Commit Graph

932 Commits (e3392dd75932c77fa2f884e2d7d8b8bfb8646bfc)

Author SHA1 Message Date
Justin Richer 06fad3a41c moved view for client API 2012-12-11 15:19:11 -05:00
Justin Richer 6344a72519 missed a few applicationName references, fixed API JSON rendering 2012-12-11 15:16:18 -05:00
Justin Richer dfd8e9c7c7 removed unused view 2012-12-11 15:15:52 -05:00
Justin Richer 179903b074 propagated client changes to service 2012-12-11 12:31:01 -05:00
Justin Richer 33ceedb283 added scope and grant_type, switched to timeunit 2012-12-11 12:11:09 -05:00
Justin Richer e2bc15c2b2 beginning of client registration refactor to track IETF dynreg spec 2012-12-10 17:36:33 -05:00
Justin Richer 94c37f5815 added redelegate scope to client list, fixed inconsistency with refresh token issuance (addresses #239) 2012-12-10 16:53:05 -05:00
Justin Richer 510ddb48b7 override the correct part of the token granter class 2012-12-10 15:54:37 -05:00
Justin Richer bdcc6af096 temporary sanity check for client ID's 2012-12-10 11:40:03 -05:00
Justin Richer cab0839430 added workarounds for quirks in SECOAUTH 2012-12-10 11:27:28 -05:00
Justin Richer edc96d646c added chained token grant 2012-12-10 10:48:38 -05:00
Justin Richer 54708fb0ac fixed id token scopes (shouldn't inherit from parent token) 2012-12-10 10:11:02 -05:00
Justin Richer e38b2b0ba5 shortened revocation endpoint url 2012-12-07 17:16:03 -05:00
Justin Richer fbc3c46128 Introspection now draft spec compliant, requires client auth
Currently this is the client that originally sent the token, we want to have a way to bind other "clients" to this token as well, like resource services. Also want to let open calls, sometimes.
2012-12-07 17:12:13 -05:00
Justin Richer 544e3d7b43 added copy constructors because Dave likes to use unmodifiable sets for no apparent reason 2012-12-07 10:06:10 -05:00
Justin Richer 7561ac9e8c client dynamic registration now protected by access token, addresses #199 2012-12-06 17:48:23 -05:00
Justin Richer 7342da6a51 completed making id tokens into access tokens 2012-12-06 16:24:04 -05:00
Justin Richer e4f9fa2bbf labeled introspection endpoint 2012-12-06 16:19:25 -05:00
Justin Richer 17374a57e0 added ISO date format to generic entity view, addresses #232 2012-12-06 16:15:14 -05:00
Justin Richer b8f701d9d8 switched id tokens to entities, they're now access tokens also
still needs some work to get the auth object right, for now we're just copying from the access token
2012-12-06 10:19:21 -05:00
Justin Richer e305d3b16b Making stable in-memory and in-file database with HSQL 2012-12-03 17:53:25 -05:00
Justin Richer d07f67bd76 let user select when grants time out 2012-11-26 14:26:07 -05:00
Justin Richer 84401531ae tie refresh token generation to "offline" scope tag 2012-11-26 13:16:19 -05:00
Justin Richer 667c3abc8a dynamic scope display/selection on approval page 2012-11-26 11:53:19 -05:00
Justin Richer 1281d75aa9 stopped re-parsing scopes 2012-11-26 11:53:19 -05:00
Justin Richer 9c3a40779b updated to SECOAUTH's horrible new object-breaking authorization request paradigm.
Bonus: it works!
