Iddawc
Handle the flow of OAuth2 and OpenID Connect authentication process from the client side.
iddawc.h
Go to the documentation of this file.
1 
24 #ifndef __IDDAWC_H
25 #define __IDDAWC_H
26 
27 #ifdef __cplusplus
28 extern "C"
29 {
30 #endif
31 
32 #include <jansson.h>
33 #include <orcania.h>
34 #include <ulfius.h>
35 #include <rhonabwy.h>
36 #include "iddawc-cfg.h"
37 
44 #define I_OK 0
45 #define I_ERROR 1
46 #define I_ERROR_PARAM 2
47 #define I_ERROR_MEMORY 3
48 #define I_ERROR_UNAUTHORIZED 4
49 #define I_ERROR_SERVER 5
50 
51 #define I_RESPONSE_TYPE_NONE 0x00000000
52 #define I_RESPONSE_TYPE_CODE 0x00000001
53 #define I_RESPONSE_TYPE_TOKEN 0x00000010
54 #define I_RESPONSE_TYPE_ID_TOKEN 0x00000100
55 #define I_RESPONSE_TYPE_PASSWORD 0x00001000
56 #define I_RESPONSE_TYPE_CLIENT_CREDENTIALS 0x00010000
57 #define I_RESPONSE_TYPE_REFRESH_TOKEN 0x00100000
58 #define I_RESPONSE_TYPE_DEVICE_CODE 0x01000000
59 
60 #define I_AUTH_METHOD_GET 0x00000001
61 #define I_AUTH_METHOD_POST 0x00000010
62 #define I_AUTH_METHOD_JWT_SIGN_SECRET 0x00000100
63 #define I_AUTH_METHOD_JWT_SIGN_PRIVKEY 0x00001000
64 #define I_AUTH_METHOD_JWT_ENCRYPT_SECRET 0x00010000
65 #define I_AUTH_METHOD_JWT_ENCRYPT_PUBKEY 0x00100000
66 
67 #define I_TOKEN_AUTH_METHOD_NONE 0x00000000
68 #define I_TOKEN_AUTH_METHOD_SECRET_BASIC 0x00000001
69 #define I_TOKEN_AUTH_METHOD_SECRET_POST 0x00000010
70 #define I_TOKEN_AUTH_METHOD_TLS_CERTIFICATE 0x00000100
71 #define I_TOKEN_AUTH_METHOD_JWT_SIGN_SECRET 0x00001000
72 #define I_TOKEN_AUTH_METHOD_JWT_SIGN_PRIVKEY 0x00010000
73 #define I_TOKEN_AUTH_METHOD_JWT_ENCRYPT_SECRET 0x00100000
74 #define I_TOKEN_AUTH_METHOD_JWT_ENCRYPT_PUBKEY 0x01000000
75 
76 #define I_STRICT_NO 0
77 #define I_STRICT_YES 1
78 
79 #define I_AUTH_SIGN_ALG_MAX_LENGTH 8
80 
81 #define I_BEARER_TYPE_HEADER 0
82 #define I_BEARER_TYPE_BODY 1
83 #define I_BEARER_TYPE_URL 2
84 
85 #define I_INTROSPECT_REVOKE_AUTH_NONE 0
86 #define I_INTROSPECT_REVOKE_AUTH_ACCESS_TOKEN 1
87 #define I_INTROSPECT_REVOKE_AUTH_CLIENT_TARGET 2
88 
89 #define I_TOKEN_TYPE_ACCESS_TOKEN 0
90 #define I_TOKEN_TYPE_ID_TOKEN 1
91 #define I_TOKEN_TYPE_USERINFO 2
92 #define I_TOKEN_TYPE_INTROSPECTION 3
93 
94 #define I_HEADER_PREFIX_BEARER "Bearer "
95 #define I_HEADER_AUTHORIZATION "Authorization"
96 #define I_BODY_URL_PARAMETER "access_token"
97 #define I_HEADER_DPOP "DPoP"
98 
99 #define I_REMOTE_VERIFY_NONE 0x0000
100 #define I_REMOTE_HOST_VERIFY_PEER 0x0001
101 #define I_REMOTE_HOST_VERIFY_HOSTNAME 0x0010
102 #define I_REMOTE_PROXY_VERIFY_PEER 0x0100
103 #define I_REMOTE_PROXY_VERIFY_HOSTNAME 0x1000
104 
105 #define I_PKCE_NONE 0
106 #define I_PKCE_METHOD_PLAIN 1
107 #define I_PKCE_METHOD_S256 2
108 
109 #define I_CLAIM_TARGET_ALL 0
110 #define I_CLAIM_TARGET_USERINFO 1
111 #define I_CLAIM_TARGET_ID_TOKEN 2
112 
113 #define I_CLAIM_ESSENTIAL_NULL 0
114 #define I_CLAIM_ESSENTIAL_TRUE 1
115 #define I_CLAIM_ESSENTIAL_FALSE 2
116 #define I_CLAIM_ESSENTIAL_IGNORE 3
117 
123 typedef enum {
143  I_OPT_ERROR = 19,
146  I_OPT_CODE = 22,
204 
215 struct _i_session {
217  char * scope;
218  char * state;
