Files
tatlock-ui/CHANGELOG.md
T
Jeroen SchweitzerandClaude Opus 4.5 04032a6dbc
Build and Push / release (push) Successful in 3s
Build and Push / build (push) Successful in 3m2s
fix(auth): remove auto-signout on 401 in AuthInterceptor
The AuthInterceptor was calling signOut() on any 401 error, which caused
the theme toggle to trigger logout when the preferences API returned 401.
Now 401 errors propagate to calling code for graceful handling.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-05 10:16:43 +01:00

13 KiB

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[1.1.16] - 2026-01-05

Fixed

  • Theme toggle causing logout due to AuthInterceptor auto-signout on 401
    • Removed aggressive signOut() call in AuthInterceptor.onError
    • 401 errors now propagate to calling code for graceful handling
    • Preferences API 401 no longer triggers full logout redirect

[1.1.15] - 2026-01-05

Fixed

  • Theme toggle causing auth issues due to AuthNotifier auto-dispose
    • Applied @persistentRiverpod annotation to AuthNotifier
    • AuthProvider now persists for app lifetime, preventing rebuild on theme change

[1.1.14] - 2026-01-04

Fixed

  • Theme toggle causing auth issues due to ThemeProvider auto-dispose
    • Added @persistentRiverpod annotation for providers that need keepAlive
    • ThemeProvider now persists for app lifetime

Added

  • @persistentRiverpod annotation in core/providers/annotations.dart
    • Reusable annotation for providers that should not auto-dispose
    • Documented in ARCHITECTURE.md

[1.1.13] - 2026-01-04

Added

  • Settings page with Appearance, Navigation, and Account sections
  • Theme toggle in user profile dropdown (System/Light/Dark)
  • Theme syncs with API preferences on login
  • Default room preference syncs with backend

Changed

  • Theme changes now persist to both local storage and API

[1.1.12] - 2026-01-04

Changed

  • Control Room navigation reorganized:
    • New "Stack" section with Containers and Proxy Hosts
    • New "Data Management" section with PostgreSQL, Redis, Qdrant, Neo4j placeholders
    • Removed: Networks, Volumes, Images (Portainer) and Redirections, Streams, Certificates (NPM)

[1.1.11] - 2026-01-04

Fixed

  • API client providers now use keepAlive: true to prevent Ref invalidation
    • Fixes "DioException [unknown]: null" error on /security/users and other API pages
    • AuthInterceptor's stored Ref was becoming invalid when provider auto-disposed

[1.1.10] - 2026-01-04

Changed

  • Removed page swipe transitions - all navigation is now instant (NoTransitionPage)

[1.1.9] - 2026-01-04

Changed

  • Moved health check to /health directory - URL is now /health instead of /health.html
    • Enables NPM forward auth path exclusion for health endpoint

[1.1.8] - 2026-01-04

Changed

  • Dark background (#1a1a2e) on web/index.html to prevent white flash during auth redirects

[1.1.7] - 2026-01-04

Removed

  • Removed /callback route from Flutter router - AuthController handles callback in main() before app starts
  • Removed _OidcCallbackPage widget - no visible auth UI needed

[1.1.6] - 2026-01-04

Changed

  • Auth moved to standalone controller - Handles OIDC completely outside Riverpod
    • New AuthController runs in main() before runApp() - avoids provider lifecycle issues
    • Handles callback, token exchange, and /auth/sync before app starts
    • If auth not ready (redirecting), app doesn't start at all
    • AuthProvider now just loads stored tokens (no async OIDC logic)
    • Fixes "Cannot use Ref after disposed" errors from autoDispose providers

[1.1.5] - 2026-01-04

Fixed

  • Race condition in OIDC callback: AuthProvider.build() was initiating silent OIDC while the callback page was processing, causing PKCE state to be cleared. Now skips silent OIDC when on /callback route.

