Test info

Profile: {'openid-configuration': 'config', 'response_type': 'code+token', 'crypto': 'sign', 'registration': 'static'}
Timestamp: 2016-02-25T19:18:36Z
Test description: Trying to use authorization code twice with 30 seconds in between uses must result in an error [Basic, Hybrid]
Test ID: OP-OAuth-2nd-30s
Issuer: https://qaportal2.gosecureauth.com/secureauth123

Test output


__AuthorizationRequest:pre__
[check-response-type]
	status: OK
	description: Checks that the asked for response type are among the supported
[check-endpoint]
	status: OK
	description: Checks that the necessary endpoint exists at a server
__After completing the test flow:__
[verify-response]
	status: OK
	description: Checks that the last response was one of a possible set of OpenID Connect Responses
__X:==== END ====__

Trace output


2.535151 ------------ DiscoveryRequest ------------
2.535173 Provider info discover from 'https://qaportal2.gosecureauth.com/secureauth123'
2.535180 --> URL: https://qaportal2.gosecureauth.com/secureauth123/.well-known/openid-configuration
2.857680 ProviderConfigurationResponse: {
  "authorization_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx",
  "check_session_iframe": "https://qaportal2.gosecureauth.com/secureauth123/OidcCheckSession.aspx",
  "claim_types_supported": [
    "normal"
  ],
  "claims_parameter_supported": false,
  "claims_supported": [
    "sub",
    "name",
    "given_name",
    "family_name",
    "middle_name",
    "nickname",
    "preferred_username",
    "profile"
  ],
  "end_session_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcEndSession.aspx",
  "grant_types_supported": [
    "authorization_code",
    "client_credentials",
    "password",
    "refresh_token"
  ],
  "id_token_signing_alg_values_supported": [
    "HS256",
    "RS256"
  ],
  "issuer": "https://qaportal2.gosecureauth.com/secureauth123",
  "jwks_uri": "https://qaportal2.gosecureauth.com/secureauth123/.well-known/jwks",
  "request_parameter_supported": false,
  "request_uri_parameter_supported": true,
  "require_request_uri_registration": true,
  "response_modes_supported": [
    "form_post",
    "fragment",
    "query"
  ],
  "response_types_supported": [
    "code",
    "token",
    "id_token",
    "id_token token",
    "code id_token",
    "code token",
    "code id_token token"
  ],
  "scopes_supported": [
    "openid",
    "profile",
    "email",
    "phone",