219  char * nonce;
220  char * redirect_uri;
221  char * redirect_to;
222  char * client_id;
224  char * username;
226  struct _u_map additional_parameters;
227  struct _u_map additional_response;
239  uint result;
240  char * error;
242  char * error_uri;
243  char * code;
245  char * access_token;
247  char * token_target;
249  char * token_type;
251  time_t expires_at;
252  char * id_token;
256  jwks_t * server_jwks;
257  char * server_kid;
258  jwa_alg server_enc_alg;
259  jwa_enc server_enc;
260  jwks_t * client_jwks;
261  char * client_kid;
263  jwa_alg client_enc_alg;
264  jwa_enc client_enc;
266  json_t * openid_config;
268  char * issuer;
269  char * userinfo;
270  json_t * j_userinfo;
271  char * token_jti;
272  uint token_exp;
283  int use_dpop;
284  char * dpop_kid;
285  jwa_alg dpop_sign_alg;
289  char * key_file;
290  char * cert_file;
294  json_t * j_claims;
296 };
297 
314 int i_global_init();
315 
319 void i_global_close();
320 
326 void i_free(void * data);
327 
333 int i_init_session(struct _i_session * i_session);
334 
339 void i_clean_session(struct _i_session * i_session);
340 
363 int i_set_response_type(struct _i_session * i_session, uint i_value);
364 
373 int i_set_result(struct _i_session * i_session, uint i_value);
374 
389 int i_set_int_parameter(struct _i_session * i_session, i_option option, uint i_value);
390 
416 int i_set_str_parameter(struct _i_session * i_session, i_option option, const char * s_value);
417 
425 int i_set_additional_parameter(struct _i_session * i_session, const char * s_key, const char * s_value);
426 
434 int i_set_additional_response(struct _i_session * i_session, const char * s_key, const char * s_value);
435 
449 int i_add_claim_request(struct _i_session * i_session, int target, const char * claim, int essential, const char * value);
450 
459 int i_remove_claim_request(struct _i_session * i_session, int target, const char * claim);
460 
468 int i_set_rich_authorization_request_json_t(struct _i_session * i_session, const char * type, json_t * j_value);
469 
477 int i_set_rich_authorization_request_str(struct _i_session * i_session, const char * type, const char * value);
478 
485 int i_remove_rich_authorization_request(struct _i_session * i_session, const char * type);
486 
493 json_t * i_get_rich_authorization_request_json_t(struct _i_session * i_session, const char * type);
494 
501 char * i_get_rich_authorization_request_str(struct _i_session * i_session, const char * type);
502 
514 uint i_get_response_type(struct _i_session * i_session);
515 
521 uint i_get_result(struct _i_session * i_session);
522 
536 uint i_get_int_parameter(struct _i_session * i_session, i_option option);
537 
562 const char * i_get_str_parameter(struct _i_session * i_session, i_option option);
563 
570 const char * i_get_additional_parameter(struct _i_session * i_session, const char * s_key);
571 
578 const char * i_get_additional_response(struct _i_session * i_session, const char * s_key);
579 
585 json_t * i_get_server_configuration(struct _i_session * i_session);
586 
592 json_t * i_get_server_jwks(struct _i_session * i_session);
