Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | More warning fixes. | Andrew Arnott | 2013-02-16 | 2 | -7/+7 |
| | |||||
* | Lots of stylecop fixes. | Andrew Arnott | 2013-02-16 | 1 | -1/+1 |
| | |||||
* | More warning fixes. | Andrew Arnott | 2013-02-10 | 1 | -1/+1 |
| | |||||
* | C# compiler warning fixes. | Andrew Arnott | 2013-02-10 | 4 | -6/+12 |
| | |||||
* | OAuth2.AuthorizationServer now builds. | Andrew Arnott | 2013-01-13 | 4 | -12/+23 |
| | |||||
* | Removes more remnants of Code Contracts. | Andrew Arnott | 2012-12-26 | 4 | -6/+0 |
| | |||||
* | Replaces DNOA's internal Requires class with Validation NuGet package. | Andrew Arnott | 2012-12-26 | 8 | -0/+8 |
| | |||||
* | CreateAccessToken reveals username to host | Andrew Arnott | 2012-12-24 | 1 | -3/+3 |
| | | | | | | | IAuthorizationServerHost.CreateAccessToken now has access to authoring usernames. Fixes #219 | ||||
* | Merge branch 'v4.1' | Andrew Arnott | 2012-12-02 | 1 | -1/+7 |
|\ | | | | | | | | | | | | | Conflicts: src/DotNetOpenAuth.OAuth2.ResourceServer/OAuth2/StandardAccessTokenAnalyzer.cs src/DotNetOpenAuth.Test/OAuth2/OAuth2TestBase.cs src/version.txt | ||||
| * | Fixes HTTP Basic auth challenge to include realm | Andrew Arnott | 2012-11-11 | 1 | -1/+7 |
| | | | | | | | | Fixes #189 | ||||
* | | Authorization servers can override the granted scopes for all grant types. | Andrew Arnott | 2012-10-30 | 1 | -5/+10 |
| | | | | | | | | | | | | This change adds the ability for authorization servers to override the granted scopes of client credential and resource owner password grant types. Fixes #225 | ||||
* | | Merge remote-tracking branch 'aarnott/master' | Andrew Arnott | 2012-10-29 | 1 | -2/+2 |
|\ \ | |/ |/| | |||||
| * | Adds AuthorizationServer.DecodeRefreshToken | Andrew Arnott | 2012-07-20 | 1 | -2/+2 |
| | | | | | | | | | | | | And a unit test. Fixes #182 | ||||
* | | Fix error message. | Andrew Arnott | 2012-08-23 | 1 | -1/+1 |
| | | |||||
* | | Replaces explicit crypto algorithm use with factories. | Andrew Arnott | 2012-07-18 | 1 | -1/+1 |
|/ | | | | Fixes #47 which requires that FIPS compliance be an option. | ||||
* | Special handling for client credential grant type | Andrew Arnott | 2012-05-29 | 1 | -0/+13 |
| | | | | | | | | Access token requests that carry client credential grants are now specially handled and signal to the authorization server that an authorization record should be created. More work toward #138 | ||||
* | Resource owner password grant method rename | Andrew Arnott | 2012-05-29 | 1 | -36/+38 |
| | | | | | | | | | | | | Renamed IAuthorizationServerHost.IsResourceOwnerCredentialValid to TryAuthorizeResourceOwnerCredentialGrant so that authorization servers are prepared to approve refresh tokens that may be issued as a result of a resource owner password grant. This also removes some of the "validation" that wasn't really doing anything useful for resource owner password grant types. Toward an eventual fix for #138 | ||||
* | Authorization Server hosts now instantiate their own AccessTokens rather ↵ | Andrew Arnott | 2012-04-25 | 1 | -6/+5 |
| | | | | | | | than just parameters. AccessTokens are now serialized via a virtual method on that instance. Fixes #38, I think. | ||||
* | Anonymous clients can now exchange resource owner credentials for refresh ↵ | Andrew Arnott | 2012-04-22 | 1 | -7/+15 |
