LeoVasanko
deabee3b5c
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
2025-12-03 22:58:48 +00:00
LeoVasanko
fd1aa11409
Add E2E tests to register and verify passkey.
2025-12-03 02:52:39 +00:00
LeoVasanko
ca1ea9d90b
Always use timezone aware UTC time.
2025-12-03 01:36:15 +00:00
LeoVasanko
2dac0be77a
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
2025-12-03 01:32:05 +00:00
LeoVasanko
f63c62d9ff
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
LeoVasanko
768a4391cf
Improved profile view layout.
2025-12-03 01:03:25 +00:00
LeoVasanko
f64876e73b
Improved profile view layout.
2025-12-03 00:52:52 +00:00
LeoVasanko
b6a3cdd3a4
Fix examples folder serving broken a couple of commits ago.
2025-12-03 00:06:32 +00:00
LeoVasanko
fd9a5afc1c
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00
LeoVasanko
8714fe9319
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
2025-12-02 22:41:12 +00:00
LeoVasanko
adbab88c86
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
LeoVasanko
5d9d2b794d
Refactor restricted app paths and naming.
2025-12-02 19:10:13 +00:00
LeoVasanko
eedbd4aaa4
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
LeoVasanko
15916047fa
Remove backend access control, now that the profile and admin apps handle that via API.
2025-12-02 18:25:58 +00:00
LeoVasanko
643d9bafab
Fix the back buttons (navigate back if you can but close if it was a new window).
2025-12-02 18:02:02 +00:00
LeoVasanko
2699aaa472
Implement Forbidden view for API calls, cleanup and better UX.
2025-12-02 17:36:37 +00:00
LeoVasanko
5422845192
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
LeoVasanko
c1ccb048f0
Update admin app authentication in API mode too, reusing components between it and the main app.
2025-12-02 15:42:55 +00:00
LeoVasanko
3030122807
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
2025-12-02 15:25:31 +00:00
LeoVasanko
d4f8e97469
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
2025-12-02 14:30:31 +00:00
LeoVasanko
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
LeoVasanko
2dca6b1eec
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/ .
2025-12-01 20:07:26 +00:00
LeoVasanko
4f50974222
Updated build-frontend script, now uses deno, npm, bun in this order.
2025-12-01 19:25:08 +00:00
LeoVasanko
c218ddad61
Centralise all cookie handling to session.py.
2025-10-05 06:48:24 +00:00
LeoVasanko
7247f7c584
Refactor /api/user/* to its own module.
2025-10-05 06:41:14 +00:00
LeoVasanko
af2834b4c0
Reset dialog UX improved.
2025-10-05 06:25:40 +00:00
LeoVasanko
ef66baff20
Harmonise ProfileView and HostApp.
2025-10-05 06:14:17 +00:00
LeoVasanko
08d4607d65
Tuning the host app.
2025-10-05 06:03:28 +00:00
LeoVasanko
1ca9e3ef58
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-05 05:55:08 +00:00
LeoVasanko
575d3cb1fb
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-05 05:26:03 +00:00
LeoVasanko
a4ac19f54c
WebSockets must use origin for finding the host calling them.
2025-10-05 05:16:51 +00:00
LeoVasanko
11887d15b2
Correction on restricted path checking (auth-host).
2025-10-05 04:59:05 +00:00
LeoVasanko
cefb9c3d92
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-05 04:49:23 +00:00
LeoVasanko
5b9a3fc27f
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-05 04:35:55 +00:00
LeoVasanko
19a6c32cf2
Fix deletion of session cookie on host logout.
2025-10-05 04:26:36 +00:00
LeoVasanko
eaa16abe2a
Better UX for profile view logout buttons.
2025-10-05 04:22:16 +00:00
LeoVasanko
01bc39a0e8
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-05 03:55:11 +00:00
LeoVasanko
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 20:59:51 +00:00
LeoVasanko
f24aaa295d
More consistent shared styling between credential and session cards.
2025-10-04 20:32:27 +00:00
LeoVasanko
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-04 06:31:54 +00:00
LeoVasanko
24692fcfec
Use git tag versioning for the Python project.
2025-10-03 04:07:11 +00:00
LeoVasanko
43850c218f
Fix reset link logic to include /auth when no configured auth-host.
2025-10-03 03:57:20 +00:00
LeoVasanko
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-03 03:42:01 +00:00
LeoVasanko
b4871c671f
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-03 00:22:02 +00:00
LeoVasanko
095768e07c
Version 0.2.0
2025-10-01 05:04:53 +00:00
LeoVasanko
2f77753354
Make the login/reset/forbidden dialogs look better.
2025-10-01 05:03:51 +00:00
LeoVasanko
ea871635e0
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-10-01 04:38:14 +00:00
LeoVasanko
c3e4c18d5c
Remove duplicate message from permission denied page.
2025-10-01 00:56:41 +00:00
LeoVasanko
a7c23b31e7
Admin app divided to separate components.
2025-10-01 00:54:18 +00:00
LeoVasanko
3f45024396
Massive style redesign, WIP.
2025-09-30 09:02:49 +00:00
LeoVasanko
2d2e4e899d
Simplified Caddy snippets (removed auth/all).
2025-09-29 08:00:19 +00:00
LeoVasanko
48f718191f
Version 0.1.2
2025-09-29 07:46:49 +00:00
LeoVasanko
e130bc5c0a
Clear sessionStorage on logout.
2025-09-29 07:45:37 +00:00
LeoVasanko
2df444b80f
chore: bump version to 0.1.1
2025-09-28 08:51:46 +00:00
LeoVasanko
5ad3ccb5ae
Implement breadcrumb navigation.
