JanssenProject / JanssenProject/jans

feat: TUI support for OpenID Dynamic Client registration via software statement (SSA) issued by Auth Server

Open
#2,981 2 comments 0 reactions 1 assignee View on GitHub

Nobody has claimed this yet.

enhancement kind-feature
Dominant language
Java
Stars
648
Forks
174
Avg merge
1d 18h
Merged PRs (30d)
110

Description

It should be possible to run the client on any workstation that has access to the config api.

An SSA is a JWT which is presentyed during dynamic client registration. It is signed by the AS (i.e. Auth Server).

If the Auth Server admin generates a software statement, the admin could provide this to the person who wants to use the TUI, and then each instance of the TUI would generate distinct client credentials

This would enable the TUI to generate a cryptographic key pair, and use dynamic client registration to obtain a client_id–i.e. use asymetric client secret instead of a shared secret (like client secret)

The software statement would pre-authorize scopes–for example the scopes needed to call the config API endpoints.

If a person starts the TUI, and it detects that there are no client credential present, it should prompt for a software statement and the OpenID Connect configuration endpoint (e.g. https://example.com/.well-known/openid-configuration). With these two pieces of data, the TUI could dynamically register, and then prompt the user to start a device flow authentication.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.