OPENID CONNECT · LAB
Name the provider, the relying party and the issuer in your own tenant
Map the OpenID Connect roles onto Lab Photos and lab-collage, find one issuer in four places, and change how the provider authenticates Ava without the relying party changing anything.
ReadyUses your lab tenant
The lesson
Builds on: From delegated access to sign-in.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
Sign Ava in to lab-collage with a password
Recorded as
oauth.authorizesucceeded (code_issued) forlab-collageabout[email protected].Ava adds an authenticator app
Recorded as
account.securitysucceeded (method_enrolled) about[email protected].The provider asks Ava for her code
Recorded as
account.second_stepsucceeded (second_step_completed) about[email protected].lab-collage receives tokens after the stronger sign-in
Recorded as
oauth.tokensucceeded forlab-collageabout[email protected].
Request console
Requests in this lab can be sent from this page to your tenant: open one and choose Send. Fill in the values below first. They stay in this page's memory and are gone when you leave; secrets are never stored or sent anywhere except the request you send.
Setup
You need
lab-collage, Ava and the shell variables from the first lab in this track, plus an authenticator app (oroathtool) for a time-based code.If Ava already has an authenticator app from an earlier lab, remove it as Ava at
$ISSUER/account/security, so this lab starts with password-only sign-in.Keep
btl-lab callbackrunning in a second terminal.Press Start.
Walkthrough
Map the roles. Fill in the lesson's role table with real names from your tenant:
| OpenID Connect role | In your lab | OAuth role it builds on |
|---|---|---|
| End-User | Ava Archer | Resource owner |
| Relying Party | lab-collage | Client |
| OpenID Provider | Lab Photos at $ISSUER | Authorization server |
| UserInfo endpoint | $ISSUER/oidc/userinfo | Protected resource |
Why it matters: these are the names you use for the rest of the track. The provider is the same authorization server you used in the OAuth labs, with a second job.
Sign Ava in through
lab-collagewithscope=openid, as in the first lab:eval "$(btl-lab pkce)"; eval "$(btl-lab state)", open the authorization URL, sign in with Ava's password, and exchange the code with-u "$CLIENT_ID:$CLIENT_SECRET". KeepID_TOKEN.
One issuer, four places. Write down the
issvalue the listener printed from the callback. Then read the provider's own statement of its issuer:
GET$ISSUER/.well-known/openid-configuration
Open in console
GET $ISSUER/.well-known/openid-configuration HTTP/1.1
Accept: application/jsonCompare all four values byte for byte:
echo "$ISSUER"
curl -s "$ISSUER/.well-known/openid-configuration" | jq -r .issuer
btl-lab decode "$ID_TOKEN" | grep '"iss"'
Why it matters: everything the relying party trusts about the provider hangs from this exact string. Your configuration, the discovery document, the callback and the token must agree character for character.
Registration carries over. Open
lab-collagein OAuth > Clients. Its client ID, redirect URIs, confidential type and secret are ordinary OAuth settings, and nothing marks it as a "relying party".
Why it matters: a relying party is still an OAuth client. OpenID Connect adds responsibilities to the client (checking the ID token, finding the account, running a session), not a new kind of registration.
Record how the provider authenticated Ava:
btl-lab decode "$ID_TOKEN"showsamr: ["pwd"]and anauth_time.
The provider changes how it authenticates. In Authentication, set the authenticator app (TOTP) method to optional if it is off. As Ava, open
$ISSUER/account/securityand add an authenticator app. By default the tenant asks every user who has a second method for it at sign-in.
Start a new
lab-collagesign-in with&prompt=loginappended to the authorization URL, so the existing session is not reused. Sign in with Ava's password, enter the code from the app, exchange the code and decode the new ID token.amrnow includesotpandmfa, andauth_timeis new.
Why it matters: the relying party sent the same kind of request both times. The provider alone decided to authenticate Ava more strongly, and reported how in the token.
The relying party decides what happens next. Write down one action the collage app might protect, for example "delete a shared collage". Nothing in the ID token grants or denies it.
Why it matters: the provider says who signed in and how. Whether that person may delete the collage stays the application's own authorization decision.
Break it
Configure the relying party with a near-miss issuer and validate the token you just received:
btl-lab verify "$ID_TOKEN" --issuer "$ISSUER/" --audience "$CLIENT_ID" --type id --nonce "$NONCE"
btl-lab verify "$ID_TOKEN" --issuer "$ISSUER" --audience "$CLIENT_ID" --type id --nonce "$NONCE"
The first run stops at the issuer check because of one trailing slash. The second ends in ACCEPT. An issuer is compared exactly, never normalized.
Sign in as Ben with
&prompt=loginin a fresh private window. He has no second method, so the provider asks only for his password and his token saysamr: ["pwd"]. Same relying party, same request, different authentication, decided by the provider for each person.
Check your work
Press Check my progress. The checks look for, in order:
oauth.authorizesucceeded withcode_issuedforlab-collageand Ava.account.securitysucceeded withmethod_enrolledfor Ava.account.second_stepsucceeded withsecond_step_completedfor Ava.oauth.tokensucceeded forlab-collageand Ava after the second step.
In Audit you also find tenant.authentication.update if you turned TOTP on in step 6, and oauth.authorize with user_signed_in for each password sign-in.
Cleanup
As Ava, remove the authenticator app at
$ISSUER/account/security. Later labs in this track sign Ava in with her password only.If TOTP was off before step 6, set it back to off in Authentication.