Leo Vasanko
|
a67fd77a32
|
Note: icon optional
|
2026-02-17 15:34:01 +00:00 |
|
Leo Vasanko
|
fa53ba11f8
|
More robust/correct discovery and icon URL handling.
|
2026-02-17 15:30:39 +00:00 |
|
Leo Vasanko
|
239b9b436b
|
Only use transparent background on the iframe. Restores default canvas color on forwarded and oidc where no original page exists behind.
|
2026-02-17 15:06:40 +00:00 |
|
Leo Vasanko
|
28f231da8e
|
Suggest icon URL for OIDC.
|
2026-02-17 14:56:24 +00:00 |
|
Leo Vasanko
|
3a05120d06
|
Consistent OIDC layout, admin app spacing. UX tuneup.
|
2026-02-17 14:13:03 +00:00 |
|
Leo Vasanko
|
7c75947662
|
Admin OIDC cleanup.
|
2026-02-17 13:36:46 +00:00 |
|
Leo Vasanko
|
8c88e6e37c
|
Vite dev proxy ./well-known/openid-configuration
|
2026-02-17 13:34:30 +00:00 |
|
Leo Vasanko
|
d526b2a98d
|
Group OIDC sessions correctly in profile view.
|
2026-02-17 12:27:57 +00:00 |
|
Leo Vasanko
|
7523a49543
|
Add preferred username and email to user data.
|
2026-02-17 12:07:25 +00:00 |
|
Leo Vasanko
|
627912fae5
|
Fix tests for earlier changes.
|
2026-02-17 01:35:11 +00:00 |
|
Leo Vasanko
|
f8c213c7dc
|
Implement backchannel logout to client.
|
2026-02-17 01:31:45 +00:00 |
|
Leo Vasanko
|
b5e308d5df
|
OIDC authentication works, remove debug.
|
2026-02-17 01:09:16 +00:00 |
|
Leo Vasanko
|
ba3695cf88
|
Aud problem debug.
|
2026-02-17 00:20:53 +00:00 |
|
Leo Vasanko
|
2e8439f876
|
Issuer problem debug.
|
2026-02-17 00:19:04 +00:00 |
|
Leo Vasanko
|
d0abd224f4
|
Issuer problem debug.
|
2026-02-17 00:17:47 +00:00 |
|
Leo Vasanko
|
5bc92ce983
|
Issuer problem debug.
|
2026-02-17 00:16:10 +00:00 |
|
Leo Vasanko
|
5019cd13fe
|
Fix again, didn't work
|
2026-02-17 00:07:26 +00:00 |
|
Leo Vasanko
|
72307fb7c3
|
Fix again, didn't work
|
2026-02-17 00:05:22 +00:00 |
|
Leo Vasanko
|
21d1e123f5
|
Fix FastAPI token grant_type validation error when missing and form was sent by client.
|
2026-02-17 00:00:51 +00:00 |
|
Leo Vasanko
|
fee833b908
|
Made PKCE and nonce optional, only when client wants them.
|
2026-02-16 23:55:42 +00:00 |
|
Leo Vasanko
|
ce68af5be3
|
Correct OIDC mode handling in restricted app.
|
2026-02-16 23:38:23 +00:00 |
|
Leo Vasanko
|
bcecb390e1
|
Fix registration broken from earlier hardening. Streamline authentication and registration to avoid duplication of this.
|
2026-02-16 21:26:24 +00:00 |
|
Leo Vasanko
|
2a318adab4
|
Add back missing ResetToken.delete() lost on earlier refactoring.
|
2026-02-16 20:53:07 +00:00 |
|
Leo Vasanko
|
30aeb9a310
|
Admin OIDC Client editing moved to its own page.
|
2026-02-16 20:32:55 +00:00 |
|
Leo Vasanko
|
09049d3094
|
Implement redirect URL autodiscovery (Trust On First Use - if none are manually defined).
|
2026-02-16 20:32:11 +00:00 |
|
Leo Vasanko
|
0081cc835b
|
[paskia-js] Inject styles when backdrop is needed for non-auth dialogs.
|
2026-02-16 19:16:09 +00:00 |
|
Leo Vasanko
|
e7e0097fba
|
User friendly admin app OIDC Client dialog. Permissions domain scoping to OIDC Clients.
