Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
55a9cbdc6e | ||
|
|
a6fc9daab9 | ||
|
|
8b3bff7df0 | ||
|
|
2b2ddc1b1b | ||
|
|
0d5986b81a | ||
|
|
31e3306997 | ||
|
|
5f3ff7f31a | ||
|
|
f90b4a0963 | ||
|
|
a95296e1fc | ||
|
|
3fa97bb0b0 | ||
|
|
f0b32ff68b |
@@ -59,10 +59,8 @@ This project uses version-tag-based CI/CD. Releases trigger automated Docker bui
|
||||
3. Commit changes: `git commit -m "chore: release vX.X.X"`
|
||||
4. Create git tag: `git tag vX.X.X`
|
||||
5. Push with tags: `git push origin master --tags`
|
||||
6. Create release in Gitea UI (git.schweitz.net → Releases → New Release)
|
||||
* Select the tag
|
||||
* Add release notes (can copy from CHANGELOG)
|
||||
* **Publish** the release (this triggers CI/CD)
|
||||
|
||||
CI/CD auto-triggers when a tag starting with `v` is pushed.
|
||||
|
||||
**What happens on release:**
|
||||
|
||||
|
||||
+60
-7
@@ -7,7 +7,66 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
## [1.1.1] - 2026-01-04
|
||||
## [1.1.10] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
- Removed page swipe transitions - all navigation is now instant (NoTransitionPage)
|
||||
|
||||
## [1.1.9] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
- Moved health check to `/health` directory - URL is now `/health` instead of `/health.html`
|
||||
- Enables NPM forward auth path exclusion for health endpoint
|
||||
|
||||
## [1.1.8] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
- Dark background (`#1a1a2e`) on web/index.html to prevent white flash during auth redirects
|
||||
|
||||
## [1.1.7] - 2026-01-04
|
||||
|
||||
### Removed
|
||||
- Removed `/callback` route from Flutter router - AuthController handles callback in main() before app starts
|
||||
- Removed `_OidcCallbackPage` widget - no visible auth UI needed
|
||||
|
||||
## [1.1.6] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
- **Auth moved to standalone controller** - Handles OIDC completely outside Riverpod
|
||||
- New `AuthController` runs in `main()` before `runApp()` - avoids provider lifecycle issues
|
||||
- Handles callback, token exchange, and /auth/sync before app starts
|
||||
- If auth not ready (redirecting), app doesn't start at all
|
||||
- `AuthProvider` now just loads stored tokens (no async OIDC logic)
|
||||
- Fixes "Cannot use Ref after disposed" errors from autoDispose providers
|
||||
|
||||
## [1.1.5] - 2026-01-04
|
||||
|
||||
### Fixed
|
||||
- Race condition in OIDC callback: AuthProvider.build() was initiating silent OIDC while the callback page was processing, causing PKCE state to be cleared. Now skips silent OIDC when on `/callback` route.
|
||||
|
||||
## [1.1.4] - 2026-01-04
|
||||
|
||||
### Fixed
|
||||
- Silent OIDC fallback: when `prompt=none` fails with `login_required` (no Authentik session), automatically fall back to regular OIDC flow to show login UI
|
||||
|
||||
## [1.1.3] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
- **Web auth uses silent OIDC with JWT Bearer tokens**
|
||||
- Uses `prompt=none` to silently obtain JWT when Authentik session exists (via NPM forward auth)
|
||||
- Flutter sends Bearer token to core-api instead of relying on forward auth cookies
|
||||
- Fixes cross-subdomain cookie issues between home.schweitz.net and api.schweitz.net
|
||||
- Callback now syncs with `/auth/sync` to get user profile and roles from core-api
|
||||
- API interceptor now adds Bearer token on web (previously skipped)
|
||||
|
||||
## [1.1.2] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
- **Web auth simplified**: Skip Flutter OIDC on web - NPM forward auth handles it
|
||||
- NPM authenticates at proxy level before app loads
|
||||
- No more redundant OIDC redirect after NPM auth completes
|
||||
- Fixes "Cannot use Ref after disposed" error from conflicting auth flows
|
||||
- Mobile still uses Flutter OIDC flow
|
||||
|
||||
### Added
|
||||
- Logout now redirects to Authentik to end SSO session
|
||||
@@ -15,12 +74,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
- Uses OIDC end_session_endpoint from discovery document
|
||||
- Redirects back to app after Authentik logout completes
|
||||
|
||||
### Fixed
|
||||
- Fixed Riverpod lifecycle error in OIDC callback page
|
||||
- "Cannot use the Ref of authProvider after it has been disposed"
|
||||
- Store notifier reference before async gap to prevent disposed ref access
|
||||
- Add mounted check at start of callback processing
|
||||
|
||||
## [1.1.0] - 2026-01-04
|
||||
|
||||
### Changed
|
||||
|
||||
@@ -10,8 +10,7 @@ import 'package:tatlock_ui/core/error/app_exception.dart';
|
||||
/// Adds authentication token to requests.
