From c813083324001552d737c51b274a0a2c19cf2106 Mon Sep 17 00:00:00 2001 From: Sajid Mannikeri Date: Mon, 23 Feb 2026 23:33:48 +0530 Subject: [PATCH 01/35] Added PKCE implementation Signed-off-by: Sajid Mannikeri --- ...ying-party-portal-fapi2-docker-compose.yml | 1 + mock-relying-party-service/app.js | 10 +- mock-relying-party-service/esignetService.js | 15 ++- mock-relying-party-ui/Dockerfile | 3 + mock-relying-party-ui/README.md | 7 +- mock-relying-party-ui/public/env-config.js | 3 +- mock-relying-party-ui/public/locales/ar.json | 3 +- mock-relying-party-ui/public/locales/en.json | 3 +- mock-relying-party-ui/public/locales/hi.json | 3 +- mock-relying-party-ui/public/locales/km.json | 3 +- mock-relying-party-ui/public/locales/kn.json | 3 +- mock-relying-party-ui/public/locales/ta.json | 3 +- mock-relying-party-ui/src/components/Login.js | 3 +- .../src/components/Sidenav.js | 7 +- .../src/constants/clientDetails.js | 2 + .../src/services/relyingPartyService.js | 102 ++++++++++++++++-- 16 files changed, 149 insertions(+), 22 deletions(-) diff --git a/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml b/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml index 608dd72d..9bec57bc 100644 --- a/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml +++ b/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml @@ -45,5 +45,6 @@ services: - PAR_CALLBACK_NAME=get_requestUri - PAR_CALLBACK_TIMEOUT=5000 - DPOP_CALLBACK_NAME=get_dpop_jkt + - CODE_CHALLENGE=get_code_challenge volumes: - ./nginx.conf:/etc/nginx/nginx.conf \ No newline at end of file diff --git a/mock-relying-party-service/app.js b/mock-relying-party-service/app.js index 2f8460ff..c0c8f3d1 100644 --- a/mock-relying-party-service/app.js +++ b/mock-relying-party-service/app.js @@ -39,8 +39,16 @@ app.get("/dpopJKT", rateLimiter, async (req, res) => { app.get("/requestUri/:clientId", async (req, res) => { try { + const { ui_locales, state, dpop_jkt, code_challenge, code_challenge_method } = req.query; res.send( - await post_GetRequestUri(req.params.clientId, req.query.ui_locales, req.query.state, req.query.dpop_jkt), + await post_GetRequestUri( + req.params.clientId, + ui_locales, + state, + dpop_jkt, + code_challenge, + code_challenge_method + ) ); } catch (error) { console.log(error); diff --git a/mock-relying-party-service/esignetService.js b/mock-relying-party-service/esignetService.js index e3f55999..861eda4a 100644 --- a/mock-relying-party-service/esignetService.js +++ b/mock-relying-party-service/esignetService.js @@ -34,8 +34,9 @@ const post_GetToken = async ({ client_id, redirect_uri, grant_type, + code_verifier, }) => { - let request = new URLSearchParams({ + const request = new URLSearchParams({ code: code, client_id: client_id, redirect_uri: redirect_uri, @@ -43,6 +44,12 @@ const post_GetToken = async ({ client_assertion_type: CLIENT_ASSERTION_TYPE, client_assertion: await generateSignedJwt(client_id, ESIGNET_AUD_URL), }); + + // Add code_verifier if provided + if (code_verifier) { + request.append("code_verifier", code_verifier); + } + const endpoint = baseUrl + getTokenEndPoint; const dpopHeaders = await buildDpopHeaders({ clientId: client_id, @@ -85,7 +92,7 @@ const post_GetToken = async ({ * @param {string} clientId clientId * @returns requestUri */ -const post_GetRequestUri = async (clientId, uiLocales, state, dpop_jkt) => { +const post_GetRequestUri = async (clientId, uiLocales, state, dpop_jkt, code_challenge, code_challenge_method) => { const clientAssertion = await generateSignedJwt( clientId, ESIGNET_PAR_AUD_URL @@ -108,6 +115,10 @@ const post_GetRequestUri = async (clientId, uiLocales, state, dpop_jkt) => { if (dpop_jkt) { params.append("dpop_jkt", dpop_jkt); } + if (code_challenge) { + params.append("code_challenge", code_challenge); + params.append("code_challenge_method", code_challenge_method); + } const endpoint = clientDetails.parEndpoint; const dpopHeaders = await buildDpopHeaders({ clientId, diff --git a/mock-relying-party-ui/Dockerfile b/mock-relying-party-ui/Dockerfile index 9d946fa6..3586c5ef 100644 --- a/mock-relying-party-ui/Dockerfile +++ b/mock-relying-party-ui/Dockerfile @@ -22,6 +22,7 @@ ARG fallback_lang ARG par_callback_name ARG par_callback_timeout ARG dpop_callback_name +ARG code_challenge ENV ESIGNET_UI_BASE_URL=$esignet_ui_base_url ENV MOCK_RELYING_PARTY_SERVER_URL=$mock_relying_party_server_url @@ -44,6 +45,7 @@ ENV FALLBACK_LANG=$fallback_lang ENV PAR_CALLBACK_NAME=$par_callback_name ENV PAR_CALLBACK_TIMEOUT=$par_callback_timeout ENV DPOP_CALLBACK_NAME=$dpop_callback_name +ENV CODE_CHALLENGE=$code_challenge # Set the environment variable as a placeholder for PUBLIC_URL ENV PUBLIC_URL=_PUBLIC_URL_ @@ -126,6 +128,7 @@ RUN echo "ESIGNET_UI_BASE_URL=$ESIGNET_UI_BASE_URL" >> ${work_dir}/env.env \ && echo "PAR_CALLBACK_NAME=$PAR_CALLBACK_NAME" >> ${work_dir}/env.env \ && echo "PAR_CALLBACK_TIMEOUT=$PAR_CALLBACK_TIMEOUT" >> ${work_dir}/env.env \ && echo "DPOP_CALLBACK_NAME=$DPOP_CALLBACK_NAME" >> ${work_dir}/env.env \ + && echo "CODE_CHALLENGE=$CODE_CHALLENGE" >> ${work_dir}/env.env \ && chmod +x configure_start.sh \ && chown ${container_user}:${container_user} configure_start.sh \ && chown -R ${container_user}:${container_user} /home/${container_user} ${work_dir} diff --git a/mock-relying-party-ui/README.md b/mock-relying-party-ui/README.md index 749b1235..9a0f7880 100644 --- a/mock-relying-party-ui/README.md +++ b/mock-relying-party-ui/README.md @@ -46,14 +46,17 @@ The application runs on PORT=5000 by default. (Example: par_callback_timeout: 5000) - DPOP_CALLBACK_NAME: **Feature flag** to enable DPoP (Demonstration of Proof-of-Possession) flow Required value: `get_dpop_jkt` (hardcoded function name - not configurable) + - CODE_CHALLENGE: **Feature flag** to enable PKCE (Proof Key for Code Exchange) flow + Required value: `get_code_challenge` (hardcoded function name - not configurable) + When enabled, the PKCE method is automatically fetched from the authorization server's `.well-known/openid-configuration` endpoint - > **Important:** PAR_CALLBACK_NAME and DPOP_CALLBACK_NAME act as feature toggles. The values correspond to hardcoded function names in the codebase and are not configurable. Include these variables to enable the respective flows, or omit them to disable the functionality. + > **Important:** PAR_CALLBACK_NAME, DPOP_CALLBACK_NAME, and CODE_CHALLENGE act as feature toggles. The values correspond to hardcoded function names in the codebase and are not configurable. Include these variables to enable the respective flows, or omit them to disable the functionality. - Build and run Docker for a service: ``` $ docker build -t : . - $ docker run -it -d -p 5000:5000 -e ESIGNET_UI_BASE_URL='http://localhost:3000' -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 -e REDIRECT_URI=http://localhost:5000/userprofile -e CLIENT_ID=healthservices -e ACRS="mosip:esignet:acr:static-code" -e MAX_AGE=21 -e DISPLAY=page -e PROMPT=consent -e GRANT_TYPE=authorization_code -e SIGN_IN_BUTTON_PLUGIN_URL='http://127.0.0.1:5500/dist/iife/index.js' -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' -e PAR_CALLBACK_NAME='get_requestUri' -e DPOP_CALLBACK_NAME='get_dpop_jkt' -e : + $ docker run -it -d -p 5000:5000 -e ESIGNET_UI_BASE_URL='http://localhost:3000' -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 -e REDIRECT_URI=http://localhost:5000/userprofile -e CLIENT_ID=healthservices -e ACRS="mosip:esignet:acr:static-code" -e MAX_AGE=21 -e DISPLAY=page -e PROMPT=consent -e GRANT_TYPE=authorization_code -e SIGN_IN_BUTTON_PLUGIN_URL='http://127.0.0.1:5500/dist/iife/index.js' -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' -e PAR_CALLBACK_NAME='get_requestUri' -e DPOP_CALLBACK_NAME='get_dpop_jkt' -e CODE_CHALLENGE='get_code_challenge' -e : ``` To host the mock relying party UI on a context path: diff --git a/mock-relying-party-ui/public/env-config.js b/mock-relying-party-ui/public/env-config.js index e26e67a6..63092ff5 100644 --- a/mock-relying-party-ui/public/env-config.js +++ b/mock-relying-party-ui/public/env-config.js @@ -21,4 +21,5 @@ window._env_ = { PAR_CALLBACK_NAME: "get_requestUri", PAR_CALLBACK_TIMEOUT: 5000, DPOP_CALLBACK_NAME: "get_dpop_jkt", -}; + CODE_CHALLENGE: "get_code_challenge" + }; diff --git a/mock-relying-party-ui/public/locales/ar.json b/mock-relying-party-ui/public/locales/ar.json index b45a27ce..65a1aee3 100644 --- a/mock-relying-party-ui/public/locales/ar.json +++ b/mock-relying-party-ui/public/locales/ar.json @@ -247,6 +247,7 @@ "request_uri_timeout": "انتهت مهلة الطلب أثناء جلب رابط URI الخاص بالطلب. يُرجى المحاولة لاحقًا.", "web_socket_fail": "لم يتم إكمال عملية التحقق من eKYC. يُرجى المحاولة مرة أخرى.", "dpop_failed": "فشل التحقق من DPoP. يُرجى المحاولة مرة أخرى.", - "invalid_dpop_proof": "لم نتمكن من إتمام المصادقة. يرجى المحاولة مرة أخرى" + "invalid_dpop_proof": "لم نتمكن من إتمام المصادقة. يرجى المحاولة مرة أخرى", + "code_challenge_failed": "فشل في إنشاء تحدي الشفرة. يرجى المحاولة مرة أخرى." } } diff --git a/mock-relying-party-ui/public/locales/en.json b/mock-relying-party-ui/public/locales/en.json index 8db4d525..458e624f 100644 --- a/mock-relying-party-ui/public/locales/en.json +++ b/mock-relying-party-ui/public/locales/en.json @@ -248,6 +248,7 @@ "request_uri_timeout": "Request timed out while fetching Request URI. Please try again later.", "web_socket_fail": "eKYC verification was not completed. Please try again.", "dpop_failed": "DPoP verification failed. Please try again.", - "invalid_dpop_proof": "Authentication could not be completed. Please try again" + "invalid_dpop_proof": "Authentication could not be completed. Please try again", + "code_challenge_failed": "Failed to generate code challenge. Please try again." } } diff --git a/mock-relying-party-ui/public/locales/hi.json b/mock-relying-party-ui/public/locales/hi.json index 1c0cccef..c12396da 100644 --- a/mock-relying-party-ui/public/locales/hi.json +++ b/mock-relying-party-ui/public/locales/hi.json @@ -246,6 +246,7 @@ "request_uri_timeout": "अनुरोध URI प्राप्त करते समय अनुरोध का समय समाप्त हो गया। कृपया बाद में पुनः प्रयास करें।", "web_socket_fail": "eKYC सत्यापन पूरा नहीं हुआ। कृपया पुनः प्रयास करें।", "dpop_failed": "DPoP सत्यापन विफल हुआ. कृपया पुनः प्रयास करें।", - "invalid_dpop_proof": "प्रमाणीकरण पूरा नहीं हो सका। कृपया पुनः प्रयास करें" + "invalid_dpop_proof": "प्रमाणीकरण पूरा नहीं हो सका। कृपया पुनः प्रयास करें", + "code_challenge_failed": "कोड चुनौती उत्पन्न करने में विफल। कृपया पुनः प्रयास करें।" } } diff --git a/mock-relying-party-ui/public/locales/km.json b/mock-relying-party-ui/public/locales/km.json index 5476009e..ce384663 100644 --- a/mock-relying-party-ui/public/locales/km.json +++ b/mock-relying-party-ui/public/locales/km.json @@ -248,6 +248,7 @@ "request_uri_timeout": "សំណើអស់ពេលពេលទៅយកសំណើ URI ។ សូមព្យាយាមម្តងទៀតនៅពេលក្រោយ។", "web_socket_fail": "ការផ្ទៀងផ្ទាត់ eKYC មិនត្រូវបានបញ្ចប់ទេ។ សូមព្យាយាមម្តងទៀត។", "dpop_failed": "ការផ្ទៀងផ្ទាត់ DPoP បានបរាជ័យ។ សូមព្យាយាមម្តងទៀត។", - "invalid_dpop_proof": "ការផ្ទៀងផ្ទាត់មិនអាចបញ្ចប់បាន។ សូមព្យាយាមម្ដងទៀត" + "invalid_dpop_proof": "ការផ្ទៀងផ្ទាត់មិនអាចបញ្ចប់បាន។ សូមព្យាយាមម្ដងទៀត", + "code_challenge_failed": "ការបង្កើតការប្រឈមកូដបានបរាជ័យ។ សូមព្យាយាមម្ដងទៀត។" } } diff --git a/mock-relying-party-ui/public/locales/kn.json b/mock-relying-party-ui/public/locales/kn.json index ff4c8385..90c949eb 100644 --- a/mock-relying-party-ui/public/locales/kn.json +++ b/mock-relying-party-ui/public/locales/kn.json @@ -246,6 +246,7 @@ "request_uri_timeout": "ವಿನಂತಿ URI ಅನ್ನು ಪಡೆಯುವಾಗ ವಿನಂತಿಯ ಸಮಯ ಮೀರಿದೆ. ದಯವಿಟ್ಟು ನಂತರ ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", "web_socket_fail": "eKYC ಪರಿಶೀಲನೆ ಪೂರ್ಣಗೊಂಡಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", "dpop_failed": "DPoP ಪರಿಶೀಲನೆ ವಿಫಲವಾಗಿದೆ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", - "invalid_dpop_proof": "ಪ್ರಾಮಾಣೀಕರಣವನ್ನು ಪೂರ್ಣಗೊಳಿಸಲಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೊಮ್ಮೆ ಪ್ರಯತ್ನಿಸಿ" + "invalid_dpop_proof": "ಪ್ರಾಮಾಣೀಕರಣವನ್ನು ಪೂರ್ಣಗೊಳಿಸಲಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೊಮ್ಮೆ ಪ್ರಯತ್ನಿಸಿ", + "code_challenge_failed": "ಕೋಡ್ ಚಾಲೆಂಜ್ ರಚಿಸಲು ವಿಫಲವಾಗಿದೆ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ." } } diff --git a/mock-relying-party-ui/public/locales/ta.json b/mock-relying-party-ui/public/locales/ta.json index 3108a28e..96102bb2 100644 --- a/mock-relying-party-ui/public/locales/ta.json +++ b/mock-relying-party-ui/public/locales/ta.json @@ -246,6 +246,7 @@ "request_uri_timeout": "கோரிக்கை URI-ஐப் பெறும்போது கோரிக்கை நேரம் முடிந்தது. தயவுசெய்து பின்னர் மீண்டும் முயற்சிக்கவும்.", "web_socket_fail": "eKYC சரிபார்ப்பு முடிக்கப்படவில்லை. மீண்டும் முயற்சிக்கவும்.", "dpop_failed": "DPoP சரிபார்ப்பு தோல்வியடைந்தது. மீண்டும் முயற்சிக்கவும்.", - "invalid_dpop_proof": "அங்கீகாரம் முடிக்க முடியவில்லை. மீண்டும் முயற்சிக்கவும்" + "invalid_dpop_proof": "அங்கீகாரம் முடிக்க முடியவில்லை. மீண்டும் முயற்சிக்கவும்", + "code_challenge_failed": "கோட் சவால் உருவாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும்." } } diff --git a/mock-relying-party-ui/src/components/Login.js b/mock-relying-party-ui/src/components/Login.js index 6110a9f2..2c58a8af 100644 --- a/mock-relying-party-ui/src/components/Login.js +++ b/mock-relying-party-ui/src/components/Login.js @@ -51,7 +51,8 @@ export default function Login({ i18nKeyPrefix = "login" }) { claims: JSON.parse(decodeURIComponent(clientDetails.userProfileClaims)), par_callback: relyingPartyService[clientDetails.par_callback_name], par_callback_timeout: clientDetails.par_callback_timeout, - dpop_callback: relyingPartyService[clientDetails.dpop_callback_name] + dpop_callback: relyingPartyService[clientDetails.dpop_callback_name], + code_challenge: relyingPartyService[clientDetails.code_challenge], }; window.SignInWithEsignetButton?.init({ diff --git a/mock-relying-party-ui/src/components/Sidenav.js b/mock-relying-party-ui/src/components/Sidenav.js index 9b4a0f16..879a2e8a 100644 --- a/mock-relying-party-ui/src/components/Sidenav.js +++ b/mock-relying-party-ui/src/components/Sidenav.js @@ -1,5 +1,5 @@ import { useTranslation } from "react-i18next"; -import React, { useState, useEffect } from "react"; +import React, { useState, useEffect, useRef } from "react"; import { Link, useNavigate, useSearchParams } from "react-router-dom"; import clientDetails from "../constants/clientDetails"; import { LoadingStates as states } from "../constants/states"; @@ -29,6 +29,7 @@ export default function Sidenav({ const [emailAddress, setEmailAddress] = useState(null); const [showMenu, setShowMenu] = useState(false); const navigate = useNavigate(); + const hasFetchedRef = useRef(false); function getAllKeys(input) { if (Array.isArray(input)) { @@ -80,6 +81,10 @@ export default function Sidenav({ useEffect(() => { const getSearchParams = async () => { + // Prevent duplicate API calls during React.StrictMode double mounting + if (hasFetchedRef.current) return; + hasFetchedRef.current = true; + let authCode = searchParams.get("code"); let errorCode = searchParams.get("error"); let error_desc = searchParams.get("error_description"); diff --git a/mock-relying-party-ui/src/constants/clientDetails.js b/mock-relying-party-ui/src/constants/clientDetails.js index a5f10dbe..151736b1 100644 --- a/mock-relying-party-ui/src/constants/clientDetails.js +++ b/mock-relying-party-ui/src/constants/clientDetails.js @@ -59,6 +59,7 @@ const par_callback_timeout = checkEmptyNullValue( 5000 ); const dpop_callback_name = window._env_.DPOP_CALLBACK_NAME; +const code_challenge = window._env_.CODE_CHALLENGE; const claims = { userinfo: { given_name: { @@ -108,6 +109,7 @@ const clientDetails = { par_callback_name: par_callback_name, par_callback_timeout: par_callback_timeout, dpop_callback_name: dpop_callback_name, + code_challenge: code_challenge, }; export default clientDetails; diff --git a/mock-relying-party-ui/src/services/relyingPartyService.js b/mock-relying-party-ui/src/services/relyingPartyService.js index 9bb31b04..32f78ab8 100644 --- a/mock-relying-party-ui/src/services/relyingPartyService.js +++ b/mock-relying-party-ui/src/services/relyingPartyService.js @@ -6,6 +6,76 @@ import { GET_DPOP_JKT, } from "../constants/routes"; +/** + * Base64URL encoding utility for PKCE + * @param {Uint8Array} buffer - Byte array to encode + * @returns {string} - Base64URL encoded string + */ +const base64UrlEncode = (buffer) => { + let binary = ''; + for (let i = 0; i < buffer.byteLength; i++) { + binary += String.fromCharCode(buffer[i]); + } + return btoa(binary).replace(/\+/g, "-").replace(/\//g, "_").replace(/=+$/, ""); +}; + +/** + * Generates a cryptographically secure code verifier + * @returns {string} - Base64URL encoded code verifier + */ +const generateCodeVerifier = () => { + return base64UrlEncode(crypto.getRandomValues(new Uint8Array(32))); +}; + +/** + * Fetches supported PKCE methods from auth server's .well-known + * @returns {Promise} - Supported code challenge method (defaults to 'S256') + */ +const get_code_challenge_method = async () => { + try { + const baseUrl = window._env_.ESIGNET_UI_BASE_URL; + const response = await axios.get(`${baseUrl}/.well-known/openid-configuration`); + const methods = response.data?.code_challenge_methods_supported; + return methods && methods.length > 0 ? methods[0] : 'S256'; + } catch (error) { + console.warn('Failed to fetch PKCE methods, defaulting to S256:', error); + return 'S256'; + } +}; + +/** + * Generates PKCE code challenge and stores verifier in sessionStorage + * @param {string} clientId - Registered client ID + * @param {string} state - Unique state value + * @returns {Promise} - Object with code_challenge and code_challenge_method + */ +const get_code_challenge = async (clientId, state) => { + const method = await get_code_challenge_method(); + + if (!method) { + console.warn('PKCE disabled: no supported method found'); + return null; + } + + const codeVerifier = generateCodeVerifier(); + let codeChallenge; + + if (method === 'plain') { + codeChallenge = codeVerifier; + } else { + const encoder = new TextEncoder(); + const data = encoder.encode(codeVerifier); + const hashBuffer = await crypto.subtle.digest('SHA-256', data); + codeChallenge = base64UrlEncode(new Uint8Array(hashBuffer)); + } + + sessionStorage.setItem(`pkce_${clientId}_${state}`, codeVerifier); + return { + code_challenge: codeChallenge, + code_challenge_method: method + }; +}; + /** * Fetches the DPoP JWK thumbprint (JKT) from the relying party server. * @param {string} clientId - Registered client ID @@ -35,14 +105,19 @@ const get_dpop_jkt = async (clientId, state) => { * @param {string} clientId - Registered client ID * @param {string} state - Unique state value for the authorization request * @param {string} ui_locales - Locale/language preference + * @param {string} dpop_jkt - DPoP JWK thumbprint (optional) + * @param {string} code_challenge - PKCE code challenge (optional) + * @param {string} code_challenge_method - PKCE method (optional) * @returns {Promise} - Request URI (URN format) */ -const get_requestUri = async (clientId, state, ui_locales, dpop_jkt) => { +const get_requestUri = async (clientId, state, ui_locales, dpop_jkt, code_challenge, code_challenge_method) => { try { const params = new URLSearchParams({ state, ui_locales, - dpop_jkt + dpop_jkt, + code_challenge, + code_challenge_method }); const endpoint = `${BASE_URL}${GET_REQUEST_URI}/${clientId}?${params.toString()}`; const response = await axios.get(endpoint, { @@ -61,6 +136,7 @@ const get_requestUri = async (clientId, state, ui_locales, dpop_jkt) => { * Typically called after receiving the auth code from the authorization server. * * @param {string} code - Authorization code received after user consent + * @param {string} state - State value from authorization request * @param {string} client_id - Registered client ID * @param {string} redirect_uri - Redirect URI used during authorization * @param {string} grant_type - OAuth 2.0 grant type (usually "authorization_code") @@ -73,13 +149,21 @@ const post_fetchUserInfo = async ( redirect_uri, grant_type ) => { - let request = { - code: code, - state: state, - client_id: client_id, - redirect_uri: redirect_uri, - grant_type: grant_type, + const request = { + code, + state, + client_id, + redirect_uri, + grant_type, }; + + // Retrieve and include code_verifier if it exists in sessionStorage (PKCE enabled) + const codeVerifier = sessionStorage.getItem(`pkce_${client_id}_${state}`); + if (codeVerifier) { + request.code_verifier = codeVerifier; + sessionStorage.removeItem(`pkce_${client_id}_${state}`); + } + const endpoint = BASE_URL + GET_USER_INFO; const response = await axios.post(endpoint, request, { headers: { @@ -187,6 +271,8 @@ const relyingPartyService = { get_nextAppointment, get_requestUri, get_dpop_jkt, + get_code_challenge, + get_code_challenge_method }; export default relyingPartyService; From 90bcd9f0216c424a2dea08397dd5ac499f3cc818 Mon Sep 17 00:00:00 2001 From: Sajid Mannikeri Date: Tue, 24 Feb 2026 12:58:49 +0530 Subject: [PATCH 02/35] fixed coderabbit comment Signed-off-by: Sajid Mannikeri --- mock-relying-party-service/esignetService.js | 2 +- mock-relying-party-ui/README.md | 2 +- .../src/services/relyingPartyService.js | 13 ++++++------- 3 files changed, 8 insertions(+), 9 deletions(-) diff --git a/mock-relying-party-service/esignetService.js b/mock-relying-party-service/esignetService.js index 861eda4a..39e377e9 100644 --- a/mock-relying-party-service/esignetService.js +++ b/mock-relying-party-service/esignetService.js @@ -115,7 +115,7 @@ const post_GetRequestUri = async (clientId, uiLocales, state, dpop_jkt, code_cha if (dpop_jkt) { params.append("dpop_jkt", dpop_jkt); } - if (code_challenge) { + if (code_challenge && code_challenge_method) { params.append("code_challenge", code_challenge); params.append("code_challenge_method", code_challenge_method); } diff --git a/mock-relying-party-ui/README.md b/mock-relying-party-ui/README.md index 9a0f7880..4558bdd7 100644 --- a/mock-relying-party-ui/README.md +++ b/mock-relying-party-ui/README.md @@ -56,7 +56,7 @@ The application runs on PORT=5000 by default. ``` $ docker build -t : . - $ docker run -it -d -p 5000:5000 -e ESIGNET_UI_BASE_URL='http://localhost:3000' -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 -e REDIRECT_URI=http://localhost:5000/userprofile -e CLIENT_ID=healthservices -e ACRS="mosip:esignet:acr:static-code" -e MAX_AGE=21 -e DISPLAY=page -e PROMPT=consent -e GRANT_TYPE=authorization_code -e SIGN_IN_BUTTON_PLUGIN_URL='http://127.0.0.1:5500/dist/iife/index.js' -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' -e PAR_CALLBACK_NAME='get_requestUri' -e DPOP_CALLBACK_NAME='get_dpop_jkt' -e CODE_CHALLENGE='get_code_challenge' -e : + $ docker run -it -d -p 5000:5000 -e ESIGNET_UI_BASE_URL='http://localhost:3000' -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 -e REDIRECT_URI=http://localhost:5000/userprofile -e CLIENT_ID=healthservices -e ACRS="mosip:esignet:acr:static-code" -e MAX_AGE=21 -e DISPLAY=page -e PROMPT=consent -e GRANT_TYPE=authorization_code -e SIGN_IN_BUTTON_PLUGIN_URL='http://127.0.0.1:5500/dist/iife/index.js' -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' -e PAR_CALLBACK_NAME='get_requestUri' -e DPOP_CALLBACK_NAME='get_dpop_jkt' -e CODE_CHALLENGE='get_code_challenge' : ``` To host the mock relying party UI on a context path: diff --git a/mock-relying-party-ui/src/services/relyingPartyService.js b/mock-relying-party-ui/src/services/relyingPartyService.js index 32f78ab8..53200eb4 100644 --- a/mock-relying-party-ui/src/services/relyingPartyService.js +++ b/mock-relying-party-ui/src/services/relyingPartyService.js @@ -112,13 +112,12 @@ const get_dpop_jkt = async (clientId, state) => { */ const get_requestUri = async (clientId, state, ui_locales, dpop_jkt, code_challenge, code_challenge_method) => { try { - const params = new URLSearchParams({ - state, - ui_locales, - dpop_jkt, - code_challenge, - code_challenge_method - }); + const params = new URLSearchParams({ state, ui_locales }); + if (dpop_jkt) params.append("dpop_jkt", dpop_jkt); + if (code_challenge && code_challenge_method) { + params.append("code_challenge", code_challenge); + params.append("code_challenge_method", code_challenge_method); + } const endpoint = `${BASE_URL}${GET_REQUEST_URI}/${clientId}?