    "address",
    "sa.readprofile",
    "sa.editprofile"
  ],
  "subject_types_supported": [
    "public"
  ],
  "token_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx",
  "token_endpoint_auth_methods_supported": [
    "client_secret_post",
    "client_secret_basic"
  ],
  "userinfo_endpoint": "https://qaportal2.gosecureauth.com/secureauth123/OidcUserInfo.aspx",
  "version": "3.0"
}
3.169217 JWKS: {
  "keys": [
    {
      "e": "AQAB",
      "kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
      "kty": "RSA",
      "n": "sy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0_cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT_1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1-uvxF1YLsuZa_QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i-5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE_JZfA-z8e7w",
      "use": "sig",
      "x5c": [
        "MIIEvTCCA6WgAwIBAgIDAPNJMA0GCSqGSIb3DQEBCwUAMEcxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1HZW9UcnVzdCBJbmMuMSAwHgYDVQQDExdSYXBpZFNTTCBTSEEyNTYgQ0EgLSBHMzAeFw0xNDEyMDcxMjM1NTlaFw0xODAyMDcyMjQ5NDJaMIGWMRMwEQYDVQQLEwpHVDU5NjE0ODM5MTEwLwYDVQQLEyhTZWUgd3d3LnJhcGlkc3NsLmNvbS9yZXNvdXJjZXMvY3BzIChjKTE0MS8wLQYDVQQLEyZEb21haW4gQ29udHJvbCBWYWxpZGF0ZWQgLSBSYXBpZFNTTChSKTEbMBkGA1UEAwwSKi5nb3NlY3VyZWF1dGguY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsy1VZq8v2oqbSaddMMxeyqVORLB3lk71T0/cAv4lWdqCAmd9LWGvVul2be1Q5QUdJgewy9G8dEpwyuT/1qmqtY1psgxua9M3uyBrtY1mYBJ4QZVMgbvfk1+uvxF1YLsuZa/QsAN0k3X5bmvQh35WVNgzVU1QXAgi8m0jxSxY2EM2GO0EMwvPXIgkU6u0yYJ6Vy4i+5Ftwztx2dyz41JTw8CF8m9S2nE4Ppxc4rfWLjCIlPPILCPUnwU2UlfPAqHUxi6RXeAubyjlL5komE6y4XstURH66gePLyfjMtWGxmZpbv4yPmffFQgMO0oYT0Y1trUTF19waIE/JZfA+z8e7wIDAQABo4IBYDCCAVwwHwYDVR0jBBgwFoAUw5zz/NNGCDS7zkZ/oHxb8+IIy1kwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNodHRwOi8vZ3Yuc3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNydDAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMC8GA1UdEQQoMCaCEiouZ29zZWN1cmVhdXRoLmNvbYIQZ29zZWN1cmVhdXRoLmNvbTArBgNVHR8EJDAiMCCgHqAchhpodHRwOi8vZ3Yuc3ltY2IuY29tL2d2LmNybDAMBgNVHRMBAf8EAjAAMEUGA1UdIAQ+MDwwOgYKYIZIAYb4RQEHNjAsMCoGCCsGAQUFBwIBFh5odHRwczovL3d3dy5yYXBpZHNzbC5jb20vbGVnYWwwDQYJKoZIhvcNAQELBQADggEBAIBtdMMzImQrQtUtBAOoE8fDupKKg3E2VR9jnuXU8ITdU7+BjiKcrHrus75hUF4BHCWyoQjOAoyQSz5M7DVzVnlVCCEgw6H+L+uvtj4k4hfVpeQVKc/NdzpGe3lQw4XuagDishXCC0otcIPn89X3Kge/6s/QIME0DuDADOB50rprDE8jFYwbiQ56P0qk+uy9R31IetyEu5fG9br35wNjAWvLS6XGIbX2Xy8cnRDhV+Eo7JvP7KEr/E5AZjt+5jTP8ZaqEoiyVFwtz40csFuV11aiecox2xW8A4LyTyy3kV8Hjrm/187y6J5iCbGQTIpL6xPuPA2NesWunoFmQFU7q4s="
