Test Name | fapi1-advanced-final-brazil-dcr-happy-flow |
---|---|
Variant | client_auth_type=private_key_jwt, fapi_auth_request_method=by_value, fapi_profile=openbanking_brazil, fapi_response_mode=plain_response |
Test ID | zSmtsTPvWatTU7A https://www.certification.openid.net/log-detail.html?public=true&log=zSmtsTPvWatTU7A |
Created | 2021-07-02T15:51:28.252592Z |
Description | Teste com cert Banrisul |
Test Version | 4.1.17 |
Test Owner | 102072781963629492257 https://accounts.google.com |
Plan ID | k8dkAHJsqT5c4 https://www.certification.openid.net/plan-detail.html?public=true&plan=k8dkAHJsqT5c4 |
Exported From | https://www.certification.openid.net |
Exported By | 102072781963629492257 https://accounts.google.com |
Suite Version | 4.1.17 |
Exported | 2021-07-03 14:01:45 (UTC) |
Status: FINISHED Result: WARNING |
SUCCESS 119 FAILURE 0 WARNING 1 REVIEW 0 INFO 11 |
2021-07-02 15:51:28 |
INFO
|
TEST-RUNNER
Test instance zSmtsTPvWatTU7A created
|
||||||||||||||
|
2021-07-02 15:51:28 |
SUCCESS
|
CreateRedirectUri
Created redirect URI
|
||
|
2021-07-02 15:51:28 |
|
GetDynamicServerConfiguration
HTTP request
|
||||||||
|
2021-07-02 15:51:29 |
RESPONSE
|
GetDynamicServerConfiguration
HTTP response
|
||||||||
|
2021-07-02 15:51:29 |
|
GetDynamicServerConfiguration
Downloaded server configuration
|
||
|
2021-07-02 15:51:29 |
SUCCESS
|
GetDynamicServerConfiguration
Successfully parsed server configuration
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
2021-07-02 15:51:29 | SUCCESS |
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
|
||
|
2021-07-02 15:51:29 |
SUCCESS
|
CheckServerConfiguration
Found required server configuration keys
|
||
|
2021-07-02 15:51:29 |
|
FetchServerKeys
Fetching server key
|
||
|
2021-07-02 15:51:29 |
|
FetchServerKeys
HTTP request
|
||||||||
|
2021-07-02 15:51:30 |
RESPONSE
|
FetchServerKeys
HTTP response
|
||||||||
|
2021-07-02 15:51:30 |
|
FetchServerKeys
Found JWK set string
|
||
|
2021-07-02 15:51:30 |
SUCCESS
|
FetchServerKeys
Found server JWK set
|
||
|
2021-07-02 15:51:30 |
SUCCESS
|
CheckServerKeysIsValid
Server JWKs is valid
|
||
|
2021-07-02 15:51:30 | SUCCESS |
ValidateServerJWKs
Valid server JWKs: keys are valid JSON, contain the required fields and are correctly encoded using unpadded base64url
|
|
2021-07-02 15:51:30 | SUCCESS |
CheckForKeyIdInServerJWKs
All keys contain kids
|
|
2021-07-02 15:51:30 | SUCCESS |
EnsureServerJwksDoesNotContainPrivateOrSymmetricKeys
Jwks does not contain any private or symmetric keys
|
|
2021-07-02 15:51:30 | SUCCESS |
FAPIEnsureMinimumServerKeyLength
Validated minimum key lengths for server_jwks
|
||
|
2021-07-02 15:51:30 |
SUCCESS
|
ValidateMTLSCertificatesHeader
MTLS certificates header is valid
|
|
2021-07-02 15:51:30 |
SUCCESS
|
ExtractMTLSCertificatesFromConfiguration
Mutual TLS authentication credentials loaded
|
||||||
|
2021-07-02 15:51:30 |
SUCCESS
|
ExtractJWKSDirectFromClientConfiguration
