LeoVasanko
|
b9b1c995f9
|
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
|
2025-12-04 01:58:18 +00:00 |
|
LeoVasanko
|
db892365dc
|
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
|
2025-12-04 00:29:42 +00:00 |
|
LeoVasanko
|
547a6cd923
|
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
|
2025-12-03 23:17:02 +00:00 |
|
LeoVasanko
|
5422845192
|
Better error messages from backend, avoid bad toasts, cleanup of session validation.
|
2025-12-02 16:37:27 +00:00 |
|
LeoVasanko
|
c218ddad61
|
Centralise all cookie handling to session.py.
|
2025-10-05 06:48:24 +00:00 |
|
LeoVasanko
|
a4ac19f54c
|
WebSockets must use origin for finding the host calling them.
|
2025-10-05 05:16:51 +00:00 |
|
LeoVasanko
|
0af7aad28c
|
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
|
2025-10-04 06:31:54 +00:00 |
|
LeoVasanko
|
e1e933c756
|
Renaming of users in registration, profile and admin app.
|
2025-09-02 06:13:01 +00:00 |
|
LeoVasanko
|
ad4bde5d0d
|
Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site).
|
2025-08-31 03:54:17 +00:00 |
|
LeoVasanko
|
54cef0f9d6
|
Fixing cascade.
|
2025-08-31 02:07:32 +00:00 |
|
LeoVasanko
|
7e45bba612
|
Almost complete org/permission handling. Much cleanup, bootstrap works.
|
2025-08-08 01:58:12 +00:00 |
|
LeoVasanko
|
df377c4a14
|
Globals restructured to their own module. Origin and RP definition.
|
2025-08-07 01:23:35 +00:00 |
|
LeoVasanko
|
82150be650
|
Error handling cleanup for WS too.
|
2025-08-06 22:53:13 +00:00 |
|
LeoVasanko
|
4ca6eb9994
|
Add New Passkey and Add New Device flows fixed.
|
2025-08-06 22:14:04 +00:00 |
|
LeoVasanko
|
b255362946
|
Refactor to not use status: success, but HTTP codes, and renamed the error key to detail to match FastAPI's own.
|
2025-08-06 22:09:55 +00:00 |
|
LeoVasanko
|
c8bb2ab12e
|
Checkpoint, fixing reset token handling broken in earlier edits.
|
2025-08-06 21:55:14 +00:00 |
|
LeoVasanko
|
a4101e708a
|
Separated session management from its FastAPI-dependent parts, creating authsession.py on main level.
Startup/main/scripts cleanup, now runs with passkey-auth command that takes CLI arguments.
|
2025-08-05 21:02:49 +00:00 |
|
LeoVasanko
|
9d0c97f403
|
Finish DB cleanup/refactoring. Working now.
|
2025-08-05 20:26:35 +00:00 |
|
LeoVasanko
|
af8dea1a02
|
Database cleanup, base class, separated from FastAPI app.
|
2025-08-05 19:55:31 +00:00 |
|
LeoVasanko
|
71db80c7ea
|
Everything works. Minor adjustments on frontend and backend for the new API.
|
2025-08-02 19:41:42 +00:00 |
|
LeoVasanko
|
f524b85f40
|
Fixes to backend API changes. The whole app is mostly functional.
|
2025-08-02 01:48:38 +00:00 |
|
LeoVasanko
|
9b82f77729
|
Major cleanup and refactoring of the backend (frontend not fully updated).
|
2025-08-02 00:32:27 +00:00 |
|
LeoVasanko
|
f86406b4d4
|
Removal of JWT code, cleanup, using User dataclass rather than UserModel in APIs.
|
2025-07-28 11:44:26 +00:00 |
|
LeoVasanko
|
fb898193e2
|
Late night hacking...?
|
2025-07-15 05:45:01 +00:00 |
|