593 
607 int i_set_parameter_list(struct _i_session * i_session, ...);
608 
614 json_t * i_export_session_json_t(struct _i_session * i_session);
615 
623 int i_import_session_json_t(struct _i_session * i_session, json_t * j_import);
624 
630 char * i_export_session_str(struct _i_session * i_session);
631 
639 int i_import_session_str(struct _i_session * i_session, const char * str_import);
640 
656 int i_get_openid_config(struct _i_session * i_session);
657 
664 int i_build_auth_url_get(struct _i_session * i_session);
665 
672 int i_run_auth_request(struct _i_session * i_session);
673 
681 int i_parse_redirect_to(struct _i_session * i_session);
682 
689 int i_run_token_request(struct _i_session * i_session);
690 
696 int i_verify_id_token(struct _i_session * i_session);
697 
705 int i_verify_jwt_access_token(struct _i_session * i_session);
706 
717 int i_get_userinfo(struct _i_session * i_session, int get_jwt);
718 
732 int i_get_userinfo_custom(struct _i_session * i_session, const char * http_method, struct _u_map * additional_query, struct _u_map * additional_headers);
733 
747 int i_get_token_introspection(struct _i_session * i_session, json_t ** j_result, int authentication, int get_jwt);
748 
759 int i_revoke_token(struct _i_session * i_session, int authentication);
760 
772 int i_register_client(struct _i_session * i_session, json_t * j_parameters, int update_session, json_t ** j_result);
773 
785 int i_manage_registration_client(struct _i_session * i_session, json_t * j_parameters, int update_session, json_t ** j_result);
786 
794 int i_get_registration_client(struct _i_session * i_session, json_t ** j_result);
795 
805 char * i_generate_dpop_token(struct _i_session * i_session, const char * htm, const char * htu, time_t iat);
806 
823 int i_perform_resource_service_request(struct _i_session * i_session, struct _u_request * http_request, struct _u_response * http_response, int refresh_if_expired, int bearer_type, int use_dpop, time_t dpop_iat);
824 
831 int i_run_par_request(struct _i_session * i_session);
832 
839 int i_run_device_auth_request(struct _i_session * i_session);
840 
845 #ifdef __cplusplus
846 }
847 #endif
848 
849 #endif // __IDDAWC_H_
i_option
Definition: iddawc.h:123
@ I_OPT_EXPIRES_AT
expires_at value after a succesfull auth or token request, time_t
Definition: iddawc.h:154
@ I_OPT_TOKEN_TYPE
token_type value after a succesfull auth or token request, string
Definition: iddawc.h:152
@ I_OPT_PUSHED_AUTH_REQ_REQUIRED
are pushed authorization requests required, boolean
Definition: iddawc.h:187
@ I_OPT_TOKEN_EXP
JWT token request expiration time in seconds.
Definition: iddawc.h:171
@ I_OPT_DEVICE_AUTH_CODE
device authorization code sent by the AS
Definition: iddawc.h:178
@ I_OPT_DPOP_SIGN_ALG
signature algorithm to use when the client signs a DPoP, values available are 'none',...
Definition: iddawc.h:195
@ I_OPT_ISSUER
issuer value, string
Definition: iddawc.h:157
@ I_OPT_REMOTE_CERT_FLAG
Flags to use with remote connexions to ignore incorrect certificates, flags available are I_REMOTE_HO...
