Commit Graph

537 Commits (899e306683be87e978c3d9b41d9acc4eceed2d48)

Author SHA1 Message Date
Michael Jett 59e2f0e127 Backbone List View Widget Initial Commit
12 years ago
Justin Richer 4af3dd89be cleaned up client api
12 years ago
Justin Richer 72c125ba64 refactored binder into two parts
12 years ago
Justin Richer be54696603 Generic GSON entity printer
12 years ago
Michael Jett 0aa6da67de Bootstrap JS Upgrade
12 years ago
Michael Jett 306e07bc36 UI Dynamic List updates
12 years ago
Michael Jett 5377a2bac4 Redirect URI UI updates
12 years ago
Justin Richer 0b1bb4f8aa call the right service api
12 years ago
Justin Richer 407c14d0dc added missing bean annotation
12 years ago
Justin Richer 3e423e9e04 explicitly exposed registration url
12 years ago
Justin Richer a674589db0 added client editing capability
12 years ago
Justin Richer a45c8bf96d upped default client secret strength
12 years ago
Justin Richer e39dcb63dd added views, fixed registration for SECOAUTH required parameter
12 years ago
Michael Jett d8037c0513 Redirect URL UI initial commit
12 years ago
Justin Richer 83873f8ae2 added defaults for SECOAUTH
12 years ago
Justin Richer 9f84126cb8 more dynamic registration
12 years ago
Justin Richer aeb6644d38 exploded version of attribute binding/processing
12 years ago
Justin Richer e4470c9361 mapped the invalid scope exception, addresses #102
12 years ago
Justin Richer 259e84c871 put null check into interceptor, addresses #183
12 years ago
Michael Jett 8361f74932 removed innocuous change
12 years ago
Michael Jett 42287edc9b junk comentt showwhich brnach we'ron
12 years ago
Michael Jett a61d94e07e Cancel buttons on client forms
12 years ago
Michael Jett 149080f776 Breadcrumbs are now fully dynamic.
12 years ago
Justin Richer 37d6d63772 inject userinfo into context for use in JSPs
12 years ago
Justin Richer b5ce8d5e8b added getByUsername to userinfo repositories and supporting classes, updated calling classes to use this
12 years ago
Michael Jett 6cb0269629 Merge remote branch 'origin/master'
12 years ago
Michael Jett dc1f1965af Refactoring breadcrumbs. The breadcrumb bar will disappear momentarily.
12 years ago
Amanda Anganes ba5572b28a Tidied up a bit, added javadoc comments to new classes
12 years ago
Amanda Anganes c23b176567 Database backed authorization-code-service now works.
12 years ago
Amanda Anganes 4b76cc514b Added a database-backed authorization-code system. Untested; needs to be injected into configuration in the place of the in-memory one and tested
12 years ago
Amanda Anganes dc61068702 Split approved site and whitelisted site scope tables.
12 years ago
Justin Richer e5b62e8935 fixed patterns and expressions on http blocks
12 years ago
Justin Richer 9eb328831f changed to proper prefix
12 years ago
Stephen Moore af01e26e10 Split up permitAll on enpoints
12 years ago
Stephen Moore d2f7e8edf9 Moved SPEL to app-context, and added enpoint permitAlls
12 years ago
Justin Richer bdfdbbadbc stats summary, addresses #62
12 years ago
Justin Richer 6cb7e74046 updated default handling to user proper backbone model handling
12 years ago
Justin Richer 74b4fab58c Client secret processing
12 years ago
Justin Richer 05fa7b148c added checks for generated client secret
12 years ago
Justin Richer 9e60da2675 added controls for client secret processing
12 years ago
Justin Richer a02f37cec3 added generators to client service API
12 years ago
Justin Richer 8520fcbf72 removed deprecated granted authority reference
12 years ago
Justin Richer a65504c0cb added new exception for userinfo, addresses #133
12 years ago
Justin Richer 209fc2d249 refactored request object endpoint to avoid urlspace conflict with SECOAUTH
12 years ago
Mike Derryberry d1218efb2a cleaned up imports
12 years ago
Mike Derryberry 55e7a4d707 moved request object auth endpoint in project setup
12 years ago
Mike Derryberry ec286b9644 removed auth bean from application-context. Added extra parameter checks in request object auth endpoint
