Test info

Profile: {'openid-configuration': 'config', 'response_type': 'code', 'crypto': 'none+sign', 'registration': 'static'}
Timestamp: 2015-04-10T01:36:33Z
Test description: ID Token has nonce when requested for code flow [Basic]
Test ID: OP-nonce-code
Issuer: https://openid.uni-id.info/express/

Test output


__AuthorizationRequest:pre__
[check-response-type]
	status: OK
	description: Checks that the asked for response type are among the supported
[check-endpoint]
	status: OK
	description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[verify-nonce]
	status: OK
	description: Verifies that the nonce recceived in the IDToken is the same as was given in the Authorization Request
[verify-response]
	status: OK
	description: Checks that the last response was one of a possible set of OpenID Connect Responses
__X:==== END ====__

Trace output


0.000306 ------------ DiscoveryRequest ------------
0.000317 Provider info discover from 'https://openid.uni-id.info/express/'
0.000324 --> URL: https://openid.uni-id.info/express/.well-known/openid-configuration
1.017003 ProviderConfigurationResponse: {
  "authorization_endpoint": "https://openid.uni-id.info/express/script/connect/authz_req/endpoint.seam",
  "claims_parameter_supported": false,
  "claims_supported": [
    "sub",
    "iss",
    "auth_time",
    "acr",
    "name",
    "given_name",
    "family_name",
    "nickname",
    "profile",
    "picture",
    "website",
    "email",
    "email_verified",
    "locale",
    "zoneinfo"
  ],
  "grant_types_supported": [
    "authorization_code",
    "implicit"
  ],
  "id_token_signing_alg_values_supported": [
    "RS256"
  ],
  "issuer": "https://openid.uni-id.info/express/",
  "jwks_uri": "https://openid.uni-id.info/express/script/connect/jwks/endpoint.seam",
  "request_parameter_supported": false,
  "request_uri_parameter_supported": true,
  "require_request_uri_registration": true,
  "response_types_supported": [
    "code",
    "token",
    "id_token",
    "code token",
    "code id_token",
    "token id_token",
    "code token id_token"
  ],
  "scopes_supported": [
    "openid",
    "email",
    "phone",
    "address",
    "profile"
  ],
  "subject_types_supported": [
    "pairwise"
  ],
  "token_endpoint": "https://openid.uni-id.info/express/script/connect/token_req/endpoint.seam",
  "token_endpoint_auth_methods_supported": [
    "client_secret_basic",
    "client_secret_post"
  ],
  "userinfo_endpoint": "https://openid.uni-id.info/express/script/connect/userinfo/endpoint.seam",
  "version": "3.0"
}
2.018111 JWKS: {
  "keys": [
    {
      "alg": "RS256",
      "e": "AQAB",
      "kid": "key1",
      "kty": "RSA",
      "n": "u8XnQhjM_rO43PGu6t2RHa6Y2hAGA63fjJfcyrrw9iu5Y3Xn7iQ3uJV93JL7RYmi55GtMB6PaRzBDckAQRVOHd8BoEPufX9567TpuThQRb2vL8ds1oL6X3p33C02HgU9rkBRGQHYi8oOaKtuUjXUeC-P-boFvHKLtvKbCbfX3Ys",
      "use": "sig"
    }
  ]
}
2.018909 ------------ AuthorizationRequest ------------
2.019300 --> URL: https://openid.uni-id.info/express/script/connect/authz_req/endpoint.seam?nonce=godmorgon&state=ENC0flZgSwZHKnCZ&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60239%2Fauthz_cb&response_type=code&client_id=https%3A%2F%2Fopenid.uni-id.info%2Fconnect_consumer%2F&scope=openid
2.019308 --> BODY: None
