Justin Richer
bdf62eaa36
need to check the sector identifier at some point
2013-09-10 16:35:51 -04:00
Justin Richer
914f2e4d93
added new call to get the UserInfo in context with the requesting client to allow for pairwise identifiers.
...
temporary implementation of pairwise identifiers in place
2013-09-10 16:01:17 -04:00
Justin Richer
149fb1bac1
services shouldn't be transactional
2013-09-10 15:26:09 -04:00
Justin Richer
29d1c7d54a
userinfo endpoint now uses OAuth2Authentication exclusively
...
(which is all it was really doing before)
2013-09-10 14:16:34 -04:00
Justin Richer
ac42c00062
id token now uses userinfo's sub
2013-09-10 13:50:49 -04:00
Justin Richer
b9da10d176
look up by username instead of subject
2013-09-10 11:39:00 -04:00
Justin Richer
9ea82aacf0
clean up unused getter/setter
2013-09-10 11:38:42 -04:00
Justin Richer
469e722f72
defer to system scope matcher in approval handler
2013-09-06 16:07:25 -04:00
Justin Richer
99ad9b883e
added validator that knows how to deal with structured scopes
2013-09-06 16:07:25 -04:00
Justin Richer
59187d47e4
use new unified parsing for approval page
2013-09-06 16:07:25 -04:00
Justin Richer
85533d50cf
scope comparison for TofuUserApprovalHandler
2013-09-06 16:07:25 -04:00
Justin Richer
1c4c53f252
scope comparison for introspection endpoint
2013-09-06 16:07:24 -04:00
Justin Richer
6152a943d8
serialize structured scopes properly (with tests)
2013-09-06 16:07:24 -04:00
Justin Richer
72f0ab631d
added transient structured value to system scope, added scope matcher function to scope service
2013-09-06 16:07:24 -04:00
Josh Mandel
b416888b07
Structured Scopes from BB+
2013-09-06 16:07:24 -04:00
Justin Richer
127507246e
if the client doesn't ask for any system scopes, but asks for some non-system scopes, they'll now get the defaults instead of none
...
addresses #498
2013-09-06 13:30:22 -04:00
Justin Richer
64bbb73d1b
cleaned up CORS filter implementation
2013-09-03 16:01:19 -04:00
Justin Richer
6ff4ae1458
added CORS filter
2013-09-03 15:17:18 -04:00
William Kim
2108311d65
Revert "refactored code to use the more generic JWT declaration."
...
This reverts commit e0b56bc72a
.
2013-08-26 15:33:08 -04:00
William Kim
e0b56bc72a
refactored code to use the more generic JWT declaration.
2013-08-26 11:32:46 -04:00
Justin Richer
ca777f7dc4
proper null check for client's preferred signature method
2013-08-20 16:45:45 -04:00
William Kim
07bec462cc
added comment about why we can't use set intersection method.
2013-08-20 14:09:14 -04:00
William Kim
b89436d7b9
UserInfoView returning intersection of claims request parameter and request object claims in effect now.
2013-08-20 08:55:56 -04:00
Amanda Anganes
941e9544e2
Compare client_ids instead of Client objects
2013-08-19 16:55:56 -04:00
Amanda Anganes
3eae6f2789
Changed client algorithm check to look for null instead of JWSAlgorithm.NONE, which is a valid value.
2013-08-19 16:55:29 -04:00
Amanda Anganes
0059c7b4cc
Use clients preferred algorithm, if any, to sign
2013-08-19 16:33:18 -04:00
William Kim
b54f33d0db
fixed json elements of "claims" and "userinfo" being processed out of order.
2013-08-19 14:15:53 -04:00
William Kim
7b813c79ee
parsing "claims" parameter directly from userinfoendpoint requests.
2013-08-19 13:32:34 -04:00
William Kim
1ffbb39a2b
refactored json parser to a private static field.
2013-08-19 13:30:56 -04:00
William Kim
89056bd911
removed test-specific constructor and default constructor.
2013-08-19 13:30:56 -04:00
Justin Richer
7d51335055
added prompt=login support, addresses #323
2013-08-14 17:00:56 -04:00
Justin Richer
a0646452ab
test for max_age, force login if not fresh enough, addresses #467
2013-08-14 16:50:51 -04:00
Justin Richer
6c1e91b7e3
auth_time is now tracked, addresses #288
2013-08-14 15:39:41 -04:00
Amanda Anganes
e88c6c4943
Changed predicates methods to use Collections2.filter rather than Sets.filter
2013-08-13 10:31:39 -04:00
William Kim
6687e3a831
override createOAuth2Request method for factory iss #465 .
2013-08-09 13:03:46 -04:00
Amanda Anganes
ef4482249c
Dyn-reg endpoint now creates the registration access token from scratch instead of calling token services; token services no longer needs to check for RAT scope to avoid expiring RATs
2013-08-09 11:49:11 -04:00
Justin Richer
15e512cec3
renamed JWSUtils -> IdTokenHashUtils, renamed internal variables
2013-08-08 14:34:19 -04:00
William Kim
cdd3a6d478
changed at_hash/c_hash impl. HMAC-SHA --> regular SHA.
2013-08-08 14:10:35 -04:00
Amanda Anganes
2d4d7f7be9
Had to hand-merge some things; git got confused
2013-08-07 10:59:55 -04:00
Amanda Anganes
861beeba64
Added c_hash function, added stub of unit test for JWSUtils
2013-08-07 10:43:26 -04:00
Amanda Anganes
37580cc21e
JWSUtils uses JWSAlgorithm to match bit length; ConnectTokenEnhancer calls the util method now
2013-08-07 10:41:53 -04:00
Amanda Anganes
3a591dc1f4
Added JWSUtils class;
2013-08-07 10:38:28 -04:00
Amanda Anganes
be97aedbc7
Used Predicates to filter expired tokens and approved sites;
2013-08-06 16:42:49 -04:00
Amanda Anganes
b3bb43881d
Moved getExpired to service layers
2013-08-06 16:33:27 -04:00
Amanda Anganes
eea37cf79c
Fixed token expiration bug by removing jsql queries. Instead expired tokens or approved sites are filtered at the repository level
2013-08-06 11:28:13 -04:00
Amanda Anganes
265214511c
Renamed oAuth2RequestFactory
2013-08-05 14:04:48 -04:00
Amanda Anganes
a4c1a7a37d
Issue 449
2013-08-02 11:20:47 -04:00
Amanda Anganes
2f711c88a7
Removed nonce service
2013-08-02 10:56:28 -04:00
Amanda Anganes
d4fbb4f599
Removed Event class
2013-08-02 10:06:41 -04:00
Amanda Anganes
ad2ace6d74
Do not expire registration tokens
2013-07-30 11:33:15 -04:00
Justin Richer
beaeaa4ccc
I can spell "consortium", I promise
2013-07-29 17:40:26 -04:00
Justin Richer
856c0ea0b5
Merge commit '023dd440d4a0e6e59a14c88013837d79a77c74e0' into 1.1-merge
...
