Commit Graph

506 Commits (61f0db20f635ecb7fcd898d20c87988cfd493b41)

Author SHA1 Message Date
Justin Richer 31e3c5e5e7 moved user approval page 2013-04-12 15:57:32 -04:00
Justin Richer 694761c026 cleaned up userinfo view 2013-04-12 15:40:05 -04:00
Justin Richer 71d6dc6afe removed special stats view 2013-04-12 15:15:43 -04:00
Amanda Anganes 7e59421f33 Commented out XRD endpoint and added TODO reference to webfinger issue 2013-04-11 10:33:27 -04:00
Amanda Anganes 34b243e0e1 Added back discovery endpoint, but renamed to not say SWD 2013-04-11 10:27:31 -04:00
Stephen Moore 23c318f6c2 Updating guava to 14.0.1 2013-04-10 15:31:32 -04:00
Amanda Anganes a723c9d921 Removed references to DefaultAuthorizationRequest in connect code 2013-04-08 10:37:13 -04:00
Amanda Anganes e17eaa499e Cleaned up classes affected by SECOAUTH changes; added Connect implementation of AuthorizationRequest and updated manager class to reflect new class & updated interface;
;
2013-04-08 10:13:27 -04:00
Justin Richer f63ea94b37 fixed bean name 2013-04-01 12:05:39 -04:00
Justin Richer c0c1847f38 fixed bean name 2013-04-01 11:59:23 -04:00
Amanda Anganes 02220a411a Fixed typo 2013-03-29 12:59:49 -04:00
Amanda Anganes 2265a3f8c3 Updated error handling messages for scope, approved site, blacklist, whitelist, and client APIs using new JsonErrorView 2013-03-29 12:47:03 -04:00
Amanda Anganes ee5b21b542 Added JsonErrorView 2013-03-29 12:47:03 -04:00
Amanda Anganes 07686d8e00 Removed superfluous try/catch around save call in ScopeAPI. 2013-03-29 12:47:03 -04:00
Justin Richer 6cc50e7cd5 switched signing & validation service to use JWK natively for keys 2013-03-28 16:43:26 -04:00
Justin Richer f54dddd8c0 fixed blacklisted field name, addresses #295 2013-03-28 16:06:02 -04:00
Justin Richer e2ad4d2e8f cleaned up spurious nosuchalgorithm exceptions, addresses #285 2013-03-28 15:06:30 -04:00
Amanda Anganes 5b321b9c86 Updated whitelist api for ui error handling 2013-03-28 12:43:47 -04:00
Amanda Anganes 666573cd34 Updated blacklist and client api for ui error handling 2013-03-28 12:37:18 -04:00
Amanda Anganes 218fe9328c Updated approved site API for error handling 2013-03-27 16:49:33 -04:00
Amanda Anganes 435fff3b1c Updated scope API for error handling 2013-03-27 16:27:55 -04:00
Amanda Anganes d24ecd2e7c Removed extra scope validation endpoint 2013-03-27 15:27:34 -04:00
Amanda Anganes 96e333afa6 Working on error handling 2013-03-27 15:27:34 -04:00
Amanda Anganes fa0a6a7b4e Finding my way around Backbone, Underscore, and Bootstrap 2013-03-27 15:27:34 -04:00
Amanda Anganes 36b08dcd6e Removed SWD code 2013-03-22 15:23:08 -04:00
Amanda Anganes fcc95f8a0a Moved nonce processing stuff into nonce service and out of ConnectAuthorizationRequestManager 2013-03-22 14:38:37 -04:00
Amanda Anganes d38c5b4200 Pared down nonce reuse exception message to just say that the nonce has already been used 2013-03-22 12:36:24 -04:00
Amanda Anganes b28b0615fa removed vestigial ClientDetailsEntityService references 2013-03-22 12:32:31 -04:00
Justin Richer 08eaaa0a12 updated repository to use proper concrete class 2013-03-21 15:20:36 -04:00
Justin Richer 8fccbf3483 added Id field to DefaultUserInfo object, switched "userId" terminology to "subject" 2013-03-20 14:29:00 -04:00
Justin Richer f44c704472 major refactor of client filter
Collapsed filter into single class
pulled server config and client config management into service classes
created service for issuer (will handle account chooser)
created auth request services (handle signed and unsigned requests)
