Justin Richer
54708fb0ac
fixed id token scopes (shouldn't inherit from parent token)
2012-12-10 10:11:02 -05:00
Justin Richer
2a206654b6
added client credential protection to revocation endpoint
2012-12-07 17:17:19 -05:00
Justin Richer
e38b2b0ba5
shortened revocation endpoint url
2012-12-07 17:16:03 -05:00
Justin Richer
fbc3c46128
Introspection now draft spec compliant, requires client auth
...
Currently this is the client that originally sent the token, we want to have a way to bind other "clients" to this token as well, like resource services. Also want to let open calls, sometimes.
2012-12-07 17:12:13 -05:00
Justin Richer
544e3d7b43
added copy constructors because Dave likes to use unmodifiable sets for no apparent reason
2012-12-07 10:06:10 -05:00
Justin Richer
64ef752f08
added refresh token granter for testing
2012-12-07 09:56:43 -05:00
Justin Richer
7561ac9e8c
client dynamic registration now protected by access token, addresses #199
2012-12-06 17:48:23 -05:00
Justin Richer
7342da6a51
completed making id tokens into access tokens
2012-12-06 16:24:04 -05:00
Justin Richer
e4f9fa2bbf
labeled introspection endpoint
2012-12-06 16:19:25 -05:00
Justin Richer
17374a57e0
added ISO date format to generic entity view, addresses #232
2012-12-06 16:15:14 -05:00
Justin Richer
3378cd5c4c
cleaned table
2012-12-06 14:24:38 -05:00
Justin Richer
b8f701d9d8
switched id tokens to entities, they're now access tokens also
...
still needs some work to get the auth object right, for now we're just copying from the access token
2012-12-06 10:19:21 -05:00
Justin Richer
2ef8d16e9c
typo, formatting
2012-12-05 15:49:50 -05:00
Justin Richer
ba7ddf17f9
added bootstrapping for clients, cleaned up sql files
2012-12-05 15:04:14 -05:00
Justin Richer
cf7ceb74f3
betterer logout button
2012-12-04 16:40:28 -05:00
Justin Richer
2f1a6864b8
made a better logout button
2012-12-04 16:37:57 -05:00
Justin Richer
838e029db1
added logout button
2012-12-04 16:18:58 -05:00
Justin Richer
d7d9e84e70
fixed user_id mapping
2012-12-04 16:18:37 -05:00
Justin Richer
f091343d84
moved back to in-memory database by default
2012-12-04 15:56:03 -05:00
Justin Richer
49e216412e
Added bootstrapped users set.
2012-12-04 15:51:10 -05:00
Justin Richer
dcc56ec9dd
temporary tables to prevent casts from leaking
2012-12-04 14:38:08 -05:00
Justin Richer
8b37011244
added casts to varchar to avoid extraneous spaces
2012-12-04 13:35:40 -05:00
Justin Richer
e305d3b16b
Making stable in-memory and in-file database with HSQL
2012-12-03 17:53:25 -05:00
Justin Richer
061c0f0814
minor cleanup
2012-12-03 16:10:07 -05:00
Stephen Moore
250432ce7f
Added information into the user_info table
2012-12-03 14:56:40 -05:00
Stephen Moore
1bcaa68cb4
Added user_info stuff... and changed serverconfig for issuer...
2012-12-03 14:56:40 -05:00
Stephen Moore
47b34d2b1b
Added blacklist table to HSQLDB sql script
2012-12-03 14:56:40 -05:00
Stephen Moore
4fdb0816eb
Moved DB to use in memory HSQLDB. Made authentication-provider use a jdbc-user-service in that in-memory hsqldb.
2012-12-03 14:56:40 -05:00
Justin Richer
fce47c239a
added slashes to patterns what needed them, removed vestigial intercept from user-context
2012-11-26 16:23:46 -05:00
Justin Richer
122a2de074
First attempt at making API not redirect to /login, failed
2012-11-26 16:05:46 -05:00
Justin Richer
d07f67bd76
let user select when grants time out
2012-11-26 14:26:07 -05:00
Justin Richer
84401531ae
tie refresh token generation to "offline" scope tag
2012-11-26 13:16:19 -05:00
Justin Richer
50040a8ef4
fixed checkbox labels
2012-11-26 12:57:49 -05:00
Justin Richer
667c3abc8a
dynamic scope display/selection on approval page
2012-11-26 11:53:19 -05:00
Justin Richer
1281d75aa9
stopped re-parsing scopes
2012-11-26 11:53:19 -05:00
Justin Richer
9c3a40779b
updated to SECOAUTH's horrible new object-breaking authorization request paradigm.
