Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -707,6 +707,39 @@ oauth2c https://oauth2c.us.authz.cloudentity.io/oauth2c/demo \
--rar '[{"type":"payment_initiation","locations":["https://example.com/payments"],"instructedAmount":{"currency":"EUR","amount":"123.50"},"creditorName":"Merchant A","creditorAccount":{"bic":"ABCIDEFFXXX","iban":"DE02100100109307118603"},"remittanceInformationUnstructured":"Ref Number Merchant"}]'
```

#### Client ID Metadata Document (CIMD)

With [CIMD](https://datatracker.ietf.org/doc/draft-ietf-oauth-client-id-metadata-document/)
the `client_id` is an https URL of a JSON document describing the client, so it
needs no registration at the authorization server. This repository publishes
example documents on GitHub Pages; they use the same test keys as the examples
above and the default callback `http://localhost:9876/callback`. They are for
testing only: the private key is public, so anyone can act as these clients.

| Document | Client authentication |
|---|---|
| [`data/cimd/public.json`](https://secureauthcorp.github.io/oauth2c/data/cimd/public.json) | `none` (public client, PKCE) |
| [`data/cimd/private-key-jwt.json`](https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt.json) | `private_key_jwt`, keys from `jwks_uri` |
| [`data/cimd/private-key-jwt-inline-jwks.json`](https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt-inline-jwks.json) | `private_key_jwt`, keys inline in `jwks` |

The authorization server must support CIMD (`client_id_metadata_document_supported`
in its metadata).

```sh
oauth2c https://<authorization-server-issuer> \
--client-id https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt.json \
--signing-key https://raw.githubusercontent.com/SecureAuthCorp/oauth2c/master/data/rsa/key.json \
--response-types code \
--response-mode query \
--grant-type authorization_code \
--auth-method private_key_jwt \
--scopes openid,email \
--pkce
```

For the public client use `--client-id https://secureauthcorp.github.io/oauth2c/data/cimd/public.json`,
`--auth-method none` and no `--signing-key`.

### Miscellaneous

#### Using HTTPs for Callback URL
Expand Down
29 changes: 29 additions & 0 deletions data/cimd/private-key-jwt-inline-jwks.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
{
"client_id": "https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt-inline-jwks.json",
"client_name": "oauth2c (private_key_jwt, inline jwks)",
"client_uri": "https://github.com/SecureAuthCorp/oauth2c",
"redirect_uris": [
"http://localhost:9876/callback"
],
"grant_types": [
"authorization_code",
"refresh_token"
],
"response_types": [
"code"
],
"token_endpoint_auth_method": "private_key_jwt",
"jwks": {
"keys": [
{
"kty": "RSA",
"e": "AQAB",
"use": "sig",
"kid": "Ana-TpIxraP9mCAwyAbxk40LqpE5Utfjjd4EQrc6sBM",
"alg": "RS256",
"n": "rhipCrDSyEJpr8JJnBORLXb4jYbzCDNJAYCUCuYts-z7iLTnfNv2AkmphbY9EpGk1j96IQZq7g4fwFLh5HS9SFEPpTRh2-5Pp1QRnd-nhSaeT7hkVXGTGjlmRDHgv1-69_MZFSuBFA9I3yzdT7LlkWwPZS7WL5MYHNtbLJSIF1ls-MLleGci5qWCcLXPqMpeG_VEA53IhfIcVIMDU3g3gWqqEM7CTWdkdJ12fUyMpEPzF1VOYGadO181zdo6sIkdyWqAoCesUv_9Xpi9weJT_yduiInb0xzpsriP_U-dXwHf0ULI7vKIqa--WMbGUHD974tSxTOknYvRSyGRHWClmw"
}
]
},
"scope": "openid email profile offline_access"
}
18 changes: 18 additions & 0 deletions data/cimd/private-key-jwt.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
{
"client_id": "https://secureauthcorp.github.io/oauth2c/data/cimd/private-key-jwt.json",
"client_name": "oauth2c (private_key_jwt, jwks_uri)",
"client_uri": "https://github.com/SecureAuthCorp/oauth2c",
"redirect_uris": [
"http://localhost:9876/callback"
],
"grant_types": [
"authorization_code",
"refresh_token"
],
"response_types": [
"code"
],
"token_endpoint_auth_method": "private_key_jwt",
"jwks_uri": "https://secureauthcorp.github.io/oauth2c/data/rsa/public.json",
"scope": "openid email profile offline_access"
}
17 changes: 17 additions & 0 deletions data/cimd/public.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
{
"client_id": "https://secureauthcorp.github.io/oauth2c/data/cimd/public.json",
"client_name": "oauth2c (public client)",
"client_uri": "https://github.com/SecureAuthCorp/oauth2c",
"redirect_uris": [
"http://localhost:9876/callback"
],
"grant_types": [
"authorization_code",
"refresh_token"
],
"response_types": [
"code"
],
"token_endpoint_auth_method": "none",
"scope": "openid email profile offline_access"
}
Loading