Compare commits

...
121 Commits
Author SHA1 Message Date
LeoVasanko 0f51f8501d Console startup box themed as well. 2026-01-31 00:30:14 +00:00
LeoVasanko a7e6eb7341 Missing theme file. Added favicon. 2026-01-31 00:25:38 +00:00
LeoVasanko 1800dc12ae Light/dark selection in user profile, if set this is preferred on the whole system, together with app overrides (the first one on the URL wins). 2026-01-30 23:31:06 +00:00
LeoVasanko cc55474e62 Light/dark override for in-app login dialogs to match app style e.g. light only 2026-01-30 22:59:52 +00:00
LeoVasanko 8ac2c8e5fa Screenshots on README. 2026-01-29 22:50:54 +00:00
LeoVasanko 2ee8ddf1d1 Log proper action for delete_session depending on what function it performs: logout, delete_session (user's own) or admin:delete_session. 2026-01-29 22:44:22 +00:00
LeoVasanko d58b3742b1 Smarter change logging on console, properly display newly created items (not available via jsondiffs). 2026-01-29 22:39:16 +00:00
LeoVasanko 5879be39a5 Better change entry logging. 2026-01-29 22:09:26 +00:00
LeoVasanko 5b3406025c Silence type checker about our unconventional imports. 2026-01-29 22:09:03 +00:00
LeoVasanko dda57ac27d Fix WS access log IP margin size change missed in earlier commit. 2026-01-29 21:39:30 +00:00
LeoVasanko 5e12dcba76 Add paskia-js to Python build; update build-frontend to use fastapi-vue utils for JS_RUNTIME that also can be set via env now. Fix paskia-js compatibility issue with deno, now works with all three runtimes. 2026-01-29 21:33:09 +00:00
LeoVasanko be7a9e7f00 Smarter access log formatting with IPv6. 2026-01-29 21:17:50 +00:00
LeoVasanko 3d2151fed7 Add support for perm=foo+bar to specify multiple scopes that are required. Multiple perm args are acceptable too. Pretty logging of permission denied errors. 2026-01-29 21:11:29 +00:00
LeoVasanko 58b56a09a4 Restrict remote auth to the existing granting user's credentials. 2026-01-29 20:24:26 +00:00
LeoVasanko 731b36b456 Cleanup auth WS code, refactor to remove duplication and pass proper context. 2026-01-29 20:15:01 +00:00
LeoVasanko 8f9cd1124c Add missing context on update_session. 2026-01-29 19:51:56 +00:00
LeoVasanko 7e49ef296a Create a stand-alone paskia npm package (paskia-js). Make the frontend use it (but from source tree to keep synced). 2026-01-29 19:46:26 +00:00
LeoVasanko af35ff3d4c Add a screenshot. 2026-01-29 19:15:17 +00:00
LeoVasanko dac1415a86 More of a normal white path color. 2026-01-29 16:57:30 +00:00
LeoVasanko 433844cf08 Refactor to separate paskia lib functionality generally useful for various apps. 2026-01-29 16:55:46 +00:00
LeoVasanko c9ea1c8948 Consistent and stronger session revalidation checks in Auth profile and Admin App. Fix missing handling of link generation network errors. 2026-01-29 16:02:29 +00:00
LeoVasanko 58f46c6abf Logging cleanup, better colors, suppress more useless messages. Enable reloading in devmode again (needs uvicorn.run to function). 2026-01-29 14:48:59 +00:00
LeoVasanko 7c4418e631 Smarter change logging on console. 2026-01-28 23:22:03 +00:00
LeoVasanko 1648c8641f Improved access logging. 2026-01-28 23:01:35 +00:00
LeoVasanko 63eb088dbd Cleanup 2026-01-28 20:31:33 +00:00
LeoVasanko e88cc004dd Implement versioning in metadata, outside of the DB itself. Cleanup to migration handling and changes. Implement new migration step using msgspec normalization. 2026-01-28 20:21:09 +00:00
LeoVasanko 76921e8b31 Add migrate:msgspec for changes in schema that don't require version bump. Rename the other migrations to migrate:sql and migrate:v{N}. 2026-01-28 19:24:15 +00:00
LeoVasanko c1b0aab296 Cleanup 2026-01-28 19:17:24 +00:00
LeoVasanko 8f89bb6d4b Modules missing git add 2026-01-28 19:04:18 +00:00
LeoVasanko d16d1ed1c2 Make database changes outside of transaction a fatal error. Fix bootstrap and migrate to work with various latest changes. 2026-01-28 19:04:00 +00:00
LeoVasanko 2cfca81672 Fix a bug with validate returning 401 when a session was refreshed. Simplify & cleanup. 2026-01-28 18:45:02 +00:00
LeoVasanko ce300ebdaf API to use msgspec structs as well. 2026-01-28 18:31:45 +00:00
LeoVasanko 7329223784 Implement full ORM. Various other cleanup. 2026-01-28 17:19:56 +00:00
LeoVasanko c8d659b5ca Move get_session_context to DB.session_ctx(). 2026-01-28 14:52:18 +00:00
LeoVasanko 29ea6426fe Problem solved, remove extraneous migration, reset to v1. 2026-01-28 02:29:53 +00:00
LeoVasanko 88a170a37b Debug DB problem 2026-01-28 02:27:26 +00:00
LeoVasanko 38d240d86d Credential update was being done out of transaction, now part of login. 2026-01-28 02:22:47 +00:00
LeoVasanko 53362b8061 Debug DB problem 2026-01-28 02:19:54 +00:00
LeoVasanko d3d5f5a3c8 Remove get_session_context setting of host (now read only op as expected). Make session host, ip and user_agent always set (the ua potentially empty string). 2026-01-28 02:14:34 +00:00
LeoVasanko d156fb9221 Fix migration logic. 2026-01-28 02:02:18 +00:00
LeoVasanko f868bc59d1 Fix migration logic. 2026-01-28 01:58:36 +00:00
LeoVasanko 0022986d4e Implement migration to remove created_at timestamp from Orgs that already has one, bumping db v1. 2026-01-28 01:52:33 +00:00
LeoVasanko b08cca754f Remove Org.created_at to maintain compatibility with old versions (the field was not being used). 2026-01-28 01:31:35 +00:00
LeoVasanko aa58f08bc5 Hardened PATCH handling (only allow updating select fields). Hardened DB transactions, rollback. 2026-01-28 01:13:05 +00:00
LeoVasanko 1062b5d6c8 Fix background task still running twice, and add a check to prevent that happening again (double expiry). 2026-01-27 23:51:13 +00:00
LeoVasanko 3d49cbf2d6 Disable API docs that display very much broken due to missing request/response typing. 2026-01-27 23:27:42 +00:00
LeoVasanko 13c49aebfd Remove unnecessary use of async now that db access doesn't need awaiting. 2026-01-27 23:16:17 +00:00
LeoVasanko abec77d561 Broken import 2026-01-27 22:46:49 +00:00
LeoVasanko 9b505ff553 DB background worker cleanup, avoid issue with double cleanup. Faster write to disk. 2026-01-27 22:21:33 +00:00
LeoVasanko ddd70e6130 Cleaner typing to avoid some checking errors. 2026-01-27 22:04:14 +00:00
LeoVasanko cf1124c251 DB transactions cleanup, better actor/user data. Simplified admin API. Use UUID to refer to a specific permission in admin API. Other cleanup. 2026-01-27 21:48:21 +00:00
LeoVasanko 7504aaf7e0 Move imports to top of file. 2026-01-27 20:16:32 +00:00
LeoVasanko e8247a2c7f Remove most remaining DB getters. Add ws auth chat helper function to avoid repetition, along with the existing register chat in wschat.py. 2026-01-27 20:01:17 +00:00
LeoVasanko 968964c4c9 Remove db.get_session. 2026-01-27 18:28:32 +00:00
LeoVasanko 6aa1a08e39 Remove list_sessions_for_user, inline db access at call sites. 2026-01-27 18:25:29 +00:00
LeoVasanko 31f40d874c DB cleanup: removed get_permission_organizations and build_org. Using db.data() for read access at call sites. 2026-01-27 18:23:17 +00:00
LeoVasanko 7530d7a710 DB cleanup continued: Made the working copy data public in DB class. 2026-01-27 18:02:16 +00:00
LeoVasanko 90d5f0e45f Remove runtime expiry checks; the db background cleanup makes this unnecessary. 2026-01-27 16:55:07 +00:00
LeoVasanko f0d1b86d6b Database cleanup continues, build functions replaced by post init. Simplified some APIs. 2026-01-27 16:53:13 +00:00
LeoVasanko dbdd1dbd3c Missing import in migrate script. 2026-01-27 16:26:48 +00:00
LeoVasanko 8f862fb4d1 Consistently use UUID type in APIs instead of UUID str as option. 2026-01-27 16:24:02 +00:00
LeoVasanko cfb917da46 DB getter refactoring. Documented call sites. Added separate function for by-scope permission lookup. 2026-01-27 15:54:28 +00:00
LeoVasanko 3a8e7d1f4f Remove credentials: 'include', a mechanism that we don't actually use. 2026-01-27 15:23:19 +00:00
LeoVasanko 86966526c4 Finalize database API class merge. 2026-01-27 03:00:18 +00:00
LeoVasanko 3196aa7688 Refactor API to match database, no _uuid postfixes. 2026-01-27 02:32:46 +00:00
LeoVasanko 2fadaea19c Update E2E tests with changes since a while back. 2026-01-27 02:24:09 +00:00
LeoVasanko cb84a81a06 Update the API to use new naming matching database. 2026-01-27 02:22:29 +00:00
LeoVasanko 9bdca1f43a Finish the database key-in-object refactoring. 2026-01-27 02:11:09 +00:00
LeoVasanko 0f29544bdb Database cleanup, better UUID passing and construction (User model). 2026-01-27 01:25:52 +00:00
LeoVasanko 4ddaa9fdf4 Cleanup and bugfixes on Bootstrap and JSONL handling. 2026-01-26 23:54:03 +00:00
LeoVasanko 7e568dbd10 Refactor validate endpoint to return session context, leaving user-info only for extra profile data. Completely separate token-info for reset tokens. Simplified by reusing same data structures in various places and mandating fields to have values not needing fallbacks. Implemented consistent AccessDenied view in profile and admin apps. 2026-01-26 19:40:48 +00:00
LeoVasanko fbc6108b7a Fix frontend-build location. Cleanup. 2026-01-25 03:26:22 +00:00
LeoVasanko 6e649f1f07 Fix test expected HTTP code. 2026-01-25 03:20:28 +00:00
LeoVasanko 8d68e5d237 Add missing set_session_host on dunder all. 2026-01-25 03:17:32 +00:00
LeoVasanko 5ee7443801 Use fastapi-vue-setup, merging its template scripts to old Paskia entry point and devserver. Simplified CLI, no longer uses serve subcommand. Fixed the URL displayed on banner to show to actual frontend/caddy server even in devmode. 2026-01-25 03:15:50 +00:00
LeoVasanko 2100a7e14f Logging cleanup, linter. 2026-01-24 01:08:00 +00:00
LeoVasanko aae33e60ce Fix errors where permission scopes were still expected for indexing. 2026-01-24 00:58:18 +00:00
LeoVasanko cebef8adfc Large refactoring for better JSONL context. Switched back the urlsafe for session tokens that need to be passed in URLs. Other minor fixes. 2026-01-24 00:40:32 +00:00
LeoVasanko 57a9c60557 Don't load existing JSONL on migrate. 2026-01-24 00:08:21 +00:00
LeoVasanko a9ef20969e Refer permissions by UUID rather than scope. 2026-01-24 00:06:08 +00:00
LeoVasanko 57748876cb Debug JSONL updates. 2026-01-23 23:49:11 +00:00
LeoVasanko ba552e24cd Debug JSONL updates. 2026-01-23 23:41:47 +00:00
LeoVasanko dbe4149b63 Debug JSONL updates. 2026-01-23 23:35:00 +00:00
LeoVasanko 3d5f82c3df Debug JSONL updates. 2026-01-23 23:29:47 +00:00
LeoVasanko 2a005692ee Fixes to JSONL management, starting from empty state rather than default DB. 2026-01-23 21:31:54 +00:00
LeoVasanko 2ec6314264 Simplify session and reset token formats; removes the token utility functions entirely. 2026-01-23 20:53:03 +00:00
LeoVasanko ae4c982a30 Fix actor fields and transactions for API operations as they are recorded to DB. 2026-01-23 20:19:33 +00:00
LeoVasanko c2933d60c2 Update migrate script with the latest database changes. 2026-01-23 19:56:44 +00:00
LeoVasanko d4ebc1bf99 Record user UUID as actor for API access. 2026-01-23 19:55:54 +00:00
LeoVasanko 0f857ffb78 Cleanup, add database versioning. 2026-01-23 19:22:23 +00:00
LeoVasanko b7ebe68665 Refactor to use UUID and bytes rather than str keys in msgspec structs because the module can automatically convert these. 2026-01-23 18:47:56 +00:00
LeoVasanko f9d23a196c Database refactor to separate modules. 2026-01-23 18:27:12 +00:00
LeoVasanko 2c6a5c72d9 Updated database to use async background worker, making changes lock-free synchronous ops. 2026-01-23 15:57:16 +00:00
LeoVasanko c13044c085 Change PUT to PATCH for intent-based updates, avoiding override of fields not intended to change. This preserves role permissions matrix even if the permission is temporarily removed from the org. 2026-01-23 15:41:23 +00:00
LeoVasanko 2c783498a4 Better handling of Org Admin permission. More guardrails for Master Admin not locking himself out by changes. Admin app UI improvements. 2026-01-23 15:11:01 +00:00
LeoVasanko 3430c7f0cf Permissions refactor. Permissions have UUID and scope (previously id) and the latter no longer needs to be unique. Org admin uses a single global permission now. Domain scoped permissions. Removed from user info the admin fields, use effective_permission checks instead. 2026-01-23 13:54:31 +00:00
LeoVasanko 236d52aa55 Replace session.renewed with .expiry for consistency with other expiring items. Fix migration script. 2026-01-23 01:39:59 +00:00
LeoVasanko 02e04da2c4 Database cleanup: make it synchronous because we work with in-memory data. Defer writes to disk and cleanup to background task. Tests passing. 2026-01-23 01:22:47 +00:00
LeoVasanko 7f3763b46d Replace SQL database with JSONL based solution that keeps history. 2026-01-23 00:54:37 +00:00
LeoVasanko 0fe55b2b62 Update docs/Caddy.md 2025-12-19 22:53:10 +00:00
LeoVasanko ccf71bf0a3 Docs updates. 2025-12-19 21:09:56 +00:00
LeoVasanko cdaeecb179 Docs updates. 2025-12-19 21:08:40 +00:00
LeoVasanko 82cdee51e4 Docs updates. 2025-12-19 21:07:20 +00:00
LeoVasanko 851e0793a6 Docs updates. 2025-12-19 21:06:27 +00:00
LeoVasanko cd681a0599 Docs updates. 2025-12-19 21:01:05 +00:00
LeoVasanko 71cb01cfda Docs updates. 2025-12-19 21:00:16 +00:00
LeoVasanko 535ac8558d Docs updates. 2025-12-19 20:59:16 +00:00
LeoVasanko c64554aeda Docs updates. 2025-12-19 20:56:47 +00:00
LeoVasanko 0bc1bae26c Docs updates. 2025-12-19 20:54:44 +00:00
LeoVasanko 156231b142 Docs updates. 2025-12-19 20:52:38 +00:00
LeoVasanko daf397b3b5 Docs updates. 2025-12-19 20:38:49 +00:00
LeoVasanko a1a5ad8520 Docs updates. 2025-12-19 20:37:25 +00:00
LeoVasanko d25124d30b Docs updates. 2025-12-19 20:23:49 +00:00
LeoVasanko 0bfb035f76 Docs updates. 2025-12-19 18:34:12 +00:00
LeoVasanko 000501b718 Add missing max-age argument to validate endpoint. 2025-12-19 18:34:01 +00:00
LeoVasanko 5a57e78814 Docs updates. 2025-12-19 18:17:28 +00:00
LeoVasanko e5b84dd28c Docs updates. 2025-12-19 17:34:09 +00:00
LeoVasanko 4b01fd9e7a Docs updates. 2025-12-19 17:28:54 +00:00
LeoVasanko 431c48f1dd Docs updates. 2025-12-19 16:06:51 +00:00
LeoVasanko 03c966919f README formatting and links. 2025-12-19 14:59:22 +00:00
LeoVasanko 2795b1061f Info fields for PyPI 2025-12-18 14:13:05 +00:00
103 changed files with 6817 additions and 4580 deletions
+1
View File
@@ -5,6 +5,7 @@ dist/
*.lock *.lock
package-lock.json package-lock.json
paskia.sqlite paskia.sqlite
paskia.jsonl
/paskia/frontend-build /paskia/frontend-build
/paskia/_version.py /paskia/_version.py
coverage-html/ coverage-html/
-105
View File
@@ -1,105 +0,0 @@
# Paskia API Documentation
This document lists the HTTP and WebSocket endpoints exposed by the Paskia
service and how they behave depending on whether a dedicated authentication host
(`--auth-host` / environment `PASSKEY_AUTH_HOST`) is configured.
## Base Paths & Host Modes
Two deployment modes:
1. Multihost (default no `--auth-host` provided)
- All endpoints are reachable on any host under the `/auth/` prefix.
- A convenience root (`/`) also serves the main app.
2. Dedicated auth host (`--auth-host auth.example.com`)
- The specified auth host serves the UI at the root (`/`, `/admin/`, reset tokens, etc.).
- Other (nonauth) hosts show a lightweight account summary at `/` or `/auth/`, while other UI routes still redirect to the auth host.
- Restricted endpoints on nonauth hosts return `404` instead of redirecting.
### Path Mapping When Auth Host Enabled
| Purpose | On Auth Host | On Other Hosts (incoming) | Action |
|---------|--------------|---------------------------|--------|
| Main UI | `/` | `/auth/` or `/` | Serve account summary SPA (no redirect) |
| Admin UI root | `/admin/` | `/auth/admin/` or `/admin/` | Redirect -> auth host `/admin/` (strip `/auth`) |
| Reset / device addition token | `/{token}` | `/auth/{token}` | Redirect -> auth host `/{token}` (strip `/auth`) |
| Static assets | `/auth/assets/*` | `/auth/assets/*` | Served directly (no redirect) |
| Unrestricted API | `/auth/api/...` | `/auth/api/...` | Served directly |
| Restricted API (admin,user,ws namespaces) | `/auth/api/{admin|user|ws}*` | same path | 404 on nonauth hosts |
| WebSocket (register/auth) | `/auth/ws/*` | `/auth/ws/*` | 404 on nonauth hosts |
Notes:
- “Strip `/auth`” means only when the path starts with that exact segment.
- A reset token is a single path segment validated by server logic; malformed tokens 404.
- Method and body are preserved for UI redirects (307 Temporary Redirect).
## HTTP UI Endpoints
| Method | Path (multihost) | Path (auth host) | Description |
|--------|-------------------|------------------|-------------|
| GET | `/auth/` | `/` | Main authentication SPA (non-auth hosts show an account summary view) |
| GET | `/auth/admin/` | `/admin/` | Admin SPA root |
| GET | `/auth/{reset_token}` | `/{reset_token}` | Reset / device addition SPA (token validated) |
## Core API (Unrestricted available on all hosts)
Always under `/auth/api/` (even on auth host):
| Method | Path | Description |
|--------|------|-------------|
| GET | `/auth/restricted/` | Authentication UI for iframe embedding (supports `?mode=login` or `?mode=reauth`) |
|--------|------|-------------|
| POST | `/auth/api/validate` | Validate & (conditionally) renew session |
| GET | `/auth/api/forward` | Auth proxy endpoint for reverse proxies (204 or 4xx) |
| POST | `/auth/api/set-session` | Set cookie from Bearer token |
| POST | `/auth/api/logout` | Logout current session |
| POST | `/auth/api/user-info` | Authenticated user + context info (also handles reset tokens) |
| POST | `/auth/api/create-link` | Create a device addition link (reset token) |
| DELETE | `/auth/api/credential/{uuid}` | Delete user credential |
| DELETE | `/auth/api/session/{session_id}` | Terminate a specific session |
| POST | `/auth/api/user/logout-all` | Terminate all sessions for the user |
| PUT | `/auth/api/user/display-name` | Update display name |
## Restricted API Namespaces
When `--auth-host` is set, requests to these paths on nonauth hosts return 404:
| Namespace | Examples |
|-----------|----------|
| `/auth/api/admin` | `/auth/api/admin/orgs`, `/auth/api/admin/orgs/{uuid}` ... |
| `/auth/api/user` | Segment prefix includes `/auth/api/user/...` endpoints (logout-all, display-name, session, credential) |
| `/auth/api/ws` | (Reserved / future) |
## WebSockets (Passkey)
| Path | Description | Host Mode Behavior |
|------|-------------|--------------------|
| `/auth/ws/register` | Register new credential (new or existing user) | 404 on nonauth hosts when auth host configured |
| `/auth/ws/authenticate` | Authenticate user & issue session | 404 on nonauth hosts when auth host configured |
## Redirection & Status Codes
| Scenario | Response |
|----------|----------|
| UI path on nonauth host (auth host configured) | 307 redirect to auth host; `/auth` prefix stripped |
| Reset token UI path on nonauth host | 307 redirect (token preserved) |
| Restricted API on nonauth host | 404 |
| Unrestricted API on any host | Normal response |
| No auth host configured | All hosts behave like multi-host mode (no redirects; everything accessible) |
## Headers for /auth/api/forward
See `Headers.md` for details of headers returned on success (204).
## Notes for Integrators
1. Always use absolute `/auth/api/...` paths for programmatic requests (they do not move when an auth host is introduced).
2. Bookmark / deep links to UI should resolve correctly after redirection if users access via a non-auth application host.
3. Treat 404 from restricted namespaces on non-auth hosts as a signal to direct users to the central auth site.
## Environment & CLI Summary
| Option | Effect |
|--------|--------|
| `--auth-host` / `PASSKEY_AUTH_HOST` | Enables dedicated host mode, root-mounts UI there, restricts certain namespaces elsewhere |
---
This document reflects current behavior of the middleware-based host routing logic.
-64
View File
@@ -1,64 +0,0 @@
## Caddy configuration
We provide a few Caddy snippets that make the configuration easier, although the `forward_auth` directive of Caddy can be used directly as well. Place the auth folder with the snippets where your Caddyfile is.
What these snippets do
- Mount the auth UI at `/auth/` proxying to `:4401` (auth backend)
- Use the forward-auth interface `/auth/api/forward` to verify the required credentials
- Render a login page or a permission denied page if needed (without changing URL)
Your backend may not use authentication at all, or it can make use of the user information passed via `Remote-*` headers by the authentication system, see [Headers.md](Headers.md) for details.
### 1) Protect the full site (auth/all)
Use this when you want “login required everywhere” which is useful to protect some service that doesn't have any authentication of its own:
```caddyfile
localhost {
import auth/all "" {
reverse_proxy :3000 # your app
}
}
```
The auth/all protects the entire site with a simple directive. Put your normal setup inside the block. In this example we don't require any permissions, only that the user is logged in. Instead of `""` you may specify `perm=myapp:login` or other permissions.
It is possible to add your own `handle @matcher` blocks prior importing `auth/all` for endpoints that don't require authentication, e.g. to exclude `/favicon.ico`.
### 2) Different areas, different permissions (auth/setup, auth/require)
When you need a more fine-grained control, use the auth/setup and auth/require snippets:
```caddyfile
localhost {
import auth/setup
@public path /.well-known/* /favicon.ico
handle @public {
root * /var/www/
file_server
}
@reports path /reports
handle @reports {
import auth/require perm=myapp:reports
reverse_proxy :3000
}
# Anywhere else, require login only
handle {
import auth/require ""
reverse_proxy :3000
}
}
```
Note: We use the `handle @name` approach rather than `handle_path` to prevent the matched path being removed out of upstream URL. Unlike bare directives, these blocks will be tried in sequence and each can contain what you'd typically put in your site definition.
---
## Override the auth backend URL (AUTH_UPSTREAM)
By default, the auth service is contacted at localhost port 4401 ("for authentication required"). You can point Caddy to a different by setting the `AUTH_UPSTREAM` environment variable for Caddy.
If unset, the snippets use `:4401` by default.
-17
View File
@@ -1,17 +0,0 @@
## Headers your app receives
When a request is allowed, the auth service adds these headers before proxying to your app (e.g., the service at `:3000`). Your app can use them for user context and authorization.
| Header | Meaning | Example |
|---|---|---|
| `Remote-User` | Authenticated user UUID | `3f1a2b3c-4d5e-6789-abcd-ef0123456789` |
| `Remote-Name` | User display name | `Jane Doe` |
| `Remote-Org` | Organization UUID | `a1b2c3d4-1111-2222-3333-444455556666` |
| `Remote-Org-Name` | Organization display name | `Acme Inc` |
| `Remote-Role` | Role UUID | `b2c3d4e5-2222-3333-4444-555566667777` |
| `Remote-Role-Name` | Role display name | `Administrators` |
| `Remote-Groups` | Commaseparated permissions the user has | `myapp:reports,auth:admin` |
| `Remote-Session-Expires` | Session expiry timestamp (ISO 8601) | `2025-09-25T14:30:00Z` |
| `Remote-Credential` | Credential UUID backing the session | `c3d4e5f6-3333-4444-5555-666677778888` |
Note: Any incoming `Remote-*` headers from clients are stripped by our [Caddy configuration](Caddy.md), so that apps can trust these values.
+16 -22
View File
@@ -1,5 +1,7 @@
# Paskia # Paskia
![Screenshot](https://git.zi.fi/leovasanko/paskia/raw/main/docs/screenshots/forbidden-light.webp)
An easy to install passkey-based authentication service that protects any web application with strong passwordless login. An easy to install passkey-based authentication service that protects any web application with strong passwordless login.
## What is Paskia? ## What is Paskia?
@@ -30,16 +32,9 @@ Install [UV](https://docs.astral.sh/uv/getting-started/installation/) and run:
uvx paskia serve --rp-id example.com uvx paskia serve --rp-id example.com
``` ```
On the first run it downloads the software and prints a registration link for the Admin. If you are going to be connecting `localhost` directly, for testing, leave out the rp-id. On the first run it downloads the software and prints a registration link for the Admin. The server will start up on [localhost:4401](http://localhost:4401) *for authentication required*, serving for `*.example.com`. If you are going to be connecting `localhost` directly, for testing, leave out the rp-id.
The server will start up on [localhost:4401](http://localhost:4401) "for authentication required", serving for `*.example.com`. Otherwise you will need a web server such as [Caddy](https://caddyserver.com/) to serve HTTPS on your actual domain names and proxy requests to Paskia and your backend apps (see documentation below).
Otherwise you will need a web server such as [Caddy](https://caddyserver.com/) to serve HTTPS on your actual domain names and proxy requests to Paskia and your backend apps.
A quick example without any config file:
```fish
sudo caddy reverse-proxy --from example.com --to :4401
```
For a permanent install of `paskia` CLI command, not needing `uvx`: For a permanent install of `paskia` CLI command, not needing `uvx`:
@@ -55,18 +50,17 @@ There is no config file. Pass only the options on CLI:
paskia serve [options] paskia serve [options]
``` ```
Optional options: | Option | Description | Default |
|--------|-------------|---------|
| Listen address | One of *host***:***port* (default all hosts, port 4401) or **unix:***path***/paskia.socket** (Unix socket) | **localhost:4401** |
| --rp-id *domain* | Main/top domain | **localhost** |
| --rp-name *"text"* | Name of your company or site | Same as rp-id |
| --origin *url* | Explicitly list the domain names served | **https://**_rp-id_ |
| --auth-host *domain* | Dedicated authentication site (e.g., **auth.example.com**) | **Unspecified:** we use **/auth/** on **every** site under rp-id.|
- Listen address (one of): ## Further Documentation
* `[host]:port`: Address and port (default: `localhost:4401`)
* `unix:/path.sock`: Unix socket
- `--rp-id <domain>`: Main domain (required for production)
- `--rp-name "<text>"`: Name of your company or site (default: same as rp-id)
- `--origin <url>`: Explicit single site (default: `https://<rp-id>`)
- `--auth-host <domain>`: Dedicated authentication site (e.g., `auth.example.com`)
## Documentation - [Caddy configuration](https://git.zi.fi/LeoVasanko/paskia/src/branch/main/docs/Caddy.md)
- [Trusted Headers for Backend Apps](https://git.zi.fi/LeoVasanko/paskia/src/branch/main/docs/Headers.md)
- `API.md`: Complete HTTP and WebSocket API reference - [Frontend integration](https://git.zi.fi/LeoVasanko/paskia/src/branch/main/docs/Integration.md)
- `Caddy.md`: Caddy configuration examples - [Paskia API](https://git.zi.fi/LeoVasanko/paskia/src/branch/main/docs/API.md)
- `Headers.md`: HTTP headers passed to protected applications
+64
View File
@@ -0,0 +1,64 @@
# Paskia API
For integrating Paskia with your app frontend, see [integration](Integration.md).
## Web Interface
| Method | Path | What it is for | Notes |
|---:|---|---|---|
| GET | `/auth/` | User profile page | |
| GET | `/auth/admin/` | Admin panel | Requires auth:admin (master) or org admin permissions. |
| GET | `/auth/{token}` | Reset / add credential URL (QR code link) | E.g. `/auth/fun.cotton.fresh.xray.lava` |
### Public JSON API: `/auth/api/*`
| Method | Path | Used for | Notes |
|---:|---|---|---|
| GET | `/auth/api/settings` | Paskia configuration | Returns RP info + base paths + session cookie name |
| POST | `/auth/api/user-info` | Full user profile | Basic information, credentials, sessions, permissions |
| POST | `/auth/api/logout` | Terminate session and delete session cookie | Signs out of the current site |
| POST | `/auth/api/validate` | Validate and renew session cookie | Optional query: `perm=` (repeatable), `max_age=` |
| GET | `/auth/api/forward` | Validate access (Caddy/Nginx) | 204 on success; 401/403 otherwise (HTML if requested) |
The `validate` and `forward` endpoints take query arguments `perm=` and `max_age=` for specific requirements on the validation of the current session.
### User JSON API: `/auth/api/user/*`
| Method | Path | Used for | Notes |
|---:|---|---|---|
| PUT | `/auth/api/user/display-name` | Update the users display name | Body: JSON `{ "display_name": "..." }` |
| POST | `/auth/api/user/logout-all` | Terminate all user sessions | Clears current host cookie |
| DELETE | `/auth/api/user/session/{session_id}` | Terminate one session | Session IDs are server-issued |
| DELETE | `/auth/api/user/credential/{uuid}` | Delete a credential | Requires recent authentication |
| POST | `/auth/api/user/create-link` | Create a device-add link | Requires recent authentication |
These are used mostly from the user profile panel and modify the current user.
### Admin API: `/auth/api/admin/*`
Normally only used via admin panel, requires auth admin permissions and can modify any users, orgs and permissions the session has access to.
E.g. Org admin cannot see anything of the other orgs that he has no admin access to. Master admin `auth:admin` can see everything and create and manage orgs.
### WebSockets: `/auth/ws/*`
| Path | Used for | Notes |
|---|---|---|
| `WS /auth/ws/authenticate` | Passkey authentication | Returns a session token |
| `WS /auth/ws/register` | Register a new credential | Adding another passkey to current user or via reset token |
| `WS /auth/ws/remote-auth/request` | Start a cross-device login/registration request | Used from unauthenticated client |
| `WS /auth/ws/remote-auth/permit` | Approve/deny a pairing code | Used to accept the request, if same words are entered |
These are for internal use only, but are documented here because they are the core piece in all passkey operations.
### Auth host mode (`--auth-host`)
#### On the auth host:
- The Web UI is served at site root (e.g. admin UI at `/admin/`), and the `/auth/...` equivalents (e.g. `/auth/admin/`) redirect to the root paths.
- All of the API stays under `/auth/api/*`
- Auth WebSockets remain at `/auth/ws/*` but take connections from other hosts to issue sessions for each of those.
#### On non-auth hosts:
- `/auth/` shows only minimal profile and allows logging out of the current site
- `/auth/api/*` is served normally.
- `/auth/api/user/*`, `/auth/api/admin/*`, and `/auth/ws/*` don't exist.
+79
View File
@@ -0,0 +1,79 @@
# Paskia Caddy Configuration
[Caddy](https://caddyserver.com/) is a modern web server that makes setting up web services easy. We provide a few Caddy snippets that make the configuration even easier, although the `forward_auth` directive of Caddy can be used directly as well. Place the [auth folder](../caddy/auth) with the snippets `require` and `setup` where your config file is (e.g. `/etc/caddy/auth`)
What these snippets do
- `setup`: Mount the auth UI at `/auth/` proxying to `:4401`
- `require`: Use `/auth/api/forward` for access control
- Render a login page or a permission denied page if needed (without changing URL)
Your backend may not use authentication at all, or it can make use of the user information passed via `Remote-*` headers by the authentication system, see [trusted headers](Headers.md) for details.
We assume the normal unprotected **Caddyfile** for your site looks like this:
```caddyfile
app.example.com {
@public path /.well-known/* /favicon.ico
handle @public {
root * /var/www/
file_server
}
handle {
reverse_proxy :3000 # Your app backend
}
}
```
Note: We use the `handle @name` approach rather than `handle_path` to keep the path unaltered. Unlike bare directives, these blocks will be tried in sequence and each can contain what you'd typically put in your site definition (by default `reverse_proxy` takes precedence and nothing reaches the static files).
We will adapt from this to protect your app.
### Protect your site (auth/setup, auth/require)
```caddyfile
app.example.com {
import auth/setup
@public path /.well-known/* /favicon.ico
handle @public {
root * /var/www/
file_server
}
@reports path /reports
handle @reports {
import auth/require perm=myapp:reports
reverse_proxy :3000
}
handle {
import auth/require max-age=12h
reverse_proxy :3000
}
}
```
The above setup allows unauthenticated access to certain files, then implements two different access controls for your backend app depending on which path is accessed. Note that the perm and max-age options may be combined, e.g. `perm=myapp:admin&max-age=5min` on a very sensitive endpoint. This will require additional authentication if the passkey hasn't been used in the last 5 minutes (automatic session renewals don't affect this). Use `""` if you only want the user to be authenticated with no time or perm requirements.
### Dedicated Authentication Site
When you setup a separate subdomain for the authentication site, just add to your config another section for the auth host:
```caddyfile
auth.example.com {
reverse_proxy :4401
}
```
Remember to specify `paskia serve --auth-host auth.example.com` to restrict the authentication services to this domain.
Note that we still reserve `/auth/` on each site for logout page and any APIs your application may require, while full user profile and global options are only available on the auth host.
Paskia does not require CORS configuration, but it can access the authentication and registration of auth host WS API from the other sites as WebSockets don't require any CORS.
### Override the paskia backend address (AUTH_UPSTREAM)
By default, the auth service is contacted at localhost port 4401. You can point Caddy to a different address by setting the `AUTH_UPSTREAM` environment variable for Caddy.
If unset, the snippets use `:4401` by default.
+23
View File
@@ -0,0 +1,23 @@
# Paskia Trusted Headers for Backend Apps
| HTTP Header | Meaning | Example |
|---|---|---|
| `Remote-User` | Authenticated user UUID | **01c03276-b8f0-**… (string) |
| `Remote-Name` | User display name | **John Doe** |
| `Remote-Org` | Organization UUID | Identifier for user's org (string) |
| `Remote-Org-Name` | Organization display name | **The Company Ltd.** |
| `Remote-Role` | Role UUID | Identifier for user's role (string) |
| `Remote-Role-Name` | Role display name | **Employee** |
| `Remote-Groups` | Permissions the user has, comma separated | **auth:admin,yourapp:reports** |
| `Remote-Session-Expires` | Session expiry timestamp (ISO 8601 UTC) | **2030-12-31T23:59:59Z** |
| `Remote-Credential` | Credential UUID | Identifier for the sign-in passkey (string) |
Similar headers are also used by other authentication systems like [Authelia](https://www.authelia.com/integration/trusted-header-sso/introduction/) to signal the backend application information about the signed in user.
When a request is allowed, the auth service adds these headers by the forward-auth mechanism before proxying to your app as **request headers**. Your app can use them for user context to show on UI, or for its own authentication needs (e.g. prevent different orgs messing up with each other's data, logging which user performed an action).
Only the UUID values should be used for identification needs, because they never change, even when things are renamed (display names change), and are never reused (created on authentication server). They are UUIDv7 so you can also extract the creation timestamp from them.
Any `Remote-*` headers from clients are stripped by our [Caddy configuration](Caddy.md) to avoid dealing with any fake headers.
Note: the headers are intended primarily for the backend, while either frontend or backend (passing the session cookie) can request `/auth/api/user-info` for more complete information, and that is the recommended way to do it in the frontend. See [integration](Integration.md) for more.
+43
View File
@@ -0,0 +1,43 @@
# Integrating Paskia with your App
Protect API routes with forward-auth (see [Caddy configuration](Caddy.md)). Optionally protect your app assets and not just the API.
Catch response status 401/403 in fetch calls to protected endpoints and implement authentication flow in this case. The response is JSON and contains `detail` (an error message describing what is needed) and `auth.iframe` (a URL). Render that URL in an iframe and retry the request after authentication (see below).
While the app is in (active) use, call `/auth/api/validate` occasionally to keep the session alive (session lifetime is 24h), otherwise the user will have to login every day. Max-age limits are unaffected by this and can be used on endpoints needing to reauthenticate with passkey more frequently.
Fetch `/auth/api/user-info` to display user/session details, or link to `/auth/` if you prefer using the built-in profile UI and not having to do anything more.
## Authentication Flow (iframe)
```js
// Show an authentication dialog
const iframe = document.createElement('iframe')
iframe.src = auth.url // from 401/403 response JSON
iframe.style.cssText = `
position: fixed;
inset: 0;
width: 100%;
height: 100%;
border: 0;
z-index: 9999;
background: transparent;
backdrop-filter: blur(0.1rem) brightness(0.7);
`
document.body.appendChild(iframe)
// Wait until user is finished with the dialog
const handler = ev => {
if (ev.origin !== location.origin) return
iframe.remove()
removeEventListener('message', handler)
if (ev.data?.type === 'auth-success') retry_original_fetch()
}
addEventListener('message', handler)
```
This describes the frontend flow for handling 401/403 responses from endpoints protected by Paskia forward-auth, without ever exiting your app.
When a protected request fails, the backend returns 401 (needs auth / reauth) or 403 (missing permission). For API requests, the response is JSON that includes an iframe URL. Your app should render that URL in a full-screen iframe overlay, and retry the request after the iframe reports success. If it reports `auth-cancel`, don't try again. The backdrop for the dialog is a stylistic choice, and you can style the background shown with the dialog any way you wish, and consider using CSS file with the iframe rather than inline styles as used in the example.
Following this flow the user gets authenticated properly and after that your app keeps running as if nothing ever happened.
Binary file not shown.

After

Width:  |  Height:  |  Size: 15 KiB

+30 -30
View File
@@ -97,14 +97,14 @@ test.describe('Passkey Authentication E2E', () => {
// Verify registration result // Verify registration result
expect(result.session_token).toBeDefined() expect(result.session_token).toBeDefined()
expect(result.session_token).toHaveLength(16) expect(result.session_token).toHaveLength(16)
expect(result.user_uuid).toBeDefined() expect(result.user).toBeDefined()
expect(result.credential_uuid).toBeDefined() expect(result.credential).toBeDefined()
expect(result.message).toContain('successfully') expect(result.message).toContain('successfully')
// Store for subsequent tests // Store for subsequent tests
sessionToken = result.session_token sessionToken = result.session_token
userUuid = result.user_uuid userUuid = result.user
credentialUuid = result.credential_uuid credentialUuid = result.credential
// Save session token for other test groups to use // Save session token for other test groups to use
saveSessionToken(sessionToken) saveSessionToken(sessionToken)
@@ -138,9 +138,9 @@ test.describe('Passkey Authentication E2E', () => {
const validation = await validateSession(page, baseUrl, sessionToken) const validation = await validateSession(page, baseUrl, sessionToken)
expect(validation.valid).toBe(true) expect(validation.valid).toBe(true)
expect(validation.user_uuid).toBe(userUuid) expect(validation.ctx.user.uuid).toBe(userUuid)
console.log(`✓ Session validated for user: ${validation.user_uuid}`) console.log(`✓ Session validated for user: ${validation.ctx.user.uuid}`)
}) })
test('should retrieve user info', async ({ page }) => { test('should retrieve user info', async ({ page }) => {
@@ -148,8 +148,8 @@ test.describe('Passkey Authentication E2E', () => {
const userInfo = await getUserInfo(page, baseUrl, sessionToken) const userInfo = await getUserInfo(page, baseUrl, sessionToken)
expect(userInfo.user.user_uuid).toBe(userUuid) expect(userInfo.ctx.user.uuid).toBe(userUuid)
expect(userInfo.user.user_name).toBe('Admin User') expect(userInfo.ctx.user.display_name).toBe('Admin User')
expect(userInfo.credentials).toBeDefined() expect(userInfo.credentials).toBeDefined()
expect(userInfo.credentials.length).toBeGreaterThanOrEqual(1) expect(userInfo.credentials.length).toBeGreaterThanOrEqual(1)
@@ -169,7 +169,7 @@ test.describe('Passkey Authentication E2E', () => {
await page.screenshot({ path: 'test-results/profile-view.png' }) await page.screenshot({ path: 'test-results/profile-view.png' })
console.log('✓ Screenshot saved: test-results/profile-view.png') console.log('✓ Screenshot saved: test-results/profile-view.png')
console.log(`✓ User info retrieved: ${userInfo.user.user_name}`) console.log(`✓ User info retrieved: ${userInfo.ctx.user.display_name}`)
console.log(`✓ Credentials count: ${userInfo.credentials.length}`) console.log(`✓ Credentials count: ${userInfo.credentials.length}`)
}) })
@@ -190,7 +190,7 @@ test.describe('Passkey Authentication E2E', () => {
displayName: 'Admin User (test device)' displayName: 'Admin User (test device)'
}) })
console.log(`✓ Added test credential: ${regResult.credential_uuid}`) console.log(`✓ Added test credential: ${regResult.credential}`)
// Now logout and authenticate with the fresh credential // Now logout and authenticate with the fresh credential
await logout(page, baseUrl, regResult.session_token) await logout(page, baseUrl, regResult.session_token)
@@ -201,7 +201,7 @@ test.describe('Passkey Authentication E2E', () => {
expect(result.session_token).toBeDefined() expect(result.session_token).toBeDefined()
expect(result.session_token).toHaveLength(16) expect(result.session_token).toHaveLength(16)
expect(result.user_uuid).toBe(userUuid) expect(result.user).toBe(userUuid)
// Update session token for subsequent tests // Update session token for subsequent tests
sessionToken = result.session_token sessionToken = result.session_token
@@ -209,7 +209,7 @@ test.describe('Passkey Authentication E2E', () => {
// Save session token for other test groups to use // Save session token for other test groups to use
saveSessionToken(sessionToken) saveSessionToken(sessionToken)
console.log(`✓ Authenticated as user: ${result.user_uuid}`) console.log(`✓ Authenticated as user: ${result.user}`)
console.log(`✓ New session token: ${sessionToken.substring(0, 4)}...`) console.log(`✓ New session token: ${sessionToken.substring(0, 4)}...`)
}) })
@@ -219,7 +219,7 @@ test.describe('Passkey Authentication E2E', () => {
const validation = await validateSession(page, baseUrl, sessionToken) const validation = await validateSession(page, baseUrl, sessionToken)
expect(validation.valid).toBe(true) expect(validation.valid).toBe(true)
expect(validation.user_uuid).toBe(userUuid) expect(validation.ctx.user.uuid).toBe(userUuid)
console.log(`✓ New session validated`) console.log(`✓ New session validated`)
}) })
@@ -291,8 +291,8 @@ test.describe('Device Addition Dialog', () => {
// Wait for the profile view to load // Wait for the profile view to load
await page.waitForSelector('[data-view="profile"]', { timeout: 5000 }) await page.waitForSelector('[data-view="profile"]', { timeout: 5000 })
// Click the "Add Another Device" button // Click the "Another Device" button
const addDeviceButton = page.getByRole('button', { name: 'Add Another Device' }) const addDeviceButton = page.getByRole('button', { name: 'Another Device' })
await expect(addDeviceButton).toBeVisible() await expect(addDeviceButton).toBeVisible()
await addDeviceButton.click() await addDeviceButton.click()
@@ -301,7 +301,7 @@ test.describe('Device Addition Dialog', () => {
await expect(dialog).toBeVisible({ timeout: 5000 }) await expect(dialog).toBeVisible({ timeout: 5000 })
// Verify dialog contains expected elements // Verify dialog contains expected elements
await expect(dialog.locator('h2')).toContainText('Device Registration Link') await expect(dialog.locator('h2')).toContainText('Add Another Device')
// Wait for QR code to be generated (canvas should have content) // Wait for QR code to be generated (canvas should have content)
const qrCanvas = dialog.locator('.qr-code') const qrCanvas = dialog.locator('.qr-code')
@@ -318,16 +318,16 @@ test.describe('Device Addition Dialog', () => {
expect(linkHref).toContain('http://localhost:4404/auth/') expect(linkHref).toContain('http://localhost:4404/auth/')
console.log(`✓ Device link displayed: ${linkText} (href: ${linkHref})`) console.log(`✓ Device link displayed: ${linkText} (href: ${linkHref})`)
// Verify expiration warning is shown // Verify help text is shown
await expect(dialog.locator('.reg-help')).toContainText('Expires') await expect(dialog.locator('.reg-help')).toContainText('Scan this QR code')
// Take screenshot of the dialog // Take screenshot of the dialog
await dialog.screenshot({ path: 'test-results/device-addition-dialog.png' }) await dialog.screenshot({ path: 'test-results/device-addition-dialog.png' })
console.log(`✓ Screenshot saved: test-results/device-addition-dialog.png`) console.log(`✓ Screenshot saved: test-results/device-addition-dialog.png`)
// Verify Copy Link button exists // Verify the QR link element is clickable (copy functionality is built into clicking it)
const copyButton = dialog.getByRole('button', { name: 'Copy Link' }) const qrLink = dialog.locator('a.qr-link')
await expect(copyButton).toBeVisible() await expect(qrLink).toBeVisible()
// Close the dialog (use the text button, not the icon button) // Close the dialog (use the text button, not the icon button)
const closeButton = dialog.locator('button.btn-secondary', { hasText: 'Close' }) const closeButton = dialog.locator('button.btn-secondary', { hasText: 'Close' })
@@ -357,12 +357,12 @@ test.describe('Device Addition Dialog', () => {
await page.waitForSelector('[data-view="profile"]', { timeout: 5000 }) await page.waitForSelector('[data-view="profile"]', { timeout: 5000 })
// Open the dialog // Open the dialog
await page.getByRole('button', { name: 'Add Another Device' }).click() await page.getByRole('button', { name: 'Another Device' }).click()
const dialog = page.locator('.device-dialog') const dialog = page.locator('.device-dialog')
await expect(dialog).toBeVisible({ timeout: 5000 }) await expect(dialog).toBeVisible({ timeout: 5000 })
// Extract the reset token from the displayed URL // Extract the reset token from the displayed URL
const linkText = dialog.locator('.qr-link p') const linkText = dialog.locator('.qr-link .link-text')
const linkContent = await linkText.textContent() const linkContent = await linkText.textContent()
// URL format: localhost/auth/word1.word2.word3.word4.word5 // URL format: localhost/auth/word1.word2.word3.word4.word5
@@ -405,7 +405,7 @@ test.describe('Device Addition Dialog', () => {
}) })
}) })
test.describe('ProfileView - Add New Passkey', () => { test.describe('ProfileView - Register New', () => {
const baseUrl = process.env.BASE_URL || 'http://localhost:4404' const baseUrl = process.env.BASE_URL || 'http://localhost:4404'
test('should show credentials list in profile', async ({ page }) => { test('should show credentials list in profile', async ({ page }) => {
@@ -427,7 +427,7 @@ test.describe('ProfileView - Add New Passkey', () => {
console.log(`✓ Profile shows ${credentialItems} credential(s) in list`) console.log(`✓ Profile shows ${credentialItems} credential(s) in list`)
}) })
test('should add a new passkey using Add New Passkey button', async ({ page }) => { test('should add a new passkey using Register New button', async ({ page }) => {
const sessionToken = getSavedSessionToken() const sessionToken = getSavedSessionToken()
test.skip(!sessionToken, 'Requires saved session token') test.skip(!sessionToken, 'Requires saved session token')
@@ -444,8 +444,8 @@ test.describe('ProfileView - Add New Passkey', () => {
const initialCredentialCount = await page.locator('.credential-item').count() const initialCredentialCount = await page.locator('.credential-item').count()
console.log(`Initial credential count: ${initialCredentialCount}`) console.log(`Initial credential count: ${initialCredentialCount}`)
// Click "Add New Passkey" button // Click "Register New" button
const addPasskeyBtn = page.locator('button:has-text("Add New Passkey")') const addPasskeyBtn = page.locator('button:has-text("Register New")')
await expect(addPasskeyBtn).toBeVisible() await expect(addPasskeyBtn).toBeVisible()
await addPasskeyBtn.click() await addPasskeyBtn.click()
@@ -490,7 +490,7 @@ test.describe('ProfileView - Add New Passkey', () => {
// Try to add a passkey - with excludeCredentials the authenticator should // Try to add a passkey - with excludeCredentials the authenticator should
// prevent re-registration of the same credential // prevent re-registration of the same credential
const addPasskeyBtn = page.locator('button:has-text("Add New Passkey")') const addPasskeyBtn = page.locator('button:has-text("Register New")')
await expect(addPasskeyBtn).toBeVisible() await expect(addPasskeyBtn).toBeVisible()
await addPasskeyBtn.click() await addPasskeyBtn.click()
@@ -541,8 +541,8 @@ test.describe('ProfileView - Multi-Authenticator', () => {
await page.waitForSelector('.credential-list', { timeout: 10000 }) await page.waitForSelector('.credential-list', { timeout: 10000 })
const initialCredentialCount = await page.locator('.credential-item').count() const initialCredentialCount = await page.locator('.credential-item').count()
// Click "Add New Passkey" button // Click "Register New" button
const addPasskeyBtn = page.locator('button:has-text("Add New Passkey")') const addPasskeyBtn = page.locator('button:has-text("Register New")')
await expect(addPasskeyBtn).toBeVisible() await expect(addPasskeyBtn).toBeVisible()
await addPasskeyBtn.click() await addPasskeyBtn.click()
+4 -4
View File
@@ -84,7 +84,7 @@ async function makeApiCall(page: Page, url: string, method = 'GET'): Promise<{ s
// Wait a tick for the page's handler to retry, then make our own call // Wait a tick for the page's handler to retry, then make our own call
setTimeout(async () => { setTimeout(async () => {
try { try {
const response = await fetch(url, { method, credentials: 'include' }); const response = await fetch(url, { method });
if (response.status === 204) { if (response.status === 204) {
resolve({ status: 204 }); resolve({ status: 204 });
} else if (response.ok) { } else if (response.ok) {
@@ -111,7 +111,7 @@ async function makeApiCall(page: Page, url: string, method = 'GET'): Promise<{ s
setTimeout(async () => { setTimeout(async () => {
if (resolved) return; if (resolved) return;
try { try {
const response = await fetch(url, { method, credentials: 'include' }); const response = await fetch(url, { method });
// Only resolve if this is a success or non-auth error // Only resolve if this is a success or non-auth error
if (response.status !== 401 && response.status !== 403) { if (response.status !== 401 && response.status !== 403) {
if (resolved) return; if (resolved) return;
@@ -242,7 +242,7 @@ test.describe('API Mode - 401 Login Flow', () => {
resetToken: deviceToken, resetToken: deviceToken,
displayName: 'API Test Device', displayName: 'API Test Device',
}) })
console.log(`✓ Registered credential: ${regResult.credential_uuid}`) console.log(`✓ Registered credential: ${regResult.credential}`)
// Logout to clear session (but keep the passkey in virtual authenticator) // Logout to clear session (but keep the passkey in virtual authenticator)
await logout(page, baseUrl, regResult.session_token) await logout(page, baseUrl, regResult.session_token)
@@ -268,7 +268,7 @@ test.describe('API Mode - 401 Login Flow', () => {
// Wait for API call to complete and verify result // Wait for API call to complete and verify result
const result = await apiCallPromise const result = await apiCallPromise
expect(result.status).toBe(200) expect(result.status).toBe(200)
expect(result.data.user).toBeDefined() expect(result.data.ctx).toBeDefined()
console.log('✓ API call succeeded after authentication') console.log('✓ API call succeeded after authentication')
// Save the session for other tests // Save the session for other tests
+39 -5
View File
@@ -12,17 +12,51 @@ const stateFile = join(__dirname, '..', '..', 'test-data', 'test-state.json')
*/ */
export interface RegistrationResult { export interface RegistrationResult {
user_uuid: string user: string
credential_uuid: string credential: string
session_token: string session_token: string
message: string message: string
} }
export interface AuthenticationResult { export interface AuthenticationResult {
user_uuid: string user: string
session_token: string session_token: string
} }
export interface SessionContext {
user: { uuid: string; display_name: string }
org: { uuid: string; display_name: string }
role: { uuid: string; display_name: string }
permissions: string[]
}
export interface UserInfo {
ctx: SessionContext
created_at: string
last_seen: string
visits: number
credentials: Array<{
credential: string
aaguid: string
created_at: string
last_used: string | null
last_verified: string | null
sign_count: number
is_current_session: boolean
}>
aaguid_info: Record<string, { name: string; icon_light?: string; icon_dark?: string }>
sessions: Array<{
id: string
credential: string
host: string
ip: string
user_agent: string
last_renewed: string
is_current: boolean
is_current_host: boolean
}>
}
/** /**
* Get the bootstrap reset token from the test state file. * Get the bootstrap reset token from the test state file.