2.385416 <-- code=eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiTHZlb3FMcmh3akF5TWxZcUdKWDhnX1NWbUZEZndfbHEiLCJleHAiOjE0Mjg2MzM5NjEsImlhdCI6MTQyODYzMDM2MSwidG9rZW5UeXBlIjoiY29kZSIsInZlciI6IjEuMCJ9.&state=ENC0flZgSwZHKnCZ
2.385697 AuthorizationResponse: {
  "code": "eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiTHZlb3FMcmh3akF5TWxZcUdKWDhnX1NWbUZEZndfbHEiLCJleHAiOjE0Mjg2MzM5NjEsImlhdCI6MTQyODYzMDM2MSwidG9rZW5UeXBlIjoiY29kZSIsInZlciI6IjEuMCJ9.",
  "state": "ENC0flZgSwZHKnCZ"
}
2.386000 ------------ AccessTokenRequest ------------
2.386313 --> URL: https://openid.uni-id.info/express/script/connect/token_req/endpoint.seam
2.386320 --> BODY: code=eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiTHZlb3FMcmh3akF5TWxZcUdKWDhnX1NWbUZEZndfbHEiLCJleHAiOjE0Mjg2MzM5NjEsImlhdCI6MTQyODYzMDM2MSwidG9rZW5UeXBlIjoiY29kZSIsInZlciI6IjEuMCJ9.&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60239%2Fauthz_cb
2.386330 --> HEADERS: {'Content-type': 'application/x-www-form-urlencoded', 'Authorization': 'Basic aHR0cHM6Ly9vcGVuaWQudW5pLWlkLmluZm8vY29ubmVjdF9jb25zdW1lci86Y2xpZW50X3NlY3JldA=='}
3.545424 <-- STATUS: 200
3.545460 <-- BODY: {"scope":"openid","expires_in":1799,"token_type":"bearer","refresh_token":"eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiN2xXVG4xaEdEM2twbXZRNEN3NkxKR1VwcUtZN1NZeVYiLCJleHAiOjE0Mjg2NDgzNjIsImlhdCI6MTQyODYzMDM2MiwidG9rZW5UeXBlIjoicmVmcmVzaF90b2tlbiIsInZlciI6IjEuMCJ9.","access_token":"eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiN2xXVG4xaEdEM2twbXZRNEN3NkxKR1VwcUtZN1NZeVYiLCJleHAiOjE0Mjg2MzIxNjIsImlhdCI6MTQyODYzMDM2MiwidG9rZW5UeXBlIjoiYWNjZXNzX3Rva2VuIiwidmVyIjoiMS4wIn0.","id_token":"eyJhbGciOiJSUzI1NiIsImtpZCI6ImtleTEiLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJodHRwczovL29wZW5pZC51bmktaWQuaW5mby9jb25uZWN0X2NvbnN1bWVyLyIsImV4cCI6MTQyODYzMjE2MiwiaWF0IjoxNDI4NjMwMzYyLCJpc3MiOiJodHRwczovL29wZW5pZC51bmktaWQuaW5mby9leHByZXNzLyIsIm5vbmNlIjoiZ29kbW9yZ29uIiwic3ViIjoiMjg2WXdid211c0hienBqQnZDYTZ3U1oweUdYVGFDS0wiLCJ1c2VyX2lkIjoiMjg2WXdid211c0hienBqQnZDYTZ3U1oweUdYVGFDS0wifQ.uVhZb5wDrZ0igv0sT81-IB2Fc7gTdwDiODmQQnhvr5BkS9PnkjQiuDSIwBsRUvH6EQLxFdB7wnXCpeOOHTxDiPci8Bz2rfd3nCz4nWsl_kmx1HvW55nCzQ0zSEt2xbHTeTvedybli-ECUebP-F4znZc_wYGMpLZBdwGQQCYw7-U"}
4.554470 AccessTokenResponse: {
  "access_token": "eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiN2xXVG4xaEdEM2twbXZRNEN3NkxKR1VwcUtZN1NZeVYiLCJleHAiOjE0Mjg2MzIxNjIsImlhdCI6MTQyODYzMDM2MiwidG9rZW5UeXBlIjoiYWNjZXNzX3Rva2VuIiwidmVyIjoiMS4wIn0.",
  "expires_in": 1799,
  "id_token": {
    "claims": {
      "aud": [
        "https://openid.uni-id.info/connect_consumer/"
      ],
      "exp": 1428632162,
      "iat": 1428630362,
      "iss": "https://openid.uni-id.info/express/",
      "nonce": "godmorgon",
      "sub": "286YwbwmusHbzpjBvCa6wSZ0yGXTaCKL",
      "user_id": "286YwbwmusHbzpjBvCa6wSZ0yGXTaCKL"
    },
    "jws header parameters": {
      "alg": "RS256",
      "kid": "key1",
      "typ": "JWT"
    }
  },
  "refresh_token": "eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJjb2RlIjoiN2xXVG4xaEdEM2twbXZRNEN3NkxKR1VwcUtZN1NZeVYiLCJleHAiOjE0Mjg2NDgzNjIsImlhdCI6MTQyODYzMDM2MiwidG9rZW5UeXBlIjoicmVmcmVzaF90b2tlbiIsInZlciI6IjEuMCJ9.",
  "scope": "openid",
  "token_type": "bearer"
}
4.555603 ==== END ====

Result

PASSED