12 years ago
Mike Derryberry 04d8faa90a updated autowired annotation
12 years ago
Mike Derryberry 20a7ebc576 autowired all member variables in request object auth endpoint
12 years ago
Mike Derryberry 694074ee58 moved endpoint, added param processing
12 years ago
Mike Derryberry 36b9c805d9 added reference to abstract endpoint class to get token granter
12 years ago
Mike Derryberry 2bdbb283b7 removed dependency on abstract endpoint class. added methods needed to authRequestObjectEndpoint (afterPropertiesSet())
12 years ago
Mike Derryberry 51ec529861 readded implementation of initializingBean
12 years ago
Mike Derryberry 638ebf2010 cleaned up AuthRequestObjectEndpoint class
12 years ago
Mike Derryberry d93f5f18e5 added state value to jwt that gets passed as request object. certain methods from SECOAUTH use this
12 years ago
Mike Derryberry 3486ea28f1 updated mimicked methods to not use jwt, but rather a jwt in an auth request
12 years ago
Mike Derryberry 1a20dcbc6e added methods that mimic behavior of private SECOATH methods
12 years ago
Mike Derryberry d5caa0b543 changed server endpoint to act like an endpoint. WIP to accept request objects, validate, and redirect
12 years ago
Mike Derryberry 7d6211afd7 cleaned up some imports, added serverEndpointRequest class
12 years ago
Mike Derryberry 28344a3c91 auth endpoint got into client code. removed
12 years ago
Mike Derryberry 2888c08083 changed cookie claim to include the response
12 years ago
Justin Richer c0a61fe47a moved jquery to page header instead of footer, added focus call on login form
12 years ago
Justin Richer 484abc4915 fixed client delete
12 years ago
Michael Jett 5e898a7b0b Id toke timeout binding for UI
12 years ago
Michael Jett aaa38a761d Mis-type for client secret
12 years ago
Michael Jett b99d2ed9dc Client Id null fix
12 years ago
Michael Jett 935b5ed43a Client Id is now editable
12 years ago
Michael Jett 0f9d4ef255 Id refactor UI
12 years ago
Justin Richer 155974d8e3 moved services and api over to using new client Id field (instead of client_id)
12 years ago
Justin Richer eb5a24690f added method to get client by its (new) Long id
12 years ago
Michael Jett 480fb8e593 Id refactor UI
12 years ago
Michael Jett ae5e1ca859 Merge remote branch 'origin/master'
12 years ago
Michael Jett 3f9e2cfa52 Horizontal UI refactor
12 years ago
Justin Richer 74a40fc973 changed auth holder reference, moved dates to timestamps
12 years ago
Justin Richer bb7d6b2e94 split scopes table
12 years ago
Justin Richer ed99bd36cf changed clientdetails entity to use @Enumerated, cleaned up .sql file foreign keys
12 years ago
Michael Jett 66e5cf3f04 Client table button UI tweaks
12 years ago
Michael Jett 8d57e0e9ef Issue # 81 Client UI - Creating new client creates duplicate
12 years ago
Michael Jett a5a102bbe4 Github Issue #116
12 years ago
Amanda Anganes 97d7bc9c13 added field to indicate whether the client has been dynamically registered
12 years ago
Amanda Anganes 170036e0b8 Added expiration to id tokens
12 years ago
Amanda Anganes 6bb9f67f5e Removed individual .sql files. All table definitions are now concatenated in database_tables.sql.
12 years ago
Amanda Anganes f724d3a9fe updated userinfo table definitions
12 years ago
Amanda Anganes 617e9568d8 Fixed bugs; I can get tokens now. User approval handler seems to be working corrrectly.
12 years ago
Amanda Anganes 49cb8bd0cb fixing bugs; needed to make all ids BIGINT AUTO-INCREMENT PRIMARY KEY in sql files
12 years ago
Amanda Anganes 0757642e67 removed "s" from allowed_scopes
12 years ago
Amanda Anganes 9c32e92da5 Cleaned up sql tables some more; sticking to _ naming convention
12 years ago
Amanda Anganes d7deda1699 Propogated AuthenticationHolder effects; this is untested but compiles and I think it is mostly correct
12 years ago
Amanda Anganes 90df91c351 Added AuthenticationHolder object, got references squared away for AccessToken side. Compiles.