*/ */
@@ -376,7 +410,7 @@ export async function validateSession(
page: Page, page: Page,
baseUrl: string, baseUrl: string,
sessionToken: string sessionToken: string
): Promise<{ valid: boolean; user_uuid: string; renewed: boolean }> { ): Promise<{ valid: boolean; ctx: SessionContext; renewed: boolean }> {
const cookieName = getSessionCookieName() const cookieName = getSessionCookieName()
const response = await page.request.post(`${baseUrl}/auth/api/validate`, { const response = await page.request.post(`${baseUrl}/auth/api/validate`, {
headers: { headers: {
@@ -393,7 +427,7 @@ export async function getUserInfo(
page: Page, page: Page,
baseUrl: string, baseUrl: string,
sessionToken: string sessionToken: string
): Promise<any> { ): Promise<UserInfo> {
const cookieName = getSessionCookieName() const cookieName = getSessionCookieName()
const response = await page.request.post(`${baseUrl}/auth/api/user-info`, { const response = await page.request.post(`${baseUrl}/auth/api/user-info`, {
headers: { headers: {
+6 -4
View File
@@ -42,21 +42,23 @@ export default async function globalSetup() {
const serverArgs = COLLECT_COVERAGE const serverArgs = COLLECT_COVERAGE
? [ ? [
'run', 'coverage', 'run', '--parallel-mode', 'run', 'coverage', 'run', '--parallel-mode',
'-m', 'paskia.fastapi', 'serve', 'localhost:4404', '-m', 'paskia.fastapi', 'localhost:4404',
'--rp-id', 'localhost' '--rp-id', 'localhost'
] ]
: [ : [
'run', 'paskia', 'serve', 'localhost:4404', 'run', 'paskia', 'localhost:4404',
'--rp-id', 'localhost' '--rp-id', 'localhost'
] ]
// Use a temporary jsonl file for test database
const testDbFile = join(testDataDir, 'test-db.jsonl')
// Start the server using Node's spawn // Start the server using Node's spawn
// Use in-memory SQLite for faster tests
const serverProcess = spawn('uv', serverArgs, { const serverProcess = spawn('uv', serverArgs, {
cwd: projectRoot, cwd: projectRoot,
env: { env: {
...process.env, ...process.env,
PASKIA_DB: 'sqlite+aiosqlite:///:memory:', PASKIA_DB: testDbFile,
COVERAGE_FILE: join(projectRoot, '.coverage'), COVERAGE_FILE: join(projectRoot, '.coverage'),
}, },
stdio: ['ignore', 'pipe', 'pipe'], stdio: ['ignore', 'pipe', 'pipe'],
+5 -12
View File
@@ -59,18 +59,11 @@ export default async function globalTeardown() {
rmSync(stateFile, { force: true }) rmSync(stateFile, { force: true })
} }
// Optionally clean up test database (keep it for debugging by default) // Clean up test database
if (process.env.CLEANUP_TEST_DB === 'true') { const testDbFile = join(testDataDir, 'test-db.jsonl')
const dbPath = join(testDataDir, 'test.sqlite') if (existsSync(testDbFile)) {
if (existsSync(dbPath)) { console.log(' Removing test database...')
console.log(' Removing test database...') rmSync(testDbFile)
rmSync(dbPath)
}
// Remove wal/shm files too
for (const ext of ['-wal', '-shm']) {
const file = dbPath + ext
if (existsSync(file)) rmSync(file)
}
} }
// Generate Python coverage report if coverage was collected // Generate Python coverage report if coverage was collected
+2 -2
View File
@@ -96,7 +96,7 @@
async function apiCall(url, method = 'GET') { async function apiCall(url, method = 'GET') {
log(`${method} ${url}...`); log(`${method} ${url}...`);
const response = await fetch(url, { method, credentials: 'include' }); const response = await fetch(url, { method });
// Server returns 401 (login/reauth) or 403 (missing permissions) // Server returns 401 (login/reauth) or 403 (missing permissions)
// with a JSON body containing the iframe URL for authentication // with a JSON body containing the iframe URL for authentication
@@ -131,7 +131,7 @@
} }
async function logout() { async function logout() {
await fetch('/auth/api/logout', { method: 'POST', credentials: 'include' }); await fetch('/auth/api/logout', { method: 'POST' });
log('Logged out'); log('Logged out');
} }
+31 -81
View File
@@ -2,10 +2,10 @@
<div class="app-shell"> <div class="app-shell">
<StatusMessage /> <StatusMessage />
<main class="app-main"> <main class="app-main">
<HostProfileView v-if="authenticated && isHostMode" :initializing="loading" /> <HostProfileView v-if="viewState === 'profile' && isHostMode" />
<ProfileView v-else-if="authenticated" /> <ProfileView v-else-if="viewState === 'profile'" />
<LoadingView v-else-if="loading" :message="loadingMessage" /> <LoadingView v-else-if="viewState === 'loading'" :message="loadingMessage" />
<AuthRequiredMessage v-else-if="showBackMessage" @reload="reloadPage" /> <AccessDenied v-else-if="viewState === 'terminal'" />
</main> </main>
</div> </div>
</template> </template>
@@ -13,18 +13,17 @@
<script setup> <script setup>
import { computed, onMounted, onUnmounted, ref } from 'vue' import { computed, onMounted, onUnmounted, ref } from 'vue'
import { useAuthStore } from '@/stores/auth' import { useAuthStore } from '@/stores/auth'
import { apiJson, getAuthIframeUrl } from '@/utils/api' import { apiJson, SessionValidator, createAuthIframe, removeAuthIframe } from 'paskia'
import { getAuthIframeUrl } from '@/utils/api'
import StatusMessage from '@/components/StatusMessage.vue' import StatusMessage from '@/components/StatusMessage.vue'
import ProfileView from '@/components/ProfileView.vue' import ProfileView from '@/components/ProfileView.vue'
import HostProfileView from '@/components/HostProfileView.vue' import HostProfileView from '@/components/HostProfileView.vue'
import LoadingView from '@/components/LoadingView.vue' import LoadingView from '@/components/LoadingView.vue'
import AuthRequiredMessage from '@/components/AccessDenied.vue' import AccessDenied from '@/components/AccessDenied.vue'
const store = useAuthStore() const store = useAuthStore()
const loading = ref(true) const viewState = ref('loading') // 'loading' | 'profile' | 'terminal'
const loadingMessage = ref('Loading...') const loadingMessage = ref('Loading...')
const authenticated = ref(false)
const showBackMessage = ref(false)
/** /**
* Normalize a host string for comparison (lowercase, strip default ports). * Normalize a host string for comparison (lowercase, strip default ports).
@@ -48,47 +47,36 @@ const isHostMode = computed(() => {
const configuredHost = normalizeHost(authHost) const configuredHost = normalizeHost(authHost)
return currentHost !== configuredHost return currentHost !== configuredHost
}) })
let validationTimer = null const userUuid = computed(() => store.userInfo?.ctx.user.uuid)
let authIframe = null
function terminateSession() {
store.userInfo = null
viewState.value = 'terminal'
}
const userUuidGetter = () => store.userInfo?.ctx.user.uuid
const sessionValidator = new SessionValidator(userUuidGetter, terminateSession)
onMounted(() => sessionValidator.start())
onUnmounted(() => sessionValidator.stop())
async function loadUserInfo() { async function loadUserInfo() {
try { try {
store.userInfo = await apiJson('/auth/api/user-info', { method: 'POST' }) store.userInfo = await apiJson('/auth/api/user-info', { method: 'POST' })
authenticated.value = true viewState.value = 'profile'
loading.value = false
startSessionValidation()
return true return true
} catch (e) { } catch {
store.userInfo = null
return false return false
} }
} }
async function showAuthIframe() { async function showAuthIframe() {
// Remove existing iframe if any
hideAuthIframe()
// Create new iframe for authentication using src URL
const url = await getAuthIframeUrl('login') const url = await getAuthIframeUrl('login')
authIframe = document.createElement('iframe') createAuthIframe(url)
authIframe.id = 'auth-iframe'
authIframe.title = 'Authentication'
authIframe.allow = 'publickey-credentials-get; publickey-credentials-create'
authIframe.src = url
document.body.appendChild(authIframe)
loadingMessage.value = 'Authentication required...' loadingMessage.value = 'Authentication required...'
} }
function hideAuthIframe() {
if (authIframe) {
authIframe.remove()
authIframe = null
}
}
function reloadPage() {
window.location.reload()
}
function handleAuthMessage(event) { function handleAuthMessage(event) {
const data = event.data const data = event.data
if (!data?.type) return if (!data?.type) return
@@ -96,8 +84,8 @@ function handleAuthMessage(event) {
switch (data.type) { switch (data.type) {
case 'auth-success': case 'auth-success':
// Authentication successful - reload user info // Authentication successful - reload user info
hideAuthIframe() removeAuthIframe()
loading.value = true viewState.value = 'loading'
loadingMessage.value = 'Loading user profile...' loadingMessage.value = 'Loading user profile...'
loadUserInfo() loadUserInfo()
break break
@@ -117,55 +105,18 @@ function handleAuthMessage(event) {
break break
case 'auth-back': case 'auth-back':
// User clicked Back - show message with reload option // User clicked Back - show terminal state
hideAuthIframe() removeAuthIframe()
loading.value = false terminateSession()
showBackMessage.value = true
store.showMessage('Authentication cancelled', 'info', 3000)
break break
case 'auth-close-request': case 'auth-close-request':
// Legacy support - treat as back // Legacy support - treat as back
hideAuthIframe() removeAuthIframe()
break break
} }
} }
async function validateSession() {
try {
await apiJson('/auth/api/validate', {
method: 'POST',
credentials: 'include'
})
// If successful, session was renewed automatically
} catch (error) {
if (error.status === 401) {
// Session expired - need to re-authenticate
console.log('Session expired, requiring re-authentication')
authenticated.value = false
loading.value = true
stopSessionValidation()
showAuthIframe()
} else {
console.error('Session validation error:', error)
// Don't treat network errors as session expiry
}
}
}
function startSessionValidation() {
// Validate session every 2 minutes
stopSessionValidation()
validationTimer = setInterval(validateSession, 2 * 60 * 1000)
}
function stopSessionValidation() {
if (validationTimer) {
clearInterval(validationTimer)
validationTimer = null
}
}
onMounted(async () => { onMounted(async () => {
// Listen for postMessage from auth iframe // Listen for postMessage from auth iframe
window.addEventListener('message', handleAuthMessage) window.addEventListener('message', handleAuthMessage)
@@ -194,8 +145,7 @@ onMounted(async () => {
onUnmounted(() => { onUnmounted(() => {
window.removeEventListener('message', handleAuthMessage) window.removeEventListener('message', handleAuthMessage)
stopSessionValidation() removeAuthIframe()
hideAuthIframe()
}) })
</script> </script>
+110 -73
View File
@@ -5,15 +5,16 @@ import CredentialList from '@/components/CredentialList.vue'
import UserBasicInfo from '@/components/UserBasicInfo.vue' import UserBasicInfo from '@/components/UserBasicInfo.vue'
import StatusMessage from '@/components/StatusMessage.vue' import StatusMessage from '@/components/StatusMessage.vue'
import LoadingView from '@/components/LoadingView.vue' import LoadingView from '@/components/LoadingView.vue'
import AuthRequiredMessage from '@/components/AccessDenied.vue' import AccessDenied from '@/components/AccessDenied.vue'
import AdminOverview from '@/admin/AdminOverview.vue' import AdminOverview from '@/admin/AdminOverview.vue'
import AdminOrgDetail from '@/admin/AdminOrgDetail.vue' import AdminOrgDetail from '@/admin/AdminOrgDetail.vue'
import AdminUserDetail from '@/admin/AdminUserDetail.vue' import AdminUserDetail from '@/admin/AdminUserDetail.vue'
import AdminDialogs from '@/admin/AdminDialogs.vue' import AdminDialogs from '@/admin/AdminDialogs.vue'
import { useAuthStore } from '@/stores/auth' import { useAuthStore } from '@/stores/auth'
import { getSettings, adminUiPath, makeUiHref } from '@/utils/settings' import { adminUiPath, makeUiHref } from '@/utils/settings'
import { apiJson } from '@/utils/api' import { apiJson, SessionValidator } from 'paskia'
import { getDirection } from '@/utils/keynav' import { getDirection } from '@/utils/keynav'
import { goBack } from '@/utils/helpers'
const info = ref(null) const info = ref(null)
const loading = ref(true) const loading = ref(true)
@@ -46,6 +47,10 @@ const adminUserDetailRef = ref(null)
// Check if any modal/dialog is open (blocks arrow key navigation) // Check if any modal/dialog is open (blocks arrow key navigation)
const hasActiveModal = computed(() => dialog.value.type !== null || showRegModal.value) const hasActiveModal = computed(() => dialog.value.type !== null || showRegModal.value)
// Derive admin status from permissions
const isMasterAdmin = computed(() => info.value?.ctx.permissions.includes('auth:admin'))
const isOrgAdmin = computed(() => info.value?.ctx.permissions.includes('auth:org:admin'))
function sanitizeRenameId() { if (renameIdValue.value) renameIdValue.value = renameIdValue.value.replace(safeIdRegex, '') } function sanitizeRenameId() { if (renameIdValue.value) renameIdValue.value = renameIdValue.value.replace(safeIdRegex, '') }
function handleGlobalClick(e) { function handleGlobalClick(e) {
@@ -60,8 +65,8 @@ function handleGlobalClick(e) {
onMounted(async () => { onMounted(async () => {
document.addEventListener('click', handleGlobalClick) document.addEventListener('click', handleGlobalClick)
window.addEventListener('hashchange', parseHash) window.addEventListener('hashchange', parseHash)
const settings = await getSettings() await authStore.loadSettings()
if (settings?.rp_name) document.title = settings.rp_name + ' Admin' if (authStore.settings?.rp_name) document.title = authStore.settings.rp_name + ' Admin'
await load() await load()
}) })
@@ -108,7 +113,7 @@ const permissionSummary = computed(() => {
return display return display
}) })
function renamePermissionDisplay(p) { openDialog('perm-display', { permission: p, id: p.id, display_name: p.display_name }) } function renamePermissionDisplay(p) { openDialog('perm-display', { permission: p, scope: p.scope, display_name: p.display_name, domain: p.domain || '' }) }
function parseHash() { function parseHash() {
@@ -125,7 +130,7 @@ function parseHash() {
async function loadOrgs() { async function loadOrgs() {
const data = await apiJson('/auth/api/admin/orgs') const data = await apiJson('/auth/api/admin/orgs')
orgs.value = data.map(o => { orgs.value = data.map(o => {
const roles = o.roles.map(r => ({ ...r, org_uuid: o.uuid, users: [] })) const roles = o.roles.map(r => ({ ...r, org: o.uuid, users: [] }))
const roleMap = Object.fromEntries(roles.map(r => [r.display_name, r])) const roleMap = Object.fromEntries(roles.map(r => [r.display_name, r]))
for (const u of o.users || []) { for (const u of o.users || []) {
if (roleMap[u.role]) roleMap[u.role].users.push(u) if (roleMap[u.role]) roleMap[u.role].users.push(u)
@@ -139,10 +144,34 @@ async function loadPermissions() {
} }
async function loadUserInfo() { async function loadUserInfo() {
info.value = await apiJson('/auth/api/user-info', { method: 'POST' }) const data = await apiJson('/auth/api/validate', { method: 'POST' })
info.value = data
authenticated.value = true authenticated.value = true
} }
function clearSensitiveState() {
info.value = null
orgs.value = []
permissions.value = []
userDetail.value = null
authenticated.value = false
}
function onSessionLost(e) {
clearSensitiveState()
if (e.name === 'AuthCancelledError') {
showBackMessage.value = true
} else {
error.value = e.message
}
}
const userUuidGetter = () => info.value?.ctx.user.uuid
const sessionValidator = new SessionValidator(userUuidGetter, onSessionLost)
onMounted(() => sessionValidator.start())
onUnmounted(() => sessionValidator.stop())
async function load() { async function load() {
loading.value = true loading.value = true
loadingMessage.value = 'Loading...' loadingMessage.value = 'Loading...'
@@ -153,7 +182,7 @@ async function load() {
// If we get here, user has admin access - now fetch user info for display // If we get here, user has admin access - now fetch user info for display
await loadUserInfo() await loadUserInfo()
if (!info.value.is_global_admin && info.value.is_org_admin && orgs.value.length === 1) { if (!isMasterAdmin.value && isOrgAdmin.value && orgs.value.length === 1) {
if (!window.location.hash || window.location.hash === '#overview') { if (!window.location.hash || window.location.hash === '#overview') {
currentOrgId.value = orgs.value[0].uuid currentOrgId.value = orgs.value[0].uuid
window.location.hash = `#org/${currentOrgId.value}` window.location.hash = `#org/${currentOrgId.value}`
@@ -163,11 +192,7 @@ async function load() {
} }
} else parseHash() } else parseHash()
} catch (e) { } catch (e) {
if (e.name === 'AuthCancelledError') { onSessionLost(e)
showBackMessage.value = true
} else {
error.value = e.message
}
} finally { } finally {
loading.value = false loading.value = false
} }
@@ -186,8 +211,6 @@ async function performOrgDeletion(orgUuid) {
} }
function deleteOrg(org) { function deleteOrg(org) {
if (!info.value?.is_global_admin) { authStore.showMessage('Global admin only'); return }
const userCount = org.roles.reduce((acc, r) => acc + r.users.length, 0) const userCount = org.roles.reduce((acc, r) => acc + r.users.length, 0)
if (userCount === 0) { if (userCount === 0) {
@@ -220,7 +243,7 @@ async function moveUserToRole(org, user, targetRoleDisplayName) {
if (user.role === targetRoleDisplayName) return if (user.role === targetRoleDisplayName) return
try { try {
await apiJson(`/auth/api/admin/orgs/${org.uuid}/users/${user.uuid}/role`, { await apiJson(`/auth/api/admin/orgs/${org.uuid}/users/${user.uuid}/role`, {
method: 'PUT', method: 'PATCH',
body: { role: targetRoleDisplayName } body: { role: targetRoleDisplayName }
}) })
await loadOrgs() await loadOrgs()
@@ -229,9 +252,9 @@ async function moveUserToRole(org, user, targetRoleDisplayName) {
} }
} }
function onUserDragStart(e, user, org_uuid) { function onUserDragStart(e, user, org) {
e.dataTransfer.effectAllowed = 'move' e.dataTransfer.effectAllowed = 'move'
e.dataTransfer.setData('text/plain', JSON.stringify({ user_uuid: user.uuid, org_uuid })) e.dataTransfer.setData('text/plain', JSON.stringify({ user_uuid: user.uuid, org }))
} }
function onRoleDragOver(e) { function onRoleDragOver(e) {
@@ -243,7 +266,7 @@ function onRoleDrop(e, org, role) {
e.preventDefault() e.preventDefault()
try { try {
const data = JSON.parse(e.dataTransfer.getData('text/plain')) const data = JSON.parse(e.dataTransfer.getData('text/plain'))
if (data.org_uuid !== org.uuid) return // only within same org if (data.org !== org.uuid) return // only within same org
const user = org.roles.flatMap(r => r.users).find(u => u.uuid === data.user_uuid) const user = org.roles.flatMap(r => r.users).find(u => u.uuid === data.user_uuid)
if (user) moveUserToRole(org, user, role.display_name) if (user) moveUserToRole(org, user, role.display_name)
} catch (_) { /* ignore */ } } catch (_) { /* ignore */ }
@@ -256,7 +279,7 @@ function updateRole(role) { openDialog('role-update', { role, name: role.display
function deleteRole(role) { function deleteRole(role) {
// UI only allows deleting empty roles, so no confirmation needed // UI only allows deleting empty roles, so no confirmation needed
apiJson(`/auth/api/admin/orgs/${role.org_uuid}/roles/${role.uuid}`, { method: 'DELETE' }) apiJson(`/auth/api/admin/orgs/${role.org}/roles/${role.uuid}`, { method: 'DELETE' })
.then(() => { .then(() => {
authStore.showMessage(`Role "${role.display_name}" deleted.`, 'success', 2500) authStore.showMessage(`Role "${role.display_name}" deleted.`, 'success', 2500)
loadOrgs() loadOrgs()
@@ -267,19 +290,17 @@ function deleteRole(role) {
} }
async function toggleRolePermission(role, pid, checked) { async function toggleRolePermission(role, pid, checked) {
// Calculate new permissions array // Optimistic update
const prevPermissions = [...role.permissions]
const newPermissions = checked const newPermissions = checked
? [...role.permissions, pid] ? [...role.permissions, pid]
: role.permissions.filter(p => p !== pid) : role.permissions.filter(p => p !== pid)
// Optimistic update
const prevPermissions = [...role.permissions]
role.permissions = newPermissions role.permissions = newPermissions
try { try {
await apiJson(`/auth/api/admin/orgs/${role.org_uuid}/roles/${role.uuid}`, { const method = checked ? 'POST' : 'DELETE'
method: 'PUT', await apiJson(`/auth/api/admin/orgs/${role.org}/roles/${role.uuid}/permissions/${pid}`, {
body: { display_name: role.display_name, permissions: newPermissions } method
}) })
await loadOrgs() await loadOrgs()
} catch (e) { } catch (e) {
@@ -289,20 +310,20 @@ async function toggleRolePermission(role, pid, checked) {
} }
// Permission actions // Permission actions
async function performPermissionDeletion(permissionId) { async function performPermissionDeletion(permissionUuid) {
const params = new URLSearchParams({ permission_id: permissionId }) const params = new URLSearchParams({ permission_uuid: permissionUuid })
await apiJson(`/auth/api/admin/permission?${params.toString()}`, { method: 'DELETE' }) await apiJson(`/auth/api/admin/permission?${params.toString()}`, { method: 'DELETE' })
await loadPermissions() await loadPermissions()
} }
function deletePermission(p) { function deletePermission(p) {
const userCount = permissionSummary.value[p.id]?.userCount || 0 const userCount = permissionSummary.value[p.uuid]?.userCount || 0
// Count roles that have this permission // Count roles that have this permission
let roleCount = 0 let roleCount = 0
for (const org of orgs.value) { for (const org of orgs.value) {
for (const role of org.roles) { for (const role of org.roles) {
if (role.permissions.includes(p.id)) { if (role.permissions.includes(p.uuid)) {
roleCount++ roleCount++
} }
} }
@@ -310,7 +331,7 @@ function deletePermission(p) {
if (roleCount === 0) { if (roleCount === 0) {
// No roles have this permission, safe to delete directly // No roles have this permission, safe to delete directly
performPermissionDeletion(p.id) performPermissionDeletion(p.uuid)
.then(() => { .then(() => {
authStore.showMessage(`Permission "${p.display_name}" deleted.`, 'success', 2500) authStore.showMessage(`Permission "${p.display_name}" deleted.`, 'success', 2500)
}) })
@@ -326,14 +347,10 @@ function deletePermission(p) {
const affects = parts.join(', ') const affects = parts.join(', ')
openDialog('confirm', { message: `Delete permission "${p.display_name}" (${affects})?`, action: async () => { openDialog('confirm', { message: `Delete permission "${p.display_name}" (${affects})?`, action: async () => {
await performPermissionDeletion(p.id) await performPermissionDeletion(p.uuid)
} }) } })
} }
function reloadPage() {
window.location.reload()
}
const selectedOrg = computed(() => orgs.value.find(o => o.uuid === currentOrgId.value) || null) const selectedOrg = computed(() => orgs.value.find(o => o.uuid === currentOrgId.value) || null)
function openOrg(o) { function openOrg(o) {
@@ -353,7 +370,7 @@ const selectedUser = computed(() => {
for (const o of orgs.value) { for (const o of orgs.value) {
for (const r of o.roles) { for (const r of o.roles) {
const u = r.users.find(x => x.uuid === currentUserId.value) const u = r.users.find(x => x.uuid === currentUserId.value)
if (u) return { ...u, org_uuid: o.uuid, role_display_name: r.display_name } if (u) return { ...u, org: o.uuid, role_display_name: r.display_name }
} }
} }
return null return null
@@ -374,14 +391,14 @@ const breadcrumbEntries = computed(() => {
// Determine organization for user view if selectedOrg not explicitly chosen. // Determine organization for user view if selectedOrg not explicitly chosen.
let orgForUser = null let orgForUser = null
if (selectedUser.value) { if (selectedUser.value) {
orgForUser = orgs.value.find(o => o.uuid === selectedUser.value.org_uuid) || null orgForUser = orgs.value.find(o => o.uuid === selectedUser.value.org) || null
} }
const orgToShow = selectedOrg.value || orgForUser const orgToShow = selectedOrg.value || orgForUser
if (orgToShow) { if (orgToShow) {
entries.push({ label: orgToShow.display_name, href: `#org/${orgToShow.uuid}` }) entries.push({ label: orgToShow.display_name, href: `#org/${orgToShow.uuid}` })
} }
if (selectedUser.value) { if (selectedUser.value) {
entries.push({ label: selectedUser.value.display_name || 'User', href: `#user/${selectedUser.value.uuid}` }) entries.push({ label: selectedUser.value.display_name, href: `#user/${selectedUser.value.uuid}` })
} }
return entries return entries
}) })
@@ -389,7 +406,7 @@ const breadcrumbEntries = computed(() => {
watch(selectedUser, async (u) => { watch(selectedUser, async (u) => {
if (!u) { userDetail.value = null; return } if (!u) { userDetail.value = null; return }
try { try {
userDetail.value = await apiJson(`/auth/api/admin/orgs/${u.org_uuid}/users/${u.uuid}`) userDetail.value = await apiJson(`/auth/api/admin/orgs/${u.org}/users/${u.uuid}`)
} catch (e) { } catch (e) {
userDetail.value = { error: e.message } userDetail.value = { error: e.message }
} }
@@ -410,11 +427,11 @@ async function toggleOrgPermission(org, permId, checked) {
const prev = [...org.permissions] const prev = [...org.permissions]
org.permissions = next org.permissions = next
try { try {
const params = new URLSearchParams({ permission_id: permId }) const params = new URLSearchParams({ permission_uuid: permId })
await apiJson(`/auth/api/admin/orgs/${org.uuid}/permission?${params.toString()}`, { method: checked ? 'POST' : 'DELETE' }) await apiJson(`/auth/api/admin/orgs/${org.uuid}/permission?${params.toString()}`, { method: checked ? 'POST' : 'DELETE' })
await loadOrgs() await loadOrgs()
} catch (e) { } catch (e) {
authStore.showMessage(e.message || 'Failed to update organization permission') authStore.showMessage(e.message || 'Failed to update organization permission', 'error')
org.permissions = prev // revert org.permissions = prev // revert
} }
} }
@@ -525,7 +542,7 @@ async function refreshUserDetail() {
await loadOrgs() await loadOrgs()
if (selectedUser.value) { if (selectedUser.value) {
try { try {
userDetail.value = await apiJson(`/auth/api/admin/orgs/${selectedUser.value.org_uuid}/users/${selectedUser.value.uuid}`) userDetail.value = await apiJson(`/auth/api/admin/orgs/${selectedUser.value.org}/users/${selectedUser.value.uuid}`)
} catch (e) { authStore.showMessage(e.message || 'Failed to reload user', 'error') } } catch (e) { authStore.showMessage(e.message || 'Failed to reload user', 'error') }
} }
} }
@@ -559,7 +576,7 @@ async function submitDialog() {
// Close dialog immediately, then perform async operation // Close dialog immediately, then perform async operation
closeDialog() closeDialog()
apiJson(`/auth/api/admin/orgs/${org.uuid}`, { method: 'PUT', body: { display_name: name, permissions: org.permissions } }) apiJson(`/auth/api/admin/orgs/${org.uuid}`, { method: 'PATCH', body: { display_name: name } })
.then(() => { .then(() => {
authStore.showMessage(`Organization renamed to "${name}".`, 'success', 2500) authStore.showMessage(`Organization renamed to "${name}".`, 'success', 2500)
loadOrgs() loadOrgs()
@@ -587,7 +604,7 @@ async function submitDialog() {
// Close dialog immediately, then perform async operation // Close dialog immediately, then perform async operation
closeDialog() closeDialog()
apiJson(`/auth/api/admin/orgs/${role.org_uuid}/roles/${role.uuid}`, { method: 'PUT', body: { display_name: name, permissions: role.permissions } }) apiJson(`/auth/api/admin/orgs/${role.org}/roles/${role.uuid}`, { method: 'PATCH', body: { display_name: name } })
.then(() => { .then(() => {
authStore.showMessage(`Role renamed to "${name}".`, 'success', 2500) authStore.showMessage(`Role renamed to "${name}".`, 'success', 2500)
loadOrgs() loadOrgs()
@@ -615,7 +632,7 @@ async function submitDialog() {
// Close dialog immediately, then perform async operation // Close dialog immediately, then perform async operation
closeDialog() closeDialog()
apiJson(`/auth/api/admin/orgs/${user.org_uuid}/users/${user.uuid}/display-name`, { method: 'PUT', body: { display_name: name } }) apiJson(`/auth/api/admin/orgs/${user.org}/users/${user.uuid}/display-name`, { method: 'PATCH', body: { display_name: name } })
.then(() => { .then(() => {
authStore.showMessage(`User renamed to "${name}".`, 'success', 2500) authStore.showMessage(`User renamed to "${name}".`, 'success', 2500)
onUserNameSaved() onUserNameSaved()
@@ -626,28 +643,28 @@ async function submitDialog() {
return // Don't call closeDialog() again return // Don't call closeDialog() again
} else if (t === 'perm-display') { } else if (t === 'perm-display') {
const { permission } = dialog.value.data const { permission } = dialog.value.data
const newId = dialog.value.data.id?.trim() const newScope = dialog.value.data.scope?.trim()
const newDisplay = dialog.value.data.display_name?.trim() const newDisplay = dialog.value.data.display_name?.trim()
const newDomain = dialog.value.data.domain?.trim() || ''
if (!newDisplay) throw new Error('Display name required') if (!newDisplay) throw new Error('Display name required')
if (!newId) throw new Error('ID required') if (!newScope) throw new Error('Scope required')
// Close dialog immediately, then perform async operation // Close dialog immediately, then perform async operation
closeDialog() closeDialog()
let apiCall; const oldDomain = permission.domain || ''
if (newId !== permission.id) { // Check if anything changed
// ID changed, use rename endpoint if (newScope === permission.scope && newDisplay === permission.display_name && newDomain === oldDomain) {
apiCall = apiJson('/auth/api/admin/permission/rename', { method: 'POST', body: { old_id: permission.id, new_id: newId, display_name: newDisplay } }) return // No changes
} else if (newDisplay !== permission.display_name) {
// Only display name changed
const params = new URLSearchParams({ permission_id: permission.id, display_name: newDisplay })
apiCall = apiJson(`/auth/api/admin/permission?${params.toString()}`, { method: 'PUT' })
} else {
// No changes
return
} }
apiCall // Always use PATCH with permission_uuid
const params = new URLSearchParams({ permission_uuid: permission.uuid })
if (newScope !== permission.scope) params.set('scope', newScope)
if (newDisplay !== permission.display_name) params.set('display_name', newDisplay)
if (newDomain !== oldDomain) params.set('domain', newDomain || '')
apiJson(`/auth/api/admin/permission?${params.toString()}`, { method: 'PATCH' })
.then(() => { .then(() => {
authStore.showMessage(`Permission "${newDisplay}" updated.`, 'success', 2500) authStore.showMessage(`Permission "${newDisplay}" updated.`, 'success', 2500)
loadPermissions() loadPermissions()
@@ -655,13 +672,15 @@ async function submitDialog() {
.catch(e => { .catch(e => {
authStore.showMessage(e.message || 'Failed to update permission', 'error') authStore.showMessage(e.message || 'Failed to update permission', 'error')
}) })
return // Don't call closeDialog() again else if (t === 'perm-create') { return // Don't call closeDialog() again
const id = dialog.value.data.id?.trim(); if (!id) throw new Error('ID required') } else if (t === 'perm-create') {
const scope = dialog.value.data.scope?.trim(); if (!scope) throw new Error('Scope required')
const display_name = dialog.value.data.display_name?.trim(); if (!display_name) throw new Error('Display name required') const display_name = dialog.value.data.display_name?.trim(); if (!display_name) throw new Error('Display name required')
const domain = dialog.value.data.domain?.trim() || ''
// Close dialog immediately, then perform async operation // Close dialog immediately, then perform async operation
closeDialog() closeDialog()
apiJson('/auth/api/admin/permissions', { method: 'POST', body: { id, display_name } }) apiJson('/auth/api/admin/permissions', { method: 'POST', body: { scope, display_name, domain: domain || undefined } })
.then(() => { .then(() => {
authStore.showMessage(`Permission "${display_name}" created.`, 'success', 2500) authStore.showMessage(`Permission "${display_name}" created.`, 'success', 2500)
loadPermissions() loadPermissions()
@@ -671,7 +690,17 @@ async function submitDialog() {
}) })
return // Don't call closeDialog() again return // Don't call closeDialog() again
} else if (t === 'confirm') { } else if (t === 'confirm') {
const action = dialog.value.data.action; if (action) await action() const action = dialog.value.data.action
// Close dialog first, then perform action (errors shown via showMessage)
closeDialog()
if (action) {
try {
await action()
} catch (e) {
authStore.showMessage(e.message || 'Action failed', 'error')
}
}
return // Already closed
} }
closeDialog() closeDialog()
} catch (e) { } catch (e) {
@@ -685,11 +714,19 @@ async function submitDialog() {
<StatusMessage /> <StatusMessage />
<main class="app-main"> <main class="app-main">
<LoadingView v-if="loading" :message="loadingMessage" /> <LoadingView v-if="loading" :message="loadingMessage" />
<AuthRequiredMessage <AccessDenied v-else-if="showBackMessage" />
v-else-if="showBackMessage" <AccessDenied
@reload="reloadPage" v-else-if="error"
icon="⚠️"
title="Error"
:message="error"
/> />
<section v-else-if="authenticated && (info?.is_global_admin || info?.is_org_admin)" class="view-root view-root--wide view-admin"> <AccessDenied
v-else-if="authenticated && !isMasterAdmin && !isOrgAdmin"
icon="⛔"
message="You do not have admin permissions for this application."
/>
<section v-else-if="authenticated && (isMasterAdmin || isOrgAdmin)" class="view-root view-root--wide view-admin">
<header class="view-header"> <header class="view-header">
<h1>{{ pageHeading }}</h1> <h1>{{ pageHeading }}</h1>
<Breadcrumbs ref="breadcrumbsRef" :entries="breadcrumbEntries" @keydown="handleBreadcrumbKeydown" /> <Breadcrumbs ref="breadcrumbsRef" :entries="breadcrumbEntries" @keydown="handleBreadcrumbKeydown" />
@@ -697,10 +734,9 @@ async function submitDialog() {
<section class="section-block admin-section"> <section class="section-block admin-section">
<div class="section-body admin-section-body"> <div class="section-body admin-section-body">
<div v-if="error" class="surface surface--tight error">{{ error }}</div> <div class="admin-panels">
<div v-else class="admin-panels">
<AdminOverview <AdminOverview
v-if="!selectedUser && !selectedOrg && (info.is_global_admin || info.is_org_admin)" v-if="!selectedUser && !selectedOrg && (isMasterAdmin || isOrgAdmin)"
ref="adminOverviewRef" ref="adminOverviewRef"
:info="info" :info="info"
:orgs="orgs" :orgs="orgs"
@@ -763,6 +799,7 @@ async function submitDialog() {
<AdminDialogs <AdminDialogs
:dialog="dialog" :dialog="dialog"
:permission-id-pattern="PERMISSION_ID_PATTERN" :permission-id-pattern="PERMISSION_ID_PATTERN"
:settings="authStore.settings"
@submit-dialog="submitDialog" @submit-dialog="submitDialog"
@close-dialog="closeDialog" @close-dialog="closeDialog"
/> />
+3
View File
@@ -1,3 +1,6 @@
import { initThemeFromCache } from '@/utils/theme'
initThemeFromCache()
import '@/assets/style.css' import '@/assets/style.css'
import { createApp } from 'vue' import { createApp } from 'vue'
+3
View File
@@ -1,3 +1,6 @@
import { initThemeFromCache } from '@/utils/theme'
initThemeFromCache()
import '@/assets/style.css' import '@/assets/style.css'
import { createApp } from 'vue' import { createApp } from 'vue'
+4 -9
View File
@@ -8,7 +8,7 @@
</template> </template>
<script setup> <script setup>
import { computed, onMounted, ref } from 'vue' import { onMounted, ref } from 'vue'
import RestrictedAuth from '@/components/RestrictedAuth.vue' import RestrictedAuth from '@/components/RestrictedAuth.vue'
// Check if this is a remote auth URL: /auth/{token} // Check if this is a remote auth URL: /auth/{token}
@@ -30,14 +30,9 @@ function extractRemoteToken() {
return null return null
} }
// Detect mode from URL hash fragment // Parse URL hash fragment
const authMode = computed(() => { const hashParams = new URLSearchParams(window.location.hash.slice(1))
const params = new URLSearchParams(window.location.hash.slice(1)) const authMode = ['reauth', 'forbidden'].includes(hashParams.get('mode')) ? hashParams.get('mode') : 'login'
const mode = params.get('mode')
if (mode === 'reauth') return 'reauth'
if (mode === 'forbidden') return 'forbidden'
return 'login'
})
function postToParent(message) { function postToParent(message) {
if (window.parent && window.parent !== window) { if (window.parent && window.parent !== window) {
+1
View File
@@ -1,3 +1,4 @@
import './theme.js'
import { createApp } from 'vue' import { createApp } from 'vue'
import RestrictedApi from './RestrictedApi.vue' import RestrictedApi from './RestrictedApi.vue'
import '@/assets/style.css' import '@/assets/style.css'
+11
View File
@@ -0,0 +1,11 @@
// Early theme for restricted app - first URL param wins, then localStorage
import { themeColors, applyTheme, getCachedTheme } from '@/utils/theme.js'
function getTheme() {
const params = new URLSearchParams(location.hash.slice(1))
return params.get('theme') || getCachedTheme() || ''
}
// Use .surface selector to preserve transparent background
applyTheme(getTheme(), '.surface')
addEventListener('hashchange', () => applyTheme(getTheme(), '.surface'))
+11 -10
View File
@@ -59,7 +59,7 @@
import { computed, onMounted, reactive, ref } from 'vue' import { computed, onMounted, reactive, ref } from 'vue'
import passkey from '@/utils/passkey' import passkey from '@/utils/passkey'
import { getSettings, uiBasePath } from '@/utils/settings' import { getSettings, uiBasePath } from '@/utils/settings'
import { apiJson, ApiError, getUserFriendlyErrorMessage } from '@/utils/api' import { apiJson, ApiError, getUserFriendlyErrorMessage } from 'paskia'
const status = reactive({ const status = reactive({
show: false, show: false,
@@ -71,12 +71,12 @@ const initializing = ref(true)
const loading = ref(false) const loading = ref(false)
const token = ref('') const token = ref('')
const settings = ref(null) const settings = ref(null)
const userInfo = ref(null) const tokenInfo = ref(null)
const displayName = ref('') const displayName = ref('')
const errorMessage = ref('') const errorMessage = ref('')
let statusTimer = null let statusTimer = null
const sessionDescriptor = computed(() => userInfo.value?.session_type || 'your enrollment') const sessionDescriptor = computed(() => tokenInfo.value?.token_type || 'your enrollment')
const subtitleMessage = computed(() => { const subtitleMessage = computed(() => {
if (initializing.value) return 'Preparing your secure enrollment…' if (initializing.value) return 'Preparing your secure enrollment…'
if (!canRegister.value) return 'This authentication link is no longer valid.' if (!canRegister.value) return 'This authentication link is no longer valid.'
@@ -85,7 +85,7 @@ const subtitleMessage = computed(() => {
const basePath = computed(() => uiBasePath()) const basePath = computed(() => uiBasePath())
const canRegister = computed(() => !!(token.value && userInfo.value)) const canRegister = computed(() => !!(token.value && tokenInfo.value))
function showMessage(message, type = 'info', duration = 3000) { function showMessage(message, type = 'info', duration = 3000) {
status.show = true status.show = true
@@ -109,15 +109,16 @@ async function fetchSettings() {
} }
} }
async function fetchUserInfo() { async function fetchTokenInfo() {
if (!token.value) return if (!token.value) return
try { try {
userInfo.value = await apiJson(`/auth/api/user-info?reset=${encodeURIComponent(token.value)}`, { tokenInfo.value = await apiJson('/auth/api/token-info', {
method: 'POST' method: 'GET',
headers: { 'Authorization': `Bearer ${token.value}` },
}) })
displayName.value = userInfo.value?.user?.user_name || '' displayName.value = tokenInfo.value.display_name
} catch (error) { } catch (error) {
console.error('Failed to load user info', error) console.error('Failed to load token info', error)
const message = error instanceof ApiError const message = error instanceof ApiError
? (error.data?.detail || 'The authentication link is invalid or expired.') ? (error.data?.detail || 'The authentication link is invalid or expired.')
