Justin Richer
7273b0a5b7
fixed discovery endpoint information, closes #805
2015-04-12 17:00:46 -05:00
Justin Richer
eb49d9624c
inject claims from OIDC auth token into permission ticket
2015-03-31 18:21:34 -04:00
Justin Richer
98cd5ba27d
added save to permission ticket system
2015-03-31 18:21:14 -04:00
Justin Richer
08413302eb
configured OIDC client on claims collection endpoint
2015-03-31 15:35:20 -04:00
Justin Richer
f48049be4d
deny tickets with no claims required (closes a race condition)
2015-03-31 10:26:06 -04:00
Justin Richer
dc10779abb
removed extraneous issuer in discovery endpoint, closes #793
2015-03-31 10:10:14 -04:00
Justin Richer
a38a0b6f75
removed extraneous bob
2015-03-30 18:19:13 -04:00
Justin Richer
6e095e3266
can now add and remove email address claims from the UI
2015-03-30 17:54:16 -04:00
Justin Richer
687517d7f4
Merge branch 'master' into claims-editing-ui
2015-03-30 12:21:59 -04:00
Justin Richer
d015d17fad
search for local users first (by email), then check remote users
2015-03-30 12:20:19 -04:00
Justin Richer
348ff7ee17
made webfinger endpoint search by email address, then by username
2015-03-30 12:18:50 -04:00
Justin Richer
5aa5cc1a10
added search by email to user info data stack
2015-03-30 12:18:50 -04:00
Justin Richer
e89d8cd985
added webfinger lookup helper service
2015-03-30 11:49:49 -04:00
Justin Richer
394785b9c4
don't give resource sets default client scopes
2015-03-30 09:57:10 -04:00
Justin Richer
7af19dbd61
added copyright text
2015-03-30 08:44:51 -04:00
Justin Richer
3e931c68b4
added policy editing overview page
2015-03-20 17:27:10 -04:00
Justin Richer
5698393d31
created claims API
2015-03-19 16:44:34 -04:00
Justin Richer
bde03411f1
Merge branch 'master' into uma
2015-03-18 21:42:26 -04:00
Justin Richer
006a4d1ec6
fixed import function of 1.2 data service
2015-03-18 21:42:18 -04:00
Justin Richer
6f149cba69
Merge branch 'master' into uma
2015-03-18 20:10:19 -04:00
Justin Richer
30e894a64a
put 'kid' into JWS header, closes #784
2015-03-18 20:09:06 -04:00
Justin Richer
866186f611
pointed data API at the correct service version
2015-03-18 19:54:42 -04:00
Justin Richer
6daeeefb33
augmented introspection unit tests with one for new permissions mode
2015-03-18 08:45:05 -04:00
Justin Richer
9f913244a0
fixed unit tests for introspection results
2015-03-18 08:00:18 -04:00
Justin Richer
7df31f1e87
completed rudimentary UMA authorization API.
...
Working: resource set registration, permission ticket creation, RPT creation from ticket
Still missing: adding required claims to resource set, adding provided claims to permission ticket
2015-03-17 22:26:12 -04:00
Justin Richer
1be9da52c6
separated ticket object from permission object to facilitate re-use of permission object with tokens
2015-03-17 21:16:29 -04:00
Justin Richer
f123366069
added scope filtering to protection api
2015-03-17 19:43:02 -04:00
Justin Richer
ff958e20b6
basic authorization support
2015-03-17 19:21:20 -04:00
Justin Richer
098519da5e
added OAuth2 error reporting to permission and resource set endpoints
2015-03-17 19:01:44 -04:00
Justin Richer
2aadb09f49
started claims service, added expiration to permissions
2015-03-16 22:52:21 -04:00
Justin Richer
c234f78dbd
Merge branch 'master' into authorization-api
2015-03-13 19:08:14 -04:00
Justin Richer
5873b336f2
fixed erroneous import
2015-03-13 19:07:27 -04:00
Justin Richer
8352145d82
Merge branch 'master' into authorization-api
...