      ],
      "x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
    }
  ]
}
3.179648 ------------ AuthorizationRequest ------------
3.180115 --> URL: https://qaportal2.gosecureauth.com/secureauth123/SecureAuth.aspx?nonce=NKEktHvezdza&state=toVdsdM1xdrhHykQ&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb&response_type=code+token&client_id=977c322203ed497eb718a51a8f35d54b&scope=openid
3.180123 --> BODY: None
7.645268 QUERY_STRING:
8.205057 <-- code=FdXV4YTQuK0cViOzZlCwW3nzCws-_InbU5zsH9bSLvc3yQE0QmGvQq8M0_Zp96SJhXQ85LsWn-VMWlHVfN5d-auBw032YutPOAMoKQmPh9abr5b54c1ev4M8_L0hoNpABgPTBjcoDfNVtkQAz2cLaEGWAoux_oVoXLmha7RGbl_jWgm04__KF7HCIoM5c7C6BlOfIeUNQK39ofrMkcw5x8Z3rWdhCNOJmyMcUURkrlinYuevNsCONbfLoCgQexO9Xe6iZbyPNMsiuNtSj7pRHjz74TMRXg803yTucCwbH9k&access_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0Mjc1ODMsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTQyODMsIm5iZiI6MTQ1NjQyNzg4M30.TJ34Asb4yczjsFjlg-O0NrSElzsWS6QaL759rkvL5tho8NiXm8Dorx2Hyq3lfVloOhnXt8RYfIdz2c9v-gQE97Ncsjz5IDDN8_biEXzVtUrHomRKXDVirDNQkzecV1CrX8zKDN5RXRNgYI-pmthOhaDmfZNjXZeIGQWWeBuMupzDqPAFfj3IlmybvpvcbgY4pWpLlPsXgwiCwoCkOZJvlxuydbgeWTv4KztXzzYuGvdPmoEW5Rtl-EKJSAUEXFU4HwDf6Xg9Amhcxyu3Zoezyi-1S0dOqw-O4Ut3ocw3RvLlVmjOYiVXctz3iOyxqzozk7lWQAHUy6aGg2_5qfa-EA&token_type=Bearer&session_state=iqAX6rnx8mYuOrHaynImyrpd7Vp5x6zijYlyXkiloho.02a7bc72201eca12d98b8d1a207b10cc&state=toVdsdM1xdrhHykQ
8.206211 AuthorizationResponse: {
  "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0Mjc1ODMsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTQyODMsIm5iZiI6MTQ1NjQyNzg4M30.TJ34Asb4yczjsFjlg-O0NrSElzsWS6QaL759rkvL5tho8NiXm8Dorx2Hyq3lfVloOhnXt8RYfIdz2c9v-gQE97Ncsjz5IDDN8_biEXzVtUrHomRKXDVirDNQkzecV1CrX8zKDN5RXRNgYI-pmthOhaDmfZNjXZeIGQWWeBuMupzDqPAFfj3IlmybvpvcbgY4pWpLlPsXgwiCwoCkOZJvlxuydbgeWTv4KztXzzYuGvdPmoEW5Rtl-EKJSAUEXFU4HwDf6Xg9Amhcxyu3Zoezyi-1S0dOqw-O4Ut3ocw3RvLlVmjOYiVXctz3iOyxqzozk7lWQAHUy6aGg2_5qfa-EA",
  "code": "FdXV4YTQuK0cViOzZlCwW3nzCws-_InbU5zsH9bSLvc3yQE0QmGvQq8M0_Zp96SJhXQ85LsWn-VMWlHVfN5d-auBw032YutPOAMoKQmPh9abr5b54c1ev4M8_L0hoNpABgPTBjcoDfNVtkQAz2cLaEGWAoux_oVoXLmha7RGbl_jWgm04__KF7HCIoM5c7C6BlOfIeUNQK39ofrMkcw5x8Z3rWdhCNOJmyMcUURkrlinYuevNsCONbfLoCgQexO9Xe6iZbyPNMsiuNtSj7pRHjz74TMRXg803yTucCwbH9k",
  "session_state": "iqAX6rnx8mYuOrHaynImyrpd7Vp5x6zijYlyXkiloho.02a7bc72201eca12d98b8d1a207b10cc",