2013-03-14 18:05:50 -04:00
Amanda Anganes 8992506a1d Fixing up logging changes 2013-03-08 09:52:24 -05:00
Amanda Anganes f9b0670ae9 Merged ClientAPI and ClientDynamicRegistrationEndpoitn by hand 2013-03-07 12:12:27 -05:00
Amanda Anganes 5cac7055a9 Standardized error handling and added logging for error conditions in endpoints 2013-03-07 11:56:57 -05:00
Amanda Anganes dbc68e4074 Working on error handling 2013-03-07 11:51:18 -05:00
Amanda Anganes 1630814b9f Marked classes where error handling needs to be added/changed 2013-03-07 11:51:18 -05:00
Justin Richer 6320fce9fd url -> uri in approval page 2013-03-07 10:39:33 -05:00
Justin Richer 27a8bcf440 now with more documentation and actual deletion 2013-03-06 11:53:16 -05:00
Justin Richer eaa9e1ded4 typo for grant types in parser 2013-03-06 11:33:54 -05:00
Justin Richer a6a2d43e8f added Read, Update, and Delete operations to dynreg endpoint 2013-03-06 11:33:31 -05:00
Justin Richer d37bac1775 simplification and documentation of client api views 2013-03-06 11:33:06 -05:00
Justin Richer c9bdba3f3a API now bound to USER for read, ADMIN for write, addresses #267 2013-03-05 17:45:33 -05:00
Justin Richer 1daf5bd357 dispatch to different views based on user role 2013-03-05 17:34:24 -05:00
Justin Richer 70b2342864 fixed split client views, fixed typos in various places 2013-03-05 17:26:25 -05:00
Justin Richer 51a7ccc397 entity -> embed 2013-03-05 16:33:13 -05:00
Justin Richer 0d25d4cb17 null-preserving static parsers instead of constructors 2013-03-05 12:10:33 -05:00
Justin Richer 6a88c13675 split client view into two classes 2013-03-04 17:50:02 -05:00
Justin Richer 4095f2179c added custom client view for API 2013-03-04 17:33:18 -05:00
Justin Richer 9aebca2e97 fixed gson parser in client API 2013-03-04 16:38:11 -05:00
Justin Richer 23efdf9f51 fix viewbean name, nullsafe client creation time, fixed default scope handling 2013-03-04 16:12:06 -05:00
Justin Richer 26f03ec070 timestamp for creation date 2013-03-04 16:11:20 -05:00
Justin Richer 235a3bf2c4 added client information response view 2013-03-04 15:45:35 -05:00
Justin Richer a2d6894f62 started serialization for client information view 2013-03-04 15:13:55 -05:00
Justin Richer db24c203ec added parser to client registration endpoint 2013-03-04 15:01:02 -05:00
Justin Richer 5c044b9eff added extra client fields to DB model, moved services to use new client model object 2013-03-04 14:22:42 -05:00
Justin Richer bd877dde82 added signature checking to request objects 2013-03-01 17:44:44 -05:00
Justin Richer 6c1e6b2d74 refactored signing and validation, added jwk-based cache, removed keyfetcher, refactored client side class structure 2013-03-01 17:44:44 -05:00
Justin Richer 385853fa1f refactored signing and validation, added jwk-based cache, removed keyfetcher, refactored client side class structure 2013-03-01 17:44:44 -05:00
Justin Richer 13a3e97113 updated request object forwarding hack 2013-03-01 17:42:48 -05:00
Amanda Anganes 60b679e942 First steps towards adding display variables to config bean 2013-02-22 17:10:14 -05:00
Justin Richer 4d725b88dd more updates to track nimbus-jose-jwt classes and use them properly 2013-02-22 12:08:01 -05:00
Justin Richer 9a98d241e8 updates to track Nimbus JOSE API changes to audience and date fields 2013-02-22 12:08:01 -05:00
Justin Richer 03e7337b9f client registration endpoint needs general rewrite to fit new spec.
Most of the problematic references will change with the rewrite, so this is a slapdash patch to make things compile for now.