|
||||
///
|
||||
/// - **LAN mode**: Skipped entirely (no auth required)
|
||||
/// - **Web**: Skipped (cookies handle auth via NPM forward auth)
|
||||
/// - **Mobile**: Adds Bearer token from OIDC authentication
|
||||
/// - **Web + Mobile**: Adds Bearer token from OIDC authentication
|
||||
class AuthInterceptor extends Interceptor {
|
||||
AuthInterceptor(this._ref);
|
||||
|
||||
@@ -25,17 +24,11 @@ class AuthInterceptor extends Interceptor {
|
||||
return;
|
||||
}
|
||||
|
||||
// Skip Bearer token on web - cookies handle auth via NPM forward auth
|
||||
if (kIsWeb) {
|
||||
handler.next(options);
|
||||
return;
|
||||
}
|
||||
|
||||
// Mobile: Add Bearer token from OIDC authentication
|
||||
// Add Bearer token for all platforms (web + mobile)
|
||||
final authState = _ref.read(authProvider);
|
||||
|
||||
authState.whenData((auth) {
|
||||
if (auth.isAuthenticated && auth.accessToken != null && auth.accessToken != 'web-session') {
|
||||
if (auth.isAuthenticated && auth.accessToken != null) {
|
||||
options.headers['Authorization'] = 'Bearer ${auth.accessToken}';
|
||||
}
|
||||
});
|
||||
|
||||
@@ -0,0 +1,288 @@
|
||||
import 'dart:convert' show jsonDecode, jsonEncode;
|
||||
import 'dart:developer' as developer;
|
||||
|
||||
import 'package:dio/dio.dart';
|
||||
import 'package:flutter/foundation.dart' show kIsWeb;
|
||||
import 'package:shared_preferences/shared_preferences.dart';
|
||||
|
||||
import '../config/app_config.dart';
|
||||
import 'auth_datasource.dart';
|
||||
import 'auth_state.dart';
|
||||
import 'oidc_service_web.dart';
|
||||
import 'permissions.dart';
|
||||
import 'user_preferences.dart';
|
||||
import 'web_utils.dart' as web_utils;
|
||||
|
||||
/// Standalone auth controller that handles OIDC flow before app starts.
|
||||
///
|
||||
/// This runs outside of Riverpod to avoid lifecycle issues. Call [initialize]
|
||||
/// in main() before runApp(). The controller will:
|
||||
/// 1. Handle callback if on /callback route (exchange code, sync, store tokens)
|
||||
/// 2. Check for valid stored tokens
|
||||
/// 3. Redirect to silent OIDC if no tokens (app won't continue)
|
||||
///
|
||||
/// Once auth is complete, [AuthProvider] can simply read the stored tokens.
|
||||
class AuthController {
|
||||
// Storage keys (same as AuthProvider)
|
||||
static const _accessTokenKey = 'auth_access_token';
|
||||
static const _refreshTokenKey = 'auth_refresh_token';
|
||||
static const _expiresAtKey = 'auth_expires_at';
|
||||
static const _userIdKey = 'auth_user_id';
|
||||
static const _authentikIdKey = 'auth_authentik_id';
|
||||
static const _userNameKey = 'auth_user_name';
|
||||
static const _userEmailKey = 'auth_user_email';
|
||||
static const _avatarUrlKey = 'auth_avatar_url';
|
||||
static const _rolesKey = 'auth_roles';
|
||||
static const _preferencesKey = 'auth_preferences';
|
||||
|
||||
/// Initialize auth before app starts.
|
||||
///
|
||||
/// Returns true if auth is ready (tokens available).
|
||||
/// Returns false if redirecting (app should not continue).
|
||||
/// Throws on error.
|
||||
static Future<bool> initialize() async {
|
||||
// Skip auth entirely for LAN mode
|
||||
if (!AppConfig.requiresAuth) {
|
||||
developer.log('Auth not required (LAN mode)', name: 'auth_controller');
|
||||
return true;
|
||||
}
|
||||
|
||||
// Only handle web auth here - mobile uses different flow
|
||||
if (!kIsWeb) {
|
||||
developer.log('Non-web platform, skipping controller init', name: 'auth_controller');
|
||||
return true;
|
||||
}
|
||||
|
||||
final currentUrl = web_utils.getCurrentUrl();
|
||||
developer.log('Auth controller init, URL: $currentUrl', name: 'auth_controller');
|
||||
|
||||
// Check if we're on the callback route
|
||||
if (currentUrl.contains('/callback')) {
|
||||
return _handleCallback(currentUrl);
|
||||
}
|
||||
|
||||
// Check for valid stored tokens
|
||||
final prefs = await SharedPreferences.getInstance();
|
||||
final accessToken = prefs.getString(_accessTokenKey);
|
||||
if (accessToken != null) {
|
||||
final expiresAtMs = prefs.getInt(_expiresAtKey);
|
||||
final expiresAt = expiresAtMs != null
|
||||
? DateTime.fromMillisecondsSinceEpoch(expiresAtMs)
|
||||
: null;
|
||||
|
||||
if (expiresAt == null || expiresAt.isAfter(DateTime.now())) {
|
||||
developer.log('Valid tokens found', name: 'auth_controller');
|
||||
return true; // Auth ready
|
||||
}
|
||||
developer.log('Tokens expired', name: 'auth_controller');
|
||||
}
|
||||
|
||||
// No valid tokens - initiate silent OIDC
|
||||
developer.log('No valid tokens, starting silent OIDC', name: 'auth_controller');
|
||||
await _initiateSilentOidc();
|
||||
return false; // Redirecting, app should not continue
|
||||
}
|
||||
|
||||
/// Handle the OIDC callback.
