[Openid-specs-ab] Issue #88: OP-claims-Combined (Supports Combining Claims Requested with scope and claims Request Parameter) sends two scope parameters (openid/certification)

Edmund Jay issues-reply at bitbucket.org
Wed Mar 11 22:50:59 UTC 2015


New issue 88: OP-claims-Combined (Supports Combining Claims Requested with scope and claims Request Parameter) sends two scope parameters
https://bitbucket.org/openid/certification/issue/88/op-claims-combined-supports-combining

Edmund Jay:

The scope parameter should be a space separated list of values


```
#!text

Test info

Profile: {'profile': 'C', 'sub': 'none', 'register': True, 'discover': True, 'extra': False}
Test ID: OP-claims-Combined
Issuer: https://connect.openid4.us
Test output


__RegistrationRequest:post__
[check]
	status: INFORMATION
	description: Registration Response
	info: {"client_id":"mnbsEDdoWfknVJE_WQyh5w","client_secret":"SO5kU4GErOZLzw","registration_access_token":"SODmrxZa2CWOdg","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/bflHb_r6v9hwatYnDHBXdg","client_id_issued_at":1426114008,"client_secret_expires_at":0,"registration_client_uri_path":"bflHb_r6v9hwatYnDHBXdg","contacts":["roland.hedberg at umu.se"],"application_type":"web","redirect_uris":["https:\/\/op.certification.openid.net:60103\/authz_cb","https:\/\/op.certification.openid.net:60103\/cb"],"post_logout_redirect_uris":["https:\/\/op.certification.openid.net:60103\/logout"],"jwks_uri":"https:\/\/op.certification.openid.net:60103\/export\/jwk_60103.json","subject_type":"pairwise","default_max_age":3600,"require_auth_time":true,"response_types":["code"],"grant_types":["authorization_code"]}
__AuthorizationRequest:pre__
[check-response-type]
	status: OK
	description: Checks that the asked for response type are among the supported
[check-endpoint]
	status: OK
	description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[check-http-response]
	status: OK
	description: Checks that the HTTP response status is within the 200 or 300 range
[verify-claims]
	status: OK
	description: Verifies that the user information returned is consistent with what was asked for
Trace output


0.000284 ------------ DiscoveryRequest ------------
0.000296 Provider info discover from 'https://connect.openid4.us'
0.000303 --> URL: https://connect.openid4.us/.well-known/openid-configuration
0.349029 ProviderConfigurationResponse: {
  "authorization_endpoint": "https://connect.openid4.us/abop/op.php/auth",
  "check_session_iframe": "https://connect.openid4.us/abop/opframe.php/1",
  "claim_types_supported": [
    "normal"
  ],
  "claims_locales_supported": [
    "en-US"
  ],
  "claims_parameter_supported": true,
  "claims_supported": [
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "preferred_username",
    "profile",
    "picture",
    "website",
    "email",
    "email_verified",
    "gender",
    "birthdate",
    "zoneinfo",
    "locale",
    "phone_number",
    "phone_number_verified",
    "address",
    "updated_at"
  ],
  "display_values_supported": [
    "page"
  ],
  "end_session_endpoint": "https://connect.openid4.us/abop/op.php/endsession",
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "id_token_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP"
  ],
  "id_token_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A256CBC-HS512",
    "A128GCM",
    "A256GCM"
  ],
  "id_token_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "issuer": "https://connect.openid4.us",
  "jwks_uri": "https://connect.openid4.us/connect4us.jwk",
  "op_policy_uri": "https://connect.openid4.us/abop/op.php/op_policy",
  "op_tos_uri": "https://connect.openid4.us/abop/op.php/op_tos",
  "registration_endpoint": "https://connect.openid4.us/abop/op.php/registration",
  "request_object_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP"
  ],
  "request_object_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A256CBC-HS512",