${params.toString()}`; const response = await axios.get(endpoint, { headers: { From 5dd6327c2726b3134c4138a026e3598ec0c00101 Mon Sep 17 00:00:00 2001 From: ase-101 Date: Wed, 25 Feb 2026 20:15:56 +0530 Subject: [PATCH 03/35] Corrected the logic to full dynamic identity schema Signed-off-by: ase-101 --- .../controller/IdentityController.java | 10 +- .../identitysystem/dto/CreateIdentity.java | 17 +++- .../identitysystem/dto/UpdateIdentity.java | 17 +++- .../service/IdentityService.java | 4 +- .../impl/AuthenticationServiceImpl.java | 15 ++- .../service/impl/IdentityServiceImpl.java | 23 +++-- .../validator/IdentitySchemaValidator.java | 7 +- .../controller/IdentityControllerTest.java | 99 ++++++++++--------- .../impl/AuthenticationServiceImplTest.java | 8 +- .../service/impl/IdentityServiceTest.java | 14 +-- 10 files changed, 121 insertions(+), 93 deletions(-) diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java index 9705b15f..c06006d5 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java @@ -40,7 +40,7 @@ public class IdentityController { @PostMapping(value = "identity", consumes = { MediaType.APPLICATION_JSON_VALUE }, produces = { MediaType.APPLICATION_JSON_VALUE }) public ResponseWrapper createIdentity - (@RequestBody @Valid RequestWrapper requestWrapper) throws MockIdentityException { + (@RequestBody @Valid CreateIdentity requestWrapper) throws MockIdentityException { ResponseWrapper response = new ResponseWrapper(); IdentityStatus identityStatus = new IdentityStatus(); @@ -54,7 +54,7 @@ public class IdentityController { @PutMapping(value = "identity", consumes = { MediaType.APPLICATION_JSON_VALUE }, produces = { MediaType.APPLICATION_JSON_VALUE }) public ResponseWrapper updateIdentity - (@RequestBody @Valid RequestWrapper requestWrapper) throws MockIdentityException { + (@RequestBody @Valid UpdateIdentity requestWrapper) throws MockIdentityException { ResponseWrapper response = new ResponseWrapper(); IdentityStatus identityStatus = new IdentityStatus(); @@ -66,10 +66,10 @@ public class IdentityController { } @GetMapping(value = "identity/{individualId}") - public ResponseWrapper getIdentity(@PathVariable(value = "individualId") String individualId) + public ResponseWrapper getIdentity(@PathVariable(value = "individualId") String individualId) throws MockIdentityException { - ResponseWrapper response = new ResponseWrapper<>(); - response.setResponse(identityService.getIdentity(individualId)); + ResponseWrapper response = new ResponseWrapper<>(); + response.setResponse(identityService.getIdentityV2(individualId)); response.setResponseTime(HelperUtil.getCurrentUTCDateTime()); return response; } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/CreateIdentity.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/CreateIdentity.java index 9c91b8db..1c57030e 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/CreateIdentity.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/CreateIdentity.java @@ -5,8 +5,21 @@ */ package io.mosip.esignet.mock.identitysystem.dto; +import com.fasterxml.jackson.databind.JsonNode; import io.mosip.esignet.mock.identitysystem.validator.IdentitySchema; +import io.mosip.esignet.mock.identitysystem.validator.RequestTime; +import jakarta.validation.constraints.NotNull; +import lombok.Data; -@IdentitySchema(action = "CREATE") -public class CreateIdentity extends IdentityData { +import static io.mosip.esignet.mock.identitysystem.util.ErrorConstants.INVALID_REQUEST; + +@Data +public class CreateIdentity { + + @RequestTime + private String requestTime; + + @NotNull(message = INVALID_REQUEST) + @IdentitySchema(action = "CREATE") + private JsonNode request; } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/UpdateIdentity.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/UpdateIdentity.java index f891bc95..c1e88df6 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/UpdateIdentity.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/dto/UpdateIdentity.java @@ -5,8 +5,21 @@ */ package io.mosip.esignet.mock.identitysystem.dto; +import com.fasterxml.jackson.databind.JsonNode; import io.mosip.esignet.mock.identitysystem.validator.IdentitySchema; +import io.mosip.esignet.mock.identitysystem.validator.RequestTime; +import jakarta.validation.constraints.NotNull; +import lombok.Data; -@IdentitySchema(action = "UPDATE") -public class UpdateIdentity extends IdentityData { +import static io.mosip.esignet.mock.identitysystem.util.ErrorConstants.INVALID_REQUEST; + +@Data +public class UpdateIdentity { + + @RequestTime + private String requestTime; + + @NotNull(message = INVALID_REQUEST) + @IdentitySchema(action = "UPDATE") + private JsonNode request; } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java index 54ae0b61..0bec9073 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java @@ -14,9 +14,9 @@ public interface IdentityService { - public void addIdentity(IdentityData mockAuthDataRequest) throws MockIdentityException; + public void addIdentity(JsonNode mockAuthDataRequest) throws MockIdentityException; - public void updateIdentity(IdentityData mockAuthDataRequest) throws MockIdentityException; + public void updateIdentity(JsonNode mockAuthDataRequest) throws MockIdentityException; public IdentityData getIdentity(String individualId) throws MockIdentityException; diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java index 2802d71b..b01584e6 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java @@ -139,11 +139,8 @@ public KycAuthResponseDto kycAuth(String relyingPartyId, String clientId, KycAut KycAuthResponseDto kycAuthResponseDto = new KycAuthResponseDto(); kycAuthResponseDto.setAuthStatus(authStatus); kycAuthResponseDto.setKycToken(kycAuth.getKycToken()); - if (psutField.equals("psut")) { - kycAuthResponseDto.setPartnerSpecificUserToken(kycAuth.getPartnerSpecificUserToken()); - } else { - kycAuthResponseDto.setPartnerSpecificUserToken(HelperUtil.getIdentityDataValue(identityData, psutField, defaultLanguage)); - } + kycAuthResponseDto.setPartnerSpecificUserToken(kycAuth.getPartnerSpecificUserToken()); + if(kycAuthDto.isClaimMetadataRequired()) { kycAuthResponseDto.setClaimMetadata(getVerifiedClaimMetadata(kycAuthDto.getIndividualId(), identityData)); } @@ -415,8 +412,8 @@ private KycAuth saveKycAuthTransaction(String transactionId, String relyingParty String kycToken = HelperUtil.generateB64EncodedHash(ALGO_SHA3_256, UUID.randomUUID().toString()); String psut; try { - psut = HelperUtil.generateB64EncodedHash(ALGO_SHA3_256, - PSUT_FORMAT.formatted(individualId, relyingPartyId)); + psut = psutField.equals("psut") ? HelperUtil.generateB64EncodedHash(ALGO_SHA3_256, + PSUT_FORMAT.formatted(individualId, relyingPartyId)) : individualId; } catch (Exception e) { log.error("Failed to generate PSUT", e); throw new MockIdentityException("mock-ida-004"); @@ -473,7 +470,9 @@ private ObjectNode buildKycData(String individualId, JsonNode identityData, Map< ObjectNode objectNode = buildVerifiedClaimsObject(verifiedClaimsNode, locales, identityData, claimsByVerificationMetadataResult.get(), kyc); if(!objectNode.isEmpty()) { - kyc.set("verified_claims", objectNode); + List verifiedList = new ArrayList<>(); + verifiedList.add(objectNode); + kyc.set("verified_claims", objectMapper.valueToTree(verifiedList)); } } } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java index 665cb5be..46f849d6 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java @@ -15,6 +15,7 @@ import java.util.Optional; import com.fasterxml.jackson.databind.JsonNode; +import com.fasterxml.jackson.databind.node.ObjectNode; import io.mosip.esignet.mock.identitysystem.dto.VerifiedClaimRequestDto; import io.mosip.esignet.mock.identitysystem.entity.VerifiedClaim; import io.mosip.esignet.mock.identitysystem.repository.VerifiedClaimRepository; @@ -66,14 +67,15 @@ public class IdentityServiceImpl implements IdentityService { private String schemaUrl; @Override - public void addIdentity(IdentityData identityData) throws MockIdentityException { - if (identityRepository.findById(identityData.getIndividualId()).isPresent()) { + public void addIdentity(JsonNode identityData) throws MockIdentityException { + String individualId = identityData.get("individualId").asText(); + if (identityRepository.findById(individualId).isPresent()) { throw new MockIdentityException(ErrorConstants.DUPLICATE_INDIVIDUAL_ID); } MockIdentity mockIdentity = new MockIdentity(); try { - if(identityData.getPassword() != null) { - identityData.setPassword(HMACUtils2.digestAsPlainText(identityData.getPassword().getBytes())); + if(identityData.hasNonNull("password")) { + ((ObjectNode)identityData).put("password", HMACUtils2.digestAsPlainText(identityData.get("password").asText().getBytes())); } mockIdentity.setIdentityJson(objectMapper.writeValueAsString(identityData)); } catch (JsonProcessingException e) { @@ -81,20 +83,21 @@ public void addIdentity(IdentityData identityData) throws MockIdentityException } catch (NoSuchAlgorithmException e) { throw new MockIdentityException(ErrorConstants.UNKNOWN_ERROR); } - mockIdentity.setIndividualId(identityData.getIndividualId()); + mockIdentity.setIndividualId(individualId); identityRepository.save(mockIdentity); } @Override - public void updateIdentity(IdentityData identityData) throws MockIdentityException { - Optional result = identityRepository.findById(identityData.getIndividualId()); + public void updateIdentity(JsonNode identityData) throws MockIdentityException { + String individualId = identityData.get("individualId").asText(); + Optional result = identityRepository.findById(individualId); if (result.isEmpty()) { throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); } MockIdentity mockIdentity = result.get(); try { - if(identityData.getPassword() != null) { - identityData.setPassword(HMACUtils2.digestAsPlainText(identityData.getPassword().getBytes())); + if(identityData.hasNonNull("password")) { + ((ObjectNode)identityData).put("password", HMACUtils2.digestAsPlainText(identityData.get("password").asText().getBytes())); } String requestedUpdateJsonString = objectMapper.writeValueAsString(identityData); Map requestedUpdate = objectMapper.readValue(requestedUpdateJsonString, Map.class); @@ -108,7 +111,7 @@ public void updateIdentity(IdentityData identityData) throws MockIdentityExcepti } catch (NoSuchAlgorithmException e) { throw new MockIdentityException(ErrorConstants.UNKNOWN_ERROR); } - mockIdentity.setIndividualId(identityData.getIndividualId()); + mockIdentity.setIndividualId(individualId); identityRepository.save(mockIdentity); } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java index 631bb8d9..b7f1859a 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java @@ -54,12 +54,7 @@ public void initSchema() { @Override public boolean isValid(Object object, ConstraintValidatorContext context) { - - if (!(object instanceof IdentityData)) { - return false; - } - IdentityData identityData=(IdentityData) object; - JsonNode identityJsonNode = objectMapper.valueToTree(identityData); + JsonNode identityJsonNode = (JsonNode)object; Set validationErrors = validateIdentityData(identityJsonNode); // Handle validation errors diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java index a5f211cc..f4cd4f5d 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java @@ -7,6 +7,7 @@ import com.fasterxml.jackson.databind.JsonNode; import com.fasterxml.jackson.databind.ObjectMapper; +import com.fasterxml.jackson.databind.node.NullNode; import com.fasterxml.jackson.databind.node.ObjectNode; import io.mosip.esignet.mock.identitysystem.dto.IdentityData; import io.mosip.esignet.mock.identitysystem.dto.LanguageValue; @@ -48,13 +49,13 @@ public class IdentityControllerTest { ObjectMapper objectMapper = new ObjectMapper(); - IdentityData identityRequest; + ObjectNode identityRequest; @BeforeEach public void init() { - identityRequest = new IdentityData(); - identityRequest.setIndividualId("826741183"); - identityRequest.setEmail("test@gmail.com"); + IdentityData identityData = new IdentityData(); + identityData.setIndividualId("826741183"); + identityData.setEmail("test@gmail.com"); List preferredNameList =new ArrayList<>(); LanguageValue engLangValue= new LanguageValue(); @@ -65,49 +66,51 @@ public void init() { arabicLangValue.setValue("سيدارت ك منصور"); preferredNameList.add(engLangValue); preferredNameList.add(arabicLangValue); - identityRequest.setFullName(preferredNameList); - identityRequest.setPreferredUsername(preferredNameList); - identityRequest.setFamilyName(preferredNameList); - identityRequest.setGivenName(preferredNameList); - identityRequest.setPreferredUsername(preferredNameList); - identityRequest.setNickName(preferredNameList); - identityRequest.setPreferredUsername(preferredNameList); - identityRequest.setMiddleName(preferredNameList); + identityData.setFullName(preferredNameList); + identityData.setPreferredUsername(preferredNameList); + identityData.setFamilyName(preferredNameList); + identityData.setGivenName(preferredNameList); + identityData.setPreferredUsername(preferredNameList); + identityData.setNickName(preferredNameList); + identityData.setPreferredUsername(preferredNameList); + identityData.setMiddleName(preferredNameList); LanguageValue mockLang = new LanguageValue(); mockLang.setLanguage("eng"); mockLang.setValue("mock"); - identityRequest.setGender(Arrays.asList(mockLang)); - identityRequest.setStreetAddress(Arrays.asList(mockLang)); - identityRequest.setLocality(Arrays.asList(mockLang)); - identityRequest.setRegion(Arrays.asList(mockLang)); + identityData.setGender(Arrays.asList(mockLang)); + identityData.setStreetAddress(Arrays.asList(mockLang)); + identityData.setLocality(Arrays.asList(mockLang)); + identityData.setRegion(Arrays.asList(mockLang)); LanguageValue langValue = new LanguageValue(); langValue.setLanguage("eng"); langValue.setValue("ind"); - identityRequest.setCountry(Arrays.asList(langValue)); - - identityRequest.setDateOfBirth("20021990"); - identityRequest.setEncodedPhoto("testencodedphoto"); - identityRequest.setGender(Arrays.asList(langValue)); - identityRequest.setLocality(Arrays.asList(langValue)); - identityRequest.setPostalCode("12011"); - identityRequest.setPin("1289001"); - identityRequest.setRegion(Arrays.asList(langValue)); - identityRequest.setFullName(Arrays.asList(langValue)); - identityRequest.setGivenName(Arrays.asList(langValue)); - identityRequest.setFamilyName(Arrays.asList(langValue)); - identityRequest.setStreetAddress(Arrays.asList(langValue)); - identityRequest.setPhone("9090909090"); - identityRequest.setPreferredLang("eng"); - identityRequest.setZoneInfo("local"); - identityRequest.setLocale("eng"); - identityRequest.setPassword("mock-password"); + identityData.setCountry(Arrays.asList(langValue)); + + identityData.setDateOfBirth("20021990"); + identityData.setEncodedPhoto("testencodedphoto"); + identityData.setGender(Arrays.asList(langValue)); + identityData.setLocality(Arrays.asList(langValue)); + identityData.setPostalCode("12011"); + identityData.setPin("1289001"); + identityData.setRegion(Arrays.asList(langValue)); + identityData.setFullName(Arrays.asList(langValue)); + identityData.setGivenName(Arrays.asList(langValue)); + identityData.setFamilyName(Arrays.asList(langValue)); + identityData.setStreetAddress(Arrays.asList(langValue)); + identityData.setPhone("9090909090"); + identityData.setPreferredLang("eng"); + identityData.setZoneInfo("local"); + identityData.setLocale("eng"); + identityData.setPassword("mock-password"); + + identityRequest = objectMapper.valueToTree(identityData); } @Test public void createIdentity_withValidIdentity_returnSuccessResponse() throws Exception { - RequestWrapper requestWrapper = new RequestWrapper(); + RequestWrapper requestWrapper = new RequestWrapper(); ZonedDateTime requestTime = ZonedDateTime.now(ZoneOffset.UTC); requestWrapper.setRequestTime(requestTime.format(DateTimeFormatter.ofPattern(UTC_DATETIME_PATTERN))); requestWrapper.setRequest(identityRequest); @@ -121,10 +124,10 @@ public void createIdentity_withValidIdentity_returnSuccessResponse() throws Exce @Test public void createIdentity_withInvalidIdentity_returnErrorResponse() throws Exception { - RequestWrapper requestWrapper = new RequestWrapper(); + RequestWrapper requestWrapper = new RequestWrapper(); ZonedDateTime requestTime = ZonedDateTime.now(ZoneOffset.UTC); requestWrapper.setRequestTime(requestTime.format(DateTimeFormatter.ofPattern(UTC_DATETIME_PATTERN))); - identityRequest.setIndividualId(null); + identityRequest.put("individualId", NullNode.getInstance()); requestWrapper.setRequest(identityRequest); Mockito.doNothing().when(identityService).addIdentity(identityRequest); @@ -137,11 +140,11 @@ public void createIdentity_withInvalidIdentity_returnErrorResponse() throws Exce @Test public void createIdentity_withInvalidNameAndLocale_returnErrorResponse() throws Exception { - RequestWrapper requestWrapper = new RequestWrapper(); + RequestWrapper requestWrapper = new RequestWrapper<>(); ZonedDateTime requestTime = ZonedDateTime.now(ZoneOffset.UTC); requestWrapper.setRequestTime(requestTime.format(DateTimeFormatter.ofPattern(UTC_DATETIME_PATTERN))); - identityRequest.setFullName(null); - identityRequest.setLocale(null); + identityRequest.put("fullName", NullNode.getInstance()); + identityRequest.put("locale", NullNode.getInstance()); requestWrapper.setRequest(identityRequest); Mockito.doNothing().when(identityService).addIdentity(identityRequest); @@ -153,7 +156,7 @@ public void createIdentity_withInvalidNameAndLocale_returnErrorResponse() throws @Test public void createIdentity_withInvalidFullName_returnErrorResponse() throws Exception { - RequestWrapper requestWrapper = new RequestWrapper(); + RequestWrapper requestWrapper = new RequestWrapper<>(); ZonedDateTime requestTime = ZonedDateTime.now(ZoneOffset.UTC); requestWrapper.setRequestTime(requestTime.format(DateTimeFormatter.ofPattern(UTC_DATETIME_PATTERN))); @@ -166,7 +169,7 @@ public void createIdentity_withInvalidFullName_returnErrorResponse() throws Exce arabicLangValue.setValue("سيدارت ك منصور"); nameList.add(engLangValue); nameList.add(arabicLangValue); - identityRequest.setFullName(nameList); + identityRequest.put("fullName", objectMapper.valueToTree(nameList)); requestWrapper.setRequest(identityRequest); Mockito.doNothing().when(identityService).addIdentity(identityRequest); @@ -178,8 +181,8 @@ public void createIdentity_withInvalidFullName_returnErrorResponse() throws Exce @Test public void getIdentity_withValidId_returnSuccessResponse() throws Exception { - identityRequest.setIndividualId("123456789"); - Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityRequest); + identityRequest.put("individualId", "123456789"); + Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityRequest); mockMvc.perform(get("/identity/{individualId}", "123456789") .contentType(MediaType.APPLICATION_JSON)).andExpect(status().isOk()) @@ -206,7 +209,7 @@ public void addVerifiedClaims_withValidDetails_returnSuccessResponse() throws Ex requestWrapper.setRequest(verifiedClaimRequestDto); Mockito.doNothing().when(identityService).addVerifiedClaim(verifiedClaimRequestDto); - Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityRequest); + Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityRequest); mockMvc.perform(post("/identity/add-verified-claim").content(objectMapper.writeValueAsString(requestWrapper)) .contentType(MediaType.APPLICATION_JSON)).andExpect(status().isOk()) @@ -237,7 +240,7 @@ public void addVerifiedClaim_withInvalidClaim_returnErrorResponse() throws Exce @Test public void updateIdentity_withValidIdentity_thenPass() throws Exception { - RequestWrapper requestWrapper = new RequestWrapper(); + RequestWrapper requestWrapper = new RequestWrapper<>(); ZonedDateTime requestTime = ZonedDateTime.now(ZoneOffset.UTC); requestWrapper.setRequestTime(requestTime.format(DateTimeFormatter.ofPattern(UTC_DATETIME_PATTERN))); requestWrapper.setRequest(identityRequest); @@ -251,10 +254,10 @@ public void updateIdentity_withValidIdentity_thenPass() throws Exception { @Test public void updateIdentity_withInValidIdentity_thenFail() throws Exception { - RequestWrapper requestWrapper = new RequestWrapper(); + RequestWrapper requestWrapper = new RequestWrapper<>(); ZonedDateTime requestTime = ZonedDateTime.now(ZoneOffset.UTC); requestWrapper.setRequestTime(requestTime.format(DateTimeFormatter.ofPattern(UTC_DATETIME_PATTERN))); - identityRequest.setFullName(null); + identityRequest.put("fullName", NullNode.getInstance()); requestWrapper.setRequest(identityRequest); Mockito.doNothing().when(identityService).updateIdentity(identityRequest); diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java index 18d22899..98390277 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java @@ -20,6 +20,7 @@ import io.mosip.esignet.mock.identitysystem.repository.VerifiedClaimRepository; import io.mosip.esignet.mock.identitysystem.service.IdentityService; import io.mosip.esignet.mock.identitysystem.util.CacheUtilService; +import io.mosip.esignet.mock.identitysystem.util.HelperUtil; import io.mosip.kernel.signature.dto.JWTSignatureResponseDto; import io.mosip.kernel.signature.service.SignatureService; import org.junit.jupiter.api.Assertions; @@ -36,6 +37,7 @@ import java.time.LocalDateTime; import java.util.*; +import static io.mosip.esignet.mock.identitysystem.util.HelperUtil.ALGO_SHA3_256; import static org.mockito.ArgumentMatchers.eq; import static org.mockito.Mockito.when; @@ -328,10 +330,10 @@ public void kycAuth_withValidKbiChallengeCustomPSUTfield_thenPass() { identityData.setFullName(List.of(languageValue)); Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); - Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); + Mockito.when(authRepository.save(Mockito.any())).thenAnswer(invocation -> invocation.getArgument(0)); KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); - Assertions.assertEquals("8267411571", kycAuthResponseDto.getPartnerSpecificUserToken()); + Assertions.assertEquals(kycAuthDto.getIndividualId(), kycAuthResponseDto.getPartnerSpecificUserToken()); Assertions.assertTrue(kycAuthResponseDto.isAuthStatus()); } @@ -357,8 +359,6 @@ public void kycAuth_withInCorrectKbiChallenge_thenFail() { identityData.setFullName(List.of(languageValue)); Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); - //Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); - KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); Assertions.assertFalse(kycAuthResponseDto.isAuthStatus()); } diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java index 7780ac05..ad26b189 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java @@ -179,22 +179,24 @@ public void addVerifiedClaim_withInValidIndividualId_thenFail() { @Test public void addIdentity_withValidDetails_thenPass() throws MockIdentityException, JsonProcessingException { IdentityData identityData = new IdentityData(); + identityData.setIndividualId("123456"); identityData.setEmail("email@gmail.com"); identityData.setEncodedPhoto("encodedPhoto"); identityData.setPassword("password"); when(identityRepository.findById(identityData.getIndividualId())).thenReturn(Optional.empty()); - identityService.addIdentity(identityData); + identityService.addIdentity(objectMapper.valueToTree(identityData)); verify(identityRepository).save(any(MockIdentity.class)); } @Test public void addIdentity_withDuplicateDetails_thenFail() throws MockIdentityException { IdentityData identityData = new IdentityData(); + identityData.setIndividualId("123456"); identityData.setEmail("email@gmail.com"); identityData.setEncodedPhoto("encodedPhoto"); when(identityRepository.findById(identityData.getIndividualId())).thenReturn(Optional.of(new MockIdentity())); try{ - identityService.addIdentity(identityData); + identityService.addIdentity(objectMapper.valueToTree(identityData)); }catch (MockIdentityException e){ Assertions.assertEquals(ErrorConstants.DUPLICATE_INDIVIDUAL_ID, e.getErrorCode()); } @@ -252,7 +254,7 @@ public void updateIdentity_withExistingIndividualId_thenPass() { mockIdentity.setIndividualId("existing-id"); mockIdentity.setIdentityJson("{\"existingField\": \"value\"}"); when(identityRepository.findById("existing-id")).thenReturn(Optional.of(mockIdentity)); - identityService.updateIdentity(identityData); + identityService.updateIdentity(objectMapper.valueToTree(identityData)); verify(identityRepository, times(1)).save(mockIdentity); Assertions.assertNotNull(mockIdentity.getIdentityJson()); } @@ -267,7 +269,7 @@ public void updateIdentity_withInvalidIdentityJson_thenFail() { mockIdentity.setIdentityJson("{ \\\"name\\\": \\\"John Doe, \\\"age\\\": 30 }"); when(identityRepository.findById("existing-id")).thenReturn(Optional.of(mockIdentity)); try { - identityService.updateIdentity(identityData); + identityService.updateIdentity(objectMapper.valueToTree(identityData)); Assertions.fail(); }catch (MockIdentityException e){ Assertions.assertEquals(ErrorConstants.JSON_PROCESSING_ERROR, e.getErrorCode()); @@ -280,7 +282,7 @@ public void updateIdentity_withNonExistingIndividualId_thenFail() { identityData.setIndividualId("non-existing-id"); when(identityRepository.findById("non-existing-id")).thenReturn(Optional.empty()); MockIdentityException exception = Assertions.assertThrows(MockIdentityException.class, () -> { - identityService.updateIdentity(identityData); + identityService.updateIdentity(objectMapper.valueToTree(identityData)); }); Assertions.assertEquals(ErrorConstants.INVALID_INDIVIDUAL_ID, exception.getErrorCode()); } @@ -334,7 +336,7 @@ public void addIdentity_whenUnableToProcessJson_thenFail() throws JsonProcessing when(mockMapper.writeValueAsString(any())).thenThrow(new JsonProcessingException("JSON error") {}); ReflectionTestUtils.setField(identityService, "objectMapper", mockMapper); MockIdentityException exception = Assertions.assertThrows(MockIdentityException.class, () -> { - identityService.addIdentity(identityData); + identityService.addIdentity(objectMapper.valueToTree(identityData)); }); Assertions.assertEquals(ErrorConstants.JSON_PROCESSING_ERROR, exception.getErrorCode()); } From 700f4e633fee64481e8af3d981f49832e2e35538 Mon Sep 17 00:00:00 2001 From: ase-101 Date: Thu, 26 Feb 2026 12:58:02 +0530 Subject: [PATCH 04/35] Fixed review comments Signed-off-by: ase-101 --- .../controller/IdentityController.java | 5 +- .../service/IdentityService.java | 7 +-- .../impl/AuthenticationServiceImpl.java | 10 +-- .../service/impl/IdentityServiceImpl.java | 31 ++++------ .../validator/IdentitySchemaValidator.java | 1 - .../controller/IdentityControllerTest.java | 4 +- .../impl/AuthenticationServiceImplTest.java | 62 +++++++++---------- .../service/impl/IdentityServiceTest.java | 19 ++---- 8 files changed, 59 insertions(+), 80 deletions(-) diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java index c06006d5..c7e3115a 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java @@ -12,13 +12,10 @@ import com.fasterxml.jackson.databind.JsonNode; import io.mosip.esignet.mock.identitysystem.dto.