|
||||
static Future<bool> _handleCallback(String url) async {
|
||||
final uri = Uri.parse(url);
|
||||
final code = uri.queryParameters['code'];
|
||||
final state = uri.queryParameters['state'];
|
||||
final error = uri.queryParameters['error'];
|
||||
|
||||
developer.log('Handling callback: code=${code != null}, error=$error', name: 'auth_controller');
|
||||
|
||||
// Handle errors
|
||||
if (error != null) {
|
||||
if (error == 'login_required') {
|
||||
// Silent auth failed - no session, start regular OIDC
|
||||
developer.log('Silent auth failed (login_required), starting regular OIDC', name: 'auth_controller');
|
||||
await _initiateRegularOidc();
|
||||
return false;
|
||||
}
|
||||
throw Exception('Auth error: $error - ${uri.queryParameters['error_description']}');
|
||||
}
|
||||
|
||||
if (code == null || state == null) {
|
||||
throw Exception('Invalid callback - missing code or state');
|
||||
}
|
||||
|
||||
// Exchange code for tokens
|
||||
developer.log('Exchanging code for tokens', name: 'auth_controller');
|
||||
final oidcService = OidcServiceWeb();
|
||||
final tokens = await oidcService.exchangeCode(code, state);
|
||||
|
||||
// Sync with core-api
|
||||
developer.log('Syncing with core-api', name: 'auth_controller');
|
||||
final dio = Dio(BaseOptions(
|
||||
baseUrl: AppConfig.coreApiUrl,
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'Accept': 'application/json',
|
||||
},
|
||||
));
|
||||
final authDatasource = AuthDatasource(dio);
|
||||
final syncResponse = await authDatasource.syncUser(tokens.accessToken);
|
||||
|
||||
developer.log('Synced user: ${syncResponse.name}', name: 'auth_controller');
|
||||
|
||||
// Store credentials
|
||||
await _storeAuth(
|
||||
accessToken: tokens.accessToken,
|
||||
refreshToken: tokens.refreshToken,
|
||||
expiresAt: tokens.expiresAt,
|
||||
userId: syncResponse.userId,
|
||||
authentikId: syncResponse.authentikId,
|
||||
userName: syncResponse.name,
|
||||
userEmail: syncResponse.email,
|
||||
avatarUrl: syncResponse.avatarUrl,
|
||||
roles: syncResponse.roles,
|
||||
preferences: syncResponse.preferences,
|
||||
);
|
||||
|
||||
// Redirect to home (removes callback params from URL)
|
||||
developer.log('Auth complete, redirecting to home', name: 'auth_controller');
|
||||
web_utils.redirectTo('/');
|
||||
return false; // Redirecting
|
||||
}
|
||||
|
||||
/// Initiate silent OIDC (prompt=none).
|
||||
static Future<void> _initiateSilentOidc() async {
|
||||
final oidcService = OidcServiceWeb();
|
||||
final authUrl = await oidcService.getAuthorizationUrl(silent: true);
|
||||
developer.log('Redirecting to silent OIDC', name: 'auth_controller');
|
||||
web_utils.redirectTo(authUrl);
|
||||
}
|
||||
|
||||
/// Initiate regular OIDC (shows login UI).
|
||||
static Future<void> _initiateRegularOidc() async {
|
||||
final oidcService = OidcServiceWeb();
|
||||
final authUrl = await oidcService.getAuthorizationUrl(silent: false);
|
||||
developer.log('Redirecting to regular OIDC', name: 'auth_controller');
|
||||
web_utils.redirectTo(authUrl);
|
||||
}
|
||||
|
||||
/// Store auth data.
|
||||
static Future<void> _storeAuth({
|
||||
required String accessToken,
|
||||
String? refreshToken,
|
||||
DateTime? expiresAt,
|
||||
String? userId,
|
||||
String? authentikId,
|
||||
String? userName,
|
||||
String? userEmail,
|
||||
String? avatarUrl,
|
||||
List<Role>? roles,
|
||||
UserPreferences? preferences,
|
||||
}) async {
|
||||
final prefs = await SharedPreferences.getInstance();
|
||||
|
||||
await prefs.setString(_accessTokenKey, accessToken);
|
||||
if (refreshToken != null) {
|
||||
await prefs.setString(_refreshTokenKey, refreshToken);
|
||||
}
|
||||
if (expiresAt != null) {
|
||||
await prefs.setInt(_expiresAtKey, expiresAt.millisecondsSinceEpoch);
|
||||
}
|
||||
if (userId != null) await prefs.setString(_userIdKey, userId);
|
||||
if (authentikId != null) await prefs.setString(_authentikIdKey, authentikId);
|
||||
if (userName != null) await prefs.setString(_userNameKey, userName);
|
||||
if (userEmail != null) await prefs.setString(_userEmailKey, userEmail);
|
||||
if (avatarUrl != null) await prefs.setString(_avatarUrlKey, avatarUrl);
|
||||
|
||||
if (roles != null) {
|
||||
final rolesJson = jsonEncode(roles.map((r) => {
|
||||
'id': r.id,
|
||||
'name': r.name,
|
||||
'domain': r.domain.value,
|
||||
'category': r.category,
|
||||
'action': r.action.name,
|
||||
}).toList());
|
||||
await prefs.setString(_rolesKey, rolesJson);
|
||||
}
|
||||
|
||||
if (preferences != null) {
|
||||
await prefs.setString(_preferencesKey, jsonEncode(preferences.toJson()));
|
||||
}
|
||||
}
|
||||
|
||||
/// Load stored auth state (for AuthProvider to use).
