Commit Graph
100 Commits
Author SHA1 Message Date
Leo Vasanko da503a3081 More robust server startup, startup logo and info screen, renewed devmode script. 2025-12-05 19:06:42 +00:00
Leo Vasanko 8b98cb6325 Updated documentation. 2025-12-05 16:15:50 +00:00
Leo Vasanko 4b16037426 Project renamed to Paskia. 2025-12-05 13:24:34 +00:00
Leo Vasanko 9d7ace8fb5 Refactor dev mode into a source repo script (remove dev subcommand from package). 2025-12-05 13:08:44 +00:00
Leo Vasanko 39c06620c4 Updated E2E tests. 2025-12-04 04:44:58 +00:00
Leo Vasanko 8011a0d910 Make dev mode run without static files, only serving assets in production. 2025-12-03 22:15:26 -06:00
Leo Vasanko 4c34217846 Cleanup old hostapp files (finished, working). 2025-12-03 22:06:54 -06:00
Leo Vasanko 5c72777c2f Missing new component. 2025-12-03 22:03:33 -06:00
Leo Vasanko 18eed4654f Integrate host app to main app (WIP). 2025-12-03 22:00:47 -06:00
Leo Vasanko b373a84065 Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests. 2025-12-03 21:19:40 -06:00
Leo Vasanko 7983d9b170 Brought examples directly to front page. 2025-12-03 21:10:08 -06:00
Leo Vasanko bc4254ad18 Fix view switching of restricted app. 2025-12-03 19:46:36 -06:00
Leo Vasanko d541377798 Make restricted app use simple fetch that doesn't do API authentication (recursively). 2025-12-03 18:20:14 -06:00
Leo Vasanko 7c82727d28 Fixed and simplified examples. 2025-12-03 18:08:52 -06:00
Leo Vasanko afbd9606db Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden). 2025-12-03 18:01:47 -06:00
Leo Vasanko 9b73684082 Log authentication options on the client. 2025-12-03 17:07:44 -06:00
Leo Vasanko 9786c2a5a8 Improved dialog layout with separate mobile portrait mode. 2025-12-03 16:06:32 -06:00
Leo Vasanko 3e10e082e2 Fix infinitely nested login iframes when the restricted app notices it needs login. 2025-12-03 15:56:17 -06:00
Leo Vasanko 7a70c933c9 Various fixes and cleanup, regressions from prior commits. 2025-12-03 15:40:59 -06:00
Leo Vasanko 6a7b1a876e Fix syntax error in reset app created by earlier commit. 2025-12-03 14:31:13 -06:00
Leo Vasanko ad63d3fb3a Better static files handling on backend, when in dev mode: fetch from vite. 2025-12-03 14:30:02 -06:00
Leo Vasanko 9488f69e53 Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode). 2025-12-03 13:58:18 -06:00
Leo Vasanko 1610869fae Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout. 2025-12-03 13:35:44 -06:00
Leo Vasanko 219dd70665 Viewing linked passkeys/sessions (by clicking either one of them). 2025-12-03 13:21:52 -06:00
Leo Vasanko 4306323c44 Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication). 2025-12-03 13:00:24 -06:00
Leo Vasanko ceb99de738 Improved auth profile UX, consistent transparent-blur dialog background everywhere. 2025-12-03 12:30:23 -06:00
Leo Vasanko ad374f5dda Formatting, tidy up, transparent auth dialog background. 2025-12-03 11:33:24 -06:00
Leo Vasanko 1ffc918a88 Improved apiFetch and jsonFetch functions. 2025-12-03 11:26:38 -06:00
Leo Vasanko 1f75e0a305 Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata. 2025-12-03 11:17:02 -06:00
Leo Vasanko 7b0a9c2a2a Reload backend only on changes on the backend or frontend-build within, not outside that in the repo. 2025-12-03 10:58:48 -06:00
Leo Vasanko 1c985527cf Add E2E tests to register and verify passkey. 2025-12-03 02:52:39 +00:00