...
Bonus: it works!
2012-11-26 11:53:19 -05:00
Justin Richer
3e327b9df6
reverted to original controller behavior
2012-11-26 11:53:19 -05:00
Justin Richer
cf4581a5eb
updated configuration to reflect secoauth changes
2012-11-26 11:53:19 -05:00
Justin Richer
45ca4e565e
updated to SECOAUTH-1.0.1-BUILD-SNAPSHOT
2012-11-26 11:53:19 -05:00
Amanda Anganes
cf1ddf0457
Determined that init binder was not needed to fix default for Boolean require_auth_time; instead use defaultValue=\"true\" in the RequestParam declaration. Also fixed bug in ClientDetails service so that it will not blow up if the client has no redirect uris registered
2012-11-21 15:39:07 -05:00
Amanda Anganes
2084639828
Working on init binder for ClientDynamicRegistrationEndpoint
2012-11-21 14:54:24 -05:00
Amanda Anganes
8b0c520534
Issue 213, writing init binder to convert null Boolean values to false before calling setters
2012-11-21 14:53:41 -05:00
Justin Richer
a2a29e7b76
trying out new confirmation controller
2012-11-21 10:00:35 -05:00
Justin Richer
d9b6918bc2
softened error from scope checker -- returns false now, allows things to pass through
2012-11-20 14:08:18 -05:00
Justin Richer
9c08944a02
Changed arity on approved sites (now can have many per user/site combo)
2012-11-20 14:07:55 -05:00
Justin Richer
58b97f7371
stupid javascript
2012-11-20 13:16:08 -05:00
Justin Richer
fda86e23e9
moved everything to use the consumes/produces framework of Spring 3.1
2012-11-20 13:12:21 -05:00
Justin Richer
51920ee381
switched to using "uneditable-input" classes instead of disabled input fields
2012-11-19 16:32:04 -05:00
Justin Richer
e303319701
got rid of postrender
2012-11-19 16:13:49 -05:00
Justin Richer
5b0c17c5de
added in checks to blacklist service upon client registration and update
2012-11-19 14:10:55 -05:00
Justin Richer
7a6c96a759
fixed links
2012-11-19 14:10:37 -05:00
Justin Richer
e9d1ed270d
service layer cleanups
2012-11-19 13:46:09 -05:00
Justin Richer
4e18fb4525
blacklist management UI
2012-11-19 13:01:16 -05:00
Justin Richer
d576df4b31
fixed render length limits on list widget
2012-11-19 11:52:30 -05:00
Justin Richer
757e21a722
added blacklist API
2012-11-16 11:57:46 -05:00
Justin Richer
1f4b97bc7e
fixed icon and variable reference
2012-11-16 10:14:28 -05:00
Justin Richer
e86f19bd7c
added dynamic icons to whitelist table
2012-11-15 17:53:38 -05:00
Justin Richer
2beff07d4b
added icons and tooltips to approved site table
2012-11-15 17:51:31 -05:00
Justin Richer
20b73ea0c4
tooltip works!
2012-11-15 17:46:13 -05:00
Justin Richer
8ecdb8a4ab
added icon to template, popover doesn't work yet
2012-11-15 17:41:00 -05:00
Justin Richer
9064b49a54
added refresh buttons to all tables, fixed loading behavior to a proper cascading function call
2012-11-15 16:55:51 -05:00
Justin Richer
a88ae8258a
Updated plus and minus buttons in list views, addresses #202
2012-11-15 16:35:17 -05:00
Justin Richer
150c4032fd
WTF MYSQL!!
...
Added "NULL" option to all appropriate TIMESTAMP columns so that they behave how we expect them to.