|
||||
static Future<AuthState> loadStoredAuth() async {
|
||||
try {
|
||||
final prefs = await SharedPreferences.getInstance();
|
||||
|
||||
final accessToken = prefs.getString(_accessTokenKey);
|
||||
if (accessToken == null) {
|
||||
return const AuthState();
|
||||
}
|
||||
|
||||
final expiresAtMs = prefs.getInt(_expiresAtKey);
|
||||
final expiresAt = expiresAtMs != null
|
||||
? DateTime.fromMillisecondsSinceEpoch(expiresAtMs)
|
||||
: null;
|
||||
|
||||
final rolesJson = prefs.getString(_rolesKey);
|
||||
final roles = rolesJson != null ? _parseRoles(rolesJson) : <Role>[];
|
||||
|
||||
final prefsJson = prefs.getString(_preferencesKey);
|
||||
final preferences = prefsJson != null
|
||||
? UserPreferences.fromJson(jsonDecode(prefsJson) as Map<String, dynamic>)
|
||||
: null;
|
||||
|
||||
return AuthState(
|
||||
isAuthenticated: true,
|
||||
accessToken: accessToken,
|
||||
refreshToken: prefs.getString(_refreshTokenKey),
|
||||
expiresAt: expiresAt,
|
||||
userId: prefs.getString(_userIdKey),
|
||||
authentikId: prefs.getString(_authentikIdKey),
|
||||
userName: prefs.getString(_userNameKey),
|
||||
userEmail: prefs.getString(_userEmailKey),
|
||||
avatarUrl: prefs.getString(_avatarUrlKey),
|
||||
roles: roles,
|
||||
preferences: preferences,
|
||||
);
|
||||
} catch (e) {
|
||||
developer.log('Failed to load stored auth: $e', name: 'auth_controller');
|
||||
return const AuthState();
|
||||
}
|
||||
}
|
||||
|
||||
static List<Role> _parseRoles(String json) {
|
||||
try {
|
||||
final list = jsonDecode(json) as List<dynamic>;
|
||||
return list.map((item) {
|
||||
final map = item as Map<String, dynamic>;
|
||||
final domain = Domain.fromString(map['domain'] as String);
|
||||
final action = Action.fromString(map['action'] as String);
|
||||
|
||||
if (domain == null || action == null) return null;
|
||||
|
||||
return Role(
|
||||
id: map['id'] as String,
|
||||
name: map['name'] as String,
|
||||
domain: domain,
|
||||
category: map['category'] as String? ?? 'general',
|
||||
action: action,
|
||||
);
|
||||
}).whereType<Role>().toList();
|
||||
} catch (e) {
|
||||
return [];
|
||||
}
|
||||
}
|
||||
|
||||
/// Clear stored auth (for logout).
|
||||
static Future<void> clearAuth() async {
|
||||
final prefs = await SharedPreferences.getInstance();
|
||||
await prefs.remove(_accessTokenKey);
|
||||
await prefs.remove(_refreshTokenKey);
|
||||
await prefs.remove(_expiresAtKey);
|
||||
await prefs.remove(_userIdKey);
|
||||
await prefs.remove(_authentikIdKey);
|
||||
await prefs.remove(_userNameKey);
|
||||
await prefs.remove(_userEmailKey);
|
||||
await prefs.remove(_avatarUrlKey);
|
||||
await prefs.remove(_rolesKey);
|
||||
await prefs.remove(_preferencesKey);
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,4 @@
|
||||
import 'dart:convert' show base64Url, jsonDecode, jsonEncode, utf8;
|
||||
import 'dart:convert' show jsonDecode, jsonEncode;
|
||||
import 'dart:developer' as developer;
|
||||
|
||||
import 'package:flutter/foundation.dart' show kIsWeb;
|
||||
@@ -40,7 +40,9 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
|
||||
@override
|
||||
Future<AuthState> build() async {
|
||||
// Load stored auth on all platforms
|
||||
// AuthController.initialize() in main() handles OIDC flow before app starts.
|
||||
// By the time we get here, tokens are already stored (or we're in LAN mode).
|
||||
// Just load the stored auth state.
|
||||
return _loadStoredAuth();
|
||||
}
|
||||
|
||||
@@ -265,27 +267,28 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
final oidcService = OidcServiceWeb();
|
||||
final tokens = await oidcService.exchangeCode(code, callbackState);
|
||||
|
||||
// Step 2: Decode JWT to extract user info (skip core-api sync)
|
||||
final claims = _decodeJwtClaims(tokens.accessToken);
|
||||
final userName = claims['name'] as String? ??
|
||||
claims['preferred_username'] as String? ??
|
||||
'User';
|
||||
final userEmail = claims['email'] as String? ?? '';
|
||||
final authentikId = claims['sub'] as String?;
|
||||
final groups = (claims['groups'] as List<dynamic>?)?.cast<String>() ?? [];
|
||||
// Step 2: Sync with core-api to get user profile and roles
|
||||
developer.log('Syncing with core-api', name: 'auth');
|
||||
final authDatasource = ref.read(authDatasourceProvider);
|
||||
final syncResponse = await authDatasource.syncUser(tokens.accessToken);
|
||||
|
||||
developer.log('JWT claims: name=$userName, email=$userEmail, groups=$groups', name: 'auth');
|
||||
developer.log(
|
||||
'Synced user: ${syncResponse.name} with ${syncResponse.roles.length} roles',
|
||||
name: 'auth',
|
||||
);
|
||||
|
||||
// Step 3: Store credentials and user data from JWT
|
||||
// Step 3: Store credentials and user data from sync response
|
||||
await _storeAuth(
|
||||
accessToken: tokens.accessToken,
|
||||
refreshToken: tokens.refreshToken,
|
||||
expiresAt: tokens.expiresAt,
|
||||
authentikId: authentikId,
|
||||
userName: userName,
|
||||
userEmail: userEmail,
|
||||
// Roles from groups - for now just store group names
|
||||
// Full role parsing can be done later if needed
|
||||
userId: syncResponse.userId,
|
||||
authentikId: syncResponse.authentikId,
|
||||
userName: syncResponse.name,
|
||||
userEmail: syncResponse.email,
|
||||
avatarUrl: syncResponse.avatarUrl,
|
||||
roles: syncResponse.roles,
|
||||
preferences: syncResponse.preferences,
|
||||
);
|
||||
|
||||
state = AsyncData(AuthState(
|
||||
@@ -293,12 +296,16 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
accessToken: tokens.accessToken,
|
||||
refreshToken: tokens.refreshToken,
|
||||
expiresAt: tokens.expiresAt,
|
||||
authentikId: authentikId,
|
||||
userName: userName,
|
||||
userEmail: userEmail,
|
||||
userId: syncResponse.userId,
|
||||
authentikId: syncResponse.authentikId,
|
||||
userName: syncResponse.name,
|
||||
userEmail: syncResponse.email,
|
||||
avatarUrl: syncResponse.avatarUrl,
|
||||
roles: syncResponse.roles,
|
||||
preferences: syncResponse.preferences,
|
||||
));
|
||||
|
||||
developer.log('Authenticated as $userName', name: 'auth');
|
||||
developer.log('Authenticated as ${syncResponse.name}', name: 'auth');
|
||||
|
||||
// Clean up the URL by removing the query parameters
|
||||
web_utils.replaceUrl('/');
|
||||
@@ -311,35 +318,6 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
}
|
||||
}
|
||||
|
||||
/// Decode JWT payload without verification (validation happens server-side).