2012-11-26 11:53:19 -05:00
Justin Richer 3e327b9df6 reverted to original controller behavior 2012-11-26 11:53:19 -05:00
Justin Richer 45ca4e565e updated to SECOAUTH-1.0.1-BUILD-SNAPSHOT 2012-11-26 11:53:19 -05:00
Amanda Anganes cf1ddf0457 Determined that init binder was not needed to fix default for Boolean require_auth_time; instead use defaultValue=\"true\" in the RequestParam declaration. Also fixed bug in ClientDetails service so that it will not blow up if the client has no redirect uris registered 2012-11-21 15:39:07 -05:00
Amanda Anganes 2084639828 Working on init binder for ClientDynamicRegistrationEndpoint 2012-11-21 14:54:24 -05:00
Amanda Anganes 8b0c520534 Issue 213, writing init binder to convert null Boolean values to false before calling setters 2012-11-21 14:53:41 -05:00
Justin Richer a2a29e7b76 trying out new confirmation controller 2012-11-21 10:00:35 -05:00
Justin Richer d9b6918bc2 softened error from scope checker -- returns false now, allows things to pass through 2012-11-20 14:08:18 -05:00
Justin Richer 9c08944a02 Changed arity on approved sites (now can have many per user/site combo) 2012-11-20 14:07:55 -05:00
Justin Richer fda86e23e9 moved everything to use the consumes/produces framework of Spring 3.1 2012-11-20 13:12:21 -05:00
Justin Richer 5b0c17c5de added in checks to blacklist service upon client registration and update 2012-11-19 14:10:55 -05:00
Justin Richer e9d1ed270d service layer cleanups 2012-11-19 13:46:09 -05:00
Justin Richer 757e21a722 added blacklist API 2012-11-16 11:57:46 -05:00
Justin Richer 33f11cb98f cleanly applied pushstate changes, new URL structure 2012-11-13 13:10:34 -05:00
Amanda Anganes 51073a7f8d Refactor part 3 2012-09-18 15:01:05 -04:00
Amanda Anganes ef80676dc1 Cleaned up web package a bit - lots of unused imports and variables 2012-09-18 14:39:07 -04:00
Amanda Anganes dd2abd94d1 Refactoring part 2 2012-09-18 14:36:27 -04:00
Amanda Anganes c40efda6b5 Refactor part 1 2012-09-18 14:24:34 -04:00
Justin Richer a9d1799eda added getter/setter to UIE schema-to-view map 2012-09-11 12:44:47 -04:00
Justin Richer 920b2a59ba Fixed error logging 2012-09-10 17:17:03 -04:00
Justin Richer 2d24435365 Created custom resolver, handler mapper
moved endpoint back to server
2012-09-10 17:17:03 -04:00
Justin Richer 7eb0a6f3d2 Moved JWK to commons 2012-09-10 17:17:03 -04:00
Amanda Anganes f3c225d8f2 Updated SECOAUTH reference, made required alterations to our configuration 2012-09-07 16:08:15 -04:00
Amanda Anganes 61b828e182 Fixed bug - removed service layer @Transactional annotations, which negated need for flush at repository level; moved @Transactional annotations. 2012-09-04 17:53:02 -04:00
Justin Richer ee7a5fd2e1 added registration URL to discovery endpoint 2012-08-30 17:18:36 -04:00
Justin Richer 11b35267b4 Refactored stats processor into a service, made home page into a smart page. 2012-08-28 17:42:43 -04:00
Justin Richer bc0ee4cbab force id consistency 2012-08-28 15:28:55 -04:00
Justin Richer 8876217baf Added cleanups to client service 2012-08-28 15:28:55 -04:00
Justin Richer d041ddb0e1 Added approvedSite API and support structure 2012-08-28 15:28:55 -04:00
Justin Richer 2bf5cfc041 service bug fix 2012-08-28 15:28:55 -04:00
Justin Richer b462d6dd96 added empty http code view 2012-08-28 15:28:55 -04:00
Justin Richer 8ae1b376fe updated whitelist service and repository 2012-08-28 15:28:55 -04:00