Conflicts:
openid-connect-client/pom.xml
openid-connect-client/src/main/java/org/mitre/oauth2/introspectingfilter/AuthorizationRequestImpl.java
openid-connect-client/src/main/java/org/mitre/oauth2/introspectingfilter/IntrospectingTokenService.java
openid-connect-client/src/main/java/org/mitre/oauth2/introspectingfilter/IntrospectionAuthorityGranter.java
openid-connect-client/src/main/java/org/mitre/oauth2/introspectingfilter/IntrospectionUrlProvider.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/OIDCAuthenticationFilter.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/OIDCAuthenticationProvider.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/keypublisher/ClientKeyPublisher.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/keypublisher/ClientKeyPublisherMapping.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/keypublisher/JwkViewResolver.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/service/AuthRequestUrlBuilder.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/service/ClientConfigurationService.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/service/impl/StaticClientConfigurationService.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/service/impl/StaticServerConfigurationService.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/service/impl/StaticSingleIssuerService.java
openid-connect-client/src/main/java/org/mitre/openid/connect/client/service/impl/ThirdPartyIssuerService.java
openid-connect-client/src/test/java/org/mitre/openid/connect/client/AbstractOIDCAuthenticationFilterTest.java
openid-connect-common/pom.xml
openid-connect-common/src/main/java/org/mitre/jose/keystore/JWKSetKeyStore.java
openid-connect-common/src/main/java/org/mitre/jwt/signer/service/JwtSigningAndValidationService.java
openid-connect-common/src/main/java/org/mitre/jwt/signer/service/impl/DefaultJwtSigningAndValidationService.java
openid-connect-common/src/main/java/org/mitre/jwt/signer/service/impl/JWKSetSigningAndValidationServiceCacheService.java
openid-connect-common/src/main/java/org/mitre/oauth2/model/AuthorizationCodeEntity.java
openid-connect-common/src/main/java/org/mitre/oauth2/model/ClientDetailsEntity.java
openid-connect-common/src/main/java/org/mitre/oauth2/model/OAuth2AccessTokenEntity.java
openid-connect-common/src/main/java/org/mitre/oauth2/model/OAuth2RefreshTokenEntity.java
openid-connect-common/src/main/java/org/mitre/oauth2/model/SystemScope.java
openid-connect-common/src/main/java/org/mitre/oauth2/repository/AuthorizationCodeRepository.java
openid-connect-common/src/main/java/org/mitre/oauth2/repository/OAuth2TokenRepository.java
openid-connect-common/src/main/java/org/mitre/oauth2/service/OAuth2TokenEntityService.java
openid-connect-common/src/main/java/org/mitre/openid/connect/config/ConfigurationPropertiesBean.java
openid-connect-common/src/main/java/org/mitre/openid/connect/config/ServerConfiguration.java
openid-connect-common/src/main/java/org/mitre/openid/connect/model/ApprovedSite.java
openid-connect-common/src/main/java/org/mitre/openid/connect/model/BlacklistedSite.java
openid-connect-common/src/main/java/org/mitre/openid/connect/model/Event.java
openid-connect-common/src/main/java/org/mitre/openid/connect/model/OIDCAuthenticationToken.java
openid-connect-common/src/main/java/org/mitre/openid/connect/model/WhitelistedSite.java
openid-connect-common/src/main/java/org/mitre/util/jpa/JpaUtil.java
openid-connect-server/.gitignore
openid-connect-server/pom.xml
openid-connect-server/src/main/java/org/mitre/oauth2/repository/impl/JpaAuthorizationCodeRepository.java
openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2AuthorizationCodeService.java
openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ClientDetailsEntityService.java
openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java
openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultSystemScopeService.java
openid-connect-server/src/main/java/org/mitre/oauth2/token/ChainedTokenGranter.java
openid-connect-server/src/main/java/org/mitre/oauth2/token/JwtAssertionTokenGranter.java
openid-connect-server/src/main/java/org/mitre/oauth2/view/TokenIntrospectionView.java
openid-connect-server/src/main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java
openid-connect-server/src/main/java/org/mitre/oauth2/web/OAuthConfirmationController.java
openid-connect-server/src/main/java/org/mitre/oauth2/web/RevocationEndpoint.java
openid-connect-server/src/main/java/org/mitre/openid/connect/ConnectOAuth2RequestFactory.java
openid-connect-server/src/main/java/org/mitre/openid/connect/assertion/JwtBearerAuthenticationProvider.java
openid-connect-server/src/main/java/org/mitre/openid/connect/assertion/JwtBearerClientAssertionTokenEndpointFilter.java
openid-connect-server/src/main/java/org/mitre/openid/connect/exception/InvalidJwtSignatureException.java
openid-connect-server/src/main/java/org/mitre/openid/connect/exception/UnknownUserInfoSchemaException.java
openid-connect-server/src/main/java/org/mitre/openid/connect/exception/UserNotFoundException.java
openid-connect-server/src/main/java/org/mitre/openid/connect/repository/impl/JpaApprovedSiteRepository.java
openid-connect-server/src/main/java/org/mitre/openid/connect/repository/impl/JpaUserInfoRepository.java
openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultApprovedSiteService.java
openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultNonceService.java
openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultStatsService.java
openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultUserInfoUserDetailsService.java
openid-connect-server/src/main/java/org/mitre/openid/connect/service/impl/DefaultWhitelistedSiteService.java
openid-connect-server/src/main/java/org/mitre/openid/connect/token/ConnectTokenEnhancer.java
openid-connect-server/src/main/java/org/mitre/openid/connect/token/TofuUserApprovalHandler.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/AbstractClientEntityView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/ClientInformationResponseView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/ExceptionAsJSONView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/JsonEntityView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/JsonErrorView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/POCOUserInfoView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/StatsSummary.java
openid-connect-server/src/main/java/org/mitre/openid/connect/view/UserInfoView.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/ApprovedSiteAPI.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/BlacklistAPI.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/ClientAPI.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/ClientDynamicRegistrationEndpoint.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/ManagerController.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/RequestObjectAuthorizationEndpoint.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/StatsAPI.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/UserInfoEndpoint.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/UserInfoInterceptor.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/WhitelistAPI.java
openid-connect-server/src/main/webapp/WEB-INF/tags/aboutContent.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/breadcrumbs.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/contactContent.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/copyright.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/header.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/landingPageAbout.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/landingPageContact.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/landingPageStats.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/landingPageWelcome.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/sidebar.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/statsContent.tag
openid-connect-server/src/main/webapp/WEB-INF/tags/topbar.tag
openid-connect-server/src/main/webapp/WEB-INF/views/about.jsp
openid-connect-server/src/main/webapp/WEB-INF/views/approve.jsp
openid-connect-server/src/main/webapp/WEB-INF/views/contact.jsp
openid-connect-server/src/main/webapp/WEB-INF/views/exception/usernotfound.jsp
openid-connect-server/src/main/webapp/WEB-INF/views/login.jsp
openid-connect-server/src/main/webapp/WEB-INF/views/manage.jsp
openid-connect-server/src/main/webapp/WEB-INF/views/stats.jsp
pom.xml
2013-07-29 16:21:20 -04:00
Justin Richer
e658ffd7fc
format/cleanup and copyright
2013-07-29 11:28:51 -04:00
Justin Richer
d4b544d519
disable token API (for now)
2013-07-29 11:23:07 -04:00
Amanda Anganes
906db0ac86
Opened token api access to all users; restricted to only show currently-logged-in-users tokens
2013-07-29 09:18:08 -04:00
Justin Richer
71da5b3d94
clean up some discovery values
2013-07-26 17:07:28 -04:00
Justin Richer
c62bed37ff
convert server to use normalizer
2013-07-26 17:07:08 -04:00
William Kim
93c3e7906f
put in line breaks into the extra long comments in DiscoveryEndpoint.java
2013-07-25 09:25:06 -04:00
Amanda Anganes
b397f0ae15
First go at adding token API; needs to be tested
2013-07-24 09:14:46 -04:00
Amanda Anganes
88db457fc4
Removed .springBeans from tracking; removed initializingbean in favor of @PostConstruct
2013-07-18 09:34:52 -04:00
William Kim
aad432c5d7
replaced stracktrace-printing with logger messages. removed some unused imports.
2013-07-16 13:52:32 -04:00
William Kim
f483d41b88
getCustomClaim -> getClaim. Also, removed outdated TODOs.
2013-07-16 13:17:25 -04:00
William Kim
0d882faeca
added a TODO and fixed some comment typos.
2013-07-15 14:24:04 -04:00
Amanda Anganes
15aea61fbe
Applied code cleanup
2013-07-12 16:58:41 -04:00
Amanda Anganes
3e23967b46
Updated code to reflect SECOAUTH changes
2013-07-12 16:21:05 -04:00
William Kim
9a6f345e15
yes, allow default scoping if the client doesn't ask for any.
2013-07-12 15:05:17 -04:00
William Kim
3d312b7eb5
Deleted PermissionDeniedException class. Unused.
2013-07-12 11:40:11 -04:00
William Kim
ada54c297d
addresses issue #382 . Throw an exception when client tries to upscope.
2013-07-12 11:36:33 -04:00
William Kim
910839e5d9
fixed typo referring to client id as a client secret in code comments.
2013-07-10 16:53:49 -04:00
Amanda Anganes
2d3f43e3b8
Added task scheduling for deleting expired tokens and approved sites. Configuration is all done in application-context.xml so that it is easy to configure
2013-07-10 14:34:37 -04:00
Justin Richer
93a0492e97
made optional parameters optional
2013-07-10 12:50:57 -04:00
Justin Richer
a9da88fb79
brought introspection endpoint and introspection token services into compliance with draft, addresses #376
2013-07-10 12:50:57 -04:00
William Kim
5ffe1a50a2
Added null-handling for Scope values from the auth request. (Without this, a NullPointerException gets thrown with null scope values).
2013-07-05 15:14:56 -04:00
William Kim
42027e451c
added REQUIRED response types to discovery doc. Also, fixed 2 typos in the list of supported grant types.
2013-06-28 15:31:50 -04:00
William Kim
2a92185433
added introspection endpoint URL to discovery document.
2013-06-28 15:31:50 -04:00
William Kim
741946d1ae
updated server discovery code comments.
2013-06-28 15:31:50 -04:00
William Kim
f27b69d06b
removed Version field from server discovery configuration.
2013-06-28 15:31:50 -04:00
William Kim
4f9cbb4b3f
added check for null
2013-06-27 09:29:47 -04:00
William Kim
dc51af5b83
removed testing builder inner class from DefaultOAuth2ProviderTokenService. Also, added more unit tests.
2013-06-25 16:31:45 -04:00
Amanda Anganes
c212821267
Fixed ChainedTokenGranter setup
2013-06-24 10:14:10 -04:00
Amanda Anganes
530c3a75ee
Applyed refactoring
2013-06-24 09:44:59 -04:00
William Kim
8935a87c23
TestDefaultWhitelistedSiteService done. Removed constructors from DefaultWhitelistedSiteService.