Leo Vasanko 6003189da2 Always use timezone aware UTC time. 2025-12-03 01:36:15 +00:00
Leo Vasanko 2e9895443b Improved session list IP handling. Hovering sessions shows Same IP on matching sessions. 2025-12-03 01:32:05 +00:00
Leo Vasanko bd13dbd1a0 Implement session termination in admin API, for completeness. 2025-12-03 01:20:52 +00:00
Leo Vasanko ca8d65ad25 Improved profile view layout. 2025-12-03 01:04:07 +00:00
Leo Vasanko 70411fa77b Improved profile view layout. 2025-12-03 00:52:52 +00:00
Leo Vasanko 3967e93c37 Fix examples folder serving broken a couple of commits ago. 2025-12-03 00:06:32 +00:00
Leo Vasanko 10ce0126b0 Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement. 2025-12-02 23:39:31 +00:00
Leo Vasanko aed48de38e Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility. 2025-12-02 22:41:12 +00:00
Leo Vasanko c83450dace Major refactor of frontend source tree such that paths better match where they are served. 2025-12-02 22:09:07 +00:00
Leo Vasanko 123a62549b Refactor restricted app paths and naming. 2025-12-02 19:10:13 +00:00
Leo Vasanko 2a5f06d707 Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app. 2025-12-02 18:34:59 +00:00
Leo Vasanko 3441a7a2b3 Remove backend access control, now that the profile and admin apps handle that via API. 2025-12-02 18:25:58 +00:00
Leo Vasanko 7ace4dcb4b Fix the back buttons (navigate back if you can but close if it was a new window). 2025-12-02 18:13:23 +00:00
Leo Vasanko 6f9f4aefc1 Implement Forbidden view for API calls, cleanup and better UX. 2025-12-02 17:36:37 +00:00
Leo Vasanko a05d4aec81 Better error messages from backend, avoid bad toasts, cleanup of session validation. 2025-12-02 16:37:27 +00:00
Leo Vasanko 77d8e97dc9 Update admin app authentication in API mode too, reusing components between it and the main app. 2025-12-02 15:42:55 +00:00
Leo Vasanko d1a7a53c19 Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages. 2025-12-02 15:25:31 +00:00
Leo Vasanko 2c777661b8 Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI. 2025-12-02 14:30:31 +00:00
Leo Vasanko cb26c61d5f Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified. 2025-12-02 03:10:16 +00:00
Leo Vasanko 74a7723300 Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/. 2025-12-01 20:07:26 +00:00
Leo Vasanko 0678d7f9ec Updated build-frontend script, now uses deno, npm, bun in this order. 2025-12-01 19:25:08 +00:00
Leo Vasanko 07525b47ae Centralise all cookie handling to session.py. 2025-10-04 18:48:24 -06:00
Leo Vasanko 1ad1644b64 Refactor /api/user/* to its own module. 2025-10-04 18:41:35 -06:00
Leo Vasanko 876215f1c1 Reset dialog UX improved. 2025-10-04 18:40:46 -06:00
Leo Vasanko 59e7e40128 Harmonise ProfileView and HostApp. 2025-10-04 18:14:17 -06:00
Leo Vasanko a0da799c9e Tuning the host app. 2025-10-04 18:06:47 -06:00
Leo Vasanko 94efb00e34 Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose. 2025-10-04 17:55:08 -06:00
Leo Vasanko f9f4d59c6b Deny creating sessions for hosts other than rp-id subdomains. 2025-10-04 17:26:03 -06:00
Leo Vasanko 45f9870d0d WebSockets must use origin for finding the host calling them. 2025-10-04 17:16:51 -06:00
Leo Vasanko 2a81544701 Correction on restricted path checking (auth-host). 2025-10-04 16:59:05 -06:00
Leo Vasanko a60c1bd5f5 Refactor auth-host redirection middleware to its own module.
