cd6 Move forward auth under /admin/api/forward 2025-09-03 03:03:39 +00:00
LeoVasanko 5c5da10c8b Moved exception handlers to sub apps. 2025-09-03 02:57:06 +00:00
LeoVasanko 6e5ea9eac0 Refactor API under /auth/api 2025-09-03 02:32:19 +00:00
LeoVasanko 5281432c96 Restructure admin app separate of user api. 2025-09-03 02:04:52 +00:00
LeoVasanko a526344842 Use rp-name for frontend branding 2025-09-02 06:48:59 +00:00
LeoVasanko e1e933c756 Renaming of users in registration, profile and admin app. 2025-09-02 06:13:01 +00:00
LeoVasanko db19ff61f6 Only allow safe characters in permission IDs 2025-08-31 07:10:00 +00:00
LeoVasanko 0e4e4f4cfa Make default permissions use only : as separator. 2025-08-31 06:43:49 +00:00
LeoVasanko c06b7ddf26 Allow specifying multiple permissions. 2025-08-31 04:47:38 +00:00
LeoVasanko c67a83abdc Add permission check on forward-auth and validate. 2025-08-31 04:13:54 +00:00
LeoVasanko ad4bde5d0d Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site). 2025-08-31 03:54:17 +00:00
LeoVasanko 54cef0f9d6 Fixing cascade. 2025-08-31 02:07:32 +00:00
LeoVasanko d229ed267c Actually usable admin panel 2025-08-30 10:38:22 +00:00
LeoVasanko 9402aae829 Almost usable admin panel 2025-08-30 09:54:51 +00:00
LeoVasanko 395ecdbd19 Major changes to server startup. Admin page tuning. 2025-08-30 08:41:38 +00:00
LeoVasanko ee3708105b Support for adding permissions on roles and orgs. 2025-08-13 03:13:35 +00:00
LeoVasanko df377c4a14 Globals restructured to their own module. Origin and RP definition. 2025-08-07 01:23:35 +00:00
LeoVasanko 5a55417dad Centralised error handling & convenience. 2025-08-06 22:44:57 +00:00
LeoVasanko b255362946 Refactor to not use status: success, but HTTP codes, and renamed the error key to detail to match FastAPI's own. 2025-08-06 22:09:55 +00:00
LeoVasanko c8bb2ab12e Checkpoint, fixing reset token handling broken in earlier edits. 2025-08-06 21:55:14 +00:00
LeoVasanko a4101e708a Separated session management from its FastAPI-dependent parts, creating authsession.py on main level.
Startup/main/scripts cleanup, now runs with passkey-auth command that takes CLI arguments.
2025-08-05 21:02:49 +00:00
LeoVasanko 9d0c97f403 Finish DB cleanup/refactoring. Working now. 2025-08-05 20:26:35 +00:00
LeoVasanko af8dea1a02 Database cleanup, base class, separated from FastAPI app. 2025-08-05 19:55:31 +00:00
LeoVasanko 71db80c7ea Everything works. Minor adjustments on frontend and backend for the new API. 2025-08-02 19:41:42 +00:00
LeoVasanko 9b82f77729 Major cleanup and refactoring of the backend (frontend not fully updated). 2025-08-02 00:32:27 +00:00
LeoVasanko fb898193e2 Late night hacking...? 2025-07-15 05:45:01 +00:00