*; import io.mosip.esignet.mock.identitysystem.dto.Error; -import io.mosip.esignet.mock.identitysystem.validator.IdentitySchema; -import io.mosip.kernel.core.exception.ErrorResponse; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.http.HttpStatus; import org.springframework.http.MediaType; import org.springframework.http.ResponseEntity; -import org.springframework.validation.annotation.Validated; import org.springframework.web.bind.annotation.*; import io.mosip.esignet.mock.identitysystem.exception.MockIdentityException; @@ -69,7 +66,7 @@ public class IdentityController { public ResponseWrapper getIdentity(@PathVariable(value = "individualId") String individualId) throws MockIdentityException { ResponseWrapper response = new ResponseWrapper<>(); - response.setResponse(identityService.getIdentityV2(individualId)); + response.setResponse(identityService.getIdentity(individualId)); response.setResponseTime(HelperUtil.getCurrentUTCDateTime()); return response; } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java index 0bec9073..4bebdacc 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java @@ -6,23 +6,18 @@ package io.mosip.esignet.mock.identitysystem.service; import com.fasterxml.jackson.databind.JsonNode; -import io.mosip.esignet.mock.identitysystem.dto.IdentityData; import io.mosip.esignet.mock.identitysystem.dto.VerifiedClaimRequestDto; import io.mosip.esignet.mock.identitysystem.exception.MockIdentityException; -import java.util.List; - public interface IdentityService { public void addIdentity(JsonNode mockAuthDataRequest) throws MockIdentityException; public void updateIdentity(JsonNode mockAuthDataRequest) throws MockIdentityException; - - public IdentityData getIdentity(String individualId) throws MockIdentityException; public void addVerifiedClaim(VerifiedClaimRequestDto request) throws MockIdentityException; - public JsonNode getIdentityV2(String individualId) throws MockIdentityException; + public JsonNode getIdentity(String individualId) throws MockIdentityException; public JsonNode getSchema(); } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java index b01584e6..e6256b06 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImpl.java @@ -122,7 +122,7 @@ public class AuthenticationServiceImpl implements AuthenticationService { public KycAuthResponseDto kycAuth(String relyingPartyId, String clientId, KycAuthDto kycAuthDto) throws MockIdentityException { //TODO validate relying party Id and client Id - JsonNode identityData = identityService.getIdentityV2(kycAuthDto.getIndividualId()); + JsonNode identityData = identityService.getIdentity(kycAuthDto.getIndividualId()); if (identityData == null) { throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); } @@ -198,7 +198,7 @@ public KycExchangeResponseDto kycExchange(String relyingPartyId, String clientId } } - JsonNode identityData = identityService.getIdentityV2(kycExchangeDto.getIndividualId()); + JsonNode identityData = identityService.getIdentity(kycExchangeDto.getIndividualId()); if (identityData == null) { throw new MockIdentityException("mock-ida-001"); } @@ -227,7 +227,7 @@ public KycExchangeResponseDto kycExchange(String relyingPartyId, String clientId public SendOtpResult sendOtp(String relyingPartyId, String clientId, SendOtpDto sendOtpDto) throws MockIdentityException { //TODO validate relying party Id and client Id - JsonNode identityData = identityService.getIdentityV2(sendOtpDto.getIndividualId()); + JsonNode identityData = identityService.getIdentity(sendOtpDto.getIndividualId()); if (identityData == null) { throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); } @@ -356,7 +356,7 @@ private boolean validateKnowledgeBasedAuth(KycAuthDto kycAuthDto, JsonNode ident private boolean validatePasswordAuth(KycAuthDto kycAuthDto, JsonNode identityData){ String passwordHash = identityData.hasNonNull("password") ? identityData.get("password").asText() : null; try { - return passwordHash != null && passwordHash.equals(HMACUtils2.digestAsPlainText(kycAuthDto.getPassword().getBytes())); + return passwordHash != null && passwordHash.equals(HMACUtils2.digestAsPlainText(kycAuthDto.getPassword().getBytes(StandardCharsets.UTF_8))); } catch (NoSuchAlgorithmException e) { log.error("Failed to decode PWD challenge or compare it with IdentityData", e); throw new MockIdentityException("auth-failed"); @@ -470,6 +470,8 @@ private ObjectNode buildKycData(String individualId, JsonNode identityData, Map< ObjectNode objectNode = buildVerifiedClaimsObject(verifiedClaimsNode, locales, identityData, claimsByVerificationMetadataResult.get(), kyc); if(!objectNode.isEmpty()) { + // The OID4IDA specification allows verified_claims to be returned as either a single object or an array of objects. + // This code normalizes all responses to arrays regardless of request format for simplicity as its mock implementation. List verifiedList = new ArrayList<>(); verifiedList.add(objectNode); kyc.set("verified_claims", objectMapper.valueToTree(verifiedList)); diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java index 46f849d6..5d1d0fe4 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java @@ -7,6 +7,7 @@ import java.io.IOException; import java.io.InputStream; +import java.nio.charset.StandardCharsets; import java.security.NoSuchAlgorithmException; import java.time.LocalDateTime; import java.time.ZoneOffset; @@ -32,7 +33,6 @@ import com.fasterxml.jackson.core.JsonProcessingException; import com.fasterxml.jackson.databind.ObjectMapper; -import io.mosip.esignet.mock.identitysystem.dto.IdentityData; import io.mosip.esignet.mock.identitysystem.entity.MockIdentity; import io.mosip.esignet.mock.identitysystem.exception.MockIdentityException; import io.mosip.esignet.mock.identitysystem.repository.IdentityRepository; @@ -68,6 +68,9 @@ public class IdentityServiceImpl implements IdentityService { @Override public void addIdentity(JsonNode identityData) throws MockIdentityException { + if(!identityData.hasNonNull("individualId")) + throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); + String individualId = identityData.get("individualId").asText(); if (identityRepository.findById(individualId).isPresent()) { throw new MockIdentityException(ErrorConstants.DUPLICATE_INDIVIDUAL_ID); @@ -75,7 +78,8 @@ public void addIdentity(JsonNode identityData) throws MockIdentityException { MockIdentity mockIdentity = new MockIdentity(); try { if(identityData.hasNonNull("password")) { - ((ObjectNode)identityData).put("password", HMACUtils2.digestAsPlainText(identityData.get("password").asText().getBytes())); + ((ObjectNode)identityData).put("password", + HMACUtils2.digestAsPlainText(identityData.get("password").asText().getBytes(StandardCharsets.UTF_8))); } mockIdentity.setIdentityJson(objectMapper.writeValueAsString(identityData)); } catch (JsonProcessingException e) { @@ -89,6 +93,9 @@ public void addIdentity(JsonNode identityData) throws MockIdentityException { @Override public void updateIdentity(JsonNode identityData) throws MockIdentityException { + if(!identityData.hasNonNull("individualId")) + throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); + String individualId = identityData.get("individualId").asText(); Optional result = identityRepository.findById(individualId); if (result.isEmpty()) { @@ -97,7 +104,8 @@ public void updateIdentity(JsonNode identityData) throws MockIdentityException { MockIdentity mockIdentity = result.get(); try { if(identityData.hasNonNull("password")) { - ((ObjectNode)identityData).put("password", HMACUtils2.digestAsPlainText(identityData.get("password").asText().getBytes())); + ((ObjectNode)identityData).put("password", + HMACUtils2.digestAsPlainText(identityData.get("password").asText().getBytes(StandardCharsets.UTF_8))); } String requestedUpdateJsonString = objectMapper.writeValueAsString(identityData); Map requestedUpdate = objectMapper.readValue(requestedUpdateJsonString, Map.class); @@ -116,20 +124,7 @@ public void updateIdentity(JsonNode identityData) throws MockIdentityException { } @Override - public IdentityData getIdentity(String individualId) throws MockIdentityException { - Optional mockIdentity = identityRepository.findById(individualId); - if (mockIdentity.isEmpty()) { - throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); - } - try { - return objectMapper.readValue(mockIdentity.get().getIdentityJson(), IdentityData.class); - } catch (JsonProcessingException e) { - throw new MockIdentityException(ErrorConstants.JSON_PROCESSING_ERROR); - } - } - - @Override - public JsonNode getIdentityV2(String individualId) throws MockIdentityException { + public JsonNode getIdentity(String individualId) throws MockIdentityException { Optional mockIdentity = identityRepository.findById(individualId); if (mockIdentity.isEmpty()) { throw new MockIdentityException(ErrorConstants.INVALID_INDIVIDUAL_ID); @@ -166,7 +161,7 @@ private InputStream getResource(String url) { @Override public void addVerifiedClaim(VerifiedClaimRequestDto verifiedClaimRequestDto) throws MockIdentityException { - JsonNode identity = getIdentityV2(verifiedClaimRequestDto.getIndividualId()); + JsonNode identity = getIdentity(verifiedClaimRequestDto.getIndividualId()); for(Entry entry : verifiedClaimRequestDto.getVerificationDetail().entrySet()){ if(!identity.hasNonNull(entry.getKey()) || (identity.get(entry.getKey()).isArray() && identity.get(entry.getKey()).isEmpty())){ diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java index b7f1859a..7bf3d776 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java @@ -3,7 +3,6 @@ import com.fasterxml.jackson.databind.JsonNode; import com.fasterxml.jackson.databind.ObjectMapper; import com.networknt.schema.*; -import io.mosip.esignet.mock.identitysystem.dto.IdentityData; import lombok.extern.slf4j.Slf4j; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.beans.factory.annotation.Value; diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java index f4cd4f5d..41c5ab7d 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java @@ -182,7 +182,7 @@ public void createIdentity_withInvalidFullName_returnErrorResponse() throws Exce @Test public void getIdentity_withValidId_returnSuccessResponse() throws Exception { identityRequest.put("individualId", "123456789"); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityRequest); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityRequest); mockMvc.perform(get("/identity/{individualId}", "123456789") .contentType(MediaType.APPLICATION_JSON)).andExpect(status().isOk()) @@ -209,7 +209,7 @@ public void addVerifiedClaims_withValidDetails_returnSuccessResponse() throws Ex requestWrapper.setRequest(verifiedClaimRequestDto); Mockito.doNothing().when(identityService).addVerifiedClaim(verifiedClaimRequestDto); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityRequest); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityRequest); mockMvc.perform(post("/identity/add-verified-claim").content(objectMapper.writeValueAsString(requestWrapper)) .contentType(MediaType.APPLICATION_JSON)).andExpect(status().isOk()) diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java index 98390277..3f41fe18 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/AuthenticationServiceImplTest.java @@ -20,7 +20,6 @@ import io.mosip.esignet.mock.identitysystem.repository.VerifiedClaimRepository; import io.mosip.esignet.mock.identitysystem.service.IdentityService; import io.mosip.esignet.mock.identitysystem.util.CacheUtilService; -import io.mosip.esignet.mock.identitysystem.util.HelperUtil; import io.mosip.kernel.signature.dto.JWTSignatureResponseDto; import io.mosip.kernel.signature.service.SignatureService; import org.junit.jupiter.api.Assertions; @@ -37,7 +36,6 @@ import java.time.LocalDateTime; import java.util.*; -import static io.mosip.esignet.mock.identitysystem.util.HelperUtil.ALGO_SHA3_256; import static org.mockito.ArgumentMatchers.eq; import static org.mockito.Mockito.when; @@ -112,7 +110,7 @@ public void kycAuth_withValidKbiChallenge_thenPass() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); @@ -126,7 +124,7 @@ public void kycAuth_withInvalidIdentity_thenFail() { kycAuthDto.setKbi("eyJmdWxsTmFtZSI6IlNpZGRoYXJ0aCBLIE1hbnNvdXIiLCJkYXRlT2ZCaXJ0aCI6IjE5ODctMTEtMjUifQ=="); kycAuthDto.setIndividualId("individualId"); kycAuthDto.setTransactionId("transactionId"); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(null); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(null); try{ authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); @@ -155,7 +153,7 @@ public void kycAuth_withoutSendOTPInvocation_thenFail() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); try{ authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); }catch (MockIdentityException e){ @@ -183,12 +181,12 @@ public void kycAuth_withSendOTPInvocation_thenPass() { sendOtpDto.setOtpChannels(Arrays.asList("email","phone")); sendOtpDto.setTransactionId("transactionId"); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); authenticationService.sendOtp("relyingPartyId", "clientId", sendOtpDto); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); when(cacheUtilService.getTransactionHash(Mockito.anyString())).thenReturn(true); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); Assertions.assertTrue(kycAuthResponseDto.isAuthStatus()); } @@ -213,7 +211,7 @@ public void kycAuth_withInValidTransactionId_thenFail() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); try{ authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); }catch (MockIdentityException e){ @@ -242,7 +240,7 @@ public void kycAuth_withValidPinChallenge_thenPass() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); @@ -271,7 +269,7 @@ public void kycAuth_withValidBiometricsChallenge_thenPass() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); @@ -300,7 +298,7 @@ public void kycAuth_withValidPwdChallenge_thenPass() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); Assertions.assertNotNull(kycAuthResponseDto); @@ -328,7 +326,7 @@ public void kycAuth_withValidKbiChallengeCustomPSUTfield_thenPass() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Mockito.when(authRepository.save(Mockito.any())).thenAnswer(invocation -> invocation.getArgument(0)); @@ -357,7 +355,7 @@ public void kycAuth_withInCorrectKbiChallenge_thenFail() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); KycAuthResponseDto kycAuthResponseDto = authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); Assertions.assertFalse(kycAuthResponseDto.isAuthStatus()); @@ -384,7 +382,7 @@ public void kycAuth_withInValidKbiChallenge_thenFail() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); try{ authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); }catch (MockIdentityException e){ @@ -409,7 +407,7 @@ public void kycAuth_withEmptyKbiChallenge_thenFail() { languageValue.setLanguage("eng"); languageValue.setValue("Siddharth K Mansour"); identityData.setFullName(List.of(languageValue)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); try{ authenticationService.kycAuth("relyingPartyId", "clientId", kycAuthDto); }catch (MockIdentityException e){ @@ -428,7 +426,7 @@ public void sendOtp_validIndividualIdAndOtpChannels_thenPass() throws MockIdenti sendOtpDto.setOtpChannels(Arrays.asList("email","phone")); sendOtpDto.setTransactionId("transactionId"); - Mockito.when(identityService.getIdentityV2(individualId)).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(individualId)).thenReturn(this.identityData); SendOtpResult result = authenticationService.sendOtp(relyingPartyId, clientId, sendOtpDto); Assertions.assertNotNull(result); @@ -444,7 +442,7 @@ public void sendOtp_invalidIndividualId_thenFail() { String individualId = "invalidId"; SendOtpDto sendOtpDto=new SendOtpDto(); sendOtpDto.setIndividualId(individualId); - Mockito.when(identityService.getIdentityV2(individualId)).thenReturn(null); + Mockito.when(identityService.getIdentity(individualId)).thenReturn(null); MockIdentityException exception = Assertions.assertThrows(MockIdentityException.class, () -> authenticationService.sendOtp(relyingPartyId, clientId, sendOtpDto)); Assertions.assertEquals("invalid_individual_id", exception.getMessage()); @@ -468,7 +466,7 @@ public void sendOtp_invalidOtpChannels_thenFail() { identityData.put("email", "test@email.com"); identityData.put("phone", "1234567890"); - Mockito.when(identityService.getIdentityV2(individualId)).thenReturn(identityData); + Mockito.when(identityService.getIdentity(individualId)).thenReturn(identityData); MockIdentityException exception = Assertions.assertThrows(MockIdentityException.class, () -> { authenticationService.sendOtp(relyingPartyId, clientId, sendOtpDto); @@ -494,7 +492,7 @@ public void sendOtp_noEmailOrMobileFound_thenFail() { ObjectNode identityData = objectMapper.createObjectNode(); identityData.put("individualId", "individualId"); - Mockito.when(identityService.getIdentityV2(individualId)).thenReturn(identityData); + Mockito.when(identityService.getIdentity(individualId)).thenReturn(identityData); try { authenticationService.sendOtp(relyingPartyId, clientId, sendOtpDto); }catch(MockIdentityException e) { @@ -561,7 +559,7 @@ public void kycExchange_withValidDetails_thenPass() throws MockIdentityException Mockito.when(authRepository.findByKycTokenAndValidityAndTransactionIdAndIndividualId( Mockito.anyString(), eq(Valid.ACTIVE), Mockito.anyString(), Mockito.anyString())) .thenReturn(Optional.of(kycAuth)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityData); Mockito.when(signatureService.jwtSign(Mockito.any())).thenReturn(jwtSignatureResponseDto); KycExchangeResponseDto response = authenticationService.kycExchange(relyingPartyId, clientId, new KycExchangeDto(kycExchangeRequestDto, null, "JWS")); @@ -608,7 +606,7 @@ public void kycExchange_withInValidJwe_thenFail() throws MockIdentityException, Mockito.when(authRepository.findByKycTokenAndValidityAndTransactionIdAndIndividualId( Mockito.anyString(), eq(Valid.ACTIVE), Mockito.anyString(), Mockito.anyString())) .thenReturn(Optional.of(kycAuth)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityData); Mockito.when(signatureService.jwtSign(Mockito.any())).thenReturn(jwtSignatureResponseDto); @@ -781,7 +779,7 @@ public void kycExchangeV2_withDetail_thenPass() { Mockito.any(), Mockito.any(), Mockito.any())).thenReturn(kycAuthOptional); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Optional> verifiedClaimsOptional = getVerifiedClaims(); @@ -841,7 +839,7 @@ public void kycExchangeV2_withInValidIndividualId_thenFail() { Mockito.when(authRepository.findByKycTokenAndValidityAndTransactionIdAndIndividualId(Mockito.any(), Mockito.any(), Mockito.any(), Mockito.any())).thenReturn(kycAuthOptional); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(null); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(null); try { authenticationService.kycExchange("relyingPartyId", "clientId", kycExchangeRequestDtoV2); @@ -960,7 +958,7 @@ public void kycExchangeV2_withDetailAndMatchedClaims_thenPass() { Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); // Mock the identityService to return JsonNode - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityDataJsonNode); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityDataJsonNode); Optional> verifiedClaimsOptional = getVerifiedClaims(); @@ -1084,7 +1082,7 @@ public void kycExchangeV2_withMultipleTrustFramework_thenPass() { Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); // Mock the identityService to return JsonNode - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityDataJsonNode); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityDataJsonNode); Optional> verifiedClaimsOptional = getVerifiedClaims(); @@ -1234,7 +1232,7 @@ public void kycExchangeV2_withMultipleLanguages_thenPass() { Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); // Mock the identityService to return JsonNode - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityDataJsonNode); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityDataJsonNode); Optional> verifiedClaimsOptional = getVerifiedClaims(); @@ -1359,7 +1357,7 @@ public void kycExchangeV2_withoutVerificationMetadata_thenPass() { Mockito.any(), Mockito.any(), Mockito.any())).thenReturn(kycAuthOptional); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); JWTSignatureResponseDto jwtSignatureResponseDto = new JWTSignatureResponseDto(); jwtSignatureResponseDto.setJwtSignedData("jwtSignedData"); @@ -1406,7 +1404,7 @@ public void kycAuth2_withValidKbiChallenge_thenPass() throws Exception { identityData.setDateOfBirth("1987/11/25"); identityData.setEmail("email@gmail.com"); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); @@ -1471,7 +1469,7 @@ public void kycAuth2_withValidKbiChallenge_and_withOutVerifiedClaim_thenPass() t identityData.setDateOfBirth("1987/11/25"); identityData.setEmail("email@gmail.com"); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(this.identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(this.identityData); Mockito.when(authRepository.save(Mockito.any())).thenReturn(new KycAuth()); @@ -1539,7 +1537,7 @@ public void sendOtp_withEmailChannelAndNoEmailFound_thenFail() { ObjectNode identityData = objectMapper.createObjectNode(); identityData.put("individualId", "individualId"); - Mockito.when(identityService.getIdentityV2("individualId")).thenReturn(identityData); + Mockito.when(identityService.getIdentity("individualId")).thenReturn(identityData); try { authenticationService.sendOtp("relyingPartyId", "clientId", sendOtpDto); Assertions.fail("Expected MockIdentityException"); @@ -1601,7 +1599,7 @@ public void kycExchange_withVerifiedClaimsWithoutStandardClaims_thenPass() { Mockito.when(authRepository.findByKycTokenAndValidityAndTransactionIdAndIndividualId( Mockito.anyString(), eq(Valid.ACTIVE), Mockito.anyString(), Mockito.anyString())) .thenReturn(Optional.of(kycAuth)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityData); VerifiedClaim verifiedClaim1 = new VerifiedClaim(); verifiedClaim1.setTrustFramework("pwd"); @@ -1662,7 +1660,7 @@ public void kycExchange_withEmptyVerifiedClaims_thenPass() { Mockito.when(authRepository.findByKycTokenAndValidityAndTransactionIdAndIndividualId( Mockito.anyString(), eq(Valid.ACTIVE), Mockito.anyString(), Mockito.anyString())) .thenReturn(Optional.of(kycAuth)); - Mockito.when(identityService.getIdentityV2(Mockito.anyString())).thenReturn(identityData); + Mockito.when(identityService.getIdentity(Mockito.anyString())).thenReturn(identityData); // Return verified claims but with different trust framework VerifiedClaim verifiedClaim = new VerifiedClaim(); diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java index ad26b189..500f1ba7 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java @@ -204,30 +204,23 @@ public void