2013-06-18 15:20:06 -04:00
William Kim
8851f4d037
TestDefaultOAuth2ClientDetailsEntityService done. Removed constructors from DefaultOAuth2ClientDetailsEntityService.
2013-06-18 15:19:55 -04:00
William Kim
4ee904cbfd
removed setter/getter from DefaultUserInfoUserDetailsService and updated test class with Mockito annotations.
2013-06-18 15:19:46 -04:00
William Kim
5428848627
updated TestDefaultApprovedSiteService to use annotation style Mocking. Allows for removal of injector constructor.
2013-06-18 15:19:46 -04:00
William Kim
01fcb4828d
removed test constructors for DefaultBlacklistedSiteService.java. Used annotation method of injecting mock objects into testing class (@InjectMocks).
2013-06-18 15:19:33 -04:00
William Kim
9a3625ae2b
made unit test for checking blacklisted sites. Introduced a new constructor to be able to inject repository for testing.
2013-06-18 15:19:33 -04:00
Justin Richer
c577b691c7
moved OIDC auth token and userinfo interception filter to common package, addresses #353
2013-06-12 14:45:03 -04:00
Justin Richer
8290d198c2
added passthrough of userinfo for remote OIDC users
2013-06-12 14:22:13 -04:00
Justin Richer
6ed7477bc0
added stats to admin UI page, restyled scopes and dynamically registered flags
2013-06-07 18:05:07 -04:00
Justin Richer
dc9d5c667e
cleaned up error log messages
2013-06-06 13:44:50 -04:00
William Kim
1b601abd6f
Removed previous constructor from DefaultUserInforUserDetailsService.java and put in getter/setter for UserInfoRepository as a replacement.
2013-06-04 16:58:14 -04:00
Amanda Anganes
a7f2e605fa
Added two unit tests using the Mockito framework
2013-05-31 15:04:18 -04:00
Josh Mandel
b0dc5fb4e2
Fix a bug where a client is deleted before details looked up. Also return 204 on success
2013-05-31 14:30:51 -04:00
Amanda Anganes
76e5ff8053
Finished cleanup, ready to create pull request
2013-05-28 12:43:33 -04:00
Justin Richer
81cd13f6d3
added RegisteredClient class to facilitate client configuration and dynamic registration, addresses #335
2013-05-20 17:19:28 -04:00
Justin Richer
545ddace95
updated registration URI, addresses #321
2013-05-10 11:54:48 -07:00
Amanda Anganes
713f0a4d25
Renamed OAuth2Request authorizatoinParameters map to requestParameters
2013-05-03 17:07:04 -04:00
Amanda Anganes
967b3f2953
Cleanup from renaming
2013-05-03 16:15:42 -04:00
Amanda Anganes
1e24b31cc3
Propogating rename of AuthorizationRequest to OAuth2Request
2013-05-03 13:53:57 -04:00
Justin Richer
4276a14978
fixed stats api view
2013-05-02 14:55:37 -04:00
Justin Richer
1e870703f8
added licence/copyright header
2013-05-02 11:45:20 -04:00
Justin Richer
8afab04544
whitespace, import, brace, annotation, and format cleanups
2013-05-02 10:47:15 -04:00
Amanda Anganes
a3771177a1
Updated json serialization of approved site objects
2013-04-29 11:17:36 -04:00
Justin Richer
dcf41eaa9e
tried to make prompt=login work, backed off for now
2013-04-25 15:19:11 -04:00
Justin Richer
8d53149d03
added functionality for prompt=none
2013-04-25 11:38:10 -04:00
Justin Richer
7292766b51
implemented prompt=consent
2013-04-24 14:08:14 -04:00
Justin Richer
ce2c90fb30
fixed error messages in auth request manager
2013-04-24 12:10:59 -04:00
Amanda Anganes
c80b1081cc
Cleaning up approvedsite => token linkage
2013-04-24 11:52:03 -04:00
Amanda Anganes
939a801048
Redid approved site -> token mapping so it is unidirectional from ApprovedSite side. Fixed some error logging, added a new view for ApprovedSite which will only show the IDs of the tokens in the approvedTokens list
2013-04-23 17:40:22 -04:00
Amanda Anganes
a79aca906e
Fixed error logging; added ApprovedSite tracking to tokens
2013-04-22 15:49:06 -04:00
Justin Richer
d7689152b8
fixed inadvertent consistency bug in granting offline_access to clients
2013-04-19 16:12:09 -04:00
Justin Richer
0e2d5830a4
updated newly-registered clients to not get refresh tokens unless they ask for offline_access scope explicitly
2013-04-19 15:40:20 -04:00
Justin Richer
fb859fc39a
added client dynamic registration service, extracted clientdetails<->json processing into its own static class
2013-04-19 14:23:11 -04:00
Justin Richer
fc1088c841
fixed display of algorithms in discovery endpoint
2013-04-19 13:39:53 -04:00
Amanda Anganes
82fca45412
Removed RequestObjectAuthorizationEndpoint as it is no longer needed with the changes to the AuthorizationEndpoint.
2013-04-17 13:10:40 -04:00
Amanda Anganes
9db8119930
Fixed request object processing, had a small bug
2013-04-17 11:28:35 -04:00
Amanda Anganes
e708f77eb3
Fixed up OIDC code so that it runs with new SECOAUTH changes; removed old AuthorizationRequestImpl class which is no longer needed
2013-04-17 09:52:09 -04:00
Justin Richer
895690df54
added webfinger discovery to server, addresses #279
2013-04-16 17:22:18 -04:00
Justin Richer
9c6b08d919
effectively removed auth_time calculations
2013-04-16 16:04:26 -04:00
Justin Richer
33af3b1ad6
updated discovery endpoint to latest spec, removed surplus specialized view
2013-04-16 15:00:57 -04:00
Justin Richer
8e8e14c638
added at_hash
2013-04-15 17:12:47 -04:00
Justin Richer
3bb43f417a
added auth time tracking
2013-04-15 16:16:18 -04:00
Justin Richer
98fff8fe99
updated error handling on introspection and revocation endpoints
2013-04-12 16:34:51 -04:00
Justin Richer
35cb14a73f
fixed comment
2013-04-12 16:08:32 -04:00
Justin Richer
743a3023dc
removed old error handlers
2013-04-12 16:04:40 -04:00
Justin Richer
31e3c5e5e7
moved user approval page
2013-04-12 15:57:32 -04:00
Justin Richer
694761c026
cleaned up userinfo view
2013-04-12 15:40:05 -04:00
Justin Richer
71d6dc6afe
removed special stats view
2013-04-12 15:15:43 -04:00
Amanda Anganes
7e59421f33
Commented out XRD endpoint and added TODO reference to webfinger issue
2013-04-11 10:33:27 -04:00
Amanda Anganes
34b243e0e1
Added back discovery endpoint, but renamed to not say SWD
2013-04-11 10:27:31 -04:00
Stephen Moore
23c318f6c2
Updating guava to 14.0.1
2013-04-10 15:31:32 -04:00
Amanda Anganes
a723c9d921
Removed references to DefaultAuthorizationRequest in connect code
2013-04-08 10:37:13 -04:00
Amanda Anganes
e17eaa499e
Cleaned up classes affected by SECOAUTH changes; added Connect implementation of AuthorizationRequest and updated manager class to reflect new class & updated interface;
...
;
2013-04-08 10:13:27 -04:00
Justin Richer
f63ea94b37
fixed bean name
2013-04-01 12:05:39 -04:00
Justin Richer
c0c1847f38
fixed bean name
2013-04-01 11:59:23 -04:00
Amanda Anganes
02220a411a
Fixed typo
2013-03-29 12:59:49 -04:00
Amanda Anganes
2265a3f8c3
Updated error handling messages for scope, approved site, blacklist, whitelist, and client APIs using new JsonErrorView
2013-03-29 12:47:03 -04:00
Amanda Anganes
ee5b21b542
Added JsonErrorView
2013-03-29 12:47:03 -04:00
Amanda Anganes
07686d8e00
Removed superfluous try/catch around save call in ScopeAPI.