Conflicts:
openid-connect-common/src/main/java/org/mitre/oauth2/service/SystemScopeService.java
openid-connect-server-webapp/src/main/webapp/WEB-INF/application-context.xml
openid-connect-server/src/main/java/org/mitre/discovery/web/DiscoveryEndpoint.java
openid-connect-server/src/main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java
openid-connect-server/src/main/java/org/mitre/openid/connect/web/ClientAPI.java
openid-connect-server/src/test/java/org/mitre/oauth2/service/impl/TestDefaultIntrospectionAuthorizer.java
2015-03-13 18:39:26 -04:00
Justin Richer
ba51df0c37
consolidated client credential filter beans
...
(note: imports magic from secoauth)
2015-03-13 18:30:09 -04:00
Justin Richer
4f12fab56b
made unused auth codes expired (they're still single-use), refactored auth code service layer
2015-03-13 13:45:49 -04:00
Justin Richer
2abcd96bbe
set fallback locale to English, ultimate fall through is to return the code string itself
2015-03-12 17:28:27 -04:00
Justin Richer
285ad71874
made input reader use UTF8, imported the first set of Swedish text to the JSON format
2015-03-12 17:07:08 -04:00
Justin Richer
80605becf1
rudimentary json-based message source
2015-03-12 15:26:23 -04:00
Justin Richer
e1fb8272cc
redirect error on prompt=none, addresses #667
2015-03-12 09:26:38 -04:00
Justin Richer
ad9b49733f
externalized queries for scopes, blacklists, user info, pairwise identifiers, and whitelists, closes #771 even harder
2015-03-11 16:13:28 -04:00
Justin Richer
15b97b1dcb
Externalized strings for named queries on auth holders, auth codes, clients, and tokens, closes #771
2015-03-11 15:51:51 -04:00
Justin Richer
61a596dc15
externalized strings from user info views
2015-03-11 14:00:14 -04:00
Justin Richer
86e95d9e6e
externalized json entity and error parameters, closes #770
2015-03-11 13:52:32 -04:00
Justin Richer
e56161e223
extracted http "code" view parameter
2015-03-11 13:39:07 -04:00
Justin Richer
1735dbca11
extracted controller URLs to constants, closes #769
2015-03-11 13:20:59 -04:00
Justin Richer
617d485478
updated all references to media types to use constants instead of literals, closes #767
2015-03-11 12:06:38 -04:00
Justin Richer
c777ebfac9
added universal OAuth exception handling
2015-03-11 11:41:28 -04:00
Justin Richer
76b7324d88
fixed execution order of introspection endpoint
2015-03-10 18:29:48 -04:00
Justin Richer
8c8f912880
fixed endpoint processing to account for client id
2015-03-10 15:37:07 -04:00
Justin Richer
ee522100b9
Merge branch 'master' into uma-introspection
...
* master:
fixed logger variable name
made logger declarations consistent across project, closes #780
Fixed logger
null safe
removed DateUtil
added icons to scope editing panel
2015-03-10 15:03:26 -04:00
Justin Richer
5d35f2c1a6
toned down errors on introspection endpoint
2015-03-10 14:58:22 -04:00
Justin Richer
65d7b00f4d
added uma-processing of scopes to introspection results
2015-03-10 12:38:37 -04:00
Justin Richer
627bcaee43
added client_id to resource sets
2015-03-10 12:38:13 -04:00
Justin Richer
e5e4c15058
removed introspection authorizer hook
2015-03-10 11:12:37 -04:00
Justin Richer
2a6a17486a
added initial uma discovery endpoint
2015-03-09 16:15:30 -04:00
Justin Richer
621399545e
cleaned up introspection endpoint processing
2015-03-09 16:15:09 -04:00
Justin Richer
764df71758
refactored introspection to allow for UMA style token access
2015-03-09 12:43:05 -04:00
Justin Richer
1da5c2cd84
fixed imports
2015-03-09 11:51:41 -04:00
Justin Richer
c7f6811961
refactored scope enforcement utilities to a separate authentication class
2015-03-09 11:51:24 -04:00
Justin Richer
48b857eb85
fixed logger variable name
2015-03-09 07:37:09 -04:00
Justin Richer
c09b63c69f