: getUserFriendlyErrorMessage(error) : getUserFriendlyErrorMessage(error)
@@ -196,7 +197,7 @@ onMounted(async () => {
initializing.value = false initializing.value = false
return return
} }
await fetchUserInfo() await fetchTokenInfo()
initializing.value = false initializing.value = false
}) })
</script> </script>
+1
View File
@@ -10,6 +10,7 @@
}, },
"dependencies": { "dependencies": {
"@simplewebauthn/browser": "^13.1.2", "@simplewebauthn/browser": "^13.1.2",
"paskia": "file:../paskia-js",
"pinia": "^3.0.3", "pinia": "^3.0.3",
"qrcode": "^1.5.4", "qrcode": "^1.5.4",
"sirv": "^3.0.2", "sirv": "^3.0.2",
BIN
View File
Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB

+13 -5
View File
@@ -1,15 +1,18 @@
<script setup> <script setup>
import { computed } from 'vue'
import Modal from '@/components/Modal.vue' import Modal from '@/components/Modal.vue'
import NameEditForm from '@/components/NameEditForm.vue' import NameEditForm from '@/components/NameEditForm.vue'
const props = defineProps({ const props = defineProps({
dialog: Object, dialog: Object,
PERMISSION_ID_PATTERN: String PERMISSION_ID_PATTERN: String,
settings: Object
}) })
const emit = defineEmits(['submitDialog', 'closeDialog']) const emit = defineEmits(['submitDialog', 'closeDialog'])
const NAME_EDIT_TYPES = new Set(['org-update', 'role-update', 'user-update-name']) const NAME_EDIT_TYPES = new Set(['org-update', 'role-update', 'user-update-name'])
const rpId = computed(() => props.settings?.rp_id || 'the configured domain')
</script> </script>
<template> <template>
@@ -21,7 +24,7 @@ const NAME_EDIT_TYPES = new Set(['org-update', 'role-update', 'user-update-name'
<template v-else-if="dialog.type==='role-update'">Edit Role</template> <template v-else-if="dialog.type==='role-update'">Edit Role</template>
<template v-else-if="dialog.type==='user-create'">Add User To Role</template> <template v-else-if="dialog.type==='user-create'">Add User To Role</template>
<template v-else-if="dialog.type==='user-update-name'">Edit User Name</template> <template v-else-if="dialog.type==='user-update-name'">Edit User Name</template>
<template v-else-if="dialog.type==='perm-create' || dialog.type==='perm-display'">{{ dialog.type === 'perm-create' ? 'Create Permission' : 'Edit Permission Display' }}</template> <template v-else-if="dialog.type==='perm-create' || dialog.type==='perm-display'">{{ dialog.type === 'perm-create' ? 'Create Permission' : 'Edit Permission' }}</template>
<template v-else-if="dialog.type==='confirm'">Confirm</template> <template v-else-if="dialog.type==='confirm'">Confirm</template>
</h3> </h3>
<form @submit.prevent="$emit('submitDialog')" class="modal-form"> <form @submit.prevent="$emit('submitDialog')" class="modal-form">
@@ -72,10 +75,14 @@ const NAME_EDIT_TYPES = new Set(['org-update', 'role-update', 'user-update-name'
<label>Display Name <label>Display Name
<input ref="displayNameInput" v-model="dialog.data.display_name" required /> <input ref="displayNameInput" v-model="dialog.data.display_name" required />
</label> </label>
<label>Permission ID <label>Permission Scope
<input v-model="dialog.data.id" :placeholder="dialog.type === 'perm-create' ? 'yourapp:permission' : dialog.data.permission.id" required :pattern="PERMISSION_ID_PATTERN" title="Allowed: A-Za-z0-9:._~-" data-form-type="other" /> <input v-model="dialog.data.scope" :placeholder="dialog.type === 'perm-create' ? 'yourapp:permission' : dialog.data.permission.scope" required :pattern="PERMISSION_ID_PATTERN" title="Allowed: A-Za-z0-9:._~-" data-form-type="other" />
</label> </label>
<p class="small muted">The permission ID is used for permission checks in the application. Changing it may break deployed applications that reference this permission.</p> <p class="small muted">E.g. yourapp:reports. Changing the scope name may break deployed applications.</p>
<label>Domain Scope
<input v-model="dialog.data.domain" placeholder="e.g. app.example.com" data-form-type="other" />
</label>
<p class="small muted">If set, this permission is effective only on the specified domain, which can be {{ rpId }} or its subdomain.</p>
</template> </template>
<template v-else-if="dialog.type==='confirm'"> <template v-else-if="dialog.type==='confirm'">
<p>{{ dialog.data.message }}</p> <p>{{ dialog.data.message }}</p>
@@ -106,4 +113,5 @@ const NAME_EDIT_TYPES = new Set(['org-update', 'role-update', 'user-update-name'
.error { color: var(--color-danger-text); } .error { color: var(--color-danger-text); }
.small { font-size: 0.9rem; } .small { font-size: 0.9rem; }
.muted { color: var(--color-text-muted); } .muted { color: var(--color-text-muted); }
.optional { font-weight: normal; color: var(--color-text-muted); font-size: 0.85em; }
</style> </style>
+13 -7
View File
@@ -26,8 +26,14 @@ const sortedRoles = computed(() => {
}) })
}) })
function permissionDisplayName(id) { // Get org's grantable permissions as full permission objects (with UUIDs)
return props.permissions.find(p => p.id === id)?.display_name || id const orgPermissions = computed(() => {
const uuidSet = new Set(props.selectedOrg.permissions || [])
return props.permissions.filter(p => uuidSet.has(p.uuid))
})
function permissionDisplayName(scope) {
return props.permissions.find(p => p.scope === scope)?.display_name || scope
} }
function toggleRolePermission(role, pid, checked) { function toggleRolePermission(role, pid, checked) {
@@ -302,17 +308,17 @@ defineExpose({ focusFirstElement })
</div> </div>
<div class="grid-head role-head add-role-head" title="Add role" @click="$emit('createRole', selectedOrg)" role="button" tabindex="0" @keydown.enter="$emit('createRole', selectedOrg)"></div> <div class="grid-head role-head add-role-head" title="Add role" @click="$emit('createRole', selectedOrg)" role="button" tabindex="0" @keydown.enter="$emit('createRole', selectedOrg)"></div>
<template v-for="pid in selectedOrg.permissions" :key="pid"> <template v-for="p in orgPermissions" :key="p.uuid">
<div class="perm-name" :title="pid">{{ permissionDisplayName(pid) }}</div> <div class="perm-name" :title="p.scope">{{ p.display_name }}</div>
<div <div
v-for="r in sortedRoles" v-for="r in sortedRoles"
:key="r.uuid + '-' + pid" :key="r.uuid + '-' + p.uuid"
class="matrix-cell" class="matrix-cell"
> >
<input <input
type="checkbox" type="checkbox"
:checked="r.permissions.includes(pid)" :checked="r.permissions.includes(p.uuid)"
@change="e => toggleRolePermission(r, pid, e.target.checked)" @change="e => toggleRolePermission(r, p.uuid, e.target.checked)"
/> />
</div> </div>
<div class="matrix-cell add-role-cell" /> <div class="matrix-cell add-role-cell" />
+29 -22
View File
@@ -24,10 +24,14 @@ const sortedOrgs = computed(() => [...props.orgs].sort((a,b)=> {
const nameCompare = a.display_name.localeCompare(b.display_name) const nameCompare = a.display_name.localeCompare(b.display_name)
return nameCompare !== 0 ? nameCompare : a.uuid.localeCompare(b.uuid) return nameCompare !== 0 ? nameCompare : a.uuid.localeCompare(b.uuid)
})) }))
const sortedPermissions = computed(() => [...props.permissions].sort((a,b)=> a.id.localeCompare(b.id))) const sortedPermissions = computed(() => [...props.permissions].sort((a,b)=> a.scope.localeCompare(b.scope)))
function permissionDisplayName(id) { // Derive admin status from permissions (info contains ctx from validate response)
return props.permissions.find(p => p.id === id)?.display_name || id const isMasterAdmin = computed(() => props.info?.ctx.permissions.includes('auth:admin'))
const isOrgAdmin = computed(() => props.info?.ctx.permissions.includes('auth:org:admin'))
function permissionDisplayName(scope) {
return props.permissions.find(p => p.scope === scope)?.display_name || scope
} }
function getRoleNames(org) { function getRoleNames(org) {
@@ -89,7 +93,7 @@ function handleTableKeydown(event, tableType) {
} else if (direction === 'down' && currentIndex === rows.length - 1) { } else if (direction === 'down' && currentIndex === rows.length - 1) {
// At bottom of org table, navigate to permissions section // At bottom of org table, navigate to permissions section
event.preventDefault() event.preventDefault()
if (tableType === 'org' && props.info.is_global_admin) { if (tableType === 'org' && isMasterAdmin.value) {
// Navigate to permissions matrix or actions // Navigate to permissions matrix or actions
if (permMatrixRef.value) { if (permMatrixRef.value) {
const firstCheckbox = permMatrixRef.value.querySelector('input[type="checkbox"]') const firstCheckbox = permMatrixRef.value.querySelector('input[type="checkbox"]')
@@ -232,7 +236,7 @@ function handlePermActionsKeydown(event) {
// Focus helper for external navigation // Focus helper for external navigation
function focusFirstElement() { function focusFirstElement() {
if (props.info.is_global_admin) { if (isMasterAdmin.value) {
focusPreferred(orgActionsRef.value, { itemSelector: 'button' }) focusPreferred(orgActionsRef.value, { itemSelector: 'button' })
} else { } else {
const firstFocusable = orgTableRef.value?.querySelector('tbody tr a, tbody tr button:not([disabled])') const firstFocusable = orgTableRef.value?.querySelector('tbody tr a, tbody tr button:not([disabled])')
@@ -245,9 +249,9 @@ defineExpose({ focusFirstElement })
<template> <template>
<div class="permissions-section" ref="orgSection"> <div class="permissions-section" ref="orgSection">
<h2>{{ info.is_global_admin ? 'Organizations' : 'Your Organizations' }}</h2> <h2>{{ isMasterAdmin ? 'Organizations' : 'Your Organizations' }}</h2>
<div class="actions" ref="orgActionsRef" @keydown="handleOrgActionsKeydown"> <div class="actions" ref="orgActionsRef" @keydown="handleOrgActionsKeydown">
<button v-if="info.is_global_admin" @click="$emit('createOrg')">+ Create Org</button> <button v-if="isMasterAdmin" @click="$emit('createOrg')">+ Create Org</button>
</div> </div>
<table class="org-table" ref="orgTableRef" @keydown="e => handleTableKeydown(e, 'org')"> <table class="org-table" ref="orgTableRef" @keydown="e => handleTableKeydown(e, 'org')">
<thead> <thead>
@@ -255,18 +259,18 @@ defineExpose({ focusFirstElement })
<th>Name</th> <th>Name</th>
<th>Roles</th> <th>Roles</th>
<th>Members</th> <th>Members</th>
<th v-if="info.is_global_admin">Actions</th> <th v-if="isMasterAdmin">Actions</th>
</tr> </tr>
</thead> </thead>
<tbody> <tbody>
<tr v-for="o in sortedOrgs" :key="o.uuid"> <tr v-for="o in sortedOrgs" :key="o.uuid">
<td> <td>
<a href="#org/{{o.uuid}}" @click.prevent="$emit('openOrg', o)">{{ o.display_name }}</a> <a href="#org/{{o.uuid}}" @click.prevent="$emit('openOrg', o)">{{ o.display_name }}</a>
<button v-if="info.is_global_admin || info.is_org_admin" @click="$emit('updateOrg', o)" class="icon-btn edit-org-btn" aria-label="Rename organization" title="Rename organization"></button> <button v-if="isMasterAdmin || isOrgAdmin" @click="$emit('updateOrg', o)" class="icon-btn edit-org-btn" aria-label="Rename organization" title="Rename organization"></button>
</td> </td>
<td class="role-names">{{ getRoleNames(o) }}</td> <td class="role-names">{{ getRoleNames(o) }}</td>
<td class="center">{{ o.roles.reduce((acc,r)=>acc + r.users.length,0) }}</td> <td class="center">{{ o.roles.reduce((acc,r)=>acc + r.users.length,0) }}</td>
<td v-if="info.is_global_admin" class="center"> <td v-if="isMasterAdmin" class="center">
<button @click="$emit('deleteOrg', o)" class="icon-btn delete-icon" aria-label="Delete organization" title="Delete organization"></button> <button @click="$emit('deleteOrg', o)" class="icon-btn delete-icon" aria-label="Delete organization" title="Delete organization"></button>
</td> </td>
</tr> </tr>
@@ -274,7 +278,7 @@ defineExpose({ focusFirstElement })
</table> </table>
</div> </div>
<div v-if="info.is_global_admin" class="permissions-section"> <div v-if="isMasterAdmin" class="permissions-section">
<h2>Permissions</h2> <h2>Permissions</h2>
<div class="matrix-wrapper" ref="permMatrixRef" @keydown="handleMatrixKeydown"> <div class="matrix-wrapper" ref="permMatrixRef" @keydown="handleMatrixKeydown">
<div class="matrix-scroll"> <div class="matrix-scroll">
@@ -292,19 +296,19 @@ defineExpose({ focusFirstElement })
<span>{{ o.display_name }}</span> <span>{{ o.display_name }}</span>
</div> </div>
<template v-for="p in sortedPermissions" :key="p.id"> <template v-for="p in sortedPermissions" :key="p.uuid">
<div class="perm-name" :title="p.id"> <div class="perm-name" :title="p.scope">
<span class="display-text">{{ p.display_name }}</span> <span class="display-text">{{ p.display_name }}</span>
</div> </div>
<div <div
v-for="o in sortedOrgs" v-for="o in sortedOrgs"
:key="o.uuid + '-' + p.id" :key="o.uuid + '-' + p.uuid"
class="matrix-cell" class="matrix-cell"
> >
<input <input
type="checkbox" type="checkbox"
:checked="o.permissions.includes(p.id)" :checked="o.permissions.includes(p.uuid)"
@change="e => $emit('toggleOrgPermission', o, p.id, e.target.checked)" @change="e => $emit('toggleOrgPermission', o, p.uuid, e.target.checked)"
/> />
</div> </div>
</template> </template>
@@ -313,28 +317,30 @@ defineExpose({ focusFirstElement })
<p class="matrix-hint muted">Toggle which permissions each organization can grant to its members.</p> <p class="matrix-hint muted">Toggle which permissions each organization can grant to its members.</p>
</div> </div>
<div class="actions" ref="permActionsRef" @keydown="handlePermActionsKeydown"> <div class="actions" ref="permActionsRef" @keydown="handlePermActionsKeydown">
<button v-if="info.is_global_admin" @click="$emit('openDialog', 'perm-create', { display_name: '', id: '' })">+ Create Permission</button> <button v-if="isMasterAdmin" @click="$emit('openDialog', 'perm-create', { display_name: '', scope: '', domain: '' })">+ Create Permission</button>
</div> </div>
<table class="org-table" ref="permTableRef" @keydown="e => handleTableKeydown(e, 'perm')"> <table class="org-table" ref="permTableRef" @keydown="e => handleTableKeydown(e, 'perm')">
<thead> <thead>
<tr> <tr>
<th scope="col">Permission</th> <th scope="col">Permission</th>
<th scope="col">Domain</th>
<th scope="col" class="center">Members</th> <th scope="col" class="center">Members</th>
<th scope="col" class="center">Actions</th> <th scope="col" class="center">Actions</th>
</tr> </tr>
</thead> </thead>
<tbody> <tbody>
<tr v-for="p in sortedPermissions" :key="p.id"> <tr v-for="p in sortedPermissions" :key="p.uuid">
<td class="perm-name-cell"> <td class="perm-name-cell">
<div class="perm-title"> <div class="perm-title">
<span class="display-text">{{ p.display_name }}</span> <span class="display-text">{{ p.display_name }}</span>
<button @click="$emit('renamePermissionDisplay', p)" class="icon-btn edit-display-btn" aria-label="Edit display name" title="Edit display name"></button> <button @click="$emit('renamePermissionDisplay', p)" class="icon-btn edit-display-btn" aria-label="Edit permission" title="Edit permission"></button>
</div> </div>
<div class="perm-id-info"> <div class="perm-id-info">
<span class="id-text">{{ p.id }}</span> <span class="id-text">{{ p.scope }}</span>
</div> </div>
</td> </td>
<td class="perm-members center">{{ permissionSummary[p.id]?.userCount || 0 }}</td> <td class="perm-domain">{{ p.domain || '—' }}</td>
<td class="perm-members center">{{ permissionSummary[p.uuid]?.userCount || 0 }}</td>
<td class="perm-actions center"> <td class="perm-actions center">
<button @click="$emit('deletePermission', p)" class="icon-btn delete-icon" aria-label="Delete permission" title="Delete permission"></button> <button @click="$emit('deletePermission', p)" class="icon-btn delete-icon" aria-label="Delete permission" title="Delete permission"></button>
</td> </td>
@@ -355,7 +361,8 @@ defineExpose({ focusFirstElement })
.org-table .role-names { max-width: 200px; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; } .org-table .role-names { max-width: 200px; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.perm-name-cell { display: flex; flex-direction: column; gap: 0.3rem; } .perm-name-cell { display: flex; flex-direction: column; gap: 0.3rem; }
.perm-title { font-weight: 600; color: var(--color-heading); } .perm-title { font-weight: 600; color: var(--color-heading); }
.perm-id-info { font-size: 0.8rem; color: var(--color-text-muted); } .perm-id-info { font-size: 0.8rem; color: var(--color-text-muted); display: flex; align-items: center; gap: 0.5rem; flex-wrap: wrap; }
.perm-domain { color: var(--color-text-muted); font-size: 0.9rem; }
.icon-btn { background: none; border: none; color: var(--color-text-muted); padding: 0.2rem; border-radius: var(--radius-sm); cursor: pointer; transition: background 0.2s ease, color 0.2s ease; } .icon-btn { background: none; border: none; color: var(--color-text-muted); padding: 0.2rem; border-radius: var(--radius-sm); cursor: pointer; transition: background 0.2s ease, color 0.2s ease; }
.icon-btn:hover { color: var(--color-heading); background: var(--color-surface-muted); } .icon-btn:hover { color: var(--color-heading); background: var(--color-surface-muted); }
.delete-icon { color: var(--color-danger); } .delete-icon { color: var(--color-danger); }
+6 -6
View File
@@ -5,7 +5,7 @@ import CredentialList from '@/components/CredentialList.vue'
import RegistrationLinkModal from '@/components/RegistrationLinkModal.vue' import RegistrationLinkModal from '@/components/RegistrationLinkModal.vue'
import SessionList from '@/components/SessionList.vue' import SessionList from '@/components/SessionList.vue'
import { useAuthStore } from '@/stores/auth' import { useAuthStore } from '@/stores/auth'
import { apiJson } from '@/utils/api' import { apiJson } from 'paskia'
import { getDirection, navigateButtonRow, focusPreferred, focusAtIndex } from '@/utils/keynav' import { getDirection, navigateButtonRow, focusPreferred, focusAtIndex } from '@/utils/keynav'
const props = defineProps({ const props = defineProps({
@@ -45,7 +45,7 @@ function handleEditName() {
async function handleDelete(credential) { async function handleDelete(credential) {
try { try {
const data = await apiJson(`/auth/api/admin/orgs/${props.selectedUser.org_uuid}/users/${props.selectedUser.uuid}/credentials/${credential.credential_uuid}`, { method: 'DELETE' }) const data = await apiJson(`/auth/api/admin/orgs/${props.selectedUser.org}/users/${props.selectedUser.uuid}/credentials/${credential.credential}`, { method: 'DELETE' })
if (data.status === 'ok') { if (data.status === 'ok') {
emit('onUserNameSaved') // Reuse to refresh user detail emit('onUserNameSaved') // Reuse to refresh user detail
} else { } else {
@@ -61,7 +61,7 @@ async function handleTerminateSession(session) {
if (!sessionId) return if (!sessionId) return
terminatingSessions.value = { ...terminatingSessions.value, [sessionId]: true } terminatingSessions.value = { ...terminatingSessions.value, [sessionId]: true }
try { try {
const data = await apiJson(`/auth/api/admin/orgs/${props.selectedUser.org_uuid}/users/${props.selectedUser.uuid}/sessions/${sessionId}`, { method: 'DELETE' }) const data = await apiJson(`/auth/api/admin/orgs/${props.selectedUser.org}/users/${props.selectedUser.uuid}/sessions/${sessionId}`, { method: 'DELETE' })
if (data.status === 'ok') { if (data.status === 'ok') {
if (data.current_session_terminated) { if (data.current_session_terminated) {
sessionStorage.clear() sessionStorage.clear()
@@ -183,7 +183,7 @@ defineExpose({ focusFirstElement })
:loading="loading" :loading="loading"
:org-display-name="userDetail.org.display_name" :org-display-name="userDetail.org.display_name"
:role-name="userDetail.role" :role-name="userDetail.role"
:update-endpoint="`/auth/api/admin/orgs/${selectedUser.org_uuid}/users/${selectedUser.uuid}/display-name`" :update-endpoint="`/auth/api/admin/orgs/${selectedUser.org}/users/${selectedUser.uuid}/display-name`"
@saved="$emit('onUserNameSaved')" @saved="$emit('onUserNameSaved')"
@edit-name="handleEditName" @edit-name="handleEditName"
/> />
@@ -212,7 +212,7 @@ defineExpose({ focusFirstElement })
:aaguid-info="userDetail.aaguid_info" :aaguid-info="userDetail.aaguid_info"
:allow-delete="true" :allow-delete="true"
:hovered-credential-uuid="hoveredCredentialUuid" :hovered-credential-uuid="hoveredCredentialUuid"
:hovered-session-credential-uuid="hoveredSession?.credential_uuid" :hovered-session-credential-uuid="hoveredSession?.credential"
:navigation-disabled="hasActiveModal" :navigation-disabled="hasActiveModal"
@delete="handleDelete" @delete="handleDelete"
@credential-hover="hoveredCredentialUuid = $event" @credential-hover="hoveredCredentialUuid = $event"
@@ -238,7 +238,7 @@ defineExpose({ focusFirstElement })
</div> </div>
<RegistrationLinkModal <RegistrationLinkModal
v-if="showRegModal" v-if="showRegModal"
:endpoint="`/auth/api/admin/orgs/${selectedUser.org_uuid}/users/${selectedUser.uuid}/create-link`" :endpoint="`/auth/api/admin/orgs/${selectedUser.org}/users/${selectedUser.uuid}/create-link`"
:user-name="userDetail?.display_name || selectedUser.display_name" :user-name="userDetail?.display_name || selectedUser.display_name"
@close="$emit('closeRegModal')" @close="$emit('closeRegModal')"
@copied="onLinkCopied" @copied="onLinkCopied"
+1 -37
View File
@@ -78,7 +78,6 @@ html {
} }
body { body {
color-scheme: light dark;
overflow: auto; overflow: auto;
scrollbar-gutter: stable; scrollbar-gutter: stable;
height: 100%; height: 100%;
@@ -132,6 +131,7 @@ a:focus-visible {
} }
.view-root { .view-root {
position: relative;
flex: 1; flex: 1;
width: 100%; width: 100%;
display: flex; display: flex;
@@ -731,42 +731,6 @@ th {
} }
} }
/* Global backdrop controlled by api.js ref-counting */
body::before {
content: '';
position: fixed;
inset: 0;
z-index: 1099;
background: transparent;
backdrop-filter: blur(0) brightness(1);
-webkit-backdrop-filter: blur(0) brightness(1);
pointer-events: none;
visibility: hidden;
transition: all 0.2s ease-out;
}
body.has-backdrop::before {
-webkit-backdrop-filter: blur(.2rem) brightness(0.5);
backdrop-filter: blur(.2rem) brightness(0.5);
visibility: visible;
}
body.has-backdrop {
overflow: auto;
}
#auth-iframe {
border: none;
position: fixed;
top: 0;
left: 0;
width: 100%;
height: 100%;
z-index: 9999;
color-scheme: auto;
background: transparent;
}
.slot-machine { .slot-machine {
padding: 0.875rem 1rem; padding: 0.875rem 1rem;
background: var(--color-surface-hover, rgba(0, 0, 0, 0.03)); background: var(--color-surface-hover, rgba(0, 0, 0, 0.03));
+18 -4
View File
@@ -1,10 +1,11 @@
<template> <template>
<div class="message-container"> <div class="message-container">
<div class="message-content"> <div class="message-content">
<h2>🔒 Access Denied</h2> <h2>{{ icon }} {{ title }}</h2>
<p v-if="message" class="error-detail">{{ message }}</p>
<div class="button-row"> <div class="button-row">
<button class="btn-secondary" @click="goBack">Back</button> <button class="btn-secondary" @click="goBack">Back</button>
<button class="btn-primary" @click="$emit('reload')">Reload Page</button> <button class="btn-primary" @click="reload">Reload Page</button>
</div> </div>
</div> </div>
</div> </div>
@@ -13,7 +14,15 @@
<script setup> <script setup>
import { goBack } from '@/utils/helpers' import { goBack } from '@/utils/helpers'
defineEmits(['reload']) const props = defineProps({
title: { type: String, default: 'Access Denied' },
icon: { type: String, default: '🔒' },
message: { type: String, default: null },
})
function reload() {
window.location.reload()
}
</script> </script>
<style scoped> <style scoped>
@@ -32,10 +41,15 @@ defineEmits(['reload'])
} }
.message-content h2 { .message-content h2 {
margin: 0 0 1.5rem; margin: 0 0 1rem;
color: var(--color-heading); color: var(--color-heading);
} }
.message-content .error-detail {
margin: 0 0 1.5rem;
color: var(--color-text-muted);
}
.message-content .button-row { .message-content .button-row {
display: flex; display: flex;
gap: 0.75rem; gap: 0.75rem;
+6 -6
View File
@@ -5,16 +5,16 @@
<template v-else> <template v-else>
<div <div
v-for="credential in credentials" v-for="credential in credentials"
:key="credential.credential_uuid" :key="credential.credential"
:class="['credential-item', { :class="['credential-item', {
'current-session': credential.is_current_session && !hoveredCredentialUuid && !hoveredSessionCredentialUuid, 'current-session': credential.is_current_session && !hoveredCredentialUuid && !hoveredSessionCredentialUuid,
'is-hovered': hoveredCredentialUuid === credential.credential_uuid, 'is-hovered': hoveredCredentialUuid === credential.credential,
'is-linked-session': hoveredSessionCredentialUuid === credential.credential_uuid 'is-linked-session': hoveredSessionCredentialUuid === credential.credential
}]" }]"
tabindex="-1" tabindex="-1"
@mousedown.prevent @mousedown.prevent
@click.capture="handleCardClick" @click.capture="handleCardClick"
@focusin="handleCredentialFocus(credential.credential_uuid)" @focusin="handleCredentialFocus(credential.credential)"
@focusout="handleCredentialBlur($event)" @focusout="handleCredentialBlur($event)"
@keydown="handleItemKeydown($event, credential)" @keydown="handleItemKeydown($event, credential)"
> >
@@ -33,8 +33,8 @@
<h4 class="item-title">{{ getCredentialAuthName(credential) }}</h4> <h4 class="item-title">{{ getCredentialAuthName(credential) }}</h4>
<div class="item-actions"> <div class="item-actions">
<span v-if="credential.is_current_session && !hoveredCredentialUuid && !hoveredSessionCredentialUuid" class="badge badge-current">Current</span> <span v-if="credential.is_current_session && !hoveredCredentialUuid && !hoveredSessionCredentialUuid" class="badge badge-current">Current</span>
<span v-else-if="hoveredCredentialUuid === credential.credential_uuid" class="badge badge-current">Selected</span> <span v-else-if="hoveredCredentialUuid === credential.credential" class="badge badge-current">Selected</span>
<span v-else-if="hoveredSessionCredentialUuid === credential.credential_uuid" class="badge badge-current">Linked</span> <span v-else-if="hoveredSessionCredentialUuid === credential.credential" class="badge badge-current">Linked</span>
<button <button
v-if="allowDelete" v-if="allowDelete"
@click="$emit('delete', credential)" @click="$emit('delete', credential)"
+8 -8
View File
@@ -8,11 +8,11 @@
<section class="section-block" ref="userInfoSection"> <section class="section-block" ref="userInfoSection">
<div class="section-body"> <div class="section-body">
<UserBasicInfo <UserBasicInfo
v-if="user" v-if="ctx"
:name="user.user_name" :name="ctx.user.display_name"
:visits="user.visits || 0" :visits="authStore.userInfo?.visits || 0"
:created-at="user.created_at" :created-at="authStore.userInfo?.created_at"
:last-seen="user.last_seen" :last-seen="authStore.userInfo?.last_seen"
:org-display-name="orgDisplayName" :org-display-name="orgDisplayName"
:role-name="roleDisplayName" :role-name="roleDisplayName"
:can-edit="false" :can-edit="false"
@@ -78,9 +78,9 @@ const currentHost = window.location.host
const userInfoSection = ref(null) const userInfoSection = ref(null)
const buttonRow = ref(null) const buttonRow = ref(null)
const user = computed(() => authStore.userInfo?.user || null) const ctx = computed(() => authStore.userInfo?.ctx || null)
const orgDisplayName = computed(() => authStore.userInfo?.org?.display_name || '') const orgDisplayName = computed(() => ctx.value?.org.display_name ?? '')
const roleDisplayName = computed(() => authStore.userInfo?.role?.display_name || '') const roleDisplayName = computed(() => ctx.value?.role.display_name ?? '')
const headingTitle = computed(() => { const headingTitle = computed(() => {
const service = authStore.settings?.rp_name const service = authStore.settings?.rp_name
+54 -16
View File
@@ -1,5 +1,15 @@
<template> <template>
<section class="view-root" data-view="profile"> <section class="view-root" data-view="profile">
<div class="theme-toggle">
<button class="theme-btn" @click="themeMenuOpen = !themeMenuOpen" :title="themeTitle">
{{ themeEmoji }}
</button>
<div v-if="themeMenuOpen" class="theme-menu" @click="themeMenuOpen = false">
<button class="theme-option top" :class="{ active: selectedTheme === '' }" @click.stop="setTheme('')" title="Auto">🌓</button>
<button class="theme-option left" :class="{ active: selectedTheme === 'light' }" @click.stop="setTheme('light')" title="Light"></button>
<button class="theme-option right" :class="{ active: selectedTheme === 'dark' }" @click.stop="setTheme('dark')" title="Dark">🌙</button>
</div>
</div>
<header class="view-header"> <header class="view-header">
<h1>User Profile</h1> <h1>User Profile</h1>
<Breadcrumbs ref="breadcrumbs" :entries="breadcrumbEntries" @keydown="handleBreadcrumbKeydown" /> <Breadcrumbs ref="breadcrumbs" :entries="breadcrumbEntries" @keydown="handleBreadcrumbKeydown" />
@@ -8,12 +18,12 @@
<section class="section-block" ref="userInfoSection"> <section class="section-block" ref="userInfoSection">
<UserBasicInfo <UserBasicInfo
v-if="authStore.userInfo?.user" v-if="authStore.userInfo?.ctx"
ref="userBasicInfo" ref="userBasicInfo"
:name="authStore.userInfo.user.user_name" :name="authStore.userInfo.ctx.user.display_name"
:visits="authStore.userInfo.user.visits || 0" :visits="authStore.userInfo.visits"
:created-at="authStore.userInfo.user.created_at" :created-at="authStore.userInfo.created_at"
:last-seen="authStore.userInfo.user.last_seen" :last-seen="authStore.userInfo.last_seen"
:loading="authStore.isLoading" :loading="authStore.isLoading"
update-endpoint="/auth/api/user/display-name" update-endpoint="/auth/api/user/display-name"
@saved="authStore.loadUserInfo()" @saved="authStore.loadUserInfo()"
@@ -47,7 +57,7 @@
:aaguid-info="authStore.userInfo?.aaguid_info || {}" :aaguid-info="authStore.userInfo?.aaguid_info || {}"
:loading="authStore.isLoading" :loading="authStore.isLoading"
:hovered-credential-uuid="hoveredCredentialUuid" :hovered-credential-uuid="hoveredCredentialUuid"
:hovered-session-credential-uuid="hoveredSession?.credential_uuid" :hovered-session-credential-uuid="hoveredSession?.credential"
:navigation-disabled="hasActiveModal" :navigation-disabled="hasActiveModal"
allow-delete allow-delete
@delete="handleDelete" @delete="handleDelete"
@@ -127,8 +137,9 @@ import { useAuthStore } from '@/stores/auth'
import { adminUiPath, makeUiHref } from '@/utils/settings' import { adminUiPath, makeUiHref } from '@/utils/settings'
import passkey from '@/utils/passkey' import passkey from '@/utils/passkey'
import { goBack } from '@/utils/helpers' import { goBack } from '@/utils/helpers'
import { apiJson } from '@/utils/api' import { apiJson } from 'paskia'
import { navigateButtonRow, focusPreferred, focusAtIndex, getDirection } from '@/utils/keynav' import { navigateButtonRow, focusPreferred, focusAtIndex, getDirection } from '@/utils/keynav'
import { updateThemeFromSession } from '@/utils/theme'
const authStore = useAuthStore() const authStore = useAuthStore()
const updateInterval = ref(null) const updateInterval = ref(null)
@@ -148,10 +159,26 @@ const breadcrumbs = ref(null)
const userBasicInfo = ref(null) const userBasicInfo = ref(null)
const userInfoSection = ref(null) const userInfoSection = ref(null)
// Theme preference
const selectedTheme = ref('')
const themeMenuOpen = ref(false)
const themeEmoji = computed(() => ({ '': '🌓', light: '', dark: '🌙' })[selectedTheme.value] || '🌓')
const themeTitle = computed(() => ({ '': 'Auto (system)', light: 'Light mode', dark: 'Dark mode' })[selectedTheme.value] || 'Theme')
watch(() => authStore.userInfo?.ctx?.user?.theme, (t) => { selectedTheme.value = t || '' }, { immediate: true })
function setTheme(theme) {
selectedTheme.value = theme
themeMenuOpen.value = false
// Apply immediately for instant feedback
updateThemeFromSession({ user: { theme } }, true)
// Save to server in background
apiJson('/auth/api/user/theme', { method: 'PATCH', body: { theme } })
.catch(e => authStore.showMessage(e.message, 'error'))
}
// Check if any modal/dialog is open (blocks arrow key navigation) // Check if any modal/dialog is open (blocks arrow key navigation)
const hasActiveModal = computed(() => showNameDialog.value || showRegLink.value) const hasActiveModal = computed(() => showNameDialog.value || showRegLink.value)
watch(showNameDialog, (newVal) => { if (newVal) newName.value = authStore.userInfo?.user?.user_name || '' }) watch(showNameDialog, (newVal) => { if (newVal) newName.value = authStore.userInfo?.ctx.user.display_name ?? '' })
onMounted(() => { onMounted(() => {
updateInterval.value = setInterval(() => { if (authStore.userInfo) authStore.userInfo = { ...authStore.userInfo } }, 60000) updateInterval.value = setInterval(() => { if (authStore.userInfo) authStore.userInfo = { ...authStore.userInfo } }, 60000)
@@ -292,7 +319,7 @@ const handleLogoutButtonKeydown = (event) => {
} }
const handleDelete = async (credential) => { const handleDelete = async (credential) => {
const credentialId = credential?.credential_uuid const credentialId = credential?.credential
if (!credentialId) return if (!credentialId) return
try { try {
await authStore.deleteCredential(credentialId) await authStore.deleteCredential(credentialId)
@@ -323,8 +350,11 @@ const terminateSession = async (session) => {
const logoutEverywhere = async () => { await authStore.logoutEverywhere() } const logoutEverywhere = async () => { await authStore.logoutEverywhere() }
const logout = async () => { await authStore.logout() } const logout = async () => { await authStore.logout() }
const openNameDialog = () => { newName.value = authStore.userInfo?.user?.user_name || ''; showNameDialog.value = true } const openNameDialog = () => { newName.value = authStore.userInfo?.ctx.user.display_name ?? ''; showNameDialog.value = true }
const isAdmin = computed(() => !!(authStore.userInfo?.is_global_admin || authStore.userInfo?.is_org_admin)) const isAdmin = computed(() => {
const perms = authStore.userInfo?.ctx.permissions
return perms.includes('auth:admin') || perms.includes('auth:org:admin')
})
const hasMultipleSessions = computed(() => sessions.value.length > 1) const hasMultipleSessions = computed(() => sessions.value.length > 1)
const breadcrumbEntries = computed(() => { const entries = [{ label: 'Auth', href: makeUiHref() }]; if (isAdmin.value) entries.push({ label: 'Admin', href: adminUiPath() }); return entries }) const breadcrumbEntries = computed(() => { const entries = [{ label: 'Auth', href: makeUiHref() }]; if (isAdmin.value) entries.push({ label: 'Admin', href: adminUiPath() }); return entries })
@@ -333,7 +363,7 @@ const saveName = async () => {
if (!name) { authStore.showMessage('Name cannot be empty', 'error'); return } if (!name) { authStore.showMessage('Name cannot be empty', 'error'); return }
try { try {
saving.value = true saving.value = true
await apiJson('/auth/api/user/display-name', { method: 'PUT', body: { display_name: name } }) await apiJson('/auth/api/user/display-name', { method: 'PATCH', body: { display_name: name } })
showNameDialog.value = false showNameDialog.value = false
await authStore.loadUserInfo() await authStore.loadUserInfo()
authStore.showMessage('Name updated successfully!', 'success', 3000) authStore.showMessage('Name updated successfully!', 'success', 3000)
@@ -349,8 +379,16 @@ const saveName = async () => {
.logout-note { margin: 0.75rem 0 0; color: var(--color-text-muted); font-size: 0.875rem; } .logout-note { margin: 0.75rem 0 0; color: var(--color-text-muted); font-size: 0.875rem; }
.remote-auth-inline { display: flex; flex-direction: column; gap: 0.5rem; } .remote-auth-inline { display: flex; flex-direction: column; gap: 0.5rem; }
.remote-auth-label { display: block; margin: 0; font-size: 0.875rem; color: var(--color-text-muted); font-weight: 500; } .remote-auth-label { display: block; margin: 0; font-size: 0.875rem; color: var(--color-text-muted); font-weight: 500; }
.remote-auth-description { .remote-auth-description { font-size: 0.75rem; color: var(--color-text-muted); }
font-size: 0.75rem; .theme-toggle { position: absolute; top: var(--layout-padding); right: var(--layout-padding); }
color: var(--color-text-muted); .theme-btn { background: none; border: none; padding: 0.25rem; font-size: 1.25rem; cursor: pointer; opacity: 0.5; transition: opacity 0.15s; }
} .theme-btn:hover { opacity: 0.8; }
.theme-menu { position: absolute; top: 100%; right: 0; width: 5rem; height: 4rem; margin-top: 0.25rem; }
.theme-option { position: absolute; background: none; border: none; font-size: 1.25rem; cursor: pointer; opacity: 0.5; padding: 0.25rem; border-radius: var(--radius-sm); transition: opacity 0.15s, transform 0.15s; }
.theme-option:hover { opacity: 1; transform: scale(1.2); }
.theme-option.active { opacity: 1; }
.theme-option.top { top: 0; left: 50%; transform: translateX(-50%); }
.theme-option.top:hover { transform: translateX(-50%) scale(1.2); }
.theme-option.left { bottom: 0; left: 0; }
.theme-option.right { bottom: 0; right: 0; }
</style> </style>
@@ -35,9 +35,10 @@
<script setup> <script setup>
import { ref, onMounted, onUnmounted, nextTick } from 'vue' import { ref, onMounted, onUnmounted, nextTick } from 'vue'
import QRCodeDisplay from '@/components/QRCodeDisplay.vue' import QRCodeDisplay from '@/components/QRCodeDisplay.vue'
import { apiJson } from '@/utils/api' import { apiJson } from 'paskia'
import { formatDate } from '@/utils/helpers' import { formatDate } from '@/utils/helpers'
import { getDirection } from '@/utils/keynav' import { getDirection } from '@/utils/keynav'
import { useAuthStore } from '@/stores/auth'
const props = defineProps({ const props = defineProps({
endpoint: { type: String, required: true }, endpoint: { type: String, required: true },
@@ -46,6 +47,7 @@ const props = defineProps({
const emit = defineEmits(['close', 'copied']) const emit = defineEmits(['close', 'copied'])
const authStore = useAuthStore()
const dialog = ref(null) const dialog = ref(null)
const linkUrl = ref(null) const linkUrl = ref(null)
const expiresAt = ref(null) const expiresAt = ref(null)
@@ -73,7 +75,8 @@ async function generateLink() {
} else { } else {
emit('close') emit('close')
} }
} catch { } catch (e) {
authStore.showMessage(e.message || 'Failed to generate link', 'error')
emit('close') emit('close')
} }
} }
+12 -13
View File
@@ -58,7 +58,7 @@
import { computed, nextTick, onMounted, onUnmounted, reactive, ref, watch } from 'vue' import { computed, nextTick, onMounted, onUnmounted, reactive, ref, watch } from 'vue'
import passkey from '@/utils/passkey' import passkey from '@/utils/passkey'
import { getSettings, uiBasePath } from '@/utils/settings' import { getSettings, uiBasePath } from '@/utils/settings'
import { fetchJson, getUserFriendlyErrorMessage } from '@/utils/api' import { fetchJson, getUserFriendlyErrorMessage } from 'paskia'
import RemoteAuthRequest from '@/components/RemoteAuthRequest.vue' import RemoteAuthRequest from '@/components/RemoteAuthRequest.vue'
import { focusDialogButton } from '@/utils/keynav' import { focusDialogButton } from '@/utils/keynav'
@@ -76,13 +76,13 @@ const status = reactive({ show: false, message: '', type: 'info' })
const initializing = ref(true) const initializing = ref(true)
const loading = ref(false) const loading = ref(false)
const settings = ref(null) const settings = ref(null)
const userInfo = ref(null) const session = ref(null)
const currentView = ref('initial') // 'initial', 'login', 'forbidden' const currentView = ref('initial') // 'initial', 'login', 'forbidden'
const authView = ref('local') // 'local' or 'remote' const authView = ref('local') // 'local' or 'remote'
const buttonRow = ref(null) const buttonRow = ref(null)
let statusTimer = null let statusTimer = null
const isAuthenticated = computed(() => !!userInfo.value?.authenticated) const isAuthenticated = computed(() => !!session.value)
const canAuthenticate = computed(() => { const canAuthenticate = computed(() => {
if (initializing.value) return false if (initializing.value) return false
@@ -115,7 +115,7 @@ const headerMessage = computed(() => {
return 'Please sign in with your passkey.' return 'Please sign in with your passkey.'
}) })
const userDisplayName = computed(() => userInfo.value?.user?.user_name || 'User') const userDisplayName = computed(() => session.value?.ctx.user.display_name || 'User')
function showMessage(message, type = 'info', duration = 3000) { function showMessage(message, type = 'info', duration = 3000) {
status.show = true status.show = true
@@ -140,22 +140,21 @@ async function fetchSettings() {
} }
} }
async function fetchUserInfo() { async function validateSession() {
try { try {
userInfo.value = await fetchJson('/auth/api/user-info', { method: 'POST' }) session.value = await fetchJson('/auth/api/validate', { method: 'POST' })
if (isAuthenticated.value && props.mode !== 'reauth') { if (isAuthenticated.value && props.mode !== 'reauth') {
currentView.value = 'forbidden' currentView.value = 'forbidden'
emit('forbidden', userInfo.value) emit('forbidden', session.value)
} else { } else {
currentView.value = 'login' currentView.value = 'login'
} }
} catch (error) { } catch (error) {
console.error('Failed to load user info', error) session.value = null
currentView.value = 'login'
if (error.status !== 401 && error.status !== 403) { if (error.status !== 401 && error.status !== 403) {
showMessage(getUserFriendlyErrorMessage(error), 'error', 4000) showMessage(getUserFriendlyErrorMessage(error), 'error', 4000)
} }
userInfo.value = null
currentView.value = 'login'
} }
} }
@@ -188,7 +187,7 @@ async function logoutUser() {
loading.value = true loading.value = true
try { try {
await fetchJson('/auth/api/logout', { method: 'POST' }) await fetchJson('/auth/api/logout', { method: 'POST' })
userInfo.value = null session.value = null
currentView.value = 'login' currentView.value = 'login'
showMessage('Logged out. You can sign in with a different account.', 'info', 3000) showMessage('Logged out. You can sign in with a different account.', 'info', 3000)
} catch (error) { } catch (error) {
@@ -266,7 +265,7 @@ watch(initializing, (newVal) => {
onMounted(async () => { onMounted(async () => {
await fetchSettings() await fetchSettings()
await fetchUserInfo() await validateSession()
initializing.value = false initializing.value = false
// Add click handler for inline links // Add click handler for inline links
@@ -280,7 +279,7 @@ onUnmounted(() => {
defineExpose({ defineExpose({
showMessage, showMessage,
isAuthenticated, isAuthenticated,
userInfo session
}) })
</script> </script>
+2 -2
View File
@@ -20,7 +20,7 @@
:class="['session-item', { :class="['session-item', {
'is-current': session.is_current && !hoveredIp && !hoveredCredentialUuid, 'is-current': session.is_current && !hoveredIp && !hoveredCredentialUuid,
'is-hovered': hoveredSession?.id === session.id, 'is-hovered': hoveredSession?.id === session.id,
'is-linked-credential': hoveredCredentialUuid === session.credential_uuid 'is-linked-credential': hoveredCredentialUuid === session.credential
}]" }]"
tabindex="-1" tabindex="-1"
@mousedown.prevent @mousedown.prevent
@@ -34,7 +34,7 @@
<div class="item-actions"> <div class="item-actions">
<span v-if="session.is_current && !hoveredIp && !hoveredCredentialUuid" class="badge badge-current">Current</span> <span v-if="session.is_current && !hoveredIp && !hoveredCredentialUuid" class="badge badge-current">Current</span>
<span v-else-if="hoveredSession?.id === session.id" class="badge badge-current">Selected</span> <span v-else-if="hoveredSession?.id === session.id" class="badge badge-current">Selected</span>
<span v-else-if="hoveredCredentialUuid === session.credential_uuid" class="badge badge-current">Linked</span> <span v-else-if="hoveredCredentialUuid === session.credential" class="badge badge-current">Linked</span>
<span v-else-if="!hoveredCredentialUuid && isSameHost(session.ip)" class="badge">Same IP</span> <span v-else-if="!hoveredCredentialUuid && isSameHost(session.ip)" class="badge">Same IP</span>
<button <button
@click="$emit('terminate', session)" @click="$emit('terminate', session)"
+8 -4
View File
@@ -1,7 +1,8 @@
import { defineStore } from 'pinia' import { defineStore } from 'pinia'
import { register, authenticate } from '@/utils/passkey' import { register, authenticate } from '@/utils/passkey'
import { getSettings } from '@/utils/settings' import { getSettings } from '@/utils/settings'
import { apiJson } from '@/utils/api' import { apiJson } from 'paskia'
import { updateThemeFromSession } from '@/utils/theme'
export const useAuthStore = defineStore('auth', { export const useAuthStore = defineStore('auth', {
state: () => ({ state: () => ({
@@ -26,16 +27,18 @@ export const useAuthStore = defineStore('auth', {
setLoading(flag) { setLoading(flag) {
this.isLoading = !!flag this.isLoading = !!flag
}, },
showMessage(message, type = 'info', duration = 3000) { showMessage(message, type = 'info', duration = null) {
// Default duration: 5 seconds for errors, 3 seconds for others
const effectiveDuration = duration ?? (type === 'error' ? 5000 : 3000)
this.status = { this.status = {
message, message,
type, type,
show: true show: true
} }
if (duration > 0) { if (effectiveDuration > 0) {
setTimeout(() => { setTimeout(() => {
this.status.show = false this.status.show = false
}, duration) }, effectiveDuration)
} }
}, },
async setSessionCookie(result) { async setSessionCookie(result) {
@@ -84,6 +87,7 @@ export const useAuthStore = defineStore('auth', {
async loadUserInfo() { async loadUserInfo() {
try { try {
this.userInfo = await apiJson('/auth/api/user-info', { method: 'POST' }) this.userInfo = await apiJson('/auth/api/user-info', { method: 'POST' })
updateThemeFromSession(this.userInfo?.ctx)
console.log('User info loaded:', this.userInfo) console.log('User info loaded:', this.userInfo)
} catch (error) { } catch (error) {
// Suppress toast for 401/403 errors - the auth iframe will handle these // Suppress toast for 401/403 errors - the auth iframe will handle these
+1 -375
View File
@@ -1,77 +1,3 @@
/**
* API fetch wrapper that handles authentication errors with iframe-based re-authentication.
*
* When a 401 or 403 response is received with an `auth` object containing `iframe` URL,
* this wrapper shows an authentication iframe and retries the original request after
* successful authentication.
*/
/** Default timeout for API requests in milliseconds */
const DEFAULT_TIMEOUT_MS = 1000
/**
* Custom error class for API errors with full response context.
*/
export class ApiError extends Error {
constructor(url, response, data) {
super(data?.detail || `Request failed: ${response.status}`)
this.name = 'ApiError'
this.url = url
this.status = response.status
this.statusText = response.statusText
this.data = data
}
}
/**
* Custom error class for network/timeout errors.
*/
export class NetworkError extends Error {
constructor(message, originalError = null) {
super(message)
this.name = 'NetworkError'
this.originalError = originalError
}
}
/**
* Error thrown when user cancels authentication.
*/
export class AuthCancelledError extends Error {
constructor() {
super('Authentication cancelled')
this.name = 'AuthCancelledError'
}
}
let authIframe = null
let authPromise = null
let authResolve = null
let authReject = null
// Global backdrop ref-count (works independently of Pinia store)
let backdropHolders = 0
/**
* Hold global backdrop (increment ref-count).
* Multiple callers can hold the backdrop; it only hides when all release.
*/
export function holdGlobalBackdrop() {
backdropHolders++
document.body.classList.add('has-backdrop')
}
/**
* Release global backdrop (decrement ref-count).
* Backdrop hides only when ref-count reaches zero.
*/
export function releaseGlobalBackdrop() {
backdropHolders = Math.max(0, backdropHolders - 1)
if (backdropHolders === 0) {
document.body.classList.remove('has-backdrop')
}
}
// Cache for auth iframe URL by mode // Cache for auth iframe URL by mode
const authIframeUrlCache = {} const authIframeUrlCache = {}
@@ -88,7 +14,7 @@ export async function getAuthIframeUrl(mode = 'login') {
} }
// Fetch from forward endpoint - it returns URL in auth.iframe on 401/403 // Fetch from forward endpoint - it returns URL in auth.iframe on 401/403
const response = await fetch('/auth/api/forward', { credentials: 'include' }) const response = await fetch('/auth/api/forward')
if (response.status === 401 || response.status === 403) { if (response.status === 401 || response.status === 403) {
const data = await response.json() const data = await response.json()
if (data.auth?.iframe) { if (data.auth?.iframe) {
@@ -104,303 +30,3 @@ export async function getAuthIframeUrl(mode = 'login') {
} }
throw new Error('Unable to fetch auth iframe URL') throw new Error('Unable to fetch auth iframe URL')
} }
/**
* Check if an auth iframe is already open (from any source).
* @returns {boolean}
*/
export function isAuthIframeOpen() {
return !!document.getElementById('auth-iframe')
}
/**
* Show the authentication iframe and return a promise that resolves on success.
* If an auth iframe is already open (from any source), hooks into its completion.
* Uses global backdrop system to avoid flicker between auth and caller's UI.
* @param {string} iframeUrl - The URL for the iframe src
* @returns {Promise<void>}
* @throws {AuthCancelledError} - If authentication is cancelled by user
*/
export function showAuthIframe(iframeUrl) {
// If we already have a promise (from us), return it
if (authPromise) return authPromise
// If there's already an iframe in the DOM (from App.vue or elsewhere),
// create a promise that hooks into the message handler
if (document.getElementById('auth-iframe')) {
authPromise = new Promise((resolve, reject) => {
authResolve = resolve
authReject = reject
})
return authPromise
}
authPromise = new Promise((resolve, reject) => {
authResolve = resolve
authReject = reject
})
// Remove existing iframe if any
hideAuthIframe()
// Hold global backdrop for auth iframe
holdGlobalBackdrop()
// Create new iframe for authentication using src URL
authIframe = document.createElement('iframe')
authIframe.id = 'auth-iframe'
authIframe.title = 'Authentication'
authIframe.allow = 'publickey-credentials-get; publickey-credentials-create'
authIframe.src = iframeUrl
document.body.appendChild(authIframe)
return authPromise
}
function hideAuthIframe() {
if (authIframe) {
authIframe.remove()
authIframe = null
releaseGlobalBackdrop()
}
}
function handleAuthMessage(event) {
const data = event.data
if (!data?.type) return
switch (data.type) {
case 'auth-success':
hideAuthIframe()
if (authResolve) {
authResolve()
authPromise = null
authResolve = null
authReject = null
}
break
case 'auth-back':
case 'auth-close-request':
hideAuthIframe()
if (authReject) {
authReject(new AuthCancelledError())
authPromise = null
authResolve = null
authReject = null
}
break
case 'auth-error':
// Keep iframe open for retry, but if cancelled, treat as back
if (data.cancelled && authReject) {
hideAuthIframe()
authReject(new AuthCancelledError())
authPromise = null
authResolve = null
authReject = null
}
break
}
}
// Install global message listener
if (typeof window !== 'undefined') {
window.addEventListener('message', handleAuthMessage)
}
/**
* Fetch wrapper that handles auth errors with iframe-based re-authentication.
* Loops until successful or user cancels authentication.
*
* @param {string|URL} url - The URL to fetch
* @param {RequestInit} [options] - Fetch options
* @param {number} [options.timeout] - Timeout in ms (default: 10000, use 0 to disable)
* @returns {Promise<Response>} - The fetch response
* @throws {AuthCancelledError} - If authentication is cancelled by user
* @throws {NetworkError} - If network error or timeout occurs
*/
export async function apiFetch(url, options = {}) {
const { timeout = DEFAULT_TIMEOUT_MS, ...fetchOptions } = options
// Ensure credentials are included for cookie-based auth
fetchOptions.credentials = fetchOptions.credentials || 'include'
while (true) {
let response
try {
response = await fetch(url, {...fetchOptions, signal: timeout && AbortSignal.timeout(timeout)})
} catch (error) {
// Handle network errors and timeouts
if (error.name === 'TimeoutError') {
throw new NetworkError('Request timed out', error)
}
if (error.name === 'AbortError') {
// Re-throw abort errors as-is (user-initiated cancellation)
throw error
}
if (error.name === 'TypeError' && error.message === 'Failed to fetch') {
throw new NetworkError('Unable to connect to server', error)
}
throw new NetworkError(error.message || 'Network error', error)
}
// Check for auth errors (401/403)
if (response.status === 401 || response.status === 403) {
// Try to parse the response to get the iframe URL
let authInfo = null
try {
const data = await response.clone().json()
authInfo = data.auth
} catch {
// If we can't parse JSON, no iframe available
}
// Authenticate via iframe (only in top-level window)
if (authInfo?.iframe && window === window.top) {
// Show auth iframe (or wait for existing one) and retry on success
// showAuthIframe returns existing promise if iframe is already open
await showAuthIframe(authInfo.iframe)
continue // Retry the original request
}
}
return response
}
}
/**
* Convenience method for JSON API calls.
* Automatically sets Accept and Content-Type headers.
* Returns parsed JSON directly if response is ok, throws ApiError otherwise.
*
* @param {string|URL} url - The URL to fetch
* @param {RequestInit} [options] - Fetch options
* @returns {Promise<any>} - Parsed JSON response
* @throws {ApiError} - If response is not ok
* @throws {NetworkError} - If network error or timeout occurs
* @throws {AuthCancelledError} - If authentication is cancelled by user
*/
export async function apiJson(url, options = {}) {
const fetchOptions = { ...options }
// Set default headers, allowing caller overrides
fetchOptions.headers = {
'Accept': 'application/json',
...fetchOptions.headers,
}
// Set Content-Type for requests with JSON body
if (fetchOptions.body && typeof fetchOptions.body === 'object' && !(fetchOptions.body instanceof FormData)) {
fetchOptions.headers = {
'Content-Type': 'application/json',
...fetchOptions.headers,
}
fetchOptions.body = JSON.stringify(fetchOptions.body)
}
const response = await apiFetch(url, fetchOptions)
const data = await response.json()
if (!response.ok) {
throw new ApiError(url, response, data)
}
return data
}
/**
* Simple JSON fetch without auto-auth iframe handling.
* Use this in contexts where showing an auth iframe would be inappropriate
* (e.g., inside the auth iframe itself).
*
* @param {string|URL} url - The URL to fetch
* @param {RequestInit} [options] - Fetch options
* @returns {Promise<any>} - Parsed JSON response
* @throws {ApiError} - If response is not ok
*/
export async function fetchJson(url, options = {}) {
const fetchOptions = {
credentials: 'include',
...options,
headers: {
'Accept': 'application/json',
...options.headers,
},
}
const response = await fetch(url, fetchOptions)
const data = await response.json()
if (!response.ok) {
throw new ApiError(url, response, data)
}
return data
}
/**
* Convert an error to a user-friendly message.
* @param {Error} error - The error to convert
* @returns {string} - User-friendly error message
*/
export function getUserFriendlyErrorMessage(error) {
if (error instanceof NetworkError) {
return error.message
}
if (error instanceof ApiError) {
return error.message
}
if (error.name === 'TimeoutError') {
return 'Request timed out'
}
if (error.name === 'TypeError' && error.message === 'Failed to fetch') {
return 'Unable to connect to server'
}
return error.message || 'An error occurred'
}
/**
* Check if an error should show a toast to the user.