Definition: iddawc.h:198
@ I_OPT_ACCESS_TOKEN
access token given after a succesfull auth or token request using the proper response_type
Definition: iddawc.h:148
@ I_OPT_PUSHED_AUTH_REQ_ENDPOINT
absolute url for the pushed authoization endpoint, string
Definition: iddawc.h:186
@ I_OPT_TOKEN_JTI
jti value, string
Definition: iddawc.h:169
@ I_OPT_TOKEN_TARGET
access_token which is the target of a revocation or an introspection, string
Definition: iddawc.h:172
@ I_OPT_INTROSPECTION_ENDPOINT
absolute url for the introspection endpoint, string
Definition: iddawc.h:175
@ I_OPT_TOKEN_TARGET_TYPE_HINT
access_token which is the target of a revocation or an introspection, string
Definition: iddawc.h:173
@ I_OPT_TOKEN_METHOD
Authentication method to use with the token endpoint, values available are I_TOKEN_AUTH_METHOD_SECRET...
Definition: iddawc.h:151
@ I_OPT_PKCE_CODE_VERIFIER_GENERATE
Generate a random PKCE code verifier.
Definition: iddawc.h:200
@ I_OPT_X5U_FLAGS
x5u flage to apply when JWK used have a x5u property, values available are R_FLAG_IGNORE_SERVER_CERTI...
Definition: iddawc.h:161
@ I_OPT_TOKEN_JTI_GENERATE
Generate a random jti value.
Definition: iddawc.h:170
@ I_OPT_SERVER_KID
key id to use if multiple jwk are available on the server, string
Definition: iddawc.h:162
@ I_OPT_PKCE_METHOD
PKCE method to use, values available are I_PKCE_NONE (no PKCE, default), I_PKCE_METHOD_PLAIN or I_PKC...
Definition: iddawc.h:201
@ I_OPT_CODE
code given after a succesfull auth request using the response_type I_RESPONSE_TYPE_CODE
Definition: iddawc.h:146
@ I_OPT_PKCE_CODE_VERIFIER
PKCE code verifier, must be a string of 43 characters minumum only using the characters [A-Z] / [a-z]...
Definition: iddawc.h:199
@ I_OPT_USE_DPOP
Generate and use a DPoP when accessing endpoints userinfo, introspection and revocation.
Definition: iddawc.h:190
@ I_OPT_OPENID_CONFIG_ENDPOINT
absolute url for the .well-known/openid-configuration endpoint, string
Definition: iddawc.h:138
@ I_OPT_ID_TOKEN
id_token given after a succesfull auth or token request using the proper response_type
Definition: iddawc.h:149
@ I_OPT_DEVICE_AUTHORIZATION_ENDPOINT
absolute url for the pushed authorization endpoint, string
Definition: iddawc.h:177
@ I_OPT_OPENID_CONFIG
result of the .well-known/openid-configuration
Definition: iddawc.h:139
@ I_OPT_NONE
Empty option to complete a i_set_parameter_list.
Definition: iddawc.h:124
@ I_OPT_CHECK_SESSION_IRAME
absolute url for the check session iframe, string
Definition: iddawc.h:185
@ I_OPT_DEVICE_AUTH_EXPIRES_IN
device authorization code expiration sent by the AS
Definition: iddawc.h:182
@ I_OPT_TLS_KEY_FILE
Path to the private key PEM file to use in a TLS authentication.
Definition: iddawc.h:196
@ I_OPT_DEVICE_AUTH_INTERVAL
device authorization code verification interval sent by the AS
Definition: iddawc.h:183
@ I_OPT_REDIRECT_URI
redirect_uri, string
Definition: iddawc.h:130
@ I_OPT_CLIENT_ENC_ALG
key encryption algorithm to use when the client encrypts a request in a JWT, values available are 'RS...
