The AuthInterceptor was calling signOut() on any 401 error, which caused the theme toggle to trigger logout when the preferences API returned 401. Now 401 errors propagate to calling code for graceful handling. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
13 KiB
13 KiB
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[Unreleased]
[1.1.16] - 2026-01-05
Fixed
- Theme toggle causing logout due to AuthInterceptor auto-signout on 401
- Removed aggressive
signOut()call inAuthInterceptor.onError - 401 errors now propagate to calling code for graceful handling
- Preferences API 401 no longer triggers full logout redirect
- Removed aggressive
[1.1.15] - 2026-01-05
Fixed
- Theme toggle causing auth issues due to AuthNotifier auto-dispose
- Applied
@persistentRiverpodannotation to AuthNotifier - AuthProvider now persists for app lifetime, preventing rebuild on theme change
- Applied
[1.1.14] - 2026-01-04
Fixed
- Theme toggle causing auth issues due to ThemeProvider auto-dispose
- Added
@persistentRiverpodannotation for providers that need keepAlive - ThemeProvider now persists for app lifetime
- Added
Added
@persistentRiverpodannotation incore/providers/annotations.dart- Reusable annotation for providers that should not auto-dispose
- Documented in ARCHITECTURE.md
[1.1.13] - 2026-01-04
Added
- Settings page with Appearance, Navigation, and Account sections
- Theme toggle in user profile dropdown (System/Light/Dark)
- Theme syncs with API preferences on login
- Default room preference syncs with backend
Changed
- Theme changes now persist to both local storage and API
[1.1.12] - 2026-01-04
Changed
- Control Room navigation reorganized:
- New "Stack" section with Containers and Proxy Hosts
- New "Data Management" section with PostgreSQL, Redis, Qdrant, Neo4j placeholders
- Removed: Networks, Volumes, Images (Portainer) and Redirections, Streams, Certificates (NPM)
[1.1.11] - 2026-01-04
Fixed
- API client providers now use
keepAlive: trueto prevent Ref invalidation- Fixes "DioException [unknown]: null" error on /security/users and other API pages
- AuthInterceptor's stored Ref was becoming invalid when provider auto-disposed
[1.1.10] - 2026-01-04
Changed
- Removed page swipe transitions - all navigation is now instant (NoTransitionPage)
[1.1.9] - 2026-01-04
Changed
- Moved health check to
/healthdirectory - URL is now/healthinstead of/health.html- Enables NPM forward auth path exclusion for health endpoint
[1.1.8] - 2026-01-04
Changed
- Dark background (
#1a1a2e) on web/index.html to prevent white flash during auth redirects
[1.1.7] - 2026-01-04
Removed
- Removed
/callbackroute from Flutter router - AuthController handles callback in main() before app starts - Removed
_OidcCallbackPagewidget - no visible auth UI needed
[1.1.6] - 2026-01-04
Changed
- Auth moved to standalone controller - Handles OIDC completely outside Riverpod
- New
AuthControllerruns inmain()beforerunApp()- avoids provider lifecycle issues - Handles callback, token exchange, and /auth/sync before app starts
- If auth not ready (redirecting), app doesn't start at all
AuthProvidernow just loads stored tokens (no async OIDC logic)- Fixes "Cannot use Ref after disposed" errors from autoDispose providers
- New
[1.1.5] - 2026-01-04
Fixed
- Race condition in OIDC callback: AuthProvider.build() was initiating silent OIDC while the callback page was processing, causing PKCE state to be cleared. Now skips silent OIDC when on
/callbackroute.