| | | | | | | | | and access tokens. (authenticated clients already could). Fixes #100 | ||||
* | Fixes access denial errors from OAuth 2 resource servers so they include the ↵ | Andrew Arnott | 2012-04-22 | 4 | -14/+22 |
| | | | | | | required parameters in their WWW-Authenticate headers. Fixes #124 | ||||
* | Fixed HTTP Basic authentication for OAuth 2 clients so that it actually ↵ | Andrew Arnott | 2012-04-19 | 5 | -12/+49 |
| | | | | works in the sample. | ||||
* | Fixed up the configuration story for OAuth 2. | Andrew Arnott | 2012-04-18 | 6 | -61/+40 |
| | |||||
* | StyleCop cleanup, and reversal of some code changes that were no longer ↵ | Andrew Arnott | 2012-04-18 | 6 | -2/+74 |
| | | | | necessary. | ||||
* | We have HTTP Basic client authentication working now in OAuth 2. | Andrew Arnott | 2012-04-18 | 6 | -7/+196 |
| | |||||
* | Authorization server hosts may now provide canonical usernames for the ↵ | Andrew Arnott | 2012-04-16 | 1 | -1/+4 |
| | | | | | | resource owner given correct resource owner credentials. Fixes #103 | ||||
* | Authorization servers now gain insight into the calling client when ↵ | Andrew Arnott | 2012-04-15 | 1 | -1/+1 |
| | | | | | | validating resource owner credential grant type requests. Fixes #101 | ||||
* | Renamed IAuthorizationServer to IAuthorizationServerHost. | Andrew Arnott | 2012-04-08 | 5 | -7/+7 |
| | | | | To avoid confusion with the concrete class AuthorizationServer. | ||||
* | Allows the authorization server to store merely the hashes of client secrets. | Andrew Arnott | 2012-04-01 | 1 | -3/+2 |
| | | | | Fixes #92 | ||||
* | Corrected old name of nonce store property. | Andrew Arnott | 2012-04-01 | 1 | -1/+1 |
| | |||||
* | Moved localizable strings into specific OAuth 2 assemblies. | Andrew Arnott | 2012-03-31 | 1 | -2/+2 |
| | |||||
* | Removed another auth server binding element. | Andrew Arnott | 2012-03-31 | 2 | -95/+0 |
| | |||||
* | Moved access token signing key to the parameters object. | Andrew Arnott | 2012-03-31 | 1 | -1/+3 |
| | | | | | | This also presumably solves the threading concerns of sharing one instance. Fixes #34 | ||||
* | Consolidated all code and token serializations to one binding element. | Andrew Arnott | 2012-03-30 | 5 | -171/+179 |
| | |||||
* | Fixed up an authorization server's token endpoint to generate more accurate ↵ | Andrew Arnott | 2012-03-30 | 2 | -14/+16 |
| | | | | error messages. | ||||
* | Added binding element comments. | Andrew Arnott | 2012-03-30 | 2 | -0/+2 |
| | |||||
* | Moved some message validation to another binding element. | Andrew Arnott | 2012-03-29 | 3 | -14/+11 |
| | |||||
* | Moved the code in AuthorizationCodeBindingElement into the ↵ | Andrew Arnott | 2012-03-29 | 3 | -89/+9 |
| | | | | AuthorizationServer class. | ||||
* | Beginning work of cleaning up the auth server binding elements. | Andrew Arnott | 2012-03-26 | 5 | -43/+28 |
| | |||||
* | All unit tests pass again. | Andrew Arnott | 2012-03-18 | 1 | -13/+19 |
| | |||||
* | Fixed failing unit test: ResourceOwnerPasswordCredentialGrant. | Andrew Arnott | 2012-03-18 | 2 | -19/+12 |
| | |||||
* | A little binding element cleanup. | Andrew Arnott | 2012-03-18 | 2 | -15/+13 |
| | |||||
* | Fixed build breaks in the solution. | Andrew Arnott | 2012-03-17 | 1 | -2/+3 |
| | |||||
* | Redistributed OAuth2 code into their more specific assemblies. | Andrew Arnott | 2012-03-16 | 9 | -0/+860 |