Extracted client JWK
|
||||
|
2021-07-02 15:51:30 | SUCCESS |
CheckDistinctKeyIdValueInClientJWKs
Distinct 'kid' value in all keys of client_jwks
|
||
|
Obtain access token for directory and retrieve a software statement |
2021-07-02 15:51:30 |
SUCCESS
|
ExtractDirectoryConfiguration
Extracted directory configuration parameters
|
||||
|
2021-07-02 15:51:30 |
|
GetDynamicServerConfiguration
HTTP request
|
||||||||||
|
2021-07-02 15:51:30 |
RESPONSE
|
GetDynamicServerConfiguration
HTTP response
|
||||||||
|
2021-07-02 15:51:30 |
|
GetDynamicServerConfiguration
Downloaded server configuration
|
||
|
2021-07-02 15:51:30 |
SUCCESS
|
GetDynamicServerConfiguration
Successfully parsed server configuration
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
2021-07-02 15:51:30 | SUCCESS |
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
|
||
|
2021-07-02 15:51:30 |
|
CreateTokenEndpointRequestForClientCredentialsGrant
Leaving off 'scope' parameter from token request
|
|
2021-07-02 15:51:30 |
SUCCESS
|
CreateTokenEndpointRequestForClientCredentialsGrant
|
||
|
2021-07-02 15:51:30 |
SUCCESS
|
SetDirectorySoftwareScopeOnTokenEndpointRequest
Set scope parameter to 'directory:software'
|
||||
|
2021-07-02 15:51:30 |
SUCCESS
|
AddClientIdToTokenEndpointRequest
|
||||||
|
2021-07-02 15:51:30 |
|
CallTokenEndpoint
HTTP request
|
||||||||||
|
2021-07-02 15:51:31 |
RESPONSE
|
CallTokenEndpoint
HTTP response
|
||||||||
|
2021-07-02 15:51:31 |
|
CallTokenEndpoint
Token endpoint response
|
||
|
2021-07-02 15:51:31 |
SUCCESS
|
CallTokenEndpoint
Parsed token endpoint response
|
||||||||
|
2021-07-02 15:51:31 |
SUCCESS
|
CheckIfTokenEndpointResponseError
No error from token endpoint
|
|
2021-07-02 15:51:31 |
SUCCESS
|
CheckForAccessTokenValue
Found an access token
|
||
|
2021-07-02 15:51:31 |
SUCCESS
|
ExtractAccessTokenFromTokenResponse
Extracted the access token
|
||||
|
2021-07-02 15:51:31 | SUCCESS |
AddMTLSEndpointAliasesToEnvironment
Added mtls_endpoint_aliases to environment
|
||
|
2021-07-02 15:51:31 |
SUCCESS
|
FAPIBrazilExtractClientMTLSCertificateSubject
Extracted subject from MTLS certificate
|
||||||
|
2021-07-02 15:51:31 |
|
FAPIBrazilCallDirectorySoftwareStatementEndpointWithBearerToken
HTTP request
|
||||||||||
|
2021-07-02 15:51:32 |
RESPONSE
|
FAPIBrazilCallDirectorySoftwareStatementEndpointWithBearerToken
HTTP response
|
||||||||
|
2021-07-02 15:51:32 |
|
FAPIBrazilCallDirectorySoftwareStatementEndpointWithBearerToken
software statement endpoint response
|
||
|
2021-07-02 15:51:32 |
SUCCESS
|
FAPIBrazilCallDirectorySoftwareStatementEndpointWithBearerToken
Parsed assertion endpoint response
|
||||||
|
Perform Dynamic Client Registration |
2021-07-02 15:51:32 |
|
StoreOriginalClientConfiguration
Created original_client_config object from the client configuration.
|
||||
|
2021-07-02 15:51:32 |
|
ExtractClientNameFromStoredConfig
Extracted client_name from stored client configuration.