Justin Richer 6a180acf3c added preliminary whitelist api 2012-08-28 15:28:55 -04:00
Justin Richer 4af3dd89be cleaned up client api 2012-08-28 12:29:59 -04:00
Justin Richer 72c125ba64 refactored binder into two parts 2012-08-28 12:29:33 -04:00
Justin Richer be54696603 Generic GSON entity printer 2012-08-28 12:29:10 -04:00
Justin Richer 0b1bb4f8aa call the right service api 2012-08-27 16:57:52 -04:00
Justin Richer 407c14d0dc added missing bean annotation 2012-08-27 16:52:00 -04:00
Justin Richer a674589db0 added client editing capability 2012-08-27 16:46:45 -04:00
Justin Richer a45c8bf96d upped default client secret strength 2012-08-27 16:46:25 -04:00
Justin Richer e39dcb63dd added views, fixed registration for SECOAUTH required parameter 2012-08-27 16:25:43 -04:00
Justin Richer 83873f8ae2 added defaults for SECOAUTH 2012-08-27 16:09:01 -04:00
Justin Richer 9f84126cb8 more dynamic registration 2012-08-27 16:00:47 -04:00
Justin Richer aeb6644d38 exploded version of attribute binding/processing 2012-08-27 14:47:04 -04:00
Justin Richer e4470c9361 mapped the invalid scope exception, addresses #102
Still can't access userinfo if you're not using OAuth2
2012-08-27 13:28:54 -04:00
Justin Richer 259e84c871 put null check into interceptor, addresses #183 2012-08-27 11:55:06 -04:00
Justin Richer 37d6d63772 inject userinfo into context for use in JSPs
addresses #99 (for real this time)
2012-08-23 18:23:52 -04:00
Justin Richer b5ce8d5e8b added getByUsername to userinfo repositories and supporting classes, updated calling classes to use this
fixed namedquery
2012-08-23 18:23:47 -04:00
Amanda Anganes ba5572b28a Tidied up a bit, added javadoc comments to new classes 2012-08-23 11:05:10 -04:00
Amanda Anganes c23b176567 Database backed authorization-code-service now works. 2012-08-23 10:46:08 -04:00
Amanda Anganes 4b76cc514b Added a database-backed authorization-code system. Untested; needs to be injected into configuration in the place of the in-memory one and tested 2012-08-22 16:54:00 -04:00
Justin Richer bdfdbbadbc stats summary, addresses #62 2012-08-21 12:20:05 -04:00
Justin Richer 05fa7b148c added checks for generated client secret 2012-08-20 12:23:02 -04:00
Justin Richer a02f37cec3 added generators to client service API 2012-08-20 12:22:18 -04:00
Justin Richer 8520fcbf72 removed deprecated granted authority reference 2012-08-17 14:40:13 -04:00
Justin Richer a65504c0cb added new exception for userinfo, addresses #133 2012-08-15 16:02:06 -04:00
Justin Richer 209fc2d249 refactored request object endpoint to avoid urlspace conflict with SECOAUTH 2012-08-15 12:06:37 -04:00
Mike Derryberry d1218efb2a cleaned up imports 2012-08-14 10:55:08 -04:00
Mike Derryberry 55e7a4d707 moved request object auth endpoint in project setup 2012-08-14 10:55:08 -04:00
Mike Derryberry ec286b9644 removed auth bean from application-context. Added extra parameter checks in request object auth endpoint 2012-08-14 10:55:08 -04:00
Mike Derryberry 04d8faa90a updated autowired annotation 2012-08-14 10:55:08 -04:00
Mike Derryberry 20a7ebc576 autowired all member variables in request object auth endpoint 2012-08-14 10:55:08 -04:00
Mike Derryberry 694074ee58 moved endpoint, added param processing 2012-08-14 10:55:08 -04:00
Mike Derryberry 36b9c805d9 added reference to abstract endpoint class to get token granter 2012-08-14 10:55:08 -04:00
