Leo Vasanko
bb2f35b0a7
Cleaned Org Admin styling.
2026-02-19 00:37:44 +00:00
Leo Vasanko
ceed798834
Simplified My Profile authentication flows, fixed some UX issues with reauth cancelled/accepted leading to incorrect states.
2026-02-18 19:04:02 +00:00
Leo Vasanko
3a4db0cb12
Always load user's theme from API if available, and update the localStorage cache. Previously in various situations the old cached value was being used instead, leading to inconsistent theming or wrong themeselector readout.
2026-02-18 18:35:41 +00:00
Leo Vasanko
5c4f6908cd
Imports to top of file.
2026-02-18 17:47:57 +00:00
Leo Vasanko
cbfa68f3dc
Fix HostProfile user properties access.
2026-02-18 03:47:08 +00:00
LeoVasanko
4604a65646
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
Leo Vasanko
148a51fee3
More minimalistic light theme. UI hint for org admin user/role management.
2026-02-14 18:36:20 +00:00
Leo Vasanko
c621a14b8d
API cleanup, using msgspec structs rather than raw responses. Admin app cleanup, better breadcrumbs.
2026-02-13 20:09:41 +00:00
Leo Vasanko
a9cf518296
Add version indication and link to our site on profile page (bottom right corner).
2026-02-11 01:36:58 +00:00
Leo Vasanko
0af7d4b939
Less eagerly enable very wide layout for user profile (only if more than 8 items for passkeys or per site sessions).
2026-02-11 01:24:23 +00:00
Leo Vasanko
419f69cef5
Style overhaul.
2026-02-11 01:18:19 +00:00
Leo Vasanko
fa378eb82e
Improved client IP and UA handling.
2026-02-05 18:02:23 +00:00
Leo Vasanko
e1f6c85ced
Improved theme picker
2026-02-05 16:19:06 +00:00
Leo Vasanko
df8bbef8de
Styling updates, more robust dynamic/userpref light/dark switching. Sync with paskia-js.
2026-02-05 15:34:02 +00:00
Leo Vasanko
9a6614f057
Improved UI feedback on registration link creation.
2026-02-05 14:26:11 +00:00
Leo Vasanko
4953920dbf
Better UI for role deletions.
2026-02-05 14:05:36 +00:00
Leo Vasanko
f39986412a
API/DB cleanup for flat URLs that don't include org where users etc. are referred to. Implement user deletion in admin app and API, UI improvement. Reset token DB factory function revised to create passphrase and key internally. Removed unneeded functions and args, using update_user_role instead of a separate deleted _in_organization function.
2026-02-05 14:05:31 +00:00
Leo Vasanko
6f1dfd1ab5
Missing theme file. Added favicon.
2026-01-31 00:25:38 +00:00
Leo Vasanko
cc439aaf12
Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins).
2026-01-30 23:31:06 +00:00
Leo Vasanko
0096727b41
Light/dark override for in-app login dialogs to match app style e.g. light only
2026-01-30 23:00:02 +00:00
Leo Vasanko
5fc5226480
Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced).
2026-01-29 19:46:26 +00:00
Leo Vasanko
d8743d9f90
Refactor to separate paskia lib functionality generally useful for various apps.
2026-01-29 16:55:46 +00:00
Leo Vasanko
760b109eef
Consistent and stronger session revalidation checks in Auth profile and Admin App. Fix missing handling of link generation network errors.
2026-01-29 16:02:29 +00:00
Leo Vasanko
8a6540aa91
Fix background task still running twice, and add a check to prevent that happening again (double expiry).
2026-01-27 23:51:13 +00:00
Leo Vasanko
071a7b9e0b
Remove credentials: 'include', a mechanism that we don't actually use.
2026-01-27 15:23:19 +00:00
Leo Vasanko
2413a32bda
Update the API to use new naming matching database.
2026-01-27 02:22:29 +00:00
Leo Vasanko
f6e995184f
Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps.
2026-01-26 19:40:48 +00:00
Leo Vasanko
2227a9bf6f
Refer permissions by UUID rather than scope.
2026-01-24 00:06:08 +00:00
Leo Vasanko
c6dadd283d
Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org.
2026-01-23 15:41:23 +00:00
Leo Vasanko
4c1db37c73
Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements.
2026-01-23 15:11:01 +00:00
Leo Vasanko
253387be97
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
Leo Vasanko
cdcaa5a199
Remove layout max width.
2025-12-10 20:53:59 +00:00
Leo Vasanko
1143032eca
Adopt <dialog> for our modals to tap into browser built-in functionality.
2025-12-10 19:41:55 +00:00
Leo Vasanko
683a912899
Revised light color scheme for a more professional look.
2025-12-10 19:40:59 +00:00
Leo Vasanko
727db38bc7
UX: Close the QR code/link dialog automatically when the code is click-to-copied.
2025-12-10 19:07:56 +00:00
Leo Vasanko
b2eb5e5e36
Fix regression from adding color-scheme: light dark improperly at :root (html) rather than at body.
2025-12-10 18:47:56 +00:00
Leo Vasanko
ccbe0f2f6f
Improved breadcrumbs on auth host.
2025-12-10 18:20:37 +00:00
Leo Vasanko
f8b927c012
Fix button row layout problem from the responsive layout cleanup before, that was causing them display stretched to full window width. Now they only shrink.
2025-12-10 17:43:10 +00:00
Leo Vasanko
8310d9f0b5
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
Leo Vasanko
b9b6c9356f
Change input placeholder that was improperly triggering Bitwarden to complete username in it. BW does not respect autocomplete at all.
2025-12-10 16:56:19 +00:00
Leo Vasanko
272964f086
Fix mobile browser code word autocomplete (on space that wasn't detected correctly).
2025-12-10 16:40:58 +00:00
Leo Vasanko
1b7b3c028f
Automatic light/dark mode. Fixes a cursor color issue on Huawei Browser, and is generally a good idea.
2025-12-10 16:40:54 +00:00
Leo Vasanko
58f659ee85
Simplify responsive layouts. Remove button vertical stacking and always fit them on the same row.
2025-12-10 16:11:43 +00:00
LeoVasanko
2487759628
Implement keyboard navigation using arrow keys in the whole application. ( #2 )
...
Reviewed-on: #2
2025-12-10 15:43:40 +00:00
Leo Vasanko
033e735248
Fix scrolling behaviour when backdrop dialogs appear.
2025-12-10 12:07:43 +00:00
Leo Vasanko
4e5014be69
Improved session group (per site) styling and UX.
2025-12-10 01:11:43 +00:00
Leo Vasanko
89268adfe2
Consistent use of red X only for deletion, and using only it for deletion rather than trashbin, while using non-red X for window close button.
2025-12-10 00:06:34 +00:00
Leo Vasanko
4a5d61cab1
Cleaner up registration link creation. Don't show the dialog until when there is a valid link. Implement a global blur backdrop with nicer effect and proper scrollbar handling (avoiding layout shifting a bit). Use the global backdrop to ensure consistent visuals between authentication and the modal being shown, along with in/out transitions.
2025-12-09 23:58:04 +00:00
Leo Vasanko
ff8acaa5f5
Code word input overhaul, more accurate cursor and selection processing. New styling for the widget that conforms with browser default style (focus outline).
2025-12-09 23:07:15 +00:00
Leo Vasanko
07fb9f79a6
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00