Leo Vasanko
f8b927c012
Fix button row layout problem from the responsive layout cleanup before, that was causing them display stretched to full window width. Now they only shrink.
2025-12-10 17:43:10 +00:00
Leo Vasanko
472fedc3ae
Fix devserver script misprocessing in some situations where auth-host was being used. Deduplicate origins on server end.
2025-12-10 17:39:09 +00:00
Leo Vasanko
8310d9f0b5
Fix link copy toast messages, remove custom toast in favor of authStore, remove a component that was no longer used.
2025-12-10 17:18:48 +00:00
Leo Vasanko
b9b6c9356f
Change input placeholder that was improperly triggering Bitwarden to complete username in it. BW does not respect autocomplete at all.
2025-12-10 16:56:19 +00:00
Leo Vasanko
272964f086
Fix mobile browser code word autocomplete (on space that wasn't detected correctly).
2025-12-10 16:40:58 +00:00
Leo Vasanko
1b7b3c028f
Automatic light/dark mode. Fixes a cursor color issue on Huawei Browser, and is generally a good idea.
2025-12-10 16:40:54 +00:00
Leo Vasanko
58f659ee85
Simplify responsive layouts. Remove button vertical stacking and always fit them on the same row.
2025-12-10 16:11:43 +00:00
Leo Vasanko
033e735248
Fix scrolling behaviour when backdrop dialogs appear.
2025-12-10 12:07:43 +00:00
Leo Vasanko
4e5014be69
Improved session group (per site) styling and UX.
2025-12-10 01:11:43 +00:00
Leo Vasanko
89268adfe2
Consistent use of red X only for deletion, and using only it for deletion rather than trashbin, while using non-red X for window close button.
2025-12-10 00:06:34 +00:00
Leo Vasanko
4a5d61cab1
Cleaner up registration link creation. Don't show the dialog until when there is a valid link. Implement a global blur backdrop with nicer effect and proper scrollbar handling (avoiding layout shifting a bit). Use the global backdrop to ensure consistent visuals between authentication and the modal being shown, along with in/out transitions.
2025-12-09 23:58:04 +00:00
Leo Vasanko
ff8acaa5f5
Code word input overhaul, more accurate cursor and selection processing. New styling for the widget that conforms with browser default style (focus outline).
2025-12-09 23:07:15 +00:00
Leo Vasanko
07fb9f79a6
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
2025-12-09 21:57:33 +00:00
Leo Vasanko
48a8f575ec
Profile view UX improvements. More consistent styling across the application.
2025-12-09 21:20:29 +00:00
Leo Vasanko
bf8c734bf7
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
2025-12-09 17:04:20 +00:00
Leo Vasanko
9835c13e25
Remove trash bin icons from tab order. Instead, implement Delete key support (Backspace accepted on Apple devices).
2025-12-09 16:54:46 +00:00
Leo Vasanko
2776a8d83a
Process IPv6 display into short format including only the network prefix, and sharing the same code also for comparisons where needed.
2025-12-09 16:33:16 +00:00
Leo Vasanko
83245bc1c8
Rename base64 functions such that imports don't need renaming.
2025-12-09 15:55:03 +00:00
Leo Vasanko
e1e4a211ec
Fix missing credential_uuid in admin user detail API that was causing linkage between sessions and their passkeys not show up.
2025-12-09 15:34:05 +00:00
Leo Vasanko
2bac94a548
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
2025-12-06 04:45:26 +00:00
Leo Vasanko
bfa3281aca
Added E2E restricted API flow tests and fixed earlier failing tests. All passing. Coverage 51% backend, 74% frontend.
2025-12-06 03:43:28 +00:00
Leo Vasanko
0203bce05e
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
2025-12-06 03:39:05 +00:00
Leo Vasanko
8d723155ba
Fixed and updated E2E test suite. Added user credential registration tests. Coverage for backend and frontend.
2025-12-06 00:52:35 +00:00
Leo Vasanko
0b17681907
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
2025-12-06 00:51:18 +00:00
Leo Vasanko
da503a3081
More robust server startup, startup logo and info screen, renewed devmode script.
2025-12-05 19:06:42 +00:00
Leo Vasanko
8b98cb6325
Updated documentation.
2025-12-05 16:15:50 +00:00
Leo Vasanko
4b16037426
Project renamed to Paskia.
2025-12-05 13:24:34 +00:00
Leo Vasanko
9d7ace8fb5
Refactor dev mode into a source repo script (remove dev subcommand from package).
2025-12-05 13:08:44 +00:00
Leo Vasanko
39c06620c4
Updated E2E tests.