Definition: iddawc.h:167
@ I_OPT_ERROR_URI
error uri of a failed request, string
Definition: iddawc.h:145
@ I_OPT_CLIENT_KID
key id to use if multiple jwk are available on the client, string
Definition: iddawc.h:165
@ I_OPT_REDIRECT_TO
url where the oauth2 is redirected to after a /auth request
Definition: iddawc.h:131
@ I_OPT_ADDITIONAL_RESPONSE
Definition: iddawc.h:135
@ I_OPT_DECRYPT_ACCESS_TOKEN
Decrypt access token when received by the AS as a JWE.
Definition: iddawc.h:194
@ I_OPT_DECRYPT_REFRESH_TOKEN
Decrypt refresh token when received by the AS as a JWE.
Definition: iddawc.h:193
@ I_OPT_NONCE
nonce value, string
Definition: iddawc.h:129
@ I_OPT_DECRYPT_CODE
Decrypt code when received by the AS as a JWE.
Definition: iddawc.h:192
@ I_OPT_RESOURCE_INDICATOR
Resource indicator as detailed in the RFC 8707.
Definition: iddawc.h:202
@ I_OPT_PUSHED_AUTH_REQ_EXPIRES_IN
pushed authorization request expiration time in seconds
Definition: iddawc.h:188
@ I_OPT_USER_PASSWORD
password for password response_types, string
Definition: iddawc.h:156
@ I_OPT_PUSHED_AUTH_REQ_URI
request_uri sent by the par endpoint result, string
Definition: iddawc.h:189
@ I_OPT_REVOCATION_ENDPOINT
absolute url for the revocation endpoint, string
Definition: iddawc.h:174
@ I_OPT_SERVER_ENC_ALG
key id to use if multiple jwk are available on the server, string
Definition: iddawc.h:163
@ I_OPT_TOKEN_ENDPOINT
absolute url for the token endpoint, string
Definition: iddawc.h:137
@ I_OPT_REFRESH_TOKEN
refresh token given after a succesfull token request using the proper response_type
Definition: iddawc.h:147
@ I_OPT_TLS_CERT_FILE
Path to the certificate PEM file to use in a TLS authentication.
Definition: iddawc.h:197
@ I_OPT_STATE_GENERATE
Generate a random state value.
Definition: iddawc.h:160
@ I_OPT_CLIENT_SECRET
client secret, string
Definition: iddawc.h:133
@ I_OPT_CLIENT_SIGN_ALG
signature algorithm to use when the client signs a request in a JWT, values available are 'none',...
Definition: iddawc.h:166
@ I_OPT_SCOPE_APPEND
append another scope value to the scope list, string
Definition: iddawc.h:127
@ I_OPT_DEVICE_AUTH_VERIFICATION_URI
device authorization verification URI sent by the AS
Definition: iddawc.h:180
@ I_OPT_REGISTRATION_ENDPOINT
absolute url for the client registration endpoint, string
Definition: iddawc.h:176
@ I_OPT_SERVER_ENC
key id to use if multiple jwk are available on the server, string
Definition: iddawc.h:164
@ I_OPT_CLIENT_ENC
data encryption algorithm to use when the client encrypts a request in a JWT, values available are 'A...
Definition: iddawc.h:168
@ I_OPT_EXPIRES_IN
expires_in value after a succesfull auth or token request, integer
Definition: iddawc.h:153
@ I_OPT_CLIENT_ID
client_id, string
Definition: iddawc.h:132
@ I_OPT_RESPONSE_TYPE
response_type, values available are I_RESPONSE_TYPE_CODE, I_RESPONSE_TYPE_TOKEN, I_RESPONSE_TYPE_ID_T...
Definition: iddawc.h:125
@ I_OPT_ERROR_DESCRIPTION
error description of a failed request, string
Definition: iddawc.h:144
@ I_OPT_AUTH_METHOD
Authentication method to use with the auth endpoint, values available are I_AUTH_METHOD_GET,...
