Test Name | oidcc-client-test-session-management |
---|---|
Variant | client_secret_basic, plain_http_request, code, default, dynamic_client |
Test ID | 9BkuOKmbg3sr4qs |
Created | 2020-08-10T17:49:52.994973Z |
Description | mod_auth_openidc session management certification |
Test Version | 4.0.10 |
Test Owner | 109716492681686172969 https://accounts.google.com |
Plan ID | lKyYHilbFWy7W |
Exported From | https://www.certification.openid.net |
Exported By | 109716492681686172969 https://accounts.google.com |
Suite Version | 4.0.10 |
Exported | 2020-08-18 09:27:14 (UTC) |
Status: FINISHED Result: PASSED |
SUCCESS 56 FAILURE 0 WARNING 0 REVIEW 0 INFO 12 |
2020-08-10 17:49:53 |
INFO
|
TEST-RUNNER
Test instance 9BkuOKmbg3sr4qs created
|
||||||||||||||
|
2020-08-10 17:49:53 | SUCCESS |
OIDCCGenerateServerConfigurationWithSessionManagement
Generated default server configuration
|
||
|
2020-08-10 17:49:53 |
|
SetTokenEndpointAuthMethodsSupportedToClientSecretBasicOnly
Changed token_endpoint_auth_methods_supported to client_secret_basic only in server configuration
|
||
|
2020-08-10 17:49:53 |
|
OIDCCGenerateServerJWKs
Generated server public private JWK sets
|
||||||
|
2020-08-10 17:49:53 | SUCCESS |
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
|
|
2020-08-10 17:49:53 | SUCCESS |
CheckDistinctKeyIdValueInServerJWKs
Distinct 'kid' value in all keys of server_jwks
|
||
|
2020-08-10 17:49:53 |
SUCCESS
|
OIDCCLoadUserInfo
Added user information
|
||
|
2020-08-10 17:49:53 |
SUCCESS
|
GetDynamicClientConfiguration
Created dynamic_client_registration_template object from the client configuration.
|
||||||||
|
2020-08-10 17:49:53 |
|
oidcc-client-test-session-management
Setup Done
|
|
2020-08-10 17:50:49 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
2020-08-10 17:50:49 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:50:50 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Registration endpoint |
2020-08-10 17:50:50 |
SUCCESS
|
OIDCCExtractDynamicRegistrationRequest
Extracted dynamic client registration request
|
||
|
2020-08-10 17:50:50 |
SUCCESS
|
EnsureRegistrationRequestContainsAtLeastOneContact
Registration request contains valid contacts
|
||
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientGrantTypes
grant_types match response_types
|
||||
|
2020-08-10 17:50:50 | SUCCESS |
OIDCCValidateClientRedirectUris
Valid redirect_uri(s) provided in registration request
|
||
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientLogoUris
Client does not contain any logo_uri
|
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientUris
Client does not contain any client_uri
|
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientPolicyUris
Client does not contain any policy_uri
|
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientTosUris
Client does not contain any tos_uri
|
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientSubjectType
A subject_type was not provided
|
|
2020-08-10 17:50:50 | INFO |
ValidateIdTokenSignedResponseAlg
Skipped evaluation due to missing required element: client id_token_signed_response_alg
|
||||||
|
2020-08-10 17:50:50 | SUCCESS |
EnsureIdTokenEncryptedResponseAlgIsSetIfEncIsSet
id_token_encrypted_response_enc is not set
|
|
2020-08-10 17:50:50 | INFO |
ValidateUserinfoSignedResponseAlg
Skipped evaluation due to missing required element: client userinfo_signed_response_alg
|
||||||
|
2020-08-10 17:50:50 | SUCCESS |
EnsureUserinfoEncryptedResponseAlgIsSetIfEncIsSet
userinfo_encrypted_response_enc is not set
|
|
2020-08-10 17:50:50 | INFO |
ValidateRequestObjectSigningAlg
Skipped evaluation due to missing required element: client request_object_signing_alg
|
||||||
|
2020-08-10 17:50:50 | SUCCESS |
EnsureRequestObjectEncryptionAlgIsSetIfEncIsSet
request_object_encryption_enc is not set
|
|
2020-08-10 17:50:50 | INFO |
ValidateTokenEndpointAuthSigningAlg
Skipped evaluation due to missing required element: client token_endpoint_auth_signing_alg
|
||||||
|
2020-08-10 17:50:50 | SUCCESS |
ValidateDefaultMaxAge
default_max_age is not set
|
|
2020-08-10 17:50:50 | INFO |
ValidateRequireAuthTime
Skipped evaluation due to missing required element: client require_auth_time
|
||||||
|
2020-08-10 17:50:50 | INFO |
ValidateDefaultAcrValues
Skipped evaluation due to missing required element: client default_acr_values
|
||||||
|
2020-08-10 17:50:50 | SUCCESS |
ValidateInitiateLoginUri
initiate_login_uri is valid
|
||
|
2020-08-10 17:50:50 | INFO |
ValidateRequestUris
Skipped evaluation due to missing required element: client request_uris
|
||||||
|
2020-08-10 17:50:50 | SUCCESS |
ValidateClientRegistrationRequestSectorIdentifierUri
A sector_identifier_uri was not provided
|
|
2020-08-10 17:50:50 |
SUCCESS
|
OIDCCRegisterClient
Registered client
|
||