|
2026-02-16 17:43:52 +00:00 |
|
Leo Vasanko
|
b73b2d6fe9
|
Renamed OIDC permissions claim to more commonly used groups. Move jwtk to a more convenient location. Draft admin app OIDC client configuratioon.
|
2026-02-16 16:54:53 +00:00 |
|
Leo Vasanko
|
eece6d4a21
|
Remove some confusion between exchange and set-session endpoints, all using set-session now with a bearer code. Using codes in remote auth as well. Full separation of cookie and OIDC codes.
|
2026-02-16 14:26:20 +00:00 |
|
Leo Vasanko
|
ebf5f6db2c
|
Route our new restricted endpoints correctly on vite dev.
|
2026-02-16 14:23:07 +00:00 |
|
Leo Vasanko
|
d653a1db35
|
Database migration to add OIDC and convert to hardened sessions.
|
2026-02-15 21:12:29 +00:00 |
|
Leo Vasanko
|
feeea30cb6
|
Hardening OIDC verification.
|
2026-02-15 20:49:13 +00:00 |
|
Leo Vasanko
|
e59852b44c
|
Session keys hardened (namespaced hashes of tokens). Various cleanup.
|
2026-02-15 20:14:48 +00:00 |
|
Leo Vasanko
|
18722f0e01
|
Implement stateful OIDC as Session objects. Add refresh tokens and backchannel logout.
|
2026-02-15 03:48:10 +00:00 |
|
Leo Vasanko
|
8132189a04
|
Rename /auth/restricted/ to auth/restricted/{iframe,oidc} for clarity and separation.
|
2026-02-15 03:05:11 +00:00 |
|
Leo Vasanko
|
701b0810bd
|
Stricter security. Moved to /auth/oidc/
|
2026-02-15 02:57:23 +00:00 |
|
Leo Vasanko
|
b5a5f2707a
|
Draft OpenID Connect support.
|
2026-02-14 23:01:13 +00:00 |
|
Leo Vasanko
|
f195818f07
|
Upgrade fastapi-vue-setup 1.0.2
|
2026-02-11 21:33:21 +00:00 |
|
Leo Vasanko
|
e16c027b53
|
Remove unused CLI bootstrap entry point.
|
2026-02-11 20:29:12 +00:00 |
|
Leo Vasanko
|
a9cf518296
|
Add version indication and link to our site on profile page (bottom right corner).
|
2026-02-11 01:36:58 +00:00 |
|
Leo Vasanko
|
0af7d4b939
|
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
|
2026-02-11 01:24:23 +00:00 |
|
Leo Vasanko
|
419f69cef5
|
Style overhaul.
|
2026-02-11 01:18:19 +00:00 |
|
Leo Vasanko
|
b1731e5abf
|
Inline get_config, rewrite update_config, DB init Config and rp_id defaults changed.
|
2026-02-10 23:17:28 +00:00 |
|
Leo Vasanko
|
9332eb63ab
|
ResetToken.hash(phrase) added avoiding code duplication.
|
2026-02-10 22:56:49 +00:00 |
|
Leo Vasanko
|
310a4e9a87
|
Remove remaining DB getter functions, inline at call site and add ResetToken.by_passphrase().
|
2026-02-10 22:48:31 +00:00 |
|
Leo Vasanko
|
6961a82f3f
|
Remove unnecessary odd getter from db.operations.
|
2026-02-10 22:37:57 +00:00 |
|
Leo Vasanko
|
f7d9d03765
|
Refactor DB lifecycle functions init and cleanup to separate db.lifecycle module.
|
2026-02-10 22:28:38 +00:00 |
|
Leo Vasanko
|
2f2934db6b
|
CRUD store and delete on the DB classes directly.
|
2026-02-10 22:19:02 +00:00 |
|
Leo Vasanko
|
f0d360758c
|
Db operations: bootstrap separated to its own module.
|
2026-02-10 22:09:07 +00:00 |
|
Leo Vasanko
|
12715ee405
|
Use strictly same now timestamp over a transaction, even for UUIDv7s generated.
|
2026-02-10 21:45:09 +00:00 |
|