  "state": "toVdsdM1xdrhHykQ",
  "token_type": "Bearer"
}
8.206749 ------------ AccessTokenRequest ------------
8.207395 --> URL: https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx
8.207403 --> BODY: code=FdXV4YTQuK0cViOzZlCwW3nzCws-_InbU5zsH9bSLvc3yQE0QmGvQq8M0_Zp96SJhXQ85LsWn-VMWlHVfN5d-auBw032YutPOAMoKQmPh9abr5b54c1ev4M8_L0hoNpABgPTBjcoDfNVtkQAz2cLaEGWAoux_oVoXLmha7RGbl_jWgm04__KF7HCIoM5c7C6BlOfIeUNQK39ofrMkcw5x8Z3rWdhCNOJmyMcUURkrlinYuevNsCONbfLoCgQexO9Xe6iZbyPNMsiuNtSj7pRHjz74TMRXg803yTucCwbH9k&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb
8.207418 --> HEADERS: {'Content-Type': 'application/x-www-form-urlencoded', 'Authorization': u'Basic OTc3YzMyMjIwM2VkNDk3ZWI3MThhNTFhOGYzNWQ1NGI6NmMxYTQ4YmFkOWRhOWVhNjBhY2YyNzQ4OTY3YzllZjE3Y2QxOWY1ZThhYmQzNGM4Mjg4MWJhNDM1NDE0OTIyNA=='}
8.775306 <-- STATUS: 200
8.775385 <-- BODY: {"access_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0Mjc1ODMsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTQyODUsIm5iZiI6MTQ1NjQyNzg4NX0.X9bx6Pc-LJj-gT7CaFcwWLg_iJQGcwoVcs7qhcgBKzSpiXboXpGKJFT-NGpzeCxiC-xrgzQdfGgS1X1b_yADFXBlkYuJsxEh47oZkSrjUh5NABNOiBak3dOsU0-bHyaKW-LR9L5R7x-cPu25TltNQpAWYwQilWFEJ1s4JDIHbhrWSMv50l6bJ2wAhYG_T8p_cC5JsQcYqHF6UcfhcpvCJ2rMR1fGc3FWJtTl7JiaIdA7LryezwlE6L04Got80fsXYS9jH-IH6u5MZQrWecy-wwXDyVDdnEc2kNIIQN0Sd6ViqZP9Q5cFV6er7nXzA_-JMDnltJ3yAkraXx6_k75M3g","id_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJhbXIiOiJwYXNzd29yZCIsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJhdXRoX3RpbWUiOjE0NTY0Mjc1ODMsInN1YiI6InVzZXI3MSIsIm5vbmNlIjoiTktFa3RIdmV6ZHphIiwiYXRfaGFzaCI6ImtmRWZUZjVFYnR1THlMMk9QNm1xTWciLCJpYXQiOjE0NTY0Mjc4ODUsImlzcyI6Imh0dHBzOi8vcWFwb3J0YWwyLmdvc2VjdXJlYXV0aC5jb20vc2VjdXJlYXV0aDEyMyIsImF1ZCI6Ijk3N2MzMjIyMDNlZDQ5N2ViNzE4YTUxYThmMzVkNTRiIiwiZXhwIjoxNDU2NTE0Mjg1LCJuYmYiOjE0NTY0Mjc4ODV9.S75OcoXnA6fAltGDao-ic7Euo2BlL5guI8xpU-MIR3oESWP6tQOYmSUKdPSw41UeUqRlpaOyu-NqDxQoerSLNv3UPaafs70Po1ajLQ5BOConKhLTiMFkeod-3UWR70mWqJAhBNgdl_X9FQMdQToPUaMA5hJas1-A1B2RxHrmTsG8ltcLEMlPsBeQtD1vpzzmGQAHJyDEeG9P4CbMMcN8XWKSApY_-pIIwOwiKahT1jeKUfDcQGoAWvVzANqJcR4FMQN2MY5fOt9703kLhPneiNaSsG1FajKibVrtowC4b-SEGtWEHH18--X2OKNBdo2NWiFJv5hSkjChcx9e7yULfA","token_type":"Bearer","expires_in":"86400"}
9.116691 AccessTokenResponse: {
