LeoVasanko
d64e63527b
CLI main and RuntimeConfig cleanup. Added a session_ctx wrapper function for easier access and avoiding hostutil import in db.
2026-02-19 14:24:16 +00:00
LeoVasanko
9b7855c0af
Faster and simplified hash_secret() that directly produces urlsafe entries.
2026-02-18 23:02:36 +00:00
LeoVasanko
68dccc1378
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko
d41cffc03e
Remove remaining DB getter functions, inline at call site and add ResetToken.by_passphrase().
2026-02-10 22:48:31 +00:00
LeoVasanko
c3df6c318c
Change host normalization to remove port numbers - sessions are per host, cookies don't respect port numbers.
2026-02-05 19:04:40 +00:00
LeoVasanko
58b56a09a4
Restrict remote auth to the existing granting user's credentials.
2026-01-29 20:24:26 +00:00
LeoVasanko
731b36b456
Cleanup auth WS code, refactor to remove duplication and pass proper context.
2026-01-29 20:15:01 +00:00
LeoVasanko
7329223784
Implement full ORM. Various other cleanup.
2026-01-28 17:19:56 +00:00
LeoVasanko
c8d659b5ca
Move get_session_context to DB.session_ctx().
2026-01-28 14:52:18 +00:00
LeoVasanko
88a170a37b
Debug DB problem
2026-01-28 02:27:26 +00:00
LeoVasanko
38d240d86d
Credential update was being done out of transaction, now part of login.
2026-01-28 02:22:47 +00:00
LeoVasanko
d3d5f5a3c8
Remove get_session_context setting of host (now read only op as expected). Make session host, ip and user_agent always set (the ua potentially empty string).
2026-01-28 02:14:34 +00:00
LeoVasanko
3d49cbf2d6
Disable API docs that display very much broken due to missing request/response typing.
2026-01-27 23:27:42 +00:00
LeoVasanko
13c49aebfd
Remove unnecessary use of async now that db access doesn't need awaiting.
2026-01-27 23:16:17 +00:00
LeoVasanko
cf1124c251
DB transactions cleanup, better actor/user data. Simplified admin API. Use UUID to refer to a specific permission in admin API. Other cleanup.
2026-01-27 21:48:21 +00:00
LeoVasanko
e8247a2c7f
Remove most remaining DB getters. Add ws auth chat helper function to avoid repetition, along with the existing register chat in wschat.py.
2026-01-27 20:01:17 +00:00
LeoVasanko
3196aa7688
Refactor API to match database, no _uuid postfixes.
2026-01-27 02:32:46 +00:00
LeoVasanko
cb84a81a06
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
LeoVasanko
9bdca1f43a
Finish the database key-in-object refactoring.
2026-01-27 02:11:09 +00:00
LeoVasanko
4ddaa9fdf4
Cleanup and bugfixes on Bootstrap and JSONL handling.
2026-01-26 23:54:03 +00:00
LeoVasanko
cebef8adfc
Large refactoring for better JSONL context. Switched back the urlsafe for session tokens that need to be passed in URLs. Other minor fixes.
2026-01-24 00:40:32 +00:00
LeoVasanko
2ec6314264
Simplify session and reset token formats; removes the token utility functions entirely.
2026-01-23 20:53:03 +00:00
LeoVasanko
ae4c982a30
Fix actor fields and transactions for API operations as they are recorded to DB.
2026-01-23 20:19:33 +00:00
LeoVasanko
f9d23a196c
Database refactor to separate modules.
2026-01-23 18:27:12 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
02e04da2c4
Database cleanup: make it synchronous because we work with in-memory data. Defer writes to disk and cleanup to background task. Tests passing.
2026-01-23 01:22:47 +00:00
LeoVasanko
7f3763b46d
Replace SQL database with JSONL based solution that keeps history.
2026-01-23 00:54:37 +00:00
LeoVasanko
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
LeoVasanko
1bed2c39d8
Implement code word based remote authentication ( #1 )
...
Add comprehensive remote authentication system allowing users to log in from one device by authenticating from another trusted device. Features include:
- Proof of Work (PoW) protection using PBKDF2-SHA512 to prevent abuse
- Simple pairing codes (3 words) protected by dynamic PoW difficulty
- Autocomplete pairing code input with error checking
- Real-time WebSocket communication between devices
Unlike device addition links and reset links with QR codes that only allow adding an authentication method, and that work offline over the duration of several days, this mechanism is strictly online, with 5 minute time limit.
2025-12-08 23:56:48 +00:00
LeoVasanko
127e06179b
More robust server startup, startup logo and info screen, renewed devmode script.
2025-12-05 19:06:42 +00:00
LeoVasanko
208115ebc3
Project renamed to Paskia.
2025-12-05 13:17:52 +00:00