|
17 | 17 | KEYDEFS = [ |
18 | 18 | {"type": "RSA", "key": '', "use": ["sig"]}, |
19 | 19 | {"type": "EC", "crv": "P-256", "use": ["sig"]} |
20 | | -] |
| 20 | + ] |
21 | 21 |
|
22 | 22 | PRIVATE_JWKS_PATH = "jwks_dir/jwks.json" |
23 | 23 | PUBLIC_JWKS_PATH = 'static/jwks.json' |
|
35 | 35 | "scope": ["openid", "profile", "email", "address", "phone"], |
36 | 36 | "token_endpoint_auth_method": ["client_secret_basic", 'client_secret_post'], |
37 | 37 | 'services': SERVICES |
38 | | -} |
| 38 | + } |
39 | 39 |
|
40 | 40 | # The keys in this dictionary are the OPs short user friendly name |
41 | 41 | # not the issuer (iss) name. |
|
55 | 55 | 'AccessToken': {}, |
56 | 56 | 'RefreshAccessToken': {}, |
57 | 57 | 'UserInfo': {} |
58 | | - } |
59 | | - }, |
| 58 | + } |
| 59 | + }, |
60 | 60 | # Supports OP information lookup but not client registration |
61 | 61 | "google": { |
62 | 62 | "issuer": "https://accounts.google.com/", |
|
68 | 68 | "scope": ["openid", "profile", "email"], |
69 | 69 | "token_endpoint_auth_method": ["client_secret_basic", |
70 | 70 | 'client_secret_post'] |
71 | | - }, |
| 71 | + }, |
72 | 72 | "allow": { |
73 | 73 | "issuer_mismatch": True |
74 | | - }, |
| 74 | + }, |
75 | 75 | # "userinfo_request_method": "GET", |
76 | 76 | "services": { |
77 | 77 | 'ProviderInfoDiscovery': {}, |
78 | 78 | 'Authorization': {}, |
79 | 79 | 'AccessToken': {}, |
80 | 80 | 'RefreshAccessToken': {}, |
81 | 81 | 'UserInfo': {} |
82 | | - } |
83 | | - }, |
| 82 | + } |
| 83 | + }, |
84 | 84 | "linkedin": { |
85 | 85 | "issuer": "https://www.linkedin.com/oauth/v2/", |
86 | 86 | "client_id": "xxxxxxx", |
|
90 | 90 | "response_types": ["code"], |
91 | 91 | "scope": ["r_basicprofile", "r_emailaddress"], |
92 | 92 | "token_endpoint_auth_method": ['client_secret_post'] |
93 | | - }, |
| 93 | + }, |
94 | 94 | "provider_info": { |
95 | 95 | "authorization_endpoint": |
96 | 96 | "https://www.linkedin.com/oauth/v2/authorization", |
97 | 97 | "token_endpoint": "https://www.linkedin.com/oauth/v2/accessToken", |
98 | 98 | "userinfo_endpoint": |
99 | 99 | "https://api.linkedin.com/v1/people/~?format=json" |
100 | | - }, |
| 100 | + }, |
101 | 101 | 'services': { |
102 | 102 | 'Authorization': {}, |
103 | 103 | 'linkedin.AccessToken': {}, |
104 | 104 | 'linkedin.UserInfo': {} |
105 | | - } |
106 | | - }, |
| 105 | + } |
| 106 | + }, |
107 | 107 | "facebook": { |
108 | 108 | "issuer": "https://www.facebook.com/v2.11/dialog/oauth", |
109 | 109 | "behaviour": { |
110 | 110 | "response_types": ["code"], |
111 | 111 | "scope": ["email", "public_profile"], |
112 | 112 | "token_endpoint_auth_method": [''] |
113 | | - }, |
| 113 | + }, |
114 | 114 | "redirect_uris": ["{}/authz_cb/facebook".format(BASEURL)], |
115 | 115 | "provider_info": { |
116 | 116 | "authorization_endpoint": |
|
119 | 119 | "https://graph.facebook.com/v2.11/oauth/access_token", |
120 | 120 | "userinfo_endpoint": |
121 | 121 | "https://graph.facebook.com/me" |
122 | | - }, |
| 122 | + }, |
123 | 123 | 'services': { |
124 | 124 | 'Authorization': {}, |
125 | 125 | 'AccessToken': {'default_authn_method': ''}, |
126 | | - 'UserInfo': {'default_authn_method':''} |
127 | | - } |
128 | | - }, |
| 126 | + 'UserInfo': {'default_authn_method': ''} |
| 127 | + } |
| 128 | + }, |
129 | 129 | 'github': { |
130 | 130 | "issuer": "https://github.com/login/oauth/authorize", |
131 | 131 | 'client_id': 'eeeeeeeee', |
|
135 | 135 | "response_types": ["code"], |
136 | 136 | "scope": ["user", "public_repo"], |
137 | 137 | "token_endpoint_auth_method": [''] |
138 | | - }, |
| 138 | + }, |
139 | 139 | "provider_info": { |
140 | 140 | "authorization_endpoint": |
141 | 141 | "https://github.com/login/oauth/authorize", |
142 | 142 | "token_endpoint": |
143 | 143 | "https://github.com/login/oauth/access_token", |
