f6c315d0dc
Improved session group (per site) styling and UX.
LeoVasanko2025-12-10 01:11:43 +00:00
504e1d0fc5
Consistent use of red X only for deletion, and using only it for deletion rather than trashbin, while using non-red X for window close button.
LeoVasanko2025-12-10 00:06:34 +00:00
a8269df0b4
Cleaner up registration link creation. Don't show the dialog until when there is a valid link. Implement a global blur backdrop with nicer effect and proper scrollbar handling (avoiding layout shifting a bit). Use the global backdrop to ensure consistent visuals between authentication and the modal being shown, along with in/out transitions.
LeoVasanko2025-12-09 23:58:04 +00:00
d58a88c43a
Code word input overhaul, more accurate cursor and selection processing. New styling for the widget that conforms with browser default style (focus outline).
LeoVasanko2025-12-09 23:07:15 +00:00
087b24388c
Fix regressions with the remote-auth preventing it from working. Minor usability and style improvements. Changed /auth/api/ws/pair name to permit, to go with other parts of the software.
LeoVasanko2025-12-09 21:57:33 +00:00
9b491164fd
Profile view UX improvements. More consistent styling across the application.
LeoVasanko2025-12-09 21:20:29 +00:00
bb34e52997
Remove different responsive styling applied to logout buttons making them appear too wide. Now all buttons behave the same.
LeoVasanko2025-12-09 17:04:20 +00:00
b9897b62b8
Remove trash bin icons from tab order. Instead, implement Delete key support (Backspace accepted on Apple devices).
LeoVasanko2025-12-09 16:54:46 +00:00
8a21edf367
Process IPv6 display into short format including only the network prefix, and sharing the same code also for comparisons where needed.
LeoVasanko2025-12-09 16:33:16 +00:00
03368b1b84
Rename base64 functions such that imports don't need renaming.
LeoVasanko2025-12-09 15:55:03 +00:00
bfc5b11cc2
Fix missing credential_uuid in admin user detail API that was causing linkage between sessions and their passkeys not show up.
LeoVasanko2025-12-09 15:34:05 +00:00
83419d1845
API tests added with near-complete coverage over user and admin APIs. 60% overall backend. (not including E2E test in coverage)
v0.5.1
LeoVasanko2025-12-06 04:45:26 +00:00
a2fe0b6f1a
Added E2E restricted API flow tests and fixed earlier failing tests. All passing. Coverage 51% backend, 74% frontend.
LeoVasanko2025-12-06 03:43:28 +00:00
a1b73711e6
Cleanup of origins handling. Added site_url and site_path such that these can be determined reliably, and we print it in the startbox.
LeoVasanko2025-12-06 03:39:05 +00:00
df5c176bcd
Fixed and updated E2E test suite. Added user credential registration tests. Coverage for backend and frontend.
LeoVasanko2025-12-06 00:52:35 +00:00
8937905c9c
Changed origin config to take multiple origins and if any are configured, restrict access to these. Removed bootstrap name options of created org and user (both can be easily renamed from web ui). Cleanup.
LeoVasanko2025-12-06 00:51:18 +00:00
127e06179b
More robust server startup, startup logo and info screen, renewed devmode script.
LeoVasanko2025-12-05 19:06:42 +00:00
a72349077c
Integrate host app to main app (WIP).
LeoVasanko2025-12-04 10:00:47 +00:00
e102b8383b
Admin app simplification by using API auth properly. Implemented promise to keep request blocked by permission check while the user authenticates, fixing concurrent requests.
LeoVasanko2025-12-04 09:19:40 +00:00
5aa8d021e6
Brought examples directly to front page.
LeoVasanko2025-12-04 08:19:32 +00:00
3d5b0aa4bf
Fix view switching of restricted app.
LeoVasanko2025-12-04 07:46:36 +00:00
29df169a67
Make restricted app use simple fetch that doesn't do API authentication (recursively).