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-04 16:49:23 -06:00
Leo Vasanko 229f066533 Add validation of the CLI specified --auth-host (needs to be within rp-id). 2025-10-04 16:35:55 -06:00
Leo Vasanko 97f653e116 Fix deletion of session cookie on host logout. 2025-10-04 16:26:36 -06:00
Leo Vasanko 29be642dbe Better UX for profile view logout buttons. 2025-10-04 16:22:16 -06:00
Leo Vasanko bfb11cc20f A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko 389e05730b Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 08:59:51 -06:00
Leo Vasanko 79b6c50a9c More consistent shared styling between credential and session cards. 2025-10-04 08:32:27 -06:00
Leo Vasanko 591ea626bf Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-03 18:31:54 -06:00
Leo Vasanko 963ab06664 Use git tag versioning for the Python project. 2025-10-02 16:09:26 -06:00
Leo Vasanko bb35e57ba4 Fix reset link logic to include /auth when no configured auth-host. 2025-10-02 15:57:20 -06:00
Leo Vasanko 5d8304bbd9 Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko fbfd0bbb47 Create registration links on the same host (subdomain) that is being used by the one who creates it. 2025-10-02 12:30:50 -06:00
Leo Vasanko eb38995cca Version 0.2.0 2025-09-30 17:04:53 -06:00
Leo Vasanko 382341e5ee Make the login/reset/forbidden dialogs look better. 2025-09-30 17:03:51 -06:00
Leo Vasanko ed7d3ee0fc Admin app: guard rails extended, consistent styling, also share styling with main app. 2025-09-30 16:38:14 -06:00
Leo Vasanko 3dff459068 Remove duplicate message from permission denied page. 2025-09-30 12:56:41 -06:00
Leo Vasanko 89b40cd080 Admin app divided to separate components. 2025-09-30 12:54:18 -06:00
Leo Vasanko d46d50b91a Massive style redesign, WIP. 2025-09-29 21:02:49 -06:00
Leo Vasanko 39beb31347 Simplified Caddy snippets (removed auth/all). 2025-09-28 20:00:19 -06:00
Leo Vasanko 41e6eb9a5a Version 0.1.2 2025-09-28 19:46:49 -06:00
Leo Vasanko d5bc3e773d Clear sessionStorage on logout. 2025-09-28 19:45:37 -06:00
Leo Vasanko ac0256c366 chore: bump version to 0.1.1 2025-09-27 20:51:46 -06:00
Leo Vasanko 6439437e8b Implement breadcrumb navigation. 2025-09-27 20:47:45 -06:00
Leo Vasanko 654618883d Implement credential reset via CLI. 2025-09-26 17:18:49 -06:00
Leo Vasanko f065a8294f Update documentation. 2025-09-26 16:59:18 -06:00
Leo Vasanko 8409c7726c Make the /auth/api/validate endpoint renew sessions if needed. 2025-09-26 16:59:11 -06:00
Leo Vasanko 971d534dca Updated example Caddyfile 2025-09-26 16:58:36 -06:00
Leo Vasanko c6a039cc50 Support auth request for WebSocket connections (using plain HTTP for auth). Use keep-alive for better performance. 2025-09-26 15:00:56 -06:00
Leo Vasanko 21a6bfd8ba Cleanup 2025-09-26 15:00:17 -06:00
Leo Vasanko eaca57f625 Minor tuning of Caddy configuration and improved documentation. 2025-09-25 19:12:11 -06:00
Leo Vasanko e514ae010d Provide user info in Remote-* headers. Caddy configuration improved. 2025-09-25 18:12:40 -06:00
Leo Vasanko b0a1bb72dc Cleaner logout. 2025-09-02 19:11:25 -06:00
Leo Vasanko b324276173 Cleaned up login/logout flows. 2025-09-02 19:08:16 -06:00
Leo Vasanko 10e55f63b5 Fix url_for query arg on reset link redirect. 2025-09-02 18:32:56 -06:00
Leo Vasanko 074daebd14 Fix matching bug 2025-09-02 18:22:21 -06:00
Leo Vasanko c9f9b28bf4 Major refactoring of admin API (permissions, paths) 2025-09-02 18:08:06 -06:00
Leo Vasanko bfc777fb56 Refactoring permissions checks. 2025-09-02 17:28:26 -06:00
Leo Vasanko 3cd6a59b26 Utility module for accessing frontend in backend code. 2025-09-02 16:06:10 -06:00
Leo Vasanko dd20e7e7f8 Move forward auth under /admin/api/forward 2025-09-02 15:03:39 -06:00