    "A128GCM",
    "A256GCM"
  ],
  "request_object_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "request_parameter_supported": true,
  "request_uri_parameter_supported": true,
  "require_request_uri_registration": false,
  "response_types_supported": [
    "code",
    "code token",
    "code id_token",
    "token",
    "token id_token",
    "code token id_token",
    "id_token"
  ],
  "scopes_supported": [
    "openid",
    "profile",
    "email",
    "address",
    "phone",
    "offline_access"
  ],
  "service_documentation": "https://connect.openid4.us/abop/op.php/servicedocs",
  "subject_types_supported": [
    "public",
    "pairwise"
  ],
  "token_endpoint": "https://connect.openid4.us/abop/op.php/token",
  "token_endpoint_auth_methods_supported": [
    "client_secret_post",
    "client_secret_basic",
    "client_secret_jwt",
    "private_key_jwt"
  ],
  "token_endpoint_auth_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "ui_locales_supported": [
    "en-US"
  ],
  "userinfo_encryption_alg_values_supported": [
    "RSA1_5",
    "RSA-OAEP"
  ],
  "userinfo_encryption_enc_values_supported": [
    "A128CBC-HS256",
    "A256CBC-HS512",
    "A128GCM",
    "A256GCM"
  ],
  "userinfo_endpoint": "https://connect.openid4.us/abop/op.php/userinfo",
  "userinfo_signing_alg_values_supported": [
    "none",
    "HS256",
    "HS384",
    "HS512",
    "RS256",
    "RS384",
    "RS512"
  ],
  "version": "3.0"
}
0.659886 JWKS: {
  "keys": [
    {
      "e": "AQAB",
      "kid": "ABOP-00",
      "kty": "RSA",
      "n": "tf_sB4M0sHearRLzz1q1JRgRdRnwk0lz-IcVDFlpp2dtDVyA-ZM8Tu1swp7upaTNykf7cp3Ne_6uW3JiKvRMDdNdvHWCzDHmbmZWGdnFF9Ve-D1cUxj4ETVpUM7AIXWbGs34fUNYl3Xzc4baSyvYbc3h6iz8AIdb_1bQLxJsHBi-ydg3NMJItgQJqBiwCmQYCOnJlekR-Ga2a5XlIx46Wsj3Pz0t0dzM8gVSU9fU3QrKKzDFCoFHTgig1YZNNW5W2H6QwANL5h-nbgre5sWmDmdnfiU6Pj5GOQDmp__rweinph8OAFNF6jVqrRZ3QJEmMnO42naWOsxV2FAUXafksQ"
    }
  ]
}
0.660808 ------------ RegistrationRequest ------------
0.661199 --> URL: https://connect.openid4.us/abop/op.php/registration
0.661206 --> BODY: {"subject_type": "pairwise", "jwks_uri": "https://op.certification.openid.net:60103/export/jwk_60103.json", "contacts": ["roland.hedberg at umu.se"], "application_type": "web", "grant_types": ["authorization_code"], "post_logout_redirect_uris": ["https://op.certification.openid.net:60103/logout"], "redirect_uris": ["https://op.certification.openid.net:60103/authz_cb", "https://op.certification.openid.net:60103/cb"], "response_types": ["code"], "require_auth_time": true, "default_max_age": 3600}
0.661215 --> HEADERS: {'Content-type': 'application/json'}
1.069207 <-- STATUS: 200
1.069306 <-- BODY: {"client_id":"mnbsEDdoWfknVJE_WQyh5w","client_secret":"SO5kU4GErOZLzw","registration_access_token":"SODmrxZa2CWOdg","registration_client_uri":"https:\/\/connect.openid4.us\/abop\/op.php\/client\/bflHb_r6v9hwatYnDHBXdg","client_id_issued_at":1426114008,"client_secret_expires_at":0,"registration_client_uri_path":"bflHb_r6v9hwatYnDHBXdg","contacts":["roland.hedberg at umu.se"],"application_type":"web","redirect_uris":["https:\/\/op.certification.openid.net:60103\/authz_cb","https:\/\/op.certification.openid.net:60103\/cb"],"post_logout_redirect_uris":["https:\/\/op.certification.openid.net:60103\/logout"],"jwks_uri":"https:\/\/op.certification.openid.net:60103\/export\/jwk_60103.json","subject_type":"pairwise","default_max_age":3600,"require_auth_time":true,"response_types":["code"],"grant_types":["authorization_code"]}
1.069977 RegistrationResponse: {
  "application_type": "web",
  "client_id": "mnbsEDdoWfknVJE_WQyh5w",
  "client_id_issued_at": 1426114008,
  "client_secret": "SO5kU4GErOZLzw",
  "client_secret_expires_at": 0,
  "contacts": [
    "roland.hedberg at umu.se"
  ],
  "default_max_age": 3600,
  "grant_types": [
    "authorization_code"
  ],
  "jwks_uri": "https://op.certification.openid.net:60103/export/jwk_60103.json",
