Test info Profile: {'openid-configuration': 'config', 'response_type': 'code', 'crypto': 'sign', 'registration': 'dynamic'} Timestamp: 2016-08-10T15:56:52Z Test description: Reject registration where a redirect_uri has a fragment [Dynamic] Test ID: OP-redirect_uri-RegFrag Issuer: https://keycloak-mposolda.rhcloud.com/auth/realms/master Test output __RegistrationRequest:post__ [check] status: INFORMATION description: Registration Response info: {"redirect_uris":["https://op.certification.openid.net:60784/authz_cb#foobar"],"grant_types":["authorization_code","refresh_token"],"response_types":["code","none"],"client_id":"8515dc4f-237b-4b9d-8131-1364232d0d30","client_secret":"de4f7376-345f-438c-aa3d-9b9460c26043","client_id_issued_at":1470844612,"client_secret_expires_at":0,"registration_client_uri":"https://keycloak-mposolda.rhcloud.com/auth/realms/master/clients-registrations/openid-connect/8515dc4f-237b-4b9d-8131-1364232d0d30","registration_access_token":"eyJhbGciOiJSUzI1NiJ9.eyJqdGkiOiIyMDAwMjA1ZS0xM2U2LTQ4ZjgtYjI3MS0yYmQyOWY3NTZmN2MiLCJleHAiOjAsIm5iZiI6MCwiaWF0IjoxNDcwODQ0NjEyLCJpc3MiOiJodHRwczovL2tleWNsb2FrLW1wb3NvbGRhLnJoY2xvdWQuY29tL2F1dGgvcmVhbG1zL21hc3RlciIsImF1ZCI6Imh0dHBzOi8va2V5Y2xvYWstbXBvc29sZGEucmhjbG91ZC5jb20vYXV0aC9yZWFsbXMvbWFzdGVyIiwidHlwIjoiUmVnaXN0cmF0aW9uQWNjZXNzVG9rZW4ifQ.hUgOWvxmE9JXQzIvDHYPhs5e6MI32u2z9ztSnah5D1p1wHN-TTQqruPCuWMuku8JjkZPR2JeOfoGSrwPdZN1Brkc09TBdbkAE97b_40Oxo7g4UCHwxo-7hQCYDhwdbhvBHuN8_pIVfWelQUlco_L2buiACc3xOBock2eK2-f1YIL-hhBGozw_r2dJSaxNutrtzpYSZfeFiYmo7ZFSuynC0L8qOkqCtZay9ZdS40qVkH7kv8LB4tX6rMOpjjbcD1RH_FxQ40HNGMUWJsxmuH2EtrO4G9Y00I1QRTlUOoXGbTib0I40VCfcp860kr3M5BxWEwDY37mF3slQIwHiGyLfQ"} __After completing the test flow:__ [verify-response] status: ERROR description: Checks that the last response was one of a possible set of OpenID Connect Responses info: Got a RegistrationResponse response __X:==== END ====__ Trace output 0.000528 ------------ DiscoveryRequest ------------ 0.000546 Provider info discover from 'https://keycloak-mposolda.rhcloud.com/auth/realms/master' 0.000554 --> URL: https://keycloak-mposolda.rhcloud.com/auth/realms/master/.well-known/openid-configuration 0.060854 ProviderConfigurationResponse: { "authorization_endpoint": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/protocol/openid-connect/auth", "claim_types_supported": [ "normal" ], "claims_parameter_supported": false, "claims_supported": [ "sub", "iss", "auth_time", "name", "given_name", "family_name", "preferred_username", "email" ], "end_session_endpoint": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/protocol/openid-connect/logout", "grant_types_supported": [ "authorization_code", "implicit", "refresh_token", "password", "client_credentials" ], "id_token_signing_alg_values_supported": [ "RS256" ], "issuer": "https://keycloak-mposolda.rhcloud.com/auth/realms/master", "jwks_uri": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/protocol/openid-connect/certs", "registration_endpoint": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/clients-registrations/openid-connect", "request_parameter_supported": false, "request_uri_parameter_supported": false, "require_request_uri_registration": true, "response_modes_supported": [ "query", "fragment", "form_post" ], "response_types_supported": [ "code", "none", "id_token", "token", "id_token token", "code id_token", "code token", "code id_token token" ], "scopes_supported": [ "openid", "offline_access" ], "subject_types_supported": [ "public" ], "token_endpoint": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/protocol/openid-connect/token", "token_endpoint_auth_methods_supported": [ "client_secret_basic", "client_secret_post", "private_key_jwt" ], "token_endpoint_auth_signing_alg_values_supported": [ "RS256" ], "token_introspection_endpoint": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/protocol/openid-connect/token/introspect", "userinfo_endpoint": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/protocol/openid-connect/userinfo", "version": "3.0" } 