Merge branch 'maxbes/lemonldap-ng-fix-1882-remove-oidcServiceMetaDataIssuer' into 'master'

Maxbes/lemonldap ng fix 1882 remove oidc service meta data issuer

See merge request lemonldap-ng/lemonldap-ng!95
This commit is contained in:
Clément OUDOT 2019-09-19 16:02:59 +02:00
commit 373f2f1a39
34 changed files with 4 additions and 47 deletions

View File

@ -68,6 +68,6 @@ our $issuerParameters = {
issuerOptions => [qw(issuersTimeout)],
};
our $samlServiceParameters = [qw(samlEntityID samlServicePrivateKeySig samlServicePrivateKeySigPwd samlServicePublicKeySig samlServicePrivateKeyEnc samlServicePrivateKeyEncPwd samlServicePublicKeyEnc samlServiceUseCertificateInResponse samlServiceSignatureMethod samlNameIDFormatMapEmail samlNameIDFormatMapX509 samlNameIDFormatMapWindows samlNameIDFormatMapKerberos samlAuthnContextMapPassword samlAuthnContextMapPasswordProtectedTransport samlAuthnContextMapTLSClient samlAuthnContextMapKerberos samlOrganizationDisplayName samlOrganizationName samlOrganizationURL samlSPSSODescriptorAuthnRequestsSigned samlSPSSODescriptorWantAssertionsSigned samlSPSSODescriptorSingleLogoutServiceHTTPRedirect samlSPSSODescriptorSingleLogoutServiceHTTPPost samlSPSSODescriptorSingleLogoutServiceSOAP samlSPSSODescriptorAssertionConsumerServiceHTTPArtifact samlSPSSODescriptorAssertionConsumerServiceHTTPPost samlSPSSODescriptorArtifactResolutionServiceArtifact samlIDPSSODescriptorWantAuthnRequestsSigned samlIDPSSODescriptorSingleSignOnServiceHTTPRedirect samlIDPSSODescriptorSingleSignOnServiceHTTPPost samlIDPSSODescriptorSingleSignOnServiceHTTPArtifact samlIDPSSODescriptorSingleLogoutServiceHTTPRedirect samlIDPSSODescriptorSingleLogoutServiceHTTPPost samlIDPSSODescriptorSingleLogoutServiceSOAP samlIDPSSODescriptorArtifactResolutionServiceArtifact samlAttributeAuthorityDescriptorAttributeServiceSOAP samlIdPResolveCookie samlMetadataForceUTF8 samlStorage samlStorageOptions samlRelayStateTimeout samlUseQueryStringSpecific samlCommonDomainCookieActivation samlCommonDomainCookieDomain samlCommonDomainCookieReader samlCommonDomainCookieWriter samlDiscoveryProtocolActivation samlDiscoveryProtocolURL samlDiscoveryProtocolPolicy samlDiscoveryProtocolIsPassive samlOverrideIDPEntityID)];
our $oidcServiceParameters = [qw(oidcServiceMetaDataIssuer oidcServiceMetaDataAuthorizeURI oidcServiceMetaDataTokenURI oidcServiceMetaDataUserInfoURI oidcServiceMetaDataJWKSURI oidcServiceMetaDataRegistrationURI oidcServiceMetaDataIntrospectionURI oidcServiceMetaDataEndSessionURI oidcServiceMetaDataCheckSessionURI oidcServiceMetaDataFrontChannelURI oidcServiceMetaDataBackChannelURI oidcServiceMetaDataAuthnContext oidcServicePrivateKeySig oidcServicePublicKeySig oidcServiceKeyIdSig oidcServiceAllowDynamicRegistration oidcServiceAllowAuthorizationCodeFlow oidcServiceAllowImplicitFlow oidcServiceAllowHybridFlow oidcStorage oidcStorageOptions)];
our $oidcServiceParameters = [qw(oidcServiceMetaDataAuthorizeURI oidcServiceMetaDataTokenURI oidcServiceMetaDataUserInfoURI oidcServiceMetaDataJWKSURI oidcServiceMetaDataRegistrationURI oidcServiceMetaDataIntrospectionURI oidcServiceMetaDataEndSessionURI oidcServiceMetaDataCheckSessionURI oidcServiceMetaDataFrontChannelURI oidcServiceMetaDataBackChannelURI oidcServiceMetaDataAuthnContext oidcServicePrivateKeySig oidcServicePublicKeySig oidcServiceKeyIdSig oidcServiceAllowDynamicRegistration oidcServiceAllowAuthorizationCodeFlow oidcServiceAllowImplicitFlow oidcServiceAllowHybridFlow oidcStorage oidcStorageOptions)];
1;