2025-12-04 04:44:58 +00:00
Leo Vasanko
8011a0d910
Make dev mode run without static files, only serving assets in production.
2025-12-03 22:15:26 -06:00
Leo Vasanko
4c34217846
Cleanup old hostapp files (finished, working).
2025-12-03 22:06:54 -06:00
Leo Vasanko
5c72777c2f
Missing new component.
2025-12-03 22:03:33 -06:00
Leo Vasanko
18eed4654f
Integrate host app to main app (WIP).
2025-12-03 22:00:47 -06:00
Leo Vasanko
b373a84065
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
2025-12-03 21:19:40 -06:00
Leo Vasanko
7983d9b170
Brought examples directly to front page.
2025-12-03 21:10:08 -06:00
Leo Vasanko
bc4254ad18
Fix view switching of restricted app.
2025-12-03 19:46:36 -06:00
Leo Vasanko
d541377798
Make restricted app use simple fetch that doesn't do API authentication (recursively).
2025-12-03 18:20:14 -06:00
Leo Vasanko
7c82727d28
Fixed and simplified examples.
2025-12-03 18:08:52 -06:00
Leo Vasanko
afbd9606db
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
2025-12-03 18:01:47 -06:00
Leo Vasanko
9b73684082
Log authentication options on the client.
2025-12-03 17:07:44 -06:00
Leo Vasanko
9786c2a5a8
Improved dialog layout with separate mobile portrait mode.
2025-12-03 16:06:32 -06:00
Leo Vasanko
3e10e082e2
Fix infinitely nested login iframes when the restricted app notices it needs login.
2025-12-03 15:56:17 -06:00
Leo Vasanko
7a70c933c9
Various fixes and cleanup, regressions from prior commits.
2025-12-03 15:40:59 -06:00
Leo Vasanko
6a7b1a876e
Fix syntax error in reset app created by earlier commit.
2025-12-03 14:31:13 -06:00
Leo Vasanko
ad63d3fb3a
Better static files handling on backend, when in dev mode: fetch from vite.
2025-12-03 14:30:02 -06:00
Leo Vasanko
9488f69e53
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
2025-12-03 13:58:18 -06:00
Leo Vasanko
1610869fae
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
2025-12-03 13:35:44 -06:00
Leo Vasanko
219dd70665
Viewing linked passkeys/sessions (by clicking either one of them).
2025-12-03 13:21:52 -06:00
Leo Vasanko
4306323c44
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
2025-12-03 13:00:24 -06:00
Leo Vasanko
ceb99de738
Improved auth profile UX, consistent transparent-blur dialog background everywhere.
2025-12-03 12:30:23 -06:00
Leo Vasanko
ad374f5dda
Formatting, tidy up, transparent auth dialog background.
2025-12-03 11:33:24 -06:00
Leo Vasanko
1ffc918a88
Improved apiFetch and jsonFetch functions.
2025-12-03 11:26:38 -06:00
Leo Vasanko
1f75e0a305
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
2025-12-03 11:17:02 -06:00
Leo Vasanko
7b0a9c2a2a
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
2025-12-03 10:58:48 -06:00
Leo Vasanko
1c985527cf
Add E2E tests to register and verify passkey.
2025-12-03 02:52:39 +00:00
Leo Vasanko
6003189da2
Always use timezone aware UTC time.
2025-12-03 01:36:15 +00:00
Leo Vasanko
2e9895443b
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
2025-12-03 01:32:05 +00:00
Leo Vasanko
bd13dbd1a0
Implement session termination in admin API, for completeness.
2025-12-03 01:20:52 +00:00
Leo Vasanko
ca8d65ad25
Improved profile view layout.
2025-12-03 01:04:07 +00:00
Leo Vasanko
70411fa77b
Improved profile view layout.
2025-12-03 00:52:52 +00:00
Leo Vasanko
3967e93c37
Fix examples folder serving broken a couple of commits ago.
2025-12-03 00:06:32 +00:00
Leo Vasanko
10ce0126b0
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
2025-12-02 23:39:31 +00:00
Leo Vasanko
aed48de38e
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
2025-12-02 22:41:12 +00:00
Leo Vasanko
c83450dace
Major refactor of frontend source tree such that paths better match where they are served.
2025-12-02 22:09:07 +00:00
Leo Vasanko
123a62549b
Refactor restricted app paths and naming.
2025-12-02 19:10:13 +00:00
Leo Vasanko
2a5f06d707
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
2025-12-02 18:34:59 +00:00
Leo Vasanko
3441a7a2b3
Remove backend access control, now that the profile and admin apps handle that via API.