144 | 144 | "userinfo_endpoint": |
145 | 145 | "https://api.github.com/user" |
146 | | - }, |
| 146 | + }, |
147 | 147 | 'services': { |
148 | 148 | 'Authorization': {}, |
149 | 149 | 'AccessToken': {}, |
150 | 150 | 'UserInfo': {'default_authn_method': ''} |
151 | | - } |
152 | | - }, |
| 151 | + } |
| 152 | + }, |
153 | 153 | "salesforce": { |
154 | 154 | "issuer": "https://login.salesforce.com", |
155 | 155 | "client_id": "xxxxxxxxx.yyy", |
|
160 | 160 | "scope": ["openid", "profile", "email"], |
161 | 161 | "token_endpoint_auth_method": ["client_secret_basic", |
162 | 162 | 'client_secret_post'] |
163 | | - }, |
| 163 | + }, |
164 | 164 | # "allow": { |
165 | 165 | # "issuer_mismatch": True |
166 | 166 | # }, |
|
171 | 171 | 'AccessToken': {}, |
172 | 172 | 'RefreshAccessToken': {}, |
173 | 173 | 'UserInfo': {} |
174 | | - }, |
| 174 | + }, |
175 | 175 | "keys": {'file': {"https://login.salesforce.com": 'salesforce.jwks'}} |
176 | | - }, |
| 176 | + }, |
177 | 177 | "okta": { |
178 | 178 | "issuer": "https://dev-968755.oktapreview.com/", |
179 | 179 | "client_id": "123456789", |
|
184 | 184 | "scope": ["openid", "profile", "email"], |
185 | 185 | "token_endpoint_auth_method": ["client_secret_basic", |
186 | 186 | 'client_secret_post'] |
187 | | - }, |
| 187 | + }, |
188 | 188 | "provider_info": { |
189 | 189 | "authorization_endpoint": |
190 | 190 | "https://dev-968755.oktapreview.com/oauth2/default/v1" |
|
193 | 193 | "https://dev-968755.oktapreview.com/oauth2/default/v1/token", |
194 | 194 | "userinfo_endpoint": |
195 | 195 | "https://dev-968755.oktapreview.com/oauth2/v1/userinfo" |
196 | | - }, |
| 196 | + }, |
197 | 197 | # "userinfo_request_method": "GET", |
198 | 198 | "services": { |
199 | 199 | 'Authorization': {}, |
200 | 200 | 'AccessToken': {}, |
201 | 201 | 'UserInfo': {} |
| 202 | + } |
| 203 | + }, |
| 204 | + 'microsoft': { |
| 205 | + 'issuer': 'https://login.microsoftonline.com/<UUID>>/v2.0', |
| 206 | + 'client_id': '1234567890', |
| 207 | + 'client_secret': 'abcdefghijklmnop', |
| 208 | + "redirect_uris": ["{}/authz_cb/microsoft".format(BASEURL)], |
| 209 | + "client_preferences": { |
| 210 | + "response_types": ["id_token"], |
| 211 | + "scope": ["openid"], |
| 212 | + "token_endpoint_auth_method": ["private_key_jwt", |
| 213 | + 'client_secret_post'], |
| 214 | + "response_mode": 'form_post' |
| 215 | + }, |
| 216 | + "allow": { |
| 217 | + "issuer_mismatch": True |
| 218 | + }, |
| 219 | + "services": { |
| 220 | + 'ProviderInfoDiscovery', |
| 221 | + 'Authorization' |
| 222 | + } |
| 223 | + }, |
| 224 | + "aws": { |
| 225 | + "issuer": "https://cognito-idp.eu-central-1.amazonaws.com/eu-central-1", |
| 226 | + 'client_id': '1234567890', |
| 227 | + 'client_secret': 'abcdefghijklmnop', |
| 228 | + "redirect_uris": ["{}/authz_cb/aws".format(BASEURL)], |
| 229 | + "behaviour": { |
| 230 | + "response_types": ["code"], |
| 231 | + "scope": ["email", "openid"], |
| 232 | + "token_endpoint_auth_method": [''] |
| 233 | + }, |
| 234 | + "provider_info": { |
| 235 | + "authorization_endpoint": |
| 236 | + "https://catalogix.auth.eu-central-1.amazoncognito.com/oauth2" |
| 237 | + "/authorize", |
| 238 | + "token_endpoint": |
| 239 | + "https://catalogix.auth.eu-central-1.amazoncognito.com/oauth2" |
| 240 | + "/token" |
| 241 | + }, |
| 242 | + 'services': { |
| 243 | + 'Authorization': {}, |
| 244 | + 'AccessToken': {} |
| 245 | + }, |
| 246 | + 'keys': { |
| 247 | + 'url': { |
| 248 | + 'https://cognito-idp.eu-central-1.amazonaws.com/eu-central-1': |
| 249 | + 'https://cognito-idp.eu-central-1.amazonaws.com/eu-central-1/.well-known/jwks.json' |
| 250 | + } |
| 251 | + } |
202 | 252 | } |
203 | 253 | } |
204 | | -} |
205 | 254 |
|
206 | 255 | # Whether an attempt to fetch the userinfo should be made |
207 | 256 | USERINFO = True |
0 commit comments