2025-09-28 08:47:45 +00:00
LeoVasanko
ec098b862c
Implement credential reset via CLI.
2025-09-27 05:18:33 +00:00
LeoVasanko
bd5a920a56
Update documentation.
2025-09-27 04:59:18 +00:00
LeoVasanko
88275beb0f
Make the /auth/api/validate endpoint renew sessions if needed.
2025-09-27 04:59:11 +00:00
LeoVasanko
d897f9c217
Updated example Caddyfile
2025-09-27 04:58:36 +00:00
LeoVasanko
fc673c8d8e
Support auth request for WebSocket connections (using plain HTTP for auth). Use keep-alive for better performance.
2025-09-27 03:00:56 +00:00
LeoVasanko
4315584589
Cleanup
2025-09-27 03:00:17 +00:00
LeoVasanko
ffbe8a6b18
Minor tuning of Caddy configuration and improved documentation.
2025-09-26 07:12:11 +00:00
LeoVasanko
39ba032450
Provide user info in Remote-* headers. Caddy configuration improved.
2025-09-26 06:12:40 +00:00
LeoVasanko
f28e69a9ce
Cleaner logout.
2025-09-03 07:11:25 +00:00
LeoVasanko
09b9894407
Cleaned up login/logout flows.
2025-09-03 07:08:16 +00:00
LeoVasanko
4052122d40
Fix url_for query arg on reset link redirect.
2025-09-03 06:32:56 +00:00
LeoVasanko
f0ff3cf977
Fix matching bug
2025-09-03 06:22:21 +00:00
LeoVasanko
07212ee1de
Major refactoring of admin API (permissions, paths)
2025-09-03 06:08:06 +00:00
LeoVasanko
340888a178
Refactoring permissions checks.
2025-09-03 05:28:26 +00:00
LeoVasanko
53f1745ebd
Utility module for accessing frontend in backend code.
2025-09-03 04:05:20 +00:00
LeoVasanko
42e0266cd6
Move forward auth under /admin/api/forward
2025-09-03 03:03:39 +00:00
LeoVasanko
982937572a
New lint option path in pyproject
2025-09-03 03:03:02 +00:00
LeoVasanko
5c5da10c8b
Moved exception handlers to sub apps.
2025-09-03 02:57:06 +00:00
LeoVasanko
0d725f85a5
Rename variable to silence linter
2025-09-03 02:45:23 +00:00
LeoVasanko
6e5ea9eac0
Refactor API under /auth/api
2025-09-03 02:32:19 +00:00
LeoVasanko
5281432c96
Restructure admin app separate of user api.
2025-09-03 02:04:52 +00:00
LeoVasanko
ed2b0f6f3c
Remove icon, prefer automatic use of /favicon.ico of the host site.
2025-09-02 22:17:40 +00:00
LeoVasanko
cf4835ff83
Redux
2025-09-02 08:21:20 +00:00
LeoVasanko
01251a4769
Support WS connections on older browsers.
2025-09-02 08:15:14 +00:00
LeoVasanko
aed9835098
Better navigation on admin app.
2025-09-02 08:04:56 +00:00
LeoVasanko
54a0d84cb5
Smarter user info
2025-09-02 08:02:52 +00:00
LeoVasanko
70a7bc791f
Fix previous
2025-09-02 07:58:48 +00:00
LeoVasanko
a84556509a
Unify user info across admin app and profile view.
2025-09-02 07:56:18 +00:00
LeoVasanko
3547144313
Use bun --bun consistently, avoid devmode origin override if specified by args rp-id and/or origin.
2025-09-02 07:47:46 +00:00
LeoVasanko
2769d8c7f0
User name editing UI (hopefully fixed)
2025-09-02 06:59:39 +00:00
LeoVasanko
a526344842
Use rp-name for frontend branding
2025-09-02 06:48:59 +00:00
LeoVasanko
93d722c4d2
Count registration also as a login.
2025-09-02 06:40:05 +00:00
LeoVasanko
b39eb59961
Linter
2025-09-02 06:29:38 +00:00
LeoVasanko
a1d5270dd7
User rename fixes.
2025-09-02 06:20:32 +00:00
LeoVasanko
e1e933c756
Renaming of users in registration, profile and admin app.
2025-09-02 06:13:01 +00:00
LeoVasanko
b9c1fe059c
Crude dialog rather than prompt() for input fields. (needs cleanup)
2025-09-02 05:34:45 +00:00
LeoVasanko
2b371c70db
Updated frontend build script
2025-09-02 05:16:48 +00:00
LeoVasanko
db19ff61f6
Only allow safe characters in permission IDs
2025-08-31 07:10:00 +00:00
LeoVasanko
0e4e4f4cfa
Make default permissions use only : as separator.
2025-08-31 06:43:49 +00:00
LeoVasanko
24404738ab
Formatting
2025-08-31 06:43:27 +00:00
LeoVasanko
3a52966fc1
Extended demo Caddyfile
2025-08-31 06:41:28 +00:00
LeoVasanko
d7735675b7
Implement Permission Denied handling.
2025-08-31 06:38:48 +00:00
LeoVasanko
c06b7ddf26
Allow specifying multiple permissions.
2025-08-31 04:47:38 +00:00
LeoVasanko
c67a83abdc
Add permission check on forward-auth and validate.
2025-08-31 04:13:54 +00:00
LeoVasanko
ad4bde5d0d
Remodel reset token handling due to browsers sometimes refusing to set the cookie when opening the link (from another site).
2025-08-31 03:54:17 +00:00