|
||
|
2021-07-02 15:51:32 | SUCCESS |
FAPIBrazilExtractJwksUriFromSoftwareStatement
Extracted JWKS URI from software statement
|
||
|
2021-07-02 15:51:32 |
|
CreateEmptyDynamicRegistrationRequest
Created empty dynamic registration request
|
|
2021-07-02 15:51:32 |
|
AddAuthorizationCodeGrantTypeToDynamicRegistrationRequest
Added 'authorization_code' to 'grant_types'
|
||
|
2021-07-02 15:51:32 |
|
AddImplicitGrantTypeToDynamicRegistrationRequest
Added 'implicit' to 'grant_types'
|
||
|
2021-07-02 15:51:32 |
|
AddRefreshTokenGrantTypeToDynamicRegistrationRequest
Added 'refresh_token' to 'grant_types'
|
||
|
2021-07-02 15:51:32 |
|
AddClientCredentialsGrantTypeToDynamicRegistrationRequest
Added 'client_credentials' to 'grant_types'
|
||
|
2021-07-02 15:51:32 |
|
AddJwksUriToDynamicRegistrationRequest
Added jwks_uri to dynamic registration request
|
||
|
2021-07-02 15:51:32 |
|
AddTokenEndpointAuthMethodToDynamicRegistrationRequestFromEnvironment
Added token endpoint auth method to dynamic registration request
|
||
|
2021-07-02 15:51:32 |
|
SetResponseTypeCodeIdTokenInDynamicRegistrationRequest
Added response_type 'code id_token' to dynamic registration request
|
||
|
2021-07-02 15:51:32 |
|
FapiBrazilVerifyRedirectUriContainedInSoftwareStatement
Required redirect_uri is present in the software statement
|
||||
|
2021-07-02 15:51:32 |
|
AddRedirectUriToDynamicRegistrationRequest
Added redirect_uris array to dynamic registration request
|
||
|
2021-07-02 15:51:32 |
|
AddSoftwareStatementToDynamicRegistrationRequest
Added software_statement to dynamic registration request
|
||
|
2021-07-02 15:51:32 |
|
CallDynamicRegistrationEndpoint
HTTP request
|
||||||||||
|
2021-07-02 15:51:34 |
RESPONSE
|
CallDynamicRegistrationEndpoint
HTTP response
|
||||||||
|
2021-07-02 15:51:34 |
|
CallDynamicRegistrationEndpoint
Registration endpoint response
|
||
|
2021-07-02 15:51:34 |
|
CallDynamicRegistrationEndpoint
Parsed registration endpoint response
|
||||||||||||||||||||||||||||||||||||||||||||||||||
|
2021-07-02 15:51:34 |
SUCCESS
|
CallDynamicRegistrationEndpoint
Extracted dynamic registration management credentials
|
||||
|
2021-07-02 15:51:34 |
|
CopyScopeFromDynamicRegistrationTemplateToClientConfiguration
Copied scope from original_client_config to client configuration
|
||
|
2021-07-02 15:51:34 |
SUCCESS
|
GetResourceEndpointConfiguration
Found a resource endpoint object
|
||||||||
|
2021-07-02 15:51:34 |
SUCCESS
|
SetProtectedResourceUrlToSingleResourceEndpoint
Set protected resource URL
|
||
|
2021-07-02 15:51:34 |
SUCCESS
|
ExtractTLSTestValuesFromResourceConfiguration
Extracted TLS information from resource endpoint
|
||
|
2021-07-02 15:51:34 |
SUCCESS
|
ExtractTLSTestValuesFromOBResourceConfiguration
Extracted TLS information from resource endpoint
|
||||
|
2021-07-02 15:51:34 |
|
fapi1-advanced-final-brazil-dcr-happy-flow
Setup Done
|
|
Use client_credentials grant to obtain Brazil consent |
2021-07-02 15:51:34 |
SUCCESS
|
CreateTokenEndpointRequestForClientCredentialsGrant
|
||||
|
2021-07-02 15:51:34 |
SUCCESS
|
SetConsentsScopeOnTokenEndpointRequest
Set scope parameter to 'consents'
|
||||
|
2021-07-02 15:51:34 |
SUCCESS
|