2025-12-02 18:25:58 +00:00
Leo Vasanko
7ace4dcb4b
Fix the back buttons (navigate back if you can but close if it was a new window).
2025-12-02 18:13:23 +00:00
Leo Vasanko
6f9f4aefc1
Implement Forbidden view for API calls, cleanup and better UX.
2025-12-02 17:36:37 +00:00
Leo Vasanko
a05d4aec81
Better error messages from backend, avoid bad toasts, cleanup of session validation.
2025-12-02 16:37:27 +00:00
Leo Vasanko
77d8e97dc9
Update admin app authentication in API mode too, reusing components between it and the main app.
2025-12-02 15:42:55 +00:00
Leo Vasanko
d1a7a53c19
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
2025-12-02 15:25:31 +00:00
Leo Vasanko
2c777661b8
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
2025-12-02 14:30:31 +00:00
Leo Vasanko
cb26c61d5f
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
2025-12-02 03:10:16 +00:00
Leo Vasanko
74a7723300
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/ .
2025-12-01 20:07:26 +00:00
Leo Vasanko
0678d7f9ec
Updated build-frontend script, now uses deno, npm, bun in this order.
2025-12-01 19:25:08 +00:00
Leo Vasanko
07525b47ae
Centralise all cookie handling to session.py.
2025-10-04 18:48:24 -06:00
Leo Vasanko
1ad1644b64
Refactor /api/user/* to its own module.
2025-10-04 18:41:35 -06:00
Leo Vasanko
876215f1c1
Reset dialog UX improved.
2025-10-04 18:40:46 -06:00
Leo Vasanko
59e7e40128
Harmonise ProfileView and HostApp.
2025-10-04 18:14:17 -06:00
Leo Vasanko
a0da799c9e
Tuning the host app.
2025-10-04 18:06:47 -06:00
Leo Vasanko
94efb00e34
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
2025-10-04 17:55:08 -06:00
Leo Vasanko
f9f4d59c6b
Deny creating sessions for hosts other than rp-id subdomains.
2025-10-04 17:26:03 -06:00
Leo Vasanko
45f9870d0d
WebSockets must use origin for finding the host calling them.
2025-10-04 17:16:51 -06:00
Leo Vasanko
2a81544701
Correction on restricted path checking (auth-host).
2025-10-04 16:59:05 -06:00
Leo Vasanko
a60c1bd5f5
Refactor auth-host redirection middleware to its own module.
...
Implement redirection to remove /auth/ from UI URLs when on auth-host.
2025-10-04 16:49:23 -06:00
Leo Vasanko
229f066533
Add validation of the CLI specified --auth-host (needs to be within rp-id).
2025-10-04 16:35:55 -06:00
Leo Vasanko
97f653e116
Fix deletion of session cookie on host logout.
2025-10-04 16:26:36 -06:00
Leo Vasanko
29be642dbe
Better UX for profile view logout buttons.
2025-10-04 16:22:16 -06:00
Leo Vasanko
bfb11cc20f
A major refactoring for more consistent and stricter flows.
...
- Force using the dedicated authentication site configured via auth-host
- Stricter host validation
- Using the restricted app consistently for all access control (instead of the old loginview).
2025-10-04 15:55:43 -06:00
Leo Vasanko
389e05730b
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
2025-10-04 08:59:51 -06:00
Leo Vasanko
79b6c50a9c
More consistent shared styling between credential and session cards.
2025-10-04 08:32:27 -06:00
Leo Vasanko
591ea626bf
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
2025-10-03 18:31:54 -06:00
Leo Vasanko
963ab06664
Use git tag versioning for the Python project.
2025-10-02 16:09:26 -06:00
Leo Vasanko
bb35e57ba4
Fix reset link logic to include /auth when no configured auth-host.
2025-10-02 15:57:20 -06:00
Leo Vasanko
5d8304bbd9
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
...
Support user-navigable URLs at / as well as /auth/, allowing for a dedicated authentication site with pretty URLs.
2025-10-02 15:44:48 -06:00
Leo Vasanko
fbfd0bbb47
Create registration links on the same host (subdomain) that is being used by the one who creates it.
2025-10-02 12:30:50 -06:00
Leo Vasanko
eb38995cca
Version 0.2.0
2025-09-30 17:04:53 -06:00
Leo Vasanko
382341e5ee
Make the login/reset/forbidden dialogs look better.
2025-09-30 17:03:51 -06:00
Leo Vasanko
ed7d3ee0fc
Admin app: guard rails extended, consistent styling, also share styling with main app.
2025-09-30 16:38:14 -06:00