Michael Jett
a4fc4e939e
ClientAPI cleanup
2012-05-15 12:41:41 -04:00
Michael Jett
f91071c350
New clients now attempt to POST to client API
2012-05-14 15:33:27 -04:00
Justin Richer
7375d00e88
added taglib hack
2012-05-11 16:10:06 -04:00
Justin Richer
e00bba7ede
factored out one more piece of the security config
2012-05-11 13:43:29 -04:00
Stephen Moore
fd91c884bb
Made interfaces... deleted a thing.
2012-05-10 17:45:10 -04:00
Justin Richer
ffe31e6049
merged config from bean config config bean bean
2012-05-09 15:32:13 -04:00
Justin Richer
e158ef6fc2
added config bean
2012-05-09 15:20:15 -04:00
Amanda Anganes
95fc66de31
Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server
2012-05-09 15:17:53 -04:00
Amanda Anganes
e33f277bbe
Updated classes to track newest version of SECOAUTH. This update closes issues #3 , #4 , #8 , and #36 (infinite redirects). This revision changes the authorization and token endpoints to be /openidconnect/auth and /openidconnect/token, respectively.
2012-05-09 15:16:56 -04:00
Michael Jett
9abb15a559
Approval page style upgraded to bootstrap 2 classes
2012-05-09 14:20:44 -04:00
Justin Richer
e6f77fd061
Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server
2012-05-08 16:58:37 -04:00
Justin Richer
c003bbf2c6
extracted user information from spring servlet config
2012-05-08 16:58:04 -04:00
Michael Jett
4f0ffd872b
Removing older version of bootstrap
2012-05-08 14:31:24 -04:00
Michael Jett
c8e3f70115
Now requiring homepage login
2012-05-08 14:09:24 -04:00
Michael Jett
7dd81ac2de
Server-side dynamics
2012-05-08 13:53:21 -04:00
Michael Jett
eb9f2617ba
New look
2012-05-08 12:11:39 -04:00
Michael Jett
23fd7b1b21
Renaming Client View class
2012-05-08 11:20:40 -04:00
Michael Jett
eda7505b7b
Client API now renders JSON for all Clients
2012-05-08 11:16:45 -04:00
Michael Jett
ba56c00318
Backbone JS support for creating a new client.
2012-05-07 18:20:40 -04:00
Michael Jett
c02bac8c38
New client actions rendered as buttons rather than anchors
2012-05-07 14:41:39 -04:00
Michael Jett
4c503a7f40
Client table now fully rendered client-side with JS templates.
2012-05-07 14:39:32 -04:00
Michael Jett
e9954f4439
Bootstrap spelling correction
2012-05-07 13:18:04 -04:00
Michael Jett
df174a1695
Test Client JS now valid. App.JS updates
2012-05-04 15:56:12 -04:00
Michael Jett
e2e2dfca43
TD now rendered dynamically
2012-05-03 18:00:50 -04:00
Michael Jett
9f979cb742
Views now load after fetching templates
2012-05-03 12:57:09 -04:00
Michael Jett
784fd14917
Client manager now renders views in bootstrap.
2012-05-01 15:50:24 -04:00
Michael Jett
3859429ed6
Client javascript test updates
2012-04-30 17:04:22 -04:00
Michael Jett
5622ccbf41
Removing Javascript CDN. This will fix cross domain issue when requesting JSON objects.
2012-04-30 11:45:37 -04:00
Michael Jett
0134c4ea96
Merge remote branch 'origin/master'
2012-04-30 11:32:05 -04:00
Michael Jett
df67c23dba
Removing Resig templating. Backbone.js provides template support.
2012-04-30 11:31:52 -04:00
Justin Richer
97dffb6414
added copyright to all java files. closes #11
2012-04-27 17:55:58 -04:00
Justin Richer
6724866099
moved jwt components, utilities, and various interfaces to -common from -server
2012-04-27 15:20:49 -04:00
Justin Richer
59ecb03548
added getter/setter for userinforepository, closes #40
2012-04-27 15:11:25 -04:00
Michael Jett
37452f4bb5
Client side JS updates
2012-04-26 16:30:03 -04:00
Michael Jett
c98204e705
Renamed mockup directory
2012-04-26 16:29:46 -04:00
Michael Jett
d1a773d512
Client backbone.js Model initial commit
2012-04-24 16:37:25 -04:00
Michael Jett
181b0ce605
Removing unneeded div el
2012-04-24 13:02:20 -04:00
Michael Jett
703a8abab5
client management now bootstrap 2 compatible
2012-04-20 12:14:06 -04:00
Michael Jett
57ebb7d287
Adding global JS to template
2012-04-20 12:13:29 -04:00
Michael Jett
897e6e85d3
Removing inline client editing popup
2012-04-20 11:35:15 -04:00
Michael Jett
2573c98c2d
Re-write of base template using bootstrap 2
2012-04-19 16:27:25 -04:00
Michael Jett
b38c8c18d6
Edit form mock-up updates. Organized forms and input.