CreateClientAuthenticationAssertionClaims
Created client assertion claims
|
||||||||||||
|
2021-07-02 15:51:34 |
SUCCESS
|
SignClientAuthenticationAssertion
Signed the client assertion
|
||
|
2021-07-02 15:51:34 |
|
AddClientAssertionToTokenEndpointRequest
Added client assertion
|
||||||||
|
2021-07-02 15:51:34 |
|
CallTokenEndpoint
HTTP request
|
||||||||||
|
2021-07-02 15:51:35 |
RESPONSE
|
CallTokenEndpoint
HTTP response
|
||||||||
|
2021-07-02 15:51:35 |
|
CallTokenEndpoint
Token endpoint response
|
||
|
2021-07-02 15:51:35 |
SUCCESS
|
CallTokenEndpoint
Parsed token endpoint response
|
||||||||
|
2021-07-02 15:51:35 |
SUCCESS
|
CheckIfTokenEndpointResponseError
No error from token endpoint
|
|
2021-07-02 15:51:35 |
SUCCESS
|
CheckForAccessTokenValue
Found an access token
|
||
|
2021-07-02 15:51:35 |
SUCCESS
|
ExtractAccessTokenFromTokenResponse
Extracted the access token
|
||||
|
2021-07-02 15:51:35 | SUCCESS |
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
|
||
|
2021-07-02 15:51:35 | SUCCESS |
ValidateExpiresIn
expires_in passed all validation checks
|
||
|
2021-07-02 15:51:35 |
|
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
|
||
|
2021-07-02 15:51:35 |
SUCCESS
|
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
|
||
|
2021-07-02 15:51:35 |
SUCCESS
|
FAPIBrazilCreateConsentRequest
|
||
|
2021-07-02 15:51:35 |
SUCCESS
|
FAPIBrazilAddExpirationToConsentRequest
Added expiration time to consent request
|
||
|
2021-07-02 15:51:35 |
|
CallConsentEndpointWithBearerToken
HTTP request
|
||||||||||
|
2021-07-02 15:51:39 |
RESPONSE
|
CallConsentEndpointWithBearerToken
HTTP response
|
||||||||
|
2021-07-02 15:51:39 |
|
CallConsentEndpointWithBearerToken
Consent endpoint response
|
||
|
2021-07-02 15:51:39 |
SUCCESS
|
CallConsentEndpointWithBearerToken
Parsed consent endpoint response
|
||||
|
2021-07-02 15:51:39 | SUCCESS |
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
|
||
|
2021-07-02 15:51:39 |
SUCCESS
|
ExtractConsentIdFromConsentEndpointResponse
Extracted the consent id
|
||
|
2021-07-02 15:51:39 |
SUCCESS
|
FAPIBrazilAddConsentIdToClientScope
Added scope of 'openid accounts consents consent consent:urn:bergs:0ecb75a6-c79c-4d5b-8917-f19139ab5f07' to client's scope
|
||||||||||||||||||||||||||||||||||||||||||||||||||
|
Make request to authorization endpoint |
2021-07-02 15:51:39 |
SUCCESS
|
CreateAuthorizationEndpointRequestFromClientInformation
Created authorization endpoint request
|
||||||
|
2021-07-02 15:51:39 |
|
CreateRandomStateValue
Created state value
|
||||
|
2021-07-02 15:51:39 |
SUCCESS
|
AddStateToAuthorizationEndpointRequest
Added state parameter to request
|
||||||||
|
2021-07-02 15:51:39 |
|
CreateRandomNonceValue
Created nonce value
|
||||
|
2021-07-02 15:51:39 |
SUCCESS
|
AddNonceToAuthorizationEndpointRequest
Added nonce parameter to request
|
||||||||||
|
2021-07-02 15:51:39 |
SUCCESS
|
SetAuthorizationEndpointRequestResponseTypeToCodeIdtoken
Added response_type parameter to request
|
||||||||||||
|
2021-07-02 15:51:39 |
SUCCESS
|
ConvertAuthorizationEndpointRequestToRequestObject
Created request object claims
|
||
|
2021-07-02 15:51:39 | SUCCESS |
AddNbfToRequestObject
Added nbf to request object claims
|
||
|
