Test info

Profile: {'openid-configuration': 'config', 'response_type': 'code', 'crypto': 'sign', 'registration': 'static'}
Timestamp: 2016-02-24T21:36:59Z
Test description: Scope requesting email claims [Basic, Implicit, Hybrid]
Test ID: OP-scope-email
Issuer: https://qaportal2.gosecureauth.com/secureauth123

Test output


__AuthorizationRequest:pre__
[check-response-type]
	status: OK
	description: Checks that the asked for response type are among the supported
[check-endpoint]
	status: OK
	description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[check-http-response]
	status: OK
	description: Checks that the HTTP response status is within the 200 or 300 range
[verify-response]
	status: OK
	description: Checks that the last response was one of a possible set of OpenID Connect Responses
[verify-scopes]
	status: OK
	description: Verifies that the claims corresponding to the requested scopes are returned
__X:==== END ====__

Trace output


0.000453 ------------ DiscoveryRequest ------------
0.000469 Provider info discover from 'https://qaportal2.gosecureauth.com/secureauth123'
0.000475 --> URL: https://qaportal2.gosecureauth.com/secureauth123/.well-known/openid-configuration
0.325531 ProviderConfigurationResponse: {
  "authorization_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx",
  "check_session_iframe": "https://qaportal2.gosecureauth.com/secureauth123/OidcCheckSession.aspx",
  "claim_types_supported": [
    "normal"
  ],
  "claims_parameter_supported": false,
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "preferred_username",
    "profile"
  ],
  "end_session_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcEndSession.aspx",
  "grant_types_supported": [
    "authorization_code",
    "client_credentials",
    "password",
    "refresh_token"
  ],
  "id_token_signing_alg_values_supported": [
    "HS256",
    "RS256"
  ],
  "issuer": "https://qaportal2.gosecureauth.com/secureauth123",
  "jwks_uri": "https://qaportal2.gosecureauth.com/secureauth123/.well-known/jwks",
  "request_parameter_supported": false,
  "request_uri_parameter_supported": true,
  "require_request_uri_registration": true,
  "response_modes_supported": [
    "form_post",
    "fragment",
    "query"
  ],
  "response_types_supported": [
    "code",
    "token",
    "id_token",
    "id_token token",
    "code id_token",
    "code token",
    "code id_token token"
  ],
  "scopes_supported": [
    "openid",
    "profile",
    "email",
    "phone",
    "address",
    "sa.readprofile",
    "sa.editprofile"
  ],
  "subject_types_supported": [
    "public"
  ],
  "token_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx",
  "token_endpoint_auth_methods_supported": [
    "client_secret_post",
    "client_secret_basic"
  ],
  "userinfo_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcUserInfo.aspx",
  "version": "3.0"
}
0.671115 JWKS: {
  "keys": [
    {
      "e": "AQAB",
