#!/usr/bin/env bash # Shared helpers. Sourced, not run. RS="${RS:-http://localhost:8081}" STUB="${STUB:-http://localhost:9000}" KC="${KC:-http://localhost:8080}" hr() { printf '%s\n' "--------------------------------------------------------------------------"; } head1(){ hr; printf ' %s\n' "$1"; hr; } # Prints status, the RFC 6750 challenge header, and the body. The WWW-Authenticate header is # the only place a claim-validation failure explains itself, so it is never omitted here. call() { local label="$1" url="$2" token="${3:-}" printf '\n$ %s\n' "$label" local args=(-s -o /tmp/.body -D /tmp/.hdr -w '%{http_code}') [ -n "$token" ] && args+=(-H "Authorization: Bearer $token") local code code=$(curl "${args[@]}" "$url") printf 'HTTP %s\n' "$code" grep -i '^www-authenticate:' /tmp/.hdr | sed 's/\r$//' || true if [ -s /tmp/.body ]; then python3 -m json.tool < /tmp/.body 2>/dev/null || cat /tmp/.body echo fi } stub_token() { curl -s -X POST "$STUB/token?$1"; } stub_state() { curl -s "$STUB/admin/state" | python3 -m json.tool; } stub_fetches() { curl -s "$STUB/admin/state" | python3 -c 'import json,sys;print(json.load(sys.stdin)["jwksFetches"])'; } kc_token() { curl -s -X POST "$KC/realms/demo/protocol/openid-connect/token" \ -d grant_type=password -d client_id=demo-client -d client_secret=demo-secret \ -d "username=$1" -d "password=$2" \ | python3 -c 'import json,sys;print(json.load(sys.stdin).get("access_token",""))' } claims() { python3 - "$1" <<'PY' import sys, base64, json tok = sys.argv[1] h, p, _ = tok.split('.') pad = lambda s: s + '=' * (-len(s) % 4) print(" header:", json.dumps(json.loads(base64.urlsafe_b64decode(pad(h))))) c = json.loads(base64.urlsafe_b64decode(pad(p))) for k in ("iss", "aud", "typ", "scope", "preferred_username", "realm_access", "resource_access"): if k in c: print(" %-18s %s" % (k, json.dumps(c[k]))) PY }