LeoVasanko2025-12-04 06:20:14 +00:00
4d4b290cc8
Revert earlier change to iframe srcdoc, using src instead, because srcdoc was not compatible with all passkey implementations (BitWarden).
LeoVasanko2025-12-04 06:01:47 +00:00
0e1b9f529b
Log authentication options on the client.
LeoVasanko2025-12-04 05:07:44 +00:00
0c3e0d3fa5
Improved dialog layout with separate mobile portrait mode.
LeoVasanko2025-12-04 04:06:32 +00:00
1782547b9e
Fix infinitely nested login iframes when the restricted app notices it needs login.
LeoVasanko2025-12-04 03:56:17 +00:00
9976e05696
Various fixes and cleanup, regressions from prior commits.
LeoVasanko2025-12-04 03:40:59 +00:00
6124fa6c01
Fix syntax error in reset app created by earlier commit.
LeoVasanko2025-12-04 02:31:13 +00:00
a6591a1fbb
Better static files handling on backend, when in dev mode: fetch from vite.
LeoVasanko2025-12-04 02:30:02 +00:00
b9b1c995f9
Update forward API to return in JSON iframe srcdoc with options injected. (currently broken in dev mode).
LeoVasanko2025-12-04 01:58:18 +00:00
4482a601f3
Fix fetch timeout rolling while in authentication flow. Now each fetch gets a fresh timeout.
LeoVasanko2025-12-04 01:35:44 +00:00
aa4b1bfd42
Viewing linked passkeys/sessions (by clicking either one of them).
LeoVasanko2025-12-04 01:21:52 +00:00
2ecf8433a1
Consistently use apiJson for fetches, with timeout and proper error handling (less code duplication).
LeoVasanko2025-12-04 01:00:24 +00:00
469d606ce5
Improved apiFetch and jsonFetch functions.
LeoVasanko2025-12-03 23:26:38 +00:00
547a6cd923
Make auth/admin apps API calls use apiFetch, a new function that asks for permission by iframe if needed. Implement max-age checks for API authz.verify as well along with a custom exception type that carries metadata.
LeoVasanko2025-12-03 23:17:02 +00:00
deabee3b5c
Reload backend only on changes on the backend or frontend-build within, not outside that in the repo.
LeoVasanko2025-12-03 22:58:48 +00:00
fd1aa11409
Add E2E tests to register and verify passkey.
LeoVasanko2025-12-03 02:52:39 +00:00
ca1ea9d90b
Always use timezone aware UTC time.
LeoVasanko2025-12-03 01:36:15 +00:00
2dac0be77a
Improved session list IP handling. Hovering sessions shows Same IP on matching sessions.
LeoVasanko2025-12-03 01:32:05 +00:00
f63c62d9ff
Implement session termination in admin API, for completeness.
LeoVasanko2025-12-03 01:20:52 +00:00
b6a3cdd3a4
Fix examples folder serving broken a couple of commits ago.
LeoVasanko2025-12-03 00:06:32 +00:00
fd9a5afc1c
Implement metadata for RestrictedForward, set by /auth/api/forward endpoint when returning the app. Use this to implement support for time-based reauth requirement.
LeoVasanko2025-12-02 23:39:31 +00:00
8714fe9319
Vite proxy config simplified. Renaming /auth/restricted to have a trailing slash for better Vite compatibility.
LeoVasanko2025-12-02 22:41:12 +00:00
adbab88c86
Major refactor of frontend source tree such that paths better match where they are served.
LeoVasanko2025-12-02 22:09:07 +00:00
5d9d2b794d
Refactor restricted app paths and naming.
LeoVasanko2025-12-02 19:10:13 +00:00
eedbd4aaa4
Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.
LeoVasanko2025-12-02 18:34:59 +00:00
15916047fa
Remove backend access control, now that the profile and admin apps handle that via API.