[1.1.4] - 2026-01-04
Fixed
- Silent OIDC fallback: when
prompt=nonefails withlogin_required(no Authentik session), automatically fall back to regular OIDC flow to show login UI
[1.1.3] - 2026-01-04
Changed
- Web auth uses silent OIDC with JWT Bearer tokens
- Uses
prompt=noneto silently obtain JWT when Authentik session exists (via NPM forward auth) - Flutter sends Bearer token to core-api instead of relying on forward auth cookies
- Fixes cross-subdomain cookie issues between home.schweitz.net and api.schweitz.net
- Callback now syncs with
/auth/syncto get user profile and roles from core-api - API interceptor now adds Bearer token on web (previously skipped)
- Uses
[1.1.2] - 2026-01-04
Changed
- Web auth simplified: Skip Flutter OIDC on web - NPM forward auth handles it
- NPM authenticates at proxy level before app loads
- No more redundant OIDC redirect after NPM auth completes
- Fixes "Cannot use Ref after disposed" error from conflicting auth flows
- Mobile still uses Flutter OIDC flow
Added
- Logout now redirects to Authentik to end SSO session
- Clears local tokens AND invalidates Authentik session
- Uses OIDC end_session_endpoint from discovery document
- Redirects back to app after Authentik logout completes
[1.1.0] - 2026-01-04
Changed
- Dockerfile rebuild fix: Added
flutter cleanbefore build to prevent stale cached artifacts- VERSION build arg added for explicit cache busting
- Reordered build steps: clean → pub get → build_runner → health.json → flutter build
- Ensures deployed app always matches the version in health.json
Fixed
- Replaced deprecated
dart:htmlwithpackage:webin iframe_view_web.dart- Uses
web.HTMLIFrameElementinstead ofhtml.IFrameElement - Fixes deprecation warnings for Flutter 3.x web builds
- Uses
[1.0.12] - 2026-01-04
Changed
- Removed login page - auth now auto-initiates from AppScaffold
- No more redirect to /login, just auto-start OIDC if not authenticated
- Shows loading screen during auth, error screen on failure with retry
- Seamless experience when Authentik session exists
Removed
- Removed /login route and _LoginPage widget
[1.0.11] - 2026-01-04
Changed
- Web auth now extracts user info directly from JWT instead of syncing with core-api
- Eliminates CORS preflight issues with /auth/sync endpoint
- Decodes JWT claims (name, email, groups) client-side
- Bearer token will be used for API authentication
[1.0.10] - 2026-01-04
Fixed
- Fixed OIDC callback route being redirected to login before processing
- Moved callback route exception check BEFORE the auth redirect check in router
- This was preventing token exchange from ever happening
- Added favicon.ico to web root for proper browser tab icon display
[1.0.9] - 2026-01-04
Fixed
- Fixed OIDC callback Riverpod state modification error
- Deferred callback processing to
addPostFrameCallbackto avoid modifying state during widget build
- Deferred callback processing to
[1.0.8] - 2026-01-04
Changed
- Switched from hash-based URLs (
/#/login) to path-based URLs (/login)- Required for OIDC callback to work correctly
- Uses conditional import to avoid breaking mobile/desktop builds
[1.0.7] - 2026-01-04
Fixed
- Fixed OIDC PKCE state loss across browser redirect
- Code verifier and state now persist in sessionStorage instead of memory
- Prevents "No code verifier" error after Authentik redirect
[1.0.6] - 2026-01-04
Fixed
- Fixed version generation in CI/CD builds
- Removed generated files (version.g.dart, health.json) from git tracking
- These files are now regenerated from pubspec.yaml during Docker build
[1.0.5] - 2026-01-04
Changed
- Web authentication now uses OIDC instead of NPM forward auth
- Added
OidcServiceWebfor browser redirect-based Authorization Code flow with PKCE - Added
/callbackroute to handle Authentik redirect after login - Login page now shows "Sign in with Authentik" button for both web and mobile
- Tokens stored in SharedPreferences and synced with core-api via
/auth/sync
- Added
- Added web utility functions (
web_utils.dart) with conditional imports for non-web platforms - Added
cryptoandwebpackages for PKCE SHA-256 and browser API access
Fixed
- Removed cross-origin cookie dependency that caused authentication failures on web
[1.0.4] - 2026-01-03
Added
health.jsongenerated at build time with app version infohealth.htmlnow displays version, title, and status from health.json
[1.0.3] - 2026-01-03
Fixed
- Fixed auth endpoint path:
/auth/me→/auth/users/me
[1.0.2] - 2026-01-03
Fixed
- Production Docker build now uses correct API URLs
- Added
