LeoVasanko
9b7855c0af
Faster and simplified hash_secret() that directly produces urlsafe entries.
2026-02-18 23:02:36 +00:00
LeoVasanko
68dccc1378
OAuth2 OpenID Connect provider support, API and DB refactoring ( #3 )
...
Allows Paskia to authenticate the user to a client site.
- User friendly client registration flow on the admin app
- Redirect-based authentication flow (per spec)
- Backchannel logout both ways to keep sessions synchronized
- Groups integrated with Paskia's permission system
- Adds email, preferred username and telephone fields on user profile
- All new user basic info layout to show the new information, better looks
- API and DB structures redesigned
- Various unrelated fixes to theming and layout
2026-02-18 02:40:27 +00:00
LeoVasanko
a944224027
Inline get_config, rewrite update_config, DB init Config and rp_id defaults changed.
2026-02-10 23:01:02 +00:00
LeoVasanko
2237e6b5e9
Db operations: bootstrap separated to its own module.
2026-02-10 22:08:54 +00:00
LeoVasanko
8b6bdd0f9c
Calculate session expiry times in operations, using a common now timestamp for everything.
2026-02-10 21:35:56 +00:00
LeoVasanko
250189dbe5
Update tests for the latest changes.
2026-02-05 19:26:20 +00:00
LeoVasanko
d16d1ed1c2
Make database changes outside of transaction a fatal error. Fix bootstrap and migrate to work with various latest changes.
2026-01-28 19:04:00 +00:00
LeoVasanko
7329223784
Implement full ORM. Various other cleanup.
2026-01-28 17:19:56 +00:00
LeoVasanko
cf1124c251
DB transactions cleanup, better actor/user data. Simplified admin API. Use UUID to refer to a specific permission in admin API. Other cleanup.
2026-01-27 21:48:21 +00:00
LeoVasanko
7504aaf7e0
Move imports to top of file.
2026-01-27 20:16:32 +00:00
LeoVasanko
7530d7a710
DB cleanup continued: Made the working copy data public in DB class.
2026-01-27 18:02:16 +00:00
LeoVasanko
8f862fb4d1
Consistently use UUID type in APIs instead of UUID str as option.
2026-01-27 16:24:02 +00:00
LeoVasanko
86966526c4
Finalize database API class merge.
2026-01-27 03:00:18 +00:00
LeoVasanko
9bdca1f43a
Finish the database key-in-object refactoring.
2026-01-27 02:11:09 +00:00
LeoVasanko
aae33e60ce
Fix errors where permission scopes were still expected for indexing.
2026-01-24 00:58:18 +00:00
LeoVasanko
cebef8adfc
Large refactoring for better JSONL context. Switched back the urlsafe for session tokens that need to be passed in URLs. Other minor fixes.
2026-01-24 00:40:32 +00:00
LeoVasanko
f9d23a196c
Database refactor to separate modules.
2026-01-23 18:27:12 +00:00
LeoVasanko
3430c7f0cf
Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead.
2026-01-23 13:54:31 +00:00
LeoVasanko
236d52aa55
Replace session.renewed with .expiry for consistency with other expiring items. Fix migration script.
2026-01-23 01:39:59 +00:00
LeoVasanko
02e04da2c4
Database cleanup: make it synchronous because we work with in-memory data. Defer writes to disk and cleanup to background task. Tests passing.
2026-01-23 01:22:47 +00:00
LeoVasanko
7f3763b46d
Replace SQL database with JSONL based solution that keeps history.
2026-01-23 00:54:37 +00:00
LeoVasanko
83419d1845
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
2025-12-06 04:45:26 +00:00