12 years ago
Amanda Anganes cf348590b0 Removed unused ClientGeneratorFactory
12 years ago
Amanda Anganes d6d80c3e60 Gave OAuth2RefreshTokenEntity a Long Id
12 years ago
Amanda Anganes 6b1dad7215 Gave OAuth2AccessTokenEntity a Long Id
12 years ago
Amanda Anganes 780839dbf9 Made things compile after ClientDetailsEntity refactoring
12 years ago
Amanda Anganes a68a4f9796 Organized ClientDetailsEntity, updated JPA annotations. Updated sql files to match. Naming conventions: table and column names with multiple words should be seperated by underscores; table and column names should be singular.
12 years ago
Amanda Anganes 15428a875e Added additional fields to ClientDetailsEntity and did some reorganization, still some more to do. Added "id" field to the sql file, but the sql still needs all of the other additional fields.
12 years ago
Justin Richer 09e528e113 added discovery info for x509 and client auth
12 years ago
Justin Richer dc7aac12f9 added custom login form, changed footer to only optionally load app
12 years ago
Amanda Anganes 8d4e046408 All logging is now org.slf4j. We had a mix of org.slf4j and apache commons-logging. Added error logging to all view which throw errors.
12 years ago
Amanda Anganes a061e64abf Merge branch 'user-approval-handler-updated-rebase'
12 years ago
Amanda Anganes 32dc92119f Cleanup completed, this works for the most part. TODO: need to make an upstream change in order to inject a new set of scopes into the AuthorizationRequest.
12 years ago
Amanda Anganes 5fb67ab7bb Did a lot of cleanup; untested but compiles
12 years ago
Amanda Anganes ae44bd5e0c Works; about to do some cleanup
12 years ago
Amanda Anganes 2f28cf33e7 Changed UserInfo refs in WhitelistedSite to String ids; updated the user approval handler to check if "remember this decision" is checked and only make a new AP if so, and to pull in the scopes selected on the approval page as the saved allowed scopes for that AP.
13 years ago
Amanda Anganes b87d54b06e Changed UserInfo references to String "userId" references
13 years ago
Amanda Anganes 845976b8ac First stages of getting the graylist portion to work. Currently no mechanism for telling the system NOT to remember your decision; that will come later. All approvals will be automatically stored with this code.
13 years ago
Justin Richer 51b8dbe065 Revert "updated jwtHeader typ to use an enum" -- set things back to using a string
13 years ago
Justin Richer 9a7e40fee7 moved all bean definitions to annotations, removed orphaned CheckID view
13 years ago
Justin Richer 1508369548 now with Walsh-flavored certificate generation
13 years ago
Justin Richer 61a8d4a787 x509 take -- bouncycastley version
13 years ago
Amanda Anganes db415bfa2b Working on user approval handler
13 years ago
Amanda Anganes a223565364 updating user approval handler
13 years ago
Amanda Anganes 676808bdac got things to deploy - could not reference UserInfo directly in ApprovedSite and WhitelistedSite; needed to reference DefaultUserInfo instead.
13 years ago
Amanda Anganes 4e10fce7ef Implementing user approval handler; made some modifications to ApprovedSite and WhitelistedSite models, repositories, and service layers.
13 years ago
Amanda Anganes 7c33e19950 Changed authorization endpoint to /authorize rather than /auth; updated SWD entry. Also removed checkid entry from SWD.