2012-11-15 15:23:54 -05:00
Justin Richer
f9aafb5edd
approved sites UI
2012-11-15 14:50:30 -05:00
Justin Richer
f4605ef2fc
cleaned out startAfter function
2012-11-15 12:18:47 -05:00
Justin Richer
845c11ad3a
methods for creating, editing, and deleting whitelist sites all function
2012-11-14 17:08:58 -05:00
Justin Richer
321172c40c
fixed load/fetch order, fixed edit form display, robustified whitelist views against missing client IDs
2012-11-14 16:30:10 -05:00
Justin Richer
f39c254353
updated variables for consistency, tracking down a data-loading bug
2012-11-14 15:21:41 -05:00
Justin Richer
51cfe1746d
whitelist editing
2012-11-14 15:20:32 -05:00
Justin Richer
bb589fc29a
fixed logic error in script inclusion
2012-11-13 18:05:15 -05:00
Justin Richer
cccbad2ca1
added whitelist button to table view
2012-11-13 17:55:29 -05:00
Justin Richer
7a9d7e6363
Fixed sidebar menu
2012-11-13 17:13:20 -05:00
Justin Richer
7b1a2529dc
added whitelist model and template
2012-11-13 17:11:09 -05:00
Justin Richer
ee0fe4a9d3
applied placeholder CSS hack to header CSS
2012-11-13 15:35:01 -05:00
Justin Richer
86ebdff82b
Revert "Placeholder UI updates"
...
This reverts commit fd89312b0c
.
2012-11-13 15:08:22 -05:00
Justin Richer
030e2ce2df
fixed link scanner
2012-11-13 15:06:09 -05:00
Justin Richer
706858c41f
added comments, fixed paths, uncommented logo hide function
2012-11-13 13:27:57 -05:00
Justin Richer
f2e1317365
added purl.js library for URL parsing
2012-11-13 13:12:15 -05:00
Justin Richer
33f11cb98f
cleanly applied pushstate changes, new URL structure
2012-11-13 13:10:34 -05:00
Justin Richer
1d8254bf2f
changed target of approve form
2012-10-24 15:06:56 -04:00
Michael Jett
be506ae952
Moved fonts local, fixed loading indicator
2012-09-25 13:37:36 -04:00
Michael Jett
84cedbb45e
Support the "Enter" key on list widget
2012-09-25 13:24:38 -04:00
Michael Jett
8fc6b2b680
Removing the rest of Justin's load hack
2012-09-25 13:18:31 -04:00
Michael Jett
fd89312b0c
Placeholder UI updates
2012-09-25 12:52:55 -04:00
Michael Jett
48941f1713
Dynamic JS loading and UI updates
2012-09-25 12:52:54 -04:00
Michael Jett
2311cdf1f2
Revert "Dynamic Client Loading Initial Commit"
...
This reverts commit a4e5335eda02cdb6b32a966d194035429ca52915.
2012-09-25 12:52:52 -04:00
Michael Jett
d7455dba14
Dynamic Client Loading Initial Commit
2012-09-25 12:52:51 -04:00
Amanda Anganes
29862f15bd
Removed a bunch of commented-out configuration
2012-09-18 15:21:55 -04:00
Amanda Anganes
51073a7f8d
Refactor part 3
2012-09-18 15:01:05 -04:00
Amanda Anganes
ef80676dc1
Cleaned up web package a bit - lots of unused imports and variables
2012-09-18 14:39:07 -04:00
Amanda Anganes
dd2abd94d1
Refactoring part 2
2012-09-18 14:36:27 -04:00
Amanda Anganes
c40efda6b5
Refactor part 1
2012-09-18 14:24:34 -04:00
Justin Richer
0b6aebfefe
Revert "removed postrender function, use render function instead"
...
This reverts commit 2b1e78d195
.