[1.1.4] - 2026-01-04

Fixed

  • Silent OIDC fallback: when prompt=none fails with login_required (no Authentik session), automatically fall back to regular OIDC flow to show login UI

[1.1.3] - 2026-01-04

Changed

  • Web auth uses silent OIDC with JWT Bearer tokens
    • Uses prompt=none to silently obtain JWT when Authentik session exists (via NPM forward auth)
    • Flutter sends Bearer token to core-api instead of relying on forward auth cookies
    • Fixes cross-subdomain cookie issues between home.schweitz.net and api.schweitz.net
    • Callback now syncs with /auth/sync to get user profile and roles from core-api
    • API interceptor now adds Bearer token on web (previously skipped)

[1.1.2] - 2026-01-04

Changed

  • Web auth simplified: Skip Flutter OIDC on web - NPM forward auth handles it
    • NPM authenticates at proxy level before app loads
    • No more redundant OIDC redirect after NPM auth completes
    • Fixes "Cannot use Ref after disposed" error from conflicting auth flows
    • Mobile still uses Flutter OIDC flow

Added

  • Logout now redirects to Authentik to end SSO session
    • Clears local tokens AND invalidates Authentik session
    • Uses OIDC end_session_endpoint from discovery document
    • Redirects back to app after Authentik logout completes

[1.1.0] - 2026-01-04

Changed

  • Dockerfile rebuild fix: Added flutter clean before build to prevent stale cached artifacts
    • VERSION build arg added for explicit cache busting
    • Reordered build steps: clean → pub get → build_runner → health.json → flutter build
    • Ensures deployed app always matches the version in health.json

Fixed

  • Replaced deprecated dart:html with package:web in iframe_view_web.dart
    • Uses web.HTMLIFrameElement instead of html.IFrameElement
    • Fixes deprecation warnings for Flutter 3.x web builds

[1.0.12] - 2026-01-04

Changed

  • Removed login page - auth now auto-initiates from AppScaffold
    • No more redirect to /login, just auto-start OIDC if not authenticated
    • Shows loading screen during auth, error screen on failure with retry
    • Seamless experience when Authentik session exists

Removed

  • Removed /login route and _LoginPage widget

[1.0.11] - 2026-01-04

Changed

  • Web auth now extracts user info directly from JWT instead of syncing with core-api
    • Eliminates CORS preflight issues with /auth/sync endpoint
    • Decodes JWT claims (name, email, groups) client-side
    • Bearer token will be used for API authentication

[1.0.10] - 2026-01-04

Fixed

  • Fixed OIDC callback route being redirected to login before processing
    • Moved callback route exception check BEFORE the auth redirect check in router
    • This was preventing token exchange from ever happening
  • Added favicon.ico to web root for proper browser tab icon display

[1.0.9] - 2026-01-04

Fixed

  • Fixed OIDC callback Riverpod state modification error
    • Deferred callback processing to addPostFrameCallback to avoid modifying state during widget build

[1.0.8] - 2026-01-04

Changed

  • Switched from hash-based URLs (/#/login) to path-based URLs (/login)
    • Required for OIDC callback to work correctly
    • Uses conditional import to avoid breaking mobile/desktop builds

[1.0.7] - 2026-01-04

Fixed

  • Fixed OIDC PKCE state loss across browser redirect
    • Code verifier and state now persist in sessionStorage instead of memory
    • Prevents "No code verifier" error after Authentik redirect

[1.0.6] - 2026-01-04

Fixed

  • Fixed version generation in CI/CD builds
  • Removed generated files (version.g.dart, health.json) from git tracking
  • These files are now regenerated from pubspec.yaml during Docker build

[1.0.5] - 2026-01-04

Changed

  • Web authentication now uses OIDC instead of NPM forward auth
    • Added OidcServiceWeb for browser redirect-based Authorization Code flow with PKCE
    • Added /callback route to handle Authentik redirect after login
    • Login page now shows "Sign in with Authentik" button for both web and mobile
    • Tokens stored in SharedPreferences and synced with core-api via /auth/sync
  • Added web utility functions (web_utils.dart) with conditional imports for non-web platforms
  • Added crypto and web packages for PKCE SHA-256 and browser API access

Fixed

  • Removed cross-origin cookie dependency that caused authentication failures on web

[1.0.4] - 2026-01-03

Added

  • health.json generated at build time with app version info
  • health.html now displays version, title, and status from health.json

[1.0.3] - 2026-01-03

Fixed

  • Fixed auth endpoint path: /auth/me → /auth/users/me

[1.0.2] - 2026-01-03

Fixed

  • Production Docker build now uses correct API URLs
    • Added --dart-define flags for CORE_API_URL and TATLOCK_API_URL
    • This enables requiresAuth=true so authentication is actually triggered
  • Updated AGENTS.md with clear service port reference table