|
||||
Map<String, dynamic> _decodeJwtClaims(String jwt) {
|
||||
try {
|
||||
final parts = jwt.split('.');
|
||||
if (parts.length != 3) {
|
||||
developer.log('Invalid JWT format', name: 'auth');
|
||||
return {};
|
||||
}
|
||||
|
||||
// Decode the payload (second part)
|
||||
String payload = parts[1];
|
||||
// Add padding if needed for base64
|
||||
switch (payload.length % 4) {
|
||||
case 2:
|
||||
payload += '==';
|
||||
break;
|
||||
case 3:
|
||||
payload += '=';
|
||||
break;
|
||||
}
|
||||
|
||||
final decoded = utf8.decode(base64Url.decode(payload));
|
||||
return jsonDecode(decoded) as Map<String, dynamic>;
|
||||
} catch (e) {
|
||||
developer.log('Failed to decode JWT: $e', name: 'auth');
|
||||
return {};
|
||||
}
|
||||
}
|
||||
|
||||
/// Sign out and clear stored credentials.
|
||||
///
|
||||
/// On web, also redirects to Authentik's logout endpoint to end the SSO session.
|
||||
|
||||
@@ -34,7 +34,12 @@ class OidcServiceWeb implements OidcService {
|
||||
///
|
||||
/// Returns a URL that the browser should navigate to for authentication.
|
||||
/// The [codeVerifier] and [state] are stored for later verification.
|
||||
Future<String> getAuthorizationUrl() async {
|
||||
///
|
||||
/// If [silent] is true, adds `prompt=none` to skip login UI.
|
||||
/// This is used when the user already has an Authentik session (via NPM).
|
||||
/// Authentik will instantly redirect back with a code, or return an error
|
||||
/// if there's no valid session.
|
||||
Future<String> getAuthorizationUrl({bool silent = false}) async {
|
||||
// Fetch OIDC discovery document
|
||||
final discovery = await _fetchDiscovery();
|
||||
final authEndpoint = discovery['authorization_endpoint'] as String;
|
||||
@@ -59,10 +64,11 @@ class OidcServiceWeb implements OidcService {
|
||||
'code_challenge': codeChallenge,
|
||||
'code_challenge_method': 'S256',
|
||||
'state': state,
|
||||
if (silent) 'prompt': 'none', // Silent auth - no UI, instant redirect
|
||||
};
|
||||
|
||||
final uri = Uri.parse(authEndpoint).replace(queryParameters: params);
|
||||
developer.log('Authorization URL: $uri', name: 'oidc_web');
|
||||
developer.log('Authorization URL (silent=$silent): $uri', name: 'oidc_web');
|
||||
return uri.toString();
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import 'package:flutter/material.dart';
|
||||
import 'package:go_router/go_router.dart';
|
||||
import 'package:tatlock_ui/features/control_room/presentation/pages/control_room_page.dart';
|
||||
import 'package:tatlock_ui/routing/app_router.dart';
|
||||
import 'package:tatlock_ui/shared/layouts/widgets/nav_panel.dart';
|
||||
|
||||
/// Route paths for Control Room.
|
||||
@@ -66,7 +67,8 @@ List<RouteBase> controlRoomRoutes() {
|
||||
GoRoute(
|
||||
path: nav.path,
|
||||
name: 'controlRoom${_capitalize(nav.id.replaceAll('-', '_'))}',
|
||||
builder: (context, state) => ControlRoomPage(nav: nav),
|
||||
pageBuilder: (context, state) =>
|
||||
noTransitionPage(context, state, ControlRoomPage(nav: nav)),
|
||||
),
|
||||
];
|
||||
}
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import 'package:flutter/material.dart';
|
||||
import 'package:go_router/go_router.dart';
|
||||
import 'package:tatlock_ui/features/security/presentation/pages/security_page.dart';
|
||||
import 'package:tatlock_ui/routing/app_router.dart';
|
||||
import 'package:tatlock_ui/shared/layouts/widgets/nav_panel.dart';
|
||||
|
||||
/// Route paths for Security room.