2021-07-02 15:51:39 | SUCCESS |
AddExpToRequestObject
Added exp to request object claims
|
||
|
2021-07-02 15:51:39 | SUCCESS |
AddAudToRequestObject
Added aud to request object claims
|
||
|
2021-07-02 15:51:39 | SUCCESS |
AddIssToRequestObject
Added iss to request object claims
|
||
|
2021-07-02 15:51:39 | SUCCESS |
AddClientIdToRequestObject
Added client_id to request object claims
|
||
|
2021-07-02 15:51:39 |
SUCCESS
|
SignRequestObject
Signed the request object
|
||||||||
|
2021-07-02 15:51:39 |
|
FAPIBrazilEncryptRequestObject
Encrypted the request object
|
||||||
|
2021-07-02 15:51:39 |
SUCCESS
|
BuildRequestObjectByValueRedirectToAuthorizationEndpoint
Sending to authorization endpoint
|
||
|
2021-07-02 15:51:39 |
REDIRECT
|
fapi1-advanced-final-brazil-dcr-happy-flow
Redirecting to authorization endpoint
|
||
|
2021-07-02 15:51:57 |
INCOMING
|
fapi1-advanced-final-brazil-dcr-happy-flow
Incoming HTTP request to test instance zSmtsTPvWatTU7A
|
||||||||||||||
|
2021-07-02 15:51:57 |
SUCCESS
|
CreateRandomImplicitSubmitUrl
Created random implicit submission URL
|
||
|
2021-07-02 15:51:57 |
OUTGOING
|
fapi1-advanced-final-brazil-dcr-happy-flow
Response to HTTP request to test instance zSmtsTPvWatTU7A
|
||||
|
2021-07-02 15:51:57 |
INCOMING
|
fapi1-advanced-final-brazil-dcr-happy-flow
Incoming HTTP request to test instance zSmtsTPvWatTU7A
|
||||||||||||||
|
2021-07-02 15:51:57 |
OUTGOING
|
fapi1-advanced-final-brazil-dcr-happy-flow
Response to HTTP request to test instance zSmtsTPvWatTU7A
|
||||||||
|
2021-07-02 15:51:57 |
|
ExtractImplicitHashToCallbackResponse
Extracted response from URL fragment
|
||
|
2021-07-02 15:51:57 |
SUCCESS
|
ExtractImplicitHashToCallbackResponse
Extracted the hash values
|
||||||||
|
2021-07-02 15:51:57 |
REDIRECT-IN
|
fapi1-advanced-final-brazil-dcr-happy-flow
Authorization endpoint response captured
|
||||||||||
|
Verify authorization endpoint response |
2021-07-02 15:51:57 | SUCCESS |
RejectErrorInUrlQuery
'error' is not present in URL query returned from authorization endpoint
|
|
2021-07-02 15:51:57 | SUCCESS |
RejectAuthCodeInUrlQuery
Authorization code is not present in URL query returned from authorization endpoint
|
|
2021-07-02 15:51:57 |
SUCCESS
|
CheckMatchingCallbackParameters
Callback parameters successfully verified
|
|
2021-07-02 15:51:57 | SUCCESS |
RejectStateInUrlQueryForHybridFlow
state is correctly not present in URL query returned from authorization endpoint (as in the hybrid flow it must be returned in the URL fragment/hash only)
|
|
2021-07-02 15:51:57 |
SUCCESS
|
CheckIfAuthorizationEndpointError
No error from authorization endpoint
|
|
2021-07-02 15:51:57 |
WARNING
|
ValidateSuccessfulHybridResponseFromAuthorizationEndpoint
authorization endpoint response includes unexpected parameters. This may be because the authorization server supports protocol extensions the conformance suite is unaware of, but may also be because the server is implementing the specification incorrectly.
|
||
|
2021-07-02 15:51:57 | SUCCESS |
CheckStateInAuthorizationResponse
State in response correctly returned
|
||
|
2021-07-02 15:51:57 |
|
ValidateIssInAuthorizationResponse
No 'iss' value in authorization response.