Mike Derryberry 2bdbb283b7 removed dependency on abstract endpoint class. added methods needed to authRequestObjectEndpoint (afterPropertiesSet()) 2012-08-14 10:55:08 -04:00
Mike Derryberry 51ec529861 readded implementation of initializingBean 2012-08-14 10:55:08 -04:00
Mike Derryberry 638ebf2010 cleaned up AuthRequestObjectEndpoint class 2012-08-14 10:55:08 -04:00
Mike Derryberry d93f5f18e5 added state value to jwt that gets passed as request object. certain methods from SECOAUTH use this 2012-08-14 10:55:08 -04:00
Mike Derryberry 3486ea28f1 updated mimicked methods to not use jwt, but rather a jwt in an auth request 2012-08-14 10:55:08 -04:00
Mike Derryberry 1a20dcbc6e added methods that mimic behavior of private SECOATH methods 2012-08-14 10:55:08 -04:00
Mike Derryberry d5caa0b543 changed server endpoint to act like an endpoint. WIP to accept request objects, validate, and redirect 2012-08-14 10:55:08 -04:00
Mike Derryberry 7d6211afd7 cleaned up some imports, added serverEndpointRequest class 2012-08-14 10:55:08 -04:00
Mike Derryberry 28344a3c91 auth endpoint got into client code. removed 2012-08-14 10:55:08 -04:00
Mike Derryberry 2888c08083 changed cookie claim to include the response 2012-08-14 10:55:07 -04:00
Justin Richer 484abc4915 fixed client delete 2012-08-10 17:24:21 -04:00
Justin Richer 155974d8e3 moved services and api over to using new client Id field (instead of client_id) 2012-08-10 16:53:31 -04:00
Justin Richer eb5a24690f added method to get client by its (new) Long id 2012-08-10 16:29:16 -04:00
Justin Richer bb7d6b2e94 split scopes table 2012-08-10 14:26:47 -04:00
Amanda Anganes 170036e0b8 Added expiration to id tokens 2012-08-09 12:44:22 -04:00
Amanda Anganes 49cb8bd0cb fixing bugs; needed to make all ids BIGINT AUTO-INCREMENT PRIMARY KEY in sql files 2012-08-09 12:44:21 -04:00
Amanda Anganes d7deda1699 Propogated AuthenticationHolder effects; this is untested but compiles and I think it is mostly correct 2012-08-09 12:44:21 -04:00
Amanda Anganes 90df91c351 Added AuthenticationHolder object, got references squared away for AccessToken side. Compiles. 2012-08-09 12:44:21 -04:00
Amanda Anganes cf348590b0 Removed unused ClientGeneratorFactory 2012-08-09 12:44:21 -04:00
Amanda Anganes d6d80c3e60 Gave OAuth2RefreshTokenEntity a Long Id 2012-08-09 12:44:21 -04:00
Amanda Anganes 6b1dad7215 Gave OAuth2AccessTokenEntity a Long Id 2012-08-09 12:44:21 -04:00
Amanda Anganes 780839dbf9 Made things compile after ClientDetailsEntity refactoring 2012-08-09 12:44:21 -04:00
Justin Richer 09e528e113 added discovery info for x509 and client auth 2012-08-07 17:30:36 -04:00
Amanda Anganes 8d4e046408 All logging is now org.slf4j. We had a mix of org.slf4j and apache commons-logging. Added error logging to all view which throw errors. 2012-08-07 10:04:38 -04:00
Amanda Anganes a061e64abf Merge branch 'user-approval-handler-updated-rebase' 2012-08-06 16:30:03 -04:00
Amanda Anganes 32dc92119f Cleanup completed, this works for the most part. TODO: need to make an upstream change in order to inject a new set of scopes into the AuthorizationRequest. 2012-08-06 16:29:22 -04:00
Amanda Anganes 5fb67ab7bb Did a lot of cleanup; untested but compiles 2012-08-06 14:33:16 -04:00
Amanda Anganes ae44bd5e0c Works; about to do some cleanup 2012-08-06 13:40:27 -04:00
