Test Info

Issuerhttps://oidc-conformance.ping-eng.com:9031
Profile[]
Test IDOP-OAuth-2nd-Revokes
Test descriptionTrying to use authorization code twice should result in revoking previously issued access tokens
Timestamp2018-09-21T17:16:02Z

Conditions


verify-response: status=WARNING, message=Got a OpenIDSchema response !? [Checks that the last response was one of a possible set of OpenID Connect Responses]
Done: status=OK

Trace Output

0.0phase<--<-- 0 --- Webfinger -->-->
0.0not expected to doWebFinger
0.0phase<--<-- 1 --- Discovery -->-->
0.0not expected to doDynamic discovery
0.001phase<--<-- 2 --- Registration -->-->
0.001register
kwargs:{'response_types': ['code id_token'], 'grant_types': ['authorization_code', 'implicit'], 'application_name': 'OIC test tool', 'application_type': 'web', 'redirect_uris': ['https://op.certification.openid.net:61401/authz_cb'], 'contacts': ['roland@example.com'], 'post_logout_redirect_uris': ['https://op.certification.openid.net:61401/logout'], 'url': 'https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2', 'jwks_uri': 'https://op.certification.openid.net:61401/static/jwks_61401.json'}
0.001RegistrationRequest
{
    "application_type": "web",
    "contacts": [
        "roland@example.com"
    ],
    "grant_types": [
        "implicit",
        "authorization_code"
    ],
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "post_logout_redirect_uris": [
        "https://op.certification.openid.net:61401/logout"
    ],
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "request_uris": [
        "https://op.certification.openid.net:61401/requests/876669ef2b3891075309a06e00b98e6ace4cfca108af01becb9a804fff95d8c4#5McAEKVTkQbMfK43"
    ],
    "response_types": [
        "code id_token"
    ]
}
0.319http response
url:https://oidc-conformance.ping-eng.com:9031/as/clients.oauth2 status_code:201
0.32RegistrationResponse
{
    "client_id": "dc-uvFVLSDqDCxDuDyT2VdRKo",
    "client_name": "dc-uvFVLSDqDCxDuDyT2VdRKo",
    "client_secret": "O6XK2aeWew0Dapv67Ykn4O",
    "client_secret_expires_at": 0,
    "grant_access_session_revocation_api": false,
    "grant_types": [
        "implicit",
        "authorization_code"
    ],
    "jwks_uri": "https://op.certification.openid.net:61401/static/jwks_61401.json",
    "persistent_grant_expiration_type": "server_default",
    "pingaccess_logout_capable": false,
    "redirect_uris": [
        "https://op.certification.openid.net:61401/authz_cb"
    ],
    "refresh_token_rolling_policy": "server_default",
    "response_types": [
        "code id_token"
    ],
    "scope": "address phone edit openid profile admin email",
    "token_endpoint_auth_method": "client_secret_basic",
    "validate_using_all_eligible_atms": false
}
0.32phase<--<-- 3 --- Note -->-->
4.063phase<--<-- 4 --- AsyncAuthn -->-->
4.064AuthorizationRequest
{
    "client_id": "dc-uvFVLSDqDCxDuDyT2VdRKo",
    "nonce": "EphPyLsnfL8YQ4st",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "response_type": "code id_token",
    "scope": "openid",
    "state": "9e0mYHzX0RevVqkx"
}
