0 | phase | <--<-- 0 --- Note -->--> |
1 | phase | <--<-- 1 --- Webfinger -->--> |
1 | not expected to do | WebFinger |
1 | phase | <--<-- 2 --- Discovery -->--> |
1 | provider_config | kwargs:{'issuer': 'https://isamfed.com:30443/test'}
|
1 | http response | url:https://isamfed.com:30443/test/.well-known/openid-configuration status_code:200
|
1 | ProviderConfigurationResponse | {
"authorization_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/authorize",
"claims_parameter_supported": false,
"claims_supported": [
"realmName",
"preferred_username",
"given_name",
"uid",
"upn",
"groupIds",
"employee_id",
"name",
"tenantId",
"mobile_number",
"department",
"job_title",
"family_name",
"email"
],
"device_authorize_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/device_authorize",
"grant_types_supported": [
"urn:ietf:params:oauth:grant-type:jwt-bearer",
"implicit",
"urn:ietf:params:oauth:grant-type:saml2-bearer",
"urn:ietf:params:oauth:grant-type:device_code",
"client_credentials",
"password",
"authorization_code",
"refresh_token"
],
"id_token_encryption_alg_values_supported": [
"RSA-OAEP-256"
],
"id_token_encryption_enc_values_supported": [
"A128CBC-HS256"
],
"id_token_signing_alg_values_supported": [
"RS256"
],
"introspect_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/introspect",
"issuer": "https://isamfed.com:30443/test",
"jwks_uri": "https://isamfed.com:30443/mga/sps/jwks",
"name": "OIDCDefinition",
"poc": "https://isamfed.com:30443/mga/",
"registration_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/register/OIDCDefinition",
"request_parameter_supported": true,
"request_uri_parameter_supported": true,
"require_request_uri_registration": false,
"response_modes_supported": [
"fragment",
"form_post"
],
"response_types_supported": [
"token",
"id_token",
"token id_token",
"code",
"code id_token",
"code token id_token",
"code token",
"none"
],
"revocation_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/revoke",
"subject_types_supported": [
"public"
],
"token_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/token",
"token_endpoint_auth_methods_supported": [
"private_key_jwt",
"client_secret_post",
"client_secret_basic"
],
"user_authorize_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/user_authorize",
"userinfo_endpoint": "https://isamfed.com:30443/mga/sps/oauth/oauth20/userinfo",
"userinfo_signing_alg_values_supported": [
"RS256"
],
"version": "3.0"
}
|
1 | phase | <--<-- 3 --- Registration -->--> |