0.129868 JWKS: { "keys": [ { "alg": "RS256", "e": "AQAB", "kid": "n9b3FMNr3I95bpYQNeNDo_cJ7lGPFAmD9fuDtGwbjwE", "kty": "RSA", "n": "wBl5s6Yr1hlFyJeIJQjXIEspMKDCwJ3iHnAXOs63F_-CYotlhjvnNOfUezcRd1nYBEj25gpBKtAIbhYneu7JcV-I7NfF2i8AOX_MsNg7Enk9B-8UtvsLlOLR3PeY2i4JlXEVyml80N__3kKz-4T7wzDekvm3rpJspWYXmeZ7CVPhwlUvW3A8ijUEykNDmYllm4BwzpOD4BlJqq7drlqYk5kkV7DczcyGmKuxXkVDEdMwiYNZG3S44vdaajV5QJi8I9WYRgn5ZJN4YuraRkPaZNFsaLQ2R07tp05BFhFpOeyuxVUfpMdcBm_r2Z0CN3DvSu6sIbKXAhy6ZGuweKh4wQ", "use": "sig" } ] } 0.144178 ------------ RegistrationRequest ------------ 0.144659 --> URL: https://keycloak-mposolda.rhcloud.com/auth/realms/master/clients-registrations/openid-connect 0.144668 --> BODY: {"subject_type": "public", "jwks_uri": "https://op.certification.openid.net:60784/export/jwk_60784.json", "contacts": ["roland.hedberg@umu.se"], "application_type": "web", "grant_types": ["authorization_code"], "post_logout_redirect_uris": ["https://op.certification.openid.net:60784/logout"], "redirect_uris": ["https://op.certification.openid.net:60784/authz_cb#foobar"], "response_types": ["code"], "require_auth_time": true, "default_max_age": 3600} 0.144684 --> HEADERS: {'Content-Type': 'application/json'} 0.241791 <-- STATUS: 201 0.241971 <-- BODY: {"redirect_uris":["https://op.certification.openid.net:60784/authz_cb#foobar"],"grant_types":["authorization_code","refresh_token"],"response_types":["code","none"],"client_id":"8515dc4f-237b-4b9d-8131-1364232d0d30","client_secret":"de4f7376-345f-438c-aa3d-9b9460c26043","client_id_issued_at":1470844612,"client_secret_expires_at":0,"registration_client_uri":"https://keycloak-mposolda.rhcloud.com/auth/realms/master/clients-registrations/openid-connect/8515dc4f-237b-4b9d-8131-1364232d0d30","registration_access_token":"eyJhbGciOiJSUzI1NiJ9.eyJqdGkiOiIyMDAwMjA1ZS0xM2U2LTQ4ZjgtYjI3MS0yYmQyOWY3NTZmN2MiLCJleHAiOjAsIm5iZiI6MCwiaWF0IjoxNDcwODQ0NjEyLCJpc3MiOiJodHRwczovL2tleWNsb2FrLW1wb3NvbGRhLnJoY2xvdWQuY29tL2F1dGgvcmVhbG1zL21hc3RlciIsImF1ZCI6Imh0dHBzOi8va2V5Y2xvYWstbXBvc29sZGEucmhjbG91ZC5jb20vYXV0aC9yZWFsbXMvbWFzdGVyIiwidHlwIjoiUmVnaXN0cmF0aW9uQWNjZXNzVG9rZW4ifQ.hUgOWvxmE9JXQzIvDHYPhs5e6MI32u2z9ztSnah5D1p1wHN-TTQqruPCuWMuku8JjkZPR2JeOfoGSrwPdZN1Brkc09TBdbkAE97b_40Oxo7g4UCHwxo-7hQCYDhwdbhvBHuN8_pIVfWelQUlco_L2buiACc3xOBock2eK2-f1YIL-hhBGozw_r2dJSaxNutrtzpYSZfeFiYmo7ZFSuynC0L8qOkqCtZay9ZdS40qVkH7kv8LB4tX6rMOpjjbcD1RH_FxQ40HNGMUWJsxmuH2EtrO4G9Y00I1QRTlUOoXGbTib0I40VCfcp860kr3M5BxWEwDY37mF3slQIwHiGyLfQ"} 0.243172 RegistrationResponse: { "client_id": "8515dc4f-237b-4b9d-8131-1364232d0d30", "client_id_issued_at": 1470844612, "client_secret": "de4f7376-345f-438c-aa3d-9b9460c26043", "client_secret_expires_at": 0, "grant_types": [ "authorization_code", "refresh_token" ], "redirect_uris": [ "https://op.certification.openid.net:60784/authz_cb#foobar" ], "registration_access_token": "eyJhbGciOiJSUzI1NiJ9.eyJqdGkiOiIyMDAwMjA1ZS0xM2U2LTQ4ZjgtYjI3MS0yYmQyOWY3NTZmN2MiLCJleHAiOjAsIm5iZiI6MCwiaWF0IjoxNDcwODQ0NjEyLCJpc3MiOiJodHRwczovL2tleWNsb2FrLW1wb3NvbGRhLnJoY2xvdWQuY29tL2F1dGgvcmVhbG1zL21hc3RlciIsImF1ZCI6Imh0dHBzOi8va2V5Y2xvYWstbXBvc29sZGEucmhjbG91ZC5jb20vYXV0aC9yZWFsbXMvbWFzdGVyIiwidHlwIjoiUmVnaXN0cmF0aW9uQWNjZXNzVG9rZW4ifQ.hUgOWvxmE9JXQzIvDHYPhs5e6MI32u2z9ztSnah5D1p1wHN-TTQqruPCuWMuku8JjkZPR2JeOfoGSrwPdZN1Brkc09TBdbkAE97b_40Oxo7g4UCHwxo-7hQCYDhwdbhvBHuN8_pIVfWelQUlco_L2buiACc3xOBock2eK2-f1YIL-hhBGozw_r2dJSaxNutrtzpYSZfeFiYmo7ZFSuynC0L8qOkqCtZay9ZdS40qVkH7kv8LB4tX6rMOpjjbcD1RH_FxQ40HNGMUWJsxmuH2EtrO4G9Y00I1QRTlUOoXGbTib0I40VCfcp860kr3M5BxWEwDY37mF3slQIwHiGyLfQ", "registration_client_uri": "https://keycloak-mposolda.rhcloud.com/auth/realms/master/clients-registrations/openid-connect/8515dc4f-237b-4b9d-8131-1364232d0d30", "response_types": [ "code", "none" ] } 0.257811 ==== END ==== Result FAILED