2012-09-13 11:27:50 -04:00
Justin Richer
ebf77bea68
Updated timeout functions
2012-09-13 11:24:48 -04:00
Justin Richer
6fdd088125
Updated client secret panel display
2012-09-13 11:24:29 -04:00
Justin Richer
be17133a99
Changed "submit" label to "save"
2012-09-13 11:02:53 -04:00
Justin Richer
2b1e78d195
removed postrender function, use render function instead
2012-09-13 10:33:52 -04:00
Justin Richer
ece1b56095
added missing brackets
2012-09-13 10:33:52 -04:00
Justin Richer
fe3e890bb3
changed to table head for input control
2012-09-13 10:33:52 -04:00
Justin Richer
d8221a2a35
added missing semicolon
2012-09-13 10:33:52 -04:00
Justin Richer
ed75b38ecc
changed list view table styling
2012-09-13 10:33:52 -04:00
Justin Richer
a4a40ffae5
unit test for x509 endpoint
2012-09-12 14:14:15 -04:00
Michael Jett
d9771f2322
Timout Bugfixes
2012-09-12 13:55:30 -04:00
Michael Jett
26c3cf5989
Timout UI refactor
2012-09-12 13:48:01 -04:00
Michael Jett
19df5ae032
Timeout form updates. Logo URL updates
2012-09-11 15:06:20 -04:00
Michael Jett
cb6767dfb4
Timout form updates
2012-09-11 15:06:17 -04:00
Justin Richer
a9d1799eda
added getter/setter to UIE schema-to-view map
2012-09-11 12:44:47 -04:00
Justin Richer
920b2a59ba
Fixed error logging
2012-09-10 17:17:03 -04:00
Justin Richer
2d24435365
Created custom resolver, handler mapper
...
moved endpoint back to server
2012-09-10 17:17:03 -04:00
Justin Richer
7eb0a6f3d2
Moved JWK to commons
2012-09-10 17:17:03 -04:00
Amanda Anganes
f3c225d8f2
Updated SECOAUTH reference, made required alterations to our configuration
2012-09-07 16:08:15 -04:00
Stephen Moore
ea16f4e2b6
Fixed merge weirdness
2012-09-07 14:09:10 -04:00
Stephen Moore
b58ed8b616
Added logoURL stuff
2012-09-07 13:51:58 -04:00
Amanda Anganes
61b828e182
Fixed bug - removed service layer @Transactional annotations, which negated need for flush at repository level; moved @Transactional annotations.
2012-09-04 17:53:02 -04:00
Michael Jett
c8f9a3de76
Merge remote-tracking branch 'origin/UI-form-updates'
2012-09-04 13:25:16 -04:00
Justin Richer
ee7a5fd2e1
added registration URL to discovery endpoint
2012-08-30 17:18:36 -04:00
Michael Jett
332fe282be
List Widget UI values cannot be null
2012-08-29 14:40:23 -04:00
Michael Jett
fe837c4fa5
comment edit
2012-08-29 13:56:10 -04:00
Michael Jett
4fcbbe639f
visual error indicators for redirect uri and scope
2012-08-29 13:54:04 -04:00
Michael Jett
15359a236a
Scope UI Auto-complete
2012-08-29 13:36:46 -04:00
Justin Richer
11b35267b4
Refactored stats processor into a service, made home page into a smart page.
2012-08-28 17:42:43 -04:00
Michael Jett
85e13bd11d
Initial Scope UI updates
2012-08-28 15:59:03 -04:00
Justin Richer
bc0ee4cbab
force id consistency
2012-08-28 15:28:55 -04:00
Justin Richer
8876217baf
Added cleanups to client service
2012-08-28 15:28:55 -04:00
Justin Richer
d041ddb0e1
Added approvedSite API and support structure
2012-08-28 15:28:55 -04:00
Justin Richer
2bf5cfc041
service bug fix
2012-08-28 15:28:55 -04:00
Justin Richer
b462d6dd96
added empty http code view
2012-08-28 15:28:55 -04:00
Justin Richer
8ae1b376fe
updated whitelist service and repository