Definition: iddawc.h:150
@ I_OPT_DEVICE_AUTH_USER_CODE
device authorization user code sent by the AS
Definition: iddawc.h:179
@ I_OPT_END_SESSION_ENDPOINT
absolute url for the end session endpoint, string
Definition: iddawc.h:184
@ I_OPT_ERROR
error value of a failed request, string
Definition: iddawc.h:143
@ I_OPT_USERINFO_ENDPOINT
absolute url for the userinfo endpoint or equivalent, string
Definition: iddawc.h:141
@ I_OPT_STATE
state value, string
Definition: iddawc.h:128
@ I_OPT_AUTH_ENDPOINT
absolute url for the auth endpoint, string
Definition: iddawc.h:136
@ I_OPT_USERNAME
username for password response_types, string
Definition: iddawc.h:155
@ I_OPT_OPENID_CONFIG_STRICT
must the .well-known/openid-configuration parameters be strictly
Definition: iddawc.h:140
@ I_OPT_SCOPE
scope values, string, multiple scopes must be separated by a space character: "scope1 openid"
Definition: iddawc.h:126
@ I_OPT_NONCE_GENERATE
Generate a random nonce value.
Definition: iddawc.h:159
@ I_OPT_USERINFO
userinfo result, string
Definition: iddawc.h:158
@ I_OPT_ADDITIONAL_PARAMETER
use this option to pass any additional parameter value in the /auth request
Definition: iddawc.h:134
@ I_OPT_DPOP_KID
key id to use when signing a DPoP
Definition: iddawc.h:191
@ I_OPT_RESULT
result of a request
Definition: iddawc.h:142
@ I_OPT_DEVICE_AUTH_VERIFICATION_URI_COMPLETE
device authorization verification URI complete sent by the AS
Definition: iddawc.h:181
int i_init_session(struct _i_session *i_session)
Definition: iddawc.c:1382
void i_clean_session(struct _i_session *i_session)
Definition: iddawc.c:1495
int i_global_init()
Definition: iddawc.c:1364
void i_free(void *data)
Definition: iddawc.c:1378
void i_global_close()
Definition: iddawc.c:1373
uint i_get_int_parameter(struct _i_session *i_session, i_option option)
Definition: iddawc.c:2568
int i_set_rich_authorization_request_json_t(struct _i_session *i_session, const char *type, json_t *j_value)
Definition: iddawc.c:4623
uint i_get_result(struct _i_session *i_session)
Definition: iddawc.c:2564
int i_set_additional_parameter(struct _i_session *i_session, const char *s_key, const char *s_value)
Definition: iddawc.c:2170
int i_remove_claim_request(struct _i_session *i_session, int target, const char *claim)
Definition: iddawc.c:2237
int i_add_claim_request(struct _i_session *i_session, int target, const char *claim, int essential, const char *value)
Definition: iddawc.c:2194
char * i_export_session_str(struct _i_session *i_session)
Definition: iddawc.c:4397
int i_import_session_json_t(struct _i_session *i_session, json_t *j_import)
Definition: iddawc.c:4271
int i_set_int_parameter(struct _i_session *i_session, i_option option, uint i_value)
Definition: iddawc.c:1563
json_t * i_get_server_jwks(struct _i_session *i_session)
Definition: iddawc.c:2899
const char * i_get_additional_parameter(struct _i_session *i_session, const char *s_key)
Definition: iddawc.c:2875
json_t * i_export_session_json_t(struct _i_session *i_session)
Definition: iddawc.c:4167
int i_set_result(struct _i_session *i_session, uint i_value)
Definition: iddawc.c:1559
const char * i_get_additional_response(struct _i_session *i_session, const char *s_key)
Definition: iddawc.c:2883
int i_set_parameter_list(struct _i_session *i_session,...)