--dart-defineflags forCORE_API_URLandTATLOCK_API_URL - This enables
requiresAuth=trueso authentication is actually triggered
- Added
- Updated AGENTS.md with clear service port reference table
[1.0.1] - 2026-01-03
Fixed
- Web authentication now works correctly with NPM forward auth
- Dio client sends cookies with requests via
withCredentials: true - Added platform-specific adapters (native vs web) for proper cookie handling
- Dio client sends cookies with requests via
[1.0.0] - 2026-01-03
Added
- Authentication System - Dual-flow auth supporting web (NPM forward auth) and mobile (OIDC)
AuthStatemodel with roles, permissions, and user preferencesAuthProviderwith automatic web session detection via/auth/me- Permission system with Domain/Action enums and hierarchical access levels
PermissionGateandAdminGatewidgets for UI permission checksRolemodel with{domain}.{category}:{action}format parsing- Route guards redirect unauthenticated users to login page
- Login page with Authentik OAuth redirect
- Mobile auth platform configuration (iOS URL schemes, Android AppAuth)
- Comprehensive auth test suite (60 unit tests)
Changed
- API interceptor skips Bearer tokens on web (uses cookies via NPM forward auth)
- Router integrates auth state for protected route access
- First stable release - Core functionality complete for home lab dashboard
[0.3.3] - 2026-01-03
Added
- Health check endpoint (
/health.html) for Portainer container monitoring - Local search filtering in DataGrid (filters cached data client-side)
- Container status badges now reflect health status (green=healthy, orange=unhealthy)
ContainerHealthenum for parsing Docker health status from status string
Changed
- Standardized header bar heights to 56px across all panels
- Container grid now correctly parses Docker API JSON format (capitalized keys)
- Status column displays clean uptime (stripped health indicators)
- Status badges have consistent minimum width (90px)
- Search bar styling improved (36px height, visible border, proper background)
- Quick links now properly persist link type (iframe vs new tab)
- Iframe switching now closes existing content before loading new link
Fixed
- Quick links form properly saves changes and refreshes panel
ContainerStatetype conflict resolved (removed duplicate enum)- Container data parsing handles null values safely
Branding
- Updated favicon and icons with Tatlock bucket logo
- Updated manifest.json with Tatlock branding
[0.3.2] - 2025-01-02
Changed
- API defaults now use LAN IPs for local development (no auth required)
- Auth interceptor skips authentication when using LAN endpoints
[0.3.0] - 2025-12-30
Added
- docs/UI_LAYOUT.md - Responsive layout specification with "Rooms of the Estate" navigation
Changed
- Directory structure now mirrors room navigation (front_hall/, control_room/, parlor/, library/, study/)
- Chat moved to top-level
lib/chat/(omnipresent, not a room) - Updated ARCHITECTURE.md and PLAN.md to reflect room-based structure
- Version generation now automated via build_runner (replaces manual script)
lib/version.g.dartauto-generated frompubspec.yamlduring build
[0.2.0] - 2024-12-30
Added
- Phase 1: Foundation complete
- Clean Architecture folder structure (
core/,features/,shared/,routing/) - Full dependency stack: Riverpod, Dio, go_router, freezed, flex_color_scheme
- Core infrastructure:
core/config/app_config.dart- Environment configurationcore/theme/app_theme.dart- Material 3 theming with FlexColorSchemecore/theme/theme_provider.dart- Theme state with persistencecore/error/app_exception.dart- Typed exception hierarchycore/api/api_client.dart- Dio HTTP clients for Core API and Tatlock APIcore/api/api_interceptors.dart- Auth, logging, error interceptorscore/auth/auth_provider.dart- Authentication state management
- Routing with go_router and shell route for navigation
- Adaptive scaffold with responsive navigation (rail/bottom nav)
- Dashboard page placeholder with welcome card and stat cards
[0.1.0] - 2024-12-30
Added
- Initial Flutter project setup with all platforms (web, android, ios, macos, linux, windows)
- Build-time version generation from pubspec.yaml (
dart run tool/generate_version.dart) - Version logging on app startup
- Project documentation (PHILOSOPHY.md, README.md, AGENTS.md, PLAN.md)
- Phase 0 technical documentation:
- docs/ARCHITECTURE.md - Clean Architecture patterns
- docs/API_INTEGRATION.md - Backend API reference
- docs/DEPLOYMENT.md - Docker and infrastructure setup
- docs/DATAGRID.md - DataGrid component specification
- docs/THEMING.md - Material 3 theming guide