2012-08-28 15:28:55 -04:00
Justin Richer
6a180acf3c
added preliminary whitelist api
2012-08-28 15:28:55 -04:00
Michael Jett
59e2f0e127
Backbone List View Widget Initial Commit
2012-08-28 12:49:33 -04:00
Justin Richer
4af3dd89be
cleaned up client api
2012-08-28 12:29:59 -04:00
Justin Richer
72c125ba64
refactored binder into two parts
2012-08-28 12:29:33 -04:00
Justin Richer
be54696603
Generic GSON entity printer
2012-08-28 12:29:10 -04:00
Michael Jett
0aa6da67de
Bootstrap JS Upgrade
2012-08-28 12:03:08 -04:00
Michael Jett
306e07bc36
UI Dynamic List updates
2012-08-27 23:46:06 -04:00
Michael Jett
5377a2bac4
Redirect URI UI updates
2012-08-27 17:12:02 -04:00
Justin Richer
0b1bb4f8aa
call the right service api
2012-08-27 16:57:52 -04:00
Justin Richer
407c14d0dc
added missing bean annotation
2012-08-27 16:52:00 -04:00
Justin Richer
3e423e9e04
explicitly exposed registration url
2012-08-27 16:46:58 -04:00
Justin Richer
a674589db0
added client editing capability
2012-08-27 16:46:45 -04:00
Justin Richer
a45c8bf96d
upped default client secret strength
2012-08-27 16:46:25 -04:00
Justin Richer
e39dcb63dd
added views, fixed registration for SECOAUTH required parameter
2012-08-27 16:25:43 -04:00
Michael Jett
d8037c0513
Redirect URL UI initial commit
2012-08-27 16:17:22 -04:00
Justin Richer
83873f8ae2
added defaults for SECOAUTH
2012-08-27 16:09:01 -04:00
Justin Richer
9f84126cb8
more dynamic registration
2012-08-27 16:00:47 -04:00
Justin Richer
aeb6644d38
exploded version of attribute binding/processing
2012-08-27 14:47:04 -04:00
Justin Richer
e4470c9361
mapped the invalid scope exception, addresses #102
...
Still can't access userinfo if you're not using OAuth2
2012-08-27 13:28:54 -04:00
Justin Richer
259e84c871
put null check into interceptor, addresses #183
2012-08-27 11:55:06 -04:00
Michael Jett
8361f74932
removed innocuous change
2012-08-24 16:00:58 -04:00
Michael Jett
42287edc9b
junk comentt showwhich brnach we'ron
2012-08-24 15:27:39 -04:00
Michael Jett
a61d94e07e
Cancel buttons on client forms
2012-08-24 14:32:13 -04:00
Michael Jett
149080f776
Breadcrumbs are now fully dynamic.
2012-08-24 12:57:10 -04:00
Justin Richer
37d6d63772
inject userinfo into context for use in JSPs
...
addresses #99 (for real this time)
2012-08-23 18:23:52 -04:00
Justin Richer
b5ce8d5e8b
added getByUsername to userinfo repositories and supporting classes, updated calling classes to use this
...
fixed namedquery
2012-08-23 18:23:47 -04:00
Michael Jett
6cb0269629
Merge remote branch 'origin/master'
2012-08-23 18:08:13 -04:00
Michael Jett
dc1f1965af
Refactoring breadcrumbs. The breadcrumb bar will disappear momentarily.
2012-08-23 18:07:22 -04:00
Amanda Anganes
ba5572b28a
Tidied up a bit, added javadoc comments to new classes
2012-08-23 11:05:10 -04:00
Amanda Anganes
c23b176567
Database backed authorization-code-service now works.
2012-08-23 10:46:08 -04:00
Amanda Anganes
4b76cc514b
Added a database-backed authorization-code system. Untested; needs to be injected into configuration in the place of the in-memory one and tested
2012-08-22 16:54:00 -04:00
Amanda Anganes
dc61068702
Split approved site and whitelisted site scope tables.