LeoVasanko2025-12-02 18:25:58 +00:00
643d9bafab
Fix the back buttons (navigate back if you can but close if it was a new window).
LeoVasanko2025-12-02 18:02:02 +00:00
2699aaa472
Implement Forbidden view for API calls, cleanup and better UX.
LeoVasanko2025-12-02 17:36:37 +00:00
5422845192
Better error messages from backend, avoid bad toasts, cleanup of session validation.
LeoVasanko2025-12-02 16:37:27 +00:00
c1ccb048f0
Update admin app authentication in API mode too, reusing components between it and the main app.
LeoVasanko2025-12-02 15:42:55 +00:00
3030122807
Implemented auth app authentication in API mode (if loading the app itself wasn't blocked). Removed unnecessary toasts when entering restricted pages.
LeoVasanko2025-12-02 15:25:31 +00:00
d4f8e97469
Refactor lengthy user info formatting to its own utility module that doesn't depend on FastAPI.
LeoVasanko2025-12-02 14:30:31 +00:00
a62e8ddf1e
Implement restricted-api for JS-driven auth calls, examples added (WIP!). Layout and styling simplified.
LeoVasanko2025-12-02 03:10:16 +00:00
2dca6b1eec
Updated frontend running dev mode using deno/npm/bun as well. Additional dev mode Caddyfile to go https://localhost/.
LeoVasanko2025-12-01 20:07:26 +00:00
4f50974222
Updated build-frontend script, now uses deno, npm, bun in this order.
LeoVasanko2025-12-01 19:25:08 +00:00
1ca9e3ef58
Don't redirect non-auth-host /auth/ to auth site but show basic info on current host, and allow logging out. Adds a new host app for this purpose.
LeoVasanko2025-10-05 05:55:08 +00:00
575d3cb1fb
Deny creating sessions for hosts other than rp-id subdomains.
LeoVasanko2025-10-05 05:26:03 +00:00
a4ac19f54c
WebSockets must use origin for finding the host calling them.
LeoVasanko2025-10-05 05:16:51 +00:00
11887d15b2
Correction on restricted path checking (auth-host).
LeoVasanko2025-10-05 04:59:05 +00:00
cefb9c3d92
Refactor auth-host redirection middleware to its own module.
LeoVasanko2025-10-05 04:49:23 +00:00
5b9a3fc27f
Add validation of the CLI specified --auth-host (needs to be within rp-id).
LeoVasanko2025-10-05 04:35:55 +00:00
19a6c32cf2
Fix deletion of session cookie on host logout.
LeoVasanko2025-10-05 04:26:36 +00:00
01bc39a0e8
A major refactoring for more consistent and stricter flows. - Force using the dedicated authentication site configured via auth-host - Stricter host validation - Using the restricted app consistently for all access control (instead of the old loginview).
LeoVasanko2025-10-05 03:55:11 +00:00
fa513940c7
Refactor user editing endpoints (only auth site) under api/user/ while leaving host-based endpoints at api root.
LeoVasanko2025-10-04 20:59:51 +00:00
f24aaa295d
More consistent shared styling between credential and session cards.
LeoVasanko2025-10-04 20:32:27 +00:00
0af7aad28c
Add host-based authentication, UTC timestamps, session management, and secure cookies; fix styling issues; refactor to remove module; update database schema for sessions and reset tokens.
LeoVasanko2025-10-04 06:31:54 +00:00
43850c218f
Fix reset link logic to include /auth when no configured auth-host.
LeoVasanko2025-10-03 03:57:20 +00:00
2f1578c4bc
Refactor user-profile, restricted access and reset token registration as separate apps so the frontend does not need to guess which context it is running in.
LeoVasanko2025-10-03 03:42:01 +00:00
b4871c671f
Create registration links on the same host (subdomain) that is being used by the one who creates it.
LeoVasanko2025-10-03 00:22:02 +00:00