1 | register | kwargs:{'response_types': ['code id_token token'], 'grant_types': ['authorization_code', 'implicit'], 'application_name': 'OIC test tool', 'application_type': 'web', 'redirect_uris': ['https://op.certification.openid.net:61737/authz_cb'], 'contacts': ['roland@example.com'], 'post_logout_redirect_uris': ['https://op.certification.openid.net:61737/logout'], 'url': 'https://isamfed.com:30443/mga/sps/oauth/oauth20/register/OIDCDefinition', 'jwks_uri': 'https://op.certification.openid.net:61737/static/jwks_61737.json', 'token_endpoint_auth_method': 'private_key_jwt'}
|
1 | RegistrationRequest | {
"application_type": "web",
"contacts": [
"roland@example.com"
],
"grant_types": [
"authorization_code",
"implicit"
],
"jwks_uri": "https://op.certification.openid.net:61737/static/jwks_61737.json",
"post_logout_redirect_uris": [
"https://op.certification.openid.net:61737/logout"
],
"redirect_uris": [
"https://op.certification.openid.net:61737/authz_cb"
],
"response_types": [
"code id_token token"
],
"token_endpoint_auth_method": "private_key_jwt"
}
|
1 | http response | url:https://isamfed.com:30443/mga/sps/oauth/oauth20/register/OIDCDefinition status_code:200
|
1 | RegistrationResponse | {
"application_type": "web",
"client_id": "Mm8fMZvHoFLHAz4sdIUc",
"client_id_issued_at": 1560784058,
"client_secret": "qlNoJ2ktoqpEpfXY8b5u",
"client_secret_expires_at": 0,
"contacts": [
"roland@example.com"
],
"grant_types": [
"authorization_code",
"implicit"
],
"jwks_uri": "https://op.certification.openid.net:61737/static/jwks_61737.json",
"post_logout_redirect_uris": [
"https://op.certification.openid.net:61737/logout"
],
"redirect_uris": [
"https://op.certification.openid.net:61737/authz_cb"
],
"registration_access_token": "k8MyZZvG1kCXRtCOG2H4",
"registration_client_uri": "https://isamfed.com:30443/mga/sps/oauth/oauth20/register/OIDCDefinition?client_id=Mm8fMZvHoFLHAz4sdIUc",
"response_types": [
"code",
"id_token",
"token"
],
"token_endpoint_auth_method": "private_key_jwt"
}
|
1 | phase | <--<-- 4 --- AsyncAuthn -->--> |
1 | AuthorizationRequest | {
"client_id": "Mm8fMZvHoFLHAz4sdIUc",
"nonce": "NHSb9f7U2G8Fcwhe",
"redirect_uri": "https://op.certification.openid.net:61737/authz_cb",
"response_type": "code id_token token",
"scope": "openid",
"state": "3Pxa4qZ2vfdCKD6f"
}
|
1 | redirect url | https://isamfed.com:30443/mga/sps/oauth/oauth20/authorize?state=3Pxa4qZ2vfdCKD6f&nonce=NHSb9f7U2G8Fcwhe&response_type=code+id_token+token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61737%2Fauthz_cb&client_id=Mm8fMZvHoFLHAz4sdIUc |