2013-03-29 12:47:03 -04:00
Justin Richer
6cc50e7cd5
switched signing & validation service to use JWK natively for keys
2013-03-28 16:43:26 -04:00
Justin Richer
f54dddd8c0
fixed blacklisted field name, addresses #295
2013-03-28 16:06:02 -04:00
Justin Richer
e2ad4d2e8f
cleaned up spurious nosuchalgorithm exceptions, addresses #285
2013-03-28 15:06:30 -04:00
Amanda Anganes
5b321b9c86
Updated whitelist api for ui error handling
2013-03-28 12:43:47 -04:00
Amanda Anganes
666573cd34
Updated blacklist and client api for ui error handling
2013-03-28 12:37:18 -04:00
Amanda Anganes
218fe9328c
Updated approved site API for error handling
2013-03-27 16:49:33 -04:00
Amanda Anganes
435fff3b1c
Updated scope API for error handling
2013-03-27 16:27:55 -04:00
Amanda Anganes
d24ecd2e7c
Removed extra scope validation endpoint
2013-03-27 15:27:34 -04:00
Amanda Anganes
96e333afa6
Working on error handling
2013-03-27 15:27:34 -04:00
Amanda Anganes
fa0a6a7b4e
Finding my way around Backbone, Underscore, and Bootstrap
2013-03-27 15:27:34 -04:00
Amanda Anganes
36b08dcd6e
Removed SWD code
2013-03-22 15:23:08 -04:00
Amanda Anganes
fcc95f8a0a
Moved nonce processing stuff into nonce service and out of ConnectAuthorizationRequestManager
2013-03-22 14:38:37 -04:00
Amanda Anganes
d38c5b4200
Pared down nonce reuse exception message to just say that the nonce has already been used
2013-03-22 12:36:24 -04:00
Amanda Anganes
b28b0615fa
removed vestigial ClientDetailsEntityService references
2013-03-22 12:32:31 -04:00
Justin Richer
08eaaa0a12
updated repository to use proper concrete class
2013-03-21 15:20:36 -04:00
Justin Richer
8fccbf3483
added Id field to DefaultUserInfo object, switched "userId" terminology to "subject"
2013-03-20 14:29:00 -04:00
Justin Richer
f44c704472
major refactor of client filter
...
Collapsed filter into single class
pulled server config and client config management into service classes
created service for issuer (will handle account chooser)
created auth request services (handle signed and unsigned requests)
2013-03-14 18:05:50 -04:00
Amanda Anganes
8992506a1d
Fixing up logging changes
2013-03-08 09:52:24 -05:00
Amanda Anganes
f9b0670ae9
Merged ClientAPI and ClientDynamicRegistrationEndpoitn by hand
2013-03-07 12:12:27 -05:00
Amanda Anganes
5cac7055a9
Standardized error handling and added logging for error conditions in endpoints
2013-03-07 11:56:57 -05:00
Amanda Anganes
dbc68e4074
Working on error handling
2013-03-07 11:51:18 -05:00
Amanda Anganes
1630814b9f
Marked classes where error handling needs to be added/changed
2013-03-07 11:51:18 -05:00
Justin Richer
6320fce9fd
url -> uri in approval page
2013-03-07 10:39:33 -05:00
Justin Richer
27a8bcf440
now with more documentation and actual deletion
2013-03-06 11:53:16 -05:00
Justin Richer
eaa9e1ded4
typo for grant types in parser
2013-03-06 11:33:54 -05:00
Justin Richer
a6a2d43e8f
added Read, Update, and Delete operations to dynreg endpoint
2013-03-06 11:33:31 -05:00
Justin Richer
d37bac1775
simplification and documentation of client api views
2013-03-06 11:33:06 -05:00
Justin Richer
c9bdba3f3a
API now bound to USER for read, ADMIN for write, addresses #267
2013-03-05 17:45:33 -05:00
Justin Richer
1daf5bd357
dispatch to different views based on user role
2013-03-05 17:34:24 -05:00
Justin Richer
70b2342864
fixed split client views, fixed typos in various places
2013-03-05 17:26:25 -05:00
Justin Richer
51a7ccc397
entity -> embed
2013-03-05 16:33:13 -05:00
Justin Richer
0d25d4cb17
null-preserving static parsers instead of constructors
2013-03-05 12:10:33 -05:00
Justin Richer
6a88c13675
split client view into two classes
2013-03-04 17:50:02 -05:00
Justin Richer
4095f2179c
added custom client view for API
2013-03-04 17:33:18 -05:00
Justin Richer
9aebca2e97
fixed gson parser in client API
2013-03-04 16:38:11 -05:00
Justin Richer
23efdf9f51
fix viewbean name, nullsafe client creation time, fixed default scope handling
2013-03-04 16:12:06 -05:00
Justin Richer
26f03ec070
timestamp for creation date
2013-03-04 16:11:20 -05:00
Justin Richer
235a3bf2c4
added client information response view
2013-03-04 15:45:35 -05:00
Justin Richer
a2d6894f62
started serialization for client information view
2013-03-04 15:13:55 -05:00
Justin Richer
db24c203ec
added parser to client registration endpoint
2013-03-04 15:01:02 -05:00
Justin Richer
5c044b9eff
added extra client fields to DB model, moved services to use new client model object
2013-03-04 14:22:42 -05:00
Justin Richer
bd877dde82
added signature checking to request objects
2013-03-01 17:44:44 -05:00
Justin Richer
6c1e6b2d74
refactored signing and validation, added jwk-based cache, removed keyfetcher, refactored client side class structure
2013-03-01 17:44:44 -05:00
Justin Richer
385853fa1f
refactored signing and validation, added jwk-based cache, removed keyfetcher, refactored client side class structure
2013-03-01 17:44:44 -05:00
Justin Richer
13a3e97113
updated request object forwarding hack
2013-03-01 17:42:48 -05:00
Amanda Anganes
60b679e942
First steps towards adding display variables to config bean
2013-02-22 17:10:14 -05:00
Justin Richer
4d725b88dd
more updates to track nimbus-jose-jwt classes and use them properly
2013-02-22 12:08:01 -05:00
Justin Richer
9a98d241e8
updates to track Nimbus JOSE API changes to audience and date fields
2013-02-22 12:08:01 -05:00
Justin Richer
03e7337b9f
client registration endpoint needs general rewrite to fit new spec.
...
Most of the problematic references will change with the rewrite, so this is a slapdash patch to make things compile for now.
2013-02-22 12:08:01 -05:00
Justin Richer
25b9940a68
request object endpoint is a placeholder, cleaning out for now
2013-02-22 12:08:01 -05:00
Justin Richer
e5732da857
added system default signing algorithm, converted token provider and enhancer to use nimbus-jose
2013-02-22 12:08:01 -05:00
Justin Richer
c01e873019
request object processor moved to nimbus-jose
2013-02-22 12:08:01 -05:00
Justin Richer
0f99e0e06d
assertion token granter moved to nimbus-jose
2013-02-22 12:08:01 -05:00
Justin Richer
10ab55a7e2
moved jwk/x509 publishing over to nimbus-jose (mostly)
2013-02-22 12:08:01 -05:00
Justin Richer
a078f7d202
patched userinfo view to use nimbus
2013-02-22 12:08:01 -05:00
Justin Richer
c7d1b47b38
converted bearer assertion framework to nimbus-jose
2013-02-22 12:08:01 -05:00
Justin Richer
910a6cf1a0
remvoed idtoken repository that was never used
2013-02-22 12:08:01 -05:00
Justin Richer
d0fdf8140e
sorting on approval page
2013-02-05 15:47:32 -05:00
Justin Richer
02846c0a8d
typo fix, DB constraints
2013-02-05 14:40:06 -05:00
Justin Richer
e622202e9e
display scopes based on request, pull scope information dynamically, addresses #208
2013-02-05 11:36:59 -05:00
Justin Richer
eb4773ce46
beginning dynamic scopes on auth page
2013-02-05 11:28:39 -05:00
Justin Richer
c2b9fd4db1
system scope ordering consistency
2013-02-05 11:11:41 -05:00
Justin Richer
801a45cc49
several bugfixes to scopes UI, works now
2013-02-03 22:04:56 -05:00
Justin Richer
a3037a18a7
system scope service applied to client creation UI
2013-02-03 22:04:55 -05:00
Justin Richer
cab36a2b80
added appropriate filterered and transformative actions to scope service
2013-02-03 22:04:55 -05:00
Justin Richer
ab35186696
added scope service, repository, and API
2013-02-03 22:02:24 -05:00
Justin Richer
a2e548c261
fixed claims processor for request object from user info endpoint
2013-02-03 22:02:23 -05:00
Justin Richer
3c190e044a
inject parsed parameters to make SECOAUTH happy
2013-02-03 22:02:23 -05:00
Justin Richer
1144d511af
inject scopes
2013-02-03 22:02:23 -05:00
Justin Richer
f9d50db1f1
don't treat openid scope special here -- by default client gets access to *all* scopes it's registered for
2013-02-03 22:02:23 -05:00
Justin Richer
078342715b
moved request object to request manager
2013-02-03 22:02:22 -05:00
Amanda Anganes
3399eed45a
Added about, contact, and stats pages. Still largely placeholders, but the topbar works correctly now at least.
