adorsys / adorsys/open-banking-gateway

Use real certificates for Xs2a Sandbox

Đang mở
#416 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
BE DevOps low priority
Ngôn ngữ chính
Java
Star
338
Fork
122
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

As xs2a-adapter supports (should support from version 0.0.8) real request signing for Sandbox API, we need to make:
0. mock-qwac-certificate of Sandbox is complete security bypass, we should drop it.
1. Sandbox should not use mock-qwac-certificate and profile. It should work with our 'OPBA mocked generated certificate' (requests done from us must be signed and Sandbox should validate the signature)
2. We need to supply 'OPBA mocked generated certificate' to xs2a-adapter so all requests from us to Sandbox must be signed.

So we generate some certificate, make Sandbox aware of it (to trust it) and sign all requests with it. Unsigned requests must fail.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.