|
|
2021-07-02 15:51:57 |
SUCCESS
|
ExtractAuthorizationCodeFromAuthorizationResponse
Found authorization code
|
||
|
2021-07-02 15:51:57 | SUCCESS |
EnsureMinimumAuthorizationCodeLength
Authorization code is of sufficient length
|
||||
|
2021-07-02 15:51:57 | SUCCESS |
EnsureMinimumAuthorizationCodeEntropy
Calculated shannon entropy seems sufficient
|
||||
|
2021-07-02 15:51:57 | SUCCESS |
ExtractIdTokenFromAuthorizationResponse
Found and parsed the id_token from authorization_endpoint_response
|
||||||
|
2021-07-02 15:51:57 | SUCCESS |
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
|
|
2021-07-02 15:51:57 | SUCCESS |
EnsureIdTokenContainsKid
kid was found in the ID token header
|
||
|
2021-07-02 15:51:57 | SUCCESS |
ValidateIdTokenNonce
Nonce values match
|
||
|
2021-07-02 15:51:57 | SUCCESS |
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
|
|
2021-07-02 15:51:57 | SUCCESS |
ValidateIdTokenSignature
id_token signature validated
|
||
|
2021-07-02 15:51:57 | SUCCESS |
ValidateIdTokenSignatureUsingKid
id_token signature validated
|
||
|
2021-07-02 15:51:57 | SUCCESS |
CheckForSubjectInIdToken
Found 'sub' in id_token
|
||
|
2021-07-02 15:51:57 | SUCCESS |
FAPIValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
|
||||
|
2021-07-02 15:51:57 | INFO |
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
|
||||||
|
2021-07-02 15:51:57 | INFO |
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
|
||||||
|
2021-07-02 15:51:57 | SUCCESS |
ExtractSHash
Extracted s_hash from ID Token
|
||||
|
2021-07-02 15:51:57 | SUCCESS |
ValidateSHash
s_hash validated successfully
|
||||||
|
2021-07-02 15:51:57 | SUCCESS |
ExtractCHash
Extracted c_hash from ID Token
|
||||
|
2021-07-02 15:51:57 | SUCCESS |
ValidateCHash
c_hash validated successfully
|
||||||
|
Call token endpoint |
2021-07-02 15:51:57 |
SUCCESS
|
CreateTokenEndpointRequestForAuthorizationCodeGrant
|
||||||
|
2021-07-02 15:51:57 |
SUCCESS
|
CreateClientAuthenticationAssertionClaims
Created client assertion claims
|
||||||||||||
|
2021-07-02 15:51:57 |
SUCCESS
|
SignClientAuthenticationAssertion
Signed the client assertion
|
||
|
2021-07-02 15:51:57 |
|
AddClientAssertionToTokenEndpointRequest
Added client assertion
|
||||||||||
|
2021-07-02 15:51:57 |
|
CallTokenEndpoint
HTTP request
|
||||||||||
|
2021-07-02 15:51:58 |
RESPONSE
|
CallTokenEndpoint
HTTP response
|
||||||||
|
2021-07-02 15:51:58 |
|
CallTokenEndpoint
Token endpoint response
|
||
|
2021-07-02 15:51:58 |
SUCCESS
|
CallTokenEndpoint
Parsed token endpoint response
|
||||||||||||||
|
Verify token endpoint response |
2021-07-02 15:51:58 |
SUCCESS
|
CheckIfTokenEndpointResponseError
No error from token endpoint
|
|
2021-07-02 15:51:58 | SUCCESS |
CheckForAccessTokenValue
Found an access token
|
||
|
2021-07-02 15:51:58 |
SUCCESS
|
ExtractAccessTokenFromTokenResponse
Extracted the access token
|
||||
|
2021-07-02 15:51:58 | SUCCESS |
ExtractExpiresInFromTokenEndpointResponse
Extracted 'expires_in'
|
||
|
2021-07-02 15:51:58 | SUCCESS |
ValidateExpiresIn
expires_in passed all validation checks
|
||
|
2021-07-02 15:51:58 | SUCCESS |
FAPIBrazilValidateExpiresIn
expires_in no greater than 900 seconds and no less than 300 seconds
|
||
|
2021-07-02 15:51:58 |
SUCCESS
|
CheckForRefreshTokenValue
Found a refresh token
|
||
|
2021-07-02 15:51:58 | SUCCESS |
EnsureMinimumRefreshTokenLength
Refresh token is of sufficient length
|
||||
|
2021-07-02 15:51:58 | SUCCESS |
EnsureMinimumRefreshTokenEntropy
Calculated shannon entropy seems sufficient
|
||||
|
2021-07-02 15:51:58 | SUCCESS |
EnsureMinimumAccessTokenLength
Access token is of sufficient length
|
||||
|
2021-07-02 15:51:58 | SUCCESS |
EnsureMinimumAccessTokenEntropy