|
||||
@@ -60,7 +61,8 @@ List<RouteBase> securityRoutes() {
|
||||
GoRoute(
|
||||
path: nav.path,
|
||||
name: 'security${_capitalize(nav.id.replaceAll('-', '_'))}',
|
||||
builder: (context, state) => SecurityPage(nav: nav),
|
||||
pageBuilder: (context, state) =>
|
||||
noTransitionPage(context, state, SecurityPage(nav: nav)),
|
||||
),
|
||||
];
|
||||
}
|
||||
|
||||
+11
-1
@@ -4,10 +4,11 @@ import 'package:flutter/material.dart';
|
||||
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
||||
|
||||
import 'app.dart';
|
||||
import 'core/auth/auth_controller.dart';
|
||||
import 'core/config/url_strategy.dart';
|
||||
import 'version.g.dart';
|
||||
|
||||
void main() {
|
||||
void main() async {
|
||||
WidgetsFlutterBinding.ensureInitialized();
|
||||
|
||||
// Use path-based URLs on web (no-op on mobile/desktop)
|
||||
@@ -18,5 +19,14 @@ void main() {
|
||||
name: 'tatlock_ui',
|
||||
);
|
||||
|
||||
// Initialize auth before starting the app.
|
||||
// This handles OIDC callback and silent auth on web.
|
||||
// If it returns false, we're redirecting and shouldn't continue.
|
||||
final authReady = await AuthController.initialize();
|
||||
if (!authReady) {
|
||||
developer.log('Auth redirecting, not starting app', name: 'tatlock_ui');
|
||||
return; // Don't run the app - browser is redirecting
|
||||
}
|
||||
|
||||
runApp(const ProviderScope(child: TatlockApp()));
|
||||
}
|
||||
|
||||
+14
-157
@@ -1,8 +1,6 @@
|
||||
import 'package:flutter/material.dart';
|
||||
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
||||
import 'package:go_router/go_router.dart';
|
||||
import 'package:riverpod_annotation/riverpod_annotation.dart';
|
||||
import 'package:tatlock_ui/core/auth/auth_provider.dart';
|
||||
import 'package:tatlock_ui/features/control_room/router.dart';
|
||||
import 'package:tatlock_ui/features/front_hall/presentation/pages/front_hall_page.dart';
|
||||
import 'package:tatlock_ui/features/security/router.dart';
|
||||
@@ -10,12 +8,19 @@ import 'package:tatlock_ui/shared/layouts/app_scaffold.dart';
|
||||
|
||||
part 'app_router.g.dart';
|
||||
|
||||
/// No-animation page builder for instant transitions
|
||||
Page<void> noTransitionPage(BuildContext context, GoRouterState state, Widget child) {
|
||||
return NoTransitionPage<void>(
|
||||
key: state.pageKey,
|
||||
child: child,
|
||||
);
|
||||
}
|
||||
|
||||
/// Route paths as constants.
|
||||
abstract class AppRoutes {
|
||||
static const frontHall = '/';
|
||||
static const parlor = '/parlor';
|
||||
static const settings = '/settings';
|
||||
static const callback = '/callback';
|
||||
}
|
||||
|
||||
/// Provides the GoRouter instance.
|
||||
@@ -25,17 +30,6 @@ GoRouter appRouter(Ref ref) {
|
||||
initialLocation: AppRoutes.frontHall,
|
||||
debugLogDiagnostics: true,
|
||||
routes: [
|
||||
// OIDC callback route (handles auth code exchange)
|
||||
GoRoute(
|
||||
path: AppRoutes.callback,
|
||||
name: 'callback',
|
||||
builder: (context, state) => _OidcCallbackPage(
|
||||
code: state.uri.queryParameters['code'],
|
||||
callbackState: state.uri.queryParameters['state'],
|
||||
error: state.uri.queryParameters['error'],
|
||||
errorDescription: state.uri.queryParameters['error_description'],
|
||||
),
|
||||
),
|
||||
// Main app routes (inside shell with app scaffold)
|
||||
ShellRoute(
|
||||
builder: (context, state, child) => AppScaffold(child: child),
|
||||
@@ -43,21 +37,22 @@ GoRouter appRouter(Ref ref) {
|
||||
GoRoute(
|
||||
path: AppRoutes.frontHall,
|
||||
name: 'frontHall',
|
||||
builder: (context, state) => const FrontHallPage(),
|
||||
pageBuilder: (context, state) =>
|
||||
noTransitionPage(context, state, const FrontHallPage()),
|
||||
),
|
||||
...controlRoomRoutes(),
|
||||
...securityRoutes(),
|
||||
GoRoute(
|
||||
path: AppRoutes.parlor,
|
||||
name: 'parlor',
|
||||
builder: (context, state) =>
|
||||
const _PlaceholderPage(title: 'Parlor'),
|
||||
pageBuilder: (context, state) =>
|
||||
noTransitionPage(context, state, const _PlaceholderPage(title: 'Parlor')),
|
||||
),
|
||||
GoRoute(
|
||||
path: AppRoutes.settings,
|
||||
name: 'settings',
|
||||
builder: (context, state) =>
|
||||
const _PlaceholderPage(title: 'Settings'),
|
||||
pageBuilder: (context, state) =>
|
||||
noTransitionPage(context, state, const _PlaceholderPage(title: 'Settings')),
|
||||
),
|
||||
],
|
||||
),
|
||||
@@ -100,141 +95,3 @@ class _PlaceholderPage extends StatelessWidget {
|
||||
}
|
||||
}
|
||||
|
||||
/// OIDC callback page that handles the authorization code exchange.