4.064redirect urlhttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=9e0mYHzX0RevVqkx&nonce=EphPyLsnfL8YQ4st&response_type=code+id_token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-uvFVLSDqDCxDuDyT2VdRKo
4.064redirecthttps://oidc-conformance.ping-eng.com:9031/as/authorization.oauth2?state=9e0mYHzX0RevVqkx&nonce=EphPyLsnfL8YQ4st&response_type=code+id_token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&client_id=dc-uvFVLSDqDCxDuDyT2VdRKo
5.694http args{}
6.022responseURL with fragment
6.022responsecode=L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O&id_token=eyJhbGciOiJSUzI1NiIsImtpZCI6InExa19WZW9TcXRKX0Y1Y2ZlRXRRRkJHcW1LOCJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy11dkZWTFNEcURDeER1RHlUMlZkUktvIiwianRpIjoibXY1RlVHbXpMWUdqbmFBdk1oaDlDZCIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzU1MDE2MSwiZXhwIjoxNTM3NTUwNDYxLCJwaS5zcmkiOiJLZnJxQmNBazFabkVrMXN4eE5qN0JRdzJpbmMiLCJub25jZSI6IkVwaFB5THNuZkw4WVE0c3QiLCJhdXRoX3RpbWUiOjE1Mzc1NDk3MDEsImNfaGFzaCI6IlY2ajVHVndVQlR2OHZ5WXR0Wk9GalEiLCJzX2hhc2giOiJoeXoxZzV5Rmxxb2V1RFp3bmRPT2pRIn0.inyWpOSF9aQ0Mb1eFoBltVJ5KPqsDzY1OC_yqjxVyCrt-scPpvJOuaE-0QRu6zXq6jMTyPDBsehrf5zQcx0oUpd2YH1UA7aSBoxpd4f9JSOEdL5BVFXCsgJCtVG4hYcJlA9zPE9CbimZEDnhblhxP5VQVW77s5t365SSnBpJNvc17YL_fha_i_TcK6XLcgTG0WP0C0zHfQ-VsqQg-WdH_l1UKvTQl2lrEKCLQsYvXFh0wyaWL81T-Onif8XKDyCV9XrDZT9Jg2k0c5twDho1qUKUO6G-hp7v6-OxmDpk3CynD10zqCnG5LaPLcvqyfOOBeVr5Kvsh1UYKeLzw8mo6g&state=9e0mYHzX0RevVqkx
6.023response{'code': 'L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6InExa19WZW9TcXRKX0Y1Y2ZlRXRRRkJHcW1LOCJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy11dkZWTFNEcURDeER1RHlUMlZkUktvIiwianRpIjoibXY1RlVHbXpMWUdqbmFBdk1oaDlDZCIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzU1MDE2MSwiZXhwIjoxNTM3NTUwNDYxLCJwaS5zcmkiOiJLZnJxQmNBazFabkVrMXN4eE5qN0JRdzJpbmMiLCJub25jZSI6IkVwaFB5THNuZkw4WVE0c3QiLCJhdXRoX3RpbWUiOjE1Mzc1NDk3MDEsImNfaGFzaCI6IlY2ajVHVndVQlR2OHZ5WXR0Wk9GalEiLCJzX2hhc2giOiJoeXoxZzV5Rmxxb2V1RFp3bmRPT2pRIn0.inyWpOSF9aQ0Mb1eFoBltVJ5KPqsDzY1OC_yqjxVyCrt-scPpvJOuaE-0QRu6zXq6jMTyPDBsehrf5zQcx0oUpd2YH1UA7aSBoxpd4f9JSOEdL5BVFXCsgJCtVG4hYcJlA9zPE9CbimZEDnhblhxP5VQVW77s5t365SSnBpJNvc17YL_fha_i_TcK6XLcgTG0WP0C0zHfQ-VsqQg-WdH_l1UKvTQl2lrEKCLQsYvXFh0wyaWL81T-Onif8XKDyCV9XrDZT9Jg2k0c5twDho1qUKUO6G-hp7v6-OxmDpk3CynD10zqCnG5LaPLcvqyfOOBeVr5Kvsh1UYKeLzw8mo6g', 'state': '9e0mYHzX0RevVqkx'}
6.33AuthorizationResponse
{
    "code": "L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O",
    "id_token": {
        "aud": [
            "dc-uvFVLSDqDCxDuDyT2VdRKo"
        ],
        "auth_time": 1537549701,
        "c_hash": "V6j5GVwUBTv8vyYttZOFjQ",
        "exp": 1537550461,
        "iat": 1537550161,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "mv5FUGmzLYGjnaAvMhh9Cd",
        "nonce": "EphPyLsnfL8YQ4st",
        "pi.sri": "KfrqBcAk1ZnEk1sxxNj7BQw2inc",
        "s_hash": "hyz1g5yFlqoeuDZwndOOjQ",
        "sub": "joe"
    },
    "state": "9e0mYHzX0RevVqkx"
}
6.33phase<--<-- 5 --- AccessToken -->-->
6.33requestop_args: {'state': '9e0mYHzX0RevVqkx'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb'}
6.33do_access_token_request
kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb', 'code': 'L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O', 'state': '9e0mYHzX0RevVqkx', 'grant_type': 'authorization_code', 'client_id': 'dc-uvFVLSDqDCxDuDyT2VdRKo'}, 'state': '9e0mYHzX0RevVqkx'}
