Thanks Ray - But under this OIDC Dynamic Client Registration scenario, the client (i.e. in this case, ownCloud Desktop client) is actually supplying the service definition to the CAS server. And according to my understanding of RFC 8252, the information provided by the client is correct/valid. Obviously, I've been able to hack the service definition which was dynamically generated by the CAS server and manually update the serviceId to "http://127.0.0.1:.*". I don't believe this type of hack should be necessary according to RFC 8252.
On Wednesday, November 24, 2021 at 12:34:16 PM UTC-5 Ray Bon wrote: > In the service definition you can use a regex. > Try something like http://127.0.0.1.* > > Ray > > On Tue, 2021-11-23 at 05:40 -0800, G Lalonde wrote: > > Notice: This message was sent from outside the University of Victoria > email system. Please be cautious with links and sensitive information. > > > As stipulated in RFC8252 ( > https://datatracker.ietf.org/doc/html/rfc8252#section-7.3) > > 7.3. Loopback Interface Redirection > > Native apps that are able to open a port on the loopback network > interface without needing special permissions (typically, those on > desktop operating systems) can use the loopback interface to receive > the OAuth redirect. > > Loopback redirect URIs use the "http" scheme and are constructed with > the loopback IP literal and whatever port the client is listening on. > That is, "http://127.0.0.1:{port}/{path}" for IPv4, > > ... > > The authorization server MUST allow any port to be specified at the > time of the request for loopback IP redirect URIs, to accommodate > clients that obtain an available ephemeral port from the operating > system at the time of the request. > > Hence, as I understand it, CAS should properly redirect an OIDC Dynamicly > created service with a serviceId of "http://127.0.0.1" while a client > later valides the url with "http://127.0.0.1:40709" > > ownCloud Client Desktop log > 11-22 14:17:39:760 [ debug sync.credentials.oauth ] [ isUrlValid ]: Checking > URL for validity: QUrl(" > https://secure.redacted.com/cas/oidc/oidcAuthorize?response_type=code&client_id=EypOKlThOZe6FDMnXPvwnefV5vwaEg2fO2Y9&redirect_uri=http://127.0.0.1:40709&code_challenge=wvuB6-9PdhJaV-vwsig3ILw2BWAigICoQ6MtnaughEE&code_challenge_method=S256&scope=openid > > offline_access email profile&prompt=select_account > consent&state=IXo0lpOqYtZMLLB_DVBTrvAyElWR5xZyFwsH5-2WhZA%3D&login_hint=someone&user=someone") > > CAS server log: > 2021-11-22 14:17:42,568 ERROR > [org.apereo.cas.support.oauth.util.OAuth20Utils] - <Unsupported > [redirect_uri]: [http://127.0.0.1:40709] does not match what is defined > for registered service: [http://127.0.0.1]. Service is considered > unauthorized. Verify the service matching strategy used in theservice > definition is correct and does in fact match the client [http://127.0. > 0.1:40709]> > > On Thursday, November 11, 2021 at 8:45:40 AM UTC-5 G Lalonde wrote: > > This latest release (RC2) has fixed the issue with the missing > "client_secret_expires_at" field but unfortunately the JSON service > definition created by the client registration (i.e. ownCloud Desktop > client) is created with a serviceId of "http://127.0.0.1" but the > redirected_uri always includes a random port number. Since I don't control > the service definition creation (the client does), I can't get the > serviceId to be "http://127.0.0.1:.*" which CAS will properly redirect. Is > there a CAS configuration setting to relax the serviceId matching or is > this an OIDC client issue? > > Currently using: cas.authn.oidc.core.dynamic-client-registration-mode=OPEN > > CAS server log: > > 2021-11-10 15:36:20,204 WARN > [org.apereo.cas.services.resource.AbstractResourceBasedServiceRegistry] - > <[ownCloud2.9.1(build5500)-1636576580202.json] does not match the > recommended pattern [(\w+-)+(\d+)\.json]. While CAS tries to be forgiving > as much as possible, it's recommended that you rename the file to match the > requested pattern to avoid issues with duplicate service loading. Future > CAS versions may try to strictly force the naming syntax, refusing to load > the file.> > 2021-11-10 15:36:20,794 ERROR > [org.apereo.cas.support.oauth.util.OAuth20Utils] - <Unsupported > [redirect_uri]: [http://127.0.0.1:40839] does not match what is defined > for registered service: [http://127.0.0.1]. Service is considered > unauthorized. Verify the service matching strategy used in the service > definition is correct and does in fact match the client [ > http://127.0.0.1:40839]> > > ownCloud Desktop client log: > > 11-10 15:36:20:107 [ info sync.httplogger ]: > "5b22ff68-93f0-4588-80b7-31b01bba9218: > Request: POST https://secure.redacted.com/cas/oidc/register Header: { > Content-Type: application/json, User-Agent: Mozilla/5.0 (Linux) > mirall/2.9.1 (build 5500) (ownCloud, ubuntu-5.4.154-0504154-generic > ClientArchitecture: x86_64 OsArchitecture: x86_64), Accept: */*, > X-Request-ID: 5b22ff68-93f0-4588-80b7-31b01bba9218, Original-Request-ID: > 5b22ff68-93f0-4588-80b7-31b01bba9218, Content-Length: 201, } Data: [{\n > \"application_type\": \"native\",\n \"client_name\": \"ownCloud 2.9.1 > (build 5500)\",\n \"redirect_uris\": [\n \"http://127.0.0.1\"\n ],\n > \"token_endpoint_auth_method\": \"client_secret_basic\"\n}\n]" > > > CAS JSON service definition created by client > (ownCloud2.9.1(build5500)-1636576580202.json) > { > @class: org.apereo.cas.services.OidcRegisteredService > serviceId: http://127.0.0.1 > name: ownCloud 2.9.1 (build 5500) > id: 1636576580202 > description: Registered service ownCloud 2.9.1 (build 5500) > logoutUrl: "" > clientSecret: EQfoYQ0uscSGDwqzQQCkiDvbUMTv4Or1QnGw > clientId: QRRw9U52xBQYyyO0glZLSmS9LII6Jg3t3kvl > dynamicallyRegistered: true > dynamicRegistrationDateTime: 2021-11-10T20:36:20.201971Z > scopes: > [ > java.util.HashSet > [ > address > phone > openid > email > profile > offline_access > ] > ] > } > > > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/62b0a277-2398-4b05-88f8-9dc890c427e5n%40apereo.org.