View File

@ -2167,9 +2167,6 @@ qr/^(?:\*\.)?(?:(?:(?:(?:[a-zA-Z0-9][-a-zA-Z0-9]*)?[a-zA-Z0-9])[.])*(?:[a-zA-Z][
'default' => 'introspect',
'type' => 'text'
},
'oidcServiceMetaDataIssuer' => {
'type' => 'text'
},
'oidcServiceMetaDataJWKSURI' => {
'default' => 'jwks',
'type' => 'text'

View File

@ -3573,10 +3573,6 @@ m{^(?:ldapi://[^/]*/?|\w[\w\-\.]*(?::\d{1,5})?|ldap(?:s|\+tls)?://\w[\w\-\.]*(?:
},
# OpenID Connect service
oidcServiceMetaDataIssuer => {
type => 'text',
documentation => 'OpenID Connect issuer',
},
oidcServiceMetaDataAuthorizeURI => {
type => 'text',
default => 'authorize',

View File

@ -1165,7 +1165,6 @@ sub tree {
title => 'oidcServiceMetaData',
help => 'openidconnectservice.html#service_configuration',
nodes => [
'oidcServiceMetaDataIssuer',
{
title => 'oidcServiceMetaDataEndPoints',
form => 'simpleInputContainer',

View File

@ -609,7 +609,6 @@
"oidcRPMetaDataOptionsRedirectUris":"عناوين إعادة التوجيه المسموح بها لتسجيل الدخول",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"عناوين إعادة التوجيه المسموح بها للخروج",
"oidcRPMetaDataOptionsExtraClaims":"ادعاءات إضافي",
"oidcServiceMetaDataIssuer":"تعريف المرسل",
"oidcServiceMetaDataTokenURI":"التوكن",
"oidcServiceMetaDataUserInfoURI":"معلومات المستخدم",
"oidcServiceMetaDataCheckSessionURI":"تحقق من الجلسة",

View File

@ -608,7 +608,6 @@
"oidcRPMetaDataOptionsRedirectUris":"Allowed redirection addresses for login",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"Allowed redirection addresses for logout",
"oidcRPMetaDataOptionsExtraClaims":"Extra claims",
"oidcServiceMetaDataIssuer":"Issuer identifier",
"oidcServiceMetaDataTokenURI":"Token",
"oidcServiceMetaDataUserInfoURI":"User Info",
"oidcServiceMetaDataCheckSessionURI":"Check Session",

View File

@ -608,7 +608,6 @@
"oidcRPMetaDataOptionsRedirectUris":"Allowed redirection addresses for login",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"Allowed redirection addresses for logout",
"oidcRPMetaDataOptionsExtraClaims":"Extra claims",
"oidcServiceMetaDataIssuer":"Issuer identifier",
"oidcServiceMetaDataTokenURI":"Token",
"oidcServiceMetaDataUserInfoURI":"User Info",
"oidcServiceMetaDataCheckSessionURI":"Check Session",

View File

@ -608,7 +608,6 @@
"oidcRPMetaDataOptionsRedirectUris":"Adresses de redirection autorisées pour la connexion",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"Adresses de redirection autorisées pour la déconnexion",
"oidcRPMetaDataOptionsExtraClaims":"Déclarations (scopes/claims)",
"oidcServiceMetaDataIssuer":"Identifiant du fournisseur",
"oidcServiceMetaDataTokenURI":"Jeton",
"oidcServiceMetaDataUserInfoURI":"Informations Utilisateur",
"oidcServiceMetaDataCheckSessionURI":"Vérification de session",