|
2020-08-10 17:50:50 |
|
OIDCCCreateClientSecretForDynamicClient
Set the secret for registered client
|
||
|
2020-08-10 17:50:50 |
SUCCESS
|
EnsureTokenEndPointAuthMethodIsClientSecretBasic
token_endpoint_auth_method is 'client_secret_basic' as expected
|
|
2020-08-10 17:50:50 | SUCCESS |
EnsureClientDoesNotHaveBothJwksAndJwksUri
Client does not have both jwks and jwks_uri set
|
||
|
2020-08-10 17:50:50 |
|
FetchClientKeys
Fetching client keys
|
||
|
2020-08-10 17:50:50 |
|
FetchClientKeys
HTTP request
|
||||||||
|
2020-08-10 17:50:50 |
RESPONSE
|
FetchClientKeys
HTTP response
|
||||||||
|
2020-08-10 17:50:50 |
|
FetchClientKeys
Found JWK set string
|
||
|
2020-08-10 17:50:50 | SUCCESS |
FetchClientKeys
Downloaded and added client JWK set to client
|
||
|
2020-08-10 17:50:50 |
SUCCESS
|
OIDCCExtractServerSigningAlg
Using the default algorithm for the first key in server jwks
|
||
|
2020-08-10 17:50:50 |
|
SetClientIdTokenSignedResponseAlgToServerSigningAlg
Set id_token_signed_response_alg for the registered client
|
||
|
2020-08-10 17:50:50 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:50:51 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Authorization endpoint |
2020-08-10 17:50:51 | SUCCESS |
EnsureRequestDoesNotContainRequestObject
Request does not contain a request parameter
|
|
2020-08-10 17:50:51 | SUCCESS |
OIDCCEnsureAuthorizationHttpRequestContainsOpenIDScope
Found 'openid' in scope http request parameter
|
||||
|
2020-08-10 17:50:51 | SUCCESS |
CreateEffectiveAuthorizationRequestParameters
Merged http request parameters with request object claims
|
||
|
2020-08-10 17:50:51 |
SUCCESS
|
ExtractRequestedScopes
Requested scopes
|
||
|
2020-08-10 17:50:51 | SUCCESS |
ExtractNonceFromAuthorizationRequest
Extracted nonce
|
||
|
2020-08-10 17:50:51 |
SUCCESS
|
EnsureResponseTypeIsCode
Response type is expected value
|
||
|
2020-08-10 17:50:51 | SUCCESS |
EnsureMatchingClientId
Client ID matched
|
||
|
2020-08-10 17:50:51 | SUCCESS |
EnsureValidRedirectUriForAuthorizationEndpointRequest
redirect_uri is one of the allowed redirect uris
|
||||
|
2020-08-10 17:50:51 | SUCCESS |
EnsureOpenIDInScopeRequest
Found 'openid' scope in request
|
||||
|
2020-08-10 17:50:51 | SUCCESS |
DisallowMaxAgeEqualsZeroAndPromptNone
The client did not send max_age=0 and prompt=none parameters as expected
|
|
2020-08-10 17:50:51 |
SUCCESS
|
CreateAuthorizationCode
Created authorization code
|
||
|
2020-08-10 17:50:51 | SUCCESS |
CalculateCHash
Successful c_hash encoding
|
||
|
2020-08-10 17:50:51 |
SUCCESS
|
CreateAuthorizationEndpointResponseParams
Added authorization_endpoint_response_params to environment
|
||
|
2020-08-10 17:50:51 | SUCCESS |
AddCodeToAuthorizationEndpointResponseParams
Added code to authorization endpoint response params
|
||
|
2020-08-10 17:50:51 |
|
GenerateSessionState
Generated session_state
|
||
|
2020-08-10 17:50:51 |
|
AddSessionStateToAuthorizationEndpointResponseParams
Added session_state to authorization endpoint response params
|
||
|
2020-08-10 17:50:51 |
|
SendAuthorizationResponseWithResponseModeQuery
Redirecting back to client
|
||
|
2020-08-10 17:50:51 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||
|
2020-08-10 17:50:51 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Token endpoint |
2020-08-10 17:50:51 | SUCCESS |
ExtractClientCredentialsFromBasicAuthorizationHeader
Extracted client authentication
|
||||||
|
2020-08-10 17:50:51 | SUCCESS |
ValidateClientIdAndSecret
Client id and secret match
|
|
2020-08-10 17:50:51 | SUCCESS |
ValidateAuthorizationCode
Found authorization code
|
||
|
2020-08-10 17:50:51 | SUCCESS |
ValidateRedirectUriForTokenEndpointRequest
redirect_uri is the same as the one used in the authorization request
|
||
|
2020-08-10 17:50:51 |
SUCCESS
|
GenerateBearerAccessToken
Generated access token
|
||
|
2020-08-10 17:50:51 | SUCCESS |
CalculateAtHash
Successful at_hash encoding
|
||
|
2020-08-10 17:50:51 |
SUCCESS
|
GenerateIdTokenClaims
Created ID Token Claims
|
||||||||||||
|
2020-08-10 17:50:51 | SUCCESS |
AddAtHashToIdTokenClaims
Added at_hash to ID token claims
|
||||
|
2020-08-10 17:50:51 | SUCCESS |
AddSidToIdTokenClaims
Added sid to ID token claims
|
||||
|
2020-08-10 17:50:51 | SUCCESS |
OIDCCSignIdToken
Signed the ID token
|
||||||
|
2020-08-10 17:50:51 | INFO |
EncryptIdToken
Skipped evaluation due to missing required element: client id_token_encrypted_response_alg
|
||||||
|
2020-08-10 17:50:51 | SUCCESS |
CreateTokenEndpointResponse
Created token endpoint response
|
||||||||
|
2020-08-10 17:50:51 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:50:52 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
2020-08-10 17:50:52 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:50:52 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Userinfo endpoint |
