Amanda Anganes
2e2c0e8e6c
Fixed bug in nonce processing
2013-01-29 13:07:41 -05:00
Amanda Anganes
3db74100a4
working on bug
2013-01-29 13:07:41 -05:00
Amanda Anganes
dd8b48e863
Reset ConnectAuthorizationRequestManager to version from master
2013-01-29 13:07:41 -05:00
Amanda Anganes
06f970e61b
Trying to fix nonce service
2013-01-29 13:07:41 -05:00
Amanda Anganes
86bf51f0a7
Added java reflection code for request object handling, needs to be tested
2013-01-29 13:07:41 -05:00
Amanda Anganes
677f0f2d4c
Stubbed out required functionality for request object filtering
2013-01-29 13:07:41 -05:00
Amanda Anganes
67e8714671
Working on request object userinfo parsing
2013-01-29 13:07:41 -05:00
Justin Richer
779001a8c8
updated copyright year
2013-01-28 13:39:25 -05:00
Justin Richer
7269700dc6
switched injector from repository to service
2013-01-24 19:32:55 -05:00
Justin Richer
f0ee36dad2
auth_type -> auth_method (addresses #258 )
2013-01-18 18:26:55 -05:00
Justin Richer
fd2253303e
changed pointer on tabs, addresses #252
2013-01-18 18:17:39 -05:00
Justin Richer
899e306683
fixed JS crash on "new client" operation
2013-01-18 18:15:19 -05:00
Justin Richer
8831bc64a2
offline -> offline_access (addresses #248 )
2013-01-18 18:03:39 -05:00
Justin Richer
27a26e0a35
(user_id/prn) -> sub
2013-01-18 16:40:05 -05:00
Justin Richer
1ab29882b4
fixed user prepoulation table
2013-01-18 15:38:53 -05:00
Justin Richer
0ab4ad4bbe
added "birthdate", addresses #253
2013-01-18 15:38:41 -05:00
Justin Richer
6ef4dc817e
genericized nimbus code, added caching
2013-01-18 15:10:48 -05:00
Justin Richer
2d21a72e7e
switched to nimbus to check JWT signature
2013-01-18 15:10:48 -05:00
Justin Richer
60bda31c54
updated custom filter
2013-01-18 15:10:48 -05:00
Justin Richer
c17bc05b0e
wiring configuration
2013-01-18 15:10:48 -05:00
Justin Richer
4262be1fd3
added jwt processing to client auth provider
2013-01-18 15:06:00 -05:00
Justin Richer
abd64eccd6
added framework for processing assertions for client auth
2013-01-18 15:06:00 -05:00
Amanda Anganes
ad5e77f7ff
Made nonce storage duration configurable in application-context.xml;
2013-01-10 10:34:40 -05:00
Amanda Anganes
59f1b1f05e
Testing, nonce handling seems to be working now
2013-01-07 13:28:30 -05:00
Amanda Anganes
a1a117cfde
Added default constructor to ConnectAuthorizationRequestManager
2013-01-07 10:54:33 -05:00
Amanda Anganes
af81e371fb
Updated application-context to use new authorization request manager
2013-01-07 10:46:55 -05:00
Amanda Anganes
77b932f5a7
Added implementation of AuthorizationRequestManager. Nonce checking will go in here
2013-01-04 15:30:24 -05:00
Amanda Anganes
1af6513499
Removed nonce checking from token service impl
2013-01-04 15:30:24 -05:00
Amanda Anganes
7e7b2527db
Added nonce to persistence.xml
2013-01-04 15:30:24 -05:00
Amanda Anganes
246ed962bb
Added stub of repository test
2013-01-04 15:30:24 -05:00
Amanda Anganes
e1dffb959c
Added NonceReuseException
2013-01-04 15:30:24 -05:00
Amanda Anganes
8f8a3754db
Added database tables for Nonce
2013-01-04 15:30:24 -05:00
Amanda Anganes
a4637ec395
Fleshed out nonce service classes, added code to token service impl to check for and store nonces. Added JodaTime library for working with dates.