made logger declarations consistent across project, closes #780
2015-03-08 21:56:33 -04:00
Wolter Eldering
849a2b3271
Fixed logger
2015-03-08 16:02:53 +01:00
Wolter Eldering
020b410ffe
null safe
2015-03-08 15:47:58 +01:00
Wolter Eldering
db2574ab53
removed DateUtil
2015-03-08 15:41:47 +01:00
Justin Richer
f266d3b151
added unit test for resource set service to make sure it catches error conditions
2015-03-06 16:56:30 -05:00
Justin Richer
35f2a03b4e
added unit test for permission service
2015-03-06 15:50:24 -05:00
Justin Richer
e59e988809
made permission service enforce scoping
2015-03-06 15:50:14 -05:00
Justin Richer
5ff9cd1bbb
implemented permission registration API
2015-02-28 17:59:37 -05:00
Justin Richer
eed8fb0b28
created skeleton of permission registration API
2015-02-28 08:33:09 -05:00
Justin Richer
c41488b103
moved an uma package to common, extracted OAuth scope enforcement utility
2015-02-28 08:32:47 -05:00
Justin Richer
5be7d64c7d
moved all uma files to their own package
2015-02-28 07:24:53 -05:00
Justin Richer
0d96b6a28a
changed name of scope to match uma spec
2015-02-27 20:46:48 -05:00
Justin Richer
7a1480bb07
moved and consolidated json utilities
2015-02-26 16:20:01 -05:00
Justin Richer
40fc70894e
fixed oauth scope check
2015-02-24 18:01:03 -05:00
Justin Richer
4878e88d4f
added list all by owner
2015-02-24 17:41:05 -05:00
Justin Richer
8d22ad03e2
implemented remove verb
2015-02-24 17:15:18 -05:00
Justin Richer
89114dcf74
implemented update
2015-02-24 16:05:18 -05:00
Justin Richer
ad228e8953
send the _id as a string
2015-02-24 15:52:29 -05:00
Justin Richer
3b6412219b
added abbreviated view, updated OAuth error handling, fixed URL mapping
2015-02-24 15:10:48 -05:00
Justin Richer
0b480bac10
implemented get
2015-02-24 15:09:52 -05:00
Justin Richer
3076da1ed8
functioning resource set repository layer
2015-02-24 12:10:54 -05:00
Justin Richer
efeead52b6
fixed typos in data layer, added blank service layer to resource set
2015-02-24 12:00:58 -05:00
Justin Richer
e7bf75e9a4
moved and consolidated json utilities
2015-02-23 13:43:08 -05:00
Justin Richer
90a7304b4e
resource set registration endpoint and service shells
2015-02-23 11:43:05 -05:00
Justin Richer
b670f44138
added UMA to version number
2015-02-19 17:55:25 -05:00
Justin Richer
720b73939f
fixed token service logic, added verification to unit tests
2015-02-18 13:57:28 -05:00
Justin Richer
97ae456099
fixed unit tests affected by scope service changes
2015-02-18 13:48:16 -05:00
Justin Richer
6885713eed
added warning suppression for data layer -- non-templated generic types have to be used here
2015-02-18 10:19:36 -05:00
Justin Richer
f4813fccee
fixed log messages on data services
2015-02-18 09:33:13 -05:00
Justin Richer
4ae981f484
updated data layer and unit tests
2015-02-18 09:23:09 -05:00
Justin Richer
593fac83cf
scopes can now be set as "restricted" instead of needing to be set "allowDynReg", closes #747
2015-02-17 18:25:52 -05:00
Justin Richer
1caf5ef8bc
removed call to deprecated http components constructor
2015-02-17 17:06:34 -05:00
Justin Richer
b376bc6059
removed some vestigial service/repository calls, closes #513
2015-02-17 16:22:40 -05:00
Justin Richer
ecfb72bc50
additional JOSE class naming
2015-02-17 15:32:20 -05:00
Justin Richer
522edda074
additional JOSE class renaming
2015-02-17 14:57:29 -05:00
Justin Richer
cef6cf17b6
externalized a number of strings, closes #385
2015-02-17 14:39:15 -05:00
Justin Richer
05f03f7c90
yet more year updates
2015-02-17 13:09:45 -05:00
Justin Richer
994ce6c743
consistently named JOSE-based classes, closes #529
2015-02-17 12:11:58 -05:00
Justin Richer
335d05bb5c
renamed data service abstract class
2015-02-17 11:56:50 -05:00
Justin Richer
685960358c
formatting cleanup
2015-02-17 11:08:46 -05:00