Definition: iddawc.c:2270
const char * i_get_str_parameter(struct _i_session *i_session, i_option option)
Definition: iddawc.c:2710
int i_remove_rich_authorization_request(struct _i_session *i_session, const char *type)
Definition: iddawc.c:4646
uint i_get_response_type(struct _i_session *i_session)
Definition: iddawc.c:2560
json_t * i_get_server_configuration(struct _i_session *i_session)
Definition: iddawc.c:2891
int i_import_session_str(struct _i_session *i_session, const char *str_import)
Definition: iddawc.c:4408
char * i_get_rich_authorization_request_str(struct _i_session *i_session, const char *type)
Definition: iddawc.c:4683
int i_set_response_type(struct _i_session *i_session, uint i_value)
Definition: iddawc.c:1555
json_t * i_get_rich_authorization_request_json_t(struct _i_session *i_session, const char *type)
Definition: iddawc.c:4666
int i_set_str_parameter(struct _i_session *i_session, i_option option, const char *s_value)
Definition: iddawc.c:1719
int i_set_additional_response(struct _i_session *i_session, const char *s_key, const char *s_value)
Definition: iddawc.c:2182
int i_set_rich_authorization_request_str(struct _i_session *i_session, const char *type, const char *value)
Definition: iddawc.c:4603
int i_revoke_token(struct _i_session *i_session, int authentication)
Definition: iddawc.c:3726
int i_build_auth_url_get(struct _i_session *i_session)
Definition: iddawc.c:2907
int i_perform_resource_service_request(struct _i_session *i_session, struct _u_request *http_request, struct _u_response *http_response, int refresh_if_expired, int bearer_type, int use_dpop, time_t dpop_iat)
Definition: iddawc.c:4512
int i_run_auth_request(struct _i_session *i_session)
Definition: iddawc.c:3071
char * i_generate_dpop_token(struct _i_session *i_session, const char *htm, const char *htu, time_t iat)
Definition: iddawc.c:4426
int i_get_userinfo_custom(struct _i_session *i_session, const char *http_method, struct _u_map *additional_query, struct _u_map *additional_headers)
Definition: iddawc.c:2446
int i_verify_jwt_access_token(struct _i_session *i_session)
Definition: iddawc.c:3697
int i_get_userinfo(struct _i_session *i_session, int get_jwt)
Definition: iddawc.c:2429
int i_run_device_auth_request(struct _i_session *i_session)
Definition: iddawc.c:4695
int i_get_registration_client(struct _i_session *i_session, json_t **j_result)
Definition: iddawc.c:4023
int i_verify_id_token(struct _i_session *i_session)
Definition: iddawc.c:3548
int i_get_openid_config(struct _i_session *i_session)
Definition: iddawc.c:2385
int i_parse_redirect_to(struct _i_session *i_session)
Definition: iddawc.c:2636
int i_get_token_introspection(struct _i_session *i_session, json_t **j_result, int authentication, int get_jwt)
Definition: iddawc.c:3819
int i_manage_registration_client(struct _i_session *i_session, json_t *j_parameters, int update_session, json_t **j_result)
Definition: iddawc.c:4092
int i_run_par_request(struct _i_session *i_session)
Definition: iddawc.c:4779
int i_register_client(struct _i_session *i_session, json_t *j_parameters, int update_session, json_t **j_result)
Definition: iddawc.c:3950
int i_run_token_request(struct _i_session *i_session)
Definition: iddawc.c:3190
Definition: iddawc.h:215
char * error_description
Definition: iddawc.h:241
uint token_method
Definition: iddawc.h:255
time_t expires_at
Definition: iddawc.h:251
struct _u_map additional_response
Definition: iddawc.h:227
char * device_authorization_endpoint
Definition: iddawc.h:236
struct _u_map additional_parameters