* @param {Error} error - The error to check
* @returns {boolean} - Whether to show a toast
*/
export function shouldShowErrorToast(error) {
// Don't show toast for user cancellations
if (error instanceof AuthCancelledError) return false
if (error.name === 'AbortError') return false
// Don't show toast for 401/403 errors - the auth iframe will handle these
if (error instanceof ApiError && (error.status === 401 || error.status === 403)) return false
return true
}
/**
* Create an API caller with error handling (toast + console.error).
* Wraps apiJson calls with consistent error handling for apps.
*
* @param {Function} showMessage - Function to show toast messages: (message, type, duration) => void
* @returns {Function} - Wrapped apiJson that handles errors
*/
export function createApiCaller(showMessage) {
/**
* @param {string|URL} url - The URL to fetch
* @param {RequestInit} [options] - Fetch options
* @returns {Promise<any>} - Parsed JSON response, or undefined on error
*/
return async function apiCall(url, options = {}) {
try {
return await apiJson(url, options)
} catch (error) {
if (!shouldShowErrorToast(error)) {
throw error
}
// Log full error details
console.error(`API error for ${url}:`, error instanceof ApiError ? { status: error.status, statusText: error.statusText, data: error.data } : error)
// Show user-friendly toast
showMessage(getUserFriendlyErrorMessage(error), 'error', 4000)
throw error
}
}
}
export default apiFetch
+1 -1
View File
@@ -1,7 +1,7 @@
import { startRegistration, startAuthentication } from '@simplewebauthn/browser' import { startRegistration, startAuthentication } from '@simplewebauthn/browser'
import aWebSocket from '@/utils/awaitable-websocket' import aWebSocket from '@/utils/awaitable-websocket'
import { getSettings } from '@/utils/settings' import { getSettings } from '@/utils/settings'
import { showAuthIframe } from '@/utils/api' import { showAuthIframe } from 'paskia'
// Generic path normalizer: if an auth_host is configured and differs from current // Generic path normalizer: if an auth_host is configured and differs from current
// host, return absolute URL (scheme derived by aWebSocket). Otherwise, keep as-is. // host, return absolute URL (scheme derived by aWebSocket). Otherwise, keep as-is.
+101
View File
@@ -0,0 +1,101 @@
// Theme override utilities - shared across apps
// User preference or URL hash can force light/dark mode
export const themeColors = {
light: {
'color-canvas': '#ffffff',
'color-surface': '#eff6ff',
'color-surface-subtle': '#dbeafe',
'color-border': '#2563eb',
'color-border-strong': '#1e40af',
'color-heading': '#1e3a8a',
'color-text': '#1e293b',
'color-text-muted': '#475569',
'color-link': '#1d4ed8',
'color-link-hover': '#1e40af',
'color-accent': '#2563eb',
'color-accent-strong': '#1e40af',
'color-accent-contrast': '#ffffff',
'color-success-text': '#166534',
'color-success-bg': '#dcfce7',
'color-error-text': '#b91c1c',
'color-error-bg': '#fee2e2',
'color-info-text': '#1e40af',
'color-info-bg': '#dbeafe',
'color-danger': '#dc2626',
'shadow-soft': '0 10px 30px rgba(30, 64, 175, 0.15)',
},
dark: {
'color-canvas': '#0f172a',
'color-surface': '#141b2f',
'color-surface-subtle': '#1b243b',
'color-border': '#25304a',
'color-border-strong': '#3d4d6b',
'color-heading': '#fff',
'color-text': '#e2e8f0',
'color-text-muted': '#94a3b8',
'color-link': '#60a5fa',
'color-link-hover': '#93c5fd',
'color-accent': '#60a5fa',
'color-accent-strong': '#3b82f6',
'color-accent-contrast': '#0b1120',
'color-success-text': '#34d399',
'color-success-bg': '#1a4d2e',
'color-error-text': '#fca5a5',
'color-error-bg': '#4a1f1f',
'color-info-text': '#bae6fd',
'color-info-bg': '#1e3a5f',
'color-danger': '#f87171',
'shadow-soft': '0 0 0 #000000',
}
}
const STYLE_ID = 'theme-override'
const TRANSITION_ID = 'theme-transition'
const STORAGE_KEY = 'paskia-theme'
/** Apply theme override CSS - selector targets .surface for restricted app, :root for main apps */
export function applyTheme(theme, selector = ':root', animate = false) {
// Add temporary transition for smooth theme change
if (animate) {
let transitionStyle = document.getElementById(TRANSITION_ID)
if (!transitionStyle) {
transitionStyle = document.createElement('style')
transitionStyle.id = TRANSITION_ID
transitionStyle.textContent = '*, *::before, *::after { transition: background-color 0.3s, color 0.3s, border-color 0.3s, box-shadow 0.3s !important; }'
document.head.appendChild(transitionStyle)
}
setTimeout(() => document.getElementById(TRANSITION_ID)?.remove(), 350)
}
document.getElementById(STYLE_ID)?.remove()
if (theme && themeColors[theme]) {
const css = `${selector} { ${Object.entries(themeColors[theme]).map(([k, v]) => `--${k}: ${v}`).join('; ')}; }`
const style = document.createElement('style')
style.id = STYLE_ID
style.textContent = css
document.head.appendChild(style)
}
}
/** Get theme from localStorage cache */
export function getCachedTheme() {
return localStorage.getItem(STORAGE_KEY) || ''
}
/** Cache theme in localStorage */
export function setCachedTheme(theme) {
if (theme) localStorage.setItem(STORAGE_KEY, theme)
else localStorage.removeItem(STORAGE_KEY)
}
/** Initialize theme from user preference (with localStorage cache for fast load) */
export function initThemeFromCache() {
applyTheme(getCachedTheme())
}
/** Update theme from session context (call after login/session load) */
export function updateThemeFromSession(ctx, animate = false) {
const theme = ctx?.user?.theme || ''
setCachedTheme(theme)
applyTheme(theme, ':root', animate)
}
+35
View File
@@ -0,0 +1,35 @@
/**
* FastAPI-Vue Vite Plugin
*
* Configures Vite for FastAPI backend integration:
* - Proxies /api/* requests to the FastAPI backend
* - Builds to the Python module's frontend-build directory
*
* Environment variables (with defaults):
* FASTAPI_VUE_BACKEND_URL=http://localhost:5180 - Backend API URL for proxying
*/
const backendUrl = process.env.FASTAPI_VUE_BACKEND_URL || "http://localhost:5180"
export default function fastapiVue({ paths = ["/api"] } = {}) {
// Build proxy configuration for each path
const proxy = {}
for (const path of paths) {
proxy[path] = {
target: backendUrl,
changeOrigin: false,
ws: true,
}
}
return {
name: "fastapi-vite",
config: () => ({
server: { proxy },
build: {
outDir: "../paskia/frontend-build",
emptyOutDir: true,
},
}),
}
}
+12 -19
View File
@@ -4,6 +4,7 @@ import { resolve } from 'node:path'
import vue from '@vitejs/plugin-vue' import vue from '@vitejs/plugin-vue'
import { existsSync, renameSync, mkdirSync } from 'node:fs' import { existsSync, renameSync, mkdirSync } from 'node:fs'
import sirv from 'sirv' import sirv from 'sirv'
import fastapiVue from './vite-plugin-fastapi.js'
// Auth host mode: when set, clients accessing the auth host get /auth/ at / and /auth/admin/ at /admin/ // Auth host mode: when set, clients accessing the auth host get /auth/ at / and /auth/admin/ at /admin/
const authHost = process.env.PASKIA_AUTH_HOST const authHost = process.env.PASKIA_AUTH_HOST
@@ -12,6 +13,14 @@ export default defineConfig(({ command }) => ({
appType: 'mpa', appType: 'mpa',
publicDir: 'public', publicDir: 'public',
plugins: [ plugins: [
fastapiVue({ paths: [
"/auth/api",
"/auth/ws",
// Passphrase links: /auth/word1.word2.word3.word4.word5
"^/auth/[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+$",
// Passphrase links: /word1.word2.word3.word4.word5
"^/[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+$",
] }),
vue(), vue(),
// Auth host routing: rewrite paths when accessing dedicated auth host // Auth host routing: rewrite paths when accessing dedicated auth host
// Must run before serve-examples to handle / correctly // Must run before serve-examples to handle / correctly
@@ -81,7 +90,9 @@ export default defineConfig(({ command }) => ({
} }
].filter(Boolean), ].filter(Boolean),
resolve: { resolve: {
alias: { '@': fileURLToPath(new URL('./src', import.meta.url)) } alias: {
'@': fileURLToPath(new URL('./src', import.meta.url)),
}
}, },
base: '/', base: '/',
server: { server: {
@@ -89,24 +100,6 @@ export default defineConfig(({ command }) => ({
allowedHosts: true, allowedHosts: true,
fs: { fs: {
allow: ['..'] allow: ['..']
},
proxy: {
// Only proxy these two specific backend API paths
'/auth/api': {
target: 'http://localhost:4402'
},
'/auth/ws': {
target: 'http://localhost:4402',
ws: true
},
// Passphrase links: /auth/word1.word2.word3.word4.word5
'^/auth/[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+$': {
target: 'http://localhost:4402'
},
// Passphrase links: /word1.word2.word3.word4.word5
'^/[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+\\.[a-z]+$': {
target: 'http://localhost:4402'
}
} }
}, },
build: { build: {
+30
View File
@@ -0,0 +1,30 @@
# Logs
logs
*.log
npm-debug.log*
yarn-debug.log*
yarn-error.log*
pnpm-debug.log*
lerna-debug.log*
node_modules
.DS_Store
dist
dist-ssr
coverage
*.local
/cypress/videos/
/cypress/screenshots/
# Editor directories and files
.vscode/*
!.vscode/extensions.json
.idea
*.suo
*.ntvs*
*.njsproj
*.sln
*.sw?
*.tsbuildinfo
+131
View File
@@ -0,0 +1,131 @@
# Paskia
![Screenshot](https://git.zi.fi/leovasanko/paskia/raw/main/docs/screenshots/forbidden-light.webp)
JavaScript utilities for [Paskia authentication system](https://git.zi.fi/leovasanko/paskia) integration into web apps.
## Installation
### NPM
No framework dependencies. Works with any framework (Vue, React, Svelte, etc.) or vanilla JS. Typescript typing included.
```sh
npm install paskia
```
```js
import { ... } from 'paskia'
```
### Plain JavaScript
Fetch the module directly from a CDN, or [download](https://cdn.jsdelivr.net/npm/paskia@latest/dist/paskia.js) first and host yourself. No Node needed.
```html
<script type="module">
import { ... } from 'https://cdn.jsdelivr.net/npm/paskia@latest/dist/paskia.js'
</script>
```
## Features
### Session Validation
Refresh session and track its validity with automatic polling. Pauses on lack of user activity to avoid useless traffic and to allow session expiry even when the page is left open but idle. This monitors that the same account stays logged in but doesn't do any permission checks.
```js
import { SessionValidator } from 'paskia'
const validator = new SessionValidator(
() => currentUser?.uuid, // getter for current user ID that we track
(error) => handleSessionLost(error) // callback when session is lost
)
validator.start() // call at your app startup/login
validator.stop() // stop the system (optional)
```
### API Fetch Utilities
Enhanced fetch functions with automatic error handling and authentication retry:
```js
import { apiJson, apiFetch } from 'paskia'
// JSON API calls with automatic auth handling
const data = await apiJson('/api/endpoint', { method: 'POST', body: { key: 'value' } })
// Raw fetch with auth handling
const response = await apiFetch('/api/endpoint')
```
When a 401/403 response includes an auth iframe URL, the request automatically pauses, displays the authentication UI, and retries upon success. In case this is not needed, use standard `fetch` or our `fetchJson`.
The JSON variants set headers automatically, with body and response in JSON.
### Authentication Overlay
Normally you use apiJson/apiFetch and they handle this automatically. If you need to wire it yourself, on a 401/403 response that includes `auth.iframe`, call `showAuthIframe(...)` and then retry the original request.
The backend returns 401/403 responses with the correct URL for proper user feedback. Alternatively you may use `/auth/restricted/#mode=login`, `mode=reauth` or `mode=forbidden` to trigger the UX flow you need.
```js
import { showAuthIframe, AuthCancelledError } from 'paskia'
const response = await fetch('/api/protected')
if (response.status === 401 || response.status === 403) {
const data = await response.json()
if (data.auth?.iframe) {
await showAuthIframe(data.auth.iframe) // Raises AuthCancelledError if the user cancels
}
}
```
This resolves after the user authenticates (possibly with another account than previously), and you should usually retry the original API request. Note that successful authentication doesn't guarantee that the user still has rights to what originally failed.
### Shared Blur Backdrop
The authentication dialog displays with a blur backdrop (z-index 1099). The auth iframe uses z-index 9999. Your app dialogs should use z-index 11009998 to appear above the backdrop but below authentication.
The backdrop is also reusable/refcounted, so you can keep consistent visuals for your own dialogs:
```js
import { holdGlobalBackdrop, releaseGlobalBackdrop } from 'paskia'
holdGlobalBackdrop()
try {
await your.own.dialog()
} finally {
releaseGlobalBackdrop()
}
```
The backdrop only disappears after all holders have released it.
## Error Handling
### AuthCancelledError (apiFetch, apiJson, showAuthIframe)
If the user clicks Back in the authentication dialog, refusing to authenticate, `AuthCancelledError` is risen (as a response to postMessage from the iframe). The dialog closes as expected and it is up to the app how to continue from there.
- Do nothing if the app can continue despite the failed operation (no UI notification needed)
- Display a simple Access Denied page with suggestion/button to reload the page to try again
Do not retry automatically.
### UI feedback
A set of small utilities are available for determining whether the user needs a notification and to format the error message.
```js
import { getUserFriendlyErrorMessage, shouldShowErrorToast } from 'paskia'
try {
await apiJson('/api/action')
} catch (e) {
if (shouldShowErrorToast(e)) {
your.message.display(getUserFriendlyErrorMessage(e))
}
}
```
+32
View File
@@ -0,0 +1,32 @@
{
"name": "paskia",
"version": "0.1.2",
"description": "Paskia authentication utilities for JavaScript",
"type": "module",
"main": "./dist/paskia.js",
"types": "./dist/paskia.d.ts",
"exports": {
".": {
"types": "./dist/paskia.d.ts",
"import": "./dist/paskia.js"
}
},
"files": [
"dist"
],
"scripts": {
"build": "vite build",
"prepublishOnly": "npm run build"
},
"devDependencies": {
"typescript": "~5.8.0",
"vite": "^7.3.1",
"vite-plugin-dts": "^4.5.4"
},
"keywords": [
"auth",
"authentication",
"paskia"
],
"license": "Unlicense"
}
+146
View File
@@ -0,0 +1,146 @@
import { showAuthIframe, AuthCancelledError } from './overlay'
export { AuthCancelledError }
const DEFAULT_TIMEOUT_MS = 1000
export interface ApiFetchOptions extends RequestInit {
timeout?: number
}
export interface FetchJsonOptions extends Omit<RequestInit, 'body'> {
timeout?: number
body?: BodyInit | Record<string, unknown> | null
}
export class ApiError extends Error {
readonly url: string
readonly status: number
readonly statusText: string
readonly data: unknown
constructor(url: string, response: Response, data: unknown) {
super((data as { detail?: string })?.detail || `Request failed: ${response.status}`)
this.name = 'ApiError'
this.url = url
this.status = response.status
this.statusText = response.statusText
this.data = data
}
}
export class NetworkError extends Error {
readonly originalError: Error | null
constructor(message: string, originalError: Error | null = null) {
super(message)
this.name = 'NetworkError'
this.originalError = originalError
}
}
export async function apiFetch(url: string, options: ApiFetchOptions = {}): Promise<Response> {
const { timeout = DEFAULT_TIMEOUT_MS, ...fetchOptions } = options
fetchOptions.credentials = fetchOptions.credentials || 'include'
while (true) {
let response: Response
try {
response = await fetch(url, {...fetchOptions, signal: timeout ? AbortSignal.timeout(timeout) : undefined})
} catch (error) {
const err = error as Error
if (err.name === 'TimeoutError') {
throw new NetworkError('Request timed out', err)
}
if (err.name === 'AbortError') {
throw error
}
if (err.name === 'TypeError' && err.message === 'Failed to fetch') {
throw new NetworkError('Unable to connect to server', err)
}
throw new NetworkError(err.message || 'Network error', err)
}
if (response.status === 401 || response.status === 403) {
let data: { auth?: { iframe?: string } } | null = null
try {
data = await response.clone().json()
} catch {}
if (data?.auth?.iframe && window === window.top) {
await showAuthIframe(data.auth.iframe)
continue // Retry the original request after successful auth
}
}
return response
}
}
type FetchFn = (url: string, options?: RequestInit) => Promise<Response>
export async function apiJson<T = unknown>(url: string, options: FetchJsonOptions = {}): Promise<T> {
return fetchJson<T>(url, options, apiFetch)
}
export async function fetchJson<T = unknown>(url: string, options: FetchJsonOptions = {}, fetchFn: FetchFn = fetch): Promise<T> {
const headers: Record<string, string> = {
'Accept': 'application/json',
...(options.headers as Record<string, string>),
}
let body: BodyInit | undefined
if (options.body && typeof options.body === 'object' && !(options.body instanceof FormData)) {
headers['Content-Type'] = 'application/json'
body = JSON.stringify(options.body)
} else {
body = options.body as BodyInit
}
const opt: RequestInit = { ...options, headers, body }
const response = await fetchFn(url, opt)
const data = await response.json() as T
if (!response.ok) {
throw new ApiError(url, response, data)
}
return data
}
export function getUserFriendlyErrorMessage(error: Error): string {
if (error instanceof NetworkError) return error.message
if (error instanceof ApiError) return error.message
if (error.name === 'TimeoutError') return 'Request timed out'
if (error.name === 'TypeError' && error.message === 'Failed to fetch') {
return 'Unable to connect to server'
}
return error.message || 'An error occurred'
}
export function shouldShowErrorToast(error: Error): boolean {
if (error instanceof AuthCancelledError) return false
if (error.name === 'AbortError') return false
if (error instanceof ApiError && (error.status === 401 || error.status === 403)) return false
return true
}
type ShowMessageFn = (message: string, type: string, duration: number) => void
export function createApiCaller(showMessage: ShowMessageFn) {
return async function apiCall<T = unknown>(url: string, options: FetchJsonOptions = {}): Promise<T> {
try {
return await apiJson<T>(url, options)
} catch (error) {
if (!shouldShowErrorToast(error as Error)) {
throw error
}
const err = error as Error
console.error(`API error for ${url}:`, err instanceof ApiError ? { status: err.status, statusText: err.statusText, data: err.data } : err)
showMessage(getUserFriendlyErrorMessage(err), 'error', 4000)
throw error
}
}
}
export default apiFetch
+25
View File
@@ -0,0 +1,25 @@
export {
ApiError,
NetworkError,
AuthCancelledError,
apiFetch,
apiJson,
fetchJson,
getUserFriendlyErrorMessage,
shouldShowErrorToast,
createApiCaller,
} from './fetch'
export type { ApiFetchOptions, FetchJsonOptions } from './fetch'
export {
holdGlobalBackdrop,
releaseGlobalBackdrop,
isAuthIframeOpen,
hideAuthIframe,
showAuthIframe,
createAuthIframe,
removeAuthIframe,
} from './overlay'
export { SessionValidator } from './validate'
+166
View File
@@ -0,0 +1,166 @@
const AUTH_IFRAME_ID = 'paskia-iframe'
const STYLES_ID = 'paskia-dialog'
const STYLES_TEXT = `\
body::before {
content: '';
position: fixed;
inset: 0;
z-index: 1099;
background: transparent;
backdrop-filter: blur(0) brightness(1);
-webkit-backdrop-filter: blur(0) brightness(1);
pointer-events: none;
visibility: hidden;
transition: all 0.2s ease-out;
}
body.paskia-backdrop::before {
-webkit-backdrop-filter: blur(.2rem) brightness(0.5);
backdrop-filter: blur(.2rem) brightness(0.5);
visibility: visible;
}
body.paskia-backdrop {
overflow: auto;
}
#${AUTH_IFRAME_ID} {
border: none;
position: fixed;
top: 0;
left: 0;
width: 100%;
height: 100%;
z-index: 9999;
color-scheme: auto;
background: transparent;
}
`
let authIframe: HTMLIFrameElement | null = null
let authPromise: Promise<void> | null = null
let authResolve: (() => void) | null = null
let authReject: ((error: Error) => void) | null = null
let messageListenerInstalled = false
let backdropHolders = 0
function injectStyles(): void {
if (document.getElementById(STYLES_ID)) return
const style = document.createElement('style')
style.id = STYLES_ID
style.textContent = STYLES_TEXT
document.head.insertBefore(style, document.head.firstChild)
}
export class AuthCancelledError extends Error {
constructor() {
super('Authentication cancelled')
this.name = 'AuthCancelledError'
}
}
export function holdGlobalBackdrop(): void {
backdropHolders++
document.body.classList.add('paskia-backdrop')
}
export function releaseGlobalBackdrop(): void {
backdropHolders = Math.max(0, backdropHolders - 1)
if (backdropHolders === 0) {
document.body.classList.remove('paskia-backdrop')
}
}
export function isAuthIframeOpen(): boolean {
return !!document.getElementById(AUTH_IFRAME_ID)
}
export function hideAuthIframe(): void {
if (authIframe) {
authIframe.remove()
authIframe = null
releaseGlobalBackdrop()
}
}
function handleAuthMessage(event: MessageEvent): void {
const data = event.data as { type?: string }
if (!data?.type) return
switch (data.type) {
case 'auth-success':
hideAuthIframe()
if (authResolve) {
authResolve()
authPromise = null
authResolve = null
authReject = null
}
break
case 'auth-back':
hideAuthIframe()
if (authReject) {
authReject(new AuthCancelledError())
authPromise = null
authResolve = null
authReject = null
}
break
}
}
function ensureMessageListener(): void {
if (messageListenerInstalled) return
if (typeof window !== 'undefined') {
window.addEventListener('message', handleAuthMessage)
messageListenerInstalled = true
}
}
export function showAuthIframe(iframeUrl: string, title = 'Authentication'): Promise<void> {
injectStyles()
ensureMessageListener()
if (authPromise) return authPromise
if (document.getElementById(AUTH_IFRAME_ID)) {
authPromise = new Promise((resolve, reject) => {
authResolve = resolve
authReject = reject
})
return authPromise
}
authPromise = new Promise((resolve, reject) => {
authResolve = resolve
authReject = reject
})
hideAuthIframe()
holdGlobalBackdrop()
authIframe = document.createElement('iframe')
authIframe.id = AUTH_IFRAME_ID
authIframe.title = title
authIframe.src = iframeUrl
document.body.appendChild(authIframe)
return authPromise
}
export function createAuthIframe(iframeUrl: string, title = 'Authentication'): HTMLIFrameElement {
injectStyles()
const existing = document.getElementById(AUTH_IFRAME_ID)
if (existing) existing.remove()
const iframe = document.createElement('iframe')
iframe.id = AUTH_IFRAME_ID
iframe.title = title
iframe.src = iframeUrl
document.body.appendChild(iframe)
return iframe
}
export function removeAuthIframe(): void {
const iframe = document.getElementById(AUTH_IFRAME_ID)
if (iframe) iframe.remove()
}
+66
View File
@@ -0,0 +1,66 @@
import { apiJson } from './fetch'
const POLL_INTERVAL = 60 * 1000
const IDLE_TIMEOUT = 5 * 60 * 1000
export class SessionValidator {
private userUuidGetter: () => string | undefined
private onSessionLost: (error: Error) => void
private pollTimer: ReturnType<typeof setInterval> | null = null
private idleTimer: ReturnType<typeof setTimeout> | null = null
private active = false
constructor(userUuidGetter: () => string | undefined, onSessionLost: (error: Error) => void) {
this.userUuidGetter = userUuidGetter
this.onSessionLost = onSessionLost
this.resetIdleTimer = this.resetIdleTimer.bind(this)
}
resetIdleTimer(): void {
if (this.idleTimer) clearTimeout(this.idleTimer)
if (!this.active) this.startPolling()
this.idleTimer = setTimeout(() => this.stopPolling(), IDLE_TIMEOUT)
}
async validate(): Promise<void> {
try {
const data = await apiJson<{ ctx?: { user?: { uuid?: string } } }>('/auth/api/validate', { method: 'POST' })
const newUuid = data.ctx?.user?.uuid
if (newUuid !== this.userUuidGetter()) {
window.location.reload()
}
} catch (error) {
if ((error as Error).name !== 'NetworkError') {
this.stopPolling()
this.onSessionLost(error as Error)
}
}
}
startPolling(): void {
if (this.active) return
this.active = true
this.pollTimer = setInterval(() => this.validate(), POLL_INTERVAL)
}
stopPolling(): void {
this.active = false
if (this.pollTimer) {
clearInterval(this.pollTimer)
this.pollTimer = null
}
}
start(): void {
window.addEventListener('pointermove', this.resetIdleTimer)
window.addEventListener('pointerdown', this.resetIdleTimer)
this.resetIdleTimer()
}
stop(): void {
window.removeEventListener('pointermove', this.resetIdleTimer)
window.removeEventListener('pointerdown', this.resetIdleTimer)
if (this.idleTimer) clearTimeout(this.idleTimer)
this.stopPolling()
}
}
+15
View File
@@ -0,0 +1,15 @@
{
"compilerOptions": {
"target": "ES2020",
"module": "ESNext",
"moduleResolution": "bundler",
"strict": true,
"declaration": true,
"declarationDir": "./dist",
"outDir": "./dist",
"rootDir": "./src",
"lib": ["ES2020", "DOM"],
"skipLibCheck": true
},
"include": ["src/**/*.ts"]
}
+17
View File
@@ -0,0 +1,17 @@
import { defineConfig } from 'vite'
import { resolve } from 'node:path'
import { fileURLToPath } from 'node:url'
import dts from 'vite-plugin-dts'
const __dirname = fileURLToPath(new URL('.', import.meta.url))
export default defineConfig({
plugins: [dts({ rollupTypes: true })],
build: {
lib: {
entry: resolve(__dirname, 'src/index.ts'),
fileName: 'paskia',
formats: ['es'],
},
},
})
+5 -4
View File
@@ -10,6 +10,7 @@ This module provides functionality to:
import json import json
from collections.abc import Iterable from collections.abc import Iterable
from importlib.resources import files from importlib.resources import files
from uuid import UUID
__ALL__ = ["AAGUID", "filter"] __ALL__ = ["AAGUID", "filter"]
@@ -18,15 +19,15 @@ AAGUID_FILE = files("paskia") / "aaguid" / "combined_aaguid.json"
AAGUID: dict[str, dict] = json.loads(AAGUID_FILE.read_text(encoding="utf-8")) AAGUID: dict[str, dict] = json.loads(AAGUID_FILE.read_text(encoding="utf-8"))
def filter(aaguids: Iterable[str]) -> dict[str, dict]: def filter(aaguids: Iterable[UUID]) -> dict[str, dict]:
""" """
Get AAGUID information only for the provided set of AAGUIDs. Get AAGUID information only for the provided set of AAGUIDs.
Args: Args:
aaguids: Set of AAGUID strings that the user has credentials for aaguids: Iterable of AAGUIDs (UUIDs) that the user has credentials for
Returns: Returns:
Dictionary mapping AAGUID to authenticator information for only Dictionary mapping AAGUID string to authenticator information for only
the AAGUIDs that the user has and that we have data for the AAGUIDs that the user has and that we have data for
""" """
return {aaguid: AAGUID[aaguid] for aaguid in aaguids if aaguid in AAGUID} return {(s := str(a)): AAGUID[s] for a in aaguids if (s := str(a)) in AAGUID}
+18 -83
View File
@@ -8,105 +8,40 @@ independent of any web framework:
- Credential management - Credential management
""" """
from datetime import datetime, timezone from datetime import UTC, datetime
from typing import TYPE_CHECKING
from uuid import UUID from uuid import UUID
from paskia.config import SESSION_LIFETIME from paskia import db
from paskia.db import ResetToken, Session from paskia.config import RESET_LIFETIME, SESSION_LIFETIME
from paskia.globals import db, passkey
from paskia.util import hostutil from paskia.util import hostutil
from paskia.util.tokens import create_token, reset_key, session_key
if TYPE_CHECKING:
from paskia.db import ResetToken
EXPIRES = SESSION_LIFETIME EXPIRES = SESSION_LIFETIME
def expires() -> datetime: def expires() -> datetime:
return datetime.now(timezone.utc) + EXPIRES return datetime.now(UTC) + EXPIRES
def reset_expires() -> datetime: def reset_expires() -> datetime:
from .config import RESET_LIFETIME return datetime.now(UTC) + RESET_LIFETIME
return datetime.now(timezone.utc) + RESET_LIFETIME
def session_expiry(session: Session) -> datetime: def get_reset(token: str) -> "ResetToken":
"""Calculate the expiration timestamp for a session (UTC aware).""" """Validate a credential reset token."""
# After migration all renewed timestamps are timezone-aware UTC
return session.renewed + EXPIRES
record = db.get_reset_token(token)
async def create_session( if record:
user_uuid: UUID,
credential_uuid: UUID,
*,
host: str,
ip: str,
user_agent: str,
) -> str:
"""Create a new session and return a session token."""
normalized_host = hostutil.normalize_host(host)
if not normalized_host:
raise ValueError("Host required for session creation")
hostname = normalized_host.split(":")[0] # Domain names only, IPs aren't supported
rp_id = passkey.instance.rp_id
if not (hostname == rp_id or hostname.endswith(f".{rp_id}")):
raise ValueError(f"Host must be the same as or a subdomain of {rp_id}")
token = create_token()
now = datetime.now(timezone.utc)
await db.instance.create_session(
user_uuid=user_uuid,
credential_uuid=credential_uuid,
key=session_key(token),
host=normalized_host,
ip=ip,
user_agent=user_agent,
renewed=now,
)
return token
async def get_reset(token: str) -> ResetToken:
"""Validate a credential reset token. Returns None if the token is not well formed (i.e. it is another type of token)."""
record = await db.instance.get_reset_token(reset_key(token))
if record and record.expiry >= datetime.now(timezone.utc):
return record return record
raise ValueError("This authentication link is no longer valid.") raise ValueError("This authentication link is no longer valid.")
async def get_session(token: str, host: str | None = None) -> Session: def delete_credential(credential_uuid: UUID, auth: str, host: str | None = None):
"""Validate a session token and return session data if valid."""
host = hostutil.normalize_host(host)
if not host:
raise ValueError("Invalid host")
session = await db.instance.get_session(session_key(token))
if session and session_expiry(session) >= datetime.now(timezone.utc):
if session.host is None:
# First time binding: store exact host:port (or IPv6 form) now.
await db.instance.set_session_host(session.key, host)
session.host = host
elif session.host != host:
raise ValueError("Session host mismatch")
return session
raise ValueError("Your session has expired. Please sign in again!")
async def refresh_session_token(token: str, *, ip: str, user_agent: str):
"""Refresh a session extending its expiry."""
session_record = await db.instance.get_session(session_key(token))
if not session_record:
raise ValueError("Session not found or expired")
updated = await db.instance.update_session(
session_key(token),
ip=ip,
user_agent=user_agent,
renewed=datetime.now(timezone.utc),
)
if not updated:
raise ValueError("Session not found or expired")
async def delete_credential(credential_uuid: UUID, auth: str, host: str | None = None):
"""Delete a specific credential for the current user.""" """Delete a specific credential for the current user."""
s = await get_session(auth, host=host) ctx = db.data().session_ctx(auth, hostutil.normalize_host(host))
await db.instance.delete_credential(credential_uuid, s.user_uuid) if not ctx:
raise ValueError("Session expired")
db.delete_credential(credential_uuid, ctx.user.uuid)
+30 -97
View File
@@ -8,26 +8,11 @@ generating a reset link for initial admin setup.
import asyncio import asyncio
import logging import logging
from datetime import datetime, timezone
import uuid7 from paskia import authsession, db, globals
from paskia.util import hostutil, passphrase
from paskia import authsession, globals logger = logging.getLogger(__name__)
from paskia.db import Org, Permission, Role, User
from paskia.util import hostutil, passphrase, tokens
def _init_logger() -> logging.Logger:
logger = logging.getLogger(__name__)
if not logger.handlers and not logging.getLogger().handlers:
h = logging.StreamHandler()
h.setFormatter(logging.Formatter("%(message)s"))
logger.addHandler(h)
logger.setLevel(logging.INFO)
return logger
logger = _init_logger()
# Shared log message template for admin reset links # Shared log message template for admin reset links
ADMIN_RESET_MESSAGE = """\ ADMIN_RESET_MESSAGE = """\
@@ -38,73 +23,25 @@ ADMIN_RESET_MESSAGE = """\
""" """
async def _create_and_log_admin_reset_link(user_uuid, message, session_type) -> str: def _log_reset_link(message: str, passphrase: str) -> str:
"""Create an admin reset link and log it with the provided message.""" """Log a reset link message and return the URL."""
token = passphrase.generate() reset_link = hostutil.reset_link_url(passphrase)
expiry = authsession.reset_expires()
await globals.db.instance.create_reset_token(
user_uuid=user_uuid,
key=tokens.reset_key(token),
expiry=expiry,
token_type=session_type,
)
reset_link = hostutil.reset_link_url(token)
logger.info(ADMIN_RESET_MESSAGE, message, reset_link) logger.info(ADMIN_RESET_MESSAGE, message, reset_link)
return reset_link return reset_link
async def bootstrap_system() -> dict: async def bootstrap_system() -> None:
""" """
Bootstrap the entire system with default data. Bootstrap the entire system with default data.
Returns: Uses db.bootstrap() which performs all operations in a single transaction.
dict: Contains information about created entities and reset link The transaction log will show a single "bootstrap" action with all changes.
""" """
# Create permission first - will fail if already exists # Call the single-transaction bootstrap function
perm0 = Permission(id="auth:admin", display_name="Master Admin") reset_passphrase = db.bootstrap()
await globals.db.instance.create_permission(perm0)
org = Org(uuid7.create(), "Organization") # Log the reset link (this is separate from the transaction log)
await globals.db.instance.create_organization(org) _log_reset_link("✅ Bootstrap completed!", reset_passphrase)
# After creation, org.permissions now includes the auto-created org admin permission
# Allow this org to grant global admin explicitly
await globals.db.instance.add_permission_to_organization(str(org.uuid), perm0.id)
# Create an Administration role granting both org and global admin
# Compose permissions for Administration role: global admin + org admin auto-perm
role = Role(
uuid7.create(),
org.uuid,
"Administration",
permissions=[perm0.id, *org.permissions],
)
await globals.db.instance.create_role(role)
user = User(
uuid=uuid7.create(),
display_name="Admin",
role_uuid=role.uuid,
created_at=datetime.now(timezone.utc),
visits=0,
)
await globals.db.instance.create_user(user)
# Generate reset link and log it
reset_link = await _create_and_log_admin_reset_link(
user.uuid, "✅ Bootstrap completed!", "admin bootstrap"
)
return {
"user": user,
"org": org,
"role": role,
"permissions": [
perm0,
*[Permission(id=p, display_name="") for p in org.permissions],
],
"reset_link": reset_link,
}
async def check_admin_credentials() -> bool: async def check_admin_credentials() -> bool:
@@ -116,17 +53,15 @@ async def check_admin_credentials() -> bool:
""" """
try: try:
# Get permission organizations to find admin users # Get permission organizations to find admin users
permission_orgs = await globals.db.instance.get_permission_organizations( p = next(
"auth:admin" (p for p in db.data().permissions.values() if p.scope == "auth:admin"), None
) )
if not p or not p.orgs:
if not permission_orgs:
return False return False
# Get users from the first organization with admin permission # Get users from the first organization with admin permission
org_users = await globals.db.instance.get_organization_users( first_org_uuid = next(iter(p.orgs))
str(permission_orgs[0].uuid) org_users = db.get_organization_users(first_org_uuid)
)
admin_users = [user for user, role in org_users if role == "Administration"] admin_users = [user for user, role in org_users if role == "Administration"]
if not admin_users: if not admin_users:
@@ -134,17 +69,19 @@ async def check_admin_credentials() -> bool:
# Check first admin user for credentials # Check first admin user for credentials
admin_user = admin_users[0] admin_user = admin_users[0]
credentials = await globals.db.instance.get_credentials_by_user_uuid(
admin_user.uuid
)
if not credentials: if not db.get_user_credential_ids(admin_user.uuid):
# Admin exists but has no credentials, create reset link # Admin exists but has no credentials, create reset link
await _create_and_log_admin_reset_link(
admin_user.uuid, token = passphrase.generate()
"⚠️ Admin user has no credentials!", expiry = authsession.reset_expires()
"admin registration", db.create_reset_token(
user_uuid=admin_user.uuid,
passphrase=token,
expiry=expiry,
token_type="admin registration",
) )
_log_reset_link("⚠️ Admin user has no credentials!", token)
return True return True
return False return False
@@ -160,16 +97,12 @@ async def bootstrap_if_needed() -> bool:
Returns: Returns:
bool: True if bootstrapping was performed, False if system was already set up bool: True if bootstrapping was performed, False if system was already set up
""" """
try: # Check if the admin permission exists - if it does, system is already bootstrapped
# Check if the admin permission exists - if it does, system is already bootstrapped if any(p.scope == "auth:admin" for p in db.data().permissions.values()):
await globals.db.instance.get_permission("auth:admin")
# Permission exists, system is already bootstrapped # Permission exists, system is already bootstrapped
# Check if admin needs credentials (only for already-bootstrapped systems) # Check if admin needs credentials (only for already-bootstrapped systems)
await check_admin_credentials() await check_admin_credentials()
return False return False
except Exception:
# Permission doesn't exist, need to bootstrap
pass
# No admin permission found, need to bootstrap # No admin permission found, need to bootstrap
# Bootstrap creates the admin user AND the reset link, so no need to check credentials after # Bootstrap creates the admin user AND the reset link, so no need to check credentials after
-1
View File
@@ -22,4 +22,3 @@ class PaskiaConfig:
host: str | None = None host: str | None = None
port: int | None = None port: int | None = None
uds: str | None = None uds: str | None = None
devmode: bool = False
+140 -403
View File
@@ -1,415 +1,152 @@
""" """
Database module for WebAuthn passkey authentication. Database module for WebAuthn passkey authentication.
This module provides dataclasses and database abstractions for managing Read: Access data() directly, use build_* to convert to public structs.
users, credentials, and sessions in a WebAuthn authentication system. CTX: data().session_ctx(key) returns SessionContext with effective permissions.
Write: Functions validate and commit, or raise ValueError.
Usage:
from paskia import db
# Read (after init)
user_data = db.data().users[user_uuid]
user = db.build_user(user_uuid)
# Context
ctx = db.data().session_ctx(session_key)
# Write
db.create_user(user)
""" """
from abc import ABC, abstractmethod import paskia.db.operations as operations
from dataclasses import dataclass, field from paskia.db.background import (
from datetime import datetime start_background,
from uuid import UUID start_cleanup,
stop_background,
stop_cleanup,
@dataclass )
class Permission: from paskia.db.operations import (
id: str # String primary key (max 128 chars) add_permission_to_org,
display_name: str add_permission_to_role,
bootstrap,
cleanup_expired,
@dataclass create_credential,
class Role: create_credential_session,
uuid: UUID create_org,
org_uuid: UUID create_permission,
display_name: str create_reset_token,
# List of permission IDs this role grants to its members create_role,
permissions: list[str] = field(default_factory=list) # permission IDs create_session,
create_user,
delete_credential,
@dataclass delete_org,
class Org: delete_permission,
uuid: UUID delete_reset_token,
display_name: str delete_role,
# All permission IDs that the Org is allowed to grant to its roles delete_session,
permissions: list[str] = field(default_factory=list) # permission IDs delete_sessions_for_user,
# Roles belonging to this org delete_user,
roles: list[Role] = field(default_factory=list) get_organization_users,
get_reset_token,
get_user_credential_ids,
@dataclass get_user_organization,
class User: init,
uuid: UUID login,
display_name: str remove_permission_from_org,
role_uuid: UUID remove_permission_from_role,
created_at: datetime | None = None set_session_host,
last_seen: datetime | None = None update_credential_sign_count,
visits: int = 0 update_org_name,
update_permission,
update_role_name,
@dataclass update_session,
class Credential: update_user_display_name,
uuid: UUID update_user_role,
credential_id: bytes # Long binary ID passed from the authenticator update_user_role_in_organization,
user_uuid: UUID update_user_theme,
aaguid: UUID )
public_key: bytes from paskia.db.structs import (
sign_count: int DB,
created_at: datetime Credential,
last_used: datetime | None = None Org,
last_verified: datetime | None = None Permission,
ResetToken,
Role,
@dataclass Session,
class Session: SessionContext,
key: bytes User,
user_uuid: UUID )
credential_uuid: UUID
host: str
ip: str def data() -> DB:
user_agent: str """Get the database instance for direct read access."""
renewed: datetime return operations._db
def metadata(self) -> dict:
"""Return session metadata for backwards compatibility."""
return {
"ip": self.ip,
"user_agent": self.user_agent,
"renewed": self.renewed.isoformat(),
}
@dataclass
class ResetToken:
key: bytes
user_uuid: UUID
expiry: datetime
token_type: str
@dataclass
class SessionContext:
session: Session
user: User
org: Org
role: Role
credential: Credential | None = None
permissions: list[Permission] | None = None
class DatabaseInterface(ABC):
"""Abstract base class defining the database interface.
This class defines the public API that database implementations should provide.
Implementations may use decorators like @with_session that modify method signatures
at runtime, so this interface focuses on the logical operations rather than
exact parameter matching.
"""
@abstractmethod
async def init_db(self) -> None:
"""Initialize database tables."""
pass
# User operations
@abstractmethod
async def get_user_by_uuid(self, user_uuid: UUID) -> User:
"""Get user record by WebAuthn user UUID."""
@abstractmethod
async def create_user(self, user: User) -> None:
"""Create a new user."""
@abstractmethod
async def update_user_display_name(
self, user_uuid: UUID, display_name: str
) -> None:
"""Update a user's display name."""
# Role operations
@abstractmethod
async def create_role(self, role: Role) -> None:
"""Create new role."""
@abstractmethod
async def update_role(self, role: Role) -> None:
"""Update a role's display name and synchronize its permissions."""
@abstractmethod
async def delete_role(self, role_uuid: UUID) -> None:
"""Delete a role by UUID. Implementations may prevent deletion if users exist."""
# Credential operations
@abstractmethod
async def create_credential(self, credential: Credential) -> None:
"""Store a credential for a user."""
@abstractmethod
async def get_credential_by_id(self, credential_id: bytes) -> Credential:
"""Get credential by credential ID."""
@abstractmethod
async def get_credentials_by_user_uuid(self, user_uuid: UUID) -> list[bytes]:
"""Get all credential IDs for a user."""
@abstractmethod
async def update_credential(self, credential: Credential) -> None:
"""Update the sign count, created_at, last_used, and last_verified for a credential."""
@abstractmethod
async def delete_credential(self, uuid: UUID, user_uuid: UUID) -> None:
"""Delete a specific credential for a user."""
# Session operations
@abstractmethod
async def create_session(
self,
user_uuid: UUID,
key: bytes,
credential_uuid: UUID,
host: str,
ip: str,
user_agent: str,
renewed: datetime,
) -> None:
"""Create a new session."""
@abstractmethod
async def get_session(self, key: bytes) -> Session | None:
"""Get session by key."""
@abstractmethod
async def delete_session(self, key: bytes) -> None:
"""Delete session by key."""
@abstractmethod
async def update_session(
self,
key: bytes,
*,
ip: str,
user_agent: str,
renewed: datetime,
) -> Session | None:
"""Update session metadata and touch renewed timestamp."""
@abstractmethod
async def set_session_host(self, key: bytes, host: str) -> None:
"""Bind a session to a specific host if not already set."""
@abstractmethod
async def list_sessions_for_user(self, user_uuid: UUID) -> list[Session]:
"""Return all sessions for a user (including other hosts)."""
@abstractmethod
async def cleanup(self) -> None:
"""Called periodically to clean up expired records."""
@abstractmethod
async def delete_sessions_for_user(self, user_uuid: UUID) -> None:
"""Delete all sessions belonging to the provided user."""
# Reset token operations
@abstractmethod
async def create_reset_token(
self,
user_uuid: UUID,
key: bytes,
expiry: datetime,
token_type: str,
) -> None:
"""Create a reset token for a user."""
@abstractmethod
async def get_reset_token(self, key: bytes) -> ResetToken | None:
"""Retrieve a reset token by key."""
@abstractmethod
async def delete_reset_token(self, key: bytes) -> None:
"""Delete a reset token by key."""
# Organization operations
@abstractmethod
async def create_organization(self, org: Org) -> None:
"""Add a new organization."""
@abstractmethod
async def get_organization(self, org_id: str) -> Org:
"""Get organization by ID, including its permission IDs and roles (with their permission IDs)."""
@abstractmethod
async def list_organizations(self) -> list[Org]:
"""List all organizations with their roles and permission IDs."""
@abstractmethod
async def update_organization(self, org: Org) -> None:
"""Update organization options."""
@abstractmethod
async def delete_organization(self, org_uuid: UUID) -> None:
"""Delete organization by ID."""
@abstractmethod
async def add_user_to_organization(
self, user_uuid: UUID, org_id: str, role: str
) -> None:
"""Set a user's organization and role."""
@abstractmethod
async def transfer_user_to_organization(
self, user_uuid: UUID, new_org_id: str, new_role: str | None = None
) -> None:
"""Transfer a user to another organization with an optional role."""
@abstractmethod
async def get_user_organization(self, user_uuid: UUID) -> tuple[Org, str]:
"""Get the organization and role for a user."""
@abstractmethod
async def get_organization_users(self, org_id: str) -> list[tuple[User, str]]:
"""Get all users in an organization with their roles."""
@abstractmethod
async def get_roles_by_organization(self, org_id: str) -> list[Role]:
"""List roles belonging to an organization."""
@abstractmethod
async def get_user_role_in_organization(
self, user_uuid: UUID, org_id: str
) -> str | None:
"""Get a user's role in a specific organization."""
@abstractmethod
async def update_user_role_in_organization(
self, user_uuid: UUID, new_role: str
) -> None:
"""Update a user's role in their organization."""
# Permission operations
@abstractmethod
async def create_permission(self, permission: Permission) -> None:
"""Create a new permission."""
@abstractmethod
async def get_permission(self, permission_id: str) -> Permission:
"""Get permission by ID."""
@abstractmethod
async def list_permissions(self) -> list[Permission]:
"""List all permissions."""
@abstractmethod
async def update_permission(self, permission: Permission) -> None:
"""Update permission details."""
@abstractmethod
async def delete_permission(self, permission_id: str) -> None:
"""Delete permission by ID."""
@abstractmethod
async def rename_permission(
self, old_id: str, new_id: str, display_name: str
) -> None:
"""Rename a permission's ID (and display name) updating all references.
This must update:
- permissions.id (primary key)
- org_permissions.permission_id
- role_permissions.permission_id
"""
@abstractmethod
async def add_permission_to_organization(
self, org_id: str, permission_id: str
) -> None:
"""Add a permission to an organization."""
@abstractmethod
async def remove_permission_from_organization(
self, org_id: str, permission_id: str
) -> None:
"""Remove a permission from an organization."""
@abstractmethod
async def get_organization_permissions(self, org_id: str) -> list[Permission]:
"""Get all permissions assigned to an organization."""
@abstractmethod
async def get_permission_organizations(self, permission_id: str) -> list[Org]:
"""Get all organizations that have a specific permission."""
# Role-permission operations
@abstractmethod
async def add_permission_to_role(self, role_uuid: UUID, permission_id: str) -> None:
"""Add a permission to a role."""
@abstractmethod
async def remove_permission_from_role(
self, role_uuid: UUID, permission_id: str
) -> None:
"""Remove a permission from a role."""
@abstractmethod
async def get_role_permissions(self, role_uuid: UUID) -> list[Permission]:
"""List all permissions granted to a role."""
@abstractmethod
async def get_permission_roles(self, permission_id: str) -> list[Role]:
"""List all roles that grant a permission."""
@abstractmethod
async def get_role(self, role_uuid: UUID) -> Role:
"""Get a role by UUID, including its permission IDs."""
# Combined operations
@abstractmethod
async def login(self, user_uuid: UUID, credential: Credential) -> None:
"""Update user and credential timestamps after successful login."""
@abstractmethod
async def create_user_and_credential(
self, user: User, credential: Credential
) -> None:
"""Create a new user and their first credential in a transaction."""
@abstractmethod
async def get_session_context(
self, session_key: bytes, host: str | None = None
) -> SessionContext | None:
"""Get complete session context including user, organization, role, and permissions."""
# Combined atomic operations
@abstractmethod
async def create_credential_session(
self,
user_uuid: UUID,
credential: Credential,
reset_key: bytes | None,
session_key: bytes,
*,
display_name: str | None = None,
host: str | None = None,
ip: str | None = None,
user_agent: str | None = None,
) -> None:
"""Atomically add a credential and create a session.
Steps (single transaction):
1. Insert credential
2. Optionally delete old reset token if provided
3. Optionally update user's display name
4. Insert new session referencing the credential
5. Update user's last_seen and increment visits (treat as a login)
"""
__all__ = [ __all__ = [
"User", # Types
"Credential", "Credential",
"Session", "DB",
"ResetToken",
"SessionContext",
"Org", "Org",
"Role",
"Permission", "Permission",
"DatabaseInterface", "ResetToken",
"Role",
"Session",
"SessionContext",
"User",
# Instance
"data",
"init",
# Background
"start_background",
"stop_background",
"start_cleanup",
"stop_cleanup",
# Builders
"build_credential",
"build_permission",
"build_reset_token",
"build_role",
"build_session",
"build_user",
# Read ops
"get_organization_users",
"get_reset_token",
"get_user_credential_ids",
"get_user_organization",
# Write ops
"add_permission_to_org",
"add_permission_to_role",
"bootstrap",
"cleanup_expired",
"create_credential",
"create_credential_session",
"create_org",
"create_permission",
"create_reset_token",
"create_role",
"create_session",
"create_user",
"delete_credential",
"delete_org",
"delete_permission",
"delete_reset_token",
"delete_role",
"delete_session",
"delete_sessions_for_user",
"delete_user",
"login",
"remove_permission_from_org",
"remove_permission_from_role",
"set_session_host",
"update_credential_sign_count",
"update_org_name",
"update_permission",
"update_role_name",
"update_session",
"update_user_display_name",
"update_user_role",
"update_user_role_in_organization",
"update_user_theme",
] ]
+108
View File
@@ -0,0 +1,108 @@
"""
Background task for database maintenance.