1 | redirect | https://isamfed.com:30443/mga/sps/oauth/oauth20/authorize?state=3Pxa4qZ2vfdCKD6f&nonce=NHSb9f7U2G8Fcwhe&response_type=code+id_token+token&scope=openid&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61737%2Fauthz_cb&client_id=Mm8fMZvHoFLHAz4sdIUc |
2 | http args | {} |
3 | response | URL with fragment |
3 | response | access_token=L1AiFby4sDdVPQ1BeRpE&state=3Pxa4qZ2vfdCKD6f&expires_in=3599&token_type=bearer&code=NFvXz1uIvtkgyujIXseHjHFo4SZTT6&scope=openid&id_token=eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2Iiwia2lkIjoiZ3RINHYzWXIyUXFMcmVCU3owQnlRUTh2a2Y4ZUZvMUtJaXQzcy0zQmJ3dyIsImN0eSI6IkpXVCJ9.KTMH2a7h07OWPGnK_y6e0hlYEW2nM7xUBq_r7sPWc8XizpTS6TPbFdsTJzymVEscjQmsl1DeIDe_AZmfeELPQ2IRHRVgj-IFNptOlvrBqBHqY6C9hGQUmmvsy12QTMz5JDLmQuUfDOFnYxQlzHz9ETYpTXQc2U6j1OH7IDnQuKe67-ETZd3TNgAwEC3c12yITpXT5QF7mioHfsiEhz2W3ynjmvBPbMF1_7FkVilGHdPPdy1F--uVhOCYHE838Onu3_LJM1qKekvmtkGgb3XfVuBHPsgf-vc-kKWWbTkUTFQsqINsFPGERqbS8oamf4OSO5-_h-IbnkRpcQDNd1HjSA.Yeb0zIFbwWWlVO-UawPHkQ.glP2rNIfXtu-fXNdHpyy5taIkL0OQlzQGdPNtf1rVmg1T91Uto7rj2lLI2BakHB5EuQPzmQLKPkecKpgI2mbSwPlcO4Anhn132QAOTuJ2HtIuRrGvBiCrGRgmvFbJDB7T_cQYYBYyjfu_iqL8IqVTz0HmtrW-byGgzPKDaAiowzBmbOgXsXwV6Qk9AfzRZ7LRUOIypjti7RGnQK8QVqtFK25s4DaZZNU_T_MWgFAMa5BiVuovybfPpETYP3rMJOiTmEWM1aXnopXciL555T5jrpUjH8aWXbpvH6tTrAAEbr5WB8CV892IEkV4Dvo5MWlXoLoyuEHi_eHlV6-0i1mXLNro3FSMn-c6AkHQvUQJ839JYKeL5lSauilyNh6QL9tHu5RSybIG5qYyZrp2d1hnQuRmfxiNo6Zdw3Kcke3Zv4dIs5I745hMInEo1ULZ-f_CaZcy0lk-SgI1mlnSRi8bPE-DfP2rNP5tFB-ZuzGW41KuVMOTGG-vwi4gpmacmSKjdE_QLCzwDHq8blIWklwUo1ArGaJ4FUsYKpy9f1JzLV7y1WXqIozI9jlOU0_5iepoUxROkjC7yW5YdE-QQgBfZMqBVmRZFuAM0rIvFDCEWdtcdcUizPV0EwZ3qf48vV_5PyolQ_JPnAR6rXHaPW2OntuwNHK-C4mabDRc9jmWEeEJi3YGSRP1ARfoCnvceHhf2e7Z_a7g0TGRt813uHQcEJZiQq99PSHcce27ClMurcUXcr8ML4f8fj5jRvVQXh7_4qolQt1PRnKSIrJs4250uNq_C7cn8cimfFbZBMzLXQ8OrrdQQkn48A5aayz7kQDQ4WCJc-MaJ9ZRxrJU3BoOcZMf4WO2zVxxH1OnEokg470z2mNumgUzKtotmAoB563Oa9mnorJO32QqVBOCv9pqKv-eS1tXS_WyYYacVOTxx6eRqlXrsP3CxM-zl8fIjP6MdLDqNtjlRMv4ntoEcsjSg.q_tJrJG3v_eNEJWfxdZXEw |
3 | response | {'access_token': 'L1AiFby4sDdVPQ1BeRpE', 'state': '3Pxa4qZ2vfdCKD6f', 'expires_in': 3599, 'token_type': 'bearer', 'code': 'NFvXz1uIvtkgyujIXseHjHFo4SZTT6', 'scope': 'openid', 'id_token': 'eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2Iiwia2lkIjoiZ3RINHYzWXIyUXFMcmVCU3owQnlRUTh2a2Y4ZUZvMUtJaXQzcy0zQmJ3dyIsImN0eSI6IkpXVCJ9.KTMH2a7h07OWPGnK_y6e0hlYEW2nM7xUBq_r7sPWc8XizpTS6TPbFdsTJzymVEscjQmsl1DeIDe_AZmfeELPQ2IRHRVgj-IFNptOlvrBqBHqY6C9hGQUmmvsy12QTMz5JDLmQuUfDOFnYxQlzHz9ETYpTXQc2U6j1OH7IDnQuKe67-ETZd3TNgAwEC3c12yITpXT5QF7mioHfsiEhz2W3ynjmvBPbMF1_7FkVilGHdPPdy1F--uVhOCYHE838Onu3_LJM1qKekvmtkGgb3XfVuBHPsgf-vc-kKWWbTkUTFQsqINsFPGERqbS8oamf4OSO5-_h-IbnkRpcQDNd1HjSA.Yeb0zIFbwWWlVO-UawPHkQ.glP2rNIfXtu-fXNdHpyy5taIkL0OQlzQGdPNtf1rVmg1T91Uto7rj2lLI2BakHB5EuQPzmQLKPkecKpgI2mbSwPlcO4Anhn132QAOTuJ2HtIuRrGvBiCrGRgmvFbJDB7T_cQYYBYyjfu_iqL8IqVTz0HmtrW-byGgzPKDaAiowzBmbOgXsXwV6Qk9AfzRZ7LRUOIypjti7RGnQK8QVqtFK25s4DaZZNU_T_MWgFAMa5BiVuovybfPpETYP3rMJOiTmEWM1aXnopXciL555T5jrpUjH8aWXbpvH6tTrAAEbr5WB8CV892IEkV4Dvo5MWlXoLoyuEHi_eHlV6-0i1mXLNro3FSMn-c6AkHQvUQJ839JYKeL5lSauilyNh6QL9tHu5RSybIG5qYyZrp2d1hnQuRmfxiNo6Zdw3Kcke3Zv4dIs5I745hMInEo1ULZ-f_CaZcy0lk-SgI1mlnSRi8bPE-DfP2rNP5tFB-ZuzGW41KuVMOTGG-vwi4gpmacmSKjdE_QLCzwDHq8blIWklwUo1ArGaJ4FUsYKpy9f1JzLV7y1WXqIozI9jlOU0_5iepoUxROkjC7yW5YdE-QQgBfZMqBVmRZFuAM0rIvFDCEWdtcdcUizPV0EwZ3qf48vV_5PyolQ_JPnAR6rXHaPW2OntuwNHK-C4mabDRc9jmWEeEJi3YGSRP1ARfoCnvceHhf2e7Z_a7g0TGRt813uHQcEJZiQq99PSHcce27ClMurcUXcr8ML4f8fj5jRvVQXh7_4qolQt1PRnKSIrJs4250uNq_C7cn8cimfFbZBMzLXQ8OrrdQQkn48A5aayz7kQDQ4WCJc-MaJ9ZRxrJU3BoOcZMf4WO2zVxxH1OnEokg470z2mNumgUzKtotmAoB563Oa9mnorJO32QqVBOCv9pqKv-eS1tXS_WyYYacVOTxx6eRqlXrsP3CxM-zl8fIjP6MdLDqNtjlRMv4ntoEcsjSg.q_tJrJG3v_eNEJWfxdZXEw'} |
3 | AuthorizationResponse | {
"access_token": "L1AiFby4sDdVPQ1BeRpE",
"code": "NFvXz1uIvtkgyujIXseHjHFo4SZTT6",
"expires_in": 3599,
"id_token": {
"at_hash": "nn_nSOUhl1ziLnNUi3V1Ug",
"aud": [
"Mm8fMZvHoFLHAz4sdIUc"
],
"c_hash": "12NEfzQ0vVmE8wRxOK1K8A",
"exp": 1560787479,
"iat": 1560784059,
"iss": "https://isamfed.com:30443/test",
"nonce": "NHSb9f7U2G8Fcwhe",
"sub": "testuser"
},
"scope": "openid",
"state": "3Pxa4qZ2vfdCKD6f",
"token_type": "bearer"
}
|
3 | phase | <--<-- 5 --- AccessToken -->--> |
3 | request | op_args: {'state': '3Pxa4qZ2vfdCKD6f'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61737/authz_cb'} |
3 | do_access_token_request | kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61737/authz_cb', 'code': 'NFvXz1uIvtkgyujIXseHjHFo4SZTT6', 'state': '3Pxa4qZ2vfdCKD6f', 'grant_type': 'authorization_code', 'client_id': 'Mm8fMZvHoFLHAz4sdIUc'}, 'state': '3Pxa4qZ2vfdCKD6f', 'authn_method': 'private_key_jwt'}
|
3 | AccessTokenRequest | {
"client_assertion": "eyJhbGciOiJSUzI1NiIsImtpZCI6Ind0MjVPZ3lSX256RzNPb1E3ZGFhMnJMNi1nTW5GZGZSekJqaFVWUHU4UlEifQ.eyJpc3MiOiAiTW04Zk1adkhvRkxIQXo0c2RJVWMiLCAic3ViIjogIk1tOGZNWnZIb0ZMSEF6NHNkSVVjIiwgImF1ZCI6IFsiaHR0cHM6Ly9pc2FtZmVkLmNvbTozMDQ0My9tZ2Evc3BzL29hdXRoL29hdXRoMjAvdG9rZW4iXSwgImp0aSI6ICJGNFNBVWJyWDBHN0tMeFdRNm05eXQ2Y2ZRd3dJYTJNdiIsICJleHAiOiAxNTYwNzg0NjYwLCAiaWF0IjogMTU2MDc4NDA2MH0.SZcMYzWsZubAZ8l5uqw0O4qrzLbIPxK3YnTbwtkny_pQ48rNBJanRsCwh-Ed5NKKF7Oz5UboidjU5Yc4IgJnv2PSylOJgXh_A56yyXiOouLkkAf09kVN9JtU5cDo8w8_TK-C3hhvaJ-EstQTlf6eD2Fo36s-GIKEZ3T01n-TzoheHKvqZyWWWlGBO03YhTzqnQlHHpWWYIno4A9eh-ViNGf_SQdwhi1FzGQeL-koPiiePsN9OGU4DkyxgAEnWe21IJjwUou78rHz5_SYkXdHt92WF_2kji-E18ZhHWZShoYkN1Q0P6pzSmdkNGB6TGflKCHvQLLsXS9y3txNNHLv4A",