2013-01-31 11:34:07 -05:00
Justin Richer
0be254c99a
updated token introspection output to match spec and client filter
2013-01-30 15:31:32 -05:00
Justin Richer
c1d33bb55b
bugfix in assertion processor
2013-01-30 14:34:16 -05:00
Amanda Anganes
2e2c0e8e6c
Fixed bug in nonce processing
2013-01-29 13:07:41 -05:00
Amanda Anganes
3db74100a4
working on bug
2013-01-29 13:07:41 -05:00
Amanda Anganes
dd8b48e863
Reset ConnectAuthorizationRequestManager to version from master
2013-01-29 13:07:41 -05:00
Amanda Anganes
06f970e61b
Trying to fix nonce service
2013-01-29 13:07:41 -05:00
Amanda Anganes
86bf51f0a7
Added java reflection code for request object handling, needs to be tested
2013-01-29 13:07:41 -05:00
Amanda Anganes
677f0f2d4c
Stubbed out required functionality for request object filtering
2013-01-29 13:07:41 -05:00
Amanda Anganes
67e8714671
Working on request object userinfo parsing
2013-01-29 13:07:41 -05:00
Justin Richer
7269700dc6
switched injector from repository to service
2013-01-24 19:32:55 -05:00
Justin Richer
f0ee36dad2
auth_type -> auth_method (addresses #258 )
2013-01-18 18:26:55 -05:00
Justin Richer
8831bc64a2
offline -> offline_access (addresses #248 )
2013-01-18 18:03:39 -05:00
Justin Richer
27a26e0a35
(user_id/prn) -> sub
2013-01-18 16:40:05 -05:00
Justin Richer
0ab4ad4bbe
added "birthdate", addresses #253
2013-01-18 15:38:41 -05:00
Justin Richer
6ef4dc817e
genericized nimbus code, added caching
2013-01-18 15:10:48 -05:00
Justin Richer
2d21a72e7e
switched to nimbus to check JWT signature
2013-01-18 15:10:48 -05:00
Justin Richer
60bda31c54
updated custom filter
2013-01-18 15:10:48 -05:00
Justin Richer
c17bc05b0e
wiring configuration
2013-01-18 15:10:48 -05:00
Justin Richer
4262be1fd3
added jwt processing to client auth provider
2013-01-18 15:06:00 -05:00
Justin Richer
abd64eccd6
added framework for processing assertions for client auth
2013-01-18 15:06:00 -05:00
Amanda Anganes
ad5e77f7ff
Made nonce storage duration configurable in application-context.xml;
2013-01-10 10:34:40 -05:00
Amanda Anganes
59f1b1f05e
Testing, nonce handling seems to be working now
2013-01-07 13:28:30 -05:00
Amanda Anganes
a1a117cfde
Added default constructor to ConnectAuthorizationRequestManager
2013-01-07 10:54:33 -05:00
Amanda Anganes
77b932f5a7
Added implementation of AuthorizationRequestManager. Nonce checking will go in here
2013-01-04 15:30:24 -05:00
Amanda Anganes
1af6513499
Removed nonce checking from token service impl
2013-01-04 15:30:24 -05:00
Amanda Anganes
246ed962bb
Added stub of repository test
2013-01-04 15:30:24 -05:00
Amanda Anganes
e1dffb959c
Added NonceReuseException
2013-01-04 15:30:24 -05:00
Amanda Anganes
a4637ec395
Fleshed out nonce service classes, added code to token service impl to check for and store nonces. Added JodaTime library for working with dates.
2013-01-04 15:30:24 -05:00
Amanda Anganes
c7ae315e98
Added initial files for nonce service. Repository and service impls are stubs
2013-01-04 15:30:24 -05:00
Justin Richer
87788f0710
let users visit home page without logging in
2012-12-18 13:56:46 -05:00
Justin Richer
f265347311
tweaked error messages
2012-12-18 12:08:36 -05:00
Justin Richer
18ddd8333f
added flag to allow introspection, relaxed same-client restrictions on introspection and chained tokens
2012-12-18 11:07:24 -05:00
Justin Richer
1f53f41648
generic entity view now takes optional HttpStatus argument
2012-12-14 17:35:21 -05:00
Justin Richer
a3790f943e
cleaned up introspection endpoint to use exceptions
2012-12-14 17:35:20 -05:00
Justin Richer
e5206f2b92
implemented jwt assertions for id tokens
2012-12-14 17:35:20 -05:00
Justin Richer
51b67ebc03
added queries to get access token from id token
2012-12-14 17:35:20 -05:00
Justin Richer
1853bd7117
added assertion token granter
2012-12-14 17:35:20 -05:00
Justin Richer
cda6163d0d
null and blank handling
2012-12-12 12:29:14 -05:00
Justin Richer
06fad3a41c
moved view for client API
2012-12-11 15:19:11 -05:00
Justin Richer
6344a72519
missed a few applicationName references, fixed API JSON rendering
2012-12-11 15:16:18 -05:00
Justin Richer
dfd8e9c7c7
removed unused view
2012-12-11 15:15:52 -05:00
Justin Richer
179903b074
propagated client changes to service
2012-12-11 12:31:01 -05:00
Justin Richer
33ceedb283
added scope and grant_type, switched to timeunit
2012-12-11 12:11:09 -05:00
Justin Richer
e2bc15c2b2
beginning of client registration refactor to track IETF dynreg spec
2012-12-10 17:36:33 -05:00
Justin Richer
94c37f5815
added redelegate scope to client list, fixed inconsistency with refresh token issuance (addresses #239 )
2012-12-10 16:53:05 -05:00
Justin Richer
510ddb48b7
override the correct part of the token granter class
2012-12-10 15:54:37 -05:00
Justin Richer
bdcc6af096
temporary sanity check for client ID's
2012-12-10 11:40:03 -05:00
Justin Richer
cab0839430
added workarounds for quirks in SECOAUTH
2012-12-10 11:27:28 -05:00
Justin Richer
edc96d646c
added chained token grant
2012-12-10 10:48:38 -05:00
Justin Richer
54708fb0ac
fixed id token scopes (shouldn't inherit from parent token)
2012-12-10 10:11:02 -05:00
Justin Richer
e38b2b0ba5
shortened revocation endpoint url
2012-12-07 17:16:03 -05:00
Justin Richer
fbc3c46128
Introspection now draft spec compliant, requires client auth
...
Currently this is the client that originally sent the token, we want to have a way to bind other "clients" to this token as well, like resource services. Also want to let open calls, sometimes.
2012-12-07 17:12:13 -05:00
Justin Richer
544e3d7b43
added copy constructors because Dave likes to use unmodifiable sets for no apparent reason
2012-12-07 10:06:10 -05:00
Justin Richer
7561ac9e8c
client dynamic registration now protected by access token, addresses #199
2012-12-06 17:48:23 -05:00
Justin Richer
7342da6a51
completed making id tokens into access tokens
2012-12-06 16:24:04 -05:00
Justin Richer
e4f9fa2bbf
labeled introspection endpoint
2012-12-06 16:19:25 -05:00
Justin Richer
17374a57e0
added ISO date format to generic entity view, addresses #232
2012-12-06 16:15:14 -05:00
Justin Richer
b8f701d9d8
switched id tokens to entities, they're now access tokens also
...
still needs some work to get the auth object right, for now we're just copying from the access token
2012-12-06 10:19:21 -05:00
Justin Richer
e305d3b16b
Making stable in-memory and in-file database with HSQL
2012-12-03 17:53:25 -05:00
Justin Richer
d07f67bd76
let user select when grants time out
2012-11-26 14:26:07 -05:00
Justin Richer
84401531ae
tie refresh token generation to "offline" scope tag
2012-11-26 13:16:19 -05:00
Justin Richer
667c3abc8a
dynamic scope display/selection on approval page
2012-11-26 11:53:19 -05:00
Justin Richer
1281d75aa9
stopped re-parsing scopes
2012-11-26 11:53:19 -05:00
Justin Richer
9c3a40779b
updated to SECOAUTH's horrible new object-breaking authorization request paradigm.
...
Bonus: it works!
2012-11-26 11:53:19 -05:00
Justin Richer
3e327b9df6
reverted to original controller behavior
2012-11-26 11:53:19 -05:00
Justin Richer
45ca4e565e
updated to SECOAUTH-1.0.1-BUILD-SNAPSHOT
2012-11-26 11:53:19 -05:00
Amanda Anganes
cf1ddf0457
Determined that init binder was not needed to fix default for Boolean require_auth_time; instead use defaultValue=\"true\" in the RequestParam declaration. Also fixed bug in ClientDetails service so that it will not blow up if the client has no redirect uris registered
2012-11-21 15:39:07 -05:00
Amanda Anganes
2084639828
Working on init binder for ClientDynamicRegistrationEndpoint
2012-11-21 14:54:24 -05:00
Amanda Anganes
8b0c520534
Issue 213, writing init binder to convert null Boolean values to false before calling setters
2012-11-21 14:53:41 -05:00
Justin Richer
a2a29e7b76
trying out new confirmation controller
2012-11-21 10:00:35 -05:00
Justin Richer
d9b6918bc2
softened error from scope checker -- returns false now, allows things to pass through
2012-11-20 14:08:18 -05:00
Justin Richer
9c08944a02
Changed arity on approved sites (now can have many per user/site combo)
2012-11-20 14:07:55 -05:00
Justin Richer
fda86e23e9
moved everything to use the consumes/produces framework of Spring 3.1
2012-11-20 13:12:21 -05:00
Justin Richer
5b0c17c5de
added in checks to blacklist service upon client registration and update
2012-11-19 14:10:55 -05:00
Justin Richer
e9d1ed270d
service layer cleanups
2012-11-19 13:46:09 -05:00
Justin Richer
757e21a722
added blacklist API
2012-11-16 11:57:46 -05:00
Justin Richer
33f11cb98f
cleanly applied pushstate changes, new URL structure
2012-11-13 13:10:34 -05:00
Amanda Anganes
51073a7f8d
Refactor part 3
2012-09-18 15:01:05 -04:00
Amanda Anganes
ef80676dc1
Cleaned up web package a bit - lots of unused imports and variables
2012-09-18 14:39:07 -04:00
Amanda Anganes
dd2abd94d1
Refactoring part 2
2012-09-18 14:36:27 -04:00
Amanda Anganes
c40efda6b5
Refactor part 1
2012-09-18 14:24:34 -04:00
Justin Richer
a9d1799eda
added getter/setter to UIE schema-to-view map
2012-09-11 12:44:47 -04:00
Justin Richer
920b2a59ba
Fixed error logging
2012-09-10 17:17:03 -04:00
Justin Richer
2d24435365
Created custom resolver, handler mapper
...