Periodically flushes pending changes to disk and cleans up expired items.
"""
import asyncio
import logging
from datetime import UTC, datetime
from paskia.db.operations import _store, cleanup_expired
FLUSH_INTERVAL = 0.1 # Flush to disk
CLEANUP_INTERVAL = 1 # Expired item cleanup
_logger = logging.getLogger(__name__)
_background_task: asyncio.Task | None = None
async def flush() -> None:
"""Write all pending database changes to disk."""
if _store is None:
_logger.warning("flush() called but _store is None")
return
await _store.flush()
async def _background_loop():
"""Background task that periodically flushes changes and cleans up."""
# Run cleanup immediately on startup to clear old expired items
cleanup_expired()
await flush()
last_cleanup = datetime.now(UTC)
while True:
try:
await asyncio.sleep(FLUSH_INTERVAL)
# Flush pending changes to disk
await flush()
# Run cleanup periodically
now = datetime.now(UTC)
if (now - last_cleanup).total_seconds() >= CLEANUP_INTERVAL:
cleanup_expired()
await flush() # Flush cleanup changes
last_cleanup = now
except asyncio.CancelledError:
# Final flush before exit
await flush()
break
except Exception:
_logger.debug("Error in database background loop", exc_info=True)
async def start_background():
"""Start the background flush/cleanup task."""
global _background_task
# Check if task exists but is no longer running (e.g., after uvicorn reload)
if _background_task is not None:
if _background_task.done():
_logger.debug("Previous background task was done, restarting")
_background_task = None
else:
# Task exists and is running - but might be in a dead event loop
try:
# Check if task is in current event loop
loop = asyncio.get_running_loop()
task_loop = _background_task.get_loop()
if loop is not task_loop:
_logger.debug("Background task in different event loop, restarting")
_background_task = None
else:
# Task is running in the same event loop - this is an error
raise RuntimeError(
"Background task is already running. "
"start_background() must not be called multiple times in the same event loop."
)
except RuntimeError:
raise # Re-raise RuntimeError from above
except Exception as e:
_logger.debug("Error checking background task loop: %s, restarting", e)
_background_task = None
if _background_task is None:
_background_task = asyncio.create_task(_background_loop())
else:
_logger.debug("Background task already running: %s", _background_task)
async def stop_background():
"""Stop the background task and flush any pending changes."""
global _background_task
if _background_task:
_background_task.cancel()
try:
await _background_task
except asyncio.CancelledError:
pass
_background_task = None
# Aliases for backwards compatibility
start_cleanup = start_background
stop_cleanup = stop_background
+282
View File
@@ -0,0 +1,282 @@
"""
JSONL persistence layer for the database.
"""
import copy
import logging
from collections import deque
from contextlib import contextmanager
from datetime import UTC, datetime
from pathlib import Path
from typing import Any
from uuid import UUID
import aiofiles
import jsondiff
import msgspec
from paskia.db.logging import log_change
from paskia.db.migrations import DBVER, apply_all_migrations
from paskia.db.structs import DB, SessionContext
_logger = logging.getLogger(__name__)
# Default database path
DB_PATH_DEFAULT = "paskia.jsonl"
class _ChangeRecord(msgspec.Struct, omit_defaults=True):
"""A single change record in the JSONL file."""
ts: datetime
a: str # action - describes the operation (e.g., "migrate", "login", "create_user")
v: int # schema version after this change
u: str | None = None # user UUID who performed the action (None for system)
diff: dict = {}
# msgspec encoder for change records
_change_encoder = msgspec.json.Encoder()
def compute_diff(previous: dict, current: dict) -> dict | None:
"""Compute JSON diff between two states.
Args:
previous: Previous state (JSON-compatible dict)
current: Current state (JSON-compatible dict)
Returns:
The diff, or None if no changes
"""
diff = jsondiff.diff(previous, current, marshal=True)
return diff if diff else None
def create_change_record(
action: str, version: int, diff: dict, user: str | None = None
) -> _ChangeRecord:
"""Create a change record for persistence."""
return _ChangeRecord(
ts=datetime.now(UTC),
a=action,
v=version,
u=user,
diff=diff,
)
# Actions that are allowed to create a new database file
_BOOTSTRAP_ACTIONS = frozenset({"bootstrap", "migrate:sql"})
async def flush_changes(
db_path: Path,
pending_changes: deque[_ChangeRecord],
) -> bool:
"""Write all pending changes to disk.
Args:
db_path: Path to the JSONL database file
pending_changes: Queue of pending change records (will be cleared on success)
Returns:
True if flush succeeded, False otherwise
"""
if not pending_changes:
return True
if not db_path.exists():
first_action = pending_changes[0].a
if first_action not in _BOOTSTRAP_ACTIONS:
_logger.error(
"Refusing to create database file with action '%s' - "
"only bootstrap or migrate can create a new database",
first_action,
)
pending_changes.clear()
return False
changes_to_write = list(pending_changes)
pending_changes.clear()
try:
lines = [_change_encoder.encode(change) for change in changes_to_write]
if not lines:
return True
async with aiofiles.open(db_path, "ab") as f:
await f.write(b"\n".join(lines) + b"\n")
return True
except OSError:
_logger.exception("Failed to flush database changes")
# Re-queue the changes on failure
for change in reversed(changes_to_write):
pending_changes.appendleft(change)
return False
class JsonlStore:
"""JSONL persistence layer for a DB instance."""
def __init__(self, db: DB, db_path: str = DB_PATH_DEFAULT):
self.db: DB = db
self.db_path = Path(db_path)
self._previous_builtins: dict[str, Any] = {}
self._pending_changes: deque[_ChangeRecord] = deque()
self._current_action: str = "system"
self._current_user: str | None = None
self._in_transaction: bool = False
self._transaction_snapshot: dict[str, Any] | None = None
self._current_version: int = DBVER # Schema version for new databases
async def load(self, db_path: str | None = None) -> None:
"""Load data from JSONL change log."""
if db_path is not None:
self.db_path = Path(db_path)
if not self.db_path.exists():
return
# Replay change log to reconstruct state
data_dict: dict = {}
try:
async with aiofiles.open(self.db_path, "rb") as f:
content = await f.read()
for line_num, line in enumerate(content.split(b"\n"), 1):
line = line.strip()
if not line:
continue
try:
change = msgspec.json.decode(line)
data_dict = jsondiff.patch(data_dict, change["diff"], marshal=True)
self._current_version = change.get("v", 0)
except Exception as e:
raise ValueError(f"Error parsing line {line_num}: {e}")
except (OSError, ValueError, msgspec.DecodeError) as e:
raise ValueError(f"Failed to load database: {e}")
if not data_dict:
return
# Set previous state for diffing (will be updated by _queue_change)
self._previous_builtins = copy.deepcopy(data_dict)
# Callback to persist each migration
async def persist_migration(
action: str, new_version: int, current: dict
) -> None:
self._current_version = new_version
self._queue_change(action, new_version, current)
# Apply schema migrations one at a time
await apply_all_migrations(data_dict, self._current_version, persist_migration)
# Decode to msgspec struct
decoder = msgspec.json.Decoder(DB)
self.db = decoder.decode(msgspec.json.encode(data_dict))
self.db._store = self
# Normalize via msgspec round-trip (handles omit_defaults etc.)
# This ensures _previous_builtins matches what msgspec would produce
normalized_dict = msgspec.to_builtins(self.db)
await persist_migration(
"migrate:msgspec", self._current_version, normalized_dict
)
def _queue_change(
self, action: str, version: int, current: dict, user: str | None = None
) -> None:
"""Queue a change record and log it.
Args:
action: The action name for the change record
version: The schema version for the change record
current: The current state as a plain dict
user: Optional user UUID who performed the action
"""
diff = compute_diff(self._previous_builtins, current)
if not diff:
return
self._pending_changes.append(create_change_record(action, version, diff, user))
# Log the change with user display name if available
user_display = None
if user:
try:
user_uuid = UUID(user)
if user_uuid in self.db.users:
user_display = self.db.users[user_uuid].display_name
except (ValueError, KeyError):
user_display = user
log_change(action, diff, user_display, self._previous_builtins)
self._previous_builtins = copy.deepcopy(current)
@contextmanager
def transaction(
self,
action: str,
ctx: SessionContext | None = None,
*,
user: str | None = None,
):
"""Wrap writes in transaction. Queues change on successful exit.
Args:
action: Describes the operation (e.g., "Created user", "Login")
ctx: Session context of user performing the action (None for system operations)
user: User UUID string (alternative to ctx when full context unavailable)
"""
if self._in_transaction:
raise RuntimeError("Nested transactions are not supported")
# Check for out-of-transaction modifications
current_state = msgspec.to_builtins(self.db)
if current_state != self._previous_builtins:
# Allow bootstrap/migrate to create a new database from empty state
is_bootstrap = action in _BOOTSTRAP_ACTIONS or action.startswith("migrate:")
if is_bootstrap and not self._previous_builtins:
pass # Expected: creating database from scratch
else:
diff = compute_diff(self._previous_builtins, current_state)
diff_json = msgspec.json.encode(diff).decode()
_logger.critical(
"Database state modified outside of transaction! "
"This indicates a bug where DB changes occurred without a transaction wrapper.\n"
f"Changes detected:\n{diff_json}"
)
raise SystemExit(1)
old_action = self._current_action
old_user = self._current_user
self._current_action = action
# Prefer ctx.user.uuid if ctx provided, otherwise use user param
self._current_user = str(ctx.user.uuid) if ctx else user
self._in_transaction = True
self._transaction_snapshot = current_state
try:
yield
current = msgspec.to_builtins(self.db)
self._queue_change(
self._current_action, self._current_version, current, self._current_user
)
except Exception:
# Rollback on error: restore from snapshot
_logger.warning("Transaction '%s' failed, rolling back changes", action)
if self._transaction_snapshot is not None:
decoder = msgspec.json.Decoder(DB)
self.db = decoder.decode(
msgspec.json.encode(self._transaction_snapshot)
)
self.db._store = self
raise
finally:
self._current_action = old_action
self._current_user = old_user
self._in_transaction = False
self._transaction_snapshot = None
async def flush(self) -> bool:
"""Write all pending changes to disk."""
return await flush_changes(self.db_path, self._pending_changes)
+318
View File
@@ -0,0 +1,318 @@
"""
Database change logging with pretty-printed diffs.
Provides a logger for JSONL database changes that formats diffs
in a human-readable path.notation style with color coding.
"""
import logging
import re
import sys
from typing import Any
logger = logging.getLogger("paskia.db")
# Pattern to match control characters and bidirectional overrides
_UNSAFE_CHARS = re.compile(
r"[\x00-\x1f\x7f-\x9f" # C0 and C1 control characters
r"\u200e\u200f" # LRM, RLM
r"\u202a-\u202e" # LRE, RLE, PDF, LRO, RLO
r"\u2066-\u2069" # LRI, RLI, FSI, PDI
r"]"
)
# ANSI color codes (matching FastAPI logging style)
_RESET = "\033[0m"
_DIM = "\033[2m"
_PATH_PREFIX = "\033[1;30m" # Dark grey for path prefix (like host in access log)
_PATH_FINAL = "\033[0m" # Default for final element (like path in access log)
_DELETE = "\033[1;31m" # Red for deletions
_ADD = "\033[0;32m" # Green for additions
_ACTION = "\033[1;34m" # Bold blue for action name
_USER = "\033[0;34m" # Blue for user display
def _use_color() -> bool:
"""Check if we should use color output."""
return sys.stderr.isatty()
def _format_value(value: Any, use_color: bool, max_len: int = 60) -> str:
"""Format a value for display, truncating if needed."""
if value is None:
return "null"
if isinstance(value, bool):
return "true" if value else "false"
if isinstance(value, (int, float)):
return str(value)
if isinstance(value, str):
# Filter out control characters and bidirectional overrides
value = _UNSAFE_CHARS.sub("", value)
# Truncate long strings
if len(value) > max_len:
return value[: max_len - 3] + "..."
return value
if isinstance(value, dict):
if not value:
return "{}"
# For small dicts, show inline
if len(value) == 1:
k, v = next(iter(value.items()))
return "{" + f"{k}: {_format_value(v, use_color, max_len=30)}" + "}"
return f"{{...{len(value)} keys}}"
if isinstance(value, list):
if not value:
return "[]"
if len(value) == 1:
return "[" + _format_value(value[0], use_color, max_len=30) + "]"
return f"[...{len(value)} items]"
# Fallback for other types
text = str(value)
if len(text) > max_len:
text = text[: max_len - 3] + "..."
return text
def _format_path(path: list[str], use_color: bool) -> str:
"""Format a path as dot notation with prefix in dark grey, final in default."""
if not path:
return ""
if not use_color:
return ".".join(path)
if len(path) == 1:
return f"{_PATH_FINAL}{path[0]}{_RESET}"
prefix = ".".join(path[:-1])
final = path[-1]
return f"{_PATH_PREFIX}{prefix}.{_RESET}{_PATH_FINAL}{final}{_RESET}"
def _get_nested(data: dict | None, path: list[str]) -> Any:
"""Get a nested value from a dict by path, or None if not found."""
if data is None:
return None
current = data
for key in path:
if not isinstance(current, dict) or key not in current:
return None
current = current[key]
return current
def _collect_changes(
diff: dict,
path: list[str],
changes: list[tuple[str, list[str], Any]],
previous: dict | None,
) -> None:
"""
Recursively collect changes from a diff into a flat list.
Each change is a tuple of (change_type, path, new_value).
change_type is one of: 'add', 'update', 'delete'
"""
if not isinstance(diff, dict):
# Leaf value - check if it existed before
existed = _get_nested(previous, path) is not None
changes.append(("update" if existed else "add", path, diff))
return
for key, value in diff.items():
if key == "$delete":
# $delete contains a list of keys to delete
if isinstance(value, list):
for deleted_key in value:
changes.append(("delete", path + [str(deleted_key)], None))
else:
changes.append(("delete", path + [str(value)], None))
elif key == "$replace":
# $replace replaces the entire collection at this path
# We need to track what was added and what was deleted
old_collection = _get_nested(previous, path)
old_keys = (
set(old_collection.keys())
if isinstance(old_collection, dict)
else set()
)
new_keys = set(value.keys()) if isinstance(value, dict) else set()
# Items that existed before but not in new = deleted
for deleted_key in old_keys - new_keys:
changes.append(("delete", path + [str(deleted_key)], None))
# Items in new collection
if isinstance(value, dict):
for rkey, rval in value.items():
existed = rkey in old_keys
changes.append(
("update" if existed else "add", path + [str(rkey)], rval)
)
elif value or not old_keys:
# Non-dict replacement or empty replacement with nothing before
changes.append(
("update" if old_collection is not None else "add", path, value)
)
elif key.startswith("$"):
# Other special operations (future-proofing)
changes.append(("add", path, {key: value}))
else:
# Regular nested key - check if this item existed before
new_path = path + [str(key)]
existed = _get_nested(previous, new_path) is not None
if existed:
# Item exists - recurse to show specific field changes
_collect_changes(value, new_path, changes, previous)
else:
# New item - record as add with full value, don't recurse
changes.append(("add", new_path, value))
def _format_change_lines(
change_type: str, path: list[str], value: Any, use_color: bool
) -> list[str]:
"""Format a single change as one or more lines."""
if change_type == "delete":
if not use_color:
return [f" {'.'.join(path)}"]
if len(path) == 1:
return [f" {_DELETE}{path[0]}{_RESET}"]
prefix = ".".join(path[:-1])
final = path[-1]
return [f" {_PATH_PREFIX}{prefix}.{_RESET}{_DELETE}{final}{_RESET}"]
if change_type == "add":
# New item being created - only final element in green
# For dict values, show children on separate indented lines
if isinstance(value, dict) and value:
lines = []
# First line: path with green final element and grey =
if not use_color:
lines.append(f" {'.'.join(path)} =")
elif len(path) == 1:
lines.append(f" {_ADD}{path[0]}{_RESET} {_DIM}={_RESET}")
else:
prefix = ".".join(path[:-1])
final = path[-1]
lines.append(
f" {_PATH_PREFIX}{prefix}.{_RESET}{_ADD}{final}{_RESET} {_DIM}={_RESET}"
)
# Child lines: indented key: value, with aligned values
max_key_len = max(len(k) for k in value.keys())
field_width = max(max_key_len, 12) # minimum 12 chars
for k, v in value.items():
v_str = _format_value(v, use_color)
padding = " " * (field_width - len(k))
if use_color:
lines.append(f" {k}{_DIM}:{_RESET}{padding} {v_str}")
else:
lines.append(f" {k}:{padding} {v_str}")
return lines
else:
value_str = _format_value(value, use_color)
if not use_color:
return [f" {'.'.join(path)} = {value_str}"]
if len(path) == 1:
return [f" {_ADD}{path[0]}{_RESET} {_DIM}={_RESET} {value_str}"]
prefix = ".".join(path[:-1])
final = path[-1]
return [
f" {_PATH_PREFIX}{prefix}.{_RESET}{_ADD}{final}{_RESET} {_DIM}={_RESET} {value_str}"
]
# update: Existing item being updated - normal path colors
value_str = _format_value(value, use_color)
path_str = _format_path(path, use_color)
if use_color:
return [f" {path_str} {_DIM}={_RESET} {value_str}"]
return [f" {path_str} = {value_str}"]
def format_diff(diff: dict, previous: dict | None = None) -> list[str]:
"""
Format a JSON diff as human-readable lines.
Args:
diff: The JSON diff dict
previous: The previous state dict (for determining add vs update)
Returns a list of formatted lines (without newlines).
Single changes return one line, multiple changes return multiple lines.
"""
use_color = _use_color()
changes: list[tuple[str, list[str], Any]] = []
_collect_changes(diff, [], changes, previous)
if not changes:
return []
# Format each change
lines = []
for change_type, path, value in changes:
lines.extend(_format_change_lines(change_type, path, value, use_color))
return lines
def format_action_header(action: str, user_display: str | None = None) -> str:
"""Format the action header line."""
use_color = _use_color()
if use_color:
action_str = f"{_ACTION}{action}{_RESET}"
if user_display:
user_str = f"{_USER}{user_display}{_RESET}"
return f"{action_str} by {user_str}"
return action_str
else:
if user_display:
return f"{action} by {user_display}"
return action
def log_change(
action: str,
diff: dict,
user_display: str | None = None,
previous: dict | None = None,
) -> None:
"""
Log a database change with pretty-printed diff.
Args:
action: The action name (e.g., "login", "admin:delete_user")
diff: The JSON diff dict
user_display: Optional display name of the user who performed the action
previous: The previous state dict (for determining add vs update)
"""
header = format_action_header(action, user_display)
diff_lines = format_diff(diff, previous)
if not diff_lines:
logger.info(header)
return
if len(diff_lines) == 1:
# Single change - combine on one line
logger.info(f"{header}{diff_lines[0]}")
else:
# Multiple changes - header on its own line, then changes
logger.info(header)
for line in diff_lines:
logger.info(line)
def configure_db_logging() -> None:
"""Configure the database logger to output to stderr without prefix."""
handler = logging.StreamHandler(sys.stderr)
handler.setFormatter(logging.Formatter("%(message)s"))
logger.addHandler(handler)
logger.setLevel(logging.INFO)
logger.propagate = False
+33
View File
@@ -0,0 +1,33 @@
"""
Database schema migrations.
Migrations are applied during database load based on the version field.
Each migration should be idempotent and only run when needed.
"""
from collections.abc import Awaitable, Callable
def migrate_v1(d: dict) -> None:
"""Remove Org.created_at fields."""
for org_data in d["orgs"].values():
org_data.pop("created_at", None)
migrations = sorted(
[f for n, f in globals().items() if n.startswith("migrate_v")],
key=lambda f: int(f.__name__.removeprefix("migrate_v")),
)
DBVER = len(migrations) # Used by bootstrap and migrate:sql to set initial version
async def apply_all_migrations(
data_dict: dict,
current_version: int,
persist: Callable[[str, int, dict], Awaitable[None]],
) -> None:
while current_version < DBVER:
migrations[current_version](data_dict)
current_version += 1
await persist(f"migrate:v{current_version}", current_version, data_dict)
+846
View File
@@ -0,0 +1,846 @@
"""
Database for WebAuthn passkey authentication.
Read operations: Access _db directly, use build_* helpers to get public structs.
Context lookup: _db.session_ctx() returns full SessionContext with effective permissions.
Write operations: Functions that validate and commit, or raise ValueError.
"""
import hashlib
import logging
import os
import secrets
from datetime import UTC, datetime
from uuid import UUID
import uuid7
from paskia.config import SESSION_LIFETIME
from paskia.db.jsonl import (
DB_PATH_DEFAULT,
JsonlStore,
)
from paskia.db.structs import (
DB,
Credential,
Org,
Permission,
ResetToken,
Role,
Session,
SessionContext,
User,
)
from paskia.util.passphrase import generate as generate_passphrase
from paskia.util.passphrase import is_well_formed as _is_passphrase
_logger = logging.getLogger(__name__)
# Global database instance (empty until init() loads data)
_db = DB()
_store = JsonlStore(_db)
_db._store = _store
_initialized = False
async def init(*args, **kwargs):
"""Load database from JSONL file."""
global _db, _initialized
if _initialized:
_logger.debug("Database already initialized, skipping reload")
return
db_path = os.environ.get("PASKIA_DB", DB_PATH_DEFAULT)
if db_path.startswith("json:"):
db_path = db_path[5:]
await _store.load(db_path)
_db = _store.db
_initialized = True
# -------------------------------------------------------------------------
# Read/lookup functions
# -------------------------------------------------------------------------
def get_user_organization(user_uuid: UUID) -> tuple[Org, str]:
"""Get the organization a user belongs to and their role name.
Raises ValueError if user not found.
Call sites:
- update_user_role_in_organization: org only
- admin_create_user_registration_link: org only
- admin_get_user_detail: org and role
- admin_update_user_display_name: org only
- admin_delete_user_credential: org only
- admin_delete_user_session: org only
"""
if user_uuid not in _db.users:
raise ValueError(f"User {user_uuid} not found")
user = _db.users[user_uuid]
role = user.role
return role.org, role.display_name
def get_organization_users(org_uuid: UUID) -> list[tuple[User, str]]:
"""Get all users in an organization with their role names.
Returns list of (User, role_display_name) tuples.
"""
org = _db.orgs[org_uuid]
return [(u, u.role.display_name) for role in org.roles for u in role.users]
def get_user_credential_ids(user_uuid: UUID) -> list[bytes]:
"""Get credential IDs for a user (for WebAuthn exclude lists).
Returns empty list if user has no credentials.
"""
assert user_uuid
return [c.credential_id for c in _db.users[user_uuid].credentials]
def _reset_key(passphrase: str) -> bytes:
"""Hash a passphrase to bytes for reset token storage."""
if not _is_passphrase(passphrase):
raise ValueError(
"Trying to reset with a session token in place of a passphrase"
if len(passphrase) == 16
else "Invalid passphrase format"
)
return hashlib.sha512(passphrase.encode()).digest()[:9]
def get_reset_token(passphrase: str) -> ResetToken | None:
"""Get reset token by passphrase.
Call sites:
- Get reset token to validate it (authsession.py:34)
"""
key = _reset_key(passphrase)
return _db.reset_tokens.get(key)
# -------------------------------------------------------------------------
# Write operations (validate, modify, commit or raise ValueError)
# -------------------------------------------------------------------------
def create_permission(perm: Permission, *, ctx: SessionContext | None = None) -> None:
"""Create a new permission."""
if perm.uuid in _db.permissions:
raise ValueError(f"Permission {perm.uuid} already exists")
with _db.transaction("admin:create_permission", ctx):
_db.permissions[perm.uuid] = perm
def update_permission(
uuid: UUID,
scope: str,
display_name: str,
domain: str | None = None,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update a permission's scope, display_name, and domain.
Only these fields can be modified; created_at and other metadata remain immutable.
"""
if uuid not in _db.permissions:
raise ValueError(f"Permission {uuid} not found")
with _db.transaction("admin:update_permission", ctx):
_db.permissions[uuid].scope = scope
_db.permissions[uuid].display_name = display_name
_db.permissions[uuid].domain = domain
def delete_permission(uuid: UUID, *, ctx: SessionContext | None = None) -> None:
"""Delete a permission and remove it from all roles."""
if uuid not in _db.permissions:
raise ValueError(f"Permission {uuid} not found")
with _db.transaction("admin:delete_permission", ctx):
# Remove this permission from all roles
for role in _db.roles.values():
role.permissions.pop(uuid, None)
del _db.permissions[uuid]
def create_org(org: Org, *, ctx: SessionContext | None = None) -> None:
"""Create a new organization with an Administration role.
Automatically creates an 'Administration' role with auth:org:admin permission.
"""
if org.uuid in _db.orgs:
raise ValueError(f"Organization {org.uuid} already exists")
with _db.transaction("admin:create_org", ctx):
new_org = Org.create(display_name=org.display_name)
new_org.uuid = org.uuid
_db.orgs[org.uuid] = new_org
# Create Administration role with org admin permission
admin_role_uuid = uuid7.create()
# Find the auth:org:admin permission UUID
org_admin_perm_uuid = None
for pid, p in _db.permissions.items():
if p.scope == "auth:org:admin":
org_admin_perm_uuid = pid
break
role_permissions = {org_admin_perm_uuid: True} if org_admin_perm_uuid else {}
admin_role = Role(
org_uuid=org.uuid,
display_name="Administration",
permissions=role_permissions,
)
admin_role.uuid = admin_role_uuid
_db.roles[admin_role_uuid] = admin_role
def update_org_name(
uuid: UUID,
display_name: str,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update organization display name."""
if uuid not in _db.orgs:
raise ValueError(f"Organization {uuid} not found")
with _db.transaction("admin:update_org_name", ctx):
_db.orgs[uuid].display_name = display_name
def delete_org(uuid: UUID, *, ctx: SessionContext | None = None) -> None:
"""Delete organization and all its roles/users."""
if uuid not in _db.orgs:
raise ValueError(f"Organization {uuid} not found")
with _db.transaction("admin:delete_org", ctx):
org = _db.orgs[uuid]
# Remove org from all permissions
for p in _db.permissions.values():
p.orgs.pop(uuid, None)
# Delete roles in this org and their users
for role in org.roles:
for user in role.users:
del _db.users[user.uuid]
del _db.roles[role.uuid]
del _db.orgs[uuid]
def add_permission_to_org(
org_uuid: UUID,
permission_uuid: UUID,
*,
ctx: SessionContext | None = None,
) -> None:
"""Grant a permission to an organization by UUID."""
if org_uuid not in _db.orgs:
raise ValueError(f"Organization {org_uuid} not found")
if permission_uuid not in _db.permissions:
raise ValueError(f"Permission {permission_uuid} not found")
with _db.transaction("admin:add_permission_to_org", ctx):
_db.permissions[permission_uuid].orgs[org_uuid] = True
def remove_permission_from_org(
org_uuid: UUID,
permission_uuid: UUID,
*,
ctx: SessionContext | None = None,
) -> None:
"""Remove a permission from an organization by UUID."""
if org_uuid not in _db.orgs:
raise ValueError(f"Organization {org_uuid} not found")
if permission_uuid not in _db.permissions:
return # Permission not found, silently return
with _db.transaction("admin:remove_permission_from_org", ctx):
_db.permissions[permission_uuid].orgs.pop(org_uuid, None)
def create_role(role: Role, *, ctx: SessionContext | None = None) -> None:
"""Create a new role."""
if role.uuid in _db.roles:
raise ValueError(f"Role {role.uuid} already exists")
if role.org_uuid not in _db.orgs:
raise ValueError(f"Organization {role.org_uuid} not found")
with _db.transaction("admin:create_role", ctx):
_db.roles[role.uuid] = role
def update_role_name(
uuid: UUID,
display_name: str,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update role display name."""
if uuid not in _db.roles:
raise ValueError(f"Role {uuid} not found")
with _db.transaction("admin:update_role_name", ctx):
_db.roles[uuid].display_name = display_name
def add_permission_to_role(
role_uuid: UUID,
permission_uuid: UUID,
*,
ctx: SessionContext | None = None,
) -> None:
"""Add permission to role by UUID."""
if role_uuid not in _db.roles:
raise ValueError(f"Role {role_uuid} not found")
if permission_uuid not in _db.permissions:
raise ValueError(f"Permission {permission_uuid} not found")
with _db.transaction("admin:add_permission_to_role", ctx):
_db.roles[role_uuid].permissions[permission_uuid] = True
def remove_permission_from_role(
role_uuid: UUID,
permission_uuid: UUID,
*,
ctx: SessionContext | None = None,
) -> None:
"""Remove permission from role by UUID."""
if role_uuid not in _db.roles:
raise ValueError(f"Role {role_uuid} not found")
with _db.transaction("admin:remove_permission_from_role", ctx):
_db.roles[role_uuid].permissions.pop(permission_uuid, None)
def delete_role(uuid: UUID, *, ctx: SessionContext | None = None) -> None:
"""Delete a role."""
if uuid not in _db.roles:
raise ValueError(f"Role {uuid} not found")
# Check no users have this role
role = _db.roles[uuid]
if role.users:
raise ValueError(f"Cannot delete role {uuid}: users still assigned")
with _db.transaction("admin:delete_role", ctx):
del _db.roles[uuid]
def create_user(new_user: User, *, ctx: SessionContext | None = None) -> None:
"""Create a new user."""
if new_user.uuid in _db.users:
raise ValueError(f"User {new_user.uuid} already exists")
if new_user.role_uuid not in _db.roles:
raise ValueError(f"Role {new_user.role_uuid} not found")
with _db.transaction("admin:create_user", ctx):
_db.users[new_user.uuid] = new_user
def update_user_display_name(
uuid: UUID,
display_name: str,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update user display name.
The acting user should be logged via ctx.
For self-service (user updating own name), pass user's ctx.
For admin operations, pass admin's ctx.
"""
if isinstance(uuid, str):
uuid = UUID(uuid)
if uuid not in _db.users:
raise ValueError(f"User {uuid} not found")
with _db.transaction("update_user_display_name", ctx):
_db.users[uuid].display_name = display_name
def update_user_theme(
uuid: UUID,
theme: str,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update user theme preference ('' for auto, 'light', 'dark')."""
if isinstance(uuid, str):
uuid = UUID(uuid)
if uuid not in _db.users:
raise ValueError(f"User {uuid} not found")
if theme not in ("", "light", "dark"):
raise ValueError(f"Invalid theme: {theme}")
with _db.transaction("update_user_theme", ctx):
_db.users[uuid].theme = theme
def update_user_role(
uuid: UUID,
role_uuid: UUID,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update user's role."""
if uuid not in _db.users:
raise ValueError(f"User {uuid} not found")
if role_uuid not in _db.roles:
raise ValueError(f"Role {role_uuid} not found")
with _db.transaction("admin:update_user_role", ctx):
_db.users[uuid].role_uuid = role_uuid
def update_user_role_in_organization(
user_uuid: UUID,
role_name: str,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update user's role by role name within their current organization."""
if user_uuid not in _db.users:
raise ValueError(f"User {user_uuid} not found")
user = _db.users[user_uuid]
org = user.org
# Find role by name in the same org
new_role_uuid = None
for r in org.roles:
if r.display_name == role_name:
new_role_uuid = r.uuid
break
if new_role_uuid is None:
raise ValueError(f"Role '{role_name}' not found in organization")
with _db.transaction("admin:update_user_role", ctx):
_db.users[user_uuid].role_uuid = new_role_uuid
def delete_user(uuid: UUID, *, ctx: SessionContext | None = None) -> None:
"""Delete user and their credentials/sessions."""
if uuid not in _db.users:
raise ValueError(f"User {uuid} not found")
user = _db.users[uuid]
with _db.transaction("admin:delete_user", ctx):
# Delete credentials
for cred in user.credentials:
del _db.credentials[cred.uuid]
# Delete sessions
for sess in user.sessions:
del _db.sessions[sess.key]
# Delete reset tokens
for token in user.reset_tokens:
del _db.reset_tokens[token.key]
del _db.users[uuid]
def create_credential(cred: Credential, *, ctx: SessionContext | None = None) -> None:
"""Create a new credential."""
if cred.uuid in _db.credentials:
raise ValueError(f"Credential {cred.uuid} already exists")
if cred.user_uuid not in _db.users:
raise ValueError(f"User {cred.user_uuid} not found")
with _db.transaction("create_credential", ctx):
_db.credentials[cred.uuid] = cred
def update_credential_sign_count(
uuid: UUID,
sign_count: int,
last_used: datetime | None = None,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update credential sign count and last_used."""
if uuid not in _db.credentials:
raise ValueError(f"Credential {uuid} not found")
with _db.transaction("update_credential_sign_count", ctx):
_db.credentials[uuid].sign_count = sign_count
if last_used:
_db.credentials[uuid].last_used = last_used
def delete_credential(
uuid: UUID,
user_uuid: UUID | None = None,
*,
ctx: SessionContext | None = None,
) -> None:
"""Delete a credential and all sessions using it.
If user_uuid is provided, validates that the credential belongs to that user.
"""
if uuid not in _db.credentials:
raise ValueError(f"Credential {uuid} not found")
cred = _db.credentials[uuid]
if user_uuid is not None:
if cred.user_uuid != user_uuid:
raise ValueError(f"Credential {uuid} does not belong to user {user_uuid}")
with _db.transaction("delete_credential", ctx):
# Delete all sessions using this credential
for sess in cred.sessions:
print(sess, repr(sess.key))
del _db.sessions[sess.key]
del _db.credentials[uuid]
def create_session(
user_uuid: UUID,
credential_uuid: UUID,
host: str,
ip: str,
user_agent: str,
expiry: datetime,
*,
ctx: SessionContext | None = None,
) -> str:
"""Create a new session. Returns the session key."""
if user_uuid not in _db.users:
raise ValueError(f"User {user_uuid} not found")
if credential_uuid not in _db.credentials:
raise ValueError(f"Credential {credential_uuid} not found")
session = Session.create(
user=user_uuid,
credential=credential_uuid,
host=host,
ip=ip,
user_agent=user_agent,
expiry=expiry,
)
if session.key in _db.sessions:
raise ValueError("Session already exists")
with _db.transaction("create_session", ctx):
_db.sessions[session.key] = session
return session.key
def update_session(
key: str,
host: str | None = None,
ip: str | None = None,
user_agent: str | None = None,
expiry: datetime | None = None,
*,
ctx: SessionContext | None = None,
) -> None:
"""Update session metadata."""
if key not in _db.sessions:
raise ValueError("Session not found")
with _db.transaction("update_session", ctx):
s = _db.sessions[key]
if host is not None:
s.host = host
if ip is not None:
s.ip = ip
if user_agent is not None:
s.user_agent = user_agent
if expiry is not None:
s.expiry = expiry
def set_session_host(key: str, host: str, *, ctx: SessionContext | None = None) -> None:
"""Set the host for a session (first-time binding)."""
update_session(key, host=host, ctx=ctx)
def delete_session(
key: str, *, ctx: SessionContext | None = None, action: str = "delete_session"
) -> None:
"""Delete a session.
The acting user should be logged via ctx.
For user logout, pass ctx of the user's session and action="logout".
For admin terminating a session, pass admin's ctx.
"""
if key not in _db.sessions:
raise ValueError("Session not found")
with _db.transaction(action, ctx):
del _db.sessions[key]
def delete_sessions_for_user(
user_uuid: UUID, *, ctx: SessionContext | None = None
) -> None:
"""Delete all sessions for a user.
The acting user should be logged via ctx.
For user logout-all, pass ctx of the user's session.
For admin bulk termination, pass admin's ctx.
"""
user = _db.users.get(user_uuid)
if not user:
return
with _db.transaction("admin:delete_sessions_for_user", ctx):
for sess in user.sessions:
del _db.sessions[sess.key]
def create_reset_token(
passphrase: str,
user_uuid: UUID,
expiry: datetime,
token_type: str,
*,
ctx: SessionContext | None = None,
user: str | None = None,
) -> None:
"""Create a reset token from a passphrase.
The acting user should be logged via ctx.
For self-service (user creating own recovery link), pass user's ctx.
For admin operations, pass admin's ctx.
For system operations (bootstrap), pass neither to log no user.
For API operations where ctx is not available but user is known, pass user.
"""
key = _reset_key(passphrase)
if key in _db.reset_tokens:
raise ValueError("Reset token already exists")
if user_uuid not in _db.users:
raise ValueError(f"User {user_uuid} not found")
with _db.transaction("create_reset_token", ctx, user=user):
_db.reset_tokens[key] = ResetToken(
user_uuid=user_uuid, expiry=expiry, token_type=token_type
)
def delete_reset_token(key: bytes, *, ctx: SessionContext | None = None) -> None:
"""Delete a reset token."""
if key not in _db.reset_tokens:
raise ValueError("Reset token not found")
with _db.transaction("delete_reset_token", ctx):
del _db.reset_tokens[key]
# -------------------------------------------------------------------------
# Cleanup (called by background task)
# -------------------------------------------------------------------------
def cleanup_expired() -> int:
"""Remove expired sessions and reset tokens. Returns count removed."""
now = datetime.now(UTC)
count = 0
with _db.transaction("expiry"):
expired_sessions = [k for k, s in _db.sessions.items() if s.expiry < now]
for k in expired_sessions:
del _db.sessions[k]
count += 1
expired_tokens = [k for k, t in _db.reset_tokens.items() if t.expiry < now]
for k in expired_tokens:
del _db.reset_tokens[k]
count += 1
return count
# -------------------------------------------------------------------------
# Composite operations (used by app code)
# -------------------------------------------------------------------------
def _create_token() -> str:
"""Generate a 16-character URL-safe session token."""
return secrets.token_urlsafe(12)
def login(
user_uuid: UUID,
credential_uuid: UUID,
sign_count: int,
host: str,
ip: str,
user_agent: str,
expiry: datetime,
) -> str:
"""Update user/credential on login and create session in a single transaction.
Updates:
- user.last_seen, user.visits
- credential.sign_count, credential.last_used
Creates:
- new session
Returns the generated session token.
"""
if isinstance(user_uuid, str):
user_uuid = UUID(user_uuid)
now = datetime.now(UTC)
if user_uuid not in _db.users:
raise ValueError(f"User {user_uuid} not found")
if credential_uuid not in _db.credentials:
raise ValueError(f"Credential {credential_uuid} not found")
session = Session.create(
user=user_uuid,
credential=credential_uuid,
host=host,
ip=ip,
user_agent=user_agent,
expiry=expiry,
)
user_str = str(user_uuid)
with _db.transaction("login", user=user_str):
# Update user
_db.users[user_uuid].last_seen = now
_db.users[user_uuid].visits += 1
# Update credential
_db.credentials[credential_uuid].sign_count = sign_count
_db.credentials[credential_uuid].last_used = now
# Create session
_db.sessions[session.key] = session
return session.key
def create_credential_session(
user_uuid: UUID,
credential: Credential,
host: str,
ip: str,
user_agent: str,
display_name: str | None = None,
reset_key: bytes | None = None,
) -> str:
"""Create a credential and session together, optionally consuming a reset token.
Used during registration to atomically:
1. Update user display_name if provided
2. Create the credential
3. Create the session
4. Delete the reset token if provided
Returns the generated session token.
"""
now = datetime.now(UTC)
expiry = now + SESSION_LIFETIME
if user_uuid not in _db.users:
raise ValueError(f"User {user_uuid} not found")
session = Session.create(
user=user_uuid,
credential=credential.uuid,
host=host,
ip=ip,
user_agent=user_agent,
expiry=expiry,
)
user_str = str(user_uuid)
with _db.transaction("create_credential_session", user=user_str):
# Update display name if provided
if display_name:
_db.users[user_uuid].display_name = display_name
# Create credential
_db.credentials[credential.uuid] = credential
# Create session
_db.sessions[session.key] = session
# Delete reset token if provided
if reset_key:
if reset_key in _db.reset_tokens:
del _db.reset_tokens[reset_key]
return session.key
# -------------------------------------------------------------------------
# Bootstrap (single transaction for initial system setup)
# -------------------------------------------------------------------------
def bootstrap(
org_name: str = "Organization",
admin_name: str = "Admin",
reset_passphrase: str | None = None,
reset_expiry: datetime | None = None,
) -> str:
"""Bootstrap the entire system in a single transaction.
Creates:
- auth:admin permission (Master Admin)
- auth:org:admin permission (Org Admin)
- Organization with Administration role
- Admin user with Administration role
- Reset token for admin registration
This is the only way to create a new database file (besides migrate).
All data is created atomically - if any step fails, nothing is written.
Args:
org_name: Display name for the organization (default: "Organization")
admin_name: Display name for the admin user (default: "Admin")
reset_passphrase: Passphrase for the reset token (generated if not provided)
reset_expiry: Expiry datetime for the reset token (default: 14 days)
Returns:
The reset passphrase for admin registration.
"""
# Check if system is already bootstrapped
for p in _db.permissions.values():
if p.scope == "auth:admin":
raise ValueError(
"System already bootstrapped (auth:admin permission exists)"
)
# Generate UUIDs upfront
perm_admin_uuid = uuid7.create()
perm_org_admin_uuid = uuid7.create()
org_uuid = uuid7.create()
role_uuid = uuid7.create()
user_uuid = uuid7.create()
# Generate reset token components
if reset_passphrase is None:
reset_passphrase = generate_passphrase()
if reset_expiry is None:
from paskia.authsession import reset_expires # noqa: PLC0415
reset_expiry = reset_expires()
reset_key = _reset_key(reset_passphrase)
now = datetime.now(UTC)
with _db.transaction("bootstrap"):
# Create auth:admin permission
perm_admin = Permission(
scope="auth:admin",
display_name="Master Admin",
orgs={org_uuid: True}, # Grant to org
)
perm_admin.uuid = perm_admin_uuid
_db.permissions[perm_admin_uuid] = perm_admin
# Create auth:org:admin permission
perm_org_admin = Permission(
scope="auth:org:admin",
display_name="Org Admin",
orgs={org_uuid: True}, # Grant to org
)
perm_org_admin.uuid = perm_org_admin_uuid
_db.permissions[perm_org_admin_uuid] = perm_org_admin
# Create organization
new_org = Org.create(display_name=org_name)
new_org.uuid = org_uuid
_db.orgs[org_uuid] = new_org
# Create Administration role with both permissions
admin_role = Role(
org_uuid=org_uuid,
display_name="Administration",
permissions={perm_admin_uuid: True, perm_org_admin_uuid: True},
)
admin_role.uuid = role_uuid
_db.roles[role_uuid] = admin_role
# Create admin user
admin_user = User(
display_name=admin_name,
role_uuid=role_uuid,
created_at=now,
last_seen=None,
visits=0,
)
admin_user.uuid = user_uuid
_db.users[user_uuid] = admin_user
# Create reset token
_db.reset_tokens[reset_key] = ResetToken(
user_uuid=user_uuid,
expiry=reset_expiry,
token_type="admin bootstrap",
)
return reset_passphrase
-1424
View File
File diff suppressed because it is too large Load Diff
+463
View File
@@ -0,0 +1,463 @@
from __future__ import annotations
import secrets
from datetime import UTC, datetime
from uuid import UUID
import msgspec
import uuid7
from paskia import db
from paskia.util.hostutil import normalize_host
# Sentinel for uuid fields before they are set by create() or DB post init
_UUID_UNSET = UUID(int=0)
class Permission(msgspec.Struct, dict=True, omit_defaults=True):
"""Permission data structure.
Mutable fields: scope, display_name, domain, orgs
Immutable fields: None (all fields can be updated via update_permission)
uuid is generated at creation.
"""
scope: str # Permission scope identifier (e.g. "auth:admin", "myapp:write")
display_name: str
domain: str | None = None # If set, scopes permission to this domain
orgs: dict[UUID, bool] = {} # org_uuid -> True (which orgs can grant this)
def __post_init__(self):
if not hasattr(self, "uuid"):
self.uuid: UUID = _UUID_UNSET
@property
def org_set(self) -> set[UUID]:
"""Get orgs that can grant this permission as a set."""
return set(self.orgs.keys())
@property
def orgs_list(self) -> list[Org]:
"""Get list of Org objects that can grant this permission."""
return [
db.data().orgs[org_uuid]
for org_uuid in self.orgs.keys()
if org_uuid in db.data().orgs
]
@classmethod
def create(
cls,
scope: str,
display_name: str,
domain: str | None = None,
) -> Permission:
"""Create a new Permission with auto-generated uuid7."""
perm = cls(
scope=scope,
display_name=display_name,
domain=domain,
)
perm.uuid = uuid7.create()
return perm
class Org(msgspec.Struct, dict=True):
"""Organization data structure."""
display_name: str
def __post_init__(self):
if not hasattr(self, "uuid"):
self.uuid: UUID = _UUID_UNSET
@property
def roles(self) -> list[Role]:
"""Get all roles that belong to this organization."""
return [r for r in db.data().roles.values() if r.org_uuid == self.uuid]
@property
def permissions(self) -> list[Permission]:
"""Get all permissions that this organization can grant."""
return [p for p in db.data().permissions.values() if self.uuid in p.orgs]
@classmethod
def create(cls, display_name: str) -> Org:
"""Create a new Org with auto-generated uuid7."""
org = cls(display_name=display_name)
org.uuid = uuid7.create()
return org
class Role(msgspec.Struct, dict=True, omit_defaults=True):
"""Role data structure.
Mutable fields: display_name, permissions
Immutable fields: org_uuid (set at creation, never modified)
uuid is generated at creation.
"""
org_uuid: UUID = msgspec.field(name="org")
display_name: str
permissions: dict[UUID, bool] = {} # permission_uuid -> True
def __post_init__(self):
if not hasattr(self, "uuid"):
self.uuid: UUID = _UUID_UNSET
@property
def permission_set(self) -> set[UUID]:
"""Get permissions as a set of UUIDs."""
return set(self.permissions.keys())
@property
def permissions_list(self) -> list[Permission]:
"""Get list of Permission objects for this role."""
return [
db.data().permissions[perm_uuid]
for perm_uuid in self.permissions.keys()
if perm_uuid in db.data().permissions
]
@property
def org(self) -> Org:
"""Get the organization object this role belongs to."""
return db.data().orgs[self.org_uuid]
@property
def users(self) -> list[User]:
"""Get all users that have this role."""
return [u for u in db.data().users.values() if u.role_uuid == self.uuid]
@classmethod
def create(
cls,
org: UUID | Org,
display_name: str,
permissions: set[UUID] | None = None,
) -> Role:
"""Create a new Role with auto-generated uuid7."""
org_uuid = org if isinstance(org, UUID) else org.uuid
role = cls(
org_uuid=org_uuid,
display_name=display_name,
permissions={p: True for p in (permissions or set())},
)
role.uuid = uuid7.create()
return role
class User(msgspec.Struct, dict=True, omit_defaults=True):
"""User data structure.
Mutable fields: display_name, role_uuid, last_seen, visits, theme
Immutable fields: created_at (set at creation, never modified)
uuid is derived from created_at using uuid7.
"""
display_name: str
role_uuid: UUID = msgspec.field(name="role")
created_at: datetime
last_seen: datetime | None = None
visits: int = 0
theme: str = "" # "" or "auto" = OS default, "light", "dark"
def __post_init__(self):
if not hasattr(self, "uuid"):
self.uuid: UUID = _UUID_UNSET
@property
def role(self) -> Role:
"""Get the role object this user has."""
return db.data().roles[self.role_uuid]
@property
def org(self) -> Org:
"""Get the organization this user belongs to (via role)."""
return self.role.org
@property
def credentials(self) -> list[Credential]:
"""Get all credentials for this user."""
return [c for c in db.data().credentials.values() if c.user_uuid == self.uuid]
@property
def sessions(self) -> list[Session]:
"""Get all sessions for this user."""
return [s for s in db.data().sessions.values() if s.user_uuid == self.uuid]
@property
def reset_tokens(self) -> list[ResetToken]:
"""Get all reset tokens for this user."""
return [t for t in db.data().reset_tokens.values() if t.user_uuid == self.uuid]
@classmethod
def create(
cls,
display_name: str,
role: UUID | Role,
created_at: datetime | None = None,
) -> User:
"""Create a new User with auto-generated uuid7."""
role_uuid = role if isinstance(role, UUID) else role.uuid
user = cls(
display_name=display_name,
role_uuid=role_uuid,
created_at=created_at or datetime.now(UTC),
)
user.uuid = uuid7.create(user.created_at)
return user
class Credential(msgspec.Struct, dict=True):
"""Credential (passkey) data structure.
Mutable fields: sign_count, last_used, last_verified
Immutable fields: credential_id, user, aaguid, public_key, created_at
uuid is derived from created_at using uuid7.
"""
credential_id: bytes # Long binary ID from the authenticator
user_uuid: UUID = msgspec.field(name="user")
aaguid: UUID
public_key: bytes
sign_count: int
created_at: datetime
last_used: datetime | None = None
last_verified: datetime | None = None
def __post_init__(self):
if not hasattr(self, "uuid"):
self.uuid: UUID = _UUID_UNSET
@property
def user(self) -> User:
"""Get the User object for this credential."""
return db.data().users[self.user_uuid]
@property
def sessions(self) -> list[Session]:
"""Get all sessions using this credential."""
return [
s for s in db.data().sessions.values() if s.credential_uuid == self.uuid
]
@classmethod
def create(
cls,
credential_id: bytes,
user: UUID | User,
aaguid: UUID,
public_key: bytes,
sign_count: int,
created_at: datetime | None = None,
) -> Credential:
"""Create a new Credential with auto-generated uuid7."""
user_uuid = user if isinstance(user, UUID) else user.uuid
now = created_at or datetime.now(UTC)
cred = cls(
credential_id=credential_id,
user_uuid=user_uuid,
aaguid=aaguid,
public_key=public_key,
sign_count=sign_count,
created_at=now,
last_used=now,
last_verified=now,
)
cred.uuid = uuid7.create(now)
return cred
class Session(msgspec.Struct, dict=True):
"""Session data structure.
Mutable fields: expiry (updated on session refresh)
Immutable fields: user_uuid, credential_uuid, host, ip, user_agent
key is stored in the dict key, not in the struct.
"""
user_uuid: UUID = msgspec.field(name="user")
credential_uuid: UUID = msgspec.field(name="credential")
host: str
ip: str
user_agent: str
expiry: datetime
def __post_init__(self):
if not hasattr(self, "key"):
self.key: str = ""
@property
def user(self) -> User:
"""Get the User object for this session."""
return db.data().users[self.user_uuid]
@property
def credential(self) -> Credential:
"""Get the Credential object for this session."""
return db.data().credentials[self.credential_uuid]
def metadata(self) -> dict:
"""Return session metadata for backwards compatibility."""
return {
"ip": self.ip,
"user_agent": self.user_agent,
"expiry": self.expiry.isoformat(),
}
@classmethod
def create(
cls,
user: UUID | User,
credential: UUID | Credential,
host: str,
ip: str,
user_agent: str,
expiry: datetime,
) -> Session:
"""Create a new Session with auto-generated key."""
user_uuid = user if isinstance(user, UUID) else user.uuid
credential_uuid = (
credential if isinstance(credential, UUID) else credential.uuid
)
session = cls(
user_uuid=user_uuid,
credential_uuid=credential_uuid,
host=host,
ip=ip,
user_agent=user_agent,
expiry=expiry,
)
session.key = secrets.token_urlsafe(12)
return session
class ResetToken(msgspec.Struct, dict=True):
"""Reset/device-addition token data structure.