2013-02-22 12:08:01 -05:00
Justin Richer 25b9940a68 request object endpoint is a placeholder, cleaning out for now 2013-02-22 12:08:01 -05:00
Justin Richer e5732da857 added system default signing algorithm, converted token provider and enhancer to use nimbus-jose 2013-02-22 12:08:01 -05:00
Justin Richer c01e873019 request object processor moved to nimbus-jose 2013-02-22 12:08:01 -05:00
Justin Richer 0f99e0e06d assertion token granter moved to nimbus-jose 2013-02-22 12:08:01 -05:00
Justin Richer 10ab55a7e2 moved jwk/x509 publishing over to nimbus-jose (mostly) 2013-02-22 12:08:01 -05:00
Justin Richer a078f7d202 patched userinfo view to use nimbus 2013-02-22 12:08:01 -05:00
Justin Richer c7d1b47b38 converted bearer assertion framework to nimbus-jose 2013-02-22 12:08:01 -05:00
Justin Richer 910a6cf1a0 remvoed idtoken repository that was never used 2013-02-22 12:08:01 -05:00
Justin Richer d0fdf8140e sorting on approval page 2013-02-05 15:47:32 -05:00
Justin Richer 02846c0a8d typo fix, DB constraints 2013-02-05 14:40:06 -05:00
Justin Richer e622202e9e display scopes based on request, pull scope information dynamically, addresses #208 2013-02-05 11:36:59 -05:00
Justin Richer eb4773ce46 beginning dynamic scopes on auth page 2013-02-05 11:28:39 -05:00
Justin Richer c2b9fd4db1 system scope ordering consistency 2013-02-05 11:11:41 -05:00
Justin Richer 801a45cc49 several bugfixes to scopes UI, works now 2013-02-03 22:04:56 -05:00
Justin Richer a3037a18a7 system scope service applied to client creation UI 2013-02-03 22:04:55 -05:00
Justin Richer cab36a2b80 added appropriate filterered and transformative actions to scope service 2013-02-03 22:04:55 -05:00
Justin Richer ab35186696 added scope service, repository, and API 2013-02-03 22:02:24 -05:00
Justin Richer a2e548c261 fixed claims processor for request object from user info endpoint 2013-02-03 22:02:23 -05:00
Justin Richer 3c190e044a inject parsed parameters to make SECOAUTH happy 2013-02-03 22:02:23 -05:00
Justin Richer 1144d511af inject scopes 2013-02-03 22:02:23 -05:00
Justin Richer f9d50db1f1 don't treat openid scope special here -- by default client gets access to *all* scopes it's registered for 2013-02-03 22:02:23 -05:00
Justin Richer 078342715b moved request object to request manager 2013-02-03 22:02:22 -05:00
Amanda Anganes 3399eed45a Added about, contact, and stats pages. Still largely placeholders, but the topbar works correctly now at least. 2013-01-31 11:34:07 -05:00
Justin Richer 0be254c99a updated token introspection output to match spec and client filter 2013-01-30 15:31:32 -05:00
Justin Richer c1d33bb55b bugfix in assertion processor 2013-01-30 14:34:16 -05:00
Amanda Anganes 2e2c0e8e6c Fixed bug in nonce processing 2013-01-29 13:07:41 -05:00
Amanda Anganes 3db74100a4 working on bug 2013-01-29 13:07:41 -05:00
Amanda Anganes dd8b48e863 Reset ConnectAuthorizationRequestManager to version from master 2013-01-29 13:07:41 -05:00
Amanda Anganes 06f970e61b Trying to fix nonce service 2013-01-29 13:07:41 -05:00
Amanda Anganes 86bf51f0a7 Added java reflection code for request object handling, needs to be tested 2013-01-29 13:07:41 -05:00
Amanda Anganes 677f0f2d4c Stubbed out required functionality for request object filtering 2013-01-29 13:07:41 -05:00
Amanda Anganes 67e8714671 Working on request object userinfo parsing 2013-01-29 13:07:41 -05:00
Justin Richer 7269700dc6 switched injector from repository to service 2013-01-24 19:32:55 -05:00
Justin Richer f0ee36dad2 auth_type -> auth_method (addresses #258) 2013-01-18 18:26:55 -05:00
Justin Richer 8831bc64a2 offline -> offline_access (addresses #248) 2013-01-18 18:03:39 -05:00
Justin Richer 27a26e0a35 (user_id/prn) -> sub 2013-01-18 16:40:05 -05:00
Justin Richer 0ab4ad4bbe added "birthdate", addresses #253 2013-01-18 15:38:41 -05:00
Justin Richer 6ef4dc817e genericized nimbus code, added caching 2013-01-18 15:10:48 -05:00
Justin Richer 2d21a72e7e switched to nimbus to check JWT signature 2013-01-18 15:10:48 -05:00