moved endpoint back to server
2012-09-10 17:17:03 -04:00
Justin Richer
7eb0a6f3d2
Moved JWK to commons
2012-09-10 17:17:03 -04:00
Amanda Anganes
f3c225d8f2
Updated SECOAUTH reference, made required alterations to our configuration
2012-09-07 16:08:15 -04:00
Amanda Anganes
61b828e182
Fixed bug - removed service layer @Transactional annotations, which negated need for flush at repository level; moved @Transactional annotations.
2012-09-04 17:53:02 -04:00
Justin Richer
ee7a5fd2e1
added registration URL to discovery endpoint
2012-08-30 17:18:36 -04:00
Justin Richer
11b35267b4
Refactored stats processor into a service, made home page into a smart page.
2012-08-28 17:42:43 -04:00
Justin Richer
bc0ee4cbab
force id consistency
2012-08-28 15:28:55 -04:00
Justin Richer
8876217baf
Added cleanups to client service
2012-08-28 15:28:55 -04:00
Justin Richer
d041ddb0e1
Added approvedSite API and support structure
2012-08-28 15:28:55 -04:00
Justin Richer
2bf5cfc041
service bug fix
2012-08-28 15:28:55 -04:00
Justin Richer
b462d6dd96
added empty http code view
2012-08-28 15:28:55 -04:00
Justin Richer
8ae1b376fe
updated whitelist service and repository
2012-08-28 15:28:55 -04:00
Justin Richer
6a180acf3c
added preliminary whitelist api
2012-08-28 15:28:55 -04:00
Justin Richer
4af3dd89be
cleaned up client api
2012-08-28 12:29:59 -04:00
Justin Richer
72c125ba64
refactored binder into two parts
2012-08-28 12:29:33 -04:00
Justin Richer
be54696603
Generic GSON entity printer
2012-08-28 12:29:10 -04:00
Justin Richer
0b1bb4f8aa
call the right service api
2012-08-27 16:57:52 -04:00
Justin Richer
407c14d0dc
added missing bean annotation
2012-08-27 16:52:00 -04:00
Justin Richer
a674589db0
added client editing capability
2012-08-27 16:46:45 -04:00
Justin Richer
a45c8bf96d
upped default client secret strength
2012-08-27 16:46:25 -04:00
Justin Richer
e39dcb63dd
added views, fixed registration for SECOAUTH required parameter
2012-08-27 16:25:43 -04:00
Justin Richer
83873f8ae2
added defaults for SECOAUTH
2012-08-27 16:09:01 -04:00
Justin Richer
9f84126cb8
more dynamic registration
2012-08-27 16:00:47 -04:00
Justin Richer
aeb6644d38
exploded version of attribute binding/processing
2012-08-27 14:47:04 -04:00
Justin Richer
e4470c9361
mapped the invalid scope exception, addresses #102
...
Still can't access userinfo if you're not using OAuth2
2012-08-27 13:28:54 -04:00
Justin Richer
259e84c871
put null check into interceptor, addresses #183
2012-08-27 11:55:06 -04:00
Justin Richer
37d6d63772
inject userinfo into context for use in JSPs
...
addresses #99 (for real this time)
2012-08-23 18:23:52 -04:00
Justin Richer
b5ce8d5e8b
added getByUsername to userinfo repositories and supporting classes, updated calling classes to use this
...
fixed namedquery
2012-08-23 18:23:47 -04:00
Amanda Anganes
ba5572b28a
Tidied up a bit, added javadoc comments to new classes
2012-08-23 11:05:10 -04:00
Amanda Anganes
c23b176567
Database backed authorization-code-service now works.
2012-08-23 10:46:08 -04:00
Amanda Anganes
4b76cc514b
Added a database-backed authorization-code system. Untested; needs to be injected into configuration in the place of the in-memory one and tested
2012-08-22 16:54:00 -04:00
Justin Richer
bdfdbbadbc
stats summary, addresses #62
2012-08-21 12:20:05 -04:00
Justin Richer
05fa7b148c
added checks for generated client secret
2012-08-20 12:23:02 -04:00
Justin Richer
a02f37cec3
added generators to client service API
2012-08-20 12:22:18 -04:00
Justin Richer
8520fcbf72
removed deprecated granted authority reference
2012-08-17 14:40:13 -04:00
Justin Richer
a65504c0cb
added new exception for userinfo, addresses #133
2012-08-15 16:02:06 -04:00
Justin Richer
209fc2d249
refactored request object endpoint to avoid urlspace conflict with SECOAUTH
2012-08-15 12:06:37 -04:00
Mike Derryberry
d1218efb2a
cleaned up imports
2012-08-14 10:55:08 -04:00
Mike Derryberry
55e7a4d707
moved request object auth endpoint in project setup
2012-08-14 10:55:08 -04:00
Mike Derryberry
ec286b9644
removed auth bean from application-context. Added extra parameter checks in request object auth endpoint
2012-08-14 10:55:08 -04:00
Mike Derryberry
04d8faa90a
updated autowired annotation
2012-08-14 10:55:08 -04:00
Mike Derryberry
20a7ebc576
autowired all member variables in request object auth endpoint
2012-08-14 10:55:08 -04:00
Mike Derryberry
694074ee58
moved endpoint, added param processing
2012-08-14 10:55:08 -04:00
Mike Derryberry
36b9c805d9
added reference to abstract endpoint class to get token granter
2012-08-14 10:55:08 -04:00
Mike Derryberry
2bdbb283b7
removed dependency on abstract endpoint class. added methods needed to authRequestObjectEndpoint (afterPropertiesSet())
2012-08-14 10:55:08 -04:00
Mike Derryberry
51ec529861
readded implementation of initializingBean
2012-08-14 10:55:08 -04:00
Mike Derryberry
638ebf2010
cleaned up AuthRequestObjectEndpoint class
2012-08-14 10:55:08 -04:00
Mike Derryberry
d93f5f18e5
added state value to jwt that gets passed as request object. certain methods from SECOAUTH use this
2012-08-14 10:55:08 -04:00
Mike Derryberry
3486ea28f1
updated mimicked methods to not use jwt, but rather a jwt in an auth request
2012-08-14 10:55:08 -04:00
Mike Derryberry
1a20dcbc6e
added methods that mimic behavior of private SECOATH methods
2012-08-14 10:55:08 -04:00
Mike Derryberry
d5caa0b543
changed server endpoint to act like an endpoint. WIP to accept request objects, validate, and redirect
2012-08-14 10:55:08 -04:00
Mike Derryberry
7d6211afd7
cleaned up some imports, added serverEndpointRequest class
2012-08-14 10:55:08 -04:00
Mike Derryberry
28344a3c91
auth endpoint got into client code. removed
2012-08-14 10:55:08 -04:00
Mike Derryberry
2888c08083
changed cookie claim to include the response
2012-08-14 10:55:07 -04:00
Justin Richer
484abc4915
fixed client delete
2012-08-10 17:24:21 -04:00
Justin Richer
155974d8e3
moved services and api over to using new client Id field (instead of client_id)
2012-08-10 16:53:31 -04:00
Justin Richer
eb5a24690f
added method to get client by its (new) Long id
2012-08-10 16:29:16 -04:00
Justin Richer
bb7d6b2e94
split scopes table
2012-08-10 14:26:47 -04:00
Amanda Anganes
170036e0b8
Added expiration to id tokens
2012-08-09 12:44:22 -04:00
Amanda Anganes
49cb8bd0cb
fixing bugs; needed to make all ids BIGINT AUTO-INCREMENT PRIMARY KEY in sql files
2012-08-09 12:44:21 -04:00
Amanda Anganes
d7deda1699
Propogated AuthenticationHolder effects; this is untested but compiles and I think it is mostly correct
2012-08-09 12:44:21 -04:00
Amanda Anganes
90df91c351
Added AuthenticationHolder object, got references squared away for AccessToken side. Compiles.