Immutable fields: All fields (tokens are created and deleted, never modified)
key is stored in the dict key, not in the struct.
"""
user_uuid: UUID = msgspec.field(name="user")
expiry: datetime
token_type: str
def __post_init__(self):
if not hasattr(self, "key"):
self.key: bytes = b""
@property
def user(self) -> User:
"""Get the User object for this reset token."""
return db.data().users[self.user_uuid]
class SessionContext(msgspec.Struct):
session: Session
user: User
org: Org
role: Role
credential: Credential
permissions: list[Permission] = []
# -------------------------------------------------------------------------
# Database storage structure
# -------------------------------------------------------------------------
class DB(msgspec.Struct, dict=True, omit_defaults=False):
"""In-memory database. Access fields directly for reads."""
permissions: dict[UUID, Permission] = {}
orgs: dict[UUID, Org] = {}
roles: dict[UUID, Role] = {}
users: dict[UUID, User] = {}
credentials: dict[UUID, Credential] = {}
sessions: dict[str, Session] = {}
reset_tokens: dict[bytes, ResetToken] = {}
def __post_init__(self):
# Store reference for persistence (not serialized)
self._store = None
# Set the key fields on all stored objects
for uuid, perm in self.permissions.items():
perm.uuid = uuid
for uuid, org in self.orgs.items():
org.uuid = uuid
for uuid, role in self.roles.items():
role.uuid = uuid
for uuid, user in self.users.items():
user.uuid = uuid
for uuid, cred in self.credentials.items():
cred.uuid = uuid
for key, session in self.sessions.items():
session.key = key
for key, token in self.reset_tokens.items():
token.key = key
def transaction(self, action, ctx=None, *, user=None):
"""Wrap writes in transaction. Delegates to JsonlStore."""
return self._store.transaction(action, ctx, user=user)
def session_ctx(
self, session_key: str, host: str | None = None
) -> SessionContext | None:
"""Get full session context with effective permissions.
Args:
session_key: The session key string
host: Optional host for binding/validation and domain-scoped permissions
Returns:
SessionContext if valid, None if session not found, expired, or host mismatch
"""
try:
s = self.sessions[session_key]
except KeyError:
return None
# Validate host matches (sessions are always created with a host)
if s.host != host:
# Session bound to different host
return None
try:
user = s.user
role = user.role
org = role.org
credential = s.credential
except KeyError:
return None
# Effective permissions: role's permissions that the org can grant
# Also filter by domain if host is provided
org_perm_uuids = {p.uuid for p in org.permissions}
normalized_host = normalize_host(host)
host_without_port = (
normalized_host.rsplit(":", 1)[0] if normalized_host else None
)
effective_perms = []
for perm_uuid in role.permission_set:
if perm_uuid not in org_perm_uuids:
continue
try:
p = self.permissions[perm_uuid]
except KeyError:
continue
# Check domain restriction
if p.domain is not None and p.domain != host_without_port:
continue
effective_perms.append(p)
return SessionContext(
session=s,
user=user,
org=org,
role=role,
credential=credential,
permissions=effective_perms,
)
+93 -186
View File
@@ -1,16 +1,31 @@
import argparse import argparse
import asyncio import asyncio
import ipaddress import json
import logging import logging
import os import os
from urllib.parse import urlparse from urllib.parse import urlparse
import uvicorn from fastapi_vue.hostutil import parse_endpoint
from uvicorn import Config, Server
from uvicorn import run as uvicorn_run
from paskia import globals as _globals
from paskia.bootstrap import bootstrap_if_needed
from paskia.config import PaskiaConfig
from paskia.db.background import flush
from paskia.fastapi import reset as reset_cmd
from paskia.util import startupbox
from paskia.util.hostutil import normalize_origin from paskia.util.hostutil import normalize_origin
DEFAULT_HOST = "localhost" DEFAULT_PORT = 4401
DEFAULT_SERVE_PORT = 4401
EPILOG = """\
Examples:
paskia # localhost:4401
paskia :8080 # All interfaces, port 8080
paskia unix:/tmp/paskia.sock
paskia reset [user] # Generate passkey reset link
"""
def is_subdomain(sub: str, domain: str) -> bool: def is_subdomain(sub: str, domain: str) -> bool:
@@ -34,80 +49,6 @@ def validate_auth_host(auth_host: str, rp_id: str) -> None:
) )
def parse_endpoint(
value: str | None, default_port: int
) -> tuple[str | None, int | None, str | None, bool]:
"""Parse an endpoint using stdlib (urllib.parse, ipaddress).
Returns (host, port, uds_path). If uds_path is not None, host/port are None.
Supported forms:
- host[:port]
- :port (uses default host)
- [ipv6][:port] (bracketed for port usage)
- ipv6 (unbracketed, no port allowed -> default port)
- unix:/path/to/socket.sock
- None -> defaults (localhost:4401)
Notes:
- For IPv6 with an explicit port you MUST use brackets (e.g. [::1]:8080)
- Unbracketed IPv6 like ::1 implies the default port.
"""
if not value:
return DEFAULT_HOST, default_port, None, False
# Port only (numeric) -> localhost:port
if value.isdigit():
try:
port_only = int(value)
except ValueError: # pragma: no cover (isdigit guards)
raise SystemExit(f"Invalid port '{value}'")
return DEFAULT_HOST, port_only, None, False
# Leading colon :port -> bind all interfaces (0.0.0.0 + ::)
if value.startswith(":") and value != ":":
port_part = value[1:]
if not port_part.isdigit():
raise SystemExit(f"Invalid port in '{value}'")
return None, int(port_part), None, True
# UNIX domain socket
if value.startswith("unix:"):
uds_path = value[5:] or None
if uds_path is None:
raise SystemExit("unix: path must not be empty")
return None, None, uds_path, False
# Unbracketed IPv6 (cannot safely contain a port) -> detect by multiple colons
if value.count(":") > 1 and not value.startswith("["):
try:
ipaddress.IPv6Address(value)
except ValueError as e: # pragma: no cover
raise SystemExit(f"Invalid IPv6 address '{value}': {e}")
return value, default_port, None, False
# Use urllib.parse for everything else (host[:port], :port, [ipv6][:port])
parsed = urlparse(f"//{value}") # // prefix lets urlparse treat it as netloc
host = parsed.hostname
port = parsed.port
# Host may be None if empty (e.g. ':5500')
if not host:
host = DEFAULT_HOST
if port is None:
port = default_port
# Validate IP literals (optional; hostname passes through)
try:
# Strip brackets if somehow present (urlparse removes them already)
ipaddress.ip_address(host)
except ValueError:
# Not an IP address -> treat as hostname; no action
pass
return host, port, None, False
def add_common_options(p: argparse.ArgumentParser) -> None: def add_common_options(p: argparse.ArgumentParser) -> None:
p.add_argument( p.add_argument(
"--rp-id", default="localhost", help="Relying Party ID (default: localhost)" "--rp-id", default="localhost", help="Relying Party ID (default: localhost)"
@@ -134,45 +75,44 @@ def main():
logging.basicConfig(level=logging.INFO, format="%(message)s", force=True) logging.basicConfig(level=logging.INFO, format="%(message)s", force=True)
parser = argparse.ArgumentParser( parser = argparse.ArgumentParser(
prog="paskia", description="Paskia authentication server" prog="paskia",
description="Paskia authentication server",
formatter_class=argparse.RawDescriptionHelpFormatter,
epilog=EPILOG,
) )
sub = parser.add_subparsers(dest="command", required=True)
# serve subcommand # Primary argument: either host:port or "reset" subcommand
serve = sub.add_parser( parser.add_argument(
"serve", help="Run the server (production style, no auto-reload)"
)
serve.add_argument(
"hostport", "hostport",
nargs="?", nargs="?",
help=( help=(
"Endpoint (default: localhost:4401). Forms: host[:port] | :port | " "Endpoint (default: localhost:4401). Forms: host[:port] | :port | "
"[ipv6][:port] | ipv6 | unix:/path.sock" "[ipv6][:port] | ipv6 | unix:/path.sock | 'reset' for credential reset"
), ),
) )
add_common_options(serve) parser.add_argument(
"reset_query",
# reset subcommand
reset = sub.add_parser(
"reset",
help=(
"Create a credential reset link for a user. Provide part of the display name or UUID. "
"If omitted, targets the master admin (first Administration role user in an auth:admin org)."
),
)
reset.add_argument(
"query",
nargs="?", nargs="?",
help="User UUID (full) or case-insensitive substring of display name. If omitted, master admin is used.", help="For 'reset' command: user UUID or substring of display name",
) )
add_common_options(reset) add_common_options(parser)
args = parser.parse_args() args = parser.parse_args()
if args.command == "serve": # Detect "reset" subcommand (first positional is "reset")
host, port, uds, all_ifaces = parse_endpoint(args.hostport, DEFAULT_SERVE_PORT) is_reset = args.hostport == "reset"
if is_reset:
endpoints = []
else: else:
host = port = uds = all_ifaces = None # type: ignore # Parse endpoint using fastapi_vue.hostutil
endpoints = parse_endpoint(args.hostport, DEFAULT_PORT)
# Extract host/port/uds from first endpoint for config display and site_url
ep = endpoints[0] if endpoints else {}
host = ep.get("host")
port = ep.get("port")
uds = ep.get("uds")
# Collect and normalize origins, handle auth_host # Collect and normalize origins, handle auth_host
origins = [normalize_origin(o) for o in (getattr(args, "origins", None) or [])] origins = [normalize_origin(o) for o in (getattr(args, "origins", None) or [])]
@@ -193,8 +133,13 @@ def main():
origins = [x for x in origins if not (x in seen or seen.add(x))] origins = [x for x in origins if not (x in seen or seen.add(x))]
# Compute site_url and site_path for reset links # Compute site_url and site_path for reset links
# Priority: auth_host > first origin with localhost > http://localhost:port # Priority: PASKIA_SITE_URL (explicit) > auth_host > first origin with localhost > http://localhost:port
if args.auth_host: explicit_site_url = os.environ.get("PASKIA_SITE_URL")
if explicit_site_url:
# Explicit site URL from devserver or deployment config
site_url = explicit_site_url.rstrip("/")
site_path = "/" if args.auth_host else "/auth/"
elif args.auth_host:
site_url = args.auth_host.rstrip("/") site_url = args.auth_host.rstrip("/")
site_path = "/" site_path = "/"
elif origins: elif origins:
@@ -215,8 +160,6 @@ def main():
site_path = "/auth/" site_path = "/auth/"
# Build runtime configuration # Build runtime configuration
from paskia.config import PaskiaConfig
config = PaskiaConfig( config = PaskiaConfig(
rp_id=args.rp_id, rp_id=args.rp_id,
rp_name=args.rp_name or None, rp_name=args.rp_name or None,
@@ -230,8 +173,6 @@ def main():
) )
# Export configuration via single JSON env variable for worker processes # Export configuration via single JSON env variable for worker processes
import json
config_json = { config_json = {
"rp_id": config.rp_id, "rp_id": config.rp_id,
"rp_name": config.rp_name, "rp_name": config.rp_name,
@@ -242,93 +183,59 @@ def main():
} }
os.environ["PASKIA_CONFIG"] = json.dumps(config_json) os.environ["PASKIA_CONFIG"] = json.dumps(config_json)
# Initialize globals (without bootstrap yet) startupbox.print_startup_config(config)
from paskia import globals as _globals # local import
asyncio.run( devmode = bool(os.environ.get("FASTAPI_VUE_FRONTEND_URL"))
_globals.init(
run_kwargs: dict = {
"log_level": "warning", # Suppress startup messages; we use custom logging
"access_log": False, # We use custom AccessLogMiddleware instead
}
if devmode:
# Security: dev mode must run on localhost:4402 to prevent
# accidental public exposure of the Vite dev server
if host != "localhost" or port != 4402:
raise SystemExit(f"Dev mode requires localhost:4402, got {host}:{port}")
run_kwargs["reload"] = True
run_kwargs["reload_dirs"] = ["paskia"]
async def async_main():
await _globals.init(
rp_id=config.rp_id, rp_id=config.rp_id,
rp_name=config.rp_name, rp_name=config.rp_name,
origins=config.origins, origins=config.origins,
bootstrap=False, bootstrap=False,
) )
) await bootstrap_if_needed()
await flush()
# Print startup configuration if is_reset:
from paskia.util import startupbox exit_code = reset_cmd.run(args.reset_query)
raise SystemExit(exit_code)
startupbox.print_startup_config(config) if len(endpoints) > 1:
async with asyncio.TaskGroup() as tg:
# Bootstrap after startup box is printed for ep in endpoints:
from paskia.bootstrap import bootstrap_if_needed tg.create_task(
Server(
asyncio.run(bootstrap_if_needed()) Config(app="paskia.fastapi:app", **run_kwargs, **ep)
).serve()
# Handle recover-admin command (no server start) )
if args.command == "reset": elif devmode:
from paskia.fastapi import reset as reset_cmd # local import # Use uvicorn.run for proper reload support (it handles subprocess spawning)
ep = endpoints[0]
exit_code = reset_cmd.run(getattr(args, "query", None)) uvicorn_run("paskia.fastapi:app", **run_kwargs, **ep)
raise SystemExit(exit_code)
if args.command == "serve":
run_kwargs: dict = {
"log_level": "info",
}
# Dev mode: enable reload when PASKIA_DEVMODE is set
devmode = bool(os.environ.get("PASKIA_DEVMODE"))
if devmode:
# Security: dev mode must run on localhost:4402 to prevent
# accidental public exposure of the Vite dev server
if host != "localhost" or port != 4402:
raise SystemExit(f"Dev mode requires localhost:4402, got {host}:{port}")
run_kwargs["reload"] = True
run_kwargs["reload_dirs"] = ["paskia"]
# Suppress uvicorn startup messages in dev mode
run_kwargs["log_level"] = "warning"
if uds:
run_kwargs["uds"] = uds
else: else:
if not all_ifaces: server = Server(
run_kwargs["host"] = host Config(app="paskia.fastapi:app", **run_kwargs, **endpoints[0])
run_kwargs["port"] = port )
await server.serve()
if all_ifaces and not uds: try:
# Dev mode with all interfaces: use simple single-server approach asyncio.run(async_main())
if devmode: except KeyboardInterrupt:
run_kwargs["host"] = "::" pass
run_kwargs["port"] = port
uvicorn.run("paskia.fastapi:app", **run_kwargs)
else:
# Production: run separate servers for IPv4 and IPv6
from uvicorn import Config, Server # noqa: E402 local import
from paskia.fastapi import (
app as fastapi_app, # noqa: E402 local import
)
async def serve_both():
servers = []
assert port is not None
for h in ("0.0.0.0", "::"):
try:
cfg = Config(
app=fastapi_app,
host=h,
port=port,
log_level="info",
)
servers.append(Server(cfg))
except Exception as e: # pragma: no cover
logging.warning(f"Failed to configure server for {h}: {e}")
tasks = [asyncio.create_task(s.serve()) for s in servers]
await asyncio.gather(*tasks)
asyncio.run(serve_both())
else:
uvicorn.run("paskia.fastapi:app", **run_kwargs)
if __name__ == "__main__": if __name__ == "__main__":
+455 -396
View File
File diff suppressed because it is too large Load Diff
+84 -121
View File
@@ -1,6 +1,6 @@
import logging import logging
from contextlib import suppress from contextlib import suppress
from datetime import datetime, timedelta, timezone from datetime import UTC, datetime, timedelta
from fastapi import ( from fastapi import (
Depends, Depends,
@@ -13,23 +13,17 @@ from fastapi import (
from fastapi.responses import JSONResponse from fastapi.responses import JSONResponse
from fastapi.security import HTTPBearer from fastapi.security import HTTPBearer
from paskia.authsession import ( from paskia import db
EXPIRES, from paskia.authsession import EXPIRES, expires, get_reset
get_reset,
get_session,
refresh_session_token,
session_expiry,
)
from paskia.fastapi import authz, session, user from paskia.fastapi import authz, session, user
from paskia.fastapi.response import MsgspecResponse
from paskia.fastapi.session import AUTH_COOKIE, AUTH_COOKIE_NAME from paskia.fastapi.session import AUTH_COOKIE, AUTH_COOKIE_NAME
from paskia.globals import db
from paskia.globals import passkey as global_passkey from paskia.globals import passkey as global_passkey
from paskia.util import frontend, hostutil, htmlutil, passphrase, userinfo from paskia.util import hostutil, htmlutil, passphrase, userinfo, vitedev
from paskia.util.tokens import session_key
bearer_auth = HTTPBearer(auto_error=True) bearer_auth = HTTPBearer(auto_error=True)
app = FastAPI() app = FastAPI(docs_url=None, redoc_url=None, openapi_url=None)
app.mount("/user", user.app) app.mount("/user", user.app)
@@ -77,42 +71,40 @@ async def validate_token(
request: Request, request: Request,
response: Response, response: Response,
perm: list[str] = Query([]), perm: list[str] = Query([]),
max_age: str | None = Query(None),
auth=AUTH_COOKIE, auth=AUTH_COOKIE,
): ):
"""Validate the current session and extend its expiry. """Validate session and return context. Refreshes session expiry."""
Always refreshes the session (sliding expiration) and re-sets the cookie with a
renewed max-age. This keeps active users logged in without needing a separate
refresh endpoint.
"""
try: try:
ctx = await authz.verify(auth, perm, host=request.headers.get("host")) ctx = await authz.verify(
auth,
" ".join(perm).split(),
host=request.headers.get("host"),
max_age=max_age,
)
except HTTPException: except HTTPException:
# Global handler will clear cookie if 401 # Global handler will clear cookie if 401
raise raise
renewed = False renewed = False
if auth: if auth:
current_expiry = session_expiry(ctx.session) consumed = EXPIRES - (ctx.session.expiry - datetime.now(UTC))
consumed = EXPIRES - (current_expiry - datetime.now(timezone.utc))
if not timedelta(0) < consumed < _REFRESH_INTERVAL: if not timedelta(0) < consumed < _REFRESH_INTERVAL:
try: db.update_session(
await refresh_session_token( auth,
auth, ip=request.client.host if request.client else "",
ip=request.client.host if request.client else "", user_agent=request.headers.get("user-agent") or "",
user_agent=request.headers.get("user-agent") or "", expiry=expires(),
) ctx=ctx,
session.set_session_cookie(response, auth) )
renewed = True session.set_session_cookie(response, auth)
except ValueError: renewed = True
# Session disappeared, e.g. due to concurrent logout; global handler will clear return MsgspecResponse(
raise authz.AuthException( {
status_code=401, detail="Session expired", mode="login" "valid": True,
) "renewed": renewed,
return { "ctx": userinfo.build_session_context(ctx),
"valid": True, }
"user_uuid": str(ctx.session.user_uuid), )
"renewed": renewed,
}
@app.get("/forward") @app.get("/forward")
@@ -139,11 +131,15 @@ async def forward_authentication(
""" """
try: try:
ctx = await authz.verify( ctx = await authz.verify(
auth, perm, host=request.headers.get("host"), max_age=max_age auth,
" ".join(perm).split(),
host=request.headers.get("host"),
max_age=max_age,
)
# Build permission scopes for Remote-Groups header
role_permissions = (
{p.scope for p in ctx.permissions} if ctx.permissions else set()
) )
role_permissions = set(ctx.role.permissions or [])
if ctx.permissions:
role_permissions.update(permission.id for permission in ctx.permissions)
remote_headers: dict[str, str] = { remote_headers: dict[str, str] = {
"Remote-User": str(ctx.user.uuid), "Remote-User": str(ctx.user.uuid),
@@ -154,17 +150,13 @@ async def forward_authentication(
"Remote-Role": str(ctx.role.uuid), "Remote-Role": str(ctx.role.uuid),
"Remote-Role-Name": ctx.role.display_name, "Remote-Role-Name": ctx.role.display_name,
"Remote-Session-Expires": ( "Remote-Session-Expires": (
session_expiry(ctx.session) ctx.session.expiry.astimezone(UTC).isoformat().replace("+00:00", "Z")
.astimezone(timezone.utc) if ctx.session.expiry.tzinfo
.isoformat() else ctx.session.expiry.replace(tzinfo=UTC)
.replace("+00:00", "Z")
if session_expiry(ctx.session).tzinfo
else session_expiry(ctx.session)
.replace(tzinfo=timezone.utc)
.isoformat() .isoformat()
.replace("+00:00", "Z") .replace("+00:00", "Z")
), ),
"Remote-Credential": str(ctx.session.credential_uuid), "Remote-Credential": str(ctx.session.credential),
} }
return Response(status_code=204, headers=remote_headers) return Response(status_code=204, headers=remote_headers)
except authz.AuthException as e: except authz.AuthException as e:
@@ -179,7 +171,7 @@ async def forward_authentication(
if wants_html: if wants_html:
# Browser request - return full-page HTML with metadata # Browser request - return full-page HTML with metadata
data_attrs = {"mode": e.mode, **e.metadata} data_attrs = {"mode": e.mode, **e.metadata}
html = (await frontend.read("/int/forward/index.html"))[0] html = (await vitedev.read("/int/forward/index.html"))[0]
html = htmlutil.patch_html_data_attrs(html, **data_attrs) html = htmlutil.patch_html_data_attrs(html, **data_attrs)
return Response( return Response(
html, status_code=e.status_code, media_type="text/html; charset=UTF-8" html, status_code=e.status_code, media_type="text/html; charset=UTF-8"
@@ -206,92 +198,61 @@ async def get_settings():
} }
@app.get("/token-info")
async def api_token_info(token: str):
"""Get information about a reset token.
Returns:
- type: "reset"
- user_name: display name of the user
- token_type: type of reset token
"""
if not passphrase.is_well_formed(token):
raise HTTPException(status_code=404, detail="Invalid token")
# Check if this is a reset token
try:
reset_token = await get_reset(token)
user = await db.instance.get_user_by_uuid(reset_token.user_uuid)
return {
"type": "reset",
"user_name": user.display_name,
"token_type": reset_token.token_type,
}
except (ValueError, Exception):
raise HTTPException(status_code=404, detail="Token not found or expired")
@app.post("/user-info") @app.post("/user-info")
async def api_user_info( async def api_user_info(
request: Request, request: Request,
response: Response, response: Response,
reset: str | None = None,
auth=AUTH_COOKIE, auth=AUTH_COOKIE,
): ):
"""Get user information including credentials, sessions, and permissions. """Get full user profile including credentials and sessions."""
if auth is None:
raise authz.AuthException(
status_code=401,
detail="Authentication required",
mode="login",
)
ctx = db.data().session_ctx(auth, request.headers.get("host"))
if not ctx:
raise HTTPException(401, "Session expired")
Can be called with either: return MsgspecResponse(
- A session cookie (auth) for authenticated users await userinfo.build_user_info(
- A reset token for users in password reset flow user_uuid=ctx.user.uuid,
""" auth=auth,
authenticated = False session_record=ctx.session,
session_record = None request_host=request.headers.get("host"),
reset_token = None )
)
@app.get("/token-info")
async def token_info(credentials=Depends(bearer_auth)):
"""Get reset/device-add token info. Pass token via Bearer header."""
token = credentials.credentials
if not passphrase.is_well_formed(token):
raise HTTPException(400, "Invalid token format")
try: try:
if reset: reset_token = get_reset(token)
if not passphrase.is_well_formed(reset):
raise ValueError("Invalid reset token")
reset_token = await get_reset(reset)
target_user_uuid = reset_token.user_uuid
else:
if auth is None:
raise authz.AuthException(
status_code=401,
detail="Authentication required",
mode="login",
)
session_record = await get_session(auth, host=request.headers.get("host"))
authenticated = True
target_user_uuid = session_record.user_uuid
except ValueError as e: except ValueError as e:
raise HTTPException(401, str(e)) raise HTTPException(401, str(e))
# Return minimal response for reset tokens u = reset_token.user
if not authenticated and reset_token: return {
return await userinfo.format_reset_user_info(target_user_uuid, reset_token) "token_type": reset_token.token_type,
"display_name": u.display_name,
# Return full user info for authenticated users }
assert auth is not None
assert session_record is not None
return await userinfo.format_user_info(
user_uuid=target_user_uuid,
auth=auth,
session_record=session_record,
request_host=request.headers.get("host"),
)
@app.post("/logout") @app.post("/logout")
async def api_logout(request: Request, response: Response, auth=AUTH_COOKIE): async def api_logout(request: Request, response: Response, auth=AUTH_COOKIE):
if not auth: if not auth:
return {"message": "Already logged out"} return {"message": "Already logged out"}
try: host = request.headers.get("host")
await get_session(auth, host=request.headers.get("host")) ctx = db.data().session_ctx(auth, host)
except ValueError: if not ctx:
return {"message": "Already logged out"} return {"message": "Already logged out"}
with suppress(Exception): with suppress(Exception):
await db.instance.delete_session(session_key(auth)) db.delete_session(auth, ctx=ctx, action="logout")
session.clear_session_cookie(response) session.clear_session_cookie(response)
return {"message": "Logged out successfully"} return {"message": "Logged out successfully"}
@@ -300,9 +261,11 @@ async def api_logout(request: Request, response: Response, auth=AUTH_COOKIE):
async def api_set_session( async def api_set_session(
request: Request, response: Response, auth=Depends(bearer_auth) request: Request, response: Response, auth=Depends(bearer_auth)
): ):
user = await get_session(auth.credentials, host=request.headers.get("host")) ctx = db.data().session_ctx(auth.credentials, request.headers.get("host"))
if not ctx:
raise HTTPException(401, "Session expired")
session.set_session_cookie(response, auth.credentials) session.set_session_cookie(response, auth.credentials)
return { return {
"message": "Session cookie set successfully", "message": "Session cookie set successfully",
"user_uuid": str(user.user_uuid), "user": str(ctx.user.uuid),
} }
+17 -10
View File
@@ -2,6 +2,7 @@ import logging
from fastapi import HTTPException from fastapi import HTTPException
from paskia.fastapi.logging import log_permission_denied
from paskia.util import permutil, sessionutil from paskia.util import permutil, sessionutil
logger = logging.getLogger(__name__) logger = logging.getLogger(__name__)
@@ -79,6 +80,9 @@ async def verify(
mode="login", mode="login",
clear_session=True, clear_session=True,
) )
# User's theme preference for iframe (only if explicitly set)
user_theme = ctx.user.theme if ctx.user.theme else None
# Check max_age requirement if specified # Check max_age requirement if specified
if max_age: if max_age:
try: try:
@@ -87,24 +91,27 @@ async def verify(
status_code=401, status_code=401,
detail="Additional authentication required", detail="Additional authentication required",
mode="reauth", mode="reauth",
theme=user_theme,
) )
except ValueError as e: except ValueError as e:
# Invalid max_age format - log but don't fail the request # Invalid max_age format - log but don't fail the request
logger.warning(f"Invalid max_age format '{max_age}': {e}") logger.warning(f"Invalid max_age format '{max_age}': {e}")
if not match(ctx, perm): if not match(ctx, perm):
# Determine which permissions are missing for clearer diagnostics effective_scopes = (
missing = sorted(set(perm) - set(ctx.role.permissions)) {p.scope for p in (ctx.permissions or [])}
logger.warning( if ctx.permissions
"Permission denied: user=%s role=%s missing=%s required=%s granted=%s", # noqa: E501 else set(ctx.role.permissions or [])
getattr(ctx.user, "uuid", "?"), )
getattr(ctx.role, "display_name", "?"), missing = sorted(set(perm) - effective_scopes)
missing, log_permission_denied(
perm, ctx, perm, missing, require_all=(match == permutil.has_all)
ctx.role.permissions,
) )
raise AuthException( raise AuthException(
status_code=403, mode="forbidden", detail="Permission required" status_code=403,
mode="forbidden",
detail="Permission required",
theme=user_theme,
) )
return ctx return ctx
+261
View File
@@ -0,0 +1,261 @@
"""Custom access logging middleware for FastAPI/Uvicorn."""
import logging
import sys
import time
from ipaddress import IPv6Address
from typing import TYPE_CHECKING
from starlette.middleware.base import BaseHTTPMiddleware
if TYPE_CHECKING:
from paskia.db.structs import SessionContext
from starlette.requests import Request
from starlette.responses import Response
logger = logging.getLogger("paskia.access")
_RESET = "\033[0m"
_STATUS_INFO = "\033[32m" # 1xx (green)
_STATUS_OK = "\033[1;92m" # 2xx (bright green)
_STATUS_REDIRECT = "\033[32m" # 3xx (green)
_STATUS_CLIENT_ERR = "\033[0;31m" # 4xx (red)
_STATUS_SERVER_ERR = "\033[1;91m" # 5xx (bold bright red)
_METHOD_READ = "\033[0;34m" # GET, HEAD, OPTIONS (blue)
_METHOD_WRITE = "\033[1;94m" # POST, PUT, DELETE, PATCH (bold bright blue)
_HOST = "\033[38;5;242m" # hostname (dark grey)
_PATH = "\033[38;5;250m" # path (white)
_TIMING = "\033[38;5;242m" # timing/devmode (dark grey)
_WS_OPEN = "\033[1;93m" # WebSocket connect (bold bright yellow)
_WS_CLOSE = "\033[33m" # WebSocket disconnect (yellow)
_WS_STATUS = "\033[38;5;242m" # WebSocket close status (dark grey)
_AUTHZ_DENIED = "\033[0;31m" # Permission denied (red)
_AUTHZ_USER = "\033[1;34m" # User info (light blue)
_AUTHZ_ORG = "\033[34m" # User info (blue)
_AUTHZ_NEEDS = "\033[1;38;5;231m" # Needs (brightest white)
_AUTHZ_MISSING = "\033[1;31m" # Missing scope (bold red)
_AUTHZ_GRANTED = "\033[0;32m" # Granted scope (green)
def format_ipv6_network(ip: str) -> str:
"""Format IPv6 address to show only network part (first 64 bits)."""
try:
addr = IPv6Address(ip)
# Get the integer representation and mask to first 64 bits
network_int = int(addr) >> 64
# Format as IPv6 with trailing ::
# Split into 4 groups of 16 bits
groups = []
for _ in range(4):
groups.insert(0, format(network_int & 0xFFFF, "x"))
network_int >>= 16
# Compress consecutive zero groups
result = ":".join(groups) + "::"
# Simplify leading zeros in groups and compress, then strip trailing ::
return str(IPv6Address(result + "0")).removesuffix("::")
except Exception:
return ip
def format_client_ip(ip: str) -> str:
"""Format client IP, compressing IPv6 to network part only."""
if not ip or ip == "-":
return "-"
if ":" in ip:
return format_ipv6_network(ip)
return ip
def status_color(status: int) -> str:
"""Return color code based on HTTP status."""
if status < 200:
return _STATUS_INFO
if status < 300:
return _STATUS_OK
if status < 400:
return _STATUS_REDIRECT
if status < 500:
return _STATUS_CLIENT_ERR
return _STATUS_SERVER_ERR
def method_color(method: str) -> str:
"""Return color code based on HTTP method."""
if method in ("GET", "HEAD", "OPTIONS"):
return _METHOD_READ
return _METHOD_WRITE
def format_access_log(
client: str, status: int, method: str, host: str, path: str, duration_ms: float
) -> str:
"""Format access log line with colors and aligned fields."""
use_color = sys.stderr.isatty()
# Format components with fixed widths for alignment
ip = format_client_ip(client).ljust(19) # IPv6 network max 19 chars
timing = f"{duration_ms:.0f}ms"
method_padded = method.ljust(7) # Longest method is OPTIONS (7)
if use_color:
status_str = f"{status_color(status)}{status}{_RESET}"
timing_str = f"{_TIMING}{timing}{_RESET}"
method_str = f"{method_color(method)}{method_padded}{_RESET}"
host_str = f"{_HOST}{host}{_RESET}"
path_str = f"{_PATH}{path}{_RESET}"
else:
status_str = str(status)
timing_str = timing
method_str = method_padded
host_str = host
path_str = path
# Format: "IP STATUS METHOD host path TIMING"
return f"{ip} {status_str} {method_str} {host_str}{path_str} {timing_str}"
# WebSocket connection counter (mod 100)
_ws_counter = 0
def _next_ws_id() -> int:
"""Get next WebSocket connection ID (0-99)."""
global _ws_counter
ws_id = _ws_counter
_ws_counter = (_ws_counter + 1) % 100
return ws_id
def log_ws_open(ws) -> int:
"""Log WebSocket connection open. Returns connection ID for use in close."""
use_color = sys.stderr.isatty()
ws_id = _next_ws_id()
client = ws.client.host if ws.client else "-"
host = ws.headers.get("host", "-")
path = ws.url.path
origin = ws.headers.get("origin")
ip = format_client_ip(client).ljust(19)
id_str = f"{ws_id:02d}".ljust(7) # Align with method field (7 chars)
# Determine if origin should be shown (omit when same as host)
# Origin header includes scheme (e.g., "https://example.com"), compare host part
origin_host = origin.split("://", 1)[-1] if origin else None
show_origin = origin_host and origin_host != host
if use_color:
# 🔌 aligned with status (takes ~2 char width), ID aligned with method
prefix = f"🔌 {_WS_OPEN}{id_str}{_RESET}"
host_str = f"{_HOST}{host}{_RESET}"
path_str = f"{_PATH}{path}{_RESET}"
origin_str = (
f" {_RESET}from {_HOST}{origin_host}{_RESET}" if show_origin else ""
)
else:
prefix = f"WS+ {id_str}"
host_str = host
path_str = path
origin_str = f" from {origin_host}" if show_origin else ""
logger.info(f"{ip} {prefix} {host_str}{path_str}{origin_str}")
return ws_id
# WebSocket close codes to human-readable status
WS_CLOSE_CODES = {
1000: "ok",
1001: "going away",
1002: "protocol error",
1003: "unsupported",
1005: "no status",
1006: "abnormal",
1007: "invalid data",
1008: "policy violation",
1009: "too large",
1010: "extension required",
1011: "server error",
1012: "restarting",
1013: "try again",
1014: "bad gateway",
1015: "tls error",
}
def log_ws_close(ws_id: int, close_code: int | None, duration: float) -> None:
"""Log WebSocket connection close with duration and status."""
use_color = sys.stderr.isatty()
id_str = f"{ws_id:02d}".ljust(7) # Align with method field (7 chars)
timing = f"{duration * 1000:.0f}ms"
# Convert close code to status text
if close_code is None:
status = "closed"
else:
status = WS_CLOSE_CODES.get(close_code, f"code {close_code}")
if use_color:
# 🔌 aligned with status, ID aligned with method
prefix = f"🔌 {_WS_CLOSE}{id_str}{_RESET}"
status_str = f"{_WS_STATUS}{status}{_RESET}"
timing_str = f"{_TIMING}{timing}{_RESET}"
else:
prefix = f"WS- {id_str}"
status_str = status
timing_str = timing
logger.info(f"{' ' * 19} {prefix} {status_str} {timing_str}")
def log_permission_denied(
ctx: "SessionContext", required: list[str], missing: list[str], *, require_all: bool
) -> None:
"""Log permission denied with org, role, user and highlighted missing scopes."""
missing_set = set(missing)
scopes = " ".join(
f"{_AUTHZ_MISSING}{s}{_RESET}"
if s in missing_set
else f"{_AUTHZ_GRANTED}{s}{_RESET}"
for s in required
)
n = "" if len(required) == 1 else " all" if require_all else " any"
logger.warning(
f"{_AUTHZ_DENIED}Permission denied{_RESET} "
f"{_AUTHZ_USER}{ctx.user.display_name}{_RESET} "
f"{_AUTHZ_ORG}({ctx.org.display_name} {ctx.role.display_name}){_RESET} "
f"{_AUTHZ_NEEDS}needs{n}:{_RESET} {scopes}"
)
class AccessLogMiddleware(BaseHTTPMiddleware):
"""Middleware that logs HTTP requests with custom format."""
async def dispatch(self, request: Request, call_next) -> Response:
start = time.perf_counter()
response = await call_next(request)
duration_ms = (time.perf_counter() - start) * 1000
client = request.client.host if request.client else "-"
host = request.headers.get("host", "-")
method = request.method
path = request.url.path
if request.url.query:
path = f"{path}?{request.url.query}"
status = response.status_code
line = format_access_log(client, status, method, host, path, duration_ms)
logger.info(line)
return response
def configure_access_logging():
"""Configure the access logger to output to stderr."""
handler = logging.StreamHandler(sys.stderr)
handler.setFormatter(logging.Formatter("%(message)s"))
logger.addHandler(handler)
logger.setLevel(logging.INFO)
logger.propagate = False
# Suppress watchfiles "X changes detected" INFO messages (keep WARNING for reload notification)
logging.getLogger("watchfiles.main").setLevel(logging.WARNING)
+47 -22
View File
@@ -1,3 +1,4 @@
import json
import logging import logging
import os import os
from contextlib import asynccontextmanager from contextlib import asynccontextmanager
@@ -5,11 +6,29 @@ from pathlib import Path
from fastapi import FastAPI, HTTPException, Request, Response from fastapi import FastAPI, HTTPException, Request, Response
from fastapi.responses import FileResponse, RedirectResponse from fastapi.responses import FileResponse, RedirectResponse
from fastapi.staticfiles import StaticFiles from fastapi_vue import Frontend
from paskia import globals
from paskia.db import start_background, stop_background
from paskia.db.logging import configure_db_logging
from paskia.fastapi import admin, api, auth_host, ws from paskia.fastapi import admin, api, auth_host, ws
from paskia.fastapi.logging import AccessLogMiddleware, configure_access_logging
from paskia.fastapi.session import AUTH_COOKIE from paskia.fastapi.session import AUTH_COOKIE
from paskia.util import frontend, hostutil, passphrase from paskia.util import hostutil, passphrase, vitedev
# Configure custom logging
configure_access_logging()
configure_db_logging()
_access_logger = logging.getLogger("paskia.access")
# Vue Frontend static files
frontend = Frontend(
Path(__file__).parent.parent / "frontend-build",
cached=["/auth/assets/"],
favicon="/paskia.webp",
)
# Path to examples/index.html when running from source tree # Path to examples/index.html when running from source tree
_EXAMPLES_DIR = Path(__file__).parent.parent.parent / "examples" _EXAMPLES_DIR = Path(__file__).parent.parent.parent / "examples"
@@ -23,10 +42,6 @@ async def lifespan(app: FastAPI): # pragma: no cover - startup path
so that uvicorn reload / multiprocess workers inherit the settings. so that uvicorn reload / multiprocess workers inherit the settings.
All keys are guaranteed to exist; values are already normalized by __main__.py. All keys are guaranteed to exist; values are already normalized by __main__.py.
""" """
import json
from paskia import globals
config = json.loads(os.environ["PASKIA_CONFIG"]) config = json.loads(os.environ["PASKIA_CONFIG"])
try: try:
@@ -42,15 +57,27 @@ async def lifespan(app: FastAPI): # pragma: no cover - startup path
# Re-raise to fail fast # Re-raise to fail fast
raise raise
# Restore info level logging after startup (suppressed during uvicorn init in dev mode) # Restore uvicorn info logging (suppressed during startup in dev mode)
if frontend.is_dev_mode(): # Keep uvicorn.error at WARNING to suppress WebSocket "connection open/closed" messages
if frontend.devmode:
logging.getLogger("uvicorn").setLevel(logging.INFO) logging.getLogger("uvicorn").setLevel(logging.INFO)
logging.getLogger("uvicorn.access").setLevel(logging.INFO) logging.getLogger("uvicorn.error").setLevel(logging.WARNING)
await frontend.load()
await start_background()
yield yield
await stop_background()
app = FastAPI(lifespan=lifespan) app = FastAPI(
lifespan=lifespan,
redirect_slashes=False,
docs_url=None,
redoc_url=None,
openapi_url=None,
)
# Custom access logging (uvicorn's access_log is disabled)
app.add_middleware(AccessLogMiddleware)
# Apply redirections to auth-host if configured (deny access to restricted endpoints, remove /auth/) # Apply redirections to auth-host if configured (deny access to restricted endpoints, remove /auth/)
app.middleware("http")(auth_host.redirect_middleware) app.middleware("http")(auth_host.redirect_middleware)
@@ -59,19 +86,11 @@ app.mount("/auth/api/admin/", admin.app)
app.mount("/auth/api/", api.app) app.mount("/auth/api/", api.app)
app.mount("/auth/ws/", ws.app) app.mount("/auth/ws/", ws.app)
# In dev mode (PASKIA_DEVMODE=1), Vite serves assets directly; skip static files mount
if not frontend.is_dev_mode():
app.mount(
"/auth/assets/",
StaticFiles(directory=frontend.file("auth", "assets")),
name="assets",
)
@app.get("/auth/restricted/") @app.get("/auth/restricted/")
async def restricted_view(): async def restricted_view():
"""Serve the restricted/authentication UI for iframe embedding.""" """Serve the restricted/authentication UI for iframe embedding."""
return Response(*await frontend.read("/auth/restricted/index.html")) return Response(*await vitedev.read("/auth/restricted/index.html"))
# Navigable URLs are defined here. We support both / and /auth/ as the base path # Navigable URLs are defined here. We support both / and /auth/ as the base path
@@ -86,7 +105,7 @@ async def frontapp(request: Request, response: Response, auth=AUTH_COOKIE):
The frontend handles mode detection (host mode vs full profile) based on settings. The frontend handles mode detection (host mode vs full profile) based on settings.
Access control is handled via APIs. Access control is handled via APIs.
""" """
return Response(*await frontend.read("/auth/index.html")) return Response(*await vitedev.read("/auth/index.html"))
@app.get("/admin", include_in_schema=False) @app.get("/admin", include_in_schema=False)
@@ -96,6 +115,7 @@ async def admin_root_redirect():
@app.get("/admin/", include_in_schema=False) @app.get("/admin/", include_in_schema=False)
@app.get("/auth/admin/", include_in_schema=False)
async def admin_root(request: Request, auth=AUTH_COOKIE): async def admin_root(request: Request, auth=AUTH_COOKIE):
return await admin.adminapp(request, auth) # Delegated to admin app return await admin.adminapp(request, auth) # Delegated to admin app
@@ -116,6 +136,11 @@ async def examples_page():
return FileResponse(index_file, media_type="text/html") return FileResponse(index_file, media_type="text/html")
# Frontend static files - must be before /{token} catch-all routes
# (actual routes registered during lifespan after frontend.load())
frontend.route(app, "/")
# Note: this catch-all handler must be the last route defined # Note: this catch-all handler must be the last route defined
@app.get("/{token}") @app.get("/{token}")
@app.get("/auth/{token}") @app.get("/auth/{token}")
@@ -127,4 +152,4 @@ async def token_link(token: str):
if not passphrase.is_well_formed(token): if not passphrase.is_well_formed(token):
raise HTTPException(status_code=404) raise HTTPException(status_code=404)
return Response(*await frontend.read("/int/reset/index.html")) return Response(*await vitedev.read("/int/reset/index.html"))
+18 -67
View File
@@ -15,15 +15,15 @@ from uuid import UUID
import base64url import base64url
from fastapi import FastAPI, WebSocket, WebSocketDisconnect from fastapi import FastAPI, WebSocket, WebSocketDisconnect
from paskia import remoteauth from paskia import db, remoteauth
from paskia.authsession import create_session from paskia.authsession import expires
from paskia.fastapi.session import infodict from paskia.fastapi.session import AUTH_COOKIE, infodict
from paskia.fastapi.wschat import authenticate_and_login
from paskia.fastapi.wsutil import validate_origin, websocket_error_handler from paskia.fastapi.wsutil import validate_origin, websocket_error_handler
from paskia.globals import db, passkey from paskia.util import passphrase, pow, useragent
from paskia.util import passphrase, pow
# Create a FastAPI subapp for remote auth WebSocket endpoints # Create a FastAPI subapp for remote auth WebSocket endpoints
app = FastAPI() app = FastAPI(docs_url=None, redoc_url=None, openapi_url=None)
@app.websocket("/request") @app.websocket("/request")
@@ -180,7 +180,7 @@ async def websocket_remote_auth_request(ws: WebSocket):
): ):
response = { response = {
"status": "authenticated", "status": "authenticated",
"user_uuid": str(result_data["user_uuid"]), "user": str(result_data["user_uuid"]),
} }
if result_data.get("session_token"): if result_data.get("session_token"):
response["session_token"] = result_data["session_token"] response["session_token"] = result_data["session_token"]
@@ -252,7 +252,7 @@ async def websocket_remote_auth_request(ws: WebSocket):
@app.websocket("/permit") @app.websocket("/permit")
@websocket_error_handler @websocket_error_handler
async def websocket_remote_auth_permit(ws: WebSocket): async def websocket_remote_auth_permit(ws: WebSocket, auth=AUTH_COOKIE):
"""Complete a remote authentication request using a 3-word pairing code. """Complete a remote authentication request using a 3-word pairing code.
This endpoint is called from the user's profile on the authenticating device. This endpoint is called from the user's profile on the authenticating device.
@@ -269,9 +269,8 @@ async def websocket_remote_auth_permit(ws: WebSocket):
6. Client sends WebAuthn response 6. Client sends WebAuthn response
7. Server sends {status: "success", message: "..."} 7. Server sends {status: "success", message: "..."}
""" """
from paskia.util import useragent
origin = validate_origin(ws) validate_origin(ws)
if remoteauth.instance is None: if remoteauth.instance is None:
raise ValueError("Remote authentication is not available") raise ValueError("Remote authentication is not available")
@@ -290,7 +289,6 @@ async def websocket_remote_auth_permit(ws: WebSocket):
) )
request = None request = None
webauthn_challenge = None
explicitly_denied = False explicitly_denied = False
try: try:
@@ -312,78 +310,31 @@ async def websocket_remote_auth_permit(ws: WebSocket):
# Handle authenticate request (no PoW needed - already validated during lookup) # Handle authenticate request (no PoW needed - already validated during lookup)
if msg.get("authenticate") and request is not None: if msg.get("authenticate") and request is not None:
# Generate authentication options ctx = await authenticate_and_login(ws, auth)
options, webauthn_challenge = passkey.instance.auth_generate_options(
credential_ids=None
)
await ws.send_json({"optionsJSON": options})
# Wait for WebAuthn response session_token = ctx.session.key
credential = passkey.instance.auth_parse(await ws.receive_json())
# Fetch and verify credential
try:
stored_cred = await db.instance.get_credential_by_id(
credential.raw_id
)
except ValueError:
raise ValueError(
f"This passkey is no longer registered with {passkey.instance.rp_name}"
)
# Verify the credential
passkey.instance.auth_verify(
credential, webauthn_challenge, stored_cred, origin
)
# Update credential last_used
await db.instance.login(stored_cred.user_uuid, stored_cred)
# Create a session for the REQUESTING device
assert stored_cred.uuid is not None
session_token = None
reset_token = None reset_token = None
if request.action == "register": if request.action == "register":
# For registration, create a reset token for device addition # For registration, create a reset token for device addition
from paskia.authsession import expires
from paskia.util import tokens
token_str = passphrase.generate() token_str = passphrase.generate()
expiry = expires() expiry = expires()
await db.instance.create_reset_token( db.create_reset_token(
user_uuid=stored_cred.user_uuid, user_uuid=ctx.user.uuid,
key=tokens.reset_key(token_str), passphrase=token_str,
expiry=expiry, expiry=expiry,
token_type="device addition", token_type="device addition",
user=str(ctx.user.uuid),
) )
reset_token = token_str reset_token = token_str
# Also create a session so the device is logged in?
# User requested: "We can make the flow always create a new session, but make additional tokens for other possibilities."
session_token = await create_session(
user_uuid=stored_cred.user_uuid,
credential_uuid=stored_cred.uuid,
host=request.host,
ip=request.ip,
user_agent=request.user_agent,
)
else:
# Default login action
session_token = await create_session(
user_uuid=stored_cred.user_uuid,
credential_uuid=stored_cred.uuid,
host=request.host,
ip=request.ip,
user_agent=request.user_agent,
)
# Complete the remote auth request (notifies the waiting device) # Complete the remote auth request (notifies the waiting device)
cred = db.data().credentials[ctx.session.credential_uuid]
completed = await remoteauth.instance.complete_request( completed = await remoteauth.instance.complete_request(
token=request.key, token=request.key,
session_token=session_token, session_token=session_token,
user_uuid=stored_cred.user_uuid, user_uuid=ctx.user.uuid,
credential_uuid=stored_cred.uuid, credential_uuid=cred.uuid,
reset_token=reset_token, reset_token=reset_token,
) )
+28 -21
View File
@@ -10,15 +10,12 @@ display name. If multiple users match, they are listed and the command
aborts. A new one-time reset link is always created. aborts. A new one-time reset link is always created.
""" """
from __future__ import annotations
import asyncio import asyncio
from uuid import UUID from uuid import UUID
from paskia import authsession as _authsession from paskia import authsession as _authsession
from paskia import globals as _g from paskia import db
from paskia.util import hostutil, passphrase from paskia.util import hostutil, passphrase
from paskia.util import tokens as _tokens
async def _resolve_targets(query: str | None): async def _resolve_targets(query: str | None):
@@ -27,23 +24,30 @@ async def _resolve_targets(query: str | None):
targets: list[tuple] = [] targets: list[tuple] = []
try: try:
q_uuid = UUID(query) q_uuid = UUID(query)
perm_orgs = await _g.db.instance.get_permission_organizations("auth:admin") p = next(
for o in perm_orgs: (p for p in db.data().permissions.values() if p.scope == "auth:admin"),
users = await _g.db.instance.get_organization_users(str(o.uuid)) None,
for u, role_name in users: )
if u.uuid == q_uuid: if p:
return [(u, role_name)] for org_uuid in p.orgs:
users = db.get_organization_users(org_uuid)
for u, role_name in users:
if u.uuid == q_uuid:
return [(u, role_name)]
# UUID not found among admin orgs -> fall back to substring search (rare case) # UUID not found among admin orgs -> fall back to substring search (rare case)
except ValueError: except ValueError:
pass pass
# Substring search # Substring search
needle = query.lower() needle = query.lower()
perm_orgs = await _g.db.instance.get_permission_organizations("auth:admin") p = next(
for o in perm_orgs: (p for p in db.data().permissions.values() if p.scope == "auth:admin"), None
users = await _g.db.instance.get_organization_users(str(o.uuid)) )
for u, role_name in users: if p:
if needle in (u.display_name or "").lower(): for org_uuid in p.orgs:
targets.append((u, role_name)) users = db.get_organization_users(org_uuid)
for u, role_name in users:
if needle in (u.display_name or "").lower():
targets.append((u, role_name))
# De-duplicate # De-duplicate
seen = set() seen = set()
deduped = [] deduped = []
@@ -53,10 +57,13 @@ async def _resolve_targets(query: str | None):
deduped.append((u, role_name)) deduped.append((u, role_name))
return deduped return deduped
# No query -> master admin # No query -> master admin
perm_orgs = await _g.db.instance.get_permission_organizations("auth:admin") p = next(
if not perm_orgs: (p for p in db.data().permissions.values() if p.scope == "auth:admin"), None
)
if not p or not p.orgs:
return [] return []
users = await _g.db.instance.get_organization_users(str(perm_orgs[0].uuid)) first_org_uuid = next(iter(p.orgs))
users = db.get_organization_users(first_org_uuid)
admin_users = [pair for pair in users if pair[1] == "Administration"] admin_users = [pair for pair in users if pair[1] == "Administration"]
return admin_users[:1] return admin_users[:1]
@@ -64,9 +71,9 @@ async def _resolve_targets(query: str | None):
async def _create_reset(user, role_name: str): async def _create_reset(user, role_name: str):
token = passphrase.generate() token = passphrase.generate()
expiry = _authsession.reset_expires() expiry = _authsession.reset_expires()
await _g.db.instance.create_reset_token( db.create_reset_token(
passphrase=token,
user_uuid=user.uuid, user_uuid=user.uuid,
key=_tokens.reset_key(token),
expiry=expiry, expiry=expiry,
token_type="manual reset", token_type="manual reset",
) )
+22
View File
@@ -0,0 +1,22 @@
"""FastAPI response utilities for msgspec.Struct serialization."""
import msgspec
from fastapi import Response
class MsgspecResponse(Response):
"""Response that uses msgspec for JSON encoding.