      "kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
      "kty": "RSA",
      "n": "sy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0_cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT_1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1-uvxF1YLsuZa_QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i-5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE_JZfA-z8e7w",
      "use": "sig",
      "x5c": [
        "MIIEvTCCA6WgAwIBAgIDAPNJMA0GCSqGSIb3DQEBCwUAMEcxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMSAwHgYDVQQDExdSYXBpZFNTTCBTSEEyNTYgQ0EgLSBHMzAeFw0xNDEyMDcxMjM1NTlaFw0xODAyMDcyMjQ5NDJaMIGWMRMwEQYDVQQLEwpHVDU5NjE0ODM5MTEwLwYDVQQLEyhTZWUgd3d3LnJhcGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTE0MS8wLQYDVQQLEyZEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEbMBkGA1UEAwwSKi5nb3NlY3VyZWF1dGguY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0/cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT/1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1+uvxF1YLsuZa/QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i+5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE/JZfA+z8e7wIDAQABo4IBYDCCAVwwHwYDVR0jBBgwFoAUw5zz/NNGCDS7zkZ/oHxb8+IIy1kwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNodHRwOi8vZ3Yuc3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNydDAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMC8GA1UdEQQoMCaCEiouZ29zZWN1cmVhdXRoLmNvbYIQZ29zZWN1cmVhdXRoLmNvbTArBgNVHR8EJDAiMCCgHqAchhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNybDAMBgNVHRMBAf8EAjAAMEUGA1UdIAQ+MDwwOgYKYIZIAYb4RQEHNjAsMCoGCCsGAQUFBwIBFh5odHRwczovL3d3dy5yYXBpZHNzbC5jb20vbGVnYWwwDQYJKoZIhvcNAQELBQADggEBAIBtdMMzImQrQtUtBAOoE8fDupKKg3E2VR9jnuXU8ITdU7+BjiKcrHrus75hUF4BHCWyoQjOAoyQSz5M7DVzVnlVCCEgw6H+L+uvtj4k4hfVpeQVKc/NdzpGe3lQw4XuagDishXCC0otcIPn89X3Kge/6s/QIME0DuDADOB50rprDE8jFYwbiQ56P0qk+uy9R31IetyEu5fG9br35wNjAWvLS6XGIbX2Xy8cnRDhV+Eo7JvP7KEr/E5AZjt+5jTP8ZaqEoiyVFwtz40csFuV11aiecox2xW8A4LyTyy3kV8Hjrm/187y6J5iCbGQTIpL6xPuPA2NesWunoFmQFU7q4s="
      ],
      "x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
    }
  ]
}
0.684314 ------------ AuthorizationRequest ------------
0.684735 --> URL: https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx?scope=openid+email&state=3KxV9r0vm1HyD6n6&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb&response_type=code&client_id=9c1838fe529b4359894b2cbba64b950c
0.684743 --> BODY: None
4.553920 <-- code=RQxc8qD4fR99tiKOok7SAK9E8f4QHxzZkzVTpZh3iYK8_wMv49_1iIK5tFeR8jsNEQbRl43GXIxyLGRLAUZineX9l7j0R56UjWtnKWq4R21QOJgXgc7x-3G4stNk8D202M4e6HujnlZBwsPUwo-Fr2fDaYuEBdEGaLZxF51_QbJf3KWR-kzNlo943qTJYRrGt3ZcesxcTnqcXG-FKLUpPHVuaqppm95WST25gTImKh_32-mS-Xpvy7B4gG4a5W47YuWfvi-jMrSOUuw6MMRenQ&session_state=MU4dTacjMx3Rcerw1TQVMKd6bjI5L-5FWmfKW_b0dEo.bb49a7c59a963c12897b7064977ba935&state=3KxV9r0vm1HyD6n6
4.554409 AuthorizationResponse: {
