adorsys / adorsys/open-banking-gateway

Use real certificates for Xs2a Sandbox

オープン
#416 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
BE DevOps low priority
主要言語
Java
スター
338
フォーク
122
PR マージ指標
30日以内にマージされた PR はありません

説明

As xs2a-adapter supports (should support from version 0.0.8) real request signing for Sandbox API, we need to make:
0. mock-qwac-certificate of Sandbox is complete security bypass, we should drop it.
1. Sandbox should not use mock-qwac-certificate and profile. It should work with our 'OPBA mocked generated certificate' (requests done from us must be signed and Sandbox should validate the signature)
2. We need to supply 'OPBA mocked generated certificate' to xs2a-adapter so all requests from us to Sandbox must be signed.

So we generate some certificate, make Sandbox aware of it (to trust it) and sign all requests with it. Unsigned requests must fail.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。