2012-08-09 12:44:21 -04:00
Amanda Anganes
cf348590b0
Removed unused ClientGeneratorFactory
2012-08-09 12:44:21 -04:00
Amanda Anganes
d6d80c3e60
Gave OAuth2RefreshTokenEntity a Long Id
2012-08-09 12:44:21 -04:00
Amanda Anganes
6b1dad7215
Gave OAuth2AccessTokenEntity a Long Id
2012-08-09 12:44:21 -04:00
Amanda Anganes
780839dbf9
Made things compile after ClientDetailsEntity refactoring
2012-08-09 12:44:21 -04:00
Justin Richer
09e528e113
added discovery info for x509 and client auth
2012-08-07 17:30:36 -04:00
Amanda Anganes
8d4e046408
All logging is now org.slf4j. We had a mix of org.slf4j and apache commons-logging. Added error logging to all view which throw errors.
2012-08-07 10:04:38 -04:00
Amanda Anganes
a061e64abf
Merge branch 'user-approval-handler-updated-rebase'
2012-08-06 16:30:03 -04:00
Amanda Anganes
32dc92119f
Cleanup completed, this works for the most part. TODO: need to make an upstream change in order to inject a new set of scopes into the AuthorizationRequest.
2012-08-06 16:29:22 -04:00
Amanda Anganes
5fb67ab7bb
Did a lot of cleanup; untested but compiles
2012-08-06 14:33:16 -04:00
Amanda Anganes
ae44bd5e0c
Works; about to do some cleanup
2012-08-06 13:40:27 -04:00
Amanda Anganes
2f28cf33e7
Changed UserInfo refs in WhitelistedSite to String ids; updated the user approval handler to check if "remember this decision" is checked and only make a new AP if so, and to pull in the scopes selected on the approval page as the saved allowed scopes for that AP.
2012-08-03 16:43:37 -04:00
Amanda Anganes
b87d54b06e
Changed UserInfo references to String "userId" references
2012-08-03 13:32:17 -04:00
Amanda Anganes
845976b8ac
First stages of getting the graylist portion to work. Currently no mechanism for telling the system NOT to remember your decision; that will come later. All approvals will be automatically stored with this code.
2012-08-03 12:49:40 -04:00
Justin Richer
9a7e40fee7
moved all bean definitions to annotations, removed orphaned CheckID view
2012-08-02 12:46:35 -04:00
Justin Richer
1508369548
now with Walsh-flavored certificate generation
2012-08-01 18:04:26 -04:00
Justin Richer
61a8d4a787
x509 take -- bouncycastley version
2012-08-01 17:19:33 -04:00
Amanda Anganes
db415bfa2b
Working on user approval handler
2012-07-31 14:50:24 -04:00
Amanda Anganes
a223565364
updating user approval handler
2012-07-31 14:50:24 -04:00
Amanda Anganes
4e10fce7ef
Implementing user approval handler; made some modifications to ApprovedSite and WhitelistedSite models, repositories, and service layers.
2012-07-31 14:50:24 -04:00
Amanda Anganes
7c33e19950
Changed authorization endpoint to /authorize rather than /auth; updated SWD entry. Also removed checkid entry from SWD.
2012-07-31 14:39:27 -04:00
Amanda Anganes
3982561a5b
Removing "throws exception" from views. Addresses issue #70
2012-07-31 12:28:46 -04:00
Justin Richer
1b5f99efec
added .json mapping to SWD
2012-07-31 10:42:42 -04:00
Amanda Anganes
02da9fceed
fixed imports
2012-07-31 09:16:05 -04:00
Justin Richer
d07667576e
cleaned up old code
2012-07-30 16:50:44 -04:00
Justin Richer
40f39a18e0
cleaning up introspection endpoint
2012-07-30 16:50:44 -04:00
Amanda Anganes
e7449901a6
Removed IdTokenGeneratorService. Addresses issue #75
2012-07-30 16:46:20 -04:00
Michael Jett
7a3ae5a757
Merge remote branch 'origin/master'
2012-07-10 17:00:30 -04:00
Michael Jett
30addb5439
Redirect URI now displayed on approval page.
2012-07-10 16:54:55 -04:00
Justin Richer
9f16f309bd
updated userinfouserdetailsservice to use username instead of userid -- this should actually be a wrapper class though
2012-07-10 16:44:29 -04:00
Justin Richer
b0a7ebd9b1
fixed JWK algorithm display
2012-07-10 14:57:12 -04:00
Justin Richer
5657bc8f28
updated configuration, confirmed works pending SECOAUTH-299
2012-07-09 11:25:45 -04:00
Amanda Anganes
01793ec57f
added preferred_username claim to userinfo endpoint
2012-07-06 16:02:11 -04:00
Amanda Anganes
50241e4da1
changed UserInfo.verified to UserInfo.emailVerified.
2012-07-06 14:11:43 -04:00
Justin Richer
dbd563f3f2
attempting to allow make use of SPEL
2012-07-05 18:21:52 -04:00
Justin Richer
f0c949fd09
added scope-based filter for userinfo
2012-07-05 17:14:51 -04:00
Justin Richer
5c1b07ae65
don't overwrite an existing JWT nonce
2012-06-28 17:04:21 -04:00
Justin Richer
de1597b214
refresh token handling fixed, removed token factory references
2012-06-28 16:55:11 -04:00
Amanda Anganes
4e3c99abe4
Merge branch 'validityIntegers'
2012-06-26 13:55:26 -04:00
Amanda Anganes
81d1af40bd
Updated our ClientDetailsEntity *TokenTimeout fields to be *ValiditySeconds, which are now typed as proper Integers in the SECOAUTH ClientDetails interface
2012-06-26 13:54:01 -04:00
Justin Richer
1127a7cfbc
refactored JWKs, updated signing servier to use them
2012-06-25 17:19:25 -04:00
Justin Richer
adb8499bee
merged derryberry code, plus tweaks, still WIP
2012-06-25 16:42:41 -04:00
Mike Derryberry
b94fbd7439
updated -common and -client code by removing throws exception, changing to rest templates, and updating test cases to use annotations
2012-06-20 09:36:55 -04:00
Justin Richer
fe3bbfb3d5
Further cleanups. Still missing:
...
- All tests extend TestCase, should use annotations instead
- Several elements throw Exception
- Key Fetchers should use RESTTemplates and be in a separate utility set
2012-06-15 17:11:58 -04:00
Justin Richer
b86abdd761
merge from pull request, plus cleanup
2012-06-15 15:36:14 -04:00
Justin Richer
731ad2e2e2
updated SECOAUTH reference, fixed some SQL files, temporarily closed token timeout issue
2012-06-15 12:05:08 -04:00
Justin Richer
ace5dd1f1e
imported userinfouserdetails filter from MITRE codebase
2012-06-13 16:33:55 -04:00
Mike Derryberry
65dc3daaf8
smart client
2012-06-12 16:09:01 -04:00
Amanda Anganes
bbf9591c92
Merge branch 'master' into issue52
...
Conflicts:
openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java
openid-connect-server/src/main/webapp/WEB-INF/spring-servlet.xml
openid-connect-server/src/main/webapp/WEB-INF/views/oauth/approve.jsp
2012-06-11 15:04:01 -04:00
Justin Richer
7a207dc162
Merge branch 'discoveryupdate'
2012-06-05 16:37:04 -04:00
Justin Richer
7df2663e00
added final slashification of configuration URLs
2012-06-05 16:36:11 -04:00
Justin Richer
fbdccdb78e
added Xrd support ( fixes #63 ), updated configuration locations ( fixes #47 )
2012-06-05 16:32:49 -04:00
Justin Richer
e44697cef9
updated JWK display to latest, closes #58
2012-06-05 16:07:19 -04:00
Justin Richer
5c72d8b95f
revocation endpoint cleanup, still needs views
2012-06-05 11:24:11 -04:00
Justin Richer
27219c066d
refactored our service to reflect upstream
2012-06-05 10:18:26 -04:00
Justin Richer
e95528a08d
added implementation to stub to read an access token by value
2012-06-05 10:11:24 -04:00
Amanda Anganes
424f8bb737
Refactored to use TokenEnhancer rather than a custom TokenGranter.
2012-05-30 16:14:00 -04:00
nemonik
8917e75010
see issue #19
2012-05-30 15:14:15 -04:00
Amanda Anganes
16aa0c59b5
Added token enhancer. Now to plug it in.
2012-05-30 12:31:12 -04:00
Amanda Anganes
2070d2e413
Updated to use AuthorizationRequestFactory rather than ClientCredentialsChecker.
