Commit Graph
100 Commits
Author SHA1 Message Date
LeoVasanko c605926c30 Implement code word based remote authentication (#1)
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:

- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices

Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
Leo Vasanko 4b16037426 Project renamed to Paskia. 2025-12-05 13:24:34 +00:00
Leo Vasanko 4c34217846 Cleanup old hostapp files (finished, working). 2025-12-03 22:06:54 -06:00
Leo Vasanko 5c72777c2f Missing new component. 2025-12-03 22:03:33 -06:00
Leo Vasanko 18eed4654f Integrate host app to main app (WIP). 2025-12-03 22:00:47 -06:00
Leo Vasanko b373a84065 Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests. 2025-12-03 21:19:40 -06:00
Leo Vasanko bc4254ad18 Fix view switching of restricted app. 2025-12-03 19:46:36 -06:00
Leo Vasanko d541377798 Make restricted app use simple fetch that doesn't do API authentication (recursively). 2025-12-03 18:20:14 -06:00
Leo Vasanko afbd9606db Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden). 2025-12-03 18:01:47 -06:00
Leo Vasanko 9b73684082 Log authentication options on the client. 2025-12-03 17:07:44 -06:00
Leo Vasanko 9786c2a5a8 Improved dialog layout with separate mobile portrait mode. 2025-12-03 16:06:32 -06:00
Leo Vasanko 3e10e082e2 Fix infinitely nested login iframes when the restricted app notices it needs login. 2025-12-03 15:56:17 -06:00
Leo Vasanko 7a70c933c9 Various fixes and cleanup, regressions from prior commits. 2025-12-03 15:40:59 -06:00
Leo Vasanko 6a7b1a876e Fix syntax error in reset app created by earlier commit. 2025-12-03 14:31:13 -06:00
Leo Vasanko 9488f69e53 Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode). 2025-12-03 13:58:18 -06:00
Leo Vasanko 1610869fae Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout. 2025-12-03 13:35:44 -06:00
Leo Vasanko 219dd70665 Viewing linked passkeys/sessions (by clicking either one of them). 2025-12-03 13:21:52 -06:00
Leo Vasanko 4306323c44 Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication). 2025-12-03 13:00:24 -06:00
Leo Vasanko ceb99de738 Improved auth profile UX, consistent transparent-blur dialog background everywhere. 2025-12-03 12:30:23 -06:00
Leo Vasanko ad374f5dda Formatting, tidy up, transparent auth dialog background. 2025-12-03 11:33:24 -06:00
Leo Vasanko 1ffc918a88 Improved apiFetch and jsonFetch functions. 2025-12-03 11:26:38 -06:00
Leo Vasanko 1f75e0a305 Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata. 2025-12-03 11:17:02 -06:00
Leo Vasanko 2e9895443b Improved session list IP handling. Hovering sessions shows Same IP on matching sessions. 2025-12-03 01:32:05 +00:00
Leo Vasanko bd13dbd1a0 Implement session termination in admin API, for completeness. 2025-12-03 01:20:52 +00:00
Leo Vasanko ca8d65ad25 Improved profile view layout. 2025-12-03 01:04:07 +00:00
Leo Vasanko 70411fa77b Improved profile view layout. 2025-12-03 00:52:52 +00:00
Leo Vasanko 3967e93c37 Fix examples folder serving broken a couple of commits ago. 2025-12-03 00:06:32 +00:00
Leo Vasanko 10ce0126b0 Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement. 2025-12-02 23:39:31 +00:00
Leo Vasanko aed48de38e Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility. 2025-12-02 22:41:12 +00:00
Leo Vasanko c83450dace Major refactor of frontend source tree such that paths better match where they are served. 2025-12-02 22:09:07 +00:00
Leo Vasanko 123a62549b Refactor restricted app paths and naming. 2025-12-02 19:10:13 +00:00
Leo Vasanko 2a5f06d707 Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app. 2025-12-02 18:34:59 +00:00
Leo Vasanko 7ace4dcb4b Fix the back buttons (navigate back if you can but close if it was a new window). 2025-12-02 18:13:23 +00:00
Leo Vasanko 6f9f4aefc1 Implement Forbidden view for API calls, cleanup and better UX. 2025-12-02 17:36:37 +00:00
Leo Vasanko a05d4aec81 Better error messages from backend, avoid bad toasts, cleanup of session validation. 2025-12-02 16:37:27 +00:00
Leo Vasanko 77d8e97dc9 Update admin app authentication in API mode too, reusing components between it and the main app. 2025-12-02 15:42:55 +00:00
Leo Vasanko d1a7a53c19 Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages. 2025-12-02 15:25:31 +00:00
Leo Vasanko cb26c61d5f Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified. 2025-12-02 03:10:16 +00:00
Leo Vasanko 876215f1c1 Reset dialog UX improved. 2025-10-04 18:40:46 -06:00
Leo Vasanko 59e7e40128 Harmonise ProfileView and HostApp. 2025-10-04 18:14:17 -06:00
Leo Vasanko a0da799c9e Tuning the host app. 2025-10-04 18:06:47 -06:00
Leo Vasanko 94efb00e34 Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose. 2025-10-04 17:55:08 -06:00
Leo Vasanko 29be642dbe Better UX for profile view logout buttons. 2025-10-04 16:22:16 -06:00
Leo Vasanko bfb11cc20f A major refactoring for more consistent and stricter flows.
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko 389e05730b Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root. 2025-10-04 08:59:51 -06:00
Leo Vasanko 79b6c50a9c More consistent shared styling between credential and session cards. 2025-10-04 08:32:27 -06:00
Leo Vasanko 591ea626bf Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens. 2025-10-03 18:31:54 -06:00
Leo Vasanko 5d8304bbd9 Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko 382341e5ee Make the login/reset/forbidden dialogs look better. 2025-09-30 17:03:51 -06:00
Leo Vasanko ed7d3ee0fc Admin app: guard rails extended, consistent styling, also share styling with main app. 2025-09-30 16:38:14 -06:00