  "code": "RQxc8qD4fR99tiKOok7SAK9E8f4QHxzZkzVTpZh3iYK8_wMv49_1iIK5tFeR8jsNEQbRl43GXIxyLGRLAUZineX9l7j0R56UjWtnKWq4R21QOJgXgc7x-3G4stNk8D202M4e6HujnlZBwsPUwo-Fr2fDaYuEBdEGaLZxF51_QbJf3KWR-kzNlo943qTJYRrGt3ZcesxcTnqcXG-FKLUpPHVuaqppm95WST25gTImKh_32-mS-Xpvy7B4gG4a5W47YuWfvi-jMrSOUuw6MMRenQ",
  "session_state": "MU4dTacjMx3Rcerw1TQVMKd6bjI5L-5FWmfKW_b0dEo.bb49a7c59a963c12897b7064977ba935",
  "state": "3KxV9r0vm1HyD6n6"
}
4.554799 ------------ AccessTokenRequest ------------
4.555217 --> URL: https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx
4.555224 --> BODY: code=RQxc8qD4fR99tiKOok7SAK9E8f4QHxzZkzVTpZh3iYK8_wMv49_1iIK5tFeR8jsNEQbRl43GXIxyLGRLAUZineX9l7j0R56UjWtnKWq4R21QOJgXgc7x-3G4stNk8D202M4e6HujnlZBwsPUwo-Fr2fDaYuEBdEGaLZxF51_QbJf3KWR-kzNlo943qTJYRrGt3ZcesxcTnqcXG-FKLUpPHVuaqppm95WST25gTImKh_32-mS-Xpvy7B4gG4a5W47YuWfvi-jMrSOUuw6MMRenQ&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb
4.555238 --> HEADERS: {'Content-Type': 'application/x-www-form-urlencoded', 'Authorization': u'Basic OWMxODM4ZmU1MjliNDM1OTg5NGIyY2JiYTY0Yjk1MGM6ZDhhYjQ1NzlkOTE3NzI3NDQ3N2I2YmM4MWFkYmZhOGM3NmU2NTg2YWE1MWJjMmIwNWNmMWVmNzlkNGNmZjUyZg=='}
5.053480 <-- STATUS: 200
5.053539 <-- BODY: {"access_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5YzE4MzhmZTUyOWI0MzU5ODk0YjJjYmJhNjRiOTUwYyIsInNjb3BlIjpbImVtYWlsIiwib3BlbmlkIl0sInN1YiI6InVzZXI3MSIsImFtciI6InBhc3N3b3JkIiwiYXV0aF90aW1lIjoxNDU2MzQ5NjkxLCJpZHAiOiJTZWN1cmVBdXRoMTIzIiwiaXNzIjoiaHR0cHM6Ly9xYXBvcnRhbDIuZ29zZWN1cmVhdXRoLmNvbS9zZWN1cmVhdXRoMTIzIiwiYXVkIjoiaHR0cHM6Ly9xYXBvcnRhbDIuZ29zZWN1cmVhdXRoLmNvbS9zZWN1cmVhdXRoMTIzIiwiZXhwIjoxNDU2NDM2MjE2LCJuYmYiOjE0NTYzNDk4MTZ9.Vl7T3wkYHoboBUEOi2ias9S3VjSPFqVKa3UQD0On4chJA6BV-1fmrfuF4beOq1RZPeWi5Vxkhv-7udYSbxOaLe5ehP4QZkusHp-KppD-3QLSFfVUUw9zlHOBU8ix5y4gNlxzVS6_h-GJQyLshIwqNOT009XizXlOuP59hi61Gvf6hPZ7CitBlHA_h3Pr7F6tAlfUyAEMC6F3r4ZuTJUlyqJ2mK294-ino3-l0WogiFTLs9tZbsr5FtJ8nk8RzbRFofKJPPPvM6TnLIJRLXYy1SDYn4o49kxMtVETGk_rhJta8hglPAd-xloFenis5KHMIgp4_jZdZf9cOcJuMqKR9w","id_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJhbXIiOiJwYXNzd29yZCIsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJhdXRoX3RpbWUiOjE0NTYzNDk2OTEsInN1YiI6InVzZXI3MSIsImVtYWlsIjoibHJhbW9zQHNlY3VyZWF1dGguY29tIiwiZW1haWxfdmVyaWZpZWQiOiJ0cnVlIiwiYXRfaGFzaCI6ImhRendvMEEtQ21tSFNZTVlBckY3dXciLCJpYXQiOjE0NTYzNDk4MTcsImlzcyI6Imh0dHBzOi8vcWFwb3J0YWwyLmdvc2VjdXJlYXV0aC5jb20vc2VjdXJlYXV0aDEyMyIsImF1ZCI6IjljMTgzOGZlNTI5YjQzNTk4OTRiMmNiYmE2NGI5NTBjIiwiZXhwIjoxNDU2NDM2MjE2LCJuYmYiOjE0NTYzNDk4MTZ9.HXGghLw3-_oAs2Cmthk6p3Ba8XhKt3rC7viHWGKlqpW2sBt4RZc_BBTRXShCfo8rLzWCIeQuUo4q23yBhyCA7-mqqX_geAC_2gtGmx_Z4dB78qSlg9--jE3NADBi-3I03JBZwTpxJB-rUdSO8g6F24qs1ZQzyK-xsOLWQ8vQ_RkUnK0wWJL84Bkuo047S155EksTLQmGOgNwqQQnownSall0JWRpr9-sVoyP3jCN37EBo-YmE7dR_MJORUPvCwQqCQMjE0CSyI94SkvnRGhegOPbakHRzLK-AAB2LefDPYe-sSKIfeZAeALxa27pYJN0Q0qM2n1lTVkslvoihpW0DA","token_type":"Bearer","expires_in":"86400"}
5.424540 AccessTokenResponse: {