Use this for returning msgspec.Struct, dict, or list with proper serialization.
"""
media_type = "application/json"
def __init__(
self,
content: msgspec.Struct | dict | list,
status_code: int = 200,
headers: dict | None = None,
):
body = msgspec.json.encode(content)
super().__init__(content=body, status_code=status_code, headers=headers)
+2 -2
View File
@@ -19,8 +19,8 @@ AUTH_COOKIE = Cookie(None, alias=AUTH_COOKIE_NAME)
def infodict(request: Request | WebSocket, type: str) -> dict: def infodict(request: Request | WebSocket, type: str) -> dict:
"""Extract client information from request.""" """Extract client information from request."""
return { return {
"ip": request.client.host if request.client else None, "ip": request.client.host if request.client else "",
"user_agent": request.headers.get("user-agent", "")[:500] or None, "user_agent": request.headers.get("user-agent", "")[:500],
"session_type": type, "session_type": type,
} }
+52 -44
View File
@@ -1,4 +1,4 @@
from datetime import timezone from datetime import UTC
from uuid import UUID from uuid import UUID
from fastapi import ( from fastapi import (
@@ -10,18 +10,16 @@ from fastapi import (
) )
from fastapi.responses import JSONResponse from fastapi.responses import JSONResponse
from paskia import db
from paskia.authsession import ( from paskia.authsession import (
delete_credential, delete_credential,
expires, expires,
get_session,
) )
from paskia.fastapi import authz, session from paskia.fastapi import authz, session
from paskia.fastapi.session import AUTH_COOKIE from paskia.fastapi.session import AUTH_COOKIE
from paskia.globals import db from paskia.util import hostutil, passphrase
from paskia.util import hostutil, passphrase, tokens
from paskia.util.tokens import decode_session_key, session_key
app = FastAPI() app = FastAPI(docs_url=None, redoc_url=None, openapi_url=None)
@app.exception_handler(authz.AuthException) @app.exception_handler(authz.AuthException)
@@ -33,7 +31,7 @@ async def auth_exception_handler(_request, exc: authz.AuthException):
) )
@app.put("/display-name") @app.patch("/display-name")
async def user_update_display_name( async def user_update_display_name(
request: Request, request: Request,
response: Response, response: Response,
@@ -44,18 +42,40 @@ async def user_update_display_name(
raise authz.AuthException( raise authz.AuthException(
status_code=401, detail="Authentication Required", mode="login" status_code=401, detail="Authentication Required", mode="login"
) )
try: host = request.headers.get("host")
s = await get_session(auth, host=request.headers.get("host")) ctx = db.data().session_ctx(auth, host)
except ValueError as e: if not ctx:
raise authz.AuthException( raise authz.AuthException(
status_code=401, detail="Session expired", mode="login" status_code=401, detail="Session expired", mode="login"
) from e )
new_name = (payload.get("display_name") or "").strip() new_name = (payload.get("display_name") or "").strip()
if not new_name: if not new_name:
raise HTTPException(status_code=400, detail="display_name required") raise HTTPException(status_code=400, detail="display_name required")
if len(new_name) > 64: if len(new_name) > 64:
raise HTTPException(status_code=400, detail="display_name too long") raise HTTPException(status_code=400, detail="display_name too long")
await db.instance.update_user_display_name(s.user_uuid, new_name) db.update_user_display_name(ctx.user.uuid, new_name, ctx=ctx)
return {"status": "ok"}
@app.patch("/theme")
async def user_update_theme(
request: Request,
payload: dict = Body(...),
auth=AUTH_COOKIE,
):
if not auth:
raise authz.AuthException(
status_code=401, detail="Authentication Required", mode="login"
)
ctx = db.data().session_ctx(auth, request.headers.get("host"))
if not ctx:
raise authz.AuthException(
status_code=401, detail="Session expired", mode="login"
)
theme = payload.get("theme", "")
if theme not in ("", "light", "dark"):
raise HTTPException(status_code=400, detail="Invalid theme")
db.update_user_theme(ctx.user.uuid, theme, ctx=ctx)
return {"status": "ok"} return {"status": "ok"}
@@ -63,13 +83,13 @@ async def user_update_display_name(
async def api_logout_all(request: Request, response: Response, auth=AUTH_COOKIE): async def api_logout_all(request: Request, response: Response, auth=AUTH_COOKIE):
if not auth: if not auth:
return {"message": "Already logged out"} return {"message": "Already logged out"}
try: host = request.headers.get("host")
s = await get_session(auth, host=request.headers.get("host")) ctx = db.data().session_ctx(auth, host)
except ValueError: if not ctx:
raise authz.AuthException( raise authz.AuthException(
status_code=401, detail="Session expired", mode="login" status_code=401, detail="Session expired", mode="login"
) )
await db.instance.delete_sessions_for_user(s.user_uuid) db.delete_sessions_for_user(ctx.user.uuid, ctx=ctx)
session.clear_session_cookie(response) session.clear_session_cookie(response)
return {"message": "Logged out from all hosts"} return {"message": "Logged out from all hosts"}
@@ -85,26 +105,19 @@ async def api_delete_session(
raise authz.AuthException( raise authz.AuthException(
status_code=401, detail="Authentication Required", mode="login" status_code=401, detail="Authentication Required", mode="login"
) )
try: host = request.headers.get("host")
current_session = await get_session(auth, host=request.headers.get("host")) ctx = db.data().session_ctx(auth, host)
except ValueError as exc: if not ctx:
raise authz.AuthException( raise authz.AuthException(
status_code=401, detail="Session expired", mode="login" status_code=401, detail="Session expired", mode="login"
) from exc )
try: target_session = db.data().sessions.get(session_id)
target_key = decode_session_key(session_id) if not target_session or target_session.user_uuid != ctx.user.uuid:
except ValueError as exc:
raise HTTPException(
status_code=400, detail="Invalid session identifier"
) from exc
target_session = await db.instance.get_session(target_key)
if not target_session or target_session.user_uuid != current_session.user_uuid:
raise HTTPException(status_code=404, detail="Session not found") raise HTTPException(status_code=404, detail="Session not found")
await db.instance.delete_session(target_key) db.delete_session(session_id, ctx=ctx)
current_terminated = target_key == session_key(auth) current_terminated = session_id == auth
if current_terminated: if current_terminated:
session.clear_session_cookie(response) # explicit because 200 session.clear_session_cookie(response) # explicit because 200
return {"status": "ok", "current_session_terminated": current_terminated} return {"status": "ok", "current_session_terminated": current_terminated}
@@ -120,7 +133,7 @@ async def api_delete_credential(
# Require recent authentication for sensitive operation # Require recent authentication for sensitive operation
await authz.verify(auth, [], host=request.headers.get("host"), max_age="5m") await authz.verify(auth, [], host=request.headers.get("host"), max_age="5m")
try: try:
await delete_credential(uuid, auth, host=request.headers.get("host")) delete_credential(uuid, auth, host=request.headers.get("host"))
except ValueError as e: except ValueError as e:
raise authz.AuthException( raise authz.AuthException(
status_code=401, detail="Session expired", mode="login" status_code=401, detail="Session expired", mode="login"
@@ -135,28 +148,23 @@ async def api_create_link(
auth=AUTH_COOKIE, auth=AUTH_COOKIE,
): ):
# Require recent authentication for sensitive operation # Require recent authentication for sensitive operation
await authz.verify(auth, [], host=request.headers.get("host"), max_age="5m") ctx = await authz.verify(auth, [], host=request.headers.get("host"), max_age="5m")
try:
s = await get_session(auth, host=request.headers.get("host"))
except ValueError as e:
raise authz.AuthException(
status_code=401, detail="Session expired", mode="login"
) from e
token = passphrase.generate() token = passphrase.generate()
expiry = expires() expiry = expires()
await db.instance.create_reset_token( db.create_reset_token(
user_uuid=s.user_uuid, user_uuid=ctx.user.uuid,
key=tokens.reset_key(token), passphrase=token,
expiry=expiry, expiry=expiry,
token_type="device addition", token_type="device addition",
ctx=ctx,
) )
url = hostutil.reset_link_url(token) url = hostutil.reset_link_url(token)
return { return {
"message": "Registration link generated successfully", "message": "Registration link generated successfully",
"url": url, "url": url,
"expires": ( "expires": (
expiry.astimezone(timezone.utc).isoformat().replace("+00:00", "Z") expiry.astimezone(UTC).isoformat().replace("+00:00", "Z")
if expiry.tzinfo if expiry.tzinfo
else expiry.replace(tzinfo=timezone.utc).isoformat().replace("+00:00", "Z") else expiry.replace(tzinfo=UTC).isoformat().replace("+00:00", "Z")
), ),
} }
+21 -76
View File
@@ -1,40 +1,21 @@
from uuid import UUID
from fastapi import FastAPI, WebSocket from fastapi import FastAPI, WebSocket
from paskia.authsession import create_session, get_reset, get_session from paskia import db
from paskia.authsession import get_reset
from paskia.fastapi import authz, remote from paskia.fastapi import authz, remote
from paskia.fastapi.session import AUTH_COOKIE, infodict from paskia.fastapi.session import AUTH_COOKIE, infodict
from paskia.fastapi.wschat import authenticate_and_login, register_chat
from paskia.fastapi.wsutil import validate_origin, websocket_error_handler from paskia.fastapi.wsutil import validate_origin, websocket_error_handler
from paskia.globals import db, passkey from paskia.globals import passkey
from paskia.util import passphrase from paskia.util import passphrase
from paskia.util.tokens import create_token, session_key
# Create a FastAPI subapp for WebSocket endpoints # Create a FastAPI subapp for WebSocket endpoints
app = FastAPI() app = FastAPI(docs_url=None, redoc_url=None, openapi_url=None)
# Mount the remote auth WebSocket endpoints # Mount the remote auth WebSocket endpoints
app.mount("/remote-auth", remote.app) app.mount("/remote-auth", remote.app)
async def register_chat(
ws: WebSocket,
user_uuid: UUID,
user_name: str,
origin: str,
credential_ids: list[bytes] | None = None,
):
"""Generate registration options and send them to the client."""
options, challenge = passkey.instance.reg_generate_options(
user_id=user_uuid,
user_name=user_name,
credential_ids=credential_ids,
)
await ws.send_json({"optionsJSON": options})
response = await ws.receive_json()
return passkey.instance.reg_verify(response, challenge, user_uuid, origin=origin)
@app.websocket("/register") @app.websocket("/register")
@websocket_error_handler @websocket_error_handler
async def websocket_register_add( async def websocket_register_add(
@@ -56,7 +37,7 @@ async def websocket_register_add(
raise ValueError( raise ValueError(
f"The reset link for {passkey.instance.rp_name} is invalid or has expired" f"The reset link for {passkey.instance.rp_name} is invalid or has expired"
) )
s = await get_reset(reset) s = get_reset(reset)
user_uuid = s.user_uuid user_uuid = s.user_uuid
else: else:
# Require recent authentication for adding a new passkey # Require recent authentication for adding a new passkey
@@ -65,37 +46,35 @@ async def websocket_register_add(
s = ctx.session s = ctx.session
# Get user information and determine effective user_name for this registration # Get user information and determine effective user_name for this registration
user = await db.instance.get_user_by_uuid(user_uuid) user = db.data().users[user_uuid]
user_name = user.display_name user_name = user.display_name
if name is not None: if name is not None:
stripped = name.strip() stripped = name.strip()
if stripped: if stripped:
user_name = stripped user_name = stripped
challenge_ids = await db.instance.get_credentials_by_user_uuid(user_uuid) credential_ids = db.get_user_credential_ids(user_uuid) or None
# WebAuthn registration # WebAuthn registration
credential = await register_chat(ws, user_uuid, user_name, origin, challenge_ids) credential = await register_chat(ws, user_uuid, user_name, origin, credential_ids)
# Create a new session and store everything in database # Create a new session and store everything in database
token = create_token()
metadata = infodict(ws, "authenticated") metadata = infodict(ws, "authenticated")
await db.instance.create_credential_session( # type: ignore[attr-defined] token = db.create_credential_session(
user_uuid=user_uuid, user_uuid=user_uuid,
credential=credential, credential=credential,
reset_key=(s.key if reset is not None else None), reset_key=(s.key if reset is not None else None),
session_key=session_key(token),
display_name=user_name, display_name=user_name,
host=host, host=host,
ip=metadata.get("ip"), ip=metadata["ip"],
user_agent=metadata.get("user_agent"), user_agent=metadata["user_agent"],
) )
auth = token auth = token
assert isinstance(auth, str) and len(auth) == 16 assert isinstance(auth, str) and len(auth) == 16
await ws.send_json( await ws.send_json(
{ {
"user_uuid": str(user.uuid), "user": str(user.uuid),
"credential_uuid": str(credential.uuid), "credential": str(credential.uuid),
"session_token": auth, "session_token": auth,
"message": "New credential added successfully", "message": "New credential added successfully",
} }
@@ -110,54 +89,20 @@ async def websocket_authenticate(ws: WebSocket, auth=AUTH_COOKIE):
# If there's an existing session, restrict to that user's credentials (reauth) # If there's an existing session, restrict to that user's credentials (reauth)
session_user_uuid = None session_user_uuid = None
credential_ids = None
if auth: if auth:
try: existing_ctx = db.data().session_ctx(auth, host)
session = await get_session(auth, host=host) if existing_ctx:
session_user_uuid = session.user_uuid session_user_uuid = existing_ctx.user.uuid
credential_ids = await db.instance.get_credentials_by_user_uuid(
session_user_uuid
)
except ValueError:
pass # Invalid/expired session - allow normal authentication
options, challenge = passkey.instance.auth_generate_options( ctx = await authenticate_and_login(ws, auth)
credential_ids=credential_ids
)
await ws.send_json({"optionsJSON": options})
# Wait for the client to use his authenticator to authenticate
credential = passkey.instance.auth_parse(await ws.receive_json())
# Fetch from the database by credential ID
try:
stored_cred = await db.instance.get_credential_by_id(credential.raw_id)
except ValueError:
raise ValueError(
f"This passkey is no longer registered with {passkey.instance.rp_name}"
)
# If reauth mode, verify the credential belongs to the session's user # If reauth mode, verify the credential belongs to the session's user
if session_user_uuid and stored_cred.user_uuid != session_user_uuid: if session_user_uuid and ctx.user.uuid != session_user_uuid:
raise ValueError("This passkey belongs to a different account") raise ValueError("This passkey belongs to a different account")
# Verify the credential matches the stored data
passkey.instance.auth_verify(credential, challenge, stored_cred, origin)
# Update both credential and user's last_seen timestamp
await db.instance.login(stored_cred.user_uuid, stored_cred)
# Create a session token for the authenticated user
assert stored_cred.uuid is not None
metadata = infodict(ws, "auth")
token = await create_session(
user_uuid=stored_cred.user_uuid,
credential_uuid=stored_cred.uuid,
host=host,
ip=metadata.get("ip") or "",
user_agent=metadata.get("user_agent") or "",
)
await ws.send_json( await ws.send_json(
{ {
"user_uuid": str(stored_cred.user_uuid), "user": str(ctx.user.uuid),
"session_token": token, "session_token": ctx.session.key,
} }
) )
+115
View File
@@ -0,0 +1,115 @@
"""
WebSocket chat functions for WebAuthn registration and authentication flows.
"""
from uuid import UUID
from fastapi import WebSocket
from paskia import db
from paskia.authsession import expires
from paskia.db import Credential, SessionContext
from paskia.fastapi.session import infodict
from paskia.fastapi.wsutil import validate_origin
from paskia.globals import passkey
from paskia.util import hostutil
async def register_chat(
ws: WebSocket,
user_uuid: UUID,
user_name: str,
origin: str,
credential_ids: list[bytes] | None = None,
):
"""Run WebAuthn registration flow and return the verified credential."""
options, challenge = passkey.instance.reg_generate_options(
user_id=user_uuid,
user_name=user_name,
credential_ids=credential_ids,
)
await ws.send_json({"optionsJSON": options})
response = await ws.receive_json()
return passkey.instance.reg_verify(response, challenge, user_uuid, origin=origin)
async def authenticate_chat(
ws: WebSocket,
credential_ids: list[bytes] | None = None,
) -> tuple[Credential, int]:
"""Run WebAuthn authentication flow and return the credential and new sign count.
Returns:
tuple of (credential, new_sign_count) where new_sign_count comes from WebAuthn verification
"""
origin = validate_origin(ws)
options, challenge = passkey.instance.auth_generate_options(
credential_ids=credential_ids
)
await ws.send_json({"optionsJSON": options})
authcred = passkey.instance.auth_parse(await ws.receive_json())
cred = next(
(
c
for c in db.data().credentials.values()
if c.credential_id == authcred.raw_id
),
None,
)
if not cred:
raise ValueError(
f"This passkey is no longer registered with {passkey.instance.rp_name}"
)
verification = passkey.instance.auth_verify(authcred, challenge, cred, origin)
return cred, verification.new_sign_count
async def authenticate_and_login(
ws: WebSocket,
auth: str | None = None,
) -> SessionContext:
"""Run WebAuthn authentication flow, create session, and return the session context.
If auth is provided, restrict authentication to credentials of that session's user.
Returns:
SessionContext for the authenticated session
"""
origin = validate_origin(ws)
host = origin.split("://", 1)[1]
normalized_host = hostutil.normalize_host(host)
if not normalized_host:
raise ValueError("Host required for session creation")
hostname = normalized_host.split(":")[0]
rp_id = passkey.instance.rp_id
if not (hostname == rp_id or hostname.endswith(f".{rp_id}")):
raise ValueError(f"Host must be the same as or a subdomain of {rp_id}")
metadata = infodict(ws, "auth")
# Get credential IDs if restricting to a user's credentials
credential_ids = None
if auth:
existing_ctx = db.data().session_ctx(auth, host)
if existing_ctx:
credential_ids = db.get_user_credential_ids(existing_ctx.user.uuid) or None
cred, new_sign_count = await authenticate_chat(ws, credential_ids)
# Create session and update user/credential
token = db.login(
user_uuid=cred.user_uuid,
credential_uuid=cred.uuid,
sign_count=new_sign_count,
host=normalized_host,
ip=metadata["ip"],
user_agent=metadata["user_agent"],
expiry=expires(),
)
# Fetch and return the full session context
ctx = db.data().session_ctx(token, normalized_host)
if not ctx:
raise ValueError("Failed to create session context")
return ctx
+10 -2
View File
@@ -3,6 +3,7 @@ Shared WebSocket utilities for FastAPI endpoints.
""" """
import logging import logging
import time
from functools import wraps from functools import wraps
import base64url import base64url
@@ -10,6 +11,7 @@ from fastapi import WebSocket, WebSocketDisconnect
from webauthn.helpers.exceptions import InvalidAuthenticationResponse from webauthn.helpers.exceptions import InvalidAuthenticationResponse
from paskia.fastapi import authz from paskia.fastapi import authz
from paskia.fastapi.logging import log_ws_close, log_ws_open
from paskia.globals import passkey from paskia.globals import passkey
from paskia.util import pow from paskia.util import pow
@@ -19,11 +21,15 @@ def websocket_error_handler(func):
@wraps(func) @wraps(func)
async def wrapper(ws: WebSocket, *args, **kwargs): async def wrapper(ws: WebSocket, *args, **kwargs):
start = time.perf_counter()
ws_id = log_ws_open(ws)
close_code = None
try: try:
await ws.accept() await ws.accept()
return await func(ws, *args, **kwargs) return await func(ws, *args, **kwargs)
except WebSocketDisconnect: except WebSocketDisconnect as e:
pass close_code = e.code
except authz.AuthException as e: except authz.AuthException as e:
await ws.send_json( await ws.send_json(
{ {
@@ -36,6 +42,8 @@ def websocket_error_handler(func):
except Exception: except Exception:
logging.exception("Internal Server Error") logging.exception("Internal Server Error")
await ws.send_json({"status": 500, "detail": "Internal Server Error"}) await ws.send_json({"status": 500, "detail": "Internal Server Error"})
finally:
log_ws_close(ws_id, close_code, time.perf_counter() - start)
return wrapper return wrapper
+8 -11
View File
@@ -1,6 +1,7 @@
from typing import Generic, TypeVar from typing import Generic, TypeVar
from paskia.db import DatabaseInterface from paskia import db, remoteauth
from paskia.bootstrap import bootstrap_if_needed
from paskia.sansio import Passkey from paskia.sansio import Passkey
T = TypeVar("T") T = TypeVar("T")
@@ -38,8 +39,11 @@ async def init(
If bootstrap=True (default) the system bootstrap_if_needed() will be invoked. If bootstrap=True (default) the system bootstrap_if_needed() will be invoked.
In FastAPI lifespan we call with bootstrap=False to avoid duplicate bootstrapping In FastAPI lifespan we call with bootstrap=False to avoid duplicate bootstrapping
since the CLI performs it once before servers start. since the CLI performs it once before servers start.
Database configuration:
Set PASKIA_DB environment variable to specify the JSONL database file path.
Default: paskia.jsonl
""" """
from . import remoteauth
# Initialize passkey instance with provided parameters # Initialize passkey instance with provided parameters
passkey.instance = Passkey( passkey.instance = Passkey(
@@ -48,24 +52,17 @@ async def init(
origins=origins, origins=origins,
) )
# Test if we have a database already initialized, otherwise use SQL # Initialize database
try: await db.init()
db.instance
except RuntimeError:
from .db import sql
await sql.init()
# Initialize remote auth manager # Initialize remote auth manager
await remoteauth.init() await remoteauth.init()
if bootstrap: if bootstrap:
# Bootstrap system if needed # Bootstrap system if needed
from .bootstrap import bootstrap_if_needed
await bootstrap_if_needed() await bootstrap_if_needed()
# Global instances # Global instances
passkey = Manager[Passkey]("Passkey") passkey = Manager[Passkey]("Passkey")
db = Manager[DatabaseInterface]("Database")
+281
View File
@@ -0,0 +1,281 @@
"""
SQL to JSON migration module for Paskia.
This module contains the legacy SQL database implementation and migration tools
for converting from the old SQLite database to the new JSONL format.
Usage:
python -m paskia.migrate --sql sqlite+aiosqlite:///paskia.sqlite --json paskia.jsonl
Or via the CLI entry point (if installed):
paskia-migrate --sql sqlite+aiosqlite:///paskia.sqlite --json paskia.jsonl
"""
import argparse
import asyncio
import re
from datetime import UTC, datetime
from uuid import UUID
import base64url
import uuid7
from sqlalchemy import select
from paskia.authsession import EXPIRES
from paskia.db.jsonl import JsonlStore
from paskia.db.structs import (
DB,
Credential,
Org,
Permission,
ResetToken,
Role,
Session,
User,
)
from .sql import (
DB as SQLDB,
)
from .sql import (
CredentialModel,
ResetTokenModel,
SessionModel,
UserModel,
)
# Re-export for convenience
__all__ = ["migrate_from_sql", "main", "SQLDB"]
# Default paths
SQL_DB_DEFAULT = "sqlite+aiosqlite:///paskia.sqlite"
JSON_DB_DEFAULT = "paskia.jsonl"
async def migrate_from_sql(
sql_db_path: str = SQL_DB_DEFAULT,
json_db_path: str = JSON_DB_DEFAULT,
) -> None:
"""Migrate data from SQL database to JSON format.
Args:
sql_db_path: SQLAlchemy connection string for the source SQL database
json_db_path: Path for the destination JSONL file
"""
# Initialize source SQL database
sql_db = SQLDB(sql_db_path)
await sql_db.init_db()
# Initialize destination JSON database (fresh, don't load existing)
db = DB()
store = JsonlStore(db, json_db_path)
db._store = store
print(f"Migrating from {sql_db_path} to {json_db_path}...")
# Build all data directly without saving (we'll save once at the end)
# Track old permission ID -> new scope mapping for migration
# Also track org-specific admin permissions to consolidate
old_org_admin_pattern = re.compile(r"^auth:org:([0-9a-f-]+)$", re.IGNORECASE)
org_admin_uuids = set() # org UUIDs that had org-specific admin permissions
# First pass: identify org-specific admin permissions
permissions = await sql_db.list_permissions()
for perm in permissions:
match = old_org_admin_pattern.match(perm.id)
if match:
org_admin_uuids.add(match.group(1).lower())
# Migrate permissions with UUID keys and scope field
# Always create exactly one common auth:org:admin permission for all org admin needs
org_admin_perm_uuid: UUID = uuid7.create()
org_admin_perm = Permission(
scope="auth:org:admin",
display_name="Org Admin",
orgs={},
)
org_admin_perm.uuid = org_admin_perm_uuid
db.permissions[org_admin_perm_uuid] = org_admin_perm
# Mapping from old permission ID to new permission UUID
perm_id_to_uuid: dict[str, UUID] = {}
for perm in permissions:
# Skip old org-specific admin permissions (auth:org:{uuid}) - they map to auth:org:admin
match = old_org_admin_pattern.match(perm.id)
if match:
perm_id_to_uuid[perm.id] = org_admin_perm_uuid
continue
# Skip if this is already auth:org:admin - we created one above
if perm.id == "auth:org:admin":
perm_id_to_uuid[perm.id] = org_admin_perm_uuid
continue
# Regular permission - create with UUID key
perm_uuid: UUID = uuid7.create()
new_perm = Permission(
scope=perm.id, # Old ID becomes the scope
display_name=perm.display_name,
orgs={},
)
new_perm.uuid = perm_uuid
db.permissions[perm_uuid] = new_perm
perm_id_to_uuid[perm.id] = perm_uuid
print(
f" Migrated {len(permissions)} permissions (with {len(org_admin_uuids)} org-specific admins consolidated to auth:org:admin)"
)
# Migrate organizations
orgs = await sql_db.list_organizations()
for org in orgs:
org_key: UUID = org.uuid
new_org = Org(display_name=org.display_name)
new_org.uuid = org_key
db.orgs[org_key] = new_org
# Update permissions to allow this org to grant them (by UUID)
for old_perm_id in org.permissions:
perm_uuid = perm_id_to_uuid.get(old_perm_id)
if perm_uuid and perm_uuid in db.permissions:
db.permissions[perm_uuid].orgs[org_key] = True
# Ensure every org can grant auth:org:admin
db.permissions[org_admin_perm_uuid].orgs[org_key] = True
print(f" Migrated {len(orgs)} organizations")
# Migrate roles - convert old permission IDs to UUIDs
role_count = 0
for org in orgs:
for role in org.roles:
role_key: UUID = role.uuid
# Convert old permission IDs to UUIDs
new_permissions: dict[UUID, bool] = {}
for old_perm_id in role.permissions or []:
perm_uuid = perm_id_to_uuid.get(old_perm_id)
if perm_uuid:
new_permissions[perm_uuid] = True
new_role = Role(
org_uuid=role.org_uuid,
display_name=role.display_name,
permissions=new_permissions,
)
new_role.uuid = role_key
db.roles[role_key] = new_role
role_count += 1
print(f" Migrated {role_count} roles")
# Migrate users
async with sql_db.session() as session:
result = await session.execute(select(UserModel))
user_models = result.scalars().all()
for um in user_models:
legacy_user = um.as_dataclass()
user_key: UUID = legacy_user.uuid
new_user = User(
display_name=legacy_user.display_name,
role_uuid=legacy_user.role_uuid,
created_at=legacy_user.created_at or datetime.now(UTC),
last_seen=legacy_user.last_seen,
visits=legacy_user.visits,
)
new_user.uuid = user_key
db.users[user_key] = new_user
print(f" Migrated {len(user_models)} users")
# Migrate credentials
async with sql_db.session() as session:
result = await session.execute(select(CredentialModel))
cred_models = result.scalars().all()
for cm in cred_models:
legacy_cred = cm.as_dataclass()
cred_key: UUID = legacy_cred.uuid
new_cred = Credential(
credential_id=legacy_cred.credential_id,
user_uuid=legacy_cred.user_uuid,
aaguid=legacy_cred.aaguid,
public_key=legacy_cred.public_key,
sign_count=legacy_cred.sign_count,
created_at=legacy_cred.created_at,
last_used=legacy_cred.last_used,
last_verified=legacy_cred.last_verified,
)
new_cred.uuid = cred_key
db.credentials[cred_key] = new_cred
print(f" Migrated {len(cred_models)} credentials")
# Migrate sessions
# Old format: b"sess" + 12 bytes -> New format: base64url string (16 chars)
async with sql_db.session() as session:
result = await session.execute(select(SessionModel))
session_models = result.scalars().all()
for sm in session_models:
sess = sm.as_dataclass()
old_key: bytes = sess.key
# Strip b"sess" prefix and encode remaining 12 bytes as base64url
if old_key.startswith(b"sess"):
session_key = base64url.enc(old_key[4:])
else:
# Already in new format or unknown - try to use as-is
session_key = base64url.enc(old_key[:12])
db.sessions[session_key] = Session(
user_uuid=sess.user_uuid,
credential_uuid=sess.credential_uuid,
host=sess.host,
ip=sess.ip,
user_agent=sess.user_agent,
expiry=sess.renewed + EXPIRES, # Convert renewed to expiry
)
print(f" Migrated {len(session_models)} sessions")
# Migrate reset tokens
# Old format: b"rset" + 16 bytes hash -> New format: 9 bytes (truncated hash)
async with sql_db.session() as session:
result = await session.execute(select(ResetTokenModel))
token_models = result.scalars().all()
for tm in token_models:
token = tm.as_dataclass()
old_key: bytes = token.key
# Strip b"rset" prefix and take first 9 bytes of hash
if old_key.startswith(b"rset"):
token_key = old_key[4:13] # 9 bytes after prefix
else:
# Already in new format or unknown - truncate to 9 bytes
token_key = old_key[:9]
db.reset_tokens[token_key] = ResetToken(
user_uuid=token.user_uuid,
expiry=token.expiry,
token_type=token.token_type,
)
print(f" Migrated {len(token_models)} reset tokens")
# Queue and flush all changes using the transaction mechanism
with db.transaction("migrate:sql"):
pass # All data already added to _data, transaction commits on exit
await store.flush()
print("Migration complete!")
def main():
"""CLI entry point for migration."""
parser = argparse.ArgumentParser(
description="Migrate Paskia database from SQL to JSON"
)
parser.add_argument(
"--sql",
default=SQL_DB_DEFAULT,
help=f"Source SQL database connection string (default: {SQL_DB_DEFAULT})",
)
parser.add_argument(
"--json",
default=JSON_DB_DEFAULT,
help=f"Destination JSONL file path (default: {JSON_DB_DEFAULT})",
)
args = parser.parse_args()
asyncio.run(migrate_from_sql(args.sql, args.json))
if __name__ == "__main__":
main()
+438
View File
@@ -0,0 +1,438 @@
"""
Legacy SQL database implementation for migration purposes.
This module provides the async SQLAlchemy database layer that was used
before the JSONL format. It is kept here for migration purposes only.
DO NOT use this module for new code. Use paskia.db instead.
"""
from contextlib import asynccontextmanager
from dataclasses import dataclass
from datetime import UTC, datetime
from uuid import UUID
from sqlalchemy import (
DateTime,
ForeignKey,
Integer,
LargeBinary,
String,
event,
select,
)
from sqlalchemy.dialects.sqlite import BLOB
from sqlalchemy.ext.asyncio import async_sessionmaker, create_async_engine
from sqlalchemy.orm import DeclarativeBase, Mapped, mapped_column
# Legacy User class for SQL schema (uses 'role_uuid' not 'role')
@dataclass
class _LegacyUser:
"""User as stored in the old SQL schema with role_uuid field."""
uuid: UUID
display_name: str
role_uuid: UUID
created_at: datetime | None = None
last_seen: datetime | None = None
visits: int = 0
# Legacy Credential class for SQL schema (uses 'user_uuid' not 'user')
@dataclass
class _LegacyCredential:
"""Credential as stored in the old SQL schema with user_uuid field."""
uuid: UUID
credential_id: bytes
user_uuid: UUID
aaguid: UUID
public_key: bytes
sign_count: int
created_at: datetime
last_used: datetime | None = None
last_verified: datetime | None = None
# Legacy Role class for SQL schema (uses 'org_uuid' not 'org')
@dataclass
class _LegacyRole:
"""Role as stored in the old SQL schema with org_uuid field."""
uuid: UUID
org_uuid: UUID
display_name: str
permissions: list[str] | None = None
# Legacy Org class for SQL schema (has mutable permissions/roles lists)
@dataclass
class _LegacyOrg:
"""Org as stored in the old SQL schema with mutable permissions/roles."""
uuid: UUID
display_name: str
permissions: list[str] | None = None
roles: list[_LegacyRole] | None = None
# Legacy Session class for SQL schema (uses 'key' as field, 'user_uuid', 'credential_uuid')
@dataclass
class _LegacySession:
"""Session as stored in the old SQL schema."""
key: bytes
user_uuid: UUID
credential_uuid: UUID
host: str
ip: str
user_agent: str
renewed: datetime
# Legacy ResetToken class for SQL schema (uses 'key' as field, 'user_uuid')
@dataclass
class _LegacyResetToken:
"""ResetToken as stored in the old SQL schema."""
key: bytes
user_uuid: UUID
token_type: str
expiry: datetime
# Local Permission class for SQL schema (uses 'id' not 'uuid' + 'scope')
@dataclass
class SqlPermission:
"""Permission as stored in the old SQL schema with id field."""
id: str
display_name: str
DB_PATH_DEFAULT = "sqlite+aiosqlite:///paskia.sqlite"
def _normalize_dt(value: datetime | None) -> datetime | None:
if value is None:
return None
if value.tzinfo is None:
return value.replace(tzinfo=UTC)
return value.astimezone(UTC)
class Base(DeclarativeBase):
pass
class OrgModel(Base):
__tablename__ = "orgs"
uuid: Mapped[bytes] = mapped_column(LargeBinary(16), primary_key=True)
display_name: Mapped[str] = mapped_column(String, nullable=False)
def as_dataclass(self):
# Base Org without permissions/roles (filled by data accessors)
return _LegacyOrg(
uuid=UUID(bytes=self.uuid),
display_name=self.display_name,
)
@staticmethod
def from_dataclass(org: _LegacyOrg):
return OrgModel(uuid=org.uuid.bytes, display_name=org.display_name)
class RoleModel(Base):
__tablename__ = "roles"
uuid: Mapped[bytes] = mapped_column(LargeBinary(16), primary_key=True)
org_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("orgs.uuid", ondelete="CASCADE"), nullable=False
)
display_name: Mapped[str] = mapped_column(String, nullable=False)
def as_dataclass(self):
# Base Role without permissions (filled by data accessors)
return _LegacyRole(
uuid=UUID(bytes=self.uuid),
org_uuid=UUID(bytes=self.org_uuid),
display_name=self.display_name,
)
@staticmethod
def from_dataclass(role: _LegacyRole):
return RoleModel(
uuid=role.uuid.bytes,
org_uuid=role.org_uuid.bytes,
display_name=role.display_name,
)
class UserModel(Base):
__tablename__ = "users"
uuid: Mapped[bytes] = mapped_column(LargeBinary(16), primary_key=True)
display_name: Mapped[str] = mapped_column(String, nullable=False)
role_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("roles.uuid", ondelete="CASCADE"), nullable=False
)
created_at: Mapped[datetime] = mapped_column(
DateTime(timezone=True), default=lambda: datetime.now(UTC)
)
last_seen: Mapped[datetime | None] = mapped_column(
DateTime(timezone=True), nullable=True
)
visits: Mapped[int] = mapped_column(Integer, nullable=False, default=0)
def as_dataclass(self) -> "_LegacyUser":
return _LegacyUser(
uuid=UUID(bytes=self.uuid),
display_name=self.display_name,
role_uuid=UUID(bytes=self.role_uuid),
created_at=_normalize_dt(self.created_at) or self.created_at,
last_seen=_normalize_dt(self.last_seen) or self.last_seen,
visits=self.visits,
)
@staticmethod
def from_dataclass(user: "_LegacyUser"):
return UserModel(
uuid=user.uuid.bytes,
display_name=user.display_name,
role_uuid=user.role_uuid.bytes,
created_at=user.created_at or datetime.now(UTC),
last_seen=user.last_seen,
visits=user.visits,
)
class CredentialModel(Base):
__tablename__ = "credentials"
uuid: Mapped[bytes] = mapped_column(LargeBinary(16), primary_key=True)
credential_id: Mapped[bytes] = mapped_column(
LargeBinary(64), unique=True, index=True
)
user_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("users.uuid", ondelete="CASCADE")
)
aaguid: Mapped[bytes] = mapped_column(LargeBinary(16), nullable=False)
public_key: Mapped[bytes] = mapped_column(BLOB, nullable=False)
sign_count: Mapped[int] = mapped_column(Integer, nullable=False)
created_at: Mapped[datetime] = mapped_column(
DateTime(timezone=True), default=lambda: datetime.now(UTC)
)
last_used: Mapped[datetime | None] = mapped_column(
DateTime(timezone=True), nullable=True
)
last_verified: Mapped[datetime | None] = mapped_column(
DateTime(timezone=True), nullable=True
)
def as_dataclass(self):
return _LegacyCredential(
uuid=UUID(bytes=self.uuid),
credential_id=self.credential_id,
user_uuid=UUID(bytes=self.user_uuid),
aaguid=UUID(bytes=self.aaguid),
public_key=self.public_key,
sign_count=self.sign_count,
created_at=_normalize_dt(self.created_at) or self.created_at,
last_used=_normalize_dt(self.last_used) or self.last_used,
last_verified=_normalize_dt(self.last_verified) or self.last_verified,
)
class SessionModel(Base):
__tablename__ = "sessions"
key: Mapped[bytes] = mapped_column(LargeBinary(16), primary_key=True)
user_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("users.uuid", ondelete="CASCADE"), nullable=False
)
credential_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16),
ForeignKey("credentials.uuid", ondelete="CASCADE"),
nullable=False,
)
host: Mapped[str] = mapped_column(String, nullable=False)
ip: Mapped[str] = mapped_column(String(64), nullable=False)
user_agent: Mapped[str] = mapped_column(String(512), nullable=False)
renewed: Mapped[datetime] = mapped_column(
DateTime(timezone=True),
default=lambda: datetime.now(UTC),
nullable=False,
)
def as_dataclass(self):
return _LegacySession(
key=self.key,
user_uuid=UUID(bytes=self.user_uuid),
credential_uuid=UUID(bytes=self.credential_uuid),
host=self.host,
ip=self.ip,
user_agent=self.user_agent,
renewed=_normalize_dt(self.renewed) or self.renewed,
)
@staticmethod
def from_dataclass(session: _LegacySession):
return SessionModel(
key=session.key,
user_uuid=session.user_uuid.bytes,
credential_uuid=session.credential_uuid.bytes,
host=session.host,
ip=session.ip,
user_agent=session.user_agent,
renewed=session.renewed,
)
class ResetTokenModel(Base):
__tablename__ = "reset_tokens"
key: Mapped[bytes] = mapped_column(LargeBinary(16), primary_key=True)
user_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("users.uuid", ondelete="CASCADE"), nullable=False
)
token_type: Mapped[str] = mapped_column(String, nullable=False)
expiry: Mapped[datetime] = mapped_column(DateTime(timezone=True), nullable=False)
def as_dataclass(self) -> _LegacyResetToken:
return _LegacyResetToken(
key=self.key,
user_uuid=UUID(bytes=self.user_uuid),
token_type=self.token_type,
expiry=_normalize_dt(self.expiry) or self.expiry,
)
class PermissionModel(Base):
__tablename__ = "permissions"
id: Mapped[str] = mapped_column(String(64), primary_key=True)
display_name: Mapped[str] = mapped_column(String, nullable=False)
def as_dataclass(self):
return SqlPermission(self.id, self.display_name)
@staticmethod
def from_dataclass(permission: SqlPermission):
return PermissionModel(
id=permission.id,
display_name=permission.display_name,
)
class OrgPermission(Base):
"""Permissions each organization is allowed to grant to its roles."""
__tablename__ = "org_permissions"
id: Mapped[int] = mapped_column(Integer, primary_key=True)
org_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("orgs.uuid", ondelete="CASCADE")
)
permission_id: Mapped[str] = mapped_column(
String(64), ForeignKey("permissions.id", ondelete="CASCADE")
)
class RolePermission(Base):
"""Permissions that each role grants to its members."""
__tablename__ = "role_permissions"
id: Mapped[int] = mapped_column(Integer, primary_key=True)
role_uuid: Mapped[bytes] = mapped_column(
LargeBinary(16), ForeignKey("roles.uuid", ondelete="CASCADE")
)
permission_id: Mapped[str] = mapped_column(
String(64), ForeignKey("permissions.id", ondelete="CASCADE")
)
class DB:
"""Legacy SQL database class for migration purposes only."""
def __init__(self, db_path: str = DB_PATH_DEFAULT):
"""Initialize with database path."""
self.engine = create_async_engine(db_path, echo=False)
# Ensure SQLite foreign key enforcement is ON for every new connection
if db_path.startswith("sqlite"):
@event.listens_for(self.engine.sync_engine, "connect")
def _fk_on(dbapi_connection, connection_record):
try:
cursor = dbapi_connection.cursor()
cursor.execute("PRAGMA foreign_keys=ON;")
cursor.close()
except Exception:
pass
self.async_session_factory = async_sessionmaker(
self.engine, expire_on_commit=False
)
@asynccontextmanager
async def session(self):
"""Async context manager that provides a database session with transaction."""
async with self.async_session_factory() as session:
async with session.begin():
yield session
await session.flush()
await session.commit()
async def init_db(self) -> None:
"""Initialize database tables."""
async with self.engine.begin() as conn:
await conn.run_sync(Base.metadata.create_all)
async def list_permissions(self) -> list[SqlPermission]:
async with self.session() as session:
result = await session.execute(select(PermissionModel))
return [p.as_dataclass() for p in result.scalars().all()]
async def list_organizations(self) -> list[_LegacyOrg]:
async with self.session() as session:
# Load all orgs
orgs_result = await session.execute(select(OrgModel))
org_models = orgs_result.scalars().all()
if not org_models:
return []
# Preload org permissions mapping
org_perms_result = await session.execute(select(OrgPermission))
org_perms = org_perms_result.scalars().all()
perms_by_org: dict[bytes, list[str]] = {}
for op in org_perms:
perms_by_org.setdefault(op.org_uuid, []).append(op.permission_id)
# Preload roles
roles_result = await session.execute(select(RoleModel))
role_models = roles_result.scalars().all()
# Preload role permissions mapping
rp_result = await session.execute(select(RolePermission))
rps = rp_result.scalars().all()
perms_by_role: dict[bytes, list[str]] = {}
for rp in rps:
perms_by_role.setdefault(rp.role_uuid, []).append(rp.permission_id)
# Build org dataclasses with roles and permission IDs
roles_by_org: dict[bytes, list[_LegacyRole]] = {}
for rm in role_models:
r_dc = rm.as_dataclass()
r_dc.permissions = perms_by_role.get(rm.uuid, [])
roles_by_org.setdefault(rm.org_uuid, []).append(r_dc)
orgs: list[_LegacyOrg] = []
for om in org_models:
o_dc = om.as_dataclass()
o_dc.permissions = perms_by_org.get(om.uuid, [])
o_dc.roles = roles_by_org.get(om.uuid, [])
orgs.append(o_dc)
return orgs
+7 -8
View File
@@ -19,12 +19,12 @@ The first 3 words of the token serve as the pairing code for manual entry.
import asyncio import asyncio
import logging import logging
from collections.abc import Callable
from dataclasses import dataclass from dataclasses import dataclass
from datetime import datetime, timedelta, timezone from datetime import UTC, datetime, timedelta
from typing import Callable
from uuid import UUID from uuid import UUID
from paskia.util import passphrase from paskia.util import passphrase, pow
# Remote auth requests expire after this duration # Remote auth requests expire after this duration
REMOTE_AUTH_LIFETIME = timedelta(minutes=5) REMOTE_AUTH_LIFETIME = timedelta(minutes=5)
@@ -94,7 +94,7 @@ class RemoteAuthManager:
async def _cleanup_expired(self): async def _cleanup_expired(self):
"""Remove expired requests and notify waiting clients.""" """Remove expired requests and notify waiting clients."""
now = datetime.now(timezone.utc) now = datetime.now(UTC)
expired_keys = [] expired_keys = []
async with self._lock: async with self._lock:
for key, req in self._requests.items(): for key, req in self._requests.items():
@@ -123,7 +123,7 @@ class RemoteAuthManager:
Returns: Returns:
(code, expiry) - The 3-word passphrase code and expiration time (code, expiry) - The 3-word passphrase code and expiration time
""" """
now = datetime.now(timezone.utc) now = datetime.now(UTC)
expiry = now + REMOTE_AUTH_LIFETIME expiry = now + REMOTE_AUTH_LIFETIME
async with self._lock: async with self._lock:
@@ -160,7 +160,7 @@ class RemoteAuthManager:
req = self._requests.get(normalized) req = self._requests.get(normalized)
if req is None: if req is None:
return None return None
now = datetime.now(timezone.utc) now = datetime.now(UTC)
if now > req.created_at + REMOTE_AUTH_LIFETIME: if now > req.created_at + REMOTE_AUTH_LIFETIME:
# Expired # Expired
del self._requests[normalized] del self._requests[normalized]
@@ -319,7 +319,6 @@ class RemoteAuthManager:
Returns: Returns:
PoW work units (pow.NORMAL or pow.HARD) PoW work units (pow.NORMAL or pow.HARD)
""" """
from paskia.util import pow
count = self.get_connection_count() count = self.get_connection_count()
return pow.HARD if count >= 10 else pow.NORMAL return pow.HARD if count >= 10 else pow.NORMAL
@@ -332,7 +331,7 @@ class RemoteAuthManager:
req = self._requests.get(token) req = self._requests.get(token)
if req is None: if req is None:
return None return None
now = datetime.now(timezone.utc) now = datetime.now(UTC)
if now > req.created_at + REMOTE_AUTH_LIFETIME: if now > req.created_at + REMOTE_AUTH_LIFETIME:
del self._requests[token] del self._requests[token]
return None return None
+6 -12
View File
@@ -8,11 +8,9 @@ This module provides a unified interface for WebAuthn operations including:
""" """
import json import json
from datetime import datetime, timezone
from urllib.parse import urlparse from urllib.parse import urlparse
from uuid import UUID from uuid import UUID
import uuid7
from webauthn import ( from webauthn import (
generate_authentication_options, generate_authentication_options,
generate_registration_options, generate_registration_options,
@@ -176,14 +174,12 @@ class Passkey:
expected_origin=origin, expected_origin=origin,
expected_rp_id=self.rp_id, expected_rp_id=self.rp_id,
) )
return Credential( return Credential.create(
uuid=uuid7.create(),
credential_id=credential.raw_id, credential_id=credential.raw_id,
user_uuid=user_uuid, user=user_uuid,
aaguid=UUID(registration.aaguid), aaguid=UUID(registration.aaguid),
public_key=registration.credential_public_key, public_key=registration.credential_public_key,
sign_count=registration.sign_count, sign_count=registration.sign_count,
created_at=datetime.now(timezone.utc),
) )
### Authentication Methods ### ### Authentication Methods ###
@@ -234,8 +230,11 @@ class Passkey:
Args: Args:
credential: The authentication credential response from the client credential: The authentication credential response from the client
expected_challenge: The earlier generated challenge bytes expected_challenge: The earlier generated challenge bytes
stored_cred: The server stored credential record (modified by this function) stored_cred: The server stored credential record (NOT modified)
origin: The origin URL (required, must be pre-validated) origin: The origin URL (required, must be pre-validated)
Returns:
VerifiedAuthentication with new_sign_count and user_verified status
""" """
# Verify the authentication response # Verify the authentication response
verification = verify_authentication_response( verification = verify_authentication_response(
@@ -246,11 +245,6 @@ class Passkey:
credential_public_key=stored_cred.public_key, credential_public_key=stored_cred.public_key,
credential_current_sign_count=stored_cred.sign_count, credential_current_sign_count=stored_cred.sign_count,
) )
stored_cred.sign_count = verification.new_sign_count
now = datetime.now(timezone.utc)
stored_cred.last_used = now
if verification.user_verified:
stored_cred.last_verified = now
return verification return verification
+110
View File
@@ -0,0 +1,110 @@
"""API response utilities using msgspec for JSON serialization.
msgspec handles UUID and datetime conversion automatically.
API structs inherit from db structs with kw_only=True to add uuid/key fields.
