Leo Vasanko
b09fb7fe26
DB background worker cleanup, avoid issue with double cleanup. Faster write to disk.
2026-01-27 22:21:33 +00:00
Leo Vasanko
d40a2b8682
DB transactions cleanup, better actor/user data. Simplified admin API. Use UUID to refer to a specific permission in admin API. Other cleanup.
2026-01-27 21:48:21 +00:00
Leo Vasanko
e3b64ef537
Move imports to top of file.
2026-01-27 20:16:32 +00:00
Leo Vasanko
a54819aba8
Remove most remaining DB getters. Add ws auth chat helper function to avoid repetition, along with the existing register chat in wschat.py.
2026-01-27 20:01:17 +00:00
Leo Vasanko
69a0aae78c
Remove db.get_session.
2026-01-27 18:28:32 +00:00
Leo Vasanko
925a582869
Remove list_sessions_for_user, inline db access at call sites.
2026-01-27 18:25:29 +00:00
Leo Vasanko
8249a9b3c1
DB cleanup: removed get_permission_organizations and build_org. Using db.data() for read access at call sites.
2026-01-27 18:23:17 +00:00
Leo Vasanko
e2a4143543
Consistently use UUID type in APIs instead of UUID str as option.
2026-01-27 16:24:02 +00:00
Leo Vasanko
bafd62a1b1
DB getter refactoring. Documented call sites. Added separate function for by-scope permission lookup.
2026-01-27 15:54:28 +00:00
Leo Vasanko
637b1b95a8
Finalize database API class merge.
2026-01-27 03:00:18 +00:00
Leo Vasanko
73e4d41f04
Refactor API to match database, no _uuid postfixes.
2026-01-27 02:32:46 +00:00
Leo Vasanko
2413a32bda
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
Leo Vasanko
db104d762b
Finish the database key-in-object refactoring.
2026-01-27 02:11:09 +00:00
Leo Vasanko
ece0ac9a16
Database cleanup, better UUID passing and construction (User model).
2026-01-27 01:25:52 +00:00
Leo Vasanko
e0e1a644de
Cleanup and bugfixes on Bootstrap and JSONL handling.
2026-01-26 23:54:03 +00:00
Leo Vasanko
f6e995184f
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
Leo Vasanko
d7665f3f8d
Fix frontend-build location. Cleanup.
2026-01-25 03:26:22 +00:00
Leo Vasanko
21364fc621
Use fastapi-vue-setup, merging its template scripts to old Paskia entry point and devserver. Simplified CLI, no longer uses serve subcommand. Fixed the URL displayed on banner to show to actual frontend/caddy server even in devmode.
2026-01-25 03:15:50 +00:00
Leo Vasanko
0097bb4011
Logging cleanup, linter.
2026-01-24 01:08:00 +00:00
Leo Vasanko
f7f529d8b9
Fix errors where permission scopes were still expected for indexing.
2026-01-24 00:58:18 +00:00
Leo Vasanko
6d340ef689
Large refactoring for better JSONL context. Switched back the urlsafe for session tokens that need to be passed in URLs. Other minor fixes.
2026-01-24 00:40:32 +00:00
Leo Vasanko
2227a9bf6f
Refer permissions by UUID rather than scope.
2026-01-24 00:06:08 +00:00
Leo Vasanko
3f5018918e
Simplify session and reset token formats; removes the token utility functions entirely.
2026-01-23 21:01:45 +00:00
Leo Vasanko
e93578f2e7
Fix actor fields and transactions for API operations as they are recorded to DB.
2026-01-23 20:19:33 +00:00
Leo Vasanko
aa26a16d5d
Record user UUID as actor for API access.
2026-01-23 19:55:54 +00:00
Leo Vasanko
0674f9ceeb
Database refactor to separate modules.
2026-01-23 18:35:35 +00:00
Leo Vasanko
c6dadd283d
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
Leo Vasanko
4c1db37c73
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
Leo Vasanko
253387be97
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
Leo Vasanko
291e0eae0b
Replace session.renewed with .expiry for consistency with other expiring items. Fix migration script.
2026-01-23 01:39:59 +00:00
Leo Vasanko
ab65f3dae2
Database cleanup: make it synchronous because we work with in-memory data. Defer writes to disk and cleanup to background task. Tests passing.
2026-01-23 01:22:47 +00:00
Leo Vasanko
887c0f92a2
Replace SQL database with JSONL based solution that keeps history.
2026-01-23 00:54:37 +00:00
Leo Vasanko
88743839af
Add missing max-age argument to validate endpoint.
2025-12-19 18:34:01 +00:00
Leo Vasanko
472fedc3ae
Fix devserver script misprocessing in some situations where auth-host was being used. Deduplicate origins on server end.
2025-12-10 17:39:09 +00:00
Leo Vasanko
07fb9f79a6
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
Leo Vasanko
e1e4a211ec
Fix missing credential_uuid in admin user detail API that was causing linkage between sessions and their passkeys not show up.
2025-12-09 15:34:05 +00:00
LeoVasanko
c605926c30
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
Leo Vasanko
2bac94a548
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
2025-12-06 04:45:26 +00:00
Leo Vasanko
0203bce05e
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
2025-12-06 03:39:05 +00:00
Leo Vasanko
0b17681907
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
2025-12-06 00:51:18 +00:00
Leo Vasanko
da503a3081
More robust server startup, startup logo and info screen, renewed devmode script.
2025-12-05 19:06:42 +00:00
Leo Vasanko
4b16037426
Project renamed to Paskia.
2025-12-05 13:24:34 +00:00