Justin Richer 60bda31c54 updated custom filter 2013-01-18 15:10:48 -05:00
Justin Richer c17bc05b0e wiring configuration 2013-01-18 15:10:48 -05:00
Justin Richer 4262be1fd3 added jwt processing to client auth provider 2013-01-18 15:06:00 -05:00
Justin Richer abd64eccd6 added framework for processing assertions for client auth 2013-01-18 15:06:00 -05:00
Amanda Anganes ad5e77f7ff Made nonce storage duration configurable in application-context.xml; 2013-01-10 10:34:40 -05:00
Amanda Anganes 59f1b1f05e Testing, nonce handling seems to be working now 2013-01-07 13:28:30 -05:00
Amanda Anganes a1a117cfde Added default constructor to ConnectAuthorizationRequestManager 2013-01-07 10:54:33 -05:00
Amanda Anganes 77b932f5a7 Added implementation of AuthorizationRequestManager. Nonce checking will go in here 2013-01-04 15:30:24 -05:00
Amanda Anganes 1af6513499 Removed nonce checking from token service impl 2013-01-04 15:30:24 -05:00
Amanda Anganes 246ed962bb Added stub of repository test 2013-01-04 15:30:24 -05:00
Amanda Anganes e1dffb959c Added NonceReuseException 2013-01-04 15:30:24 -05:00
Amanda Anganes a4637ec395 Fleshed out nonce service classes, added code to token service impl to check for and store nonces. Added JodaTime library for working with dates. 2013-01-04 15:30:24 -05:00
Amanda Anganes c7ae315e98 Added initial files for nonce service. Repository and service impls are stubs 2013-01-04 15:30:24 -05:00
Justin Richer 87788f0710 let users visit home page without logging in 2012-12-18 13:56:46 -05:00
Justin Richer f265347311 tweaked error messages 2012-12-18 12:08:36 -05:00
Justin Richer 18ddd8333f added flag to allow introspection, relaxed same-client restrictions on introspection and chained tokens 2012-12-18 11:07:24 -05:00
Justin Richer 1f53f41648 generic entity view now takes optional HttpStatus argument 2012-12-14 17:35:21 -05:00
Justin Richer a3790f943e cleaned up introspection endpoint to use exceptions 2012-12-14 17:35:20 -05:00
Justin Richer e5206f2b92 implemented jwt assertions for id tokens 2012-12-14 17:35:20 -05:00
Justin Richer 51b67ebc03 added queries to get access token from id token 2012-12-14 17:35:20 -05:00
Justin Richer 1853bd7117 added assertion token granter 2012-12-14 17:35:20 -05:00
Justin Richer cda6163d0d null and blank handling 2012-12-12 12:29:14 -05:00
Justin Richer 06fad3a41c moved view for client API 2012-12-11 15:19:11 -05:00
Justin Richer 6344a72519 missed a few applicationName references, fixed API JSON rendering 2012-12-11 15:16:18 -05:00
Justin Richer dfd8e9c7c7 removed unused view 2012-12-11 15:15:52 -05:00
Justin Richer 179903b074 propagated client changes to service 2012-12-11 12:31:01 -05:00
Justin Richer 33ceedb283 added scope and grant_type, switched to timeunit 2012-12-11 12:11:09 -05:00
Justin Richer e2bc15c2b2 beginning of client registration refactor to track IETF dynreg spec 2012-12-10 17:36:33 -05:00
Justin Richer 94c37f5815 added redelegate scope to client list, fixed inconsistency with refresh token issuance (addresses #239) 2012-12-10 16:53:05 -05:00
Justin Richer 510ddb48b7 override the correct part of the token granter class 2012-12-10 15:54:37 -05:00
Justin Richer bdcc6af096 temporary sanity check for client ID's 2012-12-10 11:40:03 -05:00
Justin Richer cab0839430 added workarounds for quirks in SECOAUTH 2012-12-10 11:27:28 -05:00
Justin Richer edc96d646c added chained token grant 2012-12-10 10:48:38 -05:00
Justin Richer 54708fb0ac fixed id token scopes (shouldn't inherit from parent token) 2012-12-10 10:11:02 -05:00
Justin Richer e38b2b0ba5 shortened revocation endpoint url 2012-12-07 17:16:03 -05:00
Justin Richer fbc3c46128 Introspection now draft spec compliant, requires client auth
Currently this is the client that originally sent the token, we want to have a way to bind other "clients" to this token as well, like resource services. Also want to let open calls, sometimes.
