spring-projects / spring-projects/spring-security

SEC-2219: OpenId Attribute Exchange does not work with Intuit Provider

Open
#2,443 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: openid type: bug type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

grady cooper (Migrated from SEC-2219) said:

org.springframework.security.openidOpenID4JavaConsumer::fetchAxAttributes() uses the attribute name to retrieve the attribute values( List values = fetchResp.getAttributeValues(attr.getName());). However, the intuit OP (which maybe a .NET provider) uses an alias scheme (not the attribute name) to provide values. Partial responses from intuit OP (notice "email" attributes value is names value.alias3 (not "email") :

&openid.ns.alias3=http://openid.net/srv/ax/1.0&openid.alias3.mode=fetch_response&openid.alias3.type.alias1=http://axschema.org/namePerson/first&openid.alias3.value.alias1=First&openid.alias3.type.alias2=http://axschema.org/namePerson/last&openid.alias3.value.alias2=Last&openid.alias3.type.alias3=http://axschema.org/contact/email&openid.alias3.value.alias3=noreply@psiflow.com

I believe the correct fix is to lookup attributes by type ( org.openid4java.message.ax.AxPayload::getAttributeValuesByTypeUri(String typeUri)) - however, I'm a newbie to openid and admittedly don't know all the compatibility issues.

security configuration for intuit OP:

                            <b:entry key=".*intuit.com.*">
                                <b:list>
                                    <b:bean class="org.springframework.security.openid.OpenIDAttribute">
                                        <b:constructor-arg name="name" value="email"/>
                                        <b:constructor-arg name="type" value="http://axschema.org/contact/email"/>
                                        <b:property name="required" value="true"/>
                                    </b:bean>
                                    <b:bean class="org.springframework.security.openid.OpenIDAttribute">
                                        <b:constructor-arg name="name" value="firstname"/>
                                        <b:constructor-arg name="type" value="http://axschema.org/namePerson/first"/>
                                        <b:property name="required" value="true"/>
                                    </b:bean>
                                    <b:bean class="org.springframework.security.openid.OpenIDAttribute">
                                        <b:constructor-arg name="name" value="lastname" />
                                        <b:constructor-arg name="type" value="http://axschema.org/namePerson/last"/>
                                        <b:property name="required" value="true"/>
                                    </b:bean>
                                    <b:bean class="org.springframework.security.openid.OpenIDAttribute">
                                        <b:constructor-arg name="name" value="realmId" />
                                        <b:constructor-arg name="type" value="http://axschema.org/intuit/realmId"/>
                                        <b:property name="required" value="true"/>
                                    </b:bean>
                                </b:list>
                            </b:entry>                              

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at org.springframework.security.openid.OpenID4JavaConsumer::fetchAxAttributes() and compare its use of fetchResp.getAttributeValues(attr.getName()) with the Intuit response and the proposed AxPayload type-URI lookup. Done means configured attributes such as email, firstname, lastname, and realmId are retrieved when the provider uses aliases rather than configured names.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authentication, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.