2012-05-30 12:08:08 -04:00
Justin Richer
ce847dd4f7
updated poco user view to contain name
2012-05-24 15:57:34 -04:00
Stephen Moore
c418ccabb1
Merge branch 'master' into userInfoEndpoint
2012-05-24 13:06:29 -04:00
Stephen Moore
1bff5ef19f
Added POCO view, Added UnknownUserInfoScheamException runtime exception
2012-05-24 11:00:49 -04:00
Stephen Moore
5c544dfe7c
Merge branch 'master' into userInfoEndpoint
2012-05-23 13:43:32 -04:00
Justin Richer
7d4d65c359
Merge branch 'userinfo_integration'
2012-05-23 13:39:03 -04:00
Justin Richer
a8e9f1d2cd
fixed rendering issues with user info view
2012-05-23 13:36:53 -04:00
Stephen Moore
9612fde10e
Check for null address, and added email
2012-05-23 13:35:05 -04:00
Justin Richer
08958d4137
Merge remote-tracking branch 'remotes/steve/userInfoEndpoint' into userinfo_integration
2012-05-23 13:11:40 -04:00
Justin Richer
06fadb5f2b
oauth provider configuration started
2012-05-23 12:55:21 -04:00
Stephen Moore
9b03831d4e
Filled in the UserInfoEndpoint, and added the JSON view for userInfo (openIdSchema)
2012-05-22 16:56:22 -04:00
Michael Jett
e5312b4c99
Client secret now editable and dynamically generated if not present
2012-05-22 14:36:40 -04:00
Michael Jett
51fe98b383
ClientAPI now sets owner for clients
2012-05-18 14:23:19 -04:00
Michael Jett
2d980a4d8f
Refactoring of routing. Client updates
2012-05-17 16:33:22 -04:00
Michael Jett
b06640c921
First stages of client-side validation worked into application
2012-05-16 17:22:25 -04:00
Michael Jett
3402a3e463
ClientAPI now fully supports RESTful DELETE
2012-05-16 14:32:40 -04:00
Michael Jett
7f5b9e2c82
ClientAPI now supports DELETE method
2012-05-16 14:03:49 -04:00
Michael Jett
af6e043239
Client Entity now initialized with non-null values so JPA won't flip. Added unified method for saving. Sync'd class member names to allow proper binding.
2012-05-16 13:27:53 -04:00
Michael Jett
0c7ea88323
Client updates.
2012-05-15 17:03:17 -04:00
Michael Jett
0f9b828066
ClientAPI admin requirement now global
2012-05-15 14:10:12 -04:00
Michael Jett
32e67730d8
ClientAPI maps to individual clients by IDs
2012-05-15 13:41:27 -04:00
Michael Jett
6b481cd3bb
ClientAPI header updates
2012-05-15 13:09:16 -04:00
Michael Jett
a4fc4e939e
ClientAPI cleanup
2012-05-15 12:41:41 -04:00
Stephen Moore
fd91c884bb
Made interfaces... deleted a thing.
2012-05-10 17:45:10 -04:00
Amanda Anganes
e33f277bbe
Updated classes to track newest version of SECOAUTH. This update closes issues #3 , #4 , #8 , and #36 (infinite redirects). This revision changes the authorization and token endpoints to be /openidconnect/auth and /openidconnect/token, respectively.
2012-05-09 15:16:56 -04:00
Michael Jett
c8e3f70115
Now requiring homepage login
2012-05-08 14:09:24 -04:00
Michael Jett
7dd81ac2de
Server-side dynamics
2012-05-08 13:53:21 -04:00
Michael Jett
23fd7b1b21
Renaming Client View class
2012-05-08 11:20:40 -04:00
Michael Jett
eda7505b7b
Client API now renders JSON for all Clients
2012-05-08 11:16:45 -04:00
Justin Richer
97dffb6414
added copyright to all java files. closes #11
2012-04-27 17:55:58 -04:00
Justin Richer
6724866099
moved jwt components, utilities, and various interfaces to -common from -server
2012-04-27 15:20:49 -04:00
Justin Richer
59ecb03548
added getter/setter for userinforepository, closes #40
2012-04-27 15:11:25 -04:00
Amanda Anganes
6899a16c2f
Merge branch 'Really_fixing_redirects'
2012-04-16 12:39:06 -04:00
Justin Richer
05b2cf8fff
removed vestigial user details code
2012-04-16 12:02:24 -04:00
Amanda Anganes
f0f339d45f
current state
2012-04-16 11:05:36 -04:00
Amanda Anganes
2fc4ce177c
This commit fixes the infinite redirect, somewhat. See updated issue #8 .
2012-04-11 15:55:19 -04:00
Amanda Anganes
486b7723d3
Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server
2012-04-10 13:45:26 -04:00
Amanda Anganes
269a354f8c
Added tables.sql, which is just a concatenation of all the other sql files. Added redirect_uris.sql, which is a NEW table needed to support clients registering multiple redirect uris.
...
This updates us to the HEAD revision of SECOAUTH, where the redirect uri field on ClientDetails has been updated to be a Set<String> instead of a single string. I updated the UI code so that it will still work, but it will need to be updated to allow users to register multiple uris.
This also closes issue #2 from the issue tracker.
2012-04-10 13:44:10 -04:00
nemonik
d056079fea
Support for ECDSA JWT signer was removed as it would require the system-wide installation and configuration of the Bouncy Castle Security Provider in order for the server to work when deployed to Tomcat. See issue ticket #20
2012-04-10 13:41:18 -04:00
nemonik
6c8661f3ad
the signature base created in the verify method of the AbstractJwtSigner did not match how the Jwt.getSignatureBase creates the signature base. also, modified the testGenerateHmacSignature to exercise
2012-04-02 22:12:03 -04:00
nemonik
267f1b2de3
bas64 decoded signature prior to verifying, modified unit rsa unit test, and fixed ecdsa signer verify
2012-04-02 21:32:42 -04:00
Justin Richer
985a4619fa
abstracted keystore loader to new function
2012-04-02 15:06:58 -04:00
Justin Richer
3dfe6df410
refactored algorithms out to their own separate Enum
2012-04-02 13:13:13 -04:00
Justin Richer
fec6a3a876
removed definition parsers, may be picked up again later
2012-04-02 12:40:53 -04:00
Amanda Anganes
b986b30695
Fixed unit tests - they were broken due to an error in application-context.xml; not because of the refactor. App context was trying to instantiate an Hmac signer with name "HMACSHA256", which should have been "HS256". I updated the exceptions thrown by the signer impls so that if an Algorithm name mismatch occurs it will tell you what it is trying to match against.
2012-03-30 13:45:04 -04:00
nemonik
0a29eba617
unit test correction, slight refactor of tested classes
2012-03-29 14:02:51 -04:00
nemonik
f215cfc50c
fix for issue 5, code refactoring across signers
2012-03-29 12:34:51 -04:00
Amanda Anganes
c50f968748
Merged to use idToken.setNonce().
2012-03-23 11:11:38 -04:00
Amanda Anganes
268b82e31d
Merge branch 'Branch_master3-23-2012'
2012-03-23 11:09:27 -04:00
Amanda Anganes
8b10b83516
Added setNonce to JwtClaims.
2012-03-23 11:08:49 -04:00
Justin Richer
4a15e51e12
pass through nonce
2012-03-23 10:52:04 -04:00
Amanda Anganes
27fe3c9eca
Implemented signing. Works, but validation does not fail if you remove the signature.
2012-03-22 14:49:02 -04:00
Amanda Anganes
68c8d1a9d2
Changed parameter for check id endpoint to access_token instead of auth_token
2012-03-22 14:19:45 -04:00
Justin Richer
826be5a1a1
changed parameter name to match spec change
2012-03-22 14:10:50 -04:00
Justin Richer
5fe036878a
fixed view for idtoken in checkid endpoint
2012-03-22 14:09:25 -04:00
Justin Richer
c51bb72fe5
merged keystore changes
2012-03-22 13:50:47 -04:00
Justin Richer
6c01134095
JWK display support for key maps, still no key ids
2012-03-22 13:48:16 -04:00
Amanda Anganes
776748f908
Merge branch '3-22-2012'
2012-03-22 13:43:59 -04:00
Amanda Anganes
ae9b5e792a
Added a ConfigurationPropertiesBean.java to hold configuration properties. Fixed up CheckIDEndpoint.java a bit - it works, but is outputting the wrong thing.
2012-03-22 13:43:30 -04:00
Justin Richer
524a8e153e
signers turned into a map
2012-03-22 13:37:21 -04:00
Justin Richer
664dd1df46
JWT claims can now have nulls in them without barfing
2012-03-22 11:46:48 -04:00
Justin Richer
c59d3fe963
it spits out JWTs! and id tokens! JWT still needs to handle nulls
2012-03-21 17:59:48 -04:00
Amanda Anganes
ebe72412fe
Authorization Grant flow works up to serializing the returned Access Token. Justin is investigating serialization problems.
2012-03-21 16:44:16 -04:00
Amanda Anganes
d94eb338ee
Auth code flow works through user approval page. Current problem is that it doesn't seem to be matching up auth codes correctly (I keep getting "invalid code" error). But, it looks like it's going through our custom token granter so that is good.
2012-03-20 15:07:18 -04:00
Justin Richer
2f29cc52b2
Merge branch 'client_refactor'
2012-03-16 16:28:51 -04:00
Justin Richer
e6e7504213
added files and shuffled things to new packages
2012-03-16 15:46:23 -04:00
Justin Richer
a0cdd8bf2f
moved server to new package location
2012-03-16 15:01:53 -04:00