Florian Forster
550f7877f2
fix: move to new org ( #177 )
...
* chore: move to new org
* chore: change import
* fix: update logging lib
Co-authored-by: Fabienne <fabienne.gerschwiler@gmail.com>
Co-authored-by: adlerhurst <silvan.reusser@gmail.com>
2022-04-26 23:48:29 +02:00
Livio Amstutz
c07557be02
feat: build the redirect after a successful login with AuthCallbackURL function ( #164 )
2022-03-16 10:55:29 +01:00
Livio Amstutz
e39146c98e
fix: ensure signer has key on OP creation
2022-01-31 07:27:52 +01:00
Livio Amstutz
eb10752e48
feat: Token Revocation, Request Object and OP Certification ( #130 )
...
FEATURES (and FIXES):
- support OAuth 2.0 Token Revocation [RFC 7009](https://datatracker.ietf.org/doc/html/rfc7009 )
- handle request object using `request` parameter [OIDC Core 1.0 Request Object](https://openid.net/specs/openid-connect-core-1_0.html#RequestObject )
- handle response mode
- added some information to the discovery endpoint:
- revocation_endpoint (added with token revocation)
- revocation_endpoint_auth_methods_supported (added with token revocation)
- revocation_endpoint_auth_signing_alg_values_supported (added with token revocation)
- token_endpoint_auth_signing_alg_values_supported (was missing)
- introspection_endpoint_auth_signing_alg_values_supported (was missing)
- request_object_signing_alg_values_supported (added with request object)
- request_parameter_supported (added with request object)
- fixed `removeUserinfoScopes ` now returns the scopes without "userinfo" scopes (profile, email, phone, addedd) [source diff](https://github.com/caos/oidc/pull/130/files#diff-fad50c8c0f065d4dbc49d6c6a38f09c992c8f5d651a479ba00e31b500543559eL170-R171 )
- improved error handling (pkg/oidc/error.go) and fixed some wrong OAuth errors (e.g. `invalid_grant` instead of `invalid_request`)
- improved MarshalJSON and added MarshalJSONWithStatus
- removed deprecated PEM decryption from `BytesToPrivateKey` [source diff](https://github.com/caos/oidc/pull/130/files#diff-fe246e428e399ccff599627c71764de51387b60b4df84c67de3febd0954e859bL11-L19 )
- NewAccessTokenVerifier now uses correct (internal) `accessTokenVerifier` [source diff](https://github.com/caos/oidc/pull/130/files#diff-3a01c7500ead8f35448456ef231c7c22f8d291710936cac91de5edeef52ffc72L52-R52 )
BREAKING CHANGE:
- move functions from `utils` package into separate packages
- added various methods to the (OP) `Configuration` interface [source diff](https://github.com/caos/oidc/pull/130/files#diff-2538e0dfc772fdc37f057aecd6fcc2943f516c24e8be794cce0e368a26d20a82R19-R32 )
- added revocationEndpoint to `WithCustomEndpoints ` [source diff](https://github.com/caos/oidc/pull/130/files#diff-19ae13a743eb7cebbb96492798b1bec556673eb6236b1387e38d722900bae1c3L355-R391 )
- remove unnecessary context parameter from JWTProfileExchange [source diff](https://github.com/caos/oidc/pull/130/files#diff-4ed8f6affa4a9631fa8a034b3d5752fbb6a819107141aae00029014e950f7b4cL14 )
2021-11-02 13:21:35 +01:00
Livio Amstutz
a63fbee93d
fix: improve JWS and key verification ( #128 )
...
* fix: improve JWS and key verification
* fix: get remote keys if no cached key matches
* fix: get remote keys if no cached key matches
* fix exactMatch
* fix exactMatch
* chore: change default branch name in .releaserc.js
2021-09-14 15:13:44 +02:00
Livio Amstutz
8a35b89815
fix: supported ui locales from config ( #107 )
2021-07-09 09:20:03 +02:00
Livio Amstutz
58e27e8073
simplify KeyProvider interface
2021-06-30 14:10:38 +02:00
Livio Amstutz
850faa159d
fix: rp verification process ( #95 )
...