Definition: iddawc.h:226
jwa_alg client_enc_alg
Definition: iddawc.h:263
char * token_target
Definition: iddawc.h:247
uint pushed_authorization_request_expires_in
Definition: iddawc.h:281
json_t * access_token_payload
Definition: iddawc.h:246
char * device_auth_verification_uri
Definition: iddawc.h:276
uint result
Definition: iddawc.h:239
char * device_auth_code
Definition: iddawc.h:274
char * redirect_to
Definition: iddawc.h:221
jwa_enc server_enc
Definition: iddawc.h:259
char * token_jti
Definition: iddawc.h:271
char * token_target_type_hint
Definition: iddawc.h:248
char * resource_indicator
Definition: iddawc.h:295
int x5u_flags
Definition: iddawc.h:265
char * redirect_uri
Definition: iddawc.h:220
jwks_t * client_jwks
Definition: iddawc.h:260
int decrypt_access_token
Definition: iddawc.h:288
char * pushed_authorization_request_uri
Definition: iddawc.h:282
char * openid_config_endpoint
Definition: iddawc.h:230
int remote_cert_flag
Definition: iddawc.h:291
char * userinfo_endpoint
Definition: iddawc.h:231
char * code
Definition: iddawc.h:243
json_t * openid_config
Definition: iddawc.h:266
char * error
Definition: iddawc.h:240
char * state
Definition: iddawc.h:218
json_t * j_claims
Definition: iddawc.h:294
int pkce_method
Definition: iddawc.h:293
json_t * j_userinfo
Definition: iddawc.h:270
uint expires_in
Definition: iddawc.h:250
char * userinfo
Definition: iddawc.h:269
char * client_id
Definition: iddawc.h:222
char * refresh_token
Definition: iddawc.h:244
char * revocation_endpoint
Definition: iddawc.h:232
char * cert_file
Definition: iddawc.h:290
char * user_password
Definition: iddawc.h:225
json_t * id_token_payload
Definition: iddawc.h:253
json_t * j_authorization_details
Definition: iddawc.h:273
uint token_exp
Definition: iddawc.h:272
int decrypt_code
Definition: iddawc.h:286
char * error_uri
Definition: iddawc.h:242
char * client_kid
Definition: iddawc.h:261
jwa_alg dpop_sign_alg
Definition: iddawc.h:285
int use_dpop
Definition: iddawc.h:283
char * token_type
Definition: iddawc.h:249
char * token_endpoint
Definition: iddawc.h:229
int openid_config_strict
Definition: iddawc.h:267
char * pkce_code_verifier
Definition: iddawc.h:292
jwa_alg server_enc_alg
Definition: iddawc.h:258
char * dpop_kid
Definition: iddawc.h:284
char * nonce
Definition: iddawc.h:219
uint require_pushed_authorization_requests
Definition: iddawc.h:280
char * access_token
Definition: iddawc.h:245
uint auth_method
Definition: iddawc.h:254
char * check_session_iframe
Definition: iddawc.h:235
char * client_secret
Definition: iddawc.h:223
char * issuer
Definition: iddawc.h:268
char * username
Definition: iddawc.h:224
uint device_auth_interval
Definition: iddawc.h:279
char * server_kid
Definition: iddawc.h:257
char * registration_endpoint
Definition: iddawc.h:237
char * scope
Definition: iddawc.h:217
uint response_type
Definition: iddawc.h:216
char * end_session_endpoint
Definition: iddawc.h:234
jwa_alg client_sign_alg
Definition: iddawc.h:262
char * device_auth_user_code
Definition: iddawc.h:275
jwa_enc client_enc
Definition: iddawc.h:264
char * pushed_authorization_request_endpoint
Definition: iddawc.h:238
char * id_token
Definition: iddawc.h:252
char * key_file
Definition: iddawc.h:289
char * authorization_endpoint
Definition: iddawc.h:228
uint device_auth_expires_in
Definition: iddawc.h:278
char * introspection_endpoint
Definition: iddawc.h:233
jwks_t * server_jwks
Definition: iddawc.h:256
int decrypt_refresh_token
Definition: iddawc.h:287
char * device_auth_verification_uri_complete
Definition: iddawc.h:277