13 years ago
Justin Richer 863693cf59 Merge pull request #128 from mtderryberry/jwe-and-jwt-fixes
13 years ago
Amanda Anganes 3982561a5b Removing "throws exception" from views. Addresses issue #70
13 years ago
Amanda Anganes 5cf6359f7d Merge branch 'master' of github.com:mitreid-connect/OpenID-Connect-Java-Spring-Server
13 years ago
Amanda Anganes 686412757f shortened urls
13 years ago
Mike Derryberry 3b2268c622 updated jwtHeader typ to use an enum
13 years ago
Justin Richer 1b5f99efec added .json mapping to SWD
13 years ago
Amanda Anganes 02da9fceed fixed imports
13 years ago
Justin Richer d07667576e cleaned up old code
13 years ago
Justin Richer 40f39a18e0 cleaning up introspection endpoint
13 years ago
Amanda Anganes e7449901a6 Removed IdTokenGeneratorService. Addresses issue #75
13 years ago
Justin Richer ee9288a72a turned down cache in default
13 years ago
Justin Richer c80f7f1fcd removed keystore dependency where it is not needed
13 years ago
Justin Richer 319568d971 refactored JWA algorithm markers to use enum instead of string as stored class
13 years ago
Justin Richer 165f3ea292 fixed some unit tests, broke others
13 years ago
Justin Richer 1f68c835c0 updated openid connect image
13 years ago
Michael Jett 7a3ae5a757 Merge remote branch 'origin/master'
13 years ago
Michael Jett 30addb5439 Redirect URI now displayed on approval page.
13 years ago
Justin Richer 9f16f309bd updated userinfouserdetailsservice to use username instead of userid -- this should actually be a wrapper class though
13 years ago
Justin Richer b0a7ebd9b1 fixed JWK algorithm display
13 years ago
Stephen Moore 84aa451095 Added comment for spring-servlet.xml
13 years ago
Justin Richer 5657bc8f28 updated configuration, confirmed works pending SECOAUTH-299
13 years ago
Justin Richer e5eb2e03d8 added implicit beans
13 years ago
Amanda Anganes 01793ec57f added preferred_username claim to userinfo endpoint
13 years ago
Amanda Anganes 8abbce3a2d fixed broken unit tests - they were pointing to the wrong spring context file;
13 years ago
Amanda Anganes 50241e4da1 changed UserInfo.verified to UserInfo.emailVerified.
13 years ago
Justin Richer 8fe132cb53 formatting
13 years ago
Justin Richer 830e07c35c moved whole configuration from servlet context into application context
13 years ago
Justin Richer dbd563f3f2 attempting to allow make use of SPEL
13 years ago
Justin Richer f0c949fd09 added scope-based filter for userinfo
13 years ago
Justin Richer c619e736f9 removed eclipse files from repository
13 years ago
Justin Richer 5c1b07ae65 don't overwrite an existing JWT nonce
13 years ago
Justin Richer 29731d52f6 Merge branch 'refreshtokens' of file:///home/jricher/Projects/workspace-sts/OpenIDConnect-MITRE/OpenID-Connect-Java-Spring-Server into refreshtokens
13 years ago
Justin Richer de1597b214 refresh token handling fixed, removed token factory references
13 years ago
Michael Jett 0dc568e5d0 Fixed more information link on approval page
13 years ago
Michael Jett a022f4d713 Authorized grant types now supported client-side
13 years ago
Michael Jett bff34f647c Allowing a null value for redirectURIs
13 years ago
Michael Jett 8fbea2516a Updated client side variable names to reflect name changes to access token and refresh token timeout
13 years ago
Amanda Anganes 4e3c99abe4 Merge branch 'validityIntegers'
13 years ago
Amanda Anganes 81d1af40bd Updated our ClientDetailsEntity *TokenTimeout fields to be *ValiditySeconds, which are now typed as proper Integers in the SECOAUTH ClientDetails interface
13 years ago
Michael Jett b6e00b9884 Base white-list functionality and template
13 years ago
Justin Richer 1127a7cfbc refactored JWKs, updated signing servier to use them
13 years ago
Justin Richer adb8499bee merged derryberry code, plus tweaks, still WIP
13 years ago
Amanda Anganes baa7ce5e7b Merge branch 'master' of github.com:mitreid-connect/OpenID-Connect-Java-Spring-Server
13 years ago
Amanda Anganes 2930719700 Added architecture diagram
13 years ago
Mike Derryberry b94fbd7439 updated -common and -client code by removing throws exception, changing to rest templates, and updating test cases to use annotations
13 years ago
Justin Richer 94256d95a1 added crypto configuration file
13 years ago
Justin Richer a38dc0ce29 added crypto configuration file
13 years ago
Justin Richer fe3bbfb3d5 Further cleanups. Still missing:
13 years ago
Justin Richer b86abdd761 merge from pull request, plus cleanup
13 years ago
Justin Richer 731ad2e2e2 updated SECOAUTH reference, fixed some SQL files, temporarily closed token timeout issue
13 years ago
U-MITRE\mjwalsh f9558f0955 stripped out check id endpoint interaction as it deprecated, refactored nonce checking based on spec change, pull user_id as id_token token claim
13 years ago
Justin Richer ace5dd1f1e imported userinfouserdetails filter from MITRE codebase
13 years ago
Mike Derryberry 65dc3daaf8 smart client
13 years ago
Amanda Anganes 2a05ff995d Added support for additional field in ClientDetailsEntity.java.