6.33AccessTokenRequest
{
    "code": "L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O",
    "grant_type": "authorization_code",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "state": "9e0mYHzX0RevVqkx"
}
6.331request_urlhttps://oidc-conformance.ping-eng.com:9031/as/token.oauth2
6.331request_http_args{'headers': {'Authorization': 'Basic ZGMtdXZGVkxTRHFEQ3hEdUR5VDJWZFJLbzpPNlhLMmFlV2V3MERhcHY2N1lrbjRP', 'Content-Type': 'application/x-www-form-urlencoded'}}
6.331requestgrant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&code=L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O&state=9e0mYHzX0RevVqkx
6.681http response
url:https://oidc-conformance.ping-eng.com:9031/as/token.oauth2 status_code:200
6.682response{'access_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy11dkZWTFNEcURDeER1RHlUMlZkUktvIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1NzM2Mn0.FMOyyPkg0F36SJOgklD-k9_rDQXrWmqfkiqL2KUnr5ckZkxl5AiEtWbGYVcU7GfKd8Z6R95mh9NDQnq85uqqHpyFBa79VjFgOPIm6cr7l0yY6mUU1Bz31tSIDswLNLtbJ5hTxlwTnIBhMB9yBQRdvkYU-9JRMMwCLywv60mZB_fBfwvTR_GabN-37WHrdTH-nwgU6FI_XNIMR6ANAkOIFBbXOt1IdGebN8OWO8DQr2Kfoz77x2i9IGg2FmmD2DyyQLT5CdBhwK8KaKNToCvmgm0cs8bb_hCK0X7W9UZ6t9_kiJrMWsoIIIkCZai8lBp0b4WDX4RRQdB5HPf8iUdJ-A', 'id_token': 'eyJhbGciOiJSUzI1NiIsImtpZCI6InExa19WZW9TcXRKX0Y1Y2ZlRXRRRkJHcW1LOCJ9.eyJzdWIiOiJqb2UiLCJhdWQiOiJkYy11dkZWTFNEcURDeER1RHlUMlZkUktvIiwianRpIjoibXY1RlVHbXpMWUdqbmFBdk1oaDlDZCIsImlzcyI6Imh0dHBzOi8vb2lkYy1jb25mb3JtYW5jZS5waW5nLWVuZy5jb206OTAzMSIsImlhdCI6MTUzNzU1MDE2MSwiZXhwIjoxNTM3NTUwNDYxLCJwaS5zcmkiOiJLZnJxQmNBazFabkVrMXN4eE5qN0JRdzJpbmMiLCJub25jZSI6IkVwaFB5THNuZkw4WVE0c3QiLCJhdXRoX3RpbWUiOjE1Mzc1NDk3MDEsImNfaGFzaCI6IlY2ajVHVndVQlR2OHZ5WXR0Wk9GalEiLCJzX2hhc2giOiJoeXoxZzV5Rmxxb2V1RFp3bmRPT2pRIn0.inyWpOSF9aQ0Mb1eFoBltVJ5KPqsDzY1OC_yqjxVyCrt-scPpvJOuaE-0QRu6zXq6jMTyPDBsehrf5zQcx0oUpd2YH1UA7aSBoxpd4f9JSOEdL5BVFXCsgJCtVG4hYcJlA9zPE9CbimZEDnhblhxP5VQVW77s5t365SSnBpJNvc17YL_fha_i_TcK6XLcgTG0WP0C0zHfQ-VsqQg-WdH_l1UKvTQl2lrEKCLQsYvXFh0wyaWL81T-Onif8XKDyCV9XrDZT9Jg2k0c5twDho1qUKUO6G-hp7v6-OxmDpk3CynD10zqCnG5LaPLcvqyfOOBeVr5Kvsh1UYKeLzw8mo6g', 'token_type': 'Bearer', 'expires_in': 7199}
6.685AccessTokenResponse
{
    "access_token": "eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy11dkZWTFNEcURDeER1RHlUMlZkUktvIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1NzM2Mn0.FMOyyPkg0F36SJOgklD-k9_rDQXrWmqfkiqL2KUnr5ckZkxl5AiEtWbGYVcU7GfKd8Z6R95mh9NDQnq85uqqHpyFBa79VjFgOPIm6cr7l0yY6mUU1Bz31tSIDswLNLtbJ5hTxlwTnIBhMB9yBQRdvkYU-9JRMMwCLywv60mZB_fBfwvTR_GabN-37WHrdTH-nwgU6FI_XNIMR6ANAkOIFBbXOt1IdGebN8OWO8DQr2Kfoz77x2i9IGg2FmmD2DyyQLT5CdBhwK8KaKNToCvmgm0cs8bb_hCK0X7W9UZ6t9_kiJrMWsoIIIkCZai8lBp0b4WDX4RRQdB5HPf8iUdJ-A",
    "expires_in": 7199,
    "id_token": {
        "aud": [
            "dc-uvFVLSDqDCxDuDyT2VdRKo"
        ],
        "auth_time": 1537549701,
        "c_hash": "V6j5GVwUBTv8vyYttZOFjQ",
        "exp": 1537550461,
        "iat": 1537550161,
        "iss": "https://oidc-conformance.ping-eng.com:9031",
        "jti": "mv5FUGmzLYGjnaAvMhh9Cd",
        "nonce": "EphPyLsnfL8YQ4st",