  "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5YzE4MzhmZTUyOWI0MzU5ODk0YjJjYmJhNjRiOTUwYyIsInNjb3BlIjpbImVtYWlsIiwib3BlbmlkIl0sInN1YiI6InVzZXI3MSIsImFtciI6InBhc3N3b3JkIiwiYXV0aF90aW1lIjoxNDU2MzQ5NjkxLCJpZHAiOiJTZWN1cmVBdXRoMTIzIiwiaXNzIjoiaHR0cHM6Ly9xYXBvcnRhbDIuZ29zZWN1cmVhdXRoLmNvbS9zZWN1cmVhdXRoMTIzIiwiYXVkIjoiaHR0cHM6Ly9xYXBvcnRhbDIuZ29zZWN1cmVhdXRoLmNvbS9zZWN1cmVhdXRoMTIzIiwiZXhwIjoxNDU2NDM2MjE2LCJuYmYiOjE0NTYzNDk4MTZ9.Vl7T3wkYHoboBUEOi2ias9S3VjSPFqVKa3UQD0On4chJA6BV-1fmrfuF4beOq1RZPeWi5Vxkhv-7udYSbxOaLe5ehP4QZkusHp-KppD-3QLSFfVUUw9zlHOBU8ix5y4gNlxzVS6_h-GJQyLshIwqNOT009XizXlOuP59hi61Gvf6hPZ7CitBlHA_h3Pr7F6tAlfUyAEMC6F3r4ZuTJUlyqJ2mK294-ino3-l0WogiFTLs9tZbsr5FtJ8nk8RzbRFofKJPPPvM6TnLIJRLXYy1SDYn4o49kxMtVETGk_rhJta8hglPAd-xloFenis5KHMIgp4_jZdZf9cOcJuMqKR9w",
  "expires_in": "86400",
  "id_token": {
    "claims": {
      "amr": [
        "password"
      ],
      "at_hash": "hQzwo0A-CmmHSYMYArF7uw",
      "aud": [
        "9c1838fe529b4359894b2cbba64b950c"
      ],
      "auth_time": 1456349691,
      "email": "lramos@secureauth.com",
      "email_verified": "true",
      "exp": 1456436216,
      "iat": 1456349817,
      "idp": "SecureAuth123",
      "iss": "https://qaportal2.gosecureauth.com/secureauth123",
      "nbf": 1456349816,
      "sub": "user71"
    },
    "jws header parameters": {
      "alg": "RS256",
      "kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
      "typ": "JWT",
      "x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
    }
  },
  "token_type": "Bearer"
}
5.439324 ------------ UserInfoRequest ------------
5.439666 --> URL: https://qaportal2.gosecureauth.com/secureauth123/OidcUserInfo.aspx
5.439673 --> BODY: None
5.439696 --> HEADERS: {'Authorization': u'Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5YzE4MzhmZTUyOWI0MzU5ODk0YjJjYmJhNjRiOTUwYyIsInNjb3BlIjpbImVtYWlsIiwib3BlbmlkIl0sInN1YiI6InVzZXI3MSIsImFtciI6InBhc3N3b3JkIiwiYXV0aF90aW1lIjoxNDU2MzQ5NjkxLCJpZHAiOiJTZWN1cmVBdXRoMTIzIiwiaXNzIjoiaHR0cHM6Ly9xYXBvcnRhbDIuZ29zZWN1cmVhdXRoLmNvbS9zZWN1cmVhdXRoMTIzIiwiYXVkIjoiaHR0cHM6Ly9xYXBvcnRhbDIuZ29zZWN1cmVhdXRoLmNvbS9zZWN1cmVhdXRoMTIzIiwiZXhwIjoxNDU2NDM2MjE2LCJuYmYiOjE0NTYzNDk4MTZ9.Vl7T3wkYHoboBUEOi2ias9S3VjSPFqVKa3UQD0On4chJA6BV-1fmrfuF4beOq1RZPeWi5Vxkhv-7udYSbxOaLe5ehP4QZkusHp-KppD-3QLSFfVUUw9zlHOBU8ix5y4gNlxzVS6_h-GJQyLshIwqNOT009XizXlOuP59hi61Gvf6hPZ7CitBlHA_h3Pr7F6tAlfUyAEMC6F3r4ZuTJUlyqJ2mK294-ino3-l0WogiFTLs9tZbsr5FtJ8nk8RzbRFofKJPPPvM6TnLIJRLXYy1SDYn4o49kxMtVETGk_rhJta8hglPAd-xloFenis5KHMIgp4_jZdZf9cOcJuMqKR9w'}
6.566662 <-- STATUS: 200
6.566734 Available verification keys: [(u'kL3mwBbniGrOr-Hhw0D8e_-rRWU', u'RSA')]
6.566767 Available decryption keys: [('a0', 'RSA'), ('a3', 'EC')]
6.566790 <-- BODY: {"amr":"password","idp":"SecureAuth123","auth_time":"1456349691","sub":"user71","email":"lramos@secureauth.com","email_verified":"true"}
6.567608 UserInfo: {
  "amr": "password",
  "auth_time": "1456349691",
  "email": "lramos@secureauth.com",
  "email_verified": "true",
  "idp": "SecureAuth123",
  "sub": "user71"
}
6.580960 ==== END ====

Result

PASSED