13 years ago
Amanda Anganes bbf9591c92 Merge branch 'master' into issue52
13 years ago
Justin Richer c3cffe1eac cleaned up bad config file
13 years ago
Justin Richer 195810fc63 Merge branch 'architecturedocs'
13 years ago
Justin Richer 7a207dc162 Merge branch 'discoveryupdate'
13 years ago
Justin Richer 250e0c730e Merge branch 'jwtupdate'
13 years ago
Justin Richer 7df2663e00 added final slashification of configuration URLs
13 years ago
Justin Richer fbdccdb78e added Xrd support (fixes #63), updated configuration locations (fixes #47)
13 years ago
Justin Richer e44697cef9 updated JWK display to latest, closes #58
13 years ago
Michael Jett 3b4e95ac10 Approval page updates
13 years ago
Michael Jett d424f44b8c Removing some whitespace
13 years ago
Justin Richer 46cd08071d cleaned up sql table references to redirect uris, see #48
13 years ago
Justin Richer 8e33a17307 moved DB schema files up a few levels, fixed test context to point to new locations
13 years ago
Justin Richer 5c72d8b95f revocation endpoint cleanup, still needs views
13 years ago
Justin Richer 27219c066d refactored our service to reflect upstream
13 years ago
Justin Richer e95528a08d added implementation to stub to read an access token by value
13 years ago
Amanda Anganes c89b1814d6 Fixed approve.jsp checkboxes (both had the same name).
13 years ago
Amanda Anganes 8684bb969f Updated approve.jsp with Jett's new code to display some checkboxes. This has been tested, and the additional parameters are persisted correctly and are available to the TokenGranter.
13 years ago
Michael Jett 68483536a6 Approval page updates. Approval and denial buttons are now in one form. Generic checkboxes are in place.
13 years ago
Amanda Anganes 424f8bb737 Refactored to use TokenEnhancer rather than a custom TokenGranter.
13 years ago
nemonik 998fc7f98b cleaned up beans layout
13 years ago
nemonik 8917e75010 see issue #19
13 years ago
Amanda Anganes 16aa0c59b5 Added token enhancer. Now to plug it in.
13 years ago
Amanda Anganes d4e107caf1 updating
13 years ago
Amanda Anganes 2070d2e413 Updated to use AuthorizationRequestFactory rather than ClientCredentialsChecker.
13 years ago
Justin Richer ce847dd4f7 updated poco user view to contain name
13 years ago
Stephen Moore c418ccabb1 Merge branch 'master' into userInfoEndpoint
13 years ago
Stephen Moore 1bff5ef19f Added POCO view, Added UnknownUserInfoScheamException runtime exception
13 years ago
Michael Jett b838ddb786 Client ID display fix
13 years ago
Michael Jett a1d85e281e Client ID now showing on display and edit page
13 years ago
Michael Jett 48ff2d3d77 Merge remote branch 'origin/master'
13 years ago
Michael Jett f8af7bf884 Adding help text for time-out options
13 years ago
Stephen Moore 5c544dfe7c Merge branch 'master' into userInfoEndpoint
13 years ago
Justin Richer 7d4d65c359 Merge branch 'userinfo_integration'
13 years ago
Justin Richer a8e9f1d2cd fixed rendering issues with user info view
13 years ago
Stephen Moore 9612fde10e Check for null address, and added email
13 years ago
Justin Richer 08958d4137 Merge remote-tracking branch 'remotes/steve/userInfoEndpoint' into userinfo_integration
13 years ago
Justin Richer 06fadb5f2b oauth provider configuration started
13 years ago
Stephen Moore 9b03831d4e Filled in the UserInfoEndpoint, and added the JSON view for userInfo (openIdSchema)
13 years ago
Michael Jett 668952ec09 Fixing typo
13 years ago
Michael Jett b59baa09a9 Cleaning up placeholder fields
13 years ago
Michael Jett c85248c40c Editing bug fix for validation
13 years ago
Michael Jett a44dee1fd6 Fixing IE compatibility with saving and editing clients
13 years ago
Michael Jett e5312b4c99 Client secret now editable and dynamically generated if not present
13 years ago
Michael Jett bd054bfd58 Client delete now requires confirmation
13 years ago
Michael Jett 6c8aeba041 Default scope is "openid"
13 years ago
Michael Jett e4f2446569 - no restraints on client name and description (neither of them required)
13 years ago
Michael Jett 51fe98b383 ClientAPI now sets owner for clients
13 years ago
Michael Jett f7a0b8de32 Client scope now supported
13 years ago
Michael Jett a1234a4fcd Timeout form fields now supported. Backbone.JS Validation error handling updates.
