Commit Graph

1917 Commits (714acb8bdd8381887b2c2171d6a6d09e95b96022)

Author SHA1 Message Date
Justin Richer 714acb8bdd [maven-release-plugin] prepare for next development iteration 2015-10-22 10:44:30 -04:00
Justin Richer 90d188653d [maven-release-plugin] prepare release mitreid-connect-1.1.19 2015-10-22 10:44:28 -04:00
Justin Richer f36efce95c backported error handler from 1.2, closes remote execution exploit 2015-10-21 14:51:17 -04:00
lgangloff cdd51061b5 https://github.com/mitreid-connect/OpenID-Connect-Java-Spring-Server/issues/838 2015-10-21 16:26:27 +02:00
Justin Richer e1f711a107 [maven-release-plugin] prepare for next development iteration 2015-10-02 18:53:20 -04:00
Justin Richer 73da330310 [maven-release-plugin] prepare release mitreid-connect-1.1.18 2015-10-02 18:53:18 -04:00
Justin Richer b09503aadb user info endpoint response uses correct client algorithms, addresses #921 2015-10-02 18:48:25 -04:00
Justin Richer d03bebe5bf fixed backported 'kid' injection 2015-10-02 18:43:58 -04:00
Justin Richer 9fac632024 added 'kid' to all signed tokens, closes #899 2015-10-01 18:57:09 -04:00
Justin Richer 89a728669a added JTI to ID tokens, closes #900 2015-10-01 18:33:34 -04:00
Justin Richer 4bb28052a1 [maven-release-plugin] prepare for next development iteration 2015-08-22 11:54:21 -04:00
Justin Richer 2cc6476295 [maven-release-plugin] prepare release mitreid-connect-1.1.17 2015-08-22 11:54:19 -04:00
Justin Richer 747e9f0bde replaced deprecated http components calls, closes #838 2015-08-21 18:12:05 -04:00
Justin Richer 629bc652b9 updated HTTP Components version 2015-08-21 18:12:05 -04:00
Justin Richer 2f172fa1e0 restricted access to /authorize to ROLE_USER accounts, closes #892 2015-08-21 10:21:08 -04:00
Mark Janssen 4e83b173f4 Upgrade Spring versions 2015-07-09 23:30:12 +02:00
Justin Richer f05981829b added JWKS URI import on data API 2015-05-29 17:08:01 -04:00
Justin Richer 7ce1286070 [maven-release-plugin] prepare for next development iteration 2015-05-29 09:14:56 -04:00
Justin Richer 166243e833 [maven-release-plugin] prepare release mitreid-connect-1.1.16 2015-05-29 09:14:54 -04:00
Justin Richer 661892bbaf added non-binary support for 1.2+ data export compatibility 2015-05-27 19:31:49 -04:00
Justin Richer 5624c12232 back ported prompt behavior to 1.1, closes #810, addresses #667 2015-05-27 12:12:01 -04:00
Justin Richer 9fd059d091 [maven-release-plugin] prepare for next development iteration 2015-05-09 17:24:19 -04:00
Justin Richer 4c53112923 [maven-release-plugin] prepare release mitreid-connect-1.1.15 2015-05-09 17:24:17 -04:00
Justin Richer 2627a4438f added strict URI matching option to redirect resolver (off by default) 2015-05-09 16:36:08 -04:00
Justin Richer 22c86d09f8 put 'kid' into JWS header, closes #784 2015-05-09 16:00:35 -04:00
Justin Richer 8569213994 moved requirement to different component, closes #759
also cleaned up comments in filter
2015-03-08 23:04:12 -04:00
William Kim 3ae8d46e44 Made the constructor public for OIDCAuthentication filter.
Backported, closes #777
2015-03-08 23:03:53 -04:00
Justin Richer b74df7b583 [maven-release-plugin] prepare for next development iteration 2015-02-27 12:46:33 -05:00
Justin Richer 2b6a4a32fa [maven-release-plugin] prepare release openid-connect-parent-1.1.14 2015-02-27 12:46:31 -05:00
Justin Richer 7cf22d98b1 updated spring release for CVE-2014-3578 2015-02-27 12:44:17 -05:00
Justin Richer f6c956825d updated copyright tag to 2015 2015-02-17 12:57:32 -05:00
Justin Richer 5214eab1e9 [maven-release-plugin] prepare for next development iteration 2015-01-25 23:14:14 -05:00
Justin Richer 3ac61839bb [maven-release-plugin] prepare release mitreid-connect-1.1.13 2015-01-25 23:14:11 -05:00
Justin Richer b65fc88809 fixed comparison of client IDs in refresh token, closes #752
Also addresses #735 (again)
2015-01-24 07:48:27 -05:00
Charif Belhaffef 7d649e5c9c add @Transient to function getAuthorizedGrantTypes() so it does not persist 2015-01-14 07:20:00 -05:00
John Brooks 321b3350f2 Changed lastWeek logic back to correct form, removed logic used for
testing.
2014-12-19 00:41:59 -05:00
Justin Richer 9979bd0603 [maven-release-plugin] prepare for next development iteration 2014-11-22 23:53:02 -05:00
Justin Richer 70237f35ad [maven-release-plugin] prepare release mitreid-connect-1.1.12 2014-11-22 23:48:19 -05:00
Justin Richer c77c9a70e8 fixed unit tests 2014-11-22 23:45:22 -05:00
Justin Richer 1ce3b51416 relaxed scope constraints on protected resources registered through self-service page 2014-11-22 22:49:51 -05:00
Justin Richer 5510f2f62c removed unused variable in dynreg page 2014-11-22 22:43:42 -05:00
Justin Richer ad5f3ef847 made offline access non-default 2014-11-22 22:43:29 -05:00
Justin Richer 4ccd948ad2 fixed checking of refresh token permissions in client service, clients can now request either refresh_token grant type or offline_access scope and it will work. added checkbox to dynreg page for ease-of-use
closes #734
2014-11-22 22:43:01 -05:00
Justin Richer e983e8a0c9 make sure that client presenting refresh token is the same client the refresh token was issued to
closes #735
2014-11-22 21:33:10 -05:00
Justin Richer 5561b75f48 removed java 1.7 operator 2014-11-13 22:22:28 -10:00
Justin Richer b5ae05162e moved test into test package 2014-11-13 22:18:00 -10:00
Justin Richer 4d22ec61cf applied list widget catch to all objects 2014-11-13 16:35:38 -10:00
Justin Richer 740e5407ef more comprehensive list widget leftover object handling in client 2014-11-13 16:35:38 -10:00
Justin Richer 57648cd9d5 client scopes now added appropriately 2014-11-13 16:35:38 -10:00
Justin Richer 51b477679a removed blur detection, started work on alternative 2014-11-13 16:35:38 -10:00