addIdentity_withDuplicateDetails_thenFail() throws MockIdentityExcep @Test public void getIdentity_withValidDetails_thenPass() throws MockIdentityException, JsonProcessingException { - IdentityData identityData = new IdentityData(); - identityData.setEmail("email@gmail.com"); - identityData.setEncodedPhoto("encodedPhoto"); MockIdentity mockIdentity = new MockIdentity(); - mockIdentity.setIndividualId("123456"); + mockIdentity.setIndividualId("8267411571"); mockIdentity.setIdentityJson("{\"individualId\":\"8267411571\",\"pin\":\"111111\",\"fullName\":[{\"language\":\"fra\",\"value\":\"Siddharth K Mansour\"},{\"language\":\"ara\",\"value\":\"تتگلدكنسَزقهِقِفل دسييسيكدكنوڤو\"},{\"language\":\"eng\",\"value\":\"Siddharth K Mansour\"}],\"email\":\"siddhartha.km@gmail.com\",\"phone\":\"+919427357934\"}"); - mockIdentity.setIdentityJson("{}"); - when(identityRepository.findById(identityData.getIndividualId())).thenReturn(Optional.of(mockIdentity)); - IdentityData result = identityService.getIdentity(identityData.getIndividualId()); + when(identityRepository.findById("8267411571")).thenReturn(Optional.of(mockIdentity)); + JsonNode result = identityService.getIdentity("8267411571"); - Assertions.assertEquals(identityData.getIndividualId(), result.getIndividualId()); + Assertions.assertEquals("8267411571", result.get("individualId").asText()); } @Test public void getIdentity_withInValidIdentityJson_thenFail() throws MockIdentityException, JsonProcessingException { - IdentityData identityData = new IdentityData(); - identityData.setEmail("email@gmail.com"); - identityData.setEncodedPhoto("encodedPhoto"); MockIdentity mockIdentity = new MockIdentity(); mockIdentity.setIndividualId("123456"); mockIdentity.setIdentityJson("{ \\\"name\\\": \\\"John Doe, \\\"age\\\": 30 }"); - when(identityRepository.findById(identityData.getIndividualId())).thenReturn(Optional.of(mockIdentity)); + when(identityRepository.findById("123456")).thenReturn(Optional.of(mockIdentity)); try { - identityService.getIdentity(identityData.getIndividualId()); + identityService.getIdentity("123456"); Assertions.fail(); }catch (MockIdentityException e){ Assertions.assertEquals(ErrorConstants.JSON_PROCESSING_ERROR, e.getErrorCode()); From dcc54accd8bf2f063a444c67fa92b126c97280a0 Mon Sep 17 00:00:00 2001 From: Harsh Kashiwal <77677724+KashiwalHarsh@users.noreply.github.com> Date: Tue, 24 Feb 2026 21:20:55 +0530 Subject: [PATCH 05/35] added proxy pass for par and dpop (#554) Signed-off-by: Harsh Kashiwal --- docker-compose/nginx.conf | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/docker-compose/nginx.conf b/docker-compose/nginx.conf index 2b835b6d..e5407a06 100644 --- a/docker-compose/nginx.conf +++ b/docker-compose/nginx.conf @@ -28,7 +28,24 @@ http { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Host $server_name; } - + location /mock-relying-party-service/requestUri { + proxy_pass http://mock-relying-party-service:8888/requestUri; + proxy_redirect off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Host $server_name; + proxy_http_version 1.1; + } + location /mock-relying-party-service/dpopJKT { + proxy_pass http://mock-relying-party-service:8888/dpopJKT ; + proxy_redirect off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Host $server_name; + proxy_http_version 1.1; + } location / { # alias /usr/share/nginx/html; From 88946225e6a97f015783a8ce9bcc3a4c41498054 Mon Sep 17 00:00:00 2001 From: Sajid Mannikeri Date: Thu, 5 Mar 2026 11:13:29 +0530 Subject: [PATCH 06/35] resolved comments Signed-off-by: Sajid Mannikeri --- .../src/services/relyingPartyService.js | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/mock-relying-party-ui/src/services/relyingPartyService.js b/mock-relying-party-ui/src/services/relyingPartyService.js index 53200eb4..e8f6c743 100644 --- a/mock-relying-party-ui/src/services/relyingPartyService.js +++ b/mock-relying-party-ui/src/services/relyingPartyService.js @@ -35,8 +35,13 @@ const get_code_challenge_method = async () => { try { const baseUrl = window._env_.ESIGNET_UI_BASE_URL; const response = await axios.get(`${baseUrl}/.well-known/openid-configuration`); - const methods = response.data?.code_challenge_methods_supported; - return methods && methods.length > 0 ? methods[0] : 'S256'; + const supportedMethods = response.data?.code_challenge_methods_supported || []; + + // Default to S256 + if (!supportedMethods || supportedMethods.length === 0) return 'S256'; + + // If method contains S256, use S256; otherwise fallback to first supported method. + return supportedMethods.includes('S256') ? 'S256' : supportedMethods[0]; } catch (error) { console.warn('Failed to fetch PKCE methods, defaulting to S256:', error); return 'S256'; From f5850c17bb36b2ed6df7042382df2a0bcdb24a7c Mon Sep 17 00:00:00 2001 From: Sajid Mannikeri Date: Thu, 5 Mar 2026 12:31:48 +0530 Subject: [PATCH 07/35] resolved review comment Signed-off-by: Sajid Mannikeri --- mock-relying-party-ui/src/services/relyingPartyService.js | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/mock-relying-party-ui/src/services/relyingPartyService.js b/mock-relying-party-ui/src/services/relyingPartyService.js index e8f6c743..e6c56b7f 100644 --- a/mock-relying-party-ui/src/services/relyingPartyService.js +++ b/mock-relying-party-ui/src/services/relyingPartyService.js @@ -165,7 +165,6 @@ const post_fetchUserInfo = async ( const codeVerifier = sessionStorage.getItem(`pkce_${client_id}_${state}`); if (codeVerifier) { request.code_verifier = codeVerifier; - sessionStorage.removeItem(`pkce_${client_id}_${state}`); } const endpoint = BASE_URL + GET_USER_INFO; @@ -174,6 +173,11 @@ const post_fetchUserInfo = async ( "Content-Type": "application/json", }, }); + + if (codeVerifier) { + sessionStorage.removeItem(`pkce_${client_id}_${state}`); + } + return response.data; }; From c902b46c95752dcb1f5a3b5a5f10e39244454320 Mon Sep 17 00:00:00 2001 From: Sajid Mannikeri Date: Thu, 5 Mar 2026 12:48:29 +0530 Subject: [PATCH 08/35] resolve review comments Signed-off-by: Sajid Mannikeri --- .../src/services/relyingPartyService.js | 26 +++++++++---------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/mock-relying-party-ui/src/services/relyingPartyService.js b/mock-relying-party-ui/src/services/relyingPartyService.js index e6c56b7f..320cc217 100644 --- a/mock-relying-party-ui/src/services/relyingPartyService.js +++ b/mock-relying-party-ui/src/services/relyingPartyService.js @@ -36,10 +36,10 @@ const get_code_challenge_method = async () => { const baseUrl = window._env_.ESIGNET_UI_BASE_URL; const response = await axios.get(`${baseUrl}/.well-known/openid-configuration`); const supportedMethods = response.data?.code_challenge_methods_supported || []; - + // Default to S256 if (!supportedMethods || supportedMethods.length === 0) return 'S256'; - + // If method contains S256, use S256; otherwise fallback to first supported method. return supportedMethods.includes('S256') ? 'S256' : supportedMethods[0]; } catch (error) { @@ -56,25 +56,25 @@ const get_code_challenge_method = async () => { */ const get_code_challenge = async (clientId, state) => { const method = await get_code_challenge_method(); - + if (!method) { console.warn('PKCE disabled: no supported method found'); return null; } - + const codeVerifier = generateCodeVerifier(); let codeChallenge; - - if (method === 'plain') { - codeChallenge = codeVerifier; - } else { + + if (method === 'S256') { const encoder = new TextEncoder(); const data = encoder.encode(codeVerifier); const hashBuffer = await crypto.subtle.digest('SHA-256', data); codeChallenge = base64UrlEncode(new Uint8Array(hashBuffer)); + } else { + codeChallenge = codeVerifier; } - - sessionStorage.setItem(`pkce_${clientId}_${state}`, codeVerifier); + + sessionStorage.setItem(`pkce_${clientId}_${state}`, codeVerifier); return { code_challenge: codeChallenge, code_challenge_method: method @@ -160,7 +160,7 @@ const post_fetchUserInfo = async ( redirect_uri, grant_type, }; - + // Retrieve and include code_verifier if it exists in sessionStorage (PKCE enabled) const codeVerifier = sessionStorage.getItem(`pkce_${client_id}_${state}`); if (codeVerifier) { @@ -173,11 +173,11 @@ const post_fetchUserInfo = async ( "Content-Type": "application/json", }, }); - + if (codeVerifier) { sessionStorage.removeItem(`pkce_${client_id}_${state}`); } - + return response.data; }; From 19537cee98aeeee4082b4c48baf36f77be9e81c7 Mon Sep 17 00:00:00 2001 From: Sachin Rana Date: Wed, 11 Mar 2026 12:03:00 +0530 Subject: [PATCH 09/35] set active_profile_env to "default" in deployment (#558) (#560) Signed-off-by: Sachin Rana --- mock-identity-system/configure_start.sh | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/mock-identity-system/configure_start.sh b/mock-identity-system/configure_start.sh index b247389d..894b181f 100644 --- a/mock-identity-system/configure_start.sh +++ b/mock-identity-system/configure_start.sh @@ -38,6 +38,12 @@ else echo "*** HSM Client installation is ignored in local profile ***" fi +## set active profile if not set +if [[ -z "$active_profile_env" ]]; then + echo "Alert: active_profile_env is not set. setting to default" + active_profile_env="default" + export active_profile_env +fi cd $work_dir From faaddba32f68a6231596b31febf76498166c4b30 Mon Sep 17 00:00:00 2001 From: Nandhukumar Date: Thu, 12 Mar 2026 18:51:35 +0530 Subject: [PATCH 10/35] docs: fix typos, remove duplicate overview, and improve README formatting (#561) (#563) Signed-off-by: Nandhukumar --- docker-compose/README.md | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/docker-compose/README.md b/docker-compose/README.md index 1001ea0b..116d4993 100644 --- a/docker-compose/README.md +++ b/docker-compose/README.md @@ -2,10 +2,6 @@ This is the docker-compose setup to run mock identity system and mock relying party portal. This is not for production use. -## Overview - -This is the docker compose setup to run esignet UI and esignet-service with mock identity system. This is not for production use. - ## I am a developer, how to setup dependent services to run mock-identity-system? 1. Run `docker compose --file dependent-docker-compose.yml up` to start all the dependent services. @@ -15,7 +11,7 @@ This is the docker compose setup to run esignet UI and esignet-service with mock ## How to start the mock Relying party UI? -1. Run [mock-relying-party-portal-docker-compose.yml](mock-relying-party-portal-docker-compose.yml) to start relying party portal. +1. Run `docker compose --file mock-relying-party-portal-docker-compose.yml up` to start relying party portal. 2. Access Relying party UI at http://localhost:3000 By default, mock Relying party portal is connecting to eSignet (Identity Provider) hosted in collab.mosip.net environment. @@ -28,7 +24,7 @@ Below environment variables should be changed to point to different environment: ## How to start the mock Relying party UI with FAPI 2.0 enabled? -1. Run [mock-relying-party-portal-fapi2-docker-compose.yml](mock-relying-party-portal-fapi2-docker-compose.yml) to start the relying party portal with DPoP and PAR enabled. +1. Run `docker compose --file mock-relying-party-portal-fapi2-docker-compose.yml up` to start the relying party portal with DPoP and PAR enabled. 2. Access the Relying party UI at http://localhost:3000 ### Required Environment Variables From 43c8ad93e1d4e4bb8d76df225a3ce19e4c666405 Mon Sep 17 00:00:00 2001 From: ase-101 Date: Fri, 13 Mar 2026 02:45:19 +0530 Subject: [PATCH 11/35] Added endpoint to fetch identity schema (#564) * Added endpoint to fetch identity schema Signed-off-by: ase-101 * Added endpoint to fetch identity schema Signed-off-by: ase-101 * Fixed testcase Signed-off-by: ase-101 --------- Signed-off-by: ase-101 --- .../controller/IdentityController.java | 7 +++++++ .../identitysystem/service/IdentityService.java | 2 ++ .../service/impl/IdentityServiceImpl.java | 15 +++++++++++++++ .../controller/IdentityControllerTest.java | 2 +- .../service/impl/IdentityServiceTest.java | 2 +- 5 files changed, 26 insertions(+), 2 deletions(-) diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java index c7e3115a..6977a88f 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/controller/IdentityController.java @@ -99,6 +99,13 @@ public ResponseEntity handleMethodArgumentNotValidException(ConstraintViolationE @GetMapping("identity/ui-spec") public ResponseWrapper getUiSpec() { + ResponseWrapper responseWrapper = new ResponseWrapper<>(); + responseWrapper.setResponse(identityService.getUISpecification()); + return responseWrapper; + } + + @GetMapping("identity/identity-schema") + public ResponseWrapper getIdentitySchema() { ResponseWrapper responseWrapper = new ResponseWrapper<>(); responseWrapper.setResponse(identityService.getSchema()); return responseWrapper; diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java index 4bebdacc..aa1e34e5 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/IdentityService.java @@ -20,4 +20,6 @@ public interface IdentityService { public JsonNode getIdentity(String individualId) throws MockIdentityException; public JsonNode getSchema(); + + public JsonNode getUISpecification(); } diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java index 5d1d0fe4..abe27d14 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceImpl.java @@ -64,6 +64,9 @@ public class IdentityServiceImpl implements IdentityService { private ResourceLoader resourceLoader; @Value("${mosip.mock.ui-spec.schema.url}") + private String uiSpecSchemaUrl; + + @Value("${mosip.mock.ida.identity.schema.url}") private String schemaUrl; @Override @@ -140,6 +143,18 @@ public JsonNode getIdentity(String individualId) throws MockIdentityException { public JsonNode getSchema() { InputStream schemaResponse = getResource(schemaUrl); ObjectMapper objectMapper = new ObjectMapper(); + try { + return objectMapper.readTree(schemaResponse); + } catch (IOException e) { + log.error("Error parsing the identity schema: {}", e.getMessage(), e); + throw new MockIdentityException("schema_not_found"); + } + } + + @Override + public JsonNode getUISpecification() { + InputStream schemaResponse = getResource(uiSpecSchemaUrl); + ObjectMapper objectMapper = new ObjectMapper(); try { return objectMapper.readTree(schemaResponse); } catch (IOException e) { diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java index 41c5ab7d..ec9a31ea 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/controller/IdentityControllerTest.java @@ -276,7 +276,7 @@ public void getUiSpec_withValidRequest_thenPass() throws Exception { ObjectNode properties = objectMapper.createObjectNode(); properties.put("individualId", "string"); mockSchema.set("properties", properties); - Mockito.when(identityService.getSchema()).thenReturn(mockSchema); + Mockito.when(identityService.getUISpecification()).thenReturn(mockSchema); mockMvc.perform(get("/identity/ui-spec") .contentType(MediaType.APPLICATION_JSON)) .andExpect(status().isOk()) diff --git a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java index 500f1ba7..acb91141 100644 --- a/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java +++ b/mock-identity-system/src/test/java/io/mosip/esignet/mock/identitysystem/service/impl/IdentityServiceTest.java @@ -303,7 +303,7 @@ public void getSchema_whenInvalidJson_thenFail() throws Exception { MockIdentityException exception = Assertions.assertThrows(MockIdentityException.class, () -> { identityService.getSchema(); }); - Assertions.assertEquals("ui_spec_not_found", exception.getMessage()); + Assertions.assertEquals("schema_not_found", exception.getMessage()); } @Test From dddf6823ab9e131152c9bb4f050c8b4a0508a4ba Mon Sep 17 00:00:00 2001 From: ase-101 Date: Fri, 13 Mar 2026 09:05:42 +0530 Subject: [PATCH 12/35] Fixed the required field validation error (#565) * Added endpoint to fetch identity schema Signed-off-by: ase-101 * Added endpoint to fetch identity schema Signed-off-by: ase-101 * Fixed required fields validation error Signed-off-by: ase-101 --------- Signed-off-by: ase-101 --- mock-identity-system/README.md | 3 +-- .../validator/IdentitySchemaValidator.java | 19 ++++++++++--------- .../resources/application-default.properties | 1 - 3 files changed, 11 insertions(+), 12 deletions(-) diff --git a/mock-identity-system/README.md b/mock-identity-system/README.md index 5f293b77..5c4e5d03 100644 --- a/mock-identity-system/README.md +++ b/mock-identity-system/README.md @@ -72,8 +72,7 @@ This validation ensures that the provided Identity data adhere to the defined sc ```` mosip.mock.ida.identity.schema.url=classpath:/mock-identity-schema.json - mosip.mock.ida.update-identity.non-mandatory.fields={"givenName","familyName","middleName","nickName","preferredUsername","gender","streetAddress","locality","region","country","pin","preferredLang","dateOfBirth","postalCode","encodedPhoto","email","phone","zoneInfo","locale","password"} -```` + ```` How It Works * For create operations: diff --git a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java index 7bf3d776..5e4ac7fd 100644 --- a/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java +++ b/mock-identity-system/src/main/java/io/mosip/esignet/mock/identitysystem/validator/IdentitySchemaValidator.java @@ -25,9 +25,6 @@ public class IdentitySchemaValidator implements ConstraintValidator nonMandatoryFieldsOnUpdate; - private String action; private JsonSchema schema; @@ -68,11 +65,9 @@ private Set validateIdentityData(JsonNode identityJsonNode) { Set errors = schema.validate(identityJsonNode); // If not a create operation, filter out specific errors if (action.equals("UPDATE")) { - // Ignore validation errors with code 1029 (null value) and for exempted fields when validating updateIdentity + // Ignore validation errors with code 1028 (null value) and for exempted fields when validating updateIdentity errors = errors.stream() - .filter(error -> !error.getCode().equals("1029") || - !nonMandatoryFieldsOnUpdate.contains(error. - getInstanceLocation().getName(0))) + .filter(error -> !error.getCode().equals("1028")) .collect(Collectors.toSet()); } return errors; @@ -80,11 +75,17 @@ private Set validateIdentityData(JsonNode identityJsonNode) { private void addValidationErrorCode(Set errors, ConstraintValidatorContext context) { context.disableDefaultConstraintViolation(); - errors.forEach(error->context. - buildConstraintViolationWithTemplate("invalid_"+error.getInstanceLocation().getName(0).toLowerCase()) + errors.forEach(error-> + context.buildConstraintViolationWithTemplate(getErrorCodeFromValidationMessage(error)) .addConstraintViolation()); } + private String getErrorCodeFromValidationMessage(ValidationMessage error) { + String fieldName = error.getInstanceLocation().getNameCount() > 0 ? error.getInstanceLocation().getName(0) : + error.getProperty(); + return fieldName != null ? "invalid_"+fieldName.toLowerCase() : "unknown_field"; + } + private InputStream getResource(String url) { try{ Resource resource = resourceLoader.getResource(url); diff --git a/mock-identity-system/src/main/resources/application-default.properties b/mock-identity-system/src/main/resources/application-default.properties index ab53aaf4..d4ef7bd8 100644 --- a/mock-identity-system/src/main/resources/application-default.properties +++ b/mock-identity-system/src/main/resources/application-default.properties @@ -30,7 +30,6 @@ mosip.mock.ida.identity.schema.url=classpath:/mock-identity-schema.json mosip.mock.ui-spec.schema.url=classpath:/mock-identity-ui-spec.json -mosip.mock.ida.update-identity.non-mandatory.fields={"fullName","givenName","familyName","middleName","nickName","preferredUsername","gender","streetAddress","locality","region","country","pin","preferredLang","dateOfBirth","postalCode","encodedPhoto","email","phone","zoneInfo","locale","password"} ##----------------------------------------- Database properties -------------------------------------------------------- mosip.mockidentitysystem.database.hostname=${database.host} From aa089e722cc23c35289f392d93012b0d85e05d54 Mon Sep 17 00:00:00 2001 From: Harsh Kashiwal Date: Thu, 9 Apr 2026 15:33:55 +0530 Subject: [PATCH 13/35] Snapshot updates 0.13.0 -> 0.13.1 Signed-off-by: Harsh Kashiwal --- mock-identity-system/pom.xml | 4 ++-- pom.xml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/mock-identity-system/pom.xml b/mock-identity-system/pom.xml index 5cdceeee..2c158b71 100644 --- a/mock-identity-system/pom.xml +++ b/mock-identity-system/pom.xml @@ -5,11 +5,11 @@ io.mosip.esignet.mock esignet-mock-parent - 0.13.0-SNAPSHOT + 0.13.1-SNAPSHOT mock-identity-system - 0.13.0-SNAPSHOT + 0.13.1-SNAPSHOT jar mock-identity-system diff --git a/pom.xml b/pom.xml index 328cb2a5..27c930e7 100644 --- a/pom.xml +++ b/pom.xml @@ -16,7 +16,7 @@ 4.0.0 io.mosip.esignet.mock esignet-mock-parent - 0.13.0-SNAPSHOT + 0.13.1-SNAPSHOT pom esignet-mock Parent project of MOSIP e-Signet Mock Services From dd0d4cd435b6247525f89e0821d174b07a03addd Mon Sep 17 00:00:00 2001 From: GurukiranP Date: Tue, 28 Apr 2026 10:51:56 +0530 Subject: [PATCH 14/35] [ES-2962] Added error messages for login_required and request_not_supported error. Signed-off-by: GurukiranP --- mock-relying-party-ui/public/locales/ar.json | 4 +++- mock-relying-party-ui/public/locales/en.json | 4 +++- mock-relying-party-ui/public/locales/hi.json | 4 +++- mock-relying-party-ui/public/locales/km.json | 4 +++- mock-relying-party-ui/public/locales/kn.json | 4 +++- mock-relying-party-ui/public/locales/ta.json | 4 +++- 6 files changed, 18 insertions(+), 6 deletions(-) diff --git a/mock-relying-party-ui/public/locales/ar.json b/mock-relying-party-ui/public/locales/ar.json index 65a1aee3..fa36edd4 100644 --- a/mock-relying-party-ui/public/locales/ar.json +++ b/mock-relying-party-ui/public/locales/ar.json @@ -248,6 +248,8 @@ "web_socket_fail": "لم يتم إكمال عملية التحقق من eKYC. يُرجى المحاولة مرة أخرى.", "dpop_failed": "فشل التحقق من DPoP. يُرجى المحاولة مرة أخرى.", "invalid_dpop_proof": "لم نتمكن من إتمام المصادقة. يرجى المحاولة مرة أخرى", - "code_challenge_failed": "فشل في إنشاء تحدي الشفرة. يرجى المحاولة مرة أخرى." + "code_challenge_failed": "فشل في إنشاء تحدي الشفرة. يرجى المحاولة مرة أخرى.", + "login_required": "تعذر إكمال تسجيل الدخول. يرجى المحاولة مرة أخرى.", + "request_not_supported": "لم نتمكن من معالجة طلبك. يرجى المحاولة مرة أخرى أو الاتصال بالمسؤول إذا استمرت المشكلة." } } diff --git a/mock-relying-party-ui/public/locales/en.json b/mock-relying-party-ui/public/locales/en.json index 458e624f..a59f6285 100644 --- a/mock-relying-party-ui/public/locales/en.json +++ b/mock-relying-party-ui/public/locales/en.json @@ -249,6 +249,8 @@ "web_socket_fail": "eKYC verification was not completed. Please try again.", "dpop_failed": "DPoP verification failed. Please try again.", "invalid_dpop_proof": "Authentication could not be completed. Please try again", - "code_challenge_failed": "Failed to generate code challenge. Please try again." + "code_challenge_failed": "Failed to generate code challenge. Please try again.", + "login_required": "Unable to complete sign-in. Please try again.", + "request_not_supported": "We couldn’t process your request. Please try again or contact admin if the issue continues." } } diff --git a/mock-relying-party-ui/public/locales/hi.json b/mock-relying-party-ui/public/locales/hi.json index c12396da..cb085ec8 100644 --- a/mock-relying-party-ui/public/locales/hi.json +++ b/mock-relying-party-ui/public/locales/hi.json @@ -247,6 +247,8 @@ "web_socket_fail": "eKYC सत्यापन पूरा नहीं हुआ। कृपया पुनः प्रयास करें।", "dpop_failed": "DPoP सत्यापन विफल हुआ. कृपया पुनः प्रयास करें।", "invalid_dpop_proof": "प्रमाणीकरण पूरा नहीं हो सका। कृपया पुनः प्रयास करें", - "code_challenge_failed": "कोड चुनौती उत्पन्न करने में विफल। कृपया पुनः प्रयास करें।" + "code_challenge_failed": "कोड चुनौती उत्पन्न करने में विफल। कृपया पुनः प्रयास करें।", + "login_required": "साइन-इन पूरा नहीं हो सका। कृपया पुनः प्रयास करें।", + "request_not_supported": "हम आपके अनुरोध को संसाधित नहीं कर सके। कृपया पुनः प्रयास करें या समस्या जारी रहने पर व्यवस्थापक से संपर्क करें।" } } diff --git a/mock-relying-party-ui/public/locales/km.json b/mock-relying-party-ui/public/locales/km.json index ce384663..9c14d869 100644 --- a/mock-relying-party-ui/public/locales/km.json +++ b/mock-relying-party-ui/public/locales/km.json @@ -249,6 +249,8 @@ "web_socket_fail": "ការផ្ទៀងផ្ទាត់ eKYC មិនត្រូវបានបញ្ចប់ទេ។ សូមព្យាយាមម្តងទៀត។", "dpop_failed": "ការផ្ទៀងផ្ទាត់ DPoP បានបរាជ័យ។ សូមព្យាយាមម្តងទៀត។", "invalid_dpop_proof": "ការផ្ទៀងផ្ទាត់មិនអាចបញ្ចប់បាន។ សូមព្យាយាមម្ដងទៀត", - "code_challenge_failed": "ការបង្កើតការប្រឈមកូដបានបរាជ័យ។ សូមព្យាយាមម្ដងទៀត។" + "code_challenge_failed": "ការបង្កើតការប្រឈមកូដបានបរាជ័យ។ សូមព្យាយាមម្ដងទៀត។", + "login_required": "មិនអាចបញ្ចប់ការចូលបានទេ។ សូមព្យាយាមម្តងទៀត។", + "request_not_supported": "យើងមិនអាចដំណើរការសំណើរបស់អ្នកបានទេ។ សូមព្យាយាមម្តងទៀត ឬទាក់ទងអ្នកគ្រប់គ្រង ប្រសិនបើបញ្ហានៅតែបន្ត។" } } diff --git a/mock-relying-party-ui/public/locales/kn.json b/mock-relying-party-ui/public/locales/kn.json index 90c949eb..26c5348e 100644 --- a/mock-relying-party-ui/public/locales/kn.json +++ b/mock-relying-party-ui/public/locales/kn.json @@ -247,6 +247,8 @@ "web_socket_fail": "eKYC ಪರಿಶೀಲನೆ ಪೂರ್ಣಗೊಂಡಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", "dpop_failed": "DPoP ಪರಿಶೀಲನೆ ವಿಫಲವಾಗಿದೆ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", "invalid_dpop_proof": "ಪ್ರಾಮಾಣೀಕರಣವನ್ನು ಪೂರ್ಣಗೊಳಿಸಲಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೊಮ್ಮೆ ಪ್ರಯತ್ನಿಸಿ", - "code_challenge_failed": "ಕೋಡ್ ಚಾಲೆಂಜ್ ರಚಿಸಲು ವಿಫಲವಾಗಿದೆ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ." + "code_challenge_failed": "ಕೋಡ್ ಚಾಲೆಂಜ್ ರಚಿಸಲು ವಿಫಲವಾಗಿದೆ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", + "login_required": "ಲಾಗಿನ್ ಪೂರ್ಣಗೊಳಿಸಲು ಸಾಧ್ಯವಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", + "request_not_supported": "ನಿಮ್ಮ ವಿನಂತಿಯನ್ನು ಪ್ರಕ್ರಿಯೆಗೊಳಿಸಲು ಸಾಧ್ಯವಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಸಮಸ್ಯೆ ಮುಂದುವರಿದರೆ ನಿರ್ವಾಹಕರನ್ನು ಸಂಪರ್ಕಿಸಿ." } } diff --git a/mock-relying-party-ui/public/locales/ta.json b/mock-relying-party-ui/public/locales/ta.json index 96102bb2..533231af 100644 --- a/mock-relying-party-ui/public/locales/ta.json +++ b/mock-relying-party-ui/public/locales/ta.json @@ -247,6 +247,8 @@ "web_socket_fail": "eKYC சரிபார்ப்பு முடிக்கப்படவில்லை. மீண்டும் முயற்சிக்கவும்.", "dpop_failed": "DPoP சரிபார்ப்பு தோல்வியடைந்தது. மீண்டும் முயற்சிக்கவும்.", "invalid_dpop_proof": "அங்கீகாரம் முடிக்க முடியவில்லை. மீண்டும் முயற்சிக்கவும்", - "code_challenge_failed": "கோட் சவால் உருவாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும்." + "code_challenge_failed": "கோட் சவால் உருவாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும்.", + "login_required": "உள்நுழைவு முடிக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும்.", + "request_not_supported": "உங்கள் கோரிக்கையை செயலாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும் அல்லது பிரச்சனை தொடர்ந்து இருந்தால் நிர்வாகியை தொடர்புகொள்ளவும்." } } From a48ecba496629b0fef6f3d94e170f7855314d162 Mon Sep 17 00:00:00 2001 From: GurukiranP Date: Mon, 18 May 2026 15:22:18 +0530 Subject: [PATCH 15/35] [ES-1616] Added new error message. Signed-off-by: GurukiranP --- mock-relying-party-ui/public/locales/ar.json | 3 ++- mock-relying-party-ui/public/locales/en.json | 3 ++- mock-relying-party-ui/public/locales/hi.json | 3 ++- mock-relying-party-ui/public/locales/km.json | 3 ++- mock-relying-party-ui/public/locales/kn.json | 3 ++- mock-relying-party-ui/public/locales/ta.json | 3 ++- 6 files changed, 12 insertions(+), 6 deletions(-) diff --git a/mock-relying-party-ui/public/locales/ar.json b/mock-relying-party-ui/public/locales/ar.json index fa36edd4..7058e6a8 100644 --- a/mock-relying-party-ui/public/locales/ar.json +++ b/mock-relying-party-ui/public/locales/ar.json @@ -250,6 +250,7 @@ "invalid_dpop_proof": "لم نتمكن من إتمام المصادقة. يرجى المحاولة مرة أخرى", "code_challenge_failed": "فشل في إنشاء تحدي الشفرة. يرجى المحاولة مرة أخرى.", "login_required": "تعذر إكمال تسجيل الدخول. يرجى المحاولة مرة أخرى.", - "request_not_supported": "لم نتمكن من معالجة طلبك. يرجى المحاولة مرة أخرى أو الاتصال بالمسؤول إذا استمرت المشكلة." + "request_not_supported": "لم نتمكن من معالجة طلبك. يرجى المحاولة مرة أخرى أو الاتصال بالمسؤول إذا استمرت المشكلة.", + "grant_exchange_failed": "تعذر التفويض. يرجى المحاولة مرة أخرى." } } diff --git a/mock-relying-party-ui/public/locales/en.json b/mock-relying-party-ui/public/locales/en.json index a59f6285..4027c412 100644 --- a/mock-relying-party-ui/public/locales/en.json +++ b/mock-relying-party-ui/public/locales/en.json @@ -251,6 +251,7 @@ "invalid_dpop_proof": "Authentication could not be completed. Please try again", "code_challenge_failed": "Failed to generate code challenge. Please try again.", "login_required": "Unable to complete sign-in. Please try again.", - "request_not_supported": "We couldn’t process your request. Please try again or contact admin if the issue continues." + "request_not_supported": "We couldn’t process your request. Please try again or contact admin if the issue continues.", + "grant_exchange_failed": "Unable to Authorize. Please try again." } } diff --git a/mock-relying-party-ui/public/locales/hi.json b/mock-relying-party-ui/public/locales/hi.json index cb085ec8..211908db 100644 --- a/mock-relying-party-ui/public/locales/hi.json +++ b/mock-relying-party-ui/public/locales/hi.json @@ -249,6 +249,7 @@ "invalid_dpop_proof": "प्रमाणीकरण पूरा नहीं हो सका। कृपया पुनः प्रयास करें", "code_challenge_failed": "कोड चुनौती उत्पन्न करने में विफल। कृपया पुनः प्रयास करें।", "login_required": "साइन-इन पूरा नहीं हो सका। कृपया पुनः प्रयास करें।", - "request_not_supported": "हम आपके अनुरोध को संसाधित नहीं कर सके। कृपया पुनः प्रयास करें या समस्या जारी रहने पर व्यवस्थापक से संपर्क करें।" + "request_not_supported": "हम आपके अनुरोध को संसाधित नहीं कर सके। कृपया पुनः प्रयास करें या समस्या जारी रहने पर व्यवस्थापक से संपर्क करें।", + "grant_exchange_failed": "प्राधिकरण में असमर्थ। कृपया पुनः प्रयास करें।" } } diff --git a/mock-relying-party-ui/public/locales/km.json b/mock-relying-party-ui/public/locales/km.json index 9c14d869..02a669fe 100644 --- a/mock-relying-party-ui/public/locales/km.json +++ b/mock-relying-party-ui/public/locales/km.json @@ -251,6 +251,7 @@ "invalid_dpop_proof": "ការផ្ទៀងផ្ទាត់មិនអាចបញ្ចប់បាន។ សូមព្យាយាមម្ដងទៀត", "code_challenge_failed": "ការបង្កើតការប្រឈមកូដបានបរាជ័យ។ សូមព្យាយាមម្ដងទៀត។", "login_required": "មិនអាចបញ្ចប់ការចូលបានទេ។ សូមព្យាយាមម្តងទៀត។", - "request_not_supported": "យើងមិនអាចដំណើរការសំណើរបស់អ្នកបានទេ។ សូមព្យាយាមម្តងទៀត ឬទាក់ទងអ្នកគ្រប់គ្រង ប្រសិនបើបញ្ហានៅតែបន្ត។" + "request_not_supported": "យើងមិនអាចដំណើរការសំណើរបស់អ្នកបានទេ។ សូមព្យាយាមម្តងទៀត ឬទាក់ទងអ្នកគ្រប់គ្រង ប្រសិនបើបញ្ហានៅតែបន្ត។", + "grant_exchange_failed": "មិនអាចអនុញ្ញាតបានទេ។ សូមព្យាយាមម្តងទៀត។" } } diff --git a/mock-relying-party-ui/public/locales/kn.json b/mock-relying-party-ui/public/locales/kn.json index 26c5348e..86b3815b 100644 --- a/mock-relying-party-ui/public/locales/kn.json +++ b/mock-relying-party-ui/public/locales/kn.json @@ -249,6 +249,7 @@ "invalid_dpop_proof": "ಪ್ರಾಮಾಣೀಕರಣವನ್ನು ಪೂರ್ಣಗೊಳಿಸಲಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೊಮ್ಮೆ ಪ್ರಯತ್ನಿಸಿ", "code_challenge_failed": "ಕೋಡ್ ಚಾಲೆಂಜ್ ರಚಿಸಲು ವಿಫಲವಾಗಿದೆ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", "login_required": "ಲಾಗಿನ್ ಪೂರ್ಣಗೊಳಿಸಲು ಸಾಧ್ಯವಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ.", - "request_not_supported": "ನಿಮ್ಮ ವಿನಂತಿಯನ್ನು ಪ್ರಕ್ರಿಯೆಗೊಳಿಸಲು ಸಾಧ್ಯವಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಸಮಸ್ಯೆ ಮುಂದುವರಿದರೆ ನಿರ್ವಾಹಕರನ್ನು ಸಂಪರ್ಕಿಸಿ." + "request_not_supported": "ನಿಮ್ಮ ವಿನಂತಿಯನ್ನು ಪ್ರಕ್ರಿಯೆಗೊಳಿಸಲು ಸಾಧ್ಯವಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಸಮಸ್ಯೆ ಮುಂದುವರಿದರೆ ನಿರ್ವಾಹಕರನ್ನು ಸಂಪರ್ಕಿಸಿ.", + "grant_exchange_failed": "ಅಧಿಕೃತಗೊಳಿಸಲು ಸಾಧ್ಯವಾಗಲಿಲ್ಲ. ದಯವಿಟ್ಟು ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ." } } diff --git a/mock-relying-party-ui/public/locales/ta.json b/mock-relying-party-ui/public/locales/ta.json index 533231af..14ffbd76 100644 --- a/mock-relying-party-ui/public/locales/ta.json +++ b/mock-relying-party-ui/public/locales/ta.json @@ -249,6 +249,7 @@ "invalid_dpop_proof": "அங்கீகாரம் முடிக்க முடியவில்லை. மீண்டும் முயற்சிக்கவும்", "code_challenge_failed": "கோட் சவால் உருவாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும்.", "login_required": "உள்நுழைவு முடிக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும்.", - "request_not_supported": "உங்கள் கோரிக்கையை செயலாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும் அல்லது பிரச்சனை தொடர்ந்து இருந்தால் நிர்வாகியை தொடர்புகொள்ளவும்." + "request_not_supported": "உங்கள் கோரிக்கையை செயலாக்க முடியவில்லை. தயவுசெய்து மீண்டும் முயற்சிக்கவும் அல்லது பிரச்சனை தொடர்ந்து இருந்தால் நிர்வாகியை தொடர்புகொள்ளவும்.", + "grant_exchange_failed": "அங்கீகரிக்க இயலவில்லை. மீண்டும் முயற்சிக்கவும்." } } From f7860fb7ca970ae31f521fc1792b9b302a43960e Mon Sep 17 00:00:00 2001 From: Abhi Date: Wed, 20 May 2026 15:44:11 +0530 Subject: [PATCH 16/35] [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock Signed-off-by: Abhi --- db_scripts/mosip_mockidentitysystem/db.sql | 6 +++--- db_scripts/mosip_mockidentitysystem/ddl.sql | 2 +- .../mosip_mockidentitysystem/deploy.properties | 1 + db_scripts/mosip_mockidentitysystem/deploy.sh | 14 +++++++------- db_scripts/mosip_mockidentitysystem/dml.sql | 2 +- db_scripts/mosip_mockidentitysystem/drop_db.sql | 2 +- db_scripts/mosip_mockidentitysystem/drop_role.sql | 2 +- db_scripts/mosip_mockidentitysystem/grants.sql | 12 ++++++------ .../mosip_mockidentitysystem/role_dbuser.sql | 2 +- deploy/postgres/init_values.yaml | 7 ++++++- 10 files changed, 28 insertions(+), 22 deletions(-) diff --git a/db_scripts/mosip_mockidentitysystem/db.sql b/db_scripts/mosip_mockidentitysystem/db.sql index cfb39611..6bcdf3ed 100644 --- a/db_scripts/mosip_mockidentitysystem/db.sql +++ b/db_scripts/mosip_mockidentitysystem/db.sql @@ -1,4 +1,4 @@ -CREATE DATABASE mosip_mockidentitysystem +CREATE DATABASE :mosipdbname ENCODING = 'UTF8' LC_COLLATE = 'en_US.UTF-8' LC_CTYPE = 'en_US.UTF-8' @@ -6,12 +6,12 @@ CREATE DATABASE mosip_mockidentitysystem OWNER = postgres TEMPLATE = template0; -COMMENT ON DATABASE mosip_mockidentitysystem IS 'Mock identity related data is stored in this database'; +COMMENT ON DATABASE :mosipdbname IS 'Mock identity related data is stored in this database'; \c mosip_mockidentitysystem postgres DROP SCHEMA IF EXISTS mockidentitysystem CASCADE; CREATE SCHEMA mockidentitysystem; ALTER SCHEMA mockidentitysystem OWNER TO postgres; -ALTER DATABASE mosip_mockidentitysystem SET search_path TO mockidentitysystem,pg_catalog,public; +ALTER DATABASE :mosipdbname SET search_path TO mockidentitysystem,pg_catalog,public; diff --git a/db_scripts/mosip_mockidentitysystem/ddl.sql b/db_scripts/mosip_mockidentitysystem/ddl.sql index 4d0a67f2..39f9c599 100644 --- a/db_scripts/mosip_mockidentitysystem/ddl.sql +++ b/db_scripts/mosip_mockidentitysystem/ddl.sql @@ -1,4 +1,4 @@ -\c mosip_mockidentitysystem +\c :mosipdbname \ir ddl/mockidentitysystem-mock_identity.sql \ir ddl/mockidentitysystem-kyc_auth.sql diff --git a/db_scripts/mosip_mockidentitysystem/deploy.properties b/db_scripts/mosip_mockidentitysystem/deploy.properties index 787a3d4d..64f0de81 100644 --- a/db_scripts/mosip_mockidentitysystem/deploy.properties +++ b/db_scripts/mosip_mockidentitysystem/deploy.properties @@ -3,4 +3,5 @@ DB_PORT=5432 SU_USER=postgres DEFAULT_DB_NAME=postgres MOSIP_DB_NAME=mosip_mockidentitysystem +DB_UNAME=mockidsystemuser DML_FLAG=1 diff --git a/db_scripts/mosip_mockidentitysystem/deploy.sh b/db_scripts/mosip_mockidentitysystem/deploy.sh index ef9cc3c0..c3627008 100644 --- a/db_scripts/mosip_mockidentitysystem/deploy.sh +++ b/db_scripts/mosip_mockidentitysystem/deploy.sh @@ -21,24 +21,24 @@ CONN=$(PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --hos echo "Terminated connections" ## Drop db and role -PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f drop_db.sql -PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f drop_role.sql +PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f drop_db.sql -v mosipdbname=$MOSIP_DB_NAME +PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f drop_role.sql -v dbuname=$DB_UNAME ## Create users echo `date "+%m/%d/%Y %H:%M:%S"` ": Creating database users" | tee -PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f role_dbuser.sql -v dbuserpwd=\'$DBUSER_PWD\' +PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f role_dbuser.sql -v dbuserpwd=\'$DBUSER_PWD\' -v dbuname=$DB_UNAME ## Create DB -PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f db.sql -PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f ddl.sql +PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f db.sql -v mosipdbname=$MOSIP_DB_NAME +PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f ddl.sql -v mosipdbname=$MOSIP_DB_NAME -v dbuname=$DB_UNAME ## Grants -PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f grants.sql +PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -f grants.sql -v mosipdbname=$MOSIP_DB_NAME -v dbuname=$DB_UNAME ## Populate tables if [ ${DML_FLAG} == 1 ] then echo `date "+%m/%d/%Y %H:%M:%S"` ": Deploying DML for ${MOSIP_DB_NAME} database" - PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -a -b -f dml.sql + PGPASSWORD=$SU_USER_PWD psql -v ON_ERROR_STOP=1 --username=$SU_USER --host=$DB_SERVERIP --port=$DB_PORT --dbname=$DEFAULT_DB_NAME -a -b -f dml.sql -v mosipdbname=$MOSIP_DB_NAME fi diff --git a/db_scripts/mosip_mockidentitysystem/dml.sql b/db_scripts/mosip_mockidentitysystem/dml.sql index 2ab890c1..60b20272 100644 --- a/db_scripts/mosip_mockidentitysystem/dml.sql +++ b/db_scripts/mosip_mockidentitysystem/dml.sql @@ -1,3 +1,3 @@ -\c mosip_mockidentitysystem +\c :mosipdbname \COPY mockidentitysystem.key_policy_def (APP_ID,KEY_VALIDITY_DURATION,PRE_EXPIRE_DAYS,ACCESS_ALLOWED,IS_ACTIVE,CR_BY,CR_DTIMES) FROM './dml/mockidentitysystem-key_policy_def.csv' delimiter ',' HEADER csv; diff --git a/db_scripts/mosip_mockidentitysystem/drop_db.sql b/db_scripts/mosip_mockidentitysystem/drop_db.sql index e82db168..36d0a024 100644 --- a/db_scripts/mosip_mockidentitysystem/drop_db.sql +++ b/db_scripts/mosip_mockidentitysystem/drop_db.sql @@ -1,2 +1,2 @@ -DROP DATABASE IF EXISTS mosip_mockidentitysystem; +DROP DATABASE IF EXISTS :mosipdbname; diff --git a/db_scripts/mosip_mockidentitysystem/drop_role.sql b/db_scripts/mosip_mockidentitysystem/drop_role.sql index 9eeb7a2b..0f6cc8f5 100644 --- a/db_scripts/mosip_mockidentitysystem/drop_role.sql +++ b/db_scripts/mosip_mockidentitysystem/drop_role.sql @@ -1 +1 @@ -drop role if exists mockidsystemuser; +drop role if exists :dbuname; diff --git a/db_scripts/mosip_mockidentitysystem/grants.sql b/db_scripts/mosip_mockidentitysystem/grants.sql index cac28cee..a9defe34 100644 --- a/db_scripts/mosip_mockidentitysystem/grants.sql +++ b/db_scripts/mosip_mockidentitysystem/grants.sql @@ -1,17 +1,17 @@ -\c mosip_mockidentitysystem +\c :mosipdbname GRANT CONNECT - ON DATABASE mosip_mockidentitysystem - TO mockidsystemuser; + ON DATABASE :mosipdbname + TO :dbuname; GRANT USAGE ON SCHEMA mockidentitysystem - TO mockidsystemuser; + TO :dbuname; GRANT SELECT,INSERT,UPDATE,DELETE,TRUNCATE,REFERENCES ON ALL TABLES IN SCHEMA mockidentitysystem - TO mockidsystemuser; + TO :dbuname; ALTER DEFAULT PRIVILEGES IN SCHEMA mockidentitysystem - GRANT SELECT,INSERT,UPDATE,DELETE,REFERENCES ON TABLES TO mockidsystemuser; + GRANT SELECT,INSERT,UPDATE,DELETE,REFERENCES ON TABLES TO :dbuname; diff --git a/db_scripts/mosip_mockidentitysystem/role_dbuser.sql b/db_scripts/mosip_mockidentitysystem/role_dbuser.sql index aa266f80..a84bca18 100644 --- a/db_scripts/mosip_mockidentitysystem/role_dbuser.sql +++ b/db_scripts/mosip_mockidentitysystem/role_dbuser.sql @@ -1,4 +1,4 @@ -CREATE ROLE mockidsystemuser WITH +CREATE ROLE :dbuname WITH INHERIT LOGIN PASSWORD :dbuserpwd; diff --git a/deploy/postgres/init_values.yaml b/deploy/postgres/init_values.yaml index ce4ca7d9..626284f9 100644 --- a/deploy/postgres/init_values.yaml +++ b/deploy/postgres/init_values.yaml @@ -4,7 +4,11 @@ databases: mosip_mockidentitysystem: enabled: true - host: "postgres-postgresql.postgres" + scriptsDir: mosip_mockidentitysystem # fixed - must match db_scripts/ folder in repo + dbName: mosip_mockidentitysystem # customize e.g. mosip_mockidentitysystem02 + dbUser: mockidentityuser # customize e.g. mockidentityuser02 + defaultDb: postgres + host: "postgres-postgresql" port: 5432 su: user: postgres @@ -12,6 +16,7 @@ databases: name: postgres-postgresql key: postgres-password dml: 1 + repoUrl: https://github.com/mosip/esignet-mock-services.git branch: develop mosip_master: From b11566a9f2a2b1ac128c82f4c1d4f2fe5a2ff124 Mon Sep 17 00:00:00 2001 From: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> Date: Thu, 21 May 2026 09:57:03 +0530 Subject: [PATCH 17/35] [MOSIP-37808] Updated DB attributes of MOSIP esignet-mock (#579) Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> --- db_scripts/mosip_mockidentitysystem/db.sql | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/db_scripts/mosip_mockidentitysystem/db.sql b/db_scripts/mosip_mockidentitysystem/db.sql index 6bcdf3ed..7580bda0 100644 --- a/db_scripts/mosip_mockidentitysystem/db.sql +++ b/db_scripts/mosip_mockidentitysystem/db.sql @@ -8,10 +8,9 @@ CREATE DATABASE :mosipdbname COMMENT ON DATABASE :mosipdbname IS 'Mock identity related data is stored in this database'; -\c mosip_mockidentitysystem postgres +\c :mosipdbname postgres DROP SCHEMA IF EXISTS mockidentitysystem CASCADE; CREATE SCHEMA mockidentitysystem; ALTER SCHEMA mockidentitysystem OWNER TO postgres; ALTER DATABASE :mosipdbname SET search_path TO mockidentitysystem,pg_catalog,public; - From 66c302e516524dffb856d5d4747572e932e859f8 Mon Sep 17 00:00:00 2001 From: Zeeshan Mehboob <82993262+zesu22@users.noreply.github.com> Date: Tue, 16 Jun 2026 09:32:04 +0530 Subject: [PATCH 18/35] Updating sign-in-with-esignet, removing optional parameter from config (#590) * [MODIFIED] used npm library for sign-in-with-esignet Signed-off-by: Zeeshan Mehboob * [MODIFIED] ignore optional parameter in sign-in-with-esignet Signed-off-by: Zeeshan Mehboob * [MODIFIED] readme file Signed-off-by: Zeeshan Mehboob * [MODIFIED] coderabbit comment resolved Signed-off-by: Zeeshan Mehboob * [MODIFIED] review comment addressed Signed-off-by: Zeeshan Mehboob * [MODIFIED] readme updated Signed-off-by: Zeeshan Mehboob --------- Signed-off-by: Zeeshan Mehboob --- mock-relying-party-ui/Dockerfile | 3 + mock-relying-party-ui/README.md | 63 ++++----- mock-relying-party-ui/package-lock.json | 56 ++++++-- mock-relying-party-ui/package.json | 1 + mock-relying-party-ui/src/components/Login.js | 70 +++++----- .../src/components/Registration.js | 39 ++---- .../src/components/Sidenav.js | 49 ++++--- .../src/components/SignUp.js | 31 ++--- .../src/components/UserProfile.js | 20 +-- .../src/constants/clientDetails.js | 126 ++++++++++++++---- mock-relying-party-ui/src/index.js | 3 +- .../src/services/clientService.js | 76 ----------- 12 files changed, 264 insertions(+), 273 deletions(-) delete mode 100644 mock-relying-party-ui/src/services/clientService.js diff --git a/mock-relying-party-ui/Dockerfile b/mock-relying-party-ui/Dockerfile index 3586c5ef..cd434f35 100644 --- a/mock-relying-party-ui/Dockerfile +++ b/mock-relying-party-ui/Dockerfile @@ -3,6 +3,7 @@ FROM node:16.13.2-alpine as build # Set a build-time environment variable ARG mockRpUIPublicUrl ARG esignet_ui_base_url +ARG authorize_endpoint ARG mock_relying_party_server_url ARG redirect_uri ARG redirect_uri_registration @@ -25,6 +26,7 @@ ARG dpop_callback_name ARG code_challenge ENV ESIGNET_UI_BASE_URL=$esignet_ui_base_url +ENV AUTHORIZE_ENDPOINT=$authorize_endpoint ENV MOCK_RELYING_PARTY_SERVER_URL=$mock_relying_party_server_url ENV REDIRECT_URI=$redirect_uri ENV REDIRECT_URI_REGISTRATION=$redirect_uri_registration @@ -109,6 +111,7 @@ COPY ./nginx/nginx.conf /etc/nginx/nginx.conf COPY --from=build /app/build ${work_dir} RUN echo "ESIGNET_UI_BASE_URL=$ESIGNET_UI_BASE_URL" >> ${work_dir}/env.env \ + && echo "AUTHORIZE_ENDPOINT=$AUTHORIZE_ENDPOINT" >> ${work_dir}/env.env \ && echo "MOCK_RELYING_PARTY_SERVER_URL=$MOCK_RELYING_PARTY_SERVER_URL" >> ${work_dir}/env.env \ && echo "REDIRECT_URI=$REDIRECT_URI" >> ${work_dir}/env.env \ && echo "REDIRECT_URI_REGISTRATION=$REDIRECT_URI_REGISTRATION" >> ${work_dir}/env.env \ diff --git a/mock-relying-party-ui/README.md b/mock-relying-party-ui/README.md index 4558bdd7..5091eddd 100644 --- a/mock-relying-party-ui/README.md +++ b/mock-relying-party-ui/README.md @@ -18,52 +18,37 @@ This portal contains 2 pages: The application runs on PORT=5000 by default. -- Environment Variables: - - - ESIGNET_UI_BASE_URL: MOSIP ESIGNET UI URL - (Example:https://esignet.dev.mosip.net/) - - MOCK_RELYING_PARTY_SERVER_URL: Internally resolved to the mock relying party server via internal NGINX - (Example:http://esignet.dev.mosip.net/mock-relying-party-server) - - REDIRECT_URI: Redirect URI passed as a parameter in the authorization request - (Example:https://health-services.com/userprofile) - - CLIENT_ID: Relying party client ID registered with MOSIP (Example:health-services) - - ACRS: Passed in the `acr_values` parameter in the authorization request (Example:mosip:esignet:acr:generated-code) - - MAX_AGE: Maximum duration (in seconds) for which a cached resource is considered valid before revalidation - (Example:max_age:21) - - DISPLAY: Specifies how the authorization server displays the authentication and consent screen. - Possible values: page, popup, wap, touch - (Example: display:page) - - PROMPT: Specifies the type of prompt to show during the authentication flow - (Example: prompt:consent) - - GRANT_TYPE: OAuth 2.0 grant type used to request access tokens - (Example: grant_type: authorization_code) - - SIGN_IN_BUTTON_PLUGIN_URL: URL for the sign-in button plugin - - SCOPE_USER_PROFILE: List of scopes requested during the authentication request - (Example: scope_user_profile: openid%20profile%20resident-service) - - PAR_CALLBACK_NAME: **Feature flag** to enable PAR (Pushed Authorization Request) flow - Required value: `get_requestUri` (hardcoded function name - not configurable) - - PAR_CALLBACK_TIMEOUT: Timeout for PAR callback in milliseconds(`optional`. Default value is 5 seconds) - (Example: par_callback_timeout: 5000) - - DPOP_CALLBACK_NAME: **Feature flag** to enable DPoP (Demonstration of Proof-of-Possession) flow - Required value: `get_dpop_jkt` (hardcoded function name - not configurable) - - CODE_CHALLENGE: **Feature flag** to enable PKCE (Proof Key for Code Exchange) flow - Required value: `get_code_challenge` (hardcoded function name - not configurable) - When enabled, the PKCE method is automatically fetched from the authorization server's `.well-known/openid-configuration` endpoint - - > **Important:** PAR_CALLBACK_NAME, DPOP_CALLBACK_NAME, and CODE_CHALLENGE act as feature toggles. The values correspond to hardcoded function names in the codebase and are not configurable. Include these variables to enable the respective flows, or omit them to disable the functionality. +### Configuration Environment Variables + +| Variable Name | Description | Example / Allowed Values | Type / Notes | +| :-------------------------------- | :------------------------------------------------------------------------------------------------ | :------------------------------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| **ESIGNET_UI_BASE_URL** | MOSIP ESIGNET UI URL | `https://esignet.dev.mosip.net/` | Required | +| **MOCK_RELYING_PARTY_SERVER_URL** | Internally resolved to the mock relying party server via internal NGINX | `http://esignet.dev.mosip.net/mock-relying-party-server` | Required | +| **AUTHORIZE_ENDPOINT** | Authorize enpoint route | `/authorize` | Required | +| **REDIRECT_URI** | Redirect URI passed as a parameter in the authorization request | `https://health-services.com/userprofile` | Required | +| **CLIENT_ID** | Relying party client ID registered with MOSIP | `health-services` | Required | +| **ACRS** | Passed in the `acr_values` parameter in the authorization request | `mosip:esignet:acr:generated-code` | Required | +| **SCOPE_USER_PROFILE** | List of URL-encoded scopes requested during the authentication request | `openid%20profile%20resident-service` | Required | +| **GRANT_TYPE** | OAuth 2.0 grant type used to request access tokens | `authorization_code` | Required | +| **MAX_AGE** | Maximum duration (in seconds) for which a cached resource is considered valid before revalidation | `21` | Optional | +| **DISPLAY** | Specifies how the authorization server displays the authentication and consent screen | `page`, `popup`, `wap`, `touch` (e.g., `page`) | Optional | +| **PROMPT** | Specifies the type of prompt to show during the authentication flow | `consent` | Optional | +| **PAR_CALLBACK_NAME** | **Feature flag** to enable PAR (Pushed Authorization Request) flow | `get_requestUri` | Hardcoded function name - not configurable | +| **PAR_CALLBACK_TIMEOUT** | Timeout for PAR callback in milliseconds | `5000` | Optional (Default: `5000` / 5s) | +| **DPOP_CALLBACK_NAME** | **Feature flag** to enable DPoP (Demonstration of Proof-of-Possession) flow | `get_dpop_jkt` | Hardcoded function name - not configurable | +| **CODE_CHALLENGE** | **Feature flag** to enable PKCE (Proof Key for Code Exchange) flow | `get_code_challenge` | Hardcoded function name - not configurable.