|
||||
class _OidcCallbackPage extends ConsumerStatefulWidget {
|
||||
const _OidcCallbackPage({
|
||||
this.code,
|
||||
this.callbackState,
|
||||
this.error,
|
||||
this.errorDescription,
|
||||
});
|
||||
|
||||
final String? code;
|
||||
final String? callbackState;
|
||||
final String? error;
|
||||
final String? errorDescription;
|
||||
|
||||
@override
|
||||
ConsumerState<_OidcCallbackPage> createState() => _OidcCallbackPageState();
|
||||
}
|
||||
|
||||
class _OidcCallbackPageState extends ConsumerState<_OidcCallbackPage> {
|
||||
bool _isProcessing = true;
|
||||
String? _error;
|
||||
|
||||
@override
|
||||
void initState() {
|
||||
super.initState();
|
||||
// Defer callback processing to avoid Riverpod state modification during build
|
||||
WidgetsBinding.instance.addPostFrameCallback((_) {
|
||||
_processCallback();
|
||||
});
|
||||
}
|
||||
|
||||
Future<void> _processCallback() async {
|
||||
// Check mounted before any async work
|
||||
if (!mounted) return;
|
||||
|
||||
// Check for error from Authentik
|
||||
if (widget.error != null) {
|
||||
setState(() {
|
||||
_isProcessing = false;
|
||||
_error = widget.errorDescription ?? widget.error;
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
// Check for required parameters
|
||||
if (widget.code == null || widget.callbackState == null) {
|
||||
setState(() {
|
||||
_isProcessing = false;
|
||||
_error = 'Invalid callback - missing code or state parameter';
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
// Get notifier reference before async gap to avoid disposed ref errors
|
||||
final authNotifier = ref.read(authProvider.notifier);
|
||||
|
||||
// Exchange code for tokens
|
||||
try {
|
||||
await authNotifier.handleOidcCallback(
|
||||
widget.code!,
|
||||
widget.callbackState!,
|
||||
);
|
||||
|
||||
// Navigate to home on success
|
||||
if (mounted) {
|
||||
context.go(AppRoutes.frontHall);
|
||||
}
|
||||
} catch (e) {
|
||||
if (mounted) {
|
||||
setState(() {
|
||||
_isProcessing = false;
|
||||
_error = e.toString();
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@override
|
||||
Widget build(BuildContext context) {
|
||||
final colorScheme = Theme.of(context).colorScheme;
|
||||
|
||||
return Scaffold(
|
||||
body: Center(
|
||||
child: ConstrainedBox(
|
||||
constraints: const BoxConstraints(maxWidth: 400),
|
||||
child: Card(
|
||||
child: Padding(
|
||||
padding: const EdgeInsets.all(32),
|
||||
child: Column(
|
||||
mainAxisSize: MainAxisSize.min,
|
||||
children: [
|
||||
Icon(
|
||||
_error != null ? Icons.error_outline : Icons.home_work_outlined,
|
||||
size: 64,
|
||||
color: _error != null ? colorScheme.error : colorScheme.primary,
|
||||
),
|
||||
const SizedBox(height: 24),
|
||||
Text(
|
||||
_error != null ? 'Authentication Failed' : 'Signing in...',
|
||||
style: Theme.of(context).textTheme.headlineMedium?.copyWith(
|
||||
fontWeight: FontWeight.w600,
|
||||
),
|
||||
),
|
||||
const SizedBox(height: 16),
|
||||
if (_isProcessing)
|
||||
const CircularProgressIndicator()
|
||||
else if (_error != null) ...[
|
||||
Container(
|
||||
padding: const EdgeInsets.all(12),
|
||||
decoration: BoxDecoration(
|
||||
color: colorScheme.errorContainer,
|
||||
borderRadius: BorderRadius.circular(8),
|
||||
),
|
||||
child: Text(
|
||||
_error!,
|
||||
style: TextStyle(color: colorScheme.onErrorContainer),
|
||||
textAlign: TextAlign.center,
|
||||
),
|
||||
),
|
||||
const SizedBox(height: 16),
|
||||
OutlinedButton.icon(
|
||||
onPressed: () => context.go(AppRoutes.frontHall),
|
||||
icon: const Icon(Icons.refresh),
|
||||
label: const Text('Try again'),
|
||||
style: OutlinedButton.styleFrom(
|
||||
minimumSize: const Size(double.infinity, 48),
|
||||
),
|
||||
),
|
||||
],
|
||||
],
|
||||
),
|
||||
),
|
||||
),
|
||||
),
|
||||
),
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
import 'package:flutter/foundation.dart' show kIsWeb;
|
||||
import 'package:flutter/material.dart';
|
||||
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
||||
import 'package:go_router/go_router.dart';
|
||||
@@ -45,6 +46,7 @@ class _AppScaffoldState extends ConsumerState<AppScaffold> {
|
||||
return _buildScaffold(context);
|
||||
}
|
||||
|
||||
// Watch auth state (works for both web and mobile)
|
||||
final authAsync = ref.watch(authProvider);
|
||||
|
||||
return authAsync.when(
|
||||
@@ -55,7 +57,13 @@ class _AppScaffoldState extends ConsumerState<AppScaffold> {
|
||||
return _buildScaffold(context);
|
||||
}
|
||||
|
||||
// Not authenticated - auto-initiate OIDC
|
||||
// On web, NPM handles auth - if we're here without auth, something is wrong
|
||||
// (NPM should have redirected to Authentik before we loaded)
|
||||
if (kIsWeb) {
|
||||
return _buildAuthErrorScreen(context, 'Authentication required');
|
||||
}
|
||||
|
||||
// Mobile: Not authenticated - auto-initiate OIDC
|
||||
if (!_authInitiated) {
|
||||
_authInitiated = true;
|
||||