Amanda Anganes 2f28cf33e7 Changed UserInfo refs in WhitelistedSite to String ids; updated the user approval handler to check if "remember this decision" is checked and only make a new AP if so, and to pull in the scopes selected on the approval page as the saved allowed scopes for that AP. 2012-08-03 16:43:37 -04:00
Amanda Anganes b87d54b06e Changed UserInfo references to String "userId" references 2012-08-03 13:32:17 -04:00
Amanda Anganes 845976b8ac First stages of getting the graylist portion to work. Currently no mechanism for telling the system NOT to remember your decision; that will come later. All approvals will be automatically stored with this code. 2012-08-03 12:49:40 -04:00
Justin Richer 9a7e40fee7 moved all bean definitions to annotations, removed orphaned CheckID view 2012-08-02 12:46:35 -04:00
Justin Richer 1508369548 now with Walsh-flavored certificate generation 2012-08-01 18:04:26 -04:00
Justin Richer 61a8d4a787 x509 take -- bouncycastley version 2012-08-01 17:19:33 -04:00
Amanda Anganes db415bfa2b Working on user approval handler 2012-07-31 14:50:24 -04:00
Amanda Anganes a223565364 updating user approval handler 2012-07-31 14:50:24 -04:00
Amanda Anganes 4e10fce7ef Implementing user approval handler; made some modifications to ApprovedSite and WhitelistedSite models, repositories, and service layers. 2012-07-31 14:50:24 -04:00
Amanda Anganes 7c33e19950 Changed authorization endpoint to /authorize rather than /auth; updated SWD entry. Also removed checkid entry from SWD. 2012-07-31 14:39:27 -04:00
Amanda Anganes 3982561a5b Removing "throws exception" from views. Addresses issue #70 2012-07-31 12:28:46 -04:00
Justin Richer 1b5f99efec added .json mapping to SWD 2012-07-31 10:42:42 -04:00
Amanda Anganes 02da9fceed fixed imports 2012-07-31 09:16:05 -04:00
Justin Richer d07667576e cleaned up old code 2012-07-30 16:50:44 -04:00
Justin Richer 40f39a18e0 cleaning up introspection endpoint 2012-07-30 16:50:44 -04:00
Amanda Anganes e7449901a6 Removed IdTokenGeneratorService. Addresses issue #75 2012-07-30 16:46:20 -04:00
Michael Jett 7a3ae5a757 Merge remote branch 'origin/master' 2012-07-10 17:00:30 -04:00
Michael Jett 30addb5439 Redirect URI now displayed on approval page. 2012-07-10 16:54:55 -04:00
Justin Richer 9f16f309bd updated userinfouserdetailsservice to use username instead of userid -- this should actually be a wrapper class though 2012-07-10 16:44:29 -04:00
Justin Richer b0a7ebd9b1 fixed JWK algorithm display 2012-07-10 14:57:12 -04:00
Justin Richer 5657bc8f28 updated configuration, confirmed works pending SECOAUTH-299 2012-07-09 11:25:45 -04:00
Amanda Anganes 01793ec57f added preferred_username claim to userinfo endpoint 2012-07-06 16:02:11 -04:00
Amanda Anganes 50241e4da1 changed UserInfo.verified to UserInfo.emailVerified. 2012-07-06 14:11:43 -04:00
Justin Richer dbd563f3f2 attempting to allow make use of SPEL 2012-07-05 18:21:52 -04:00
Justin Richer f0c949fd09 added scope-based filter for userinfo 2012-07-05 17:14:51 -04:00
Justin Richer 5c1b07ae65 don't overwrite an existing JWT nonce 2012-06-28 17:04:21 -04:00
Justin Richer de1597b214 refresh token handling fixed, removed token factory references 2012-06-28 16:55:11 -04:00
Amanda Anganes 4e3c99abe4 Merge branch 'validityIntegers' 2012-06-26 13:55:26 -04:00
Amanda Anganes 81d1af40bd Updated our ClientDetailsEntity *TokenTimeout fields to be *ValiditySeconds, which are now typed as proper Integers in the SECOAUTH ClientDetails interface 2012-06-26 13:54:01 -04:00
