All files / src/handlers DynamicRegistrationRequest.js

100% Statements 48/48
100% Branches 15/15
100% Functions 10/10
100% Lines 47/47
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209            1x 1x 1x 1x 1x                             1x   1x                             9x   9x 1x             8x 1x             7x 1x       7x 6x                       7x 7x   7x 1x           6x 6x                   2x 2x 2x   2x                   2x 2x 2x     2x                         2x 2x 2x                     5x   5x     5x           5x 2x     5x         5x                 1x 1x                 6x 6x                   7x   7x                 1x      
'use strict'
 
/**
 * Dependencies
 * @ignore
 */
const {JWT} = require('@trust/jose')
const crypto = require('@trust/webcrypto')
const url = require('url')
const BaseRequest = require('./BaseRequest')
const Client = require('../Client')
 
/**
 * DynamicRegistrationRequest
 */
class DynamicRegistrationRequest extends BaseRequest {
 
  /**
   * Request Handler
   *
   * @param {HTTPRequest} req
   * @param {HTTPResponse} res
   * @param {Provider} provider
   */
  static handle (req, res, provider) {
    let request = new DynamicRegistrationRequest(req, res, provider)
 
    return Promise.resolve(request)
      .then(request.validate)
      .then(request.register)
      .then(request.token)
      .then(request.respond)
      .catch(request.error.bind(request))
  }
 
  /**
   * Validate
   *
   * @param {DynamicRegistrationRequest} request
   * @returns {DynamicRegistrationRequest}
   */
  validate (request) {
    let registration = request.req.body
 
    if (!registration) {
      return request.badRequest({
        error: 'invalid_request',
        error_description: 'Missing registration request body'
      })
    }
 
    // Return an explicit error on missing redirect_uris
    if (!registration.redirect_uris) {
      return request.badRequest({
        error: 'invalid_request',
        error_description: 'Missing redirect_uris parameter'
      })
    }
 
    // generate a client id unless one is provided
    if (!registration['client_id']) {
      registration['client_id'] = request.identifier()
    }
 
    // generate a client secret for non-implicit clients
    if (!request.implicit(registration)) {
      registration.client_secret = request.secret()
    }
 
    /**
     * TODO: Validate that the `frontchannel_logout_uri` domain and port is the same as one of the `redirect_uris` values
     * @see https://openid.net/specs/openid-connect-frontchannel-1_0.html#RPLogout
     *
     * The domain, port, and scheme of this URL MUST be the same as that of a
     * registered Redirection URI value.
     */
 
    // initialize and validate a client
    let client = new Client(registration)
    let validation = client.validate()
 
    if (!validation.valid) {
      return request.badRequest({
        error: 'invalid_request',
        error_description: 'Client validation error: ' + JSON.stringify(validation)
      })
    }
 
    request.client = client
    return request
  }
 
  /**
   * register
   *
   * @param {DynamicRegistrationRequest} request
   * @returns {Promise}
   */
  register (request) {
    let backend = request.provider.backend
    let client = request.client
    let id = client['client_id']
 
    return backend.put('clients', id, client).then(client => request)
  }
 
  /**
   * token
   *
   * @param {DynamicRegistrationRequest} request
   * @returns {Promise}
   */
  token (request) {
    let {provider, client} = request
    let {issuer, keys} = provider
    let alg = client['id_token_signed_response_alg']
 
    // create a registration access token
    let jwt = new JWT({
      header: {
        alg
      },
      payload: {
        iss: issuer,
        aud: client['client_id'],
        sub: client['client_id']
      },
      key: keys.register.signing[alg].privateKey
    })
 
    // sign the token
    return jwt.encode().then(compact => {
      request.compact = compact
      return request
    })
  }
 
  /**
   * respond
   *
   * @param {DynamicRegistrationRequest} request
   * @returns {Promise}
   */
  respond (request) {
    let {client, compact, provider, res} = request
 
    let clientUri = url.resolve(provider.issuer,
      '/register/' + encodeURIComponent(client.client_id))
 
    let response = Object.assign({}, client, {
      registration_access_token: compact,
      registration_client_uri: clientUri,
      client_id_issued_at: Math.floor(Date.now() / 1000)
    })
 
    if (client.client_secret) {
      response.client_secret_expires_at = 0
    }
 
    res.set({
      'Cache-Control': 'no-store',
      'Pragma': 'no-cache'
    })
 
    res.status(201).json(response)
  }
 
  /**
   * identifier
   *
   * @returns {string}
   */
  identifier () {
    let value = crypto.getRandomValues(new Uint8Array(16))
    return Buffer.from(value).toString('hex')
  }
 
  /**
   * secret
   *
   * @returns {string}
   */
  secret () {
    let value = crypto.getRandomValues(new Uint8Array(16))
    return Buffer.from(value).toString('hex')
  }
 
  /**
   * implicit
   *
   * @param {Object} registration
   * @returns {Boolean}
   */
  implicit (registration) {
    let responseTypes = registration['response_types']
 
    return !!(responseTypes
      && responseTypes.length === 1
      && responseTypes[0] === 'id_token token')
  }
}
 
/**
 * Export
 */
module.exports = DynamicRegistrationRequest