WidgetsBinding.instance.addPostFrameCallback((_) {
|
||||
@@ -66,7 +74,7 @@ class _AppScaffoldState extends ConsumerState<AppScaffold> {
|
||||
// Show loading while redirecting to Authentik
|
||||
return _buildAuthLoadingScreen(context, 'Redirecting to sign in...');
|
||||
},
|
||||
loading: () => _buildAuthLoadingScreen(context, 'Checking authentication...'),
|
||||
loading: () => _buildAuthLoadingScreen(context, 'Loading user info...'),
|
||||
error: (error, _) => _buildAuthErrorScreen(context, error),
|
||||
);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,53 @@
|
||||
# Increase buffer size for large headers from Authentik
|
||||
proxy_buffers 8 16k;
|
||||
proxy_buffer_size 32k;
|
||||
|
||||
# Exclude static assets from forward auth
|
||||
# These paths bypass auth_request but still proxy to upstream
|
||||
location ~ ^/(manifest\.json|favicon\.(ico|png)|health|icons|assets) {
|
||||
auth_request off;
|
||||
proxy_pass $forward_scheme://$server:$port;
|
||||
}
|
||||
|
||||
# Forward authentication via standalone outpost
|
||||
auth_request /outpost.goauthentik.io/auth/nginx;
|
||||
error_page 401 = @goauthentik_proxy_signin;
|
||||
|
||||
# Capture auth response headers
|
||||
auth_request_set $auth_cookie $upstream_http_set_cookie;
|
||||
auth_request_set $authentik_username $upstream_http_x_authentik_username;
|
||||
auth_request_set $authentik_groups $upstream_http_x_authentik_groups;
|
||||
auth_request_set $authentik_email $upstream_http_x_authentik_email;
|
||||
auth_request_set $authentik_name $upstream_http_x_authentik_name;
|
||||
auth_request_set $authentik_uid $upstream_http_x_authentik_uid;
|
||||
|
||||
# Forward auth headers to application
|
||||
add_header Set-Cookie $auth_cookie;
|
||||
proxy_set_header X-authentik-username $authentik_username;
|
||||
proxy_set_header X-authentik-groups $authentik_groups;
|
||||
proxy_set_header X-authentik-email $authentik_email;
|
||||
proxy_set_header X-authentik-name $authentik_name;
|
||||
proxy_set_header X-authentik-uid $authentik_uid;
|
||||
|
||||
# Outpost proxy location
|
||||
location /outpost.goauthentik.io {
|
||||
proxy_pass https://localhost:9444/outpost.goauthentik.io;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Host $http_host;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
|
||||
# WebSocket support
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
}
|
||||
|
||||
# Signin redirect handler
|
||||
location @goauthentik_proxy_signin {
|
||||
internal;
|
||||
return 302 /outpost.goauthentik.io/start?rd=$request_uri;
|
||||
}
|
||||
+1
-1
@@ -16,7 +16,7 @@ publish_to: 'none' # Remove this line if you wish to publish to pub.dev
|
||||
# https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html
|
||||
# In Windows, build-name is used as the major, minor, and patch parts
|
||||
# of the product and file versions while build-number is used as the build suffix.
|
||||
version: 1.1.1+1
|
||||
version: 1.1.10+1
|
||||
|
||||
environment:
|
||||
sdk: ^3.10.4
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env dart
|
||||
// Generates web/health.json from pubspec.yaml
|
||||
// Generates web/health/health.json from pubspec.yaml
|
||||
// Run: dart run tool/generate_health_json.dart
|
||||
|
||||
// ignore_for_file: avoid_print
|
||||
@@ -37,15 +37,15 @@ void main() {
|
||||
'fullVersion': '$version+$buildNumber',
|
||||
};
|
||||
|
||||
final webDir = Directory('web');
|
||||
if (!webDir.existsSync()) {
|
||||
webDir.createSync(recursive: true);
|
||||
final healthDir = Directory('web/health');
|
||||
if (!healthDir.existsSync()) {
|
||||
healthDir.createSync(recursive: true);
|
||||
}
|
||||
|
||||
final healthFile = File('web/health.json');
|
||||
final healthFile = File('web/health/health.json');
|
||||
healthFile.writeAsStringSync(
|
||||
const JsonEncoder.withIndent(' ').convert(health),
|
||||
);
|
||||
|
||||
print('Generated web/health.json with version $version+$buildNumber');
|
||||
print('Generated web/health/health.json with version $version+$buildNumber');
|
||||
}
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"status": "healthy",
|
||||
"name": "tatlock_ui",
|
||||
"title": "Tatlock - a Home Lab AI",
|
||||
"version": "1.0.4",
|
||||
"buildNumber": 1,
|
||||
"fullVersion": "1.0.4+1"
|
||||
}
|
||||
@@ -13,7 +13,7 @@
|
||||
<h1 id="status">Loading...</h1>
|
||||
<pre id="data"></pre>
|
||||
<script>
|
||||
fetch('/health.json')
|
||||
fetch('./health.json')
|
||||
.then(r => r.json())
|
||||
.then(data => {
|
||||
document.getElementById('status').textContent = data.status?.toUpperCase() || 'OK';
|
||||
@@ -32,6 +32,13 @@
|
||||
|
||||
<title>Tatlock</title>
|
||||
<link rel="manifest" href="manifest.json">
|
||||
<style>
|
||||
body {
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
background-color: #1a1a2e;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<script src="flutter_bootstrap.js" async></script>
|
||||
|
||||
Reference in New Issue
Block a user