View File

@ -608,7 +608,6 @@
"oidcRPMetaDataOptionsRedirectUris":"Indirizzi di reindirizzazione consentiti per l'accesso",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"Indirizzi di reindirizzazione consentiti per il logout",
"oidcRPMetaDataOptionsExtraClaims":"Richieste supplementari",
"oidcServiceMetaDataIssuer":"Identificatore dell'emittente",
"oidcServiceMetaDataTokenURI":"Token",
"oidcServiceMetaDataUserInfoURI":"Informazioni utente",
"oidcServiceMetaDataCheckSessionURI":"Controlla sessione",

View File

@ -608,7 +608,6 @@
"oidcRPMetaDataOptionsRedirectUris":"Allowed redirection addresses for login",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"Allowed redirection addresses for logout",
"oidcRPMetaDataOptionsExtraClaims":"Xác nhận bổ sung",
"oidcServiceMetaDataIssuer":"Định danh Người phát hành",
"oidcServiceMetaDataTokenURI":"Token",
"oidcServiceMetaDataUserInfoURI":"Thông tin người dùng",
"oidcServiceMetaDataCheckSessionURI":"Kiểm tra phiên",

View File

@ -608,7 +608,6 @@
"oidcRPMetaDataOptionsRedirectUris":"Allowed redirection addresses for login",
"oidcRPMetaDataOptionsPostLogoutRedirectUris":"Allowed redirection addresses for logout",
"oidcRPMetaDataOptionsExtraClaims":"Extra claims",
"oidcServiceMetaDataIssuer":"Issuer identifier",
"oidcServiceMetaDataTokenURI":"令牌",
"oidcServiceMetaDataUserInfoURI":"用户信息",
"oidcServiceMetaDataCheckSessionURI":"Check Session",

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

View File

@ -2743,11 +2743,6 @@
},
{
"_nodes": [{
"default": "http://auth.example.com",
"id": "oidcServiceMetaDataIssuer",
"title": "oidcServiceMetaDataIssuer"
},
{
"_nodes": [{
"default": "authorize",
"id": "oidcServiceMetaDataAuthorizeURI",

View File

@ -3948,11 +3948,6 @@
},
{
"_nodes" : [
{
"default" : "http://auth.example.com",
"id" : "oidcServiceMetaDataIssuer",
"title" : "oidcServiceMetaDataIssuer"
},
{
"_nodes" : [
{

View File

@ -43,7 +43,7 @@ has iss => (
is => 'ro',
lazy => 1,
default => sub {
$_[0]->conf->{oidcServiceMetaDataIssuer} || $_[0]->conf->{portal};
$_[0]->conf->{portal};
}
);

View File

@ -229,7 +229,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -327,7 +327,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com/",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -280,7 +280,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com/",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -327,7 +327,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com/",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -327,7 +327,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com/",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -237,7 +237,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -228,7 +228,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -228,7 +228,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -133,7 +133,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -145,7 +145,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -35,7 +35,6 @@ my $op = LLNG::Manager::Test->new( {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -35,7 +35,6 @@ my $op = LLNG::Manager::Test->new( {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -355,7 +355,6 @@ sub op {
name => "cn"
}
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -445,7 +445,6 @@ sub sp {
email => 'email',
},
},
oidcServiceMetaDataIssuer => "http://auth.sp.com",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",
oidcServiceMetaDataEndSessionURI => "logout",

View File

@ -425,7 +425,6 @@ sub sp {
email => 'email',
},
},
oidcServiceMetaDataIssuer => "http://auth.sp.com",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",
oidcServiceMetaDataEndSessionURI => "logout",

View File

@ -427,7 +427,6 @@ sub sp {
email => 'email',
},
},
oidcServiceMetaDataIssuer => "http://auth.sp.com",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",
oidcServiceMetaDataEndSessionURI => "logout",

View File

@ -292,7 +292,6 @@ sub op {
email => 'email',
},
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",

View File

@ -290,7 +290,6 @@ sub op {
email => 'email',
},
},
oidcServiceMetaDataIssuer => "http://auth.op.com",
oidcServiceMetaDataAuthorizeURI => "authorize",
oidcServiceMetaDataCheckSessionURI => "checksession.html",
oidcServiceMetaDataJWKSURI => "jwks",