  "post_logout_redirect_uris": [
    "https://op.certification.openid.net:60103/logout"
  ],
  "redirect_uris": [
    "https://op.certification.openid.net:60103/authz_cb",
    "https://op.certification.openid.net:60103/cb"
  ],
  "registration_access_token": "SODmrxZa2CWOdg",
  "registration_client_uri": "https://connect.openid4.us/abop/op.php/client/bflHb_r6v9hwatYnDHBXdg",
  "registration_client_uri_path": "bflHb_r6v9hwatYnDHBXdg",
  "require_auth_time": true,
  "response_types": [
    "code"
  ],
  "subject_type": "pairwise"
}
1.071374 ------------ AuthorizationRequest ------------
1.071978 --> URL: https://connect.openid4.us/abop/op.php/auth?scopes=openid&scopes=phone&state=Z9EVT7Lfv1dqUUiQ&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60103%2Fauthz_cb&response_type=code&client_id=mnbsEDdoWfknVJE_WQyh5w&scope=openid&claims=%7B%22id_token%22%3A+%7B%22email%22%3A+%22%7B%5C%22essential%5C%22%3A+true%7D%22%7D%7D
1.071986 --> BODY: None
4.315553 <-- state=Z9EVT7Lfv1dqUUiQ&session_state=0f8dc974525af1d56db7237f4cd3cd929ed9ca20cb6995918e5a7367408f04db.abbdbc22afbd147affbe8674f52b580e&code=pJYqezr9JbTU2sdo2POFf9quNnEDhHDAC3Yjc8kNwsY
4.315851 AuthorizationResponse: {
  "code": "pJYqezr9JbTU2sdo2POFf9quNnEDhHDAC3Yjc8kNwsY",
  "session_state": "0f8dc974525af1d56db7237f4cd3cd929ed9ca20cb6995918e5a7367408f04db.abbdbc22afbd147affbe8674f52b580e",
  "state": "Z9EVT7Lfv1dqUUiQ"
}
4.316171 ------------ AccessTokenRequest ------------
4.316494 --> URL: https://connect.openid4.us/abop/op.php/token
4.316500 --> BODY: code=pJYqezr9JbTU2sdo2POFf9quNnEDhHDAC3Yjc8kNwsY&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60103%2Fauthz_cb
4.316509 --> HEADERS: {'Content-type': 'application/x-www-form-urlencoded', 'Authorization': 'Basic bW5ic0VEZG9XZmtuVkpFX1dReWg1dzpTTzVrVTRHRXJPWkx6dw=='}
4.747286 <-- STATUS: 200
4.747408 <-- BODY: {"access_token":"29lzOl0RFWd-ibEHny2HmHkkqF448Pgj35kULB6XIpo","token_type":"Bearer","expires_in":3600,"id_token":"eyJhbGciOiJSUzI1NiIsImprdSI6Imh0dHBzOlwvXC9jb25uZWN0Lm9wZW5pZDQudXNcL2Nvbm5lY3Q0dXMuandrIiwia2lkIjoiQUJPUC0wMCJ9.eyJpc3MiOiJodHRwczpcL1wvY29ubmVjdC5vcGVuaWQ0LnVzIiwic3ViIjoiZDRkMTkzNjhkYmNiNGQ2Y2RiZDI4YzZmMjRmZjVlM2RlYjE1YzYyNTNhNTViZTcwNGFjOTI1NzAzNTI1YTM4YSIsImF1ZCI6WyJtbmJzRURkb1dma25WSkVfV1F5aDV3Il0sImV4cCI6MTQyNjExNDMxMiwiaWF0IjoxNDI2MTE0MDEyLCJhdXRoX3RpbWUiOjE0MjYxMTMwNTcsImVtYWlsIjoiYWxpY2VAd29uZGVybGFuZC5jb20ifQ.gn1huqxwwuDtAWOKSUadkjm6nHK-TEEAeRwwA5Xm4i0zxKyHvptdrNYloISAF3djqKtHv-Xg0QyEc7Ai_t0NAlMp0DHW1vD_oFqVkItGZyUgXQFsbUz3Gdc_IaVdqxZ3dlfYiJix1RoER2YnnJyVeIGicBPOoY5_7JnwdirBLlPN3NYYoTVl7UXIuykAqJ_C18-StDzQOJ8aJK-aP-Bx8Xu0OSAXJVjnZg1iMpddAdXEYU2YB9dPJXT34-NDxLTQKNiFN9HBwWwcsSX41PXiSz66dDuV4vALYg-P7BZsRI_3kP1SQGpvh6v329dym1TRgmXgu-iTI6Zle1Lo0n-FJw"}
5.079637 AccessTokenResponse: {
  "access_token": "29lzOl0RFWd-ibEHny2HmHkkqF448Pgj35kULB6XIpo",
  "expires_in": 3600,
  "id_token": {
    "aud": [
      "mnbsEDdoWfknVJE_WQyh5w"
    ],
    "auth_time": 1426113057,
    "email": "alice at wonderland.com",
    "exp": 1426114312,
    "iat": 1426114012,
    "iss": "https://connect.openid4.us",
    "sub": "d4d19368dbcb4d6cdbd28c6f24ff5e3deb15c6253a55be704ac925703525a38a"
  },
  "token_type": "Bearer"
}
5.080859 ------------ UserInfoRequest ------------
5.081126 --> URL: https://connect.openid4.us/abop/op.php/userinfo
5.081132 --> BODY: None
5.081141 --> HEADERS: {'Authorization': u'Bearer 29lzOl0RFWd-ibEHny2HmHkkqF448Pgj35kULB6XIpo'}
5.478573 <-- STATUS: 200
5.478627 Available verification keys: [(u'ABOP-00', u'RSA')]
5.478655 Available decryption keys: [('a0', 'RSA'), ('a3', 'EC')]
5.478744 <-- BODY: {"sub":"d4d19368dbcb4d6cdbd28c6f24ff5e3deb15c6253a55be704ac925703525a38a"}
5.479216 UserInfo: {
  "sub": "d4d19368dbcb4d6cdbd28c6f24ff5e3deb15c6253a55be704ac925703525a38a"
}
Result

PASSED
```




More information about the Openid-specs-ab mailing list