7796c38c08
Add pairwise SID with a UUIDv4, a significatant upgrade over User.id.to_s. Complete allowing admin to enforce TOTP per user
Dan Milne
2025-11-23 11:16:06 +11:00
ab0085e9c9
More complete oidc
Dan Milne
2025-11-18 20:02:45 +11:00
1ee3302319
Improvements derived from rodauth-oauth
Dan Milne
2025-11-12 22:17:55 +11:00
67f28faaca
Improve some front end views. More descriptive error condition reporting. Updates to CLINCH_HOST for better WEBAUTHN
Dan Milne
2025-11-12 16:24:05 +11:00
33ad956508
Add test
Dan Milne
2025-11-12 15:50:04 +11:00
11ec753c68
Bump up the forward auth token ttl, fix leaking of error data
Dan Milne
2025-11-09 12:27:53 +11:00
4df2eee4d9
Bug fix for domain names with empty string instead of null. Form errors and some security fixes
Dan Milne
2025-11-09 12:22:41 +11:00
d9f11abbbf
Fixes for OIDC and HTML
Dan Milne
2025-11-09 12:04:26 +11:00
c92e69fa4a
Add PCKE
Dan Milne
2025-11-09 11:54:45 +11:00
038801f34b
Add pkce
Dan Milne
2025-11-09 10:21:29 +11:00
044b9239d6
Ok - this time add the new controllers we stripped out of inline and add back the csp
Dan Milne
2025-11-04 18:55:20 +11:00
e9b1995e89
Remove unneeded stuff
Dan Milne
2025-11-04 18:47:31 +11:00
fb14ce032f
Strip out more inline javascript code. Encrypt backup codes and treat the backup codes attribute as a json array
Dan Milne
2025-11-04 18:46:11 +11:00
bf104a9983
Fix CSP errors - migrate inline JS to stimulus controllers. Add a URL for applications so users can discover them
Dan Milne
2025-11-04 17:06:53 +11:00
ec13dd2b60
Fix storing passkeys
Dan Milne
2025-11-04 16:32:50 +11:00
57abc0b804
Add webauthn
Dan Milne
2025-11-04 16:20:11 +11:00
19bfc21f11
Move sessions into their own view for easier management
Dan Milne
2025-11-04 15:19:39 +11:00
ef15db77f9
Massive refactor. Merge forward_auth into App, remove references to unimplemented OIDC federation and SAML features. Add group and user custom claims. Groups now allocate which apps a user can use
Dan Milne
2025-11-04 13:21:55 +11:00
4d1bc1ab66
Update readme
Dan Milne
2025-10-29 22:39:49 +11:00
517029247d
Update the .env.example file
Dan Milne
2025-10-29 16:35:27 +11:00
bfcc5cdc84
More nuanced domain fetching for host validation
Dan Milne
2025-10-29 16:31:56 +11:00
81871426e9
Update docs
Dan Milne
2025-10-29 16:08:49 +11:00
ddcb297c74
Add comprhensive csp polices and reporting endpoint. Add environment support require for protecting against rebinding attacks on ip addresses
Dan Milne
2025-10-29 15:37:53 +11:00
6f7de94623
Rate limit the forward_auth controller
Dan Milne
2025-10-29 13:55:36 +11:00
baa75a3456
Use the IPAddr library to detect ipv4 and ipv6 addresses
Dan Milne
2025-10-29 13:47:02 +11:00
c3205abffa
Improve finding the requested host's domain for setting the domain cookie
Dan Milne
2025-10-29 10:19:51 +11:00
a2008d0750
remove incorrectly named files
Dan Milne
2025-10-28 09:01:27 +11:00
810561d74b
Rename thumbshots
Dan Milne
2025-10-28 08:58:05 +11:00
2ee895888d
Add screenshots
Dan Milne
2025-10-28 08:52:15 +11:00
6c9fc429f1
Increase thumb
Dan Milne
2025-10-28 08:35:09 +11:00
7d200b849e
Add a screenshot
Dan Milne
2025-10-28 08:33:50 +11:00
7074242907
Update docs. Implemented a one-time token to work around domain cookies not being immediately return by the browser. Reduce db queries on /api/verify requests.
Dan Milne
2025-10-28 08:20:12 +11:00
da6fd5b800
More logs
Dan Milne
2025-10-27 23:54:34 +11:00
cfab21b130
More tests
Dan Milne
2025-10-26 23:56:02 +11:00
c80bcafdb7
Bug fix
Dan Milne
2025-10-26 23:20:44 +11:00
f050541e14
Merge pull request #1 from dkam/dependabot/github_actions/actions/upload-artifact-5
Dan Milne
2025-10-27 20:05:01 +11:00
431e947a4c
Some more tests. Fix invitation link and password reset links. After creating their account and setting a password, the user is logged in
Dan Milne
2025-10-26 23:09:38 +11:00
8dd3e60071
Add a list_sign_in_at field for users so magick links work
Dan Milne
2025-10-26 22:40:54 +11:00
e4e7a0873e
Fixes
Dan Milne
2025-10-26 22:03:03 +11:00
b5b1d94d47
Fix the CLINCH_HOST issue.
Dan Milne
2025-10-26 21:59:27 +11:00
52cfd6122c
Typo. More tests
Dan Milne
2025-10-26 20:42:18 +11:00
87796e0478
Type
Dan Milne
2025-10-26 20:28:14 +11:00
227e29ce0a
Fix/add some tests. Configure email sending address
Dan Milne
2025-10-26 20:13:39 +11:00
d98f777e7d
Refactor email delivery and background jobs system
Dan Milne
2025-10-26 16:30:02 +11:00
88428bfd97
Add configuration foward-auth headers
Dan Milne
2025-10-26 14:41:20 +11:00
2679634a2b
Port 3000
Dan Milne
2025-10-25 16:00:09 +11:00
2d5823213c
Update readme
Dan Milne
2025-10-25 13:50:15 +11:00
5921cf82c2
Add invite button and routes for resending invitations
Dan Milne
2025-10-25 13:49:10 +11:00
df834b6e57
Add license
Dan Milne
2025-10-25 13:34:33 +11:00
471c16890b
Bump actions/upload-artifact from 4 to 5
dependabot[bot]
2025-10-25 02:34:28 +00:00
39757a43dc
Add an invite system
Dan Milne
2025-10-24 23:26:07 +11:00
5463723455
Increase the thing
Dan Milne
2025-10-24 20:48:58 +11:00
e36850f8ba
Bug fix
Dan Milne
2025-10-24 17:07:12 +11:00
0af3dbefed
Remember that we concented.
Dan Milne
2025-10-24 17:01:03 +11:00