diff --git a/README.md b/README.md index e66c7d4..9f113ee 100644 --- a/README.md +++ b/README.md @@ -707,6 +707,39 @@ oauth2c https://oauth2c.us.authz.cloudentity.io/oauth2c/demo \ --rar '[{"type":"payment_initiation","locations":["https://example.com/payments"],"instructedAmount":{"currency":"EUR","amount":"123.50"},"creditorName":"Merchant A","creditorAccount":{"bic":"ABCIDEFFXXX","iban":"DE02100100109307118603"},"remittanceInformationUnstructured":"Ref Number Merchant"}]' ``` +#### Client ID Metadata Document (CIMD) + +With [CIMD](https://datatracker.ietf.org/doc/draft-ietf-oauth-client-id-metadata-document/) +the `client_id` is an https URL of a JSON document describing the client, so it +needs no registration at the authorization server. This repository publishes +example documents on GitHub Pages; they use the same test keys as the examples +above and the default callback `http://localhost:9876/callback`. They are for +testing only: the private key is public, so anyone can act as these clients. + +| Document | Client authentication | +|---|---| +| [`data/cimd/public.json`](https://secureauthcorp.github.io/oauth2c/data/cimd/public.json) | `none` (public client, PKCE) | +| [`data/cimd/private-key-jwt.json`](https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt.json) | `private_key_jwt`, keys from `jwks_uri` | +| [`data/cimd/private-key-jwt-inline-jwks.json`](https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt-inline-jwks.json) | `private_key_jwt`, keys inline in `jwks` | + +The authorization server must support CIMD (`client_id_metadata_document_supported` +in its metadata). + +```sh +oauth2c https:// \ + --client-id https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt.json \ + --signing-key https://raw.githubusercontent.com/SecureAuthCorp/oauth2c/master/data/rsa/key.json \ + --response-types code \ + --response-mode query \ + --grant-type authorization_code \ + --auth-method private_key_jwt \ + --scopes openid,email \ + --pkce +``` + +For the public client use `--client-id https://secureauthcorp.github.io/oauth2c/data/cimd/public.json`, +`--auth-method none` and no `--signing-key`. + ### Miscellaneous #### Using HTTPs for Callback URL diff --git a/data/cimd/private-key-jwt-inline-jwks.json b/data/cimd/private-key-jwt-inline-jwks.json new file mode 100644 index 0000000..1afb47e --- /dev/null +++ b/data/cimd/private-key-jwt-inline-jwks.json @@ -0,0 +1,29 @@ +{ + "client_id": "https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt-inline-jwks.json", + "client_name": "oauth2c (private_key_jwt, inline jwks)", + "client_uri": "https://github.com/SecureAuthCorp/oauth2c", + "redirect_uris": [ + "http://localhost:9876/callback" + ], + "grant_types": [ + "authorization_code", + "refresh_token" + ], + "response_types": [ + "code" + ], + "token_endpoint_auth_method": "private_key_jwt", + "jwks": { + "keys": [ + { + "kty": "RSA", + "e": "AQAB", + "use": "sig", + "kid": "Ana-TpIxraP9mCAwyAbxk40LqpE5Utfjjd4EQrc6sBM", + "alg": "RS256", + "n": "rhipCrDSyEJpr8JJnBORLXb4jYbzCDNJAYCUCuYts-z7iLTnfNv2AkmphbY9EpGk1j96IQZq7g4fwFLh5HS9SFEPpTRh2-5Pp1QRnd-nhSaeT7hkVXGTGjlmRDHgv1-69_MZFSuBFA9I3yzdT7LlkWwPZS7WL5MYHNtbLJSIF1ls-MLleGci5qWCcLXPqMpeG_VEA53IhfIcVIMDU3g3gWqqEM7CTWdkdJ12fUyMpEPzF1VOYGadO181zdo6sIkdyWqAoCesUv_9Xpi9weJT_yduiInb0xzpsriP_U-dXwHf0ULI7vKIqa--WMbGUHD974tSxTOknYvRSyGRHWClmw" + } + ] + }, + "scope": "openid email profile offline_access" +} diff --git a/data/cimd/private-key-jwt.json b/data/cimd/private-key-jwt.json new file mode 100644 index 0000000..99ce8cc --- /dev/null +++ b/data/cimd/private-key-jwt.json @@ -0,0 +1,18 @@ +{ + "client_id": "https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt.json", + "client_name": "oauth2c (private_key_jwt, jwks_uri)", + "client_uri": "https://github.com/SecureAuthCorp/oauth2c", + "redirect_uris": [ + "http://localhost:9876/callback" + ], + "grant_types": [ + "authorization_code", + "refresh_token" + ], + "response_types": [ + "code" + ], + "token_endpoint_auth_method": "private_key_jwt", + "jwks_uri": "https://secureauthcorp.github.io/oauth2c/data/rsa/public.json", + "scope": "openid email profile offline_access" +} diff --git a/data/cimd/public.json b/data/cimd/public.json new file mode 100644 index 0000000..1cee394 --- /dev/null +++ b/data/cimd/public.json @@ -0,0 +1,17 @@ +{ + "client_id": "https://secureauthcorp.github.io/oauth2c/data/cimd/public.json", + "client_name": "oauth2c (public client)", + "client_uri": "https://github.com/SecureAuthCorp/oauth2c", + "redirect_uris": [ + "http://localhost:9876/callback" + ], + "grant_types": [ + "authorization_code", + "refresh_token" + ], + "response_types": [ + "code" + ], + "token_endpoint_auth_method": "none", + "scope": "openid email profile offline_access" +}