[1.0.1] - 2026-01-03

Fixed

  • Web authentication now works correctly with NPM forward auth
    • Dio client sends cookies with requests via withCredentials: true
    • Added platform-specific adapters (native vs web) for proper cookie handling

[1.0.0] - 2026-01-03

Added

  • Authentication System - Dual-flow auth supporting web (NPM forward auth) and mobile (OIDC)
    • AuthState model with roles, permissions, and user preferences
    • AuthProvider with automatic web session detection via /auth/me
    • Permission system with Domain/Action enums and hierarchical access levels
    • PermissionGate and AdminGate widgets for UI permission checks
    • Role model with {domain}.{category}:{action} format parsing
    • Route guards redirect unauthenticated users to login page
  • Login page with Authentik OAuth redirect
  • Mobile auth platform configuration (iOS URL schemes, Android AppAuth)
  • Comprehensive auth test suite (60 unit tests)

Changed

  • API interceptor skips Bearer tokens on web (uses cookies via NPM forward auth)
  • Router integrates auth state for protected route access
  • First stable release - Core functionality complete for home lab dashboard

[0.3.3] - 2026-01-03

Added

  • Health check endpoint (/health.html) for Portainer container monitoring
  • Local search filtering in DataGrid (filters cached data client-side)
  • Container status badges now reflect health status (green=healthy, orange=unhealthy)
  • ContainerHealth enum for parsing Docker health status from status string

Changed

  • Standardized header bar heights to 56px across all panels
  • Container grid now correctly parses Docker API JSON format (capitalized keys)
  • Status column displays clean uptime (stripped health indicators)
  • Status badges have consistent minimum width (90px)
  • Search bar styling improved (36px height, visible border, proper background)
  • Quick links now properly persist link type (iframe vs new tab)
  • Iframe switching now closes existing content before loading new link

Fixed

  • Quick links form properly saves changes and refreshes panel
  • ContainerState type conflict resolved (removed duplicate enum)
  • Container data parsing handles null values safely

Branding

  • Updated favicon and icons with Tatlock bucket logo
  • Updated manifest.json with Tatlock branding

[0.3.2] - 2025-01-02

Changed

  • API defaults now use LAN IPs for local development (no auth required)
  • Auth interceptor skips authentication when using LAN endpoints

[0.3.0] - 2025-12-30

Added

  • docs/UI_LAYOUT.md - Responsive layout specification with "Rooms of the Estate" navigation

Changed

  • Directory structure now mirrors room navigation (front_hall/, control_room/, parlor/, library/, study/)
  • Chat moved to top-level lib/chat/ (omnipresent, not a room)
  • Updated ARCHITECTURE.md and PLAN.md to reflect room-based structure
  • Version generation now automated via build_runner (replaces manual script)
  • lib/version.g.dart auto-generated from pubspec.yaml during build

[0.2.0] - 2024-12-30

Added

  • Phase 1: Foundation complete
  • Clean Architecture folder structure (core/, features/, shared/, routing/)
  • Full dependency stack: Riverpod, Dio, go_router, freezed, flex_color_scheme
  • Core infrastructure:
    • core/config/app_config.dart - Environment configuration
    • core/theme/app_theme.dart - Material 3 theming with FlexColorScheme
    • core/theme/theme_provider.dart - Theme state with persistence
    • core/error/app_exception.dart - Typed exception hierarchy
    • core/api/api_client.dart - Dio HTTP clients for Core API and Tatlock API
    • core/api/api_interceptors.dart - Auth, logging, error interceptors
    • core/auth/auth_provider.dart - Authentication state management
  • Routing with go_router and shell route for navigation
  • Adaptive scaffold with responsive navigation (rail/bottom nav)
  • Dashboard page placeholder with welcome card and stat cards

[0.1.0] - 2024-12-30

Added

  • Initial Flutter project setup with all platforms (web, android, ios, macos, linux, windows)
  • Build-time version generation from pubspec.yaml (dart run tool/generate_version.dart)
  • Version logging on app startup
  • Project documentation (PHILOSOPHY.md, README.md, AGENTS.md, PLAN.md)
  • Phase 0 technical documentation:
    • docs/ARCHITECTURE.md - Clean Architecture patterns
    • docs/API_INTEGRATION.md - Backend API reference
    • docs/DEPLOYMENT.md - Docker and infrastructure setup
    • docs/DATAGRID.md - DataGrid component specification
    • docs/THEMING.md - Material 3 theming guide