[Openid-specs-ab] Issue #37: OP-J-06 (Reject registration where a redirect_uri has a fragment) - Invalid result displayed (openid/certification)
Edmund Jay
issues-reply at bitbucket.org
Tue Jan 27 18:08:36 UTC 2015
New issue 37: OP-J-06 (Reject registration where a redirect_uri has a fragment) - Invalid result displayed
https://bitbucket.org/openid/certification/issue/37/op-j-06-reject-registration-where-a
Edmund Jay:
The OP returns an error indicating the registration is invalid so the test should pass but the result is displaying a fail (red light).
Below is the trace :
0.000157 ------------ DiscoveryRequest ------------
0.000169 Provider info discover from 'https://connect.openid4.us/'
0.839538 ProviderConfigurationResponse: {'claims_supported': [u'name', u'given_name', u'family_name', u'middle_name', u'nickname', u'preferred_username', u'profile', u'picture', u'website', u'email', u'email_verified', u'gender', u'birthdate', u'zoneinfo', u'locale', u'phone_number', u'phone_number_verified', u'address', u'updated_at'], 'version': u'3.0', 'op_policy_uri': u'https://connect.openid4.us/abop/op.php/op_policy', 'subject_types_supported': [u'public', u'pairwise'], 'request_parameter_supported': True, 'userinfo_signing_alg_values_supported': [u'none', u'HS256', u'HS384', u'HS512', u'RS256', u'RS384', u'RS512'], 'issuer': u'https://connect.openid4.us', 'ui_locales_supported': [u'en-US'], 'id_token_encryption_enc_values_supported': [u'A128CBC-HS256', u'A256CBC-HS512', u'A128GCM', u'A256GCM'], 'require_request_uri_registration': False, 'grant_types_supported': [u'authorization_code', u'implicit'], 'token_endpoint': u'https://connect.openid4.us/abop/op.php/token', 'dis
play_values_supported': [u'page'], 'request_uri_parameter_supported': True, 'claims_locales_supported': [u'en-US'], 'service_documentation': u'https://connect.openid4.us/abop/op.php/servicedocs', 'registration_endpoint': u'https://connect.openid4.us/abop/op.php/registration', 'jwks_uri': u'https://connect.openid4.us/connect4us.jwk', 'userinfo_encryption_alg_values_supported': [u'RSA1_5', u'RSA-OAEP'], 'scopes_supported': [u'openid', u'profile', u'email', u'address', u'phone', u'offline_access'], 'token_endpoint_auth_methods_supported': [u'client_secret_post', u'client_secret_basic', u'client_secret_jwt', u'private_key_jwt'], 'userinfo_encryption_enc_values_supported': [u'A128CBC-HS256', u'A256CBC-HS512', u'A128GCM', u'A256GCM'], 'id_token_signing_alg_values_supported': [u'none', u'HS256', u'HS384', u'HS512', u'RS256', u'RS384', u'RS512'], 'request_object_encryption_enc_values_supported': [u'A128CBC-HS256', u'A256CBC-HS512', u'A128GCM', u'A256GCM'], 'claims_parameter_supporte
d': True, 'id_token_encryption_alg_values_supported': [u'RSA1_5', u'RSA-OAEP'], 'token_endpoint_auth_signing_alg_values_supported': [u'none', u'HS256', u'HS384', u'HS512', u'RS256', u'RS384', u'RS512'], 'userinfo_endpoint': u'https://connect.openid4.us/abop/op.php/userinfo', 'request_object_signing_alg_values_supported': [u'none', u'HS256', u'HS384', u'HS512', u'RS256', u'RS384', u'RS512'], 'op_tos_uri': u'https://connect.openid4.us/abop/op.php/op_tos', u'check_session_iframe': u'https://connect.openid4.us/abop/opframe.php/1', 'request_object_encryption_alg_values_supported': [u'RSA1_5', u'RSA-OAEP'], 'response_types_supported': [u'code', u'code token', u'code id_token', u'token', u'token id_token', u'code token id_token', u'id_token'], u'end_session_endpoint': u'https://connect.openid4.us/abop/op.php/endsession', 'authorization_endpoint': u'https://connect.openid4.us/abop/op.php/auth', 'claim_types_supported': [u'normal']}
1.689416 JWKS: {
"keys":[
{
"kty":"RSA",
"n":"tf_sB4M0sHearRLzz1q1JRgRdRnwk0lz-IcVDFlpp2dtDVyA-ZM8Tu1swp7upaTNykf7cp3Ne_6uW3JiKvRMDdNdvHWCzDHmbmZWGdnFF9Ve-D1cUxj4ETVpUM7AIXWbGs34fUNYl3Xzc4baSyvYbc3h6iz8AIdb_1bQLxJsHBi-ydg3NMJItgQJqBiwCmQYCOnJlekR-Ga2a5XlIx46Wsj3Pz0t0dzM8gVSU9fU3QrKKzDFCoFHTgig1YZNNW5W2H6QwANL5h-nbgre5sWmDmdnfiU6Pj5GOQDmp__rweinph8OAFNF6jVqrRZ3QJEmMnO42naWOsxV2FAUXafksQ",
"e":"AQAB",
"kid":"ABOP-00"
}
]
}
1.689970 ------------ RegistrationRequest ------------
1.690315 --> URL: https://connect.openid4.us/abop/op.php/registration
1.690321 --> BODY: {"subject_type": "public", "jwks_uri": "https://oictest.umdc.umu.se:8102/export/jwk_8102.json", "application_type": "web", "grant_types": ["authorization_code"], "redirect_uris": ["https://oictest.umdc.umu.se:8102/authz_cb#foobar"], "response_types": ["code"], "require_auth_time": true, "scope": ["openid", "profile", "email", "address", "phone"], "default_max_age": 3600}
1.690328 --> HEADERS: {'Content-type': 'application/json'}
2.488704 <-- STATUS: 400
2.488840 ErrorResponse: {'error_description': u'redirect_uris is invalid', 'error': u'invalid_redirect_uri'}
More information about the Openid-specs-ab
mailing list