13 years ago
Michael Jett 2d980a4d8f Refactoring of routing. Client updates
13 years ago
Michael Joseph Walsh 6f43040587 slight sequence diagrams tweaks, mods to account-chooser and openid-connect-client
13 years ago
Michael Jett b06640c921 First stages of client-side validation worked into application
13 years ago
Michael Jett c45991b561 Adding backbone.js validations framework
13 years ago
Michael Jett 3402a3e463 ClientAPI now fully supports RESTful DELETE
13 years ago
Michael Jett 7f5b9e2c82 ClientAPI now supports DELETE method
13 years ago
Michael Jett abf3f0ec33 Merge remote branch 'origin/master'
13 years ago
Michael Jett af6e043239 Client Entity now initialized with non-null values so JPA won't flip. Added unified method for saving. Sync'd class member names to allow proper binding.
13 years ago
Michael Joseph Walsh 7e3ce2d583 mods to reflect client <-> account chooser protocol, and refactoring...
13 years ago
Michael Jett 0c7ea88323 Client updates.
13 years ago
Michael Jett 0f9b828066 ClientAPI admin requirement now global
13 years ago
Michael Jett 32e67730d8 ClientAPI maps to individual clients by IDs
13 years ago
Michael Jett 6b481cd3bb ClientAPI header updates
13 years ago
Michael Jett a4fc4e939e ClientAPI cleanup
13 years ago
Michael Jett f91071c350 New clients now attempt to POST to client API
13 years ago
Justin Richer 5e81ed6346 added some content to the architecture file
13 years ago
Justin Richer 7375d00e88 added taglib hack
13 years ago
Justin Richer e00bba7ede factored out one more piece of the security config
13 years ago
Stephen Moore fd91c884bb Made interfaces... deleted a thing.
13 years ago
Justin Richer ffe31e6049 merged config from bean config config bean bean
13 years ago
Justin Richer e158ef6fc2 added config bean
13 years ago
Amanda Anganes 95fc66de31 Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server
13 years ago
Amanda Anganes e33f277bbe Updated classes to track newest version of SECOAUTH. This update closes issues #3, #4, #8, and #36 (infinite redirects). This revision changes the authorization and token endpoints to be /openidconnect/auth and /openidconnect/token, respectively.
13 years ago
Michael Jett 9abb15a559 Approval page style upgraded to bootstrap 2 classes
13 years ago
Justin Richer e6f77fd061 Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server
13 years ago
Justin Richer c003bbf2c6 extracted user information from spring servlet config
13 years ago
Michael Jett 4f0ffd872b Removing older version of bootstrap
13 years ago
Michael Jett c8e3f70115 Now requiring homepage login
13 years ago
Michael Jett 7dd81ac2de Server-side dynamics
13 years ago
Michael Jett eb9f2617ba New look
13 years ago
Michael Jett 23fd7b1b21 Renaming Client View class
13 years ago
Michael Jett eda7505b7b Client API now renders JSON for all Clients
13 years ago
Michael Jett ba56c00318 Backbone JS support for creating a new client.
13 years ago