        "pi.sri": "KfrqBcAk1ZnEk1sxxNj7BQw2inc",
        "s_hash": "hyz1g5yFlqoeuDZwndOOjQ",
        "sub": "joe"
    },
    "token_type": "Bearer"
}
6.685phase<--<-- 6 --- AccessToken -->-->
6.685requestop_args: {'state': '9e0mYHzX0RevVqkx'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb'}
6.685do_access_token_request
kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61401/authz_cb', 'code': 'L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O', 'state': '9e0mYHzX0RevVqkx', 'grant_type': 'authorization_code', 'client_id': 'dc-uvFVLSDqDCxDuDyT2VdRKo'}, 'state': '9e0mYHzX0RevVqkx'}
6.685AccessTokenRequest
{
    "code": "L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O",
    "grant_type": "authorization_code",
    "redirect_uri": "https://op.certification.openid.net:61401/authz_cb",
    "state": "9e0mYHzX0RevVqkx"
}
6.685request_urlhttps://oidc-conformance.ping-eng.com:9031/as/token.oauth2
6.685request_http_args{'headers': {'Authorization': 'Basic ZGMtdXZGVkxTRHFEQ3hEdUR5VDJWZFJLbzpPNlhLMmFlV2V3MERhcHY2N1lrbjRP', 'Content-Type': 'application/x-www-form-urlencoded'}}
6.685requestgrant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61401%2Fauthz_cb&code=L0fJCBs4qyh5goOdnTdUY8WQwJciy06YK8dZeT9O&state=9e0mYHzX0RevVqkx
7.044http response
url:https://oidc-conformance.ping-eng.com:9031/as/token.oauth2 status_code:400 message:{"error_description":"Authorization code is invalid or expired.","error":"invalid_grant"}
7.045response{'error_description': 'Authorization code is invalid or expired.', 'error': 'invalid_grant'}
7.045eventGot expected error
7.045TokenErrorResponse
{
    "error": "invalid_grant",
    "error_description": "Authorization code is invalid or expired."
}
7.045phase<--<-- 7 --- UserInfo -->-->
7.045do_user_info_request
kwargs:{'state': '9e0mYHzX0RevVqkx', 'method': 'GET', 'authn_method': 'bearer_header'}
7.045request{'body': None}
7.045request_urlhttps://oidc-conformance.ping-eng.com:9031/idp/userinfo.openid
7.045request_http_args{'headers': {'Authorization': 'Bearer eyJhbGciOiJSUzI1NiIsImtpZCI6ImsxIn0.eyJzY29wZSI6WyJvcGVuaWQiXSwiY2xpZW50X2lkX25hbWUiOiJkYy11dkZWTFNEcURDeER1RHlUMlZkUktvIiwiVXNlcm5hbWUiOiJqb2UiLCJPcmdOYW1lIjoiUGluZyBJZGVudGl0eSBDb3Jwb3JhdGlvbiIsImV4cCI6MTUzNzU1NzM2Mn0.FMOyyPkg0F36SJOgklD-k9_rDQXrWmqfkiqL2KUnr5ckZkxl5AiEtWbGYVcU7GfKd8Z6R95mh9NDQnq85uqqHpyFBa79VjFgOPIm6cr7l0yY6mUU1Bz31tSIDswLNLtbJ5hTxlwTnIBhMB9yBQRdvkYU-9JRMMwCLywv60mZB_fBfwvTR_GabN-37WHrdTH-nwgU6FI_XNIMR6ANAkOIFBbXOt1IdGebN8OWO8DQr2Kfoz77x2i9IGg2FmmD2DyyQLT5CdBhwK8KaKNToCvmgm0cs8bb_hCK0X7W9UZ6t9_kiJrMWsoIIIkCZai8lBp0b4WDX4RRQdB5HPf8iUdJ-A'}}
7.373http response
url:https://oidc-conformance.ping-eng.com:9031/idp/userinfo.openid status_code:200
7.374eventExpected error not received
7.374OpenIDSchema
{
    "sub": "joe"
}
7.374OpenIDSchema
{
    "sub": "joe"
}
7.374phase<--<-- 8 --- Done -->-->
7.374end
7.374assertionVerifyResponse
7.374conditionverify-response: status=WARNING, message=Got a OpenIDSchema response !? [Checks that the last response was one of a possible set of OpenID Connect Responses]
7.374conditionDone: status=OK

Result

WARNING
Warnings:
Got a OpenIDSchema response !?