2013-01-04 15:30:24 -05:00
Amanda Anganes
c7ae315e98
Added initial files for nonce service. Repository and service impls are stubs
2013-01-04 15:30:24 -05:00
Justin Richer
cbcfe55bb9
added introspection flag to client bootstrap
2013-01-02 14:16:31 -05:00
Justin Richer
4068952a81
fixed well size, added comment
2013-01-02 10:19:55 -05:00
Justin Richer
655092a12b
added introspection checkbox, added access tab
...
Signed-off-by: Justin Richer <jricher@mitre.org>
2012-12-21 16:38:52 -05:00
Justin Richer
9a1b2d7fac
made client edit page tabbable (that was seriously easy)
2012-12-21 16:26:34 -05:00
Justin Richer
48866c15f2
button display cleanup
2012-12-21 16:07:59 -05:00
Justin Richer
a85b1f5d74
split approved sites into two tables
2012-12-21 15:35:33 -05:00
Justin Richer
198a45369a
buttonsize tweak
2012-12-21 15:03:45 -05:00
Justin Richer
f12efc1b80
added dynreg caution block
2012-12-21 14:48:15 -05:00
Justin Richer
231e81a426
updated icons
2012-12-21 14:28:07 -05:00
Justin Richer
797d521691
cleaned up logged-in button
2012-12-21 13:04:33 -05:00
Justin Richer
7ebbe3acc4
removed mockups
2012-12-21 11:01:22 -05:00
Justin Richer
7459767646
fixed validation problem with new backbone
2012-12-20 17:46:34 -05:00
Justin Richer
37bca0d5fb
cleaned out backbone validation plugin
2012-12-20 17:31:22 -05:00
Justin Richer
9dd54d47bb
updated versions of backbone and underscore
2012-12-20 17:31:08 -05:00
Justin Richer
e0672757bf
update to bootstrap 2.2.2
2012-12-20 12:44:02 -05:00
Justin Richer
8ad28b41aa
fixing CSS and collapsing headerbar
2012-12-20 12:35:30 -05:00
Justin Richer
67a682d53a
added default router to backbone app
2012-12-18 13:56:57 -05:00
Justin Richer
87788f0710
let users visit home page without logging in
2012-12-18 13:56:46 -05:00
Justin Richer
f265347311
tweaked error messages
2012-12-18 12:08:36 -05:00
Justin Richer
18ddd8333f
added flag to allow introspection, relaxed same-client restrictions on introspection and chained tokens
2012-12-18 11:07:24 -05:00
Justin Richer
6eabc895b9
moved database file to a reasonable name
2012-12-17 13:45:39 -05:00
Justin Richer
1f53f41648
generic entity view now takes optional HttpStatus argument
2012-12-14 17:35:21 -05:00
Justin Richer
a3790f943e
cleaned up introspection endpoint to use exceptions
2012-12-14 17:35:20 -05:00
Justin Richer
e5206f2b92
implemented jwt assertions for id tokens
2012-12-14 17:35:20 -05:00
Justin Richer
51b67ebc03
added queries to get access token from id token
2012-12-14 17:35:20 -05:00
Justin Richer
1853bd7117
added assertion token granter
2012-12-14 17:35:20 -05:00
Justin Richer
0d6c96f410
moved JPA adapter to data-context, addresses #242
2012-12-14 09:43:42 -05:00
Justin Richer
2a74be5baf
bringing mysql tables up to date
2012-12-13 16:54:21 -05:00
Justin Richer
2c104a71e2
cleaned up mysql table
2012-12-13 16:04:45 -05:00
Justin Richer
cda6163d0d
null and blank handling
2012-12-12 12:29:14 -05:00
Justin Richer
06fad3a41c
moved view for client API
2012-12-11 15:19:11 -05:00
Justin Richer
6344a72519
missed a few applicationName references, fixed API JSON rendering
2012-12-11 15:16:18 -05:00
Justin Richer
dfd8e9c7c7
removed unused view
2012-12-11 15:15:52 -05:00
Justin Richer
dd04df6a22
fixed javascript bugs
2012-12-11 14:08:10 -05:00
Justin Richer
f12d3c7d30
fixed variable reference