"""
from datetime import UTC, datetime
from uuid import UUID
import msgspec
from paskia.db.structs import Org, Permission, Role, User
from paskia.util import useragent
def _utc_datetime(dt: datetime | None) -> datetime | None:
"""Convert datetime to UTC, handling both aware and naive datetimes."""
if dt is None:
return None
if dt.tzinfo:
return dt.astimezone(UTC)
return dt.replace(tzinfo=UTC)
def format_datetime(dt: datetime | None) -> str | None:
"""Format a datetime to ISO 8601 string with Z suffix for UTC."""
if dt is None:
return None
utc_dt = _utc_datetime(dt)
return utc_dt.isoformat().replace("+00:00", "Z") if utc_dt else None
# -------------------------------------------------------------------------
# API structs - inherit from db structs, add uuid for serialization
# -------------------------------------------------------------------------
class ApiUser(User, kw_only=True):
"""User with uuid serialized."""
uuid: UUID
@classmethod
def from_db(cls, u: User) -> "ApiUser":
return cls(uuid=u.uuid, **msgspec.structs.asdict(u))
class ApiOrg(Org, kw_only=True):
"""Org with uuid serialized."""
uuid: UUID
@classmethod
def from_db(cls, o: Org) -> "ApiOrg":
return cls(uuid=o.uuid, **msgspec.structs.asdict(o))
class ApiRole(Role, kw_only=True):
"""Role with uuid serialized."""
uuid: UUID
@classmethod
def from_db(cls, r: Role) -> "ApiRole":
return cls(uuid=r.uuid, **msgspec.structs.asdict(r))
class ApiPermission(Permission, kw_only=True):
"""Permission with uuid serialized."""
uuid: UUID
@classmethod
def from_db(cls, p: Permission) -> "ApiPermission":
return cls(uuid=p.uuid, **msgspec.structs.asdict(p))
class ApiSession(msgspec.Struct):
"""Session for API responses with computed fields."""
id: str
credential_uuid: UUID = msgspec.field(name="credential")
host: str
ip: str
user_agent: str
last_renewed: datetime
is_current: bool = False
is_current_host: bool = False
@classmethod
def from_db(
cls,
s, # Session
*,
current_key: str,
normalized_host: str | None,
expires_delta, # timedelta
) -> "ApiSession":
return cls(
id=s.key,
credential_uuid=s.credential_uuid,
host=s.host,
ip=s.ip,
user_agent=useragent.compact_user_agent(s.user_agent),
last_renewed=s.expiry - expires_delta,
is_current=s.key == current_key,
is_current_host=bool(
normalized_host and s.host and s.host == normalized_host
),
)
+1 -1
View File
@@ -11,7 +11,7 @@ __all__ = ["path", "file", "read", "is_dev_mode"]
def _get_dev_server() -> str | None: def _get_dev_server() -> str | None:
"""Get the dev server URL from environment, or None if not in dev mode.""" """Get the dev server URL from environment, or None if not in dev mode."""
return os.environ.get("PASKIA_DEVMODE") or None return os.environ.get("FASTAPI_VUE_FRONTEND_URL") or None
def _resolve_static_dir() -> Path: def _resolve_static_dir() -> Path:
+1 -2
View File
@@ -3,7 +3,7 @@
import json import json
import os import os
from functools import lru_cache from functools import lru_cache
from urllib.parse import urlsplit from urllib.parse import urlparse, urlsplit
@lru_cache(maxsize=1) @lru_cache(maxsize=1)
@@ -24,7 +24,6 @@ def dedicated_auth_host() -> str | None:
auth_host = _load_config().get("auth_host") auth_host = _load_config().get("auth_host")
if not auth_host: if not auth_host:
return None return None
from urllib.parse import urlparse
parsed = urlparse(auth_host if "://" in auth_host else f"//{auth_host}") parsed = urlparse(auth_host if "://" in auth_host else f"//{auth_host}")
return parsed.netloc or parsed.path or None return parsed.netloc or parsed.path or None
+16 -5
View File
@@ -3,9 +3,8 @@
from collections.abc import Sequence from collections.abc import Sequence
from fnmatch import fnmatchcase from fnmatch import fnmatchcase
from paskia.globals import db from paskia import db
from paskia.util.hostutil import normalize_host from paskia.util.hostutil import normalize_host
from paskia.util.tokens import session_key
__all__ = ["has_any", "has_all", "session_context"] __all__ = ["has_any", "has_all", "session_context"]
@@ -17,16 +16,28 @@ def _match(perms: set[str], patterns: Sequence[str]):
) )
def _get_effective_scopes(ctx) -> set[str]:
"""Get effective permission scopes from context.
Returns scopes from ctx.permissions (filtered by org) if available,
otherwise falls back to ctx.role.permissions for backwards compatibility.
"""
if ctx.permissions:
return {p.scope for p in ctx.permissions}
# Fallback for contexts without effective permissions computed
return set(ctx.role.permissions or [])
def has_any(ctx, patterns: Sequence[str]) -> bool: def has_any(ctx, patterns: Sequence[str]) -> bool:
return any(_match(ctx.role.permissions, patterns)) if ctx else False return any(_match(_get_effective_scopes(ctx), patterns)) if ctx else False
def has_all(ctx, patterns: Sequence[str]) -> bool: def has_all(ctx, patterns: Sequence[str]) -> bool:
return all(_match(ctx.role.permissions, patterns)) if ctx else False return all(_match(_get_effective_scopes(ctx), patterns)) if ctx else False
async def session_context(auth: str | None, host: str | None = None): async def session_context(auth: str | None, host: str | None = None):
if not auth: if not auth:
return None return None
normalized_host = normalize_host(host) if host else None normalized_host = normalize_host(host) if host else None
return await db.instance.get_session_context(session_key(auth), normalized_host) return db.data().session_ctx(auth, normalized_host)
+5 -4
View File
@@ -1,7 +1,8 @@
"""Utility functions for session validation and checking.""" """Utility functions for session validation and checking."""
from datetime import datetime, timezone from datetime import UTC, datetime
from paskia.authsession import EXPIRES
from paskia.db import SessionContext from paskia.db import SessionContext
from paskia.util.timeutil import parse_duration from paskia.util.timeutil import parse_duration
@@ -27,11 +28,11 @@ def check_session_age(ctx: SessionContext, max_age: str | None) -> bool:
max_age_delta = parse_duration(max_age) max_age_delta = parse_duration(max_age)
# Use credential's last_used time if available, fall back to session renewed # Use credential's last_used time if available, fall back to session renewed time
if ctx.credential and ctx.credential.last_used: if ctx.credential and ctx.credential.last_used:
auth_time = ctx.credential.last_used auth_time = ctx.credential.last_used
else: else:
auth_time = ctx.session.renewed auth_time = ctx.session.expiry - EXPIRES
time_since_auth = datetime.now(timezone.utc) - auth_time time_since_auth = datetime.now(UTC) - auth_time
return time_since_auth <= max_age_delta return time_since_auth <= max_age_delta
+36 -8
View File
@@ -1,6 +1,7 @@
"""Startup configuration box formatting utilities.""" """Startup configuration box formatting utilities."""
import os import os
import re
from sys import stderr from sys import stderr
from typing import TYPE_CHECKING from typing import TYPE_CHECKING
@@ -11,12 +12,26 @@ if TYPE_CHECKING:
BOX_WIDTH = 60 # Inner width (excluding box chars) BOX_WIDTH = 60 # Inner width (excluding box chars)
# ANSI color codes
RESET = "\033[0m"
YELLOW = "\033[33m" # Dark yellow
BRIGHT_YELLOW = "\033[93m" # Bright yellow
BRIGHT_WHITE = "\033[1;37m" # Bold bright white
def _visible_len(text: str) -> int:
"""Calculate visible length of text, ignoring ANSI escape codes."""
return len(re.sub(r"\033\[[0-9;]*m", "", text))
def line(text: str = "") -> str: def line(text: str = "") -> str:
"""Format a line inside the box with proper padding, truncating if needed.""" """Format a line inside the box with proper padding, truncating if needed."""
if len(text) > BOX_WIDTH: visible = _visible_len(text)
if visible > BOX_WIDTH:
text = text[: BOX_WIDTH - 1] + "" text = text[: BOX_WIDTH - 1] + ""
return f"{text:<{BOX_WIDTH}}\n" visible = BOX_WIDTH
padding = BOX_WIDTH - visible
return f"{text}{' ' * padding}\n"
def top() -> str: def top() -> str:
@@ -29,19 +44,32 @@ def bottom() -> str:
def print_startup_config(config: "PaskiaConfig") -> None: def print_startup_config(config: "PaskiaConfig") -> None:
"""Print server configuration on startup.""" """Print server configuration on startup."""
# Key graphic with yellow shading (bright for highlights, dark for body)
Y = YELLOW # Dark yellow for main body
B = BRIGHT_YELLOW # Bright yellow for highlights/edges
W = BRIGHT_WHITE # Bold white for URL
R = RESET
lines = [top()] lines = [top()]
lines.append(line(" ▄▄▄▄▄")) lines.append(line(f" {B}▄▄▄▄▄{R}"))
lines.append(line("█ █ Paskia " + __version__)) lines.append(line(f"{B}{Y} {B}{R} Paskia " + __version__))
lines.append(line("█ █▄▄▄▄▄▄▄▄▄▄▄▄")) lines.append(line(f"{B}{Y} {B}{Y}▄▄▄▄▄▄▄▄▄▄▄▄{R}"))
lines.append(line("█ █▀▀▀▀█▀▀█▀▀█ " + config.site_url + config.site_path)) lines.append(
lines.append(line(" ▀▀▀▀▀")) line(
f"{B}{Y} {B}{Y}▀▀▀▀{B}{Y}▀▀{B}{Y}▀▀{B}{R} {W}"
+ config.site_url
+ config.site_path
+ R
)
)
lines.append(line(f" {Y}▀▀▀▀▀{R}"))
# Format auth host section # Format auth host section
if config.auth_host: if config.auth_host:
lines.append(line(f"Auth Host: {config.auth_host}")) lines.append(line(f"Auth Host: {config.auth_host}"))
# Show frontend URL if in dev mode # Show frontend URL if in dev mode
devmode = os.environ.get("PASKIA_DEVMODE") devmode = os.environ.get("FASTAPI_VUE_FRONTEND_URL")
if devmode: if devmode:
lines.append(line(f"Dev Frontend: {devmode}")) lines.append(line(f"Dev Frontend: {devmode}"))
-44
View File
@@ -1,44 +0,0 @@
import hashlib
import secrets
import base64url
from paskia.util.passphrase import is_well_formed
def create_token() -> str:
return secrets.token_urlsafe(12) # 16 characters Base64
def session_key(token: str) -> bytes:
if len(token) != 16:
raise ValueError("Session token must be exactly 16 characters long")
return b"sess" + base64url.dec(token)
def encode_session_key(key: bytes) -> str:
"""Encode an opaque session key for external representation."""
return base64url.enc(key)
def decode_session_key(encoded: str) -> bytes:
"""Decode an opaque session key from its public representation."""
if not encoded:
raise ValueError("Invalid session identifier")
try:
raw = base64url.dec(encoded)
except Exception as exc: # pragma: no cover - defensive
raise ValueError("Invalid session identifier") from exc
if not raw.startswith(b"sess"):
raise ValueError("Invalid session identifier")
return raw
def reset_key(passphrase: str) -> bytes:
if not is_well_formed(passphrase):
raise ValueError(
"Trying to reset with a session token in place of a passphrase"
if len(passphrase) == 16
else "Invalid passphrase format"
)
return b"rset" + hashlib.sha512(passphrase.encode()).digest()[:12]
+45 -141
View File
@@ -1,159 +1,63 @@
"""User information formatting and retrieval logic.""" """User information formatting and retrieval logic."""
from datetime import timezone from paskia import aaguid, db
from paskia.authsession import EXPIRES
from paskia import aaguid from paskia.db import SessionContext
from paskia.authsession import session_key from paskia.util import hostutil, permutil
from paskia.globals import db from paskia.util.apistructs import ApiSession
from paskia.util import hostutil, permutil, tokens, useragent
def _format_datetime(dt): def build_session_context(ctx: SessionContext) -> dict:
"""Format a datetime object to ISO 8601 string with UTC timezone.""" """Build session context dict from SessionContext."""
if dt is None: result = {
return None "user": {"uuid": ctx.user.uuid, "display_name": ctx.user.display_name},
if dt.tzinfo: "org": {"uuid": ctx.org.uuid, "display_name": ctx.org.display_name},
return dt.astimezone(timezone.utc).isoformat().replace("+00:00", "Z") "role": {"uuid": ctx.role.uuid, "display_name": ctx.role.display_name},
else: "permissions": [p.scope for p in ctx.permissions],
return dt.replace(tzinfo=timezone.utc).isoformat().replace("+00:00", "Z") }
if ctx.user.theme:
result["user"]["theme"] = ctx.user.theme
return result
async def format_user_info( async def build_user_info(
*, *,
user_uuid, user_uuid,
auth: str, auth: str,
session_record, session_record,
request_host: str | None, request_host: str | None,
) -> dict: ) -> dict:
"""Format complete user information for authenticated users. """Build user info dict for authenticated users."""
Args:
user_uuid: UUID of the user to fetch information for
auth: Authentication token
session_record: Current session record
request_host: Host header from the request
Returns:
Dictionary containing formatted user information including:
- User details
- Organization and role information
- Credentials list
- Sessions list
- Permissions
"""
u = await db.instance.get_user_by_uuid(user_uuid)
ctx = await permutil.session_context(auth, request_host) ctx = await permutil.session_context(auth, request_host)
user = db.data().users[user_uuid]
normalized_host = hostutil.normalize_host(request_host)
# Fetch and format credentials credentials = sorted(user.credentials, key=lambda c: c.created_at)
credential_ids = await db.instance.get_credentials_by_user_uuid(user_uuid) return {
credentials: list[dict] = [] "ctx": build_session_context(ctx),
user_aaguids: set[str] = set() "created_at": ctx.user.created_at,
"last_seen": ctx.user.last_seen,
for cred_id in credential_ids: "visits": ctx.user.visits,
try: "credentials": [
c = await db.instance.get_credential_by_id(cred_id)
except ValueError:
continue
aaguid_str = str(c.aaguid)
user_aaguids.add(aaguid_str)
credentials.append(
{ {
"credential_uuid": str(c.uuid), "credential": c.uuid,
"aaguid": aaguid_str, "aaguid": c.aaguid,
"created_at": _format_datetime(c.created_at), "created_at": c.created_at,
"last_used": _format_datetime(c.last_used), "last_used": c.last_used,
"last_verified": _format_datetime(c.last_verified), "last_verified": c.last_verified,
"sign_count": c.sign_count, "sign_count": c.sign_count,
"is_current_session": session_record.credential_uuid == c.uuid, "is_current_session": session_record.credential == c.uuid,
} }
) for c in credentials
],
credentials.sort(key=lambda cred: cred["created_at"]) "aaguid_info": aaguid.filter(c.aaguid for c in credentials),
aaguid_info = aaguid.filter(user_aaguids) "sessions": [
ApiSession.from_db(
# Format role and org information s,
role_info = None current_key=auth,
org_info = None normalized_host=normalized_host,
effective_permissions: list[str] = [] expires_delta=EXPIRES,
is_global_admin = False )
is_org_admin = False for s in user.sessions
],
if ctx:
role_info = {
"uuid": str(ctx.role.uuid),
"display_name": ctx.role.display_name,
"permissions": ctx.role.permissions,
}
org_info = {
"uuid": str(ctx.org.uuid),
"display_name": ctx.org.display_name,
"permissions": ctx.org.permissions,
}
effective_permissions = [p.id for p in (ctx.permissions or [])]
is_global_admin = "auth:admin" in (role_info["permissions"] or [])
is_org_admin = any(
p.startswith("auth:org:") for p in (role_info["permissions"] or [])
)
# Format sessions
normalized_request_host = hostutil.normalize_host(request_host)
session_records = await db.instance.list_sessions_for_user(user_uuid)
current_session_key = session_key(auth)
sessions_payload: list[dict] = []
for entry in session_records:
sessions_payload.append(
{
"id": tokens.encode_session_key(entry.key),
"credential_uuid": str(entry.credential_uuid),
"host": entry.host,
"ip": entry.ip,
"user_agent": useragent.compact_user_agent(entry.user_agent),
"last_renewed": _format_datetime(entry.renewed),
"is_current": entry.key == current_session_key,
"is_current_host": bool(
normalized_request_host
and entry.host
and entry.host == normalized_request_host
),
}
)
return {
"authenticated": True,
"user": {
"user_uuid": str(u.uuid),
"user_name": u.display_name,
"created_at": _format_datetime(u.created_at),
"last_seen": _format_datetime(u.last_seen),
"visits": u.visits,
},
"org": org_info,
"role": role_info,
"permissions": effective_permissions,
"is_global_admin": is_global_admin,
"is_org_admin": is_org_admin,
"credentials": credentials,
"aaguid_info": aaguid_info,
"sessions": sessions_payload,
}
async def format_reset_user_info(user_uuid, reset_token) -> dict:
"""Format minimal user information for reset token requests.
Args:
user_uuid: UUID of the user
reset_token: Reset token record
Returns:
Dictionary with minimal user info for password reset flow
"""
u = await db.instance.get_user_by_uuid(user_uuid)
return {
"authenticated": False,
"session_type": reset_token.token_type,
"user": {"user_uuid": str(u.uuid), "user_name": u.display_name},
} }
+71
View File
@@ -0,0 +1,71 @@
"""Vite dev server proxy for fetching frontend files during development.
In dev mode (FASTAPI_VUE_FRONTEND_URL set), fetches files from Vite.
In production, reads from the static build directory.
This complements fastapi_vue.Frontend which handles static file serving
but doesn't provide server-side fetching of HTML content.
"""
import asyncio
import mimetypes
import os
from importlib import resources
from pathlib import Path
import httpx
__all__ = ["read"]
def _get_dev_server() -> str | None:
"""Get the dev server URL from environment, or None if not in dev mode."""
return os.environ.get("FASTAPI_VUE_FRONTEND_URL") or None
def _resolve_static_dir() -> Path:
"""Resolve the static files directory."""
# Try packaged path via importlib.resources (works for wheel/installed).
try: # pragma: no cover - trivial path resolution
pkg_dir = resources.files("paskia") / "frontend-build"
fs_path = Path(str(pkg_dir))
if fs_path.is_dir():
return fs_path
except Exception: # pragma: no cover - defensive
pass
# Fallback for editable/development before build.
return Path(__file__).parent.parent / "frontend-build"
_static_dir: Path = _resolve_static_dir()
async def read(filepath: str) -> tuple[bytes, int, dict[str, str]]:
"""Read file content and return response tuple.
In dev mode, fetches from the Vite dev server.
In production, reads from the static build directory.
Args:
filepath: Path relative to frontend root, e.g. "/auth/index.html"
Returns:
Tuple of (content, status_code, headers) suitable for
FastAPI Response(*args).
"""
dev_server = _get_dev_server()
if dev_server:
async with httpx.AsyncClient() as client:
resp = await client.get(f"{dev_server}{filepath}")
resp.raise_for_status()
mime = resp.headers.get("content-type", "application/octet-stream")
# Strip charset suffix if present
mime = mime.split(";")[0].strip()
return resp.content, resp.status_code, {"content-type": mime}
else:
# Production: read from static build
file_path = _static_dir / filepath.lstrip("/")
content = await asyncio.to_thread(file_path.read_bytes)
mime, _ = mimetypes.guess_type(str(file_path))
return content, 200, {"content-type": mime or "application/octet-stream"}
+18 -8
View File
@@ -6,6 +6,7 @@ build-backend = "hatchling.build"
name = "paskia" name = "paskia"
dynamic = ["version"] dynamic = ["version"]
description = "Passkey Auth made easy: all sites and APIs can be guarded even without any changes on the protected site." description = "Passkey Auth made easy: all sites and APIs can be guarded even without any changes on the protected site."
readme = "README.md"
keywords = [ "forward_auth", "auth_request", "FastAPI" ] keywords = [ "forward_auth", "auth_request", "FastAPI" ]
authors = [ authors = [
{name = "Leo Vasanko"}, {name = "Leo Vasanko"},
@@ -15,13 +16,19 @@ dependencies = [
"websockets>=12.0", "websockets>=12.0",
"webauthn>=1.11.1", "webauthn>=1.11.1",
"base64url>=1.0.0", "base64url>=1.0.0",
"sqlalchemy[asyncio]>=2.0.0",
"aiosqlite>=0.19.0",
"uuid7-standard>=1.0.0", "uuid7-standard>=1.0.0",
"pyjwt>=2.8.0", "pyjwt>=2.8.0",
"user-agents>=2.2.0", "user-agents>=2.2.0",
"jsondiff>=2.2.1",
"msgspec>=0.20.0",
"aiofiles>=25.1.0",
"fastapi-vue>=0.3.0",
] ]
requires-python = ">=3.10" requires-python = ">=3.11"
[project.urls]
Homepage = "https://git.zi.fi/LeoVasanko/paskia"
Repository = "https://github.com/LeoVasanko/paskia"
[tool.hatch.version] [tool.hatch.version]
source = "vcs" source = "vcs"
@@ -37,6 +44,10 @@ dev = [
"pytest-asyncio>=0.24.0", "pytest-asyncio>=0.24.0",
"httpx>=0.27.0", "httpx>=0.27.0",
] ]
migrate = [
"sqlalchemy[asyncio]>=2.0.0",
"aiosqlite>=0.19.0",
]
[tool.coverage.run] [tool.coverage.run]
source = ["paskia"] source = ["paskia"]
@@ -63,12 +74,8 @@ filterwarnings = [
"ignore::DeprecationWarning", "ignore::DeprecationWarning",
] ]
[tool.ruff]
target-version = "py39"
line-length = 88
[tool.ruff.lint] [tool.ruff.lint]
select = ["E", "F", "I", "N", "W", "UP"] select = ["E", "F", "I", "N", "W", "UP", "PLC0415"]
ignore = ["E501"] # Line too long ignore = ["E501"] # Line too long
isort.known-first-party = ["paskia"] isort.known-first-party = ["paskia"]
@@ -84,7 +91,10 @@ dev = [
[project.scripts] [project.scripts]
paskia = "paskia.fastapi.__main__:main" paskia = "paskia.fastapi.__main__:main"
paskia-migrate = "paskia.migrate:main"
[tool.hatch.build] [tool.hatch.build]
artifacts = ["paskia/frontend-build"] artifacts = ["paskia/frontend-build"]
targets.sdist.hooks.custom.path = "scripts/build-frontend.py" targets.sdist.hooks.custom.path = "scripts/build-frontend.py"
packages = ["paskia"]
only-packages = true
+24 -24
View File
@@ -1,43 +1,43 @@
import shutil """Hatch build hook for building paskia-js and Vue frontend during package build."""
import subprocess import subprocess
from pathlib import Path from pathlib import Path
from sys import stderr from sys import stderr
from hatchling.builders.hooks.plugin.interface import BuildHookInterface from hatchling.builders.hooks.plugin.interface import BuildHookInterface # type: ignore
# Import utilities from fastapi-vue
exec(Path(__file__).parent.joinpath("fastapi-vue", "util.py").read_text("UTF-8")) # noqa: S102
def run(cmd, **kwargs): def run(cmd, **kwargs):
"""Run a command and display it."""
display_cmd = [Path(cmd[0]).name, *cmd[1:]] display_cmd = [Path(cmd[0]).name, *cmd[1:]]
stderr.write(f"### {' '.join(display_cmd)}\n") stderr.write(f"### {' '.join(display_cmd)}\n")
subprocess.run(cmd, check=True, **kwargs) subprocess.run(cmd, check=True, **kwargs)
def find_build_tool():
install = [
("deno", "install", "--allow-scripts=npm:vue-demi"),
("npm", "install"),
("bun", "--bun", "install"),
]
build = [
("deno", "task", "build"),
("npm", "run", "build"),
("bun", "--bun", "run", "build"),
]
for i, b in zip(install, build, strict=False):
if tool := shutil.which(i[0]):
return [tool, *i[1:]], [tool, *b[1:]]
raise RuntimeError("Deno, npm or Bun is required for building but none was found")
class CustomBuildHook(BuildHookInterface): class CustomBuildHook(BuildHookInterface):
"""Build hook that compiles paskia-js and Vue frontend before packaging."""
def initialize(self, version, build_data): def initialize(self, version, build_data):
super().initialize(version, build_data) super().initialize(version, build_data)
stderr.write(">>> Building the frontend\n") stderr.write(">>> Building paskia-js library\n")
install_cmd, build_cmd = find_build_tool() install_cmd, build_cmd = find_build_tool() # noqa: F821 # type: ignore
try:
# Install dependencies for paskia-js
run(install_cmd, cwd="paskia-js")
stderr.write("\n")
# Build paskia-js
run(build_cmd, cwd="paskia-js")
stderr.write("\n")
except Exception as e:
stderr.write(f"Error occurred while building paskia-js: {e}\n")
raise
stderr.write(">>> Building the frontend\n")
try: try:
run(install_cmd, cwd="frontend") run(install_cmd, cwd="frontend")
+277
View File
@@ -0,0 +1,277 @@
#!/usr/bin/env -S uv run
# auto-upgrade@fastapi-vue-setup - remove this if you modify this file
"""Run Vite development server for frontend and FastAPI backend with auto-reload.
Usage:
uv run scripts/devserver.py [host:port] [--backend host:port]
The optional host:port argument sets where the Vite frontend listens.
Supported forms: host[:port], :port (all interfaces), or just port.
The --backend option sets where the FastAPI backend listens (default: localhost:5180).
Environment:
JS_RUNTIME Path or name of JS runtime to use (deno, npm/node or bun).
FASTAPI_VUE_FRONTEND_URL Set by this script for the backend to know where Vite is.
"""
import argparse
import asyncio
import contextlib
import os
from pathlib import Path
from sys import stderr
import httpx
from fastapi_vue.hostutil import parse_endpoint
exec((Path(__file__).parent / "fastapi-vue/util.py").read_text("UTF-8")) # noqa: S102
DEFAULT_VITE_PORT = 5173
DEFAULT_BACKEND_PORT = 5180
FRONTEND_PATH = Path(__file__).parent.parent / "frontend"
EPILOG = """
scripts/devserver.py # Default ports on localhost
scripts/devserver.py 3000 # Vite on localhost:3000
scripts/devserver.py :3000 --backend 8000 # *:3000, localhost:8000
"""
BUN_BUG = """\
┃ ⚠️ Bun cannot correctly proxy API requests to the backend.
┃ Bug report: https://github.com/oven-sh/bun/issues/9882
┃ Consider using deno or npm instead for development.
"""
def resolve_frontend_tools(
vite_port: int, all_ifaces: bool
) -> tuple[list[str], list[str], str]:
"""Resolve frontend install and dev commands.
Returns (install_cmd, dev_cmd, tool_name).
Raises SystemExit if tools are not available.
"""
if not (FRONTEND_PATH / "package.json").exists():
stderr.write(f"┃ ⚠️ Frontend source not found at {FRONTEND_PATH}\n")
raise SystemExit(1)
result = find_js_runtime() # noqa # type: ignore
if result is None:
if not os.environ.get("JS_RUNTIME"):
stderr.write("┃ ⚠️ deno, npm or bun needed to run the frontend server.\n")
raise SystemExit(1)
tool, name = result
install_args = {
"deno": ("install", "--quiet", "--allow-scripts=npm:vue-demi"),
"npm": ("install", "--silent"),
"bun": ("install", "--silent"),
}
dev_args = {
"deno": ("run", "dev", "--"),
"npm": ("--silent", "run", "dev", "--"),
"bun": ("run", "dev", "--"),
}
install_cmd = [tool, *install_args[name]]
dev_cmd = [
tool,
*dev_args[name],
"--clearScreen=false",
f"--port={vite_port}",
]
if all_ifaces:
dev_cmd.append("--host")
if name == "bun":
stderr.write(BUN_BUG)
return install_cmd, dev_cmd, name
async def wait_for_backend(host: str, port: int):
"""Wait for the backend to be ready by polling the health endpoint."""
max_attempts = 50
url = f"http://{host}:{port}"
async with httpx.AsyncClient() as client:
for attempt in range(max_attempts):
try:
await client.get(url, timeout=1.0)
stderr.write("✓ Backend ready!\n")
return True
except httpx.RequestError:
if attempt == max_attempts - 1:
stderr.write("┃ ⚠️ Backend didn't start in time\n")
return False
await asyncio.sleep(0.1)
return False
async def _terminate_process(proc: asyncio.subprocess.Process, name: str) -> None:
"""Gracefully terminate a subprocess."""
if proc.returncode is not None:
return
try:
proc.terminate()
except ProcessLookupError:
return
try:
await asyncio.wait_for(proc.wait(), timeout=2)
except TimeoutError:
try:
proc.kill()
except ProcessLookupError:
return
await proc.wait()
async def run_devserver(
vite_port: int,
all_ifaces: bool,
backend_host: str,
backend_port: int,
) -> None:
"""Run the development server with install, backend, and frontend."""
install_cmd, dev_cmd, tool_name = resolve_frontend_tools(vite_port, all_ifaces)
# Tell the backend where the Vite dev server is
os.environ["FASTAPI_VUE_FRONTEND_URL"] = f"http://localhost:{vite_port}"
# Tell Vite where the backend is (for proxying /api requests)
os.environ["FASTAPI_VUE_BACKEND_URL"] = f"http://{backend_host}:{backend_port}"
backend_cmd = [
"uvicorn",
"paskia.app:app",
"--host",
backend_host,
"--port",
str(backend_port),
"--reload",
]
cwd = str(Path(__file__).parent.parent)
frontend_cwd = str(FRONTEND_PATH)
backend_proc: asyncio.subprocess.Process | None = None
install_proc: asyncio.subprocess.Process | None = None
frontend_proc: asyncio.subprocess.Process | None = None
try:
# Start install (concurrent with backend)
stderr.write(f">>> {tool_name} {' '.join(install_cmd[1:])}\n")
install_proc = await asyncio.create_subprocess_exec(
*install_cmd, cwd=frontend_cwd
)
await asyncio.sleep(0.1)
# Start backend (concurrent with install)
stderr.write(f">>> {' '.join(backend_cmd)}\n")
backend_proc = await asyncio.create_subprocess_exec(*backend_cmd, cwd=cwd)
# Wait for install to complete and backend to be ready
install_task = asyncio.create_task(install_proc.wait(), name="install")
backend_ready_task = asyncio.create_task(
wait_for_backend(backend_host, backend_port), name="backend_ready"
)
done, pending = await asyncio.wait(
{install_task, backend_ready_task},
return_when=asyncio.FIRST_COMPLETED,
)
for task in done:
if task.get_name() == "install":
if task.result() != 0:
stderr.write("┃ ⚠️ Install failed\n")
raise SystemExit(1)
elif task.get_name() == "backend_ready" and not task.result():
raise SystemExit(1)
if pending:
done2, _ = await asyncio.wait(pending)
for task in done2:
if task.get_name() == "install":
if task.result() != 0:
stderr.write("┃ ⚠️ Install failed\n")
raise SystemExit(1)
elif task.get_name() == "backend_ready" and not task.result():
raise SystemExit(1)
install_proc = None
# Start Vite dev server
stderr.write(f">>> {tool_name} {' '.join(dev_cmd[1:])}\n")
frontend_proc = await asyncio.create_subprocess_exec(*dev_cmd, cwd=frontend_cwd)
# Wait for either process to exit
done, pending = await asyncio.wait(
{
asyncio.create_task(backend_proc.wait(), name="backend"),
asyncio.create_task(frontend_proc.wait(), name="frontend"),
},
return_when=asyncio.FIRST_COMPLETED,
)
for t in done:
t.result()
for t in pending:
t.cancel()
except asyncio.CancelledError:
stderr.write("\n✓ Shutting down...\n")
finally:
if frontend_proc is not None:
await _terminate_process(frontend_proc, "frontend")
if install_proc is not None:
await _terminate_process(install_proc, "install")
if backend_proc is not None:
await _terminate_process(backend_proc, "backend")
def main():
parser = argparse.ArgumentParser(
description="Run Vite and FastAPI development servers",
formatter_class=argparse.RawDescriptionHelpFormatter,
epilog=EPILOG,
)
parser.add_argument(
"frontend",
nargs="?",
metavar="host:port",
help="Vite frontend endpoint (default: localhost:5173)",
)
parser.add_argument(
"--backend",
metavar="host:port",
help="FastAPI backend endpoint (default: localhost:5180)",
)
args = parser.parse_args()
# parse_endpoint returns list of dicts with host/port or uds keys
# Multiple entries means bind all interfaces (IPv4 + IPv6)
vite_endpoints = parse_endpoint(args.frontend, DEFAULT_VITE_PORT)
backend_endpoints = parse_endpoint(args.backend, DEFAULT_BACKEND_PORT)
# Vite doesn't support unix sockets
if "uds" in vite_endpoints[0]:
stderr.write("┃ ⚠️ Unix sockets not supported for frontend\n")
raise SystemExit(1)
if "uds" in backend_endpoints[0]:
stderr.write("┃ ⚠️ Unix sockets not supported for backend\n")
raise SystemExit(1)
vite_port = vite_endpoints[0]["port"]
all_ifaces = len(vite_endpoints) > 1
backend_host = backend_endpoints[0]["host"]
backend_port = backend_endpoints[0]["port"]
with contextlib.suppress(KeyboardInterrupt):
asyncio.run(run_devserver(vite_port, all_ifaces, backend_host, backend_port))
if __name__ == "__main__":
main()
+32 -13
View File
@@ -6,12 +6,17 @@ not from the installed package. It starts both the Vite frontend dev server
and the FastAPI backend with auto-reload enabled. and the FastAPI backend with auto-reload enabled.
Usage: Usage:
uv run scripts/dev.py [host:port] [options...] uv run scripts/devserver.py [host:port] [options...]
The optional host:port argument sets where the Vite frontend listens. The optional host:port argument sets where the Vite frontend listens.
All other options are forwarded to `paskia serve`. All other options are forwarded to `paskia`.
Backend always listens on localhost:4402. Backend always listens on localhost:4402.
Environment:
FASTAPI_VUE_FRONTEND_URL Set by this script for the backend to know where Vite is.
FASTAPI_VUE_BACKEND_URL Set by this script for Vite to know where to proxy API calls.
PASKIA_SITE_URL User-facing URL for reset links (Caddy HTTPS or Vite HTTP).
Options: Options:
--caddy Run Caddy as HTTPS proxy on port 443 (requires sudo) --caddy Run Caddy as HTTPS proxy on port 443 (requires sudo)
--rp-id HOST Relying Party ID (used as hostname for Caddy) --rp-id HOST Relying Party ID (used as hostname for Caddy)
@@ -118,7 +123,13 @@ def parse_endpoint(
return host, port, None, False return host, port, None, False
def run_vite(vite_url: str, vite_host: str | None, vite_port: int, auth_host: str | None = None): def run_vite(
vite_url: str,
vite_host: str | None,
vite_port: int,
env: dict,
auth_host: str | None = None,
):
"""Spawn the frontend dev server (deno, npm, or bunx) as a background process.""" """Spawn the frontend dev server (deno, npm, or bunx) as a background process."""
devpath = Path(__file__).parent.parent / "frontend" devpath = Path(__file__).parent.parent / "frontend"
if not (devpath / "package.json").exists(): if not (devpath / "package.json").exists():
@@ -160,10 +171,12 @@ def run_vite(vite_url: str, vite_host: str | None, vite_port: int, auth_host: st
full_cmd = cmd + vite_args full_cmd = cmd + vite_args
stderr.write(f">>> {' '.join([tool_name, *full_cmd[1:]])}\n") stderr.write(f">>> {' '.join([tool_name, *full_cmd[1:]])}\n")
vite_env = os.environ.copy() vite_env = env.copy()
if auth_host: if auth_host:
vite_env["PASKIA_AUTH_HOST"] = auth_host vite_env["PASKIA_AUTH_HOST"] = auth_host
vite_process = subprocess.Popen(full_cmd, cwd=str(devpath), shell=False, env=vite_env) vite_process = subprocess.Popen(
full_cmd, cwd=str(devpath), shell=False, env=vite_env
)
except Exception as e: except Exception as e:
stderr.write( stderr.write(
f"┃ ⚠️ Vite couldn't start: {e}\n" f"┃ ⚠️ Vite couldn't start: {e}\n"
@@ -387,7 +400,7 @@ def main():
if all_ifaces: if all_ifaces:
vite_host = "0.0.0.0" vite_host = "0.0.0.0"
# Build Vite URL for PASKIA_DEVMODE (always use localhost for URL) # Build Vite URL for FASTAPI_VUE_FRONTEND_URL (always use localhost for URL)
vite_url = f"http://localhost:{vite_port}" vite_url = f"http://localhost:{vite_port}"
# Compute origins for Caddy (user-specified or auto-generated) # Compute origins for Caddy (user-specified or auto-generated)
@@ -420,15 +433,21 @@ def main():
if not run_caddy(caddy_origins, vite_port): if not run_caddy(caddy_origins, vite_port):
raise SystemExit(1) raise SystemExit(1)
# Start Vite dev server # Set dev mode env vars for subprocesses (fastapi-vue convention)
run_vite(vite_url, vite_host, vite_port, args.auth_host)
# Set dev mode with Vite URL in environment for subprocess
env = os.environ.copy() env = os.environ.copy()
env["PASKIA_DEVMODE"] = vite_url env["FASTAPI_VUE_FRONTEND_URL"] = vite_url
env["FASTAPI_VUE_BACKEND_URL"] = f"http://localhost:{BACKEND_PORT}"
# User-facing URL: Caddy HTTPS when running, else Vite HTTP
if args.caddy:
env["PASKIA_SITE_URL"] = caddy_origins[0] # auth-host or https://{rp-id}
else:
env["PASKIA_SITE_URL"] = vite_url
# Build command with origin args # Start Vite dev server
cmd = ["paskia", "serve", f"localhost:{BACKEND_PORT}"] run_vite(vite_url, vite_host, vite_port, env, args.auth_host)
# Build command with origin args (no serve subcommand, host:port is first arg)
cmd = ["paskia", f"localhost:{BACKEND_PORT}"]
# Pass through rp-id (always pass, has default) # Pass through rp-id (always pass, has default)
cmd.extend(["--rp-id", args.rp_id]) cmd.extend(["--rp-id", args.rp_id])
+34
View File
@@ -0,0 +1,34 @@
"""Hatch build hook for building Vue frontend during package build."""
import subprocess
from pathlib import Path
from sys import stderr
from hatchling.builders.hooks.plugin.interface import BuildHookInterface # type: ignore
exec(Path(__file__).with_name("util.py").read_text("UTF-8")) # noqa: S102
def run(cmd, **kwargs):
"""Run a command and display it."""
display_cmd = [Path(cmd[0]).name, *cmd[1:]]
stderr.write(f"### {' '.join(display_cmd)}\n")
subprocess.run(cmd, check=True, **kwargs)
class CustomBuildHook(BuildHookInterface):
"""Build hook that compiles Vue frontend before packaging."""
def initialize(self, version, build_data):
super().initialize(version, build_data)
stderr.write(">>> Building the frontend\n")
install_cmd, build_cmd = find_build_tool() # noqa # type: ignore
try:
run(install_cmd, cwd="frontend")
stderr.write("\n")
run(build_cmd, cwd="frontend")
except Exception as e:
stderr.write(f"Error occurred while building frontend: {e}\n")
raise
+87
View File
@@ -0,0 +1,87 @@
"""Shared utilities for build and dev scripts."""
import os
import shutil
from pathlib import Path
from sys import stderr
def find_js_runtime() -> tuple[str, str] | None:
"""Find a JavaScript runtime from JS_RUNTIME env or auto-detect.
Returns (tool_path, tool_name) where tool_name is "deno", "npm", or "bun".
Returns None if no runtime is found.
"""
options = ["deno", "npm", "bun"]
# Check for JS_RUNTIME environment variable
if js_runtime_env := os.environ.get("JS_RUNTIME"):
js_runtime = js_runtime_env
js_path = Path(js_runtime)
runtime_name = js_path.name
# Map node to npm
if runtime_name == "node":
runtime_name = "npm"
js_runtime = str(js_path.parent / "npm") if js_path.parent.name else "npm"
for option in options:
if option == runtime_name or runtime_name.startswith(option):
tool = shutil.which(js_runtime)
if tool is None:
stderr.write(f"┃ ⚠️ JS_RUNTIME={js_runtime_env} not found\n")
return None
return tool, option
stderr.write(f"┃ ⚠️ JS_RUNTIME={js_runtime_env} not recognized\n")
return None
# Auto-detect
for option in options:
if tool := shutil.which(option):
return tool, option
return None
def find_build_tool():
"""Find JavaScript runtime and construct install/build commands.
Returns (install_cmd, build_cmd) tuples of command lists.
Raises RuntimeError if no runtime is found.
"""
install = {
"deno": ("install", "--allow-scripts=npm:vue-demi"),
"npm": ("install",),
"bun": ("--bun", "install"),
}
# Run vite directly for deno to avoid npm-run-all2/run-p issues
build = {
"deno": ("run", "-A", "npm:vite", "build"),
"npm": ("run", "build"),
"bun": ("--bun", "run", "build"),
}
result = find_js_runtime()
if result is None:
raise RuntimeError(
"Deno, npm or Bun is required for building but none was found"
)
tool, name = result
return [tool, *install[name]], [tool, *build[name]]
def find_dev_tool():
"""Find JavaScript runtime and construct dev command.
Returns (dev_cmd, tool_name) or (None, None) if not found.
"""
dev_args = {
"deno": ("run", "dev", "--"),
"npm": ("--silent", "run", "dev", "--"),
"bun": ("run", "dev", "--"),
}
result = find_js_runtime()
if result is None:
return None, None
tool, name = result
return [tool, *dev_args[name]], name
+84 -97
View File
@@ -11,24 +11,35 @@ in the database to test authenticated endpoints.
import asyncio import asyncio
import os import os
import tempfile
from collections.abc import AsyncGenerator from collections.abc import AsyncGenerator
from datetime import datetime, timezone
from uuid import UUID from uuid import UUID
import httpx import httpx
import pytest import pytest
import pytest_asyncio import pytest_asyncio
import uuid7
from paskia import globals import paskia.db.operations as ops_db
from paskia.db import Credential, Org, Permission, Role, User from paskia import globals as paskia_globals
from paskia.db.sql import DB from paskia.authsession import expires, reset_expires
from paskia.db import (
Credential,
Org,
Permission,
Role,
User,
create_credential,
create_reset_token,
create_role,
create_session,
create_user,
)
from paskia.db.jsonl import JsonlStore
from paskia.db.operations import DB
from paskia.fastapi.mainapp import app
from paskia.fastapi.session import AUTH_COOKIE_NAME from paskia.fastapi.session import AUTH_COOKIE_NAME
from paskia.sansio import Passkey from paskia.sansio import Passkey
from paskia.util.tokens import create_token, session_key from paskia.util.passphrase import generate
# Use in-memory SQLite for tests
os.environ["PASKIA_DB"] = "sqlite+aiosqlite:///:memory:"
@pytest.fixture(scope="session") @pytest.fixture(scope="session")
@@ -41,16 +52,29 @@ def event_loop():
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def test_db() -> AsyncGenerator[DB, None]: async def test_db() -> AsyncGenerator[DB, None]:
"""Create an in-memory SQLite database for testing. """Create an in-memory JSON database for testing.
We use :memory: for speed - each test gets a fresh database. Uses bootstrap() to properly initialize the database with:
- auth:admin and auth:org:admin permissions
- A default organization with Administration role
- An admin user with the Administration role
""" """
db = DB("sqlite+aiosqlite:///:memory:")
await db.init_db() with tempfile.NamedTemporaryFile(suffix=".jsonl", delete=True) as f:
globals.db._instance = db db = DB()
yield db store = JsonlStore(db, f.name)
# Clean up db._store = store
globals.db._instance = None await store.load()
ops_db._db = db
ops_db._store = store
# Bootstrap creates the initial permissions, org, role, and admin user
ops_db.bootstrap(
org_name="Test Organization",
admin_name="Test Admin",
)
yield db
ops_db._db = None
ops_db._store = None
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
@@ -61,118 +85,91 @@ async def passkey_instance() -> Passkey:
rp_name="Test RP", rp_name="Test RP",
origins=["http://localhost:4401"], origins=["http://localhost:4401"],
) )
globals.passkey._instance = pk paskia_globals.passkey._instance = pk
yield pk yield pk
globals.passkey._instance = None paskia_globals.passkey._instance = None
@pytest_asyncio.fixture(scope="function")
async def test_org(test_db: DB, admin_permission: Permission) -> Org:
"""Create a test organization with admin permission."""
org = Org(
uuid=uuid7.create(),
display_name="Test Organization",
permissions=["auth:admin"], # Org can grant this permission
)
await test_db.create_organization(org)
return org
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def admin_permission(test_db: DB) -> Permission: async def admin_permission(test_db: DB) -> Permission:
"""Create the auth:admin permission.""" """Get the auth:admin permission created by bootstrap."""
perm = Permission(id="auth:admin", display_name="Master Admin") return next(p for p in test_db.permissions.values() if p.scope == "auth:admin")
await test_db.create_permission(perm)
return perm
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def test_role(test_db: DB, test_org: Org, admin_permission: Permission) -> Role: async def org_admin_permission(test_db: DB) -> Permission:
"""Create a test role with admin permission.""" """Get the auth:org:admin permission created by bootstrap."""
role = Role( return next(p for p in test_db.permissions.values() if p.scope == "auth:org:admin")
uuid=uuid7.create(),
org_uuid=test_org.uuid,
display_name="Test Admin Role", @pytest_asyncio.fixture(scope="function")
permissions=["auth:admin", f"auth:org:{test_org.uuid}"], async def test_org(test_db: DB) -> Org:
) """Get the test organization created by bootstrap."""
await test_db.create_role(role) # Bootstrap creates exactly one org
return role return next(iter(test_db.orgs.values()))
@pytest_asyncio.fixture(scope="function")
async def test_role(test_db: DB) -> Role:
"""Get the Administration role created by bootstrap."""
# Bootstrap creates exactly one role (Administration)
return next(iter(test_db.roles.values()))
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def user_role(test_db: DB, test_org: Org) -> Role: async def user_role(test_db: DB, test_org: Org) -> Role:
"""Create a test role without admin permission (regular user).""" """Create a test role without admin permission (regular user)."""
role = Role( role = Role.create(
uuid=uuid7.create(), org=test_org.uuid,
org_uuid=test_org.uuid,
display_name="User Role", display_name="User Role",
permissions=[],
) )
await test_db.create_role(role) create_role(role)
return role return role
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def test_user(test_db: DB, test_role: Role) -> User: async def test_user(test_db: DB) -> User:
"""Create a test user with admin role.""" """Get the admin user created by bootstrap."""
user = User( # Bootstrap creates exactly one user (admin)
uuid=uuid7.create(), return next(iter(test_db.users.values()))
display_name="Test Admin",
role_uuid=test_role.uuid,
created_at=datetime.now(timezone.utc),
visits=0,
)
await test_db.create_user(user)
return user
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def regular_user(test_db: DB, user_role: Role) -> User: async def regular_user(test_db: DB, user_role: Role) -> User:
"""Create a regular test user without admin permissions.""" """Create a regular test user without admin permissions."""
user = User( user = User.create(
uuid=uuid7.create(),
display_name="Regular User", display_name="Regular User",
role_uuid=user_role.uuid, role=user_role.uuid,
created_at=datetime.now(timezone.utc),
visits=0,
) )
await test_db.create_user(user) create_user(user)
return user return user
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def test_credential(test_db: DB, test_user: User) -> Credential: async def test_credential(test_db: DB, test_user: User) -> Credential:
"""Create a test credential for the admin user.""" """Create a test credential for the admin user."""
credential = Credential( credential = Credential.create(
uuid=uuid7.create(),
credential_id=os.urandom(32), credential_id=os.urandom(32),
user_uuid=test_user.uuid, user=test_user.uuid,
aaguid=UUID("00000000-0000-0000-0000-000000000000"), aaguid=UUID("00000000-0000-0000-0000-000000000000"),
public_key=os.urandom(64), public_key=os.urandom(64),
sign_count=0, sign_count=0,
created_at=datetime.now(timezone.utc),
last_used=None,
last_verified=None,
) )
await test_db.create_credential(credential) create_credential(credential)
return credential return credential
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def regular_credential(test_db: DB, regular_user: User) -> Credential: async def regular_credential(test_db: DB, regular_user: User) -> Credential:
"""Create a test credential for the regular user.""" """Create a test credential for the regular user."""
credential = Credential( credential = Credential.create(
uuid=uuid7.create(),
credential_id=os.urandom(32), credential_id=os.urandom(32),
user_uuid=regular_user.uuid, user=regular_user.uuid,
aaguid=UUID("00000000-0000-0000-0000-000000000000"), aaguid=UUID("00000000-0000-0000-0000-000000000000"),
public_key=os.urandom(64), public_key=os.urandom(64),
sign_count=0, sign_count=0,
created_at=datetime.now(timezone.utc),
last_used=None,
last_verified=None,
) )
await test_db.create_credential(credential) create_credential(credential)
return credential return credential
@@ -181,17 +178,14 @@ async def session_token(
test_db: DB, test_user: User, test_credential: Credential test_db: DB, test_user: User, test_credential: Credential
) -> str: ) -> str:
"""Create a session for the admin user and return the token.""" """Create a session for the admin user and return the token."""
token = create_token() return create_session(
await test_db.create_session(
user_uuid=test_user.uuid, user_uuid=test_user.uuid,
credential_uuid=test_credential.uuid, credential_uuid=test_credential.uuid,
key=session_key(token),
host="localhost:4401", host="localhost:4401",
ip="127.0.0.1", ip="127.0.0.1",
user_agent="pytest", user_agent="pytest",
renewed=datetime.now(timezone.utc), expiry=expires(),
) )
return token
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
@@ -199,30 +193,24 @@ async def regular_session_token(
test_db: DB, regular_user: User, regular_credential: Credential test_db: DB, regular_user: User, regular_credential: Credential
) -> str: ) -> str:
"""Create a session for a regular user and return the token.""" """Create a session for a regular user and return the token."""
token = create_token() return create_session(
await test_db.create_session(
user_uuid=regular_user.uuid, user_uuid=regular_user.uuid,
credential_uuid=regular_credential.uuid, credential_uuid=regular_credential.uuid,
key=session_key(token),
host="localhost:4401", host="localhost:4401",
ip="127.0.0.1", ip="127.0.0.1",
user_agent="pytest", user_agent="pytest",
renewed=datetime.now(timezone.utc), expiry=expires(),
) )
return token
@pytest_asyncio.fixture(scope="function") @pytest_asyncio.fixture(scope="function")
async def reset_token(test_db: DB, test_user: User, test_credential: Credential) -> str: async def reset_token(test_db: DB, test_user: User, test_credential: Credential) -> str:
"""Create a reset token for the test user.""" """Create a reset token for the test user."""
from paskia.authsession import reset_expires
from paskia.util.passphrase import generate
from paskia.util.tokens import reset_key
token = generate() token = generate()
await test_db.create_reset_token( create_reset_token(
user_uuid=test_user.uuid, user_uuid=test_user.uuid,
key=reset_key(token), passphrase=token,
expiry=reset_expires(), expiry=reset_expires(),
token_type="reset", token_type="reset",
) )
@@ -239,7 +227,6 @@ async def client(
initialized first. initialized first.
""" """
# Import app after globals are set # Import app after globals are set
from paskia.fastapi.mainapp import app
transport = httpx.ASGITransport(app=app) transport = httpx.ASGITransport(app=app)
async with httpx.AsyncClient( async with httpx.AsyncClient(

Some files were not shown because too many files have changed in this diff Show More