2012-08-22 15:21:42 -04:00
Justin Richer
e5b62e8935
fixed patterns and expressions on http blocks
2012-08-21 14:02:35 -04:00
Justin Richer
9eb328831f
changed to proper prefix
2012-08-21 13:55:47 -04:00
Stephen Moore
af01e26e10
Split up permitAll on enpoints
2012-08-21 12:54:55 -04:00
Stephen Moore
d2f7e8edf9
Moved SPEL to app-context, and added enpoint permitAlls
2012-08-21 12:53:48 -04:00
Justin Richer
bdfdbbadbc
stats summary, addresses #62
2012-08-21 12:20:05 -04:00
Justin Richer
6cb7e74046
updated default handling to user proper backbone model handling
2012-08-20 16:49:39 -04:00
Justin Richer
74b4fab58c
Client secret processing
2012-08-20 16:06:12 -04:00
Justin Richer
05fa7b148c
added checks for generated client secret
2012-08-20 12:23:02 -04:00
Justin Richer
9e60da2675
added controls for client secret processing
2012-08-20 12:22:38 -04:00
Justin Richer
a02f37cec3
added generators to client service API
2012-08-20 12:22:18 -04:00
Justin Richer
8520fcbf72
removed deprecated granted authority reference
2012-08-17 14:40:13 -04:00
Justin Richer
a65504c0cb
added new exception for userinfo, addresses #133
2012-08-15 16:02:06 -04:00
Justin Richer
209fc2d249
refactored request object endpoint to avoid urlspace conflict with SECOAUTH
2012-08-15 12:06:37 -04:00
Mike Derryberry
d1218efb2a
cleaned up imports
2012-08-14 10:55:08 -04:00
Mike Derryberry
55e7a4d707
moved request object auth endpoint in project setup
2012-08-14 10:55:08 -04:00
Mike Derryberry
ec286b9644
removed auth bean from application-context. Added extra parameter checks in request object auth endpoint
2012-08-14 10:55:08 -04:00
Mike Derryberry
04d8faa90a
updated autowired annotation
2012-08-14 10:55:08 -04:00
Mike Derryberry
20a7ebc576
autowired all member variables in request object auth endpoint
2012-08-14 10:55:08 -04:00
Mike Derryberry
694074ee58
moved endpoint, added param processing
2012-08-14 10:55:08 -04:00
Mike Derryberry
36b9c805d9
added reference to abstract endpoint class to get token granter
2012-08-14 10:55:08 -04:00
Mike Derryberry
2bdbb283b7
removed dependency on abstract endpoint class. added methods needed to authRequestObjectEndpoint (afterPropertiesSet())
2012-08-14 10:55:08 -04:00
Mike Derryberry
51ec529861
readded implementation of initializingBean
2012-08-14 10:55:08 -04:00
Mike Derryberry
638ebf2010
cleaned up AuthRequestObjectEndpoint class
2012-08-14 10:55:08 -04:00
Mike Derryberry
d93f5f18e5
added state value to jwt that gets passed as request object. certain methods from SECOAUTH use this
2012-08-14 10:55:08 -04:00
Mike Derryberry
3486ea28f1
updated mimicked methods to not use jwt, but rather a jwt in an auth request
2012-08-14 10:55:08 -04:00
Mike Derryberry
1a20dcbc6e
added methods that mimic behavior of private SECOATH methods
2012-08-14 10:55:08 -04:00
Mike Derryberry
d5caa0b543
changed server endpoint to act like an endpoint. WIP to accept request objects, validate, and redirect
2012-08-14 10:55:08 -04:00
Mike Derryberry
7d6211afd7
cleaned up some imports, added serverEndpointRequest class
2012-08-14 10:55:08 -04:00
Mike Derryberry
28344a3c91
auth endpoint got into client code. removed
2012-08-14 10:55:08 -04:00
Mike Derryberry
2888c08083
changed cookie claim to include the response
2012-08-14 10:55:07 -04:00
Justin Richer
c0a61fe47a
moved jquery to page header instead of footer, added focus call on login form
2012-08-14 10:48:38 -04:00
Justin Richer
484abc4915
fixed client delete
2012-08-10 17:24:21 -04:00
Michael Jett
5e898a7b0b
Id toke timeout binding for UI
2012-08-10 17:20:23 -04:00
Michael Jett
aaa38a761d
Mis-type for client secret
2012-08-10 17:18:43 -04:00
Michael Jett
b99d2ed9dc
Client Id null fix
2012-08-10 17:15:35 -04:00
Michael Jett
935b5ed43a
Client Id is now editable
2012-08-10 17:11:13 -04:00
Michael Jett
0f9d4ef255
Id refactor UI
2012-08-10 17:05:28 -04:00
Justin Richer
155974d8e3
moved services and api over to using new client Id field (instead of client_id)
2012-08-10 16:53:31 -04:00
Justin Richer
eb5a24690f
added method to get client by its (new) Long id
2012-08-10 16:29:16 -04:00
Michael Jett
480fb8e593
Id refactor UI
2012-08-10 16:26:54 -04:00