2012-12-07 17:12:13 -05:00
Justin Richer 544e3d7b43 added copy constructors because Dave likes to use unmodifiable sets for no apparent reason 2012-12-07 10:06:10 -05:00
Justin Richer 7561ac9e8c client dynamic registration now protected by access token, addresses #199 2012-12-06 17:48:23 -05:00
Justin Richer 7342da6a51 completed making id tokens into access tokens 2012-12-06 16:24:04 -05:00
Justin Richer e4f9fa2bbf labeled introspection endpoint 2012-12-06 16:19:25 -05:00
Justin Richer 17374a57e0 added ISO date format to generic entity view, addresses #232 2012-12-06 16:15:14 -05:00
Justin Richer b8f701d9d8 switched id tokens to entities, they're now access tokens also
still needs some work to get the auth object right, for now we're just copying from the access token
2012-12-06 10:19:21 -05:00
Justin Richer e305d3b16b Making stable in-memory and in-file database with HSQL 2012-12-03 17:53:25 -05:00
Justin Richer d07f67bd76 let user select when grants time out 2012-11-26 14:26:07 -05:00
Justin Richer 84401531ae tie refresh token generation to "offline" scope tag 2012-11-26 13:16:19 -05:00
Justin Richer 667c3abc8a dynamic scope display/selection on approval page 2012-11-26 11:53:19 -05:00
Justin Richer 1281d75aa9 stopped re-parsing scopes 2012-11-26 11:53:19 -05:00
Justin Richer 9c3a40779b updated to SECOAUTH's horrible new object-breaking authorization request paradigm.
Bonus: it works!
2012-11-26 11:53:19 -05:00
Justin Richer 3e327b9df6 reverted to original controller behavior 2012-11-26 11:53:19 -05:00
Justin Richer 45ca4e565e updated to SECOAUTH-1.0.1-BUILD-SNAPSHOT 2012-11-26 11:53:19 -05:00
Amanda Anganes cf1ddf0457 Determined that init binder was not needed to fix default for Boolean require_auth_time; instead use defaultValue=\"true\" in the RequestParam declaration. Also fixed bug in ClientDetails service so that it will not blow up if the client has no redirect uris registered 2012-11-21 15:39:07 -05:00
Amanda Anganes 2084639828 Working on init binder for ClientDynamicRegistrationEndpoint 2012-11-21 14:54:24 -05:00
Amanda Anganes 8b0c520534 Issue 213, writing init binder to convert null Boolean values to false before calling setters 2012-11-21 14:53:41 -05:00
Justin Richer a2a29e7b76 trying out new confirmation controller 2012-11-21 10:00:35 -05:00
Justin Richer d9b6918bc2 softened error from scope checker -- returns false now, allows things to pass through 2012-11-20 14:08:18 -05:00
Justin Richer 9c08944a02 Changed arity on approved sites (now can have many per user/site combo) 2012-11-20 14:07:55 -05:00
Justin Richer fda86e23e9 moved everything to use the consumes/produces framework of Spring 3.1 2012-11-20 13:12:21 -05:00
Justin Richer 5b0c17c5de added in checks to blacklist service upon client registration and update 2012-11-19 14:10:55 -05:00
Justin Richer e9d1ed270d service layer cleanups 2012-11-19 13:46:09 -05:00
Justin Richer 757e21a722 added blacklist API 2012-11-16 11:57:46 -05:00
Justin Richer 33f11cb98f cleanly applied pushstate changes, new URL structure 2012-11-13 13:10:34 -05:00
Amanda Anganes 51073a7f8d Refactor part 3 2012-09-18 15:01:05 -04:00
Amanda Anganes ef80676dc1 Cleaned up web package a bit - lots of unused imports and variables 2012-09-18 14:39:07 -04:00
Amanda Anganes dd2abd94d1 Refactoring part 2 2012-09-18 14:36:27 -04:00
Amanda Anganes c40efda6b5 Refactor part 1 2012-09-18 14:24:34 -04:00
