LeoVasanko
49119fac81
Fix HostProfile user properties access.
2026-02-18 03:47:08 +00:00
LeoVasanko
68dccc1378
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko
f830d7d0ec
More minimalistic light theme. UI hint for org admin user/role management.
2026-02-14 18:36:20 +00:00
LeoVasanko
c1f8020f6b
API cleanup, using msgspec structs rather than raw responses. Admin app cleanup, better breadcrumbs.
2026-02-13 20:09:41 +00:00
LeoVasanko
fc0541762e
Add version indication and link to our site on profile page (bottom right corner).
2026-02-11 01:36:58 +00:00
LeoVasanko
cebaa2a757
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
2026-02-11 01:24:15 +00:00
LeoVasanko
4ebe5ae968
Style overhaul.
2026-02-11 01:18:19 +00:00
LeoVasanko
8444d0399e
Improved theme picker
2026-02-05 16:19:06 +00:00
LeoVasanko
1800dc12ae
Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins).
2026-01-30 23:31:06 +00:00
LeoVasanko
7e49ef296a
Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced).
2026-01-29 19:46:26 +00:00
LeoVasanko
433844cf08
Refactor to separate paskia lib functionality generally useful for various apps.
2026-01-29 16:55:46 +00:00
LeoVasanko
cb84a81a06
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
LeoVasanko
7e568dbd10
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
LeoVasanko
c13044c085
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
720d875eb5
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
LeoVasanko
3f0de04a49
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
LeoVasanko
ca73febe2f
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
2025-12-10 15:43:40 +00:00
LeoVasanko
9b491164fd
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
LeoVasanko
bb34e52997
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
aa4b1bfd42
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-04 01:21:52 +00:00
LeoVasanko
2ecf8433a1
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-04 01:00:24 +00:00
LeoVasanko
db892365dc
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-04 00:29:42 +00:00
LeoVasanko
547a6cd923
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 23:17:02 +00:00
LeoVasanko
643d9bafab
Fix the back buttons (navigate back if you can but close if it was a new window).
2025-12-02 18:02:02 +00:00
LeoVasanko
3030122807
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
2025-12-02 15:25:31 +00:00
LeoVasanko
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
LeoVasanko
ef66baff20
Harmonise ProfileView and HostApp.
2025-10-05 06:14:17 +00:00
LeoVasanko
eaa16abe2a
Better UX for profile view logout buttons.
2025-10-05 04:22:16 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
3f45024396
Massive style redesign, WIP.
2025-09-30 09:02:49 +00:00
LeoVasanko
5ad3ccb5ae
Implement breadcrumb navigation.
2025-09-28 08:47:45 +00:00
LeoVasanko
09b9894407
Cleaned up login/logout flows.
2025-09-03 07:08:16 +00:00
LeoVasanko
6e5ea9eac0
Refactor API under /auth/api
2025-09-03 02:32:19 +00:00
LeoVasanko
a84556509a
Unify user info across admin app and profile view.
2025-09-02 07:56:18 +00:00
LeoVasanko
2769d8c7f0
User name editing UI (hopefully fixed)
2025-09-02 06:59:39 +00:00
LeoVasanko
a1d5270dd7
User rename fixes.
2025-09-02 06:20:32 +00:00
LeoVasanko
e1e933c756
Renaming of users in registration, profile and admin app.
2025-09-02 06:13:01 +00:00
LeoVasanko
75bcdb8b18
Basic navigation between auth and user pages.
2025-08-30 08:50:37 +00:00
LeoVasanko
7e45bba612
Almost complete org/permission handling. Much cleanup, bootstrap works.
2025-08-08 01:58:12 +00:00
LeoVasanko
039613a8b3
Cleaner error message on aborted Passkey operations.
2025-08-07 00:00:23 +00:00
LeoVasanko
04953c7903
Frontend component selection logic simplified.
2025-08-06 23:33:34 +00:00
LeoVasanko
764bbd1115
Avoid loading user info twice to show profile.
2025-08-06 22:57:41 +00:00
LeoVasanko
f1ef7e43cc
Frontend adjusted for the new API.
2025-08-02 01:16:10 +00:00
LeoVasanko
158115f172
Refactor to get user info from a single endpoint
2025-07-15 00:30:10 +00:00