"client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer",
"code": "NFvXz1uIvtkgyujIXseHjHFo4SZTT6",
"grant_type": "authorization_code",
"redirect_uri": "https://op.certification.openid.net:61737/authz_cb",
"state": "3Pxa4qZ2vfdCKD6f"
}
|
3 | request_url | https://isamfed.com:30443/mga/sps/oauth/oauth20/token |
3 | request_http_args | {'headers': {'Content-Type': 'application/x-www-form-urlencoded'}} |
3 | request | grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61737%2Fauthz_cb&code=NFvXz1uIvtkgyujIXseHjHFo4SZTT6&state=3Pxa4qZ2vfdCKD6f&client_assertion=eyJhbGciOiJSUzI1NiIsImtpZCI6Ind0MjVPZ3lSX256RzNPb1E3ZGFhMnJMNi1nTW5GZGZSekJqaFVWUHU4UlEifQ.eyJpc3MiOiAiTW04Zk1adkhvRkxIQXo0c2RJVWMiLCAic3ViIjogIk1tOGZNWnZIb0ZMSEF6NHNkSVVjIiwgImF1ZCI6IFsiaHR0cHM6Ly9pc2FtZmVkLmNvbTozMDQ0My9tZ2Evc3BzL29hdXRoL29hdXRoMjAvdG9rZW4iXSwgImp0aSI6ICJGNFNBVWJyWDBHN0tMeFdRNm05eXQ2Y2ZRd3dJYTJNdiIsICJleHAiOiAxNTYwNzg0NjYwLCAiaWF0IjogMTU2MDc4NDA2MH0.SZcMYzWsZubAZ8l5uqw0O4qrzLbIPxK3YnTbwtkny_pQ48rNBJanRsCwh-Ed5NKKF7Oz5UboidjU5Yc4IgJnv2PSylOJgXh_A56yyXiOouLkkAf09kVN9JtU5cDo8w8_TK-C3hhvaJ-EstQTlf6eD2Fo36s-GIKEZ3T01n-TzoheHKvqZyWWWlGBO03YhTzqnQlHHpWWYIno4A9eh-ViNGf_SQdwhi1FzGQeL-koPiiePsN9OGU4DkyxgAEnWe21IJjwUou78rHz5_SYkXdHt92WF_2kji-E18ZhHWZShoYkN1Q0P6pzSmdkNGB6TGflKCHvQLLsXS9y3txNNHLv4A&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer |
3 | http response | url:https://isamfed.com:30443/mga/sps/oauth/oauth20/token status_code:200
|
3 | response | {'access_token': 'o5I9YfaO5QPUtsnEONxY', 'refresh_token': 'EPMirdxIOHjUr84LxNQaGVDIAfP6OSzce3VkvIgK', 'scope': 'openid', 'id_token': 'eyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2Iiwia2lkIjoiZ3RINHYzWXIyUXFMcmVCU3owQnlRUTh2a2Y4ZUZvMUtJaXQzcy0zQmJ3dyIsImN0eSI6IkpXVCJ9.ZMwUg-cL3ODc7ZceenDbz7VCQ9eDkx8Rxq-Th_8w63pQWk_YpkcOVVAoI-GLCOhS2p3KP5V7bbhGyHJ0lsLvk-33p9lhFMU9SXu8Mw1i8AlIHLwvIZAJZmHacvyYFKIW87DUf4Sl7sy0Jw6yS4ijnpjlm77wA75DkikYuT66V3iKTdx1ri_k3dEO9IjB1dBd-7FGfFbr1K789S_hTV-FQ467qb4TaTDawEStgpFLCzGV9F9mUFp7-L8H-ro3X_EthMwr7u5o3M5h25a0COgKoZnoxpqcsCo8EVtN3BoWr2vC0NjLDrFvAeNnj92_DC7cNEtEMNHiBiJXVm7y_JeC_g.r0FuyhsDQt8-1FLHJY-n_w.kU9DW6A764NXgxE_3iFx4418q_Zg57KNQZLQ1WhHjE1dHyVMLqFMiZSFpcEyPOmMVcVOEXvV3H1g_sy7DROMRaI8r-3ucpEYHL9Dd05FkF1Ta8UU99NQyREJ1Ml5PTv34Jn7j1RcQs-Os4aZ1M0Iz4g5k2qFjciX9qqlVolVZn1nS_cH27CMaVScx5D3Bhb_gs4a9yuWSvU6EtyLjbX5llSOqqNDcIF8nZUZShicwmidmXPOa9FS6X7A_W3ajFLSdjUhzQ8c1IB2sNt9DwSvi1g2liYwVeRlt2BOPbNUe5XAt3dnydiumHvPsDydkwUUAoICO_7vefYVNOsYRYRpWRALqLPOxv3l5R229oq_aVzv4Rk-smwDHIPF_7vNZ7Q0hxJkDn5LgWvUTJ5ye4eqFxMI88YdRypdO9ig29lbDtRARBMhfv9JYmDMT2qNbxT-FpQeCZdAcB50dWZiQSm5AeHZb48YGjbLME6UPIsNd_7RYMDManeAw41Yggy8D6ExpMFplMurBDGU35iqU_winRA6StZZ3DebwmLgZLIZLf41Y2eyMRwcHkQ8F9tM3z7d9ayKiTwhwhLrTNmKKBWok9sNoi7meLPkkP82fyy5lbdMrB976z51ICiTNzwQ4_3PlM27ZtmOEPM-KK3S1amf5j1lwwwpVP91otvTppu_DPWY_Z0Cv63ejoNtB_P7ygR0PlUMbS6PNbfNFuZ_ycq4dI-n3WMeuSiTZDYBnro_-q0JrlSWrcBHkcDGTvQ3ctx_lQ8xO15Y3GozlWMwzEHIWU8vL9mJnsVu2OEomLAEhFcQ890IoLv4FhUUbAS-c6aGHHomVcNaflPclpP4PEJr-xlxn2oFcwa5yqfLUhycLEDved5jbcprtef8ajkvdXEqRA_jO314xA5_6qOmHPNGpu-bTR-7_zgyYv7C4NHuBANMsEuwoGDcWhecFFEj71_zong5yEmu4ZcpsIvVUf6jZg.pTpKLvd2cvhDGZaUiaDIHQ', 'token_type': 'bearer', 'expires_in': 3599} |
3 | AccessTokenResponse | {
"access_token": "o5I9YfaO5QPUtsnEONxY",
"expires_in": 3599,
"id_token": {
"at_hash": "2QyJKfXNAMbvwR0HPjT5tA",
"aud": [
"Mm8fMZvHoFLHAz4sdIUc"
],
"exp": 1560787480,
"iat": 1560784060,
"iss": "https://isamfed.com:30443/test",
"nonce": "NHSb9f7U2G8Fcwhe",
"rt_hash": "HNe2bMvSwAru5144kjDRkw",
"sub": "testuser"
},
"refresh_token": "EPMirdxIOHjUr84LxNQaGVDIAfP6OSzce3VkvIgK",
"scope": "openid",
"token_type": "bearer"
}
|
3 | jws header | {'kid': '_uhPdeGrTWxobFeH0XbzjJpRrzp3CB9nknx1yFV1G-0', 'alg': 'RS256'} |
3 | jwe header | {'alg': 'RSA-OAEP-256', 'enc': 'A128CBC-HS256', 'kid': 'gtH4v3Yr2QqLreBSz0ByQQ8vkf8eFo1KIit3s-3Bbww', 'cty': 'JWT'} |
3 | phase | <--<-- 6 --- TimeDelay -->--> |
34 | phase | <--<-- 7 --- AccessToken -->--> |
34 | request | op_args: {'state': '3Pxa4qZ2vfdCKD6f'}, req_args: {'redirect_uri': 'https://op.certification.openid.net:61737/authz_cb'} |
34 | do_access_token_request | kwargs:{'request_args': {'redirect_uri': 'https://op.certification.openid.net:61737/authz_cb', 'code': 'NFvXz1uIvtkgyujIXseHjHFo4SZTT6', 'state': '3Pxa4qZ2vfdCKD6f', 'grant_type': 'authorization_code', 'client_id': 'Mm8fMZvHoFLHAz4sdIUc'}, 'state': '3Pxa4qZ2vfdCKD6f', 'authn_method': 'private_key_jwt'}
|
34 | AccessTokenRequest | {
"client_assertion": "eyJhbGciOiJSUzI1NiIsImtpZCI6Ind0MjVPZ3lSX256RzNPb1E3ZGFhMnJMNi1nTW5GZGZSekJqaFVWUHU4UlEifQ.eyJpc3MiOiAiTW04Zk1adkhvRkxIQXo0c2RJVWMiLCAic3ViIjogIk1tOGZNWnZIb0ZMSEF6NHNkSVVjIiwgImF1ZCI6IFsiaHR0cHM6Ly9pc2FtZmVkLmNvbTozMDQ0My9tZ2Evc3BzL29hdXRoL29hdXRoMjAvdG9rZW4iXSwgImp0aSI6ICJ5TU9pdjJyZUFLd2hpejJ4VVdYclFnSHd4a0xWWmVNNCIsICJleHAiOiAxNTYwNzg0NjkxLCAiaWF0IjogMTU2MDc4NDA5MX0.jvhAMdtfSzbVBSAIzfMTEYuo7BFVFjWhN0OwQBIXJoUtfe4zwRr4uySIttpwaAyuksvbn6Zg1g_w7ZTZbfSHVqcannxB-emv8zLyW1XV5-37lYfoqtO0qKwErFY0uEwDoYeYQm8LtIPz6UrG-H1Wh_UdL14kdm73QUBvNVAqr1K45O10nycOYwy9zJ3elMr9embWo7UWpY4DiZagQdHyY8XSg4PT9J8tPDcEoXJtRdgUFat0LlhbsJEseZAEShhPNFNydc3LVIVeQur9o-3WtCfJ4aTGvKK8bv6uv-Scc-oK6hOSaF_8EnrQBjaaJr9Si6lPPcpsg5ewf9u3GRQ8IQ",