* fix: rp verification process
* types
* comments
* fix cli client
2021-06-23 11:08:54 +02:00
Livio Amstutz
14faebbb77
fix: check grant types and add refresh token to discovery
2021-05-27 13:44:11 +02:00
Livio Amstutz
1049c44c3e
Merge remote-tracking branch 'origin/token-introspection' into signingkey
...
# Conflicts:
# pkg/op/mock/storage.mock.go
# pkg/op/storage.go
2021-02-12 13:02:04 +01:00
Livio Amstutz
5678693d44
clenaup
2021-02-12 12:52:33 +01:00
Livio Amstutz
960be5af1f
introspect and client assertion
2021-02-01 17:17:40 +01:00
Livio Amstutz
50ab51bb46
introspect and client assertion
2021-01-28 08:41:36 +01:00
Livio Amstutz
a1a21f0d59
introspect
2021-01-08 15:01:23 +01:00
Livio Amstutz
b2f23dc5b7
Merge branch 'master' into signingkey
2020-12-16 08:01:37 +01:00
Fabi
27f3bc0f4a
fix: change callbackpath ( #74 )
...
* fix: append client id to aud
* handle new callback path
Co-authored-by: Livio Amstutz <livio.a@gmail.com>
2020-11-30 11:21:09 +01:00
Livio Amstutz
2ebbd7a2e0
fix: grant_types_supported in discovery
2020-10-21 10:36:34 +02:00
Livio Amstutz
06dcac4c2f
fix: remove signing key creation (when not found)
2020-10-19 15:26:34 +02:00
Livio Amstutz
b8d892443c
claims assertion
2020-10-14 16:41:04 +02:00
Livio Amstutz
542ec6ed7b
refactoring
2020-09-25 16:41:25 +02:00
Livio Amstutz
c90a9d53c8
cleanup
2020-09-16 16:23:38 +02:00
Livio Amstutz
64797c1df6
cleanup
2020-09-16 15:22:15 +02:00
Livio Amstutz
a56a4a018a
harmonize jwtProfile and existing interfaces / functions
2020-09-15 16:59:27 +02:00
Livio Amstutz
8790b54e0d
update some op interfaces
2020-09-15 07:25:44 +02:00
Livio Amstutz
45230569d3
change RP interfaces
2020-09-14 07:52:16 +02:00
Livio Amstutz
143ff3482c
change verifier interfaces
2020-09-11 10:45:07 +02:00
Livio Amstutz
eaf47fde8e
change some interfaces
2020-09-09 16:00:19 +02:00
Livio Amstutz
a37a8461a5
lot of unfinished changes
2020-09-08 16:07:49 +02:00
Livio Amstutz
c828290ef1
fix: improve interceptor handling ( #49 )
2020-08-28 14:51:38 +02:00
Livio Amstutz
d02653e75d
fix: add authorization to cors ( #48 )
2020-08-24 16:08:07 +02:00
Livio Amstutz
6e71c17f1d
pass origin into GetUserinfoFromToken
2020-08-24 07:52:22 +02:00
Livio Amstutz
c88e6b4ab3
fix: explicit allow Origin from request
2020-08-10 15:49:32 +02:00
Livio Amstutz
628bc4ed65
fix: end session ( #35 )
...
* fix: handle code separately
* fix: option to ignore expiration on id_token and error handling
* fix: op handler as http.Handler
* fix: terminate session possible wihtout id_token_hint
2020-07-06 12:52:22 +02:00
Livio Amstutz
e8f3010910
feat: terminate session (front channel logout)
2020-03-03 11:31:23 +01:00
Livio Amstutz
3f97c5c3ed
feat: add cors * to handler
2020-02-27 12:56:47 +01:00
Livio Amstutz
93709a18b6
add readiness and partial key rotation
2020-02-11 17:17:09 +01:00
Livio Amstutz
f0d17fd839
feat: add http interceptor function for auth and token endpoints
2020-02-06 11:12:00 +01:00
Livio Amstutz
6d0890e280
initial commit
2020-01-31 15:22:16 +01:00