Calculated shannon entropy seems sufficient
|
||||
|
2021-07-02 15:51:58 | SUCCESS |
ExtractIdTokenFromTokenResponse
Found and parsed the id_token from token_endpoint_response
|
||||||
|
2021-07-02 15:51:58 | SUCCESS |
ValidateIdToken
ID token iss, aud, exp, iat, auth_time, acr & nbf claims passed validation checks
|
|
2021-07-02 15:51:58 | SUCCESS |
EnsureIdTokenContainsKid
kid was found in the ID token header
|
||
|
2021-07-02 15:51:58 | SUCCESS |
ValidateIdTokenNonce
Nonce values match
|
||
|
2021-07-02 15:51:58 | SUCCESS |
ValidateIdTokenACRClaimAgainstRequest
Nothing to check; the conformance suite did not request an acr claim in request object
|
|
2021-07-02 15:51:58 | SUCCESS |
ValidateIdTokenSignature
id_token signature validated
|
||
|
2021-07-02 15:51:58 | SUCCESS |
ValidateIdTokenSignatureUsingKid
id_token signature validated
|
||
|
2021-07-02 15:51:58 | SUCCESS |
CheckForSubjectInIdToken
Found 'sub' in id_token
|
||
|
2021-07-02 15:51:58 | SUCCESS |
FAPIBrazilValidateIdTokenSigningAlg
id_token was signed with a permitted algorithm
|
||||
|
2021-07-02 15:51:58 | INFO |
FAPIValidateIdTokenEncryptionAlg
Skipped evaluation due to missing required element: id_token jwe_header
|
||||||
|
2021-07-02 15:51:58 | INFO |
FAPIValidateEncryptedIdTokenHasKid
Skipped evaluation due to missing required element: id_token jwe_header
|
||||||
|
2021-07-02 15:51:58 | SUCCESS |
ExtractCHash
Extracted c_hash from ID Token
|
||||
|
2021-07-02 15:51:58 | INFO |
ExtractSHash
Couldn't find s_hash in ID token
|
|
2021-07-02 15:51:58 | INFO |
ExtractAtHash
Couldn't find at_hash in ID token
|
|
2021-07-02 15:51:58 | SUCCESS |
ValidateCHash
c_hash validated successfully
|
||||||
|
2021-07-02 15:51:58 | INFO |
ValidateSHash
Skipped evaluation due to missing required object: s_hash
|
||||
|
2021-07-02 15:51:58 | INFO |
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
|
||||
|
Verify at_hash in the authorization endpoint id_token |
2021-07-02 15:51:58 | INFO |
ExtractAtHash
Couldn't find at_hash in ID token
|
|
2021-07-02 15:51:58 | INFO |
ValidateAtHash
Skipped evaluation due to missing required object: at_hash
|
||||
|
Resource server endpoint tests |
2021-07-02 15:51:58 |
|
CreateEmptyResourceEndpointRequestHeaders
Created empty headers
|
||
|
2021-07-02 15:51:58 | SUCCESS |
AddFAPIAuthDateToResourceEndpointRequest
Added x-fapi-auth-date to resource endpoint request headers
|
||
|
2021-07-02 15:51:58 |
|
AddIpV4FapiCustomerIpAddressToResourceEndpointRequest
Added x-fapi-customer-ip-address containing IPv4 address to resource endpoint request headers
|
||
|
2021-07-02 15:51:58 |
|
CreateRandomFAPIInteractionId
Created interaction ID
|
||
|
2021-07-02 15:51:58 | SUCCESS |
AddFAPIInteractionIdToResourceEndpointRequest
Added x-fapi-interaction-id to resource endpoint request headers
|
||
|
2021-07-02 15:51:58 |
|
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP request
|
||||||||||
|
2021-07-02 15:51:59 |
RESPONSE
|
CallProtectedResourceWithBearerTokenAndCustomHeaders
HTTP response
|
||||||||
|
2021-07-02 15:51:59 | SUCCESS |
CallProtectedResourceWithBearerTokenAndCustomHeaders
Got a response from the resource endpoint
|
||||||
|
2021-07-02 15:51:59 | SUCCESS |
CheckForDateHeaderInResourceResponse
Date header present and validated
|
||||
|
2021-07-02 15:51:59 | SUCCESS |
CheckForFAPIInteractionIdInResourceResponse
Found x-fapi-interaction-id
|
||
|
2021-07-02 15:51:59 | SUCCESS |
EnsureMatchingFAPIInteractionId
Interaction ID matched
|
||
|
2021-07-02 15:51:59 | SUCCESS |
EnsureResourceResponseReturnedJsonContentType
Response content type is JSON
|
||
|
2021-07-02 15:51:59 |
FINISHED
|
fapi1-advanced-final-brazil-dcr-happy-flow
Test has run to completion
|
||
|