Justin Richer 1127a7cfbc refactored JWKs, updated signing servier to use them 2012-06-25 17:19:25 -04:00
Justin Richer adb8499bee merged derryberry code, plus tweaks, still WIP 2012-06-25 16:42:41 -04:00
Mike Derryberry b94fbd7439 updated -common and -client code by removing throws exception, changing to rest templates, and updating test cases to use annotations 2012-06-20 09:36:55 -04:00
Justin Richer fe3bbfb3d5 Further cleanups. Still missing:
- All tests extend TestCase, should use annotations instead
- Several elements throw Exception
- Key Fetchers should use RESTTemplates and be in a separate utility set
2012-06-15 17:11:58 -04:00
Justin Richer b86abdd761 merge from pull request, plus cleanup 2012-06-15 15:36:14 -04:00
Justin Richer 731ad2e2e2 updated SECOAUTH reference, fixed some SQL files, temporarily closed token timeout issue 2012-06-15 12:05:08 -04:00
Justin Richer ace5dd1f1e imported userinfouserdetails filter from MITRE codebase 2012-06-13 16:33:55 -04:00
Mike Derryberry 65dc3daaf8 smart client 2012-06-12 16:09:01 -04:00
Amanda Anganes bbf9591c92 Merge branch 'master' into issue52
Conflicts:
	openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java
	openid-connect-server/src/main/webapp/WEB-INF/spring-servlet.xml
	openid-connect-server/src/main/webapp/WEB-INF/views/oauth/approve.jsp
2012-06-11 15:04:01 -04:00
Justin Richer 7a207dc162 Merge branch 'discoveryupdate' 2012-06-05 16:37:04 -04:00
Justin Richer 7df2663e00 added final slashification of configuration URLs 2012-06-05 16:36:11 -04:00
Justin Richer fbdccdb78e added Xrd support (fixes #63), updated configuration locations (fixes #47) 2012-06-05 16:32:49 -04:00
Justin Richer e44697cef9 updated JWK display to latest, closes #58 2012-06-05 16:07:19 -04:00
Justin Richer 5c72d8b95f revocation endpoint cleanup, still needs views 2012-06-05 11:24:11 -04:00
Justin Richer 27219c066d refactored our service to reflect upstream 2012-06-05 10:18:26 -04:00
Justin Richer e95528a08d added implementation to stub to read an access token by value 2012-06-05 10:11:24 -04:00
Amanda Anganes 424f8bb737 Refactored to use TokenEnhancer rather than a custom TokenGranter. 2012-05-30 16:14:00 -04:00
nemonik 8917e75010 see issue #19 2012-05-30 15:14:15 -04:00
Amanda Anganes 16aa0c59b5 Added token enhancer. Now to plug it in. 2012-05-30 12:31:12 -04:00
Amanda Anganes 2070d2e413 Updated to use AuthorizationRequestFactory rather than ClientCredentialsChecker. 2012-05-30 12:08:08 -04:00
Justin Richer ce847dd4f7 updated poco user view to contain name 2012-05-24 15:57:34 -04:00
Stephen Moore c418ccabb1 Merge branch 'master' into userInfoEndpoint 2012-05-24 13:06:29 -04:00
Stephen Moore 1bff5ef19f Added POCO view, Added UnknownUserInfoScheamException runtime exception 2012-05-24 11:00:49 -04:00
Stephen Moore 5c544dfe7c Merge branch 'master' into userInfoEndpoint 2012-05-23 13:43:32 -04:00
Justin Richer 7d4d65c359 Merge branch 'userinfo_integration' 2012-05-23 13:39:03 -04:00
Justin Richer a8e9f1d2cd fixed rendering issues with user info view 2012-05-23 13:36:53 -04:00
Stephen Moore 9612fde10e Check for null address, and added email 2012-05-23 13:35:05 -04:00
Justin Richer 08958d4137 Merge remote-tracking branch 'remotes/steve/userInfoEndpoint' into userinfo_integration 2012-05-23 13:11:40 -04:00
Justin Richer 06fadb5f2b oauth provider configuration started 2012-05-23 12:55:21 -04:00