When enabled, the PKCE method is automatically fetched from the server's `.well-known/openid-configuration` endpoint. | - Build and run Docker for a service: - ``` + ```bash $ docker build -t : . - $ docker run -it -d -p 5000:5000 -e ESIGNET_UI_BASE_URL='http://localhost:3000' -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 -e REDIRECT_URI=http://localhost:5000/userprofile -e CLIENT_ID=healthservices -e ACRS="mosip:esignet:acr:static-code" -e MAX_AGE=21 -e DISPLAY=page -e PROMPT=consent -e GRANT_TYPE=authorization_code -e SIGN_IN_BUTTON_PLUGIN_URL='http://127.0.0.1:5500/dist/iife/index.js' -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' -e PAR_CALLBACK_NAME='get_requestUri' -e DPOP_CALLBACK_NAME='get_dpop_jkt' -e CODE_CHALLENGE='get_code_challenge' : + $ docker run -it -d -p 5000:5000 -e ESIGNET_UI_BASE_URL='http://localhost:3000' -e MOCK_RELYING_PARTY_SERVER_URL=http://localhost:8888 -e REDIRECT_URI=http://localhost:5000/userprofile -e CLIENT_ID=healthservices -e ACRS="mosip:esignet:acr:static-code" -e MAX_AGE=21 -e DISPLAY=page -e PROMPT=consent -e GRANT_TYPE=authorization_code -e AUTHORIZE_ENDPOINT=/authorize -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' -e PAR_CALLBACK_NAME='get_requestUri' -e DPOP_CALLBACK_NAME='get_dpop_jkt' -e CODE_CHALLENGE='get_code_challenge' : ``` To host the mock relying party UI on a context path: - 1. In the NGINX configuration file, remove the `/` location block and add a new one with the desired context path: - ``` + ```nginx location /healthservices { alias /usr/share/nginx/healthservices; try_files $uri $uri/ /healthservices/index.html; @@ -72,7 +57,7 @@ The application runs on PORT=5000 by default. 2. Pass the context path in the environment variable `MOCK_RP_UI_PUBLIC_URL` during `docker run`. - ``` + ```bash $ docker build -t : . $ docker run -it -d -p 3000:3000 -e MOCK_RP_UI_PUBLIC_URL='healthservices' : @@ -81,7 +66,7 @@ The application runs on PORT=5000 by default. - Build and run on local system: Update the "/mock-relying-party-ui/public/env-config.js" file with the required values, then run: - ``` + ```bash $ npm start ``` diff --git a/mock-relying-party-ui/package-lock.json b/mock-relying-party-ui/package-lock.json index 3fdaa8b9..828ad775 100644 --- a/mock-relying-party-ui/package-lock.json +++ b/mock-relying-party-ui/package-lock.json @@ -9,7 +9,8 @@ "version": "0.1.0", "dependencies": { "@emotion/react": "^11.10.4", - "axios": "^1.12.0", + "@mosip/sign-in-with-esignet": "^0.1.1-beta.0", + "axios": "^1.13.5", "cors": "^2.8.5", "cra-template": "1.1.3", "i18next": "^21.10.0", @@ -3144,6 +3145,12 @@ "integrity": "sha512-Vo+PSpZG2/fmgmiNzYK9qWRh8h/CHrwD0mo1h1DzL4yzHNSfWYujGTYsWGreD000gcgmZ7K4Ys6Tx9TxtsKdDw==", "license": "MIT" }, + "node_modules/@mosip/sign-in-with-esignet": { + "version": "0.1.1-beta.0", + "resolved": "https://registry.npmjs.org/@mosip/sign-in-with-esignet/-/sign-in-with-esignet-0.1.1-beta.0.tgz", + "integrity": "sha512-gBlift3oPuI18wAon6HiEfFUwwOfP8zAvOgv49l9CCV06en6BzDaeR+QWJPDo+M2FDjalvkul05pytJVntAs4w==", + "license": "MPL-2.0" + }, "node_modules/@nicolo-ribaudo/eslint-scope-5-internals": { "version": "5.1.1-v1", "resolved": "https://registry.npmjs.org/@nicolo-ribaudo/eslint-scope-5-internals/-/eslint-scope-5-internals-5.1.1-v1.tgz", @@ -5047,14 +5054,15 @@ } }, "node_modules/axios": { - "version": "1.13.2", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.13.2.tgz", - "integrity": "sha512-VPk9ebNqPcy5lRGuSlKx752IlDatOjT9paPlm8A7yOuW2Fbvp4X3JznJtT4f0GzGLLiWE9W8onz51SqLYwzGaA==", + "version": "1.17.0", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.17.0.tgz", + "integrity": "sha512-J8SwNxprqqpbfenehxWYXE7CW+wM1BB4w3+N+g+/Wx40xM4rsLrfPmHHxSWIxJLYDgSY/HqlFPIYb2/S3rxafw==", "license": "MIT", "dependencies": { - "follow-redirects": "^1.15.6", - "form-data": "^4.0.4", - "proxy-from-env": "^1.1.0" + "follow-redirects": "^1.16.0", + "form-data": "^4.0.5", + "https-proxy-agent": "^5.0.1", + "proxy-from-env": "^2.1.0" } }, "node_modules/axobject-query": { @@ -8489,9 +8497,9 @@ "license": "ISC" }, "node_modules/follow-redirects": { - "version": "1.15.11", - "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.11.tgz", - "integrity": "sha512-deG2P0JfjrTxl50XGCDyfI97ZGVCxIpfKYmfyrQ54n5FO/0gfIES8C/Psl6kWVDolizcaaxZJnTS0QSMxvnsBQ==", + "version": "1.16.0", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.16.0.tgz", + "integrity": "sha512-y5rN/uOsadFT/JfYwhxRS5R7Qce+g3zG97+JrtFZlC9klX/W5hD7iiLzScI4nZqUS7DNUdhPgw4xI8W2LuXlUw==", "funding": [ { "type": "individual", @@ -14159,10 +14167,13 @@ } }, "node_modules/proxy-from-env": { - "version": "1.1.0", - "resolved": "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-1.1.0.tgz", - "integrity": "sha512-D+zkORCbA9f1tdWRK0RaCR3GPv50cMxcrz4X8k5LTSUD1Dkw47mKJEZQNunItRTkWwgtaUSo1RVFRIG9ZXiFYg==", - "license": "MIT" + "version": "2.1.0", + "resolved": "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-2.1.0.tgz", + "integrity": "sha512-cJ+oHTW1VAEa8cJslgmUZrc+sjRKgAKl3Zyse6+PV38hZe/V6Z14TbCuXcan9F9ghlz4QrFr2c92TNF82UkYHA==", + "license": "MIT", + "engines": { + "node": ">=10" + } }, "node_modules/psl": { "version": "1.15.0", @@ -16872,6 +16883,23 @@ } } }, + "node_modules/tailwindcss/node_modules/yaml": { + "version": "2.9.0", + "resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.0.tgz", + "integrity": "sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==", + "license": "ISC", + "optional": true, + "peer": true, + "bin": { + "yaml": "bin.mjs" + }, + "engines": { + "node": ">= 14.6" + }, + "funding": { + "url": "https://github.com/sponsors/eemeli" + } + }, "node_modules/tapable": { "version": "2.3.0", "resolved": "https://registry.npmjs.org/tapable/-/tapable-2.3.0.tgz", diff --git a/mock-relying-party-ui/package.json b/mock-relying-party-ui/package.json index 6c736403..2409ace8 100644 --- a/mock-relying-party-ui/package.json +++ b/mock-relying-party-ui/package.json @@ -4,6 +4,7 @@ "private": true, "dependencies": { "@emotion/react": "^11.10.4", + "@mosip/sign-in-with-esignet": "^0.1.1-beta.0", "axios": "^1.13.5", "cors": "^2.8.5", "cra-template": "1.1.3", diff --git a/mock-relying-party-ui/src/components/Login.js b/mock-relying-party-ui/src/components/Login.js index 2c58a8af..f9cf0ca3 100644 --- a/mock-relying-party-ui/src/components/Login.js +++ b/mock-relying-party-ui/src/components/Login.js @@ -2,27 +2,29 @@ import { useEffect, useState } from "react"; import { Error } from "../common/Errors"; import { useTranslation } from "react-i18next"; import { useSearchParams } from "react-router-dom"; -import clientDetails from "../constants/clientDetails"; -import { useExternalScript } from "../hooks/useExternalScript"; +import { getOidcConfig } from "../constants/clientDetails"; import relyingPartyService from "../services/relyingPartyService"; +import { init } from "@mosip/sign-in-with-esignet"; export default function Login({ i18nKeyPrefix = "login" }) { const { i18n, t } = useTranslation("translation", { keyPrefix: i18nKeyPrefix, }); - const [searchParams, setSearchParams] = useSearchParams(); + const [searchParams] = useSearchParams(); const [error, setError] = useState(null); - const signInButtonScript = window._env_.SIGN_IN_BUTTON_PLUGIN_URL; - const state = useExternalScript(signInButtonScript); - + useEffect(() => { const getSearchParams = async () => { - let errorCode = searchParams.get("error"); - let error_desc = searchParams.get("error_description"); + const errorCode = searchParams.get("error"); + const error_desc = searchParams.get("error_description"); if (errorCode) { - setError({ errorCode: errorCode, errorMsg: error_desc, showToast: true }); + setError({ + errorCode: errorCode, + errorMsg: error_desc, + showToast: true, + }); } }; getSearchParams(); @@ -32,39 +34,25 @@ export default function Login({ i18nKeyPrefix = "login" }) { i18n.on("languageChanged", function (lng) { renderSignInButton(); }); - }, [state]); + }, []); const renderSignInButton = () => { - const oidcConfig = { - authorizeUri: clientDetails.uibaseUrl + clientDetails.authorizeEndpoint, - redirect_uri: clientDetails.redirect_uri_userprofile, - client_id: clientDetails.clientId, - scope: clientDetails.scopeUserProfile, - nonce: clientDetails.nonce, - state: clientDetails.state, - acr_values: clientDetails.acr_values, - claims_locales: clientDetails.claims_locales, - display: clientDetails.display, - prompt: clientDetails.prompt, - max_age: clientDetails.max_age, + const oidcConfig = getOidcConfig({ + isRegistration: false, ui_locales: i18n.language, - claims: JSON.parse(decodeURIComponent(clientDetails.userProfileClaims)), - par_callback: relyingPartyService[clientDetails.par_callback_name], - par_callback_timeout: clientDetails.par_callback_timeout, - dpop_callback: relyingPartyService[clientDetails.dpop_callback_name], - code_challenge: relyingPartyService[clientDetails.code_challenge], - }; + relyingPartyService, + }); - window.SignInWithEsignetButton?.init({ + init({ oidcConfig: oidcConfig, buttonConfig: { shape: "soft_edges", labelText: t("sign_in_with"), - width: "100%" + width: "100%", }, signInElement: document.getElementById("sign-in-with-esignet"), }); - } + }; const handleLogin = (e) => { e.preventDefault(); @@ -81,8 +69,10 @@ export default function Login({ i18nKeyPrefix = "login" }) {
- +
- + {error && ( - + )}
@@ -127,7 +123,7 @@ export default function Login({ i18nKeyPrefix = "login" }) {
- {state === "ready" &&
} +

diff --git a/mock-relying-party-ui/src/components/Registration.js b/mock-relying-party-ui/src/components/Registration.js index b487e45c..26dca39e 100644 --- a/mock-relying-party-ui/src/components/Registration.js +++ b/mock-relying-party-ui/src/components/Registration.js @@ -1,10 +1,11 @@ import { useEffect, useState } from "react"; import { useSearchParams } from "react-router-dom"; import { Error } from "../common/Errors"; -import clientDetails from "../constants/clientDetails"; +import { clientDetails, getOidcConfig } from "../constants/clientDetails"; import { LoadingStates as states } from "../constants/states"; import LoadingIndicator from "../common/LoadingIndicator"; import { useTranslation } from "react-i18next"; +import { init } from "@mosip/sign-in-with-esignet"; export default function Registration({ relyingPartyService, @@ -64,33 +65,22 @@ export default function Registration({ }, []); const renderSignInButton = () => { - - const oidcConfig = { - authorizeUri: clientDetails.uibaseUrl + clientDetails.authorizeEndpoint, - redirect_uri: clientDetails.redirect_uri_registration, - client_id: clientDetails.clientId, - scope: clientDetails.scopeRegistration, - nonce: clientDetails.nonce, - state: clientDetails.state, - acr_values: clientDetails.acr_values, - claims_locales: clientDetails.claims_locales, - display: clientDetails.display, - prompt: clientDetails.prompt, - max_age: clientDetails.max_age, + const oidcConfig = getOidcConfig({ + isRegistration: true, ui_locales: i18n.language, - claims: JSON.parse(decodeURIComponent(clientDetails.registrationClaims)), - }; + relyingPartyService, + }); - window.SignInWithEsignetButton?.init({ + init({ oidcConfig: oidcConfig, buttonConfig: { shape: "soft_edges", labelText: t("fetch_details"), - width: "100%" + width: "100%", }, signInElement: document.getElementById("sign-in-with-esignet"), }); - } + }; //Handle Login API Integration here const getUserDetails = async (authCode) => { @@ -98,17 +88,17 @@ export default function Registration({ setUserInfo(null); try { - let client_id = clientDetails.clientId; - let redirect_uri = clientDetails.redirect_uri_registration; - let grant_type = clientDetails.grant_type; + const client_id = clientDetails.clientId; + const redirect_uri = clientDetails.redirect_uri_registration; + const grant_type = clientDetails.grant_type; var userInfo = await post_fetchUserInfo( authCode, client_id, redirect_uri, - grant_type + grant_type, ); - let address = getAddress(userInfo?.address); + const address = getAddress(userInfo?.address); setAddress(address); setUserInfo(userInfo); setEmailAddress(userInfo?.email_verified ?? userInfo?.email); @@ -252,7 +242,6 @@ export default function Registration({

-
diff --git a/mock-relying-party-ui/src/components/Sidenav.js b/mock-relying-party-ui/src/components/Sidenav.js index 879a2e8a..e2062e87 100644 --- a/mock-relying-party-ui/src/components/Sidenav.js +++ b/mock-relying-party-ui/src/components/Sidenav.js @@ -1,7 +1,7 @@ import { useTranslation } from "react-i18next"; import React, { useState, useEffect, useRef } from "react"; import { Link, useNavigate, useSearchParams } from "react-router-dom"; -import clientDetails from "../constants/clientDetails"; +import { clientDetails } from "../constants/clientDetails"; import { LoadingStates as states } from "../constants/states"; import Select from "react-select"; import LoadingIndicator from "../common/LoadingIndicator"; @@ -65,7 +65,7 @@ export default function Sidenav({ }; useEffect(() => { - let lang = langOptions?.find((option) => { + const lang = langOptions?.find((option) => { return option.value === i18n.language; }); setSelectedLang(lang); @@ -73,7 +73,7 @@ export default function Sidenav({ //Gets fired when changeLanguage got called. i18n.on("languageChanged", function (lng) { - let lang = langOptions.find((option) => { + const lang = langOptions.find((option) => { return option.value === lng; }); setSelectedLang(lang); @@ -85,10 +85,10 @@ export default function Sidenav({ if (hasFetchedRef.current) return; hasFetchedRef.current = true; - let authCode = searchParams.get("code"); - let errorCode = searchParams.get("error"); - let error_desc = searchParams.get("error_description"); - let state = searchParams.get("state"); + const authCode = searchParams.get("code"); + const errorCode = searchParams.get("error"); + const error_desc = searchParams.get("error_description"); + const state = searchParams.get("state"); if (errorCode) { navigateToLogin(errorCode, error_desc); return; @@ -113,15 +113,15 @@ export default function Sidenav({ setUserInfo(null); setStatus(states.LOADING); try { - let client_id = clientDetails.clientId; - let redirect_uri = clientDetails.redirect_uri_userprofile; - let grant_type = clientDetails.grant_type; + const client_id = clientDetails.clientId; + const redirect_uri = clientDetails.redirect_uri_userprofile; + const grant_type = clientDetails.grant_type; var userInfo = await post_fetchUserInfo( authCode, state, client_id, redirect_uri, - grant_type + grant_type, ); setUserDetail(userInfo); } catch (errormsg) { @@ -137,28 +137,28 @@ export default function Sidenav({ // Checking and getting Verified claims. const setUserDetail = (userInfoResponse) => { - let addressDetails = getClaimDetails(userInfoResponse, "address"); - let address = getAddress(addressDetails.value); + const addressDetails = getClaimDetails(userInfoResponse, "address"); + const address = getAddress(addressDetails.value); setAddress(address); const emailDetails = getClaimDetails(userInfoResponse, "email"); setEmailAddress(emailDetails); - let tempUserInfo = { + const tempUserInfo = { name: getClaimDetails(userInfoResponse, "name"), email: emailAddress, phone_number: getClaimDetails(userInfoResponse, "phone_number"), gender: getClaimDetails(userInfoResponse, "gender"), address: { value: address, - verified: addressDetails.verified + verified: addressDetails.verified, }, birthdate: getClaimDetails(userInfoResponse, "birthdate"), - picture: getClaimDetails(userInfoResponse, "picture") - } + picture: getClaimDetails(userInfoResponse, "picture"), + }; setUserInfo(tempUserInfo); setStatus(states.LOADED); localStorage.setItem(userInfo_keyname, JSON.stringify(userInfoResponse)); - } + }; const getClaimDetails = (userInfo, fieldName) => { let result = { value: null, verified: false }; @@ -245,7 +245,6 @@ export default function Sidenav({ return address.substring(0, address.length - 2); }; - const verifiedIcon = ( {messagesInfo?.messages?.map((message, index) => { const pastDate = new Date( - currentDate.getTime() - message["days"] * 24 * 60 * 60 * 1000 + currentDate.getTime() - message["days"] * 24 * 60 * 60 * 1000, ); const formattedDate = new Intl.DateTimeFormat(i18n.language, { dateStyle: "full", @@ -362,7 +361,7 @@ export default function Sidenav({ {claimInfo?.claimproviders?.map((item, idx) => { const pastDate = new Date( - currentDate.getTime() - item["days"] * 24 * 60 * 60 * 1000 + currentDate.getTime() - item["days"] * 24 * 60 * 60 * 1000, ); return ( @@ -694,7 +693,9 @@ export default function Sidenav({ alt={"profile_picture"} className="h-10 w-10 ml-3 mr-3" src={ - userInfo?.picture?.value ? userInfo.picture?.value : "User-Profile-Icon.png" + userInfo?.picture?.value + ? userInfo.picture?.value + : "User-Profile-Icon.png" } />
@@ -783,9 +784,7 @@ export default function Sidenav({ {"profile_picture"}

{ renderSignInButton(); @@ -19,33 +21,22 @@ export default function SignUp({ i18nKeyPrefix = "signup" }) { }, []); const renderSignInButton = () => { - - const oidcConfig = { - authorizeUri: clientDetails.uibaseUrl + clientDetails.authorizeEndpoint, - redirect_uri: clientDetails.redirect_uri_userprofile, - client_id: clientDetails.clientId, - scope: clientDetails.scopeUserProfile, - nonce: clientDetails.nonce, - state: clientDetails.state, - acr_values: clientDetails.acr_values, - claims_locales: clientDetails.claims_locales, - display: clientDetails.display, - prompt: clientDetails.prompt, - max_age: clientDetails.max_age, + const oidcConfig = getOidcConfig({ + isRegistration: false, ui_locales: i18n.language, - claims: JSON.parse(decodeURIComponent(clientDetails.userProfileClaims)), - }; + relyingPartyService, + }); - window.SignInWithEsignetButton?.init({ + init({ oidcConfig: oidcConfig, buttonConfig: { shape: "soft_edges", labelText: t("sign_up_with"), - width: "100%" + width: "100%", }, signInElement: document.getElementById("sign-in-with-esignet"), }); - } + }; const handleLogin = (e) => { e.preventDefault(); diff --git a/mock-relying-party-ui/src/components/UserProfile.js b/mock-relying-party-ui/src/components/UserProfile.js index e289c6bb..5d638e44 100644 --- a/mock-relying-party-ui/src/components/UserProfile.js +++ b/mock-relying-party-ui/src/components/UserProfile.js @@ -1,7 +1,7 @@ import React, { useEffect, useState } from "react"; import { useNavigate, useSearchParams } from "react-router-dom"; import { Error } from "../common/Errors"; -import clientDetails from "../constants/clientDetails"; +import { clientDetails } from "../constants/clientDetails"; import { LoadingStates as states } from "../constants/states"; import LoadingIndicator from "../common/LoadingIndicator"; import { useTranslation } from "react-i18next"; @@ -42,10 +42,10 @@ export default function UserProfile({ useEffect(() => { const getSearchParams = async () => { - let authCode = searchParams.get("code"); - let errorCode = searchParams.get("error"); - let error_desc = searchParams.get("error_description"); - let state = searchParams.get("state"); + const authCode = searchParams.get("code"); + const errorCode = searchParams.get("error"); + const error_desc = searchParams.get("error_description"); + const state = searchParams.get("state"); if (errorCode) { navigateToLogin(errorCode, error_desc); @@ -71,19 +71,19 @@ export default function UserProfile({ setUserInfo(null); try { - let client_id = clientDetails.clientId; - let redirect_uri = clientDetails.redirect_uri_userprofile; - let grant_type = clientDetails.grant_type; + const client_id = clientDetails.clientId; + const redirect_uri = clientDetails.redirect_uri_userprofile; + const grant_type = clientDetails.grant_type; var userInfo = await post_fetchUserInfo( authCode, state, client_id, redirect_uri, - grant_type + grant_type, ); - let address = getAddress(userInfo?.address); + const address = getAddress(userInfo?.address); setAddress(address); setUserInfo(userInfo); setEmailAddress(userInfo?.email_verified ?? userInfo?.email); diff --git a/mock-relying-party-ui/src/constants/clientDetails.js b/mock-relying-party-ui/src/constants/clientDetails.js index 151736b1..14db0174 100644 --- a/mock-relying-party-ui/src/constants/clientDetails.js +++ b/mock-relying-party-ui/src/constants/clientDetails.js @@ -14,52 +14,52 @@ const generateRandomString = (strLength = 16) => { return result; }; +// mandatory parameters const state = generateRandomString(); const nonce = generateRandomString(); const responseType = "code"; +const clientId = window._env_.CLIENT_ID; +const uibaseUrl = window._env_.ESIGNET_UI_BASE_URL; +const authorizeEndpoint = checkEmptyNullValue( + window._env_.AUTHORIZE_ENDPOINT, + "/authorize", +); const scopeUserProfile = checkEmptyNullValue( window._env_.SCOPE_USER_PROFILE, - "openid profile" + "openid profile", ); const scopeRegistration = checkEmptyNullValue( window._env_.SCOPE_REGISTRATION, - "openid profile" + "openid profile", ); -const display = checkEmptyNullValue(window._env_.DISPLAY, "page"); -const prompt = checkEmptyNullValue(window._env_.PROMPT, "consent"); -const grantType = checkEmptyNullValue( - window._env_.GRANT_TYPE, - "authorization_code" -); -const maxAge = window._env_.MAX_AGE; -const claimsLocales = checkEmptyNullValue(window._env_.CLAIMS_LOCALES, "en"); -const authorizeEndpoint = "/authorize"; -const clientId = window._env_.CLIENT_ID; -const uibaseUrl = window._env_.ESIGNET_UI_BASE_URL; const redirect_uri_userprofile = checkEmptyNullValue( window._env_.REDIRECT_URI_USER_PROFILE, - window._env_.REDIRECT_URI + window._env_.REDIRECT_URI, ); const redirect_uri_registration = checkEmptyNullValue( window._env_.REDIRECT_URI_REGISTRATION, - window._env_.REDIRECT_URI + window._env_.REDIRECT_URI, ); + +// optional parameters +const maxAge = window._env_.MAX_AGE; const acr_values = window._env_.ACRS; -const userProfileClaims = checkEmptyNullValue( - window._env_.CLAIMS_USER_PROFILE, - "{}" -); -const registrationClaims = checkEmptyNullValue( - window._env_.CLAIMS_REGISTRATION, - "{}" -); +const display = window._env_.DISPLAY; +const prompt = window._env_.PROMPT; +const claimsLocales = window._env_.CLAIMS_LOCALES; +const userProfileClaims = window._env_.CLAIMS_USER_PROFILE; +const registrationClaims = window._env_.CLAIMS_REGISTRATION; +const grantType = window._env_.GRANT_TYPE; + +// callback method and its properties for PAR, DPoP and code challenge, if applicable const par_callback_name = window._env_.PAR_CALLBACK_NAME; const par_callback_timeout = checkEmptyNullValue( window._env_.PAR_CALLBACK_TIMEOUT, - 5000 + 5000, ); const dpop_callback_name = window._env_.DPOP_CALLBACK_NAME; const code_challenge = window._env_.CODE_CHALLENGE; + const claims = { userinfo: { given_name: { @@ -112,4 +112,80 @@ const clientDetails = { code_challenge: code_challenge, }; -export default clientDetails; +/** + * Safely parses the raw claims string into a JSON object. + * @param {string} rawClaims - It is the raw claims string from env-config which needs to be parsed to JSON object and set in the config. This is expected to be a URI encoded JSON string. + * @returns json object if the rawClaims is a valid JSON string, else returns null. This is to avoid app crash in case of invalid JSON string in env-config for claims. + */ +const safeParseClaims = (rawClaims) => { + try { + return JSON.parse(decodeURIComponent(rawClaims)); + } catch { + return null; // Return null if parsing fails + } +}; + +/** + * Generates the OIDC configuration based on the provided parameters. + * @param {*} It will be an object having below properties: + * isRegistration: boolean value to indicate whether the config is for registration or login. Based on this appropriate scope, claims and redirect_uri will be set in the config. + * ui_locales: it is the locale value to be sent in the oidcConfig for internationalization support in the IDP. This value will be coming from the i18n instance of react-i18next in the Login and Registration components. + * relyingPartyService: it is the service object which has the callback methods implemented for PAR, DPoP and code challenge. This will be used to get the reference of the callback methods based on the callback method names defined in env-config and set them in oidcConfig. + * @returns oidcConfig object which will be used in the init method of sign-in-with-esignet to render the sign in button and trigger the authentication flow with IDP on click of the button. + */ +const getOidcConfig = ({ + isRegistration = false, + ui_locales, + relyingPartyService, +}) => { + const parsedUserProfile = + !isRegistration && userProfileClaims + ? safeParseClaims(userProfileClaims) + : null; + const parsedRegProfile = + isRegistration && registrationClaims + ? safeParseClaims(registrationClaims) + : null; + + const oidcConfig = { + // mandatory parameters + authorizeUri: uibaseUrl + authorizeEndpoint, + redirect_uri: isRegistration + ? redirect_uri_registration + : redirect_uri_userprofile, + client_id: clientId, + scope: isRegistration ? scopeRegistration : scopeUserProfile, + // generate new nonce and state for each config generation to ensure uniqueness for each auth request + nonce: generateRandomString(), + state: generateRandomString(), + // optional parameters - only added to config if they have non-empty values in env-config + ...(acr_values && { acr_values }), + ...(claimsLocales && { claims_locales: claimsLocales }), + ...(display && { display }), + ...(prompt && { prompt }), + ...(maxAge && { max_age: maxAge }), + ...(ui_locales && { ui_locales }), + // userprofile claims + ...(parsedUserProfile && { claims: parsedUserProfile }), + // registration claims + ...(parsedRegProfile && { claims: parsedRegProfile }), + // callback methods for PAR, DPoP and code challenge, if applicable + ...(par_callback_name && + relyingPartyService?.[par_callback_name] && { + par_callback: relyingPartyService[par_callback_name], + par_callback_timeout: par_callback_timeout, + }), + ...(dpop_callback_name && + relyingPartyService?.[dpop_callback_name] && { + dpop_callback: relyingPartyService[dpop_callback_name], + }), + ...(code_challenge && + relyingPartyService?.[code_challenge] && { + code_challenge: relyingPartyService[code_challenge], + }), + }; + + return oidcConfig; +}; + +export { clientDetails, getOidcConfig }; diff --git a/mock-relying-party-ui/src/index.js b/mock-relying-party-ui/src/index.js index fbf83245..6ca828e4 100644 --- a/mock-relying-party-ui/src/index.js +++ b/mock-relying-party-ui/src/index.js @@ -2,13 +2,12 @@ import React from "react"; import ReactDOM from "react-dom/client"; import "./index.css"; import App from "./App"; -import reportWebVitals from "./reportWebVitals"; import "./i18n"; ReactDOM.createRoot(document.getElementById("root")).render( - + , ); // If you want to start measuring performance in your app, pass a function diff --git a/mock-relying-party-ui/src/services/clientService.js b/mock-relying-party-ui/src/services/clientService.js deleted file mode 100644 index 3c8a76c8..00000000 --- a/mock-relying-party-ui/src/services/clientService.js +++ /dev/null @@ -1,76 +0,0 @@ -import clientDetails from "../constants/clientDetails"; - -/** - * creates redirect URI for sign in/sign up form - * @returns redirect URI for sign in/sign up form - */ -const getURIforSignIn = () => { - return getURI( - clientDetails.redirect_uri_userprofile, - clientDetails.scopeUserProfile, - clientDetails.userProfileClaims - ); -}; - -/** - * creates redirect URI for registration form - * @returns redirect URI for registration form - */ -const getURIforRegistration = () => { - return getURI( - clientDetails.redirect_uri_registration, - clientDetails.scopeRegistration, - clientDetails.registrationClaims - ); -}; - -const getURI = (redirect_uri, scope, encodedClaims) => { - let nonce = clientDetails.nonce; - let state = clientDetails.state; - let clientId = clientDetails.clientId; - let response_type = clientDetails.response_type; - let acr_values = clientDetails.acr_values; - let display = clientDetails.display; - let prompt = clientDetails.prompt; - let maxAge = clientDetails.max_age; - let claimsLocales = clientDetails.claims_locales; - let uibaseUrl = clientDetails.uibaseUrl; - let authorizeEndpoint = clientDetails.authorizeEndpoint; - - let uri_UI = - uibaseUrl + - authorizeEndpoint + - "?nonce=" + - nonce + - "&state=" + - state + - "&client_id=" + - clientId + - "&redirect_uri=" + - redirect_uri + - "&response_type=" + - response_type + - "&scope=" + - scope + - "&acr_values=" + - acr_values + - "&claims=" + - encodedClaims + - "&display=" + - display + - "&prompt=" + - prompt + - "&max_age=" + - maxAge + - "&claims_locales=" + - claimsLocales; - - return uri_UI; -}; - -const clientService = { - getURIforSignIn, - getURIforRegistration, -}; - -export default clientService; From 3fc8da6d964211a1e4a923686cc2048a77f9ed8c Mon Sep 17 00:00:00 2001 From: Zeeshan Mehboob <82993262+zesu22@users.noreply.github.com> Date: Tue, 16 Jun 2026 09:50:54 +0530 Subject: [PATCH 19/35] [1996] added configurable token and userinfo endpoint (#591) * [1996] added configurable token and userinfo endpoint Signed-off-by: Zeeshan Mehboob * [1996] add kid only, if private key has it Signed-off-by: Zeeshan Mehboob * [1996] default value of token & userinfo endpoint Signed-off-by: Zeeshan Mehboob --------- Signed-off-by: Zeeshan Mehboob --- mock-relying-party-service/Dockerfile | 4 +++ mock-relying-party-service/config.js | 2 ++ mock-relying-party-service/esignetService.js | 6 ++-- mock-relying-party-service/utils.js | 32 +++++++++----------- 4 files changed, 25 insertions(+), 19 deletions(-) diff --git a/mock-relying-party-service/Dockerfile b/mock-relying-party-service/Dockerfile index 6bb5614b..cdcaff6c 100644 --- a/mock-relying-party-service/Dockerfile +++ b/mock-relying-party-service/Dockerfile @@ -6,6 +6,8 @@ ARG esignet_aud_url ARG client_private_key ARG userinfo_response_type ARG jwe_userinfo_private_key +ARG token_endpoint=/oauth/v2/token +ARG userinfo_endpoint=/oidc/userinfo # can be passed during Docker build as build time environment for github branch to pickup configuration from. ARG container_user=mosip @@ -39,6 +41,8 @@ ENV ESIGNET_AUD_URL=${esignet_aud_url} ENV CLIENT_PRIVATE_KEY=${client_private_key} ENV USERINFO_RESPONSE_TYPE=${userinfo_response_type} ENV JWE_USERINFO_PRIVATE_KEY=${jwe_userinfo_private_key} +ENV TOKEN_ENDPOINT=${token_endpoint} +ENV USERINFO_ENDPOINT=${userinfo_endpoint} ## Create the work directory and Change permissions of files inside working directory diff --git a/mock-relying-party-service/config.js b/mock-relying-party-service/config.js index 38827402..037562be 100644 --- a/mock-relying-party-service/config.js +++ b/mock-relying-party-service/config.js @@ -2,6 +2,8 @@ module.exports = { ESIGNET_SERVICE_URL: process.env.ESIGNET_SERVICE_URL ?? "http://localhost:8088/v1/esignet", PORT: process.env.PORT ?? 8888, + TOKEN_ENDPOINT: process.env.TOKEN_ENDPOINT ?? "/oauth/v2/token", + USERINFO_ENDPOINT: process.env.USERINFO_ENDPOINT ?? "/oidc/userinfo", CLIENT_PRIVATE_KEY: process.env.CLIENT_PRIVATE_KEY ?? "ewoJInAiOiAiMC00MElTeFhEbUM4U1ZydWRnMWU3dlFza3lXbG9oYWRtODNSQWtVeUg2UzRoMWFUUHJOd0xWbjlXQU5ueVJUcXVwRDFGcjhtWVo3ZjluWjJNa01qNDVVVjh1aUlqUVpyM2NyTXEwWUdrenRfTHZ3aExkdVdPSl96OV85elpOSGNrWGVpNEc4UVFGSlFZYjNUTmRHc1ZWU3dmZjY4U1NvZW44b3F2a2JrQUpzIiwKCSJrdHkiOiAiUlNBIiwKCSJxIjogIjZhczg4b2RjYlAyTURUOWxrYWhLMno0UUlIMjV6c2FfVWRMZ0F0THdEVnBla1hmSk5PUXZ1cU5ZMUd3M0p3czZ1UERMR2NFSzQyTXllT2RDRnFrbEZUdkRKbEpYTUZ2Z1dybUdiQ1VNdkpMLXJGeU8ta0NUR25GQlg2MG96ZEpiamZCdDNFM1FZeDNHOTA3Wml1dTlvMGF6ZXkxREp0cV96S3dlYXJFLXhUcyIsCgkiZCI6ICJCZ2RlaUNaYnI1cVo0aGFTaGc5dVFpblpSWVBTVVRZY181OFlndlEwV2tQS201ZklOT2dPSlB2aW1kS1lCdDhPdElXYmhvalR5bjBUS3JHUFBBcUZaQ25HWTE2SGtDVU4zMU1ibHVEMnd4WXo2U1BwWjF6c21QOFBiUVVWb3pqRUZlTHBpVE42bnVid19za1NfOUdHcmwxQ1BiMjV3VFBsWnRJM3VRNUlpUExfWUQ1al93NV9KN3RlakFhUmJobEpqNDhaRGE0Q1I4QmthVWkyUWFRbUxveWlPXzFPLVUtTmYxNy10MUM2ekZGS0tIUXgybE5sdEUxeEZRb0hCNFd1QkEyR25QNUxnTkZKU0x2MHA5NWdRSzM3blAwVFRjdWlaVmx2RmNtYkdJX2lsV2x4UktKVUQzbVpSNm56MjVYNFNhcFVXc3ducm5tN0p0VUFfVUdWR3ciLAoJImUiOiAiQVFBQiIsCgkidXNlIjogInNpZyIsCgkia2lkIjogIjFiYmRjOWRlLWMyNGYtNDgwMS1iNmIzLTY5MWFjMDc2NDFhZiIsCgkicWkiOiAicG1MX0c3VDRPRl9wcjJSQ3pra3VwaTFkQ2J3UlgzOWJNRUlzM3VpcnZrb1BSNUNFTnZ1dnNYUTBPaWFzM3RheHpMYTRuRzVKVlhIa3lPSVg4VXNLMU5GcnpaUFJLYmZOWDNoNUVBbmwzSTdjWk10b1lKTG5hd1VxYU5UdWtPbURDaFBsS3gxZlZqVXdzeU5uNUhTQW5tQmlhT21tX1JIbzM2dFBoZ2FQVXRFIiwKCSJkcCI6ICJlM2IyWDYwWk9vTVlyaE9QZ0s3aGM0eEV1NlRmRGNMbkp2R01waW54dllXVkN5Tmd2TktFczZjTmRNem5GYnBkMVRyRnplNm1TWkRwSVFoNmEyVzU3c2ZYOVotS2piNEQ4VDVJWmk5eGZTellOMk1qWVRmZ0dEVDNTSzlGWnFMc1FNTFYzTEpYWVdHUy1wNUFBY2FaQTAxSFZOLW1pV2xFVmdyTlFfVEF0NmsiLAoJImRxIjogIllnLUJxVW9UQ0k0eTZ4QlM0SmllcVhsWExUdDE4WWZJbkY4QnNVMnlmZmdSdmJ4bVRQTUI4TEpDUWdzVDdpZXhRaEdUT2tDZ0FDTU4tRjBjaUFQOTB2WmNoRVdEMzRCX0c3UEY3TFp6ck9PSFN2QWc5SGFMQlVySUk0MjRsUC1WZW5DT3VpaFJybmE5bS1XVU44LU1xdXV0d0tDVEVNZzJPMzl6MkZSX3dpYyIsCgkibiI6ICJ3WEdRQTU3NENVLVdUV1BJTGQ0UzNfMXNKZjBZb2Ywa3dNZU5jdFhjMXRoUW83MExqZm45ZjRpZ3BSZTdmOHFOc19XNmRMdUxXZW1GaEdKQlFCUTd2dmlja0VDS05KZm9fRXpTRF95eVBDZzdrX0FHYlRXVGt1b09iSHJwaWx3Skd5S1ZTa09JdWpIX0ZxSElWa3drVlhqV2MyNUxzYjhHcTRuQUhOUUVxcWdhWVBMRWk1ZXZDUjZTMEZ6Y1hUUHVSaDl6SC1jTTBPbmp2NG9ycmZZcEVyNjFIY1JwNU1YTDU1Yjd5Qm9JWWxYRDhOZmFsY2dkcld6cDRWWkh2UTh5VDlHNWVhZjI3WFVuNlpCZUJmN1ZuRUxjS0ZUeXcxcEsyd3FvT3hSQmM4WTF3TzZyRXk4UGxDVTZ3RC1tYkl6Y2pHMXdVZm5iZ3ZKT000QTVHNDFxdVEiCn0=", diff --git a/mock-relying-party-service/esignetService.js b/mock-relying-party-service/esignetService.js index 39e377e9..4ef0b879 100644 --- a/mock-relying-party-service/esignetService.js +++ b/mock-relying-party-service/esignetService.js @@ -4,6 +4,8 @@ const { ESIGNET_AUD_URL, ESIGNET_PAR_AUD_URL, CLIENT_ASSERTION_TYPE, + TOKEN_ENDPOINT, + USERINFO_ENDPOINT, } = require("./config"); const clientDetails = require("./clientDetails"); @@ -17,8 +19,8 @@ const { } = require("./utils"); const baseUrl = ESIGNET_SERVICE_URL.trim(); -const getTokenEndPoint = "/oauth/v2/token"; -const getUserInfoEndPoint = "/oidc/userinfo"; +const getTokenEndPoint = TOKEN_ENDPOINT.trim(); +const getUserInfoEndPoint = USERINFO_ENDPOINT.trim(); /** * Triggers /oauth/v2/token API on esignet service to fetch access token diff --git a/mock-relying-party-service/utils.js b/mock-relying-party-service/utils.js index 019d03c5..cb9239b3 100644 --- a/mock-relying-party-service/utils.js +++ b/mock-relying-party-service/utils.js @@ -38,33 +38,32 @@ const getBaseUrl = (serviceUrl) => { /** * Generates client assertion signedJWT * @param {string} clientId registered client id - * @returns client assertion signedJWT + * @param {string} audience token endpoint URL as audience + * @returns {Promise} client assertion signedJWT */ const generateSignedJwt = async (clientId, audience) => { - // Set headers for JWT - var header = { - alg: alg, + const decodeKey = Buffer.from(CLIENT_PRIVATE_KEY, "base64").toString(); + const jwkObject = JSON.parse(decodeKey); + const privateKey = await importJWK(jwkObject, alg); + + const header = { + alg, typ: "JWT", + ...(jwkObject.kid && { kid: jwkObject.kid }), }; - var payload = { + const payload = { iss: clientId, sub: clientId, aud: audience, }; - var decodeKey = Buffer.from(CLIENT_PRIVATE_KEY, "base64")?.toString(); - const jwkObject = JSON.parse(decodeKey); - const privateKey = await importJWK(jwkObject, alg); - - const jwt = new SignJWT(payload) + return new SignJWT(payload) .setProtectedHeader(header) .setIssuedAt() - .setJti(Math.random().toString(36).substring(2, 7)) + .setJti(crypto.randomUUID()) .setExpirationTime(expirationTime) .sign(privateKey); - - return jwt; }; const generateRandomString = (strLength = 16) => { @@ -91,7 +90,7 @@ const decodeUserInfoResponse = async (userInfoResponse) => { if (isJWE) { const jwkJson = Buffer.from(JWE_USERINFO_PRIVATE_KEY, "base64").toString( - "utf-8" + "utf-8", ); const jwkParsed = JSON.parse(jwkJson); @@ -140,7 +139,7 @@ const generateDpopJKT = async (clientId, state) => { cache.set( `${clientId}###${state}`, - JSON.stringify({ publicKey, privateKey }) + JSON.stringify({ publicKey, privateKey }), ); const dpopJKT = await calculateJwkThumbprint(publicKey); @@ -175,7 +174,6 @@ const calculateAth = (accessToken) => { return hash.toString("base64url"); }; - const buildDpopHeaders = async (params) => { if (!params.clientId || !params.state) return {}; @@ -196,7 +194,7 @@ const rateLimiter = rateLimit({ max: 10, standardHeaders: true, legacyHeaders: false, - message: { message: "Too many requests, please try again later."} + message: { message: "Too many requests, please try again later." }, }); module.exports = { From e8fc0f1e2200741b832bfba21bb01d4f3473b12b Mon Sep 17 00:00:00 2001 From: Zeeshan Mehboob <82993262+zesu22@users.noreply.github.com> Date: Tue, 16 Jun 2026 23:21:49 +0530 Subject: [PATCH 20/35] [1966] bypass for json userInfoResponse (#592) * [1966] bypass for json userInfoResponse Signed-off-by: Zeeshan Mehboob * [1966] bypass for json userInfoResponse Signed-off-by: Zeeshan Mehboob --------- Signed-off-by: Zeeshan Mehboob --- mock-relying-party-service/package-lock.json | 117 ++++++++++++++++--- mock-relying-party-service/utils.js | 9 ++ 2 files changed, 109 insertions(+), 17 deletions(-) diff --git a/mock-relying-party-service/package-lock.json b/mock-relying-party-service/package-lock.json index 07cae4f8..911b48bd 100644 --- a/mock-relying-party-service/package-lock.json +++ b/mock-relying-party-service/package-lock.json @@ -9,7 +9,7 @@ "version": "1.0.0", "license": "MIT", "dependencies": { - "axios": "^1.12.0", + "axios": "^1.13.5", "express": "^4.21.2", "express-rate-limit": "^8.0.1", "joi": "^17.7.1", @@ -67,6 +67,41 @@ "node": ">= 0.6" } }, + "node_modules/agent-base": { + "version": "6.0.2", + "resolved": "https://registry.npmjs.org/agent-base/-/agent-base-6.0.2.tgz", + "integrity": "sha512-RZNwNclF7+MS/8bDg70amg32dyeZGZxiDuQmZxKLAlQjr3jGyLx+4Kkk58UO7D2QdgFIQCovuSuZESne6RG6XQ==", + "license": "MIT", + "dependencies": { + "debug": "4" + }, + "engines": { + "node": ">= 6.0.0" + } + }, + "node_modules/agent-base/node_modules/debug": { + "version": "4.4.3", + "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz", + "integrity": "sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==", + "license": "MIT", + "dependencies": { + "ms": "^2.1.3" + }, + "engines": { + "node": ">=6.0" + }, + "peerDependenciesMeta": { + "supports-color": { + "optional": true + } + } + }, + "node_modules/agent-base/node_modules/ms": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz", + "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==", + "license": "MIT" + }, "node_modules/anymatch": { "version": "3.1.2", "resolved": "https://registry.npmjs.org/anymatch/-/anymatch-3.1.2.tgz", @@ -87,16 +122,19 @@ "node_modules/asynckit": { "version": "0.4.0", "resolved": "https://registry.npmjs.org/asynckit/-/asynckit-0.4.0.tgz", - "integrity": "sha512-Oei9OH4tRh0YqU3GxhX79dM/mwVgvbZJaSNaRk+bshkj0S5cfHcgYakreBjrHwatXKbz+IoIdYLxrKim2MjW0Q==" + "integrity": "sha512-Oei9OH4tRh0YqU3GxhX79dM/mwVgvbZJaSNaRk+bshkj0S5cfHcgYakreBjrHwatXKbz+IoIdYLxrKim2MjW0Q==", + "license": "MIT" }, "node_modules/axios": { - "version": "1.13.1", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.13.1.tgz", - "integrity": "sha512-hU4EGxxt+j7TQijx1oYdAjw4xuIp1wRQSsbMFwSthCWeBQur1eF+qJ5iQ5sN3Tw8YRzQNKb8jszgBdMDVqwJcw==", + "version": "1.17.0", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.17.0.tgz", + "integrity": "sha512-J8SwNxprqqpbfenehxWYXE7CW+wM1BB4w3+N+g+/Wx40xM4rsLrfPmHHxSWIxJLYDgSY/HqlFPIYb2/S3rxafw==", + "license": "MIT", "dependencies": { - "follow-redirects": "^1.15.6", - "form-data": "^4.0.4", - "proxy-from-env": "^1.1.0" + "follow-redirects": "^1.16.0", + "form-data": "^4.0.5", + "https-proxy-agent": "^5.0.1", + "proxy-from-env": "^2.1.0" } }, "node_modules/balanced-match": { @@ -232,6 +270,7 @@ "version": "1.0.8", "resolved": "https://registry.npmjs.org/combined-stream/-/combined-stream-1.0.8.tgz", "integrity": "sha512-FQN4MRfuJeHf7cBbBMJFXhKSDq+2kAArBlmRBvcvFE5BB1HZKXtSFASDhdlz9zOYwxh8lDdnvmMOe/+5cdoEdg==", + "license": "MIT", "dependencies": { "delayed-stream": "~1.0.0" }, @@ -291,6 +330,7 @@ "version": "1.0.0", "resolved": "https://registry.npmjs.org/delayed-stream/-/delayed-stream-1.0.0.tgz", "integrity": "sha512-ZySD7Nf91aLB0RxL4KGrKHBXl7Eds1DAmEdcoVawXnLD7SDhpNgtuII2aAkg7a7QS41jxPSZ17p4VdGnMHk3MQ==", + "license": "MIT", "engines": { "node": ">=0.4.0" } @@ -377,6 +417,7 @@ "version": "2.1.0", "resolved": "https://registry.npmjs.org/es-set-tostringtag/-/es-set-tostringtag-2.1.0.tgz", "integrity": "sha512-j6vWzfrGVfyXxge+O0x5sh6cvxAog0a/4Rdd2K36zCMV5eJ+/+tOAngRO8cODMNWbVRdVlmGZQL2YS3yR8bIUA==", + "license": "MIT", "dependencies": { "es-errors": "^1.3.0", "get-intrinsic": "^1.2.6", @@ -495,9 +536,9 @@ } }, "node_modules/follow-redirects": { - "version": "1.15.9", - "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.9.tgz", - "integrity": "sha512-gew4GsXizNgdoRyqmyfMHyAmXsZDk6mHkSxZFCzW9gwlbtOW44CDtYavM+y+72qD/Vq2l550kMF52DT8fOLJqQ==", + "version": "1.16.0", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.16.0.tgz", + "integrity": "sha512-y5rN/uOsadFT/JfYwhxRS5R7Qce+g3zG97+JrtFZlC9klX/W5hD7iiLzScI4nZqUS7DNUdhPgw4xI8W2LuXlUw==", "funding": [ { "type": "individual", @@ -515,9 +556,10 @@ } }, "node_modules/form-data": { - "version": "4.0.4", - "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.4.tgz", - "integrity": "sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==", + "version": "4.0.5", + "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.5.tgz", + "integrity": "sha512-8RipRLol37bNs2bhoV67fiTEvdTrbMUYcFTiy3+wuuOnUog2QBHCZWXDRijWQfAkhBj2Uf5UnVaiWwA5vdd82w==", + "license": "MIT", "dependencies": { "asynckit": "^0.4.0", "combined-stream": "^1.0.8", @@ -626,6 +668,7 @@ "version": "1.0.2", "resolved": "https://registry.npmjs.org/has-tostringtag/-/has-tostringtag-1.0.2.tgz", "integrity": "sha512-NqADB8VjPFLM2V0VvHUewwwsw0ZWBaIdgo+ieHtK3hasLz4qeCRjYcqfB6AQrBggRKppKF8L52/VqdVsO47Dlw==", + "license": "MIT", "dependencies": { "has-symbols": "^1.0.3" }, @@ -664,6 +707,42 @@ "node": ">= 0.8" } }, + "node_modules/https-proxy-agent": { + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/https-proxy-agent/-/https-proxy-agent-5.0.1.tgz", + "integrity": "sha512-dFcAjpTQFgoLMzC2VwU+C/CbS7uRL0lWmxDITmqm7C+7F0Odmj6s9l6alZc6AELXhrnggM2CeWSXHGOdX2YtwA==", + "license": "MIT", + "dependencies": { + "agent-base": "6", + "debug": "4" + }, + "engines": { + "node": ">= 6" + } + }, + "node_modules/https-proxy-agent/node_modules/debug": { + "version": "4.4.3", + "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz", + "integrity": "sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==", + "license": "MIT", + "dependencies": { + "ms": "^2.1.3" + }, + "engines": { + "node": ">=6.0" + }, + "peerDependenciesMeta": { + "supports-color": { + "optional": true + } + } + }, + "node_modules/https-proxy-agent/node_modules/ms": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz", + "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==", + "license": "MIT" + }, "node_modules/iconv-lite": { "version": "0.4.24", "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.4.24.tgz", @@ -991,9 +1070,13 @@ } }, "node_modules/proxy-from-env": { - "version": "1.1.0", - "resolved": "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-1.1.0.tgz", - "integrity": "sha512-D+zkORCbA9f1tdWRK0RaCR3GPv50cMxcrz4X8k5LTSUD1Dkw47mKJEZQNunItRTkWwgtaUSo1RVFRIG9ZXiFYg==" + "version": "2.1.0", + "resolved": "https://registry.npmjs.org/proxy-from-env/-/proxy-from-env-2.1.0.tgz", + "integrity": "sha512-cJ+oHTW1VAEa8cJslgmUZrc+sjRKgAKl3Zyse6+PV38hZe/V6Z14TbCuXcan9F9ghlz4QrFr2c92TNF82UkYHA==", + "license": "MIT", + "engines": { + "node": ">=10" + } }, "node_modules/pstree.remy": { "version": "1.1.8", diff --git a/mock-relying-party-service/utils.js b/mock-relying-party-service/utils.js index cb9239b3..7fbc53cb 100644 --- a/mock-relying-party-service/utils.js +++ b/mock-relying-party-service/utils.js @@ -84,6 +84,15 @@ const generateRandomString = (strLength = 16) => { */ const decodeUserInfoResponse = async (userInfoResponse) => { try { + // If userInfoResponse is already a parsed object (not a JWS/JWE string), + // return it directly without decoding. + if (typeof userInfoResponse === "object" && userInfoResponse !