2012-04-19 15:51:38 -04:00
Michael Jett
51b8650327
Bootstrap 2 html test updates - removing compile javascript
2012-04-19 12:37:40 -04:00
Amanda Anganes
2e4f312f79
Fixed tests - they were pointing to the wrong context file.
2012-04-18 10:55:28 -04:00
Amanda Anganes
a9088b4999
Merge branch 'Single_Spring_Context_file'
2012-04-18 10:33:57 -04:00
Amanda Anganes
07a305b8b7
Refactored code to use a single spring context file. This uses the default oauth/authorize and oauth/token URLs, but it seems to be free of the infinite redirect issue. Next up: try putting in our custom URLs.
2012-04-17 15:32:07 -04:00
Michael Jett
8ab1fc1b60
Bootstrap 2 html tests
2012-04-16 16:44:31 -04:00
Michael Jett
9c86a23ee1
Bootstrap 2
2012-04-16 16:14:25 -04:00
Michael Jett
ed304fa391
Edit client mock-up.
2012-04-16 15:09:06 -04:00
Michael Jett
c4edd7111e
Breadcrumb tag renders "crumb" attribute
2012-04-16 13:13:41 -04:00
Michael Jett
dc42eb7789
Client management page now renders test JSON
2012-04-16 13:13:41 -04:00
Amanda Anganes
6899a16c2f
Merge branch 'Really_fixing_redirects'
2012-04-16 12:39:06 -04:00
Amanda Anganes
5d78bc4e0a
Infinite redirect issue fully fixed, with our custom urls for the authorization and token endpoints. See issue #8 .
2012-04-16 12:37:14 -04:00
Amanda Anganes
67edc1c191
Seems to be fixed! Added the "security:" prefix to the first http block in application-context. The compiler should have been catching that there was no matching for http w/o it, but it was just letting it through.
2012-04-16 12:23:23 -04:00
Justin Richer
05b2cf8fff
removed vestigial user details code
2012-04-16 12:02:24 -04:00
Amanda Anganes
f0f339d45f
current state
2012-04-16 11:05:36 -04:00
Amanda Anganes
69dc1fe361
Removing our custom authorization endpoint and token endpoint urls, as well as the filter required by those custom urls (in web.xml), fixes the infinite redirect problem. This has been submitted as an issue to the SECOAUTH team.
2012-04-11 17:08:15 -04:00
Amanda Anganes
2fc4ce177c
This commit fixes the infinite redirect, somewhat. See updated issue #8 .
2012-04-11 15:55:19 -04:00
Amanda Anganes
17f6e2a2fb
Removed tables.sql.
2012-04-10 14:05:39 -04:00
Amanda Anganes
486b7723d3
Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server
2012-04-10 13:45:26 -04:00
Amanda Anganes
269a354f8c
Added tables.sql, which is just a concatenation of all the other sql files. Added redirect_uris.sql, which is a NEW table needed to support clients registering multiple redirect uris.
...
This updates us to the HEAD revision of SECOAUTH, where the redirect uri field on ClientDetails has been updated to be a Set<String> instead of a single string. I updated the UI code so that it will still work, but it will need to be updated to allow users to register multiple uris.
This also closes issue #2 from the issue tracker.
2012-04-10 13:44:10 -04:00
nemonik
d056079fea
Support for ECDSA JWT signer was removed as it would require the system-wide installation and configuration of the Bouncy Castle Security Provider in order for the server to work when deployed to Tomcat. See issue ticket #20
2012-04-10 13:41:18 -04:00
Amanda Anganes
14f6eca026
Merge branch 'fixing_redirects'
2012-04-09 10:53:39 -04:00
Amanda Anganes
5b09c93024
Cleaned up the context files a bit, no big changes yet.