Stephen Moore 9b03831d4e Filled in the UserInfoEndpoint, and added the JSON view for userInfo (openIdSchema) 2012-05-22 16:56:22 -04:00
Michael Jett e5312b4c99 Client secret now editable and dynamically generated if not present 2012-05-22 14:36:40 -04:00
Michael Jett 51fe98b383 ClientAPI now sets owner for clients 2012-05-18 14:23:19 -04:00
Michael Jett 2d980a4d8f Refactoring of routing. Client updates 2012-05-17 16:33:22 -04:00
Michael Jett b06640c921 First stages of client-side validation worked into application 2012-05-16 17:22:25 -04:00
Michael Jett 3402a3e463 ClientAPI now fully supports RESTful DELETE 2012-05-16 14:32:40 -04:00
Michael Jett 7f5b9e2c82 ClientAPI now supports DELETE method 2012-05-16 14:03:49 -04:00
Michael Jett af6e043239 Client Entity now initialized with non-null values so JPA won't flip. Added unified method for saving. Sync'd class member names to allow proper binding. 2012-05-16 13:27:53 -04:00
Michael Jett 0c7ea88323 Client updates. 2012-05-15 17:03:17 -04:00
Michael Jett 0f9b828066 ClientAPI admin requirement now global 2012-05-15 14:10:12 -04:00
Michael Jett 32e67730d8 ClientAPI maps to individual clients by IDs 2012-05-15 13:41:27 -04:00
Michael Jett 6b481cd3bb ClientAPI header updates 2012-05-15 13:09:16 -04:00
Michael Jett a4fc4e939e ClientAPI cleanup 2012-05-15 12:41:41 -04:00
Stephen Moore fd91c884bb Made interfaces... deleted a thing. 2012-05-10 17:45:10 -04:00
Amanda Anganes e33f277bbe Updated classes to track newest version of SECOAUTH. This update closes issues #3, #4, #8, and #36 (infinite redirects). This revision changes the authorization and token endpoints to be /openidconnect/auth and /openidconnect/token, respectively. 2012-05-09 15:16:56 -04:00
Michael Jett c8e3f70115 Now requiring homepage login 2012-05-08 14:09:24 -04:00
Michael Jett 7dd81ac2de Server-side dynamics 2012-05-08 13:53:21 -04:00
Michael Jett 23fd7b1b21 Renaming Client View class 2012-05-08 11:20:40 -04:00
Michael Jett eda7505b7b Client API now renders JSON for all Clients 2012-05-08 11:16:45 -04:00
Justin Richer 97dffb6414 added copyright to all java files. closes #11 2012-04-27 17:55:58 -04:00
Justin Richer 6724866099 moved jwt components, utilities, and various interfaces to -common from -server 2012-04-27 15:20:49 -04:00
Justin Richer 59ecb03548 added getter/setter for userinforepository, closes #40 2012-04-27 15:11:25 -04:00
Amanda Anganes 6899a16c2f Merge branch 'Really_fixing_redirects' 2012-04-16 12:39:06 -04:00
Justin Richer 05b2cf8fff removed vestigial user details code 2012-04-16 12:02:24 -04:00
Amanda Anganes f0f339d45f current state 2012-04-16 11:05:36 -04:00
Amanda Anganes 2fc4ce177c This commit fixes the infinite redirect, somewhat. See updated issue #8. 2012-04-11 15:55:19 -04:00
Amanda Anganes 486b7723d3 Merge branch 'master' of github.com:jricher/OpenID-Connect-Java-Spring-Server 2012-04-10 13:45:26 -04:00
Amanda Anganes 269a354f8c Added tables.sql, which is just a concatenation of all the other sql files. Added redirect_uris.sql, which is a NEW table needed to support clients registering multiple redirect uris.
This updates us to the HEAD revision of SECOAUTH, where the redirect uri field on ClientDetails has been updated to be a Set<String> instead of a single string. I updated the UI code so that it will still work, but it will need to be updated to allow users to register multiple uris.
This also closes issue #2 from the issue tracker.