== null) { + console.log( + "userInfoResponse is already an object, returning it directly", + ); + return userInfoResponse; + } + const parts = userInfoResponse.split("."); const isJWE = USERINFO_RESPONSE_TYPE.toLowerCase() === "jwe" && parts.length === 5; From 4cb75db46f693568578dcc46592d0bf8bfe9716d Mon Sep 17 00:00:00 2001 From: bhumi46 <111699703+bhumi46@users.noreply.github.com> Date: Wed, 17 Jun 2026 17:55:54 +0530 Subject: [PATCH 21/35] [mosip/mosip-infra#1890] Added domainConfig support in helm charts (#589) * [mosip/mosip-infra#1890] Removed esignet-global, added domainConfig support in helm charts Signed-off-by: bhumi46 * [mosip/mosip-infra#1890] Set chart versions to 0.0.1-develop Signed-off-by: bhumi46 * migrate to domainConfig helm values #1890 Signed-off-by: bhumi46 --------- Signed-off-by: bhumi46 Co-authored-by: bhumi46 --- helm/mock-identity-system/templates/deployment.yaml | 4 ++++ helm/mock-identity-system/values.yaml | 2 ++ helm/mock-relying-party-service/templates/deployment.yaml | 4 ++++ helm/mock-relying-party-service/values.yaml | 2 ++ 4 files changed, 12 insertions(+) diff --git a/helm/mock-identity-system/templates/deployment.yaml b/helm/mock-identity-system/templates/deployment.yaml index 7f453f37..a8ebfbfb 100644 --- a/helm/mock-identity-system/templates/deployment.yaml +++ b/helm/mock-identity-system/templates/deployment.yaml @@ -97,6 +97,10 @@ spec: {{- if .Values.extraEnvVars }} {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }} {{- end }} + {{- range $key, $val := .Values.domainConfig }} + - name: {{ $key }} + value: {{ $val | quote }} + {{- end }} envFrom: {{- if .Values.extraEnvVarsCM }} {{- range .Values.extraEnvVarsCM }} diff --git a/helm/mock-identity-system/values.yaml b/helm/mock-identity-system/values.yaml index 88e06d47..f08a01d6 100644 --- a/helm/mock-identity-system/values.yaml +++ b/helm/mock-identity-system/values.yaml @@ -504,3 +504,5 @@ istio: prefix: /v1/mock-identity-system/ enable_insecure: false + +domainConfig: {} diff --git a/helm/mock-relying-party-service/templates/deployment.yaml b/helm/mock-relying-party-service/templates/deployment.yaml index 8527aa81..fb6d09ca 100644 --- a/helm/mock-relying-party-service/templates/deployment.yaml +++ b/helm/mock-relying-party-service/templates/deployment.yaml @@ -107,6 +107,10 @@ spec: {{- if .Values.extraEnvVars }} {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }} {{- end }} + {{- range $key, $val := .Values.domainConfig }} + - name: {{ $key }} + value: {{ $val | quote }} + {{- end }} envFrom: {{- if .Values.envVarsCM }} {{- range .Values.envVarsCM }} diff --git a/helm/mock-relying-party-service/values.yaml b/helm/mock-relying-party-service/values.yaml index da3a654e..102798fa 100644 --- a/helm/mock-relying-party-service/values.yaml +++ b/helm/mock-relying-party-service/values.yaml @@ -460,3 +460,5 @@ istio: reWritemock_relying_party_servicePrefix: "" enable_insecure: false + +domainConfig: {} From 9c0150bc966a6ee6c17b1357933aeadc5e069075 Mon Sep 17 00:00:00 2001 From: Mahesh-Binayak <76687012+Mahesh-Binayak@users.noreply.github.com> Date: Tue, 7 Jul 2026 19:31:06 +0530 Subject: [PATCH 22/35] Gpg update Test (#596) * ci: point kattu maven workflows at @develop to test kattu#353 Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis(-new) reusable-workflow references to mosip/kattu@develop so the GPG-key-import migration (mosip/kattu#353) is exercised by this repo's CI once it merges. Co-Authored-By: Claude Opus 4.8 Signed-off-by: Mahesh.Binayak * ci: pass GPG_PRIVATE_KEY secret from caller workflows (kattu#353) kattu#353 imports the signing key from the GPG_PRIVATE_KEY secret (now required: true in maven-build / maven-publish-to-nexus workflow_call), so the caller must forward it. Added GPG_PRIVATE_KEY to the maven-build and maven-publish-to-nexus caller jobs only (sonar workflows don't declare it). Co-Authored-By: Claude Opus 4.8 Signed-off-by: Mahesh.Binayak * ci: point maven workflows at Mahesh-Binayak/kattu@gpgupdate-masterj21 gpgupdate-masterj21 = master-java21 + the GPG-secret-import / key-age / simplify4u-pgpverify changes, keeping master-java21's interface intact. Repoints maven-build / maven-publish-to-nexus / maven-sonar-analysis to it, restores MAVEN_NON_EXEC_ARTIFACTS, and forwards GPG_PRIVATE_KEY to the build/publish jobs. Other workflows (docker-build, npm-*, sonar-new@develop) and commented refs are left unchanged. Co-Authored-By: Claude Opus 4.8 Signed-off-by: Mahesh.Binayak * ci: point maven workflows at mosip/kattu@gpgupdate-masterj21 The gpgupdate-masterj21 branch now lives on mosip/kattu; reference it there instead of the fork. Interface unchanged; GPG_PRIVATE_KEY forwarded. Co-Authored-By: Claude Opus 4.8 Signed-off-by: Mahesh.Binayak --------- Signed-off-by: Mahesh.Binayak Co-authored-by: Claude Opus 4.8 --- .github/workflows/push-trigger.yml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/push-trigger.yml b/.github/workflows/push-trigger.yml index 5d8a562b..7e6a0c2f 100644 --- a/.github/workflows/push-trigger.yml +++ b/.github/workflows/push-trigger.yml @@ -24,7 +24,7 @@ on: jobs: build-maven-esignet-mock-services: - uses: mosip/kattu/.github/workflows/maven-build.yml@master-java21 + uses: mosip/kattu/.github/workflows/maven-build.yml@gpgupdate-masterj21 with: SERVICE_LOCATION: ./ BUILD_ARTIFACT: esignet-mock-services @@ -33,12 +33,13 @@ jobs: OSSRH_SECRET: ${{ secrets.OSSRH_SECRET }} OSSRH_TOKEN: ${{ secrets.OSSRH_TOKEN }} GPG_SECRET: ${{ secrets.GPG_SECRET }} + GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }} publish_to_nexus: if: "${{ !contains(github.ref, 'master') && github.event_name != 'pull_request' }}" needs: build-maven-esignet-mock-services - uses: mosip/kattu/.github/workflows/maven-publish-to-nexus.yml@master-java21 + uses: mosip/kattu/.github/workflows/maven-publish-to-nexus.yml@gpgupdate-masterj21 with: SERVICE_LOCATION: ./ secrets: @@ -47,13 +48,14 @@ jobs: OSSRH_URL: ${{ secrets.RELEASE_URL }} OSSRH_TOKEN: ${{ secrets.OSSRH_TOKEN }} GPG_SECRET: ${{ secrets.GPG_SECRET }} + GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK }} sonar_analysis: needs: build-maven-esignet-mock-services if: "${{ github.event_name != 'pull_request' }}" - uses: mosip/kattu/.github/workflows/maven-sonar-analysis.yml@master-java21 + uses: mosip/kattu/.github/workflows/maven-sonar-analysis.yml@gpgupdate-masterj21 with: SERVICE_LOCATION: ./ secrets: From 815e67bf2b7a3d96b1463aa5eb89163a628c5a55 Mon Sep 17 00:00:00 2001 From: Praful Rakhade Date: Wed, 8 Jul 2026 12:50:16 +0530 Subject: [PATCH 23/35] [issue:1963] Updated helm for thunder deployment (#593) Signed-off-by: Prafulrakhade --- helm/mock-relying-party-service/values.yaml | 2 ++ helm/mock-relying-party-ui/values.yaml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/helm/mock-relying-party-service/values.yaml b/helm/mock-relying-party-service/values.yaml index 102798fa..4d015da4 100644 --- a/helm/mock-relying-party-service/values.yaml +++ b/helm/mock-relying-party-service/values.yaml @@ -74,6 +74,8 @@ mock_relying_party_service: ESIGNET_SERVICE_URL: http://esignet.namespace/v1/esignet ESIGNET_AUD_URL: https://esignet.sandbox.xyz.net/v1/esignet/oauth/v2/token USERINFO_RESPONSE_TYPE: jwt + TOKEN_ENDPOINT: /oauth2/token + USERINFO_ENDPOINT: /oauth2/userinfo ## Port on which this particular spring service module is running. containerPort: 8888 diff --git a/helm/mock-relying-party-ui/values.yaml b/helm/mock-relying-party-ui/values.yaml index bfd29b43..8e356ab0 100644 --- a/helm/mock-relying-party-ui/values.yaml +++ b/helm/mock-relying-party-ui/values.yaml @@ -432,6 +432,8 @@ mock_relying_party_ui: CLAIMS_REGISTRATION: '%7B%22userinfo%22:%7B%22given_name%22:%7B%22essential%22:true%7D,%22phone_number%22:%7B%22essential%22:false%7D,%22email%22:%7B%22essential%22:true%7D,%22picture%22:%7B%22essential%22:false%7D,%22gender%22:%7B%22essential%22:false%7D,%22birthdate%22:%7B%22essential%22:false%7D,%22address%22:%7B%22essential%22:false%7D%7D,%22id_token%22:%7B%7D%7D' DEFAULT_LANG: en FALLBACK_LANG: '%7B%22label%22%3A%22English%22%2C%22value%22%3A%22en%22%7D' + AUTHORIZE_ENDPOINT: /v1/esignet/oauth2/authorize + CODE_CHALLENGE: get_code_challenge ## oidc UI swagger should have only internal access. Hence linked to internal gateway ## We create a gateway for oidc specific URL(s) listed under `hosts` istio: From 716d0f0a1ab6bb18299104641f06f52711785bfe Mon Sep 17 00:00:00 2001 From: Swapnil Date: Tue, 28 Jul 2026 22:16:43 +0530 Subject: [PATCH 24/35] [issue:597] Add PKCS12 keystore support to mock-identity-system as an alternative to SoftHSM (#599) install.sh now prompts to opt into a PKCS12 mounted-volume keystore instead of SoftHSM; SoftHSM provisioning only runs when PKCS12 isn't selected. The chart gained a PersistentVolumeClaim template, a fixed volume-permissions init container (was a literal unfilled placeholder), persistence volume wiring in the deployment, and additive extraEnvVarsAdditional support. Signed-off-by: Swapnil --- deploy/mock-identity-system/install.sh | 80 ++++++++++++++++++- .../templates/deployment.yaml | 20 ++++- helm/mock-identity-system/templates/pvc.yaml | 32 ++++++++ helm/mock-identity-system/values.yaml | 21 ++--- 4 files changed, 138 insertions(+), 15 deletions(-) create mode 100644 helm/mock-identity-system/templates/pvc.yaml diff --git a/deploy/mock-identity-system/install.sh b/deploy/mock-identity-system/install.sh index 1e562dbc..e26d0524 100755 --- a/deploy/mock-identity-system/install.sh +++ b/deploy/mock-identity-system/install.sh @@ -59,14 +59,88 @@ function installing_mock-identity-system() { ENABLE_INSECURE='--set enable_insecure=true'; fi - ../copy_cm_func.sh secret softhsm-mock-identity-system softhsm $NS - ../copy_cm_func.sh configmap softhsm-mock-identity-system-share softhsm $NS + while true; do + read -p "For PKCS12 mounted keys, opt 'y' to enable volume (y/n) [ default: n ]: " enable_volume + enable_volume=${enable_volume:-n} + + if [[ "$enable_volume" == "y" || "$enable_volume" == "Y" ]]; then + enable_volume=true + break + elif [[ "$enable_volume" == "n" || "$enable_volume" == "N" ]]; then + enable_volume=false + break + else + echo "Invalid input. Please enter 'y' or 'n'." + fi + done + + HSM_HELM_ARGS='' + if [[ $enable_volume == 'true' ]]; then + default_volume_size=100M + read -p "Provide the size for volume [ default : 100M ]" volume_size + volume_size=${volume_size:-$default_volume_size} + + default_volume_mount_path='/home/mosip/config/' + read -p "Provide the mount path for volume [ default : '/home/mosip/config/' ] : " volume_mount_path + volume_mount_path=${volume_mount_path:-$default_volume_mount_path} + + default_keystore_pass='1234' + read -p "Provide the PKCS12 keystore password [ default : 1234 ] : " keystore_pass + keystore_pass=${keystore_pass:-$default_keystore_pass} + + kubectl -n $NS create secret generic mockid-pkcs12-secret \ + --from-literal=keystore-pass="$keystore_pass" \ + --dry-run=client -o yaml | kubectl apply -f - + + pkcs12_env_file=$(mktemp) + cat < "$pkcs12_env_file" +extraEnvVarsAdditional: + - name: MOSIP_KERNEL_KEYMANAGER_HSM_KEYSTORE_TYPE + value: "PKCS12" + - name: MOSIP_KERNEL_KEYMANAGER_HSM_CONFIG_PATH + value: "${volume_mount_path}keystore.p12" + - name: MOSIP_KERNEL_KEYMANAGER_HSM_KEYSTORE_PASS + valueFrom: + secretKeyRef: + name: mockid-pkcs12-secret + key: keystore-pass +EOF + + PVC_CLAIM_NAME='mockid-pkcs12' + HSM_HELM_ARGS="--set persistence.enabled=true \ + --set volumePermissions.enabled=true \ + --set persistence.size=$volume_size \ + --set persistence.mountDir=\"$volume_mount_path\" \ + --set persistence.pvc_claim_name=\"$PVC_CLAIM_NAME\" \ + -f $pkcs12_env_file \ + " + else + ../copy_cm_func.sh secret softhsm-mock-identity-system softhsm $NS + ../copy_cm_func.sh configmap softhsm-mock-identity-system-share softhsm $NS + + softhsm_env_file=$(mktemp) + cat < "$softhsm_env_file" +extraEnvVarsAdditional: + - name: SOFTHSM_MOCK_IDENTITY_SYSTEM_SECURITY_PIN + valueFrom: + secretKeyRef: + name: softhsm-mock-identity-system + key: security-pin + - name: hsm_local_dir_name + value: hsm-client +extraEnvVarsCM: + - softhsm-mock-identity-system-share +EOF + + HSM_HELM_ARGS="-f $softhsm_env_file" + fi + ../copy_cm_func.sh configmap esignet-global esignet $NS ../copy_cm_func.sh configmap redis-config redis $NS ../copy_cm_func.sh secret redis redis $NS echo Installing mock-identity-system - helm -n $NS install mock-identity-system mosip/mock-identity-system --set metrics.serviceMonitor.enabled=$servicemonitorflag --version $CHART_VERSION $ENABLE_INSECURE -f values.yaml --wait + helm -n $NS install mock-identity-system mosip/mock-identity-system --set metrics.serviceMonitor.enabled=$servicemonitorflag --version $CHART_VERSION $ENABLE_INSECURE $HSM_HELM_ARGS -f values.yaml --wait kubectl -n $NS get deploy mock-identity-system -o name | xargs -n1 -t kubectl -n $NS rollout status diff --git a/helm/mock-identity-system/templates/deployment.yaml b/helm/mock-identity-system/templates/deployment.yaml index a8ebfbfb..0439553f 100644 --- a/helm/mock-identity-system/templates/deployment.yaml +++ b/helm/mock-identity-system/templates/deployment.yaml @@ -60,15 +60,17 @@ spec: image: {{ include "mock-identity-system.volumePermissions.image" . }} imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} command: - - %%commands%% + - /bin/bash + - -c + - chown -R 1001:1001 {{ .Values.persistence.mountDir }} securityContext: runAsUser: 0 {{- if .Values.volumePermissions.resources }} resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} {{- end }} volumeMounts: - - name: foo - mountPath: bar + - name: {{ .Values.persistence.volume_name }} + mountPath: {{ .Values.persistence.mountDir }} {{- end }} {{- if .Values.enable_insecure }} {{- include "common.tplvalues.render" (dict "value" .Values.initContainers "context" $) | nindent 8 }} @@ -97,6 +99,9 @@ spec: {{- if .Values.extraEnvVars }} {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }} {{- end }} + {{- if .Values.extraEnvVarsAdditional }} + {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVarsAdditional "context" $) | nindent 12 }} + {{- end }} {{- range $key, $val := .Values.domainConfig }} - name: {{ $key }} value: {{ $val | quote }} @@ -143,6 +148,10 @@ spec: name: cacerts subPath: cacerts {{- end }} + {{- if .Values.persistence.enabled }} + - name: {{ .Values.persistence.volume_name }} + mountPath: {{ .Values.persistence.mountDir }} + {{- end }} {{- if .Values.sidecars }} {{- include "common.tplvalues.render" ( dict "value" .Values.sidecars "context" $) | nindent 8 }} {{- end }} @@ -151,3 +160,8 @@ spec: - name: cacerts emptyDir: {} {{- end }} + {{- if .Values.persistence.enabled }} + - name: {{ .Values.persistence.volume_name }} + persistentVolumeClaim: + claimName: {{ .Values.persistence.existingClaim | default .Values.persistence.pvc_claim_name }} + {{- end }} diff --git a/helm/mock-identity-system/templates/pvc.yaml b/helm/mock-identity-system/templates/pvc.yaml new file mode 100644 index 00000000..ee5be08a --- /dev/null +++ b/helm/mock-identity-system/templates/pvc.yaml @@ -0,0 +1,32 @@ +{{- if and .Values.persistence.enabled (not .Values.persistence.existingClaim) }} +kind: PersistentVolumeClaim +apiVersion: v1 +metadata: + name: {{ .Values.persistence.pvc_claim_name }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + annotations: + {{- if .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} + "helm.sh/resource-policy": keep +spec: + accessModes: + {{- if not (empty .Values.persistence.accessModes) }} + {{- range .Values.persistence.accessModes }} + - {{ . | quote }} + {{- end }} + {{- else }} + - {{ .Values.persistence.accessModes | quote }} + {{- end }} + resources: + requests: + storage: {{ .Values.persistence.size | quote }} + {{- include "common.storage.class" (dict "persistence" .Values.persistence "global" .Values.global) | nindent 2 }} + {{- if .Values.persistence.dataSource }} + dataSource: {{- include "common.tplvalues.render" (dict "value" .Values.persistence.dataSource "context" $) | nindent 4 }} + {{- end }} +{{- end }} diff --git a/helm/mock-identity-system/values.yaml b/helm/mock-identity-system/values.yaml index f08a01d6..419b29cd 100644 --- a/helm/mock-identity-system/values.yaml +++ b/helm/mock-identity-system/values.yaml @@ -266,13 +266,6 @@ extraEnvVars: secretKeyRef: name: db-common-secrets key: db-dbuser-password - - name: SOFTHSM_MOCK_IDENTITY_SYSTEM_SECURITY_PIN - valueFrom: - secretKeyRef: - name: softhsm-mock-identity-system - key: security-pin - - name: hsm_local_dir_name - value: hsm-client - name: MOSIP_ESIGNET_MOCK_SUPPORTED_FIELDS value: individualId,password - name: MOSIP_ESIGNET_HOST @@ -296,10 +289,18 @@ extraEnvVars: name: redis key: redis-password +## Additional environment variables to append on top of extraEnvVars, without +## having to restate the entries already declared there +## Example: +## extraEnvVarsAdditional: +## - name: FOO +## value: "bar" +## +extraEnvVarsAdditional: [] + ## ConfigMap with extra environment variables that used ## -extraEnvVarsCM: - - softhsm-mock-identity-system-share +extraEnvVarsCM: [] ## Secret with extra environment variables ## @@ -389,6 +390,8 @@ persistence: existingClaim: # Dir where config and keys are written inside container mountDir: + volume_name: config + pvc_claim_name: ## Init containers parameters: ## volumePermissions: Change the owner and group of the persistent volume mountpoint to runAsUser:fsGroup values from the securityContext section. From 98d748c9449f329e651b6f31e2a6d4bece94f551 Mon Sep 17 00:00:00 2001 From: Sajid Mannikeri Date: Wed, 29 Jul 2026 18:42:08 +0530 Subject: [PATCH 25/35] Fix default prompt value (#600) Signed-off-by: Sajid Mannikeri Co-authored-by: Sajid Mannikeri --- mock-relying-party-service/clientDetails.js | 2 +- mock-relying-