  "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSIsImtpZCI6ImtMM213QmJuaUdyT3ItSGh3MEQ4ZV8tclJXVSJ9.eyJjbGllbnRfaWQiOiI5NzdjMzIyMjAzZWQ0OTdlYjcxOGE1MWE4ZjM1ZDU0YiIsInNjb3BlIjoib3BlbmlkIiwic3ViIjoidXNlcjcxIiwiYW1yIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE0NTY0Mjc1ODMsImlkcCI6IlNlY3VyZUF1dGgxMjMiLCJpc3MiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJhdWQiOiJodHRwczovL3FhcG9ydGFsMi5nb3NlY3VyZWF1dGguY29tL3NlY3VyZWF1dGgxMjMiLCJleHAiOjE0NTY1MTQyODUsIm5iZiI6MTQ1NjQyNzg4NX0.X9bx6Pc-LJj-gT7CaFcwWLg_iJQGcwoVcs7qhcgBKzSpiXboXpGKJFT-NGpzeCxiC-xrgzQdfGgS1X1b_yADFXBlkYuJsxEh47oZkSrjUh5NABNOiBak3dOsU0-bHyaKW-LR9L5R7x-cPu25TltNQpAWYwQilWFEJ1s4JDIHbhrWSMv50l6bJ2wAhYG_T8p_cC5JsQcYqHF6UcfhcpvCJ2rMR1fGc3FWJtTl7JiaIdA7LryezwlE6L04Got80fsXYS9jH-IH6u5MZQrWecy-wwXDyVDdnEc2kNIIQN0Sd6ViqZP9Q5cFV6er7nXzA_-JMDnltJ3yAkraXx6_k75M3g",
  "expires_in": "86400",
  "id_token": {
    "claims": {
      "amr": [
        "password"
      ],
      "at_hash": "kfEfTf5EbtuLyL2OP6mqMg",
      "aud": [
        "977c322203ed497eb718a51a8f35d54b"
      ],
      "auth_time": 1456427583,
      "exp": 1456514285,
      "iat": 1456427885,
      "idp": "SecureAuth123",
      "iss": "https://qaportal2.gosecureauth.com/secureauth123",
      "nbf": 1456427885,
      "nonce": "NKEktHvezdza",
      "sub": "user71"
    },
    "jws header parameters": {
      "alg": "RS256",
      "kid": "kL3mwBbniGrOr-Hhw0D8e_-rRWU",
      "typ": "JWT",
      "x5t": "kL3mwBbniGrOr-Hhw0D8e_-rRWU"
    }
  },
  "token_type": "Bearer"
}
39.177679 ------------ AccessTokenRequest ------------
39.178154 --> URL: https://qaportal2.gosecureauth.com/secureauth123/OidcToken.aspx
39.178162 --> BODY: code=FdXV4YTQuK0cViOzZlCwW3nzCws-_InbU5zsH9bSLvc3yQE0QmGvQq8M0_Zp96SJhXQ85LsWn-VMWlHVfN5d-auBw032YutPOAMoKQmPh9abr5b54c1ev4M8_L0hoNpABgPTBjcoDfNVtkQAz2cLaEGWAoux_oVoXLmha7RGbl_jWgm04__KF7HCIoM5c7C6BlOfIeUNQK39ofrMkcw5x8Z3rWdhCNOJmyMcUURkrlinYuevNsCONbfLoCgQexO9Xe6iZbyPNMsiuNtSj7pRHjz74TMRXg803yTucCwbH9k&grant_type=authorization_code&redirect_uri=https%3A%2F%2Fop.certification.openid.net%3A60097%2Fauthz_cb
39.178182 --> HEADERS: {'Content-Type': 'application/x-www-form-urlencoded', 'Authorization': u'Basic OTc3YzMyMjIwM2VkNDk3ZWI3MThhNTFhOGYzNWQ1NGI6NmMxYTQ4YmFkOWRhOWVhNjBhY2YyNzQ4OTY3YzllZjE3Y2QxOWY1ZThhYmQzNGM4Mjg4MWJhNDM1NDE0OTIyNA=='}
39.501765 <-- STATUS: 200
39.501810 <-- BODY: {"error":"invalid_grant","error_description":"Invalid code."}
39.502499 TokenErrorResponse: {
  "error": "invalid_grant",
  "error_description": "Invalid code."
}
39.512061 ==== END ====

Result

PASSED