Justin Richer a9d1799eda added getter/setter to UIE schema-to-view map 2012-09-11 12:44:47 -04:00
Justin Richer 920b2a59ba Fixed error logging 2012-09-10 17:17:03 -04:00
Justin Richer 2d24435365 Created custom resolver, handler mapper
moved endpoint back to server
2012-09-10 17:17:03 -04:00
Justin Richer 7eb0a6f3d2 Moved JWK to commons 2012-09-10 17:17:03 -04:00
Amanda Anganes f3c225d8f2 Updated SECOAUTH reference, made required alterations to our configuration 2012-09-07 16:08:15 -04:00
Amanda Anganes 61b828e182 Fixed bug - removed service layer @Transactional annotations, which negated need for flush at repository level; moved @Transactional annotations. 2012-09-04 17:53:02 -04:00
Justin Richer ee7a5fd2e1 added registration URL to discovery endpoint 2012-08-30 17:18:36 -04:00
Justin Richer 11b35267b4 Refactored stats processor into a service, made home page into a smart page. 2012-08-28 17:42:43 -04:00
Justin Richer bc0ee4cbab force id consistency 2012-08-28 15:28:55 -04:00
Justin Richer 8876217baf Added cleanups to client service 2012-08-28 15:28:55 -04:00
Justin Richer d041ddb0e1 Added approvedSite API and support structure 2012-08-28 15:28:55 -04:00
Justin Richer 2bf5cfc041 service bug fix 2012-08-28 15:28:55 -04:00
Justin Richer b462d6dd96 added empty http code view 2012-08-28 15:28:55 -04:00
Justin Richer 8ae1b376fe updated whitelist service and repository 2012-08-28 15:28:55 -04:00
Justin Richer 6a180acf3c added preliminary whitelist api 2012-08-28 15:28:55 -04:00
Justin Richer 4af3dd89be cleaned up client api 2012-08-28 12:29:59 -04:00
Justin Richer 72c125ba64 refactored binder into two parts 2012-08-28 12:29:33 -04:00
Justin Richer be54696603 Generic GSON entity printer 2012-08-28 12:29:10 -04:00
Justin Richer 0b1bb4f8aa call the right service api 2012-08-27 16:57:52 -04:00
Justin Richer 407c14d0dc added missing bean annotation 2012-08-27 16:52:00 -04:00
Justin Richer a674589db0 added client editing capability 2012-08-27 16:46:45 -04:00
Justin Richer a45c8bf96d upped default client secret strength 2012-08-27 16:46:25 -04:00
Justin Richer e39dcb63dd added views, fixed registration for SECOAUTH required parameter 2012-08-27 16:25:43 -04:00
Justin Richer 83873f8ae2 added defaults for SECOAUTH 2012-08-27 16:09:01 -04:00
Justin Richer 9f84126cb8 more dynamic registration 2012-08-27 16:00:47 -04:00
Justin Richer aeb6644d38 exploded version of attribute binding/processing 2012-08-27 14:47:04 -04:00
Justin Richer e4470c9361 mapped the invalid scope exception, addresses #102
Still can't access userinfo if you're not using OAuth2
2012-08-27 13:28:54 -04:00
Justin Richer 259e84c871 put null check into interceptor, addresses #183 2012-08-27 11:55:06 -04:00
Justin Richer 37d6d63772 inject userinfo into context for use in JSPs
addresses #99 (for real this time)
2012-08-23 18:23:52 -04:00
Justin Richer b5ce8d5e8b added getByUsername to userinfo repositories and supporting classes, updated calling classes to use this
fixed namedquery
2012-08-23 18:23:47 -04:00
Amanda Anganes ba5572b28a Tidied up a bit, added javadoc comments to new classes 2012-08-23 11:05:10 -04:00
Amanda Anganes c23b176567 Database backed authorization-code-service now works. 2012-08-23 10:46:08 -04:00
Amanda Anganes 4b76cc514b Added a database-backed authorization-code system. Untested; needs to be injected into configuration in the place of the in-memory one and tested 2012-08-22 16:54:00 -04:00