2012-04-10 13:44:10 -04:00
nemonik d056079fea Support for ECDSA JWT signer was removed as it would require the system-wide installation and configuration of the Bouncy Castle Security Provider in order for the server to work when deployed to Tomcat. See issue ticket #20 2012-04-10 13:41:18 -04:00
nemonik 6c8661f3ad the signature base created in the verify method of the AbstractJwtSigner did not match how the Jwt.getSignatureBase creates the signature base. also, modified the testGenerateHmacSignature to exercise 2012-04-02 22:12:03 -04:00
nemonik 267f1b2de3 bas64 decoded signature prior to verifying, modified unit rsa unit test, and fixed ecdsa signer verify 2012-04-02 21:32:42 -04:00
Justin Richer 985a4619fa abstracted keystore loader to new function 2012-04-02 15:06:58 -04:00
Justin Richer 3dfe6df410 refactored algorithms out to their own separate Enum 2012-04-02 13:13:13 -04:00
Justin Richer fec6a3a876 removed definition parsers, may be picked up again later 2012-04-02 12:40:53 -04:00
Amanda Anganes b986b30695 Fixed unit tests - they were broken due to an error in application-context.xml; not because of the refactor. App context was trying to instantiate an Hmac signer with name "HMACSHA256", which should have been "HS256". I updated the exceptions thrown by the signer impls so that if an Algorithm name mismatch occurs it will tell you what it is trying to match against. 2012-03-30 13:45:04 -04:00
nemonik 0a29eba617 unit test correction, slight refactor of tested classes 2012-03-29 14:02:51 -04:00
nemonik f215cfc50c fix for issue 5, code refactoring across signers 2012-03-29 12:34:51 -04:00
Amanda Anganes c50f968748 Merged to use idToken.setNonce(). 2012-03-23 11:11:38 -04:00
Amanda Anganes 268b82e31d Merge branch 'Branch_master3-23-2012' 2012-03-23 11:09:27 -04:00
Amanda Anganes 8b10b83516 Added setNonce to JwtClaims. 2012-03-23 11:08:49 -04:00
Justin Richer 4a15e51e12 pass through nonce 2012-03-23 10:52:04 -04:00
Amanda Anganes 27fe3c9eca Implemented signing. Works, but validation does not fail if you remove the signature. 2012-03-22 14:49:02 -04:00
Amanda Anganes 68c8d1a9d2 Changed parameter for check id endpoint to access_token instead of auth_token 2012-03-22 14:19:45 -04:00
Justin Richer 826be5a1a1 changed parameter name to match spec change 2012-03-22 14:10:50 -04:00
Justin Richer 5fe036878a fixed view for idtoken in checkid endpoint 2012-03-22 14:09:25 -04:00
Justin Richer c51bb72fe5 merged keystore changes 2012-03-22 13:50:47 -04:00
Justin Richer 6c01134095 JWK display support for key maps, still no key ids 2012-03-22 13:48:16 -04:00
Amanda Anganes 776748f908 Merge branch '3-22-2012' 2012-03-22 13:43:59 -04:00
Amanda Anganes ae9b5e792a Added a ConfigurationPropertiesBean.java to hold configuration properties. Fixed up CheckIDEndpoint.java a bit - it works, but is outputting the wrong thing. 2012-03-22 13:43:30 -04:00
Justin Richer 524a8e153e signers turned into a map 2012-03-22 13:37:21 -04:00
Justin Richer 664dd1df46 JWT claims can now have nulls in them without barfing 2012-03-22 11:46:48 -04:00
Justin Richer c59d3fe963 it spits out JWTs! and id tokens! JWT still needs to handle nulls 2012-03-21 17:59:48 -04:00
Amanda Anganes ebe72412fe Authorization Grant flow works up to serializing the returned Access Token. Justin is investigating serialization problems. 2012-03-21 16:44:16 -04:00
Amanda Anganes d94eb338ee Auth code flow works through user approval page. Current problem is that it doesn't seem to be matching up auth codes correctly (I keep getting "invalid code" error). But, it looks like it's going through our custom token granter so that is good. 2012-03-20 15:07:18 -04:00
Justin Richer 2f29cc52b2 Merge branch 'client_refactor' 2012-03-16 16:28:51 -04:00
Justin Richer e6e7504213 added files and shuffled things to new packages 2012-03-16 15:46:23 -04:00
Justin Richer a0cdd8bf2f moved server to new package location 2012-03-16 15:01:53 -04:00