2012-04-09 10:53:02 -04:00
Justin Richer
eabc49cb01
fixed documentation, included python source to generate signature
2012-04-09 10:52:17 -04:00
Justin Richer
c21607dcbe
fixed hmac unit test after signature base string was fixed in underlying code
2012-04-09 10:48:02 -04:00
nemonik
6c8661f3ad
the signature base created in the verify method of the AbstractJwtSigner did not match how the Jwt.getSignatureBase creates the signature base. also, modified the testGenerateHmacSignature to exercise
2012-04-02 22:12:03 -04:00
nemonik
267f1b2de3
bas64 decoded signature prior to verifying, modified unit rsa unit test, and fixed ecdsa signer verify
2012-04-02 21:32:42 -04:00
Justin Richer
985a4619fa
abstracted keystore loader to new function
2012-04-02 15:06:58 -04:00
Justin Richer
3dfe6df410
refactored algorithms out to their own separate Enum
2012-04-02 13:13:13 -04:00
Justin Richer
fec6a3a876
removed definition parsers, may be picked up again later
2012-04-02 12:40:53 -04:00
Amanda Anganes
b986b30695
Fixed unit tests - they were broken due to an error in application-context.xml; not because of the refactor. App context was trying to instantiate an Hmac signer with name "HMACSHA256", which should have been "HS256". I updated the exceptions thrown by the signer impls so that if an Algorithm name mismatch occurs it will tell you what it is trying to match against.
2012-03-30 13:45:04 -04:00
nemonik
0a29eba617
unit test correction, slight refactor of tested classes
2012-03-29 14:02:51 -04:00
nemonik
1209e9a83f
fix to JwtTest unit test
2012-03-29 12:54:03 -04:00
nemonik
f215cfc50c
fix for issue 5, code refactoring across signers
2012-03-29 12:34:51 -04:00
nemonik
4f407a3a11
added rsa1024 key to keystore
2012-03-28 18:02:03 -04:00
Amanda Anganes
c50f968748
Merged to use idToken.setNonce().
2012-03-23 11:11:38 -04:00
Amanda Anganes
268b82e31d
Merge branch 'Branch_master3-23-2012'
2012-03-23 11:09:27 -04:00
Amanda Anganes
8b10b83516
Added setNonce to JwtClaims.
2012-03-23 11:08:49 -04:00
Justin Richer
4a15e51e12
pass through nonce
2012-03-23 10:52:04 -04:00
Justin Richer
6c3552ebfa
changed mitre account names
2012-03-23 10:37:58 -04:00
Amanda Anganes
27fe3c9eca
Implemented signing. Works, but validation does not fail if you remove the signature.
2012-03-22 14:49:02 -04:00
Amanda Anganes
68c8d1a9d2
Changed parameter for check id endpoint to access_token instead of auth_token
2012-03-22 14:19:45 -04:00
Justin Richer
826be5a1a1
changed parameter name to match spec change
2012-03-22 14:10:50 -04:00
Justin Richer
5fe036878a
fixed view for idtoken in checkid endpoint
2012-03-22 14:09:25 -04:00
Justin Richer
c51bb72fe5
merged keystore changes
2012-03-22 13:50:47 -04:00
Justin Richer
6c01134095
JWK display support for key maps, still no key ids
2012-03-22 13:48:16 -04:00
Amanda Anganes
776748f908
Merge branch '3-22-2012'
2012-03-22 13:43:59 -04:00
Amanda Anganes
ae9b5e792a
Added a ConfigurationPropertiesBean.java to hold configuration properties. Fixed up CheckIDEndpoint.java a bit - it works, but is outputting the wrong thing.
2012-03-22 13:43:30 -04:00
Justin Richer
d5e7000365
disabled custom namespace parsers for keystores
2012-03-22 13:39:51 -04:00
Justin Richer
524a8e153e
signers turned into a map
2012-03-22 13:37:21 -04:00
Justin Richer
664dd1df46
JWT claims can now have nulls in them without barfing
2012-03-22 11:46:48 -04:00
Justin Richer
c59d3fe963
it spits out JWTs! and id tokens! JWT still needs to handle nulls
2012-03-21 17:59:48 -04:00
Amanda Anganes
ebe72412fe
Authorization Grant flow works up to serializing the returned Access Token. Justin is investigating serialization problems.
2012-03-21 16:44:16 -04:00
Amanda Anganes
d94eb338ee
Auth code flow works through user approval page. Current problem is that it doesn't seem to be matching up auth codes correctly (I keep getting "invalid code" error). But, it looks like it's going through our custom token granter so that is good.
2012-03-20 15:07:18 -04:00
Justin Richer
8263ce0dd5
added external class to persistence context
2012-03-16 17:01:24 -04:00
Justin Richer
b463cabc69
fixed configuration, moved sql file
2012-03-16 16:46:46 -04:00
Justin Richer
2f29cc52b2
Merge branch 'client_refactor'
2012-03-16 16:28:51 -04:00
Justin Richer
e6e7504213
added files and shuffled things to new packages
2012-03-16 15:46:23 -04:00
Justin Richer
a0cdd8bf2f
moved server to new package location
2012-03-16 15:01:53 -04:00