"client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer",
"code": "NFvXz1uIvtkgyujIXseHjHFo4SZTT6",
"grant_type": "authorization_code",
"redirect_uri": "https://op.certification.openid.net:61737/authz_cb",
"state": "3Pxa4qZ2vfdCKD6f"
}
|
34 | request_url | https://isamfed.com:30443/mga/sps/oauth/oauth20/token |
34 | request_http_args | {'headers': {'Content-Type': 'application/x-www-form-urlencoded'}} |
34 | request | grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A61737%2Fauthz_cb&code=NFvXz1uIvtkgyujIXseHjHFo4SZTT6&state=3Pxa4qZ2vfdCKD6f&client_assertion=eyJhbGciOiJSUzI1NiIsImtpZCI6Ind0MjVPZ3lSX256RzNPb1E3ZGFhMnJMNi1nTW5GZGZSekJqaFVWUHU4UlEifQ.eyJpc3MiOiAiTW04Zk1adkhvRkxIQXo0c2RJVWMiLCAic3ViIjogIk1tOGZNWnZIb0ZMSEF6NHNkSVVjIiwgImF1ZCI6IFsiaHR0cHM6Ly9pc2FtZmVkLmNvbTozMDQ0My9tZ2Evc3BzL29hdXRoL29hdXRoMjAvdG9rZW4iXSwgImp0aSI6ICJ5TU9pdjJyZUFLd2hpejJ4VVdYclFnSHd4a0xWWmVNNCIsICJleHAiOiAxNTYwNzg0NjkxLCAiaWF0IjogMTU2MDc4NDA5MX0.jvhAMdtfSzbVBSAIzfMTEYuo7BFVFjWhN0OwQBIXJoUtfe4zwRr4uySIttpwaAyuksvbn6Zg1g_w7ZTZbfSHVqcannxB-emv8zLyW1XV5-37lYfoqtO0qKwErFY0uEwDoYeYQm8LtIPz6UrG-H1Wh_UdL14kdm73QUBvNVAqr1K45O10nycOYwy9zJ3elMr9embWo7UWpY4DiZagQdHyY8XSg4PT9J8tPDcEoXJtRdgUFat0LlhbsJEseZAEShhPNFNydc3LVIVeQur9o-3WtCfJ4aTGvKK8bv6uv-Scc-oK6hOSaF_8EnrQBjaaJr9Si6lPPcpsg5ewf9u3GRQ8IQ&client_assertion_type=urn%3Aietf%3Aparams%3Aoauth%3Aclient-assertion-type%3Ajwt-bearer |
34 | http response | url:https://isamfed.com:30443/mga/sps/oauth/oauth20/token status_code:400 message:{"error_description":"FBTOAU211E The [authorization_grant] received of type [authorization_code] does not exist.","error":"invalid_grant"}
|
34 | response | {'error_description': 'FBTOAU211E The [authorization_grant] received of type [authorization_code] does not exist.', 'error': 'invalid_grant'} |
34 | event | Got expected error |
34 | TokenErrorResponse | {
"error": "invalid_grant",
"error_description": "FBTOAU211E The [authorization_grant] received of type [authorization_code] does not exist."
}
|
34 | phase | <--<-- 8 --- Done -->--> |
34 | end | |
34 | assertion | CheckHTTPErrorResponse |
34 | condition | check-http-error-response: status=OK [Checks that an error code is either 400 or 401 which are the only ones accepted by OAuth2/OIDC.] |
34 | assertion | VerifyResponse |
34 | condition | verify-response: status=OK [Checks that the last response was one of a possible set of OpenID Connect Responses] |
34 | condition | Done: status=OK |