2012-12-11 13:37:14 -05:00
Justin Richer
920777128d
switched to uncompressed jquery
2012-12-11 13:29:19 -05:00
Justin Richer
829c8ae5f4
tweaked functionality of grant types and scopes
2012-12-11 13:16:33 -05:00
Justin Richer
cc36851bdd
propagated field name change to UI
2012-12-11 12:38:55 -05:00
Justin Richer
179903b074
propagated client changes to service
2012-12-11 12:31:01 -05:00
Justin Richer
2f7891d02c
updated mysql table to new schema
2012-12-11 12:27:24 -05:00
Justin Richer
bcfa37040e
missed one
2012-12-11 12:18:51 -05:00
Justin Richer
33ceedb283
added scope and grant_type, switched to timeunit
2012-12-11 12:11:09 -05:00
Justin Richer
e2bc15c2b2
beginning of client registration refactor to track IETF dynreg spec
2012-12-10 17:36:33 -05:00
Justin Richer
94c37f5815
added redelegate scope to client list, fixed inconsistency with refresh token issuance (addresses #239 )
2012-12-10 16:53:05 -05:00
Justin Richer
510ddb48b7
override the correct part of the token granter class
2012-12-10 15:54:37 -05:00
Justin Richer
bdcc6af096
temporary sanity check for client ID's
2012-12-10 11:40:03 -05:00
Justin Richer
cab0839430
added workarounds for quirks in SECOAUTH
2012-12-10 11:27:28 -05:00
Justin Richer
edc96d646c
added chained token grant
2012-12-10 10:48:38 -05:00
Justin Richer
54708fb0ac
fixed id token scopes (shouldn't inherit from parent token)
2012-12-10 10:11:02 -05:00
Justin Richer
2a206654b6
added client credential protection to revocation endpoint
2012-12-07 17:17:19 -05:00
Justin Richer
e38b2b0ba5
shortened revocation endpoint url
2012-12-07 17:16:03 -05:00
Justin Richer
fbc3c46128
Introspection now draft spec compliant, requires client auth
...
Currently this is the client that originally sent the token, we want to have a way to bind other "clients" to this token as well, like resource services. Also want to let open calls, sometimes.
2012-12-07 17:12:13 -05:00
Justin Richer
544e3d7b43
added copy constructors because Dave likes to use unmodifiable sets for no apparent reason
2012-12-07 10:06:10 -05:00
Justin Richer
64ef752f08
added refresh token granter for testing
2012-12-07 09:56:43 -05:00
Justin Richer
7561ac9e8c
client dynamic registration now protected by access token, addresses #199
2012-12-06 17:48:23 -05:00
Justin Richer
7342da6a51
completed making id tokens into access tokens
2012-12-06 16:24:04 -05:00
Justin Richer
e4f9fa2bbf
labeled introspection endpoint
2012-12-06 16:19:25 -05:00
Justin Richer
17374a57e0
added ISO date format to generic entity view, addresses #232
2012-12-06 16:15:14 -05:00
Justin Richer
3378cd5c4c
cleaned table
2012-12-06 14:24:38 -05:00
Justin Richer
b8f701d9d8
switched id tokens to entities, they're now access tokens also
...
still needs some work to get the auth object right, for now we're just copying from the access token
2012-12-06 10:19:21 -05:00
Justin Richer
2ef8d16e9c
typo, formatting
2012-12-05 15:49:50 -05:00
Justin Richer
ba7ddf17f9
added bootstrapping for clients, cleaned up sql files
2012-12-05 15:04:14 -05:00
Justin Richer
cf7ceb74f3
betterer logout button
2012-12-04 16:40:28 -05:00
Justin Richer
2f1a6864b8
made a better logout button
2012-12-04 16:37:57 -05:00
Justin Richer
838e029db1
added logout button
2012-12-04 16:18:58 -05:00
Justin Richer
d7d9e84e70
fixed user_id mapping
2012-12-04 16:18:37 -05:00