2020-08-10 17:50:52 | SUCCESS |
OIDCCExtractBearerAccessTokenFromRequest
Found access token on incoming request
|
||
|
2020-08-10 17:50:52 | SUCCESS |
RequireBearerAccessToken
Found access token in request
|
||
|
2020-08-10 17:50:52 | SUCCESS |
FilterUserInfoForScopes
User info endpoint output
|
||
|
2020-08-10 17:50:52 |
|
ClearAccessTokenFromRequest
Condition ran but did not log anything
|
|
2020-08-10 17:50:52 | INFO |
AddIssAndAudToUserInfoResponse
Skipped evaluation due to missing required element: client userinfo_signed_response_alg
|
||||||
|
2020-08-10 17:50:52 | INFO |
SignUserInfoResponse
Skipped evaluation due to missing required element: client userinfo_signed_response_alg
|
||||||
|
2020-08-10 17:50:52 | INFO |
EncryptUserInfoResponse
Skipped evaluation due to missing required element: client userinfo_encrypted_response_alg
|
||||||
|
2020-08-10 17:50:52 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:50:52 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
check_session_iframe requested |
2020-08-10 17:50:52 |
|
LogCheckSessionIframeRequest
The client requested check_session_iframe
|
|
2020-08-10 17:50:52 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||
|
2020-08-10 17:50:59 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:50:59 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:50:59 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:50:59 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
check_session_iframe requested |
2020-08-10 17:50:59 |
|
LogCheckSessionIframeRequest
The client requested check_session_iframe
|
|
2020-08-10 17:50:59 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||
|
2020-08-10 17:51:04 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:04 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:04 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:05 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:05 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:05 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:09 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:09 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:09 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:10 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:10 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:10 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:16 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:16 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:16 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:17 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:17 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:17 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:20 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:20 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:20 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:20 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:20 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:20 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:23 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:23 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:23 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:25 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:25 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe
|
||
|
2020-08-10 17:51:25 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:26 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
End session endpoint |
2020-08-10 17:51:26 | SUCCESS |
ValidateIdTokenHintInRPInitiatedLogoutRequest
id_token_hint was issued by this test instance
|
||
|
2020-08-10 17:51:26 | SUCCESS |
ValidatePostLogoutRedirectUri
post_logout_redirect_uri is one of the registered post_logout_redirect_uris
|
||
|
2020-08-10 17:51:26 |
|
CreatePostLogoutRedirectUriParams
Added post_logout_redirect_uri parameters to environment
|
||
|
2020-08-10 17:51:26 | SUCCESS |
CreatePostLogoutRedirectUriRedirect
Created post_logout_redirect_uri redirect
|
||
|
2020-08-10 17:51:26 |
|
LogoutByRemovingSessionState
Removed session state
|
|
2020-08-10 17:51:26 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||
|
2020-08-10 17:51:30 |
INCOMING
|
oidcc-client-test-session-management
Incoming HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||||||||
|
Get session state - postMessage callback |
2020-08-10 17:51:30 |
|
LogGetSessionStateRequest
OP iframe received postMessage request from RP iframe but the user is not logged in
|
|
2020-08-10 17:51:30 |
OUTGOING
|
oidcc-client-test-session-management
Response to HTTP request to test instance 9BkuOKmbg3sr4qs
|
||||||||
|
2020-08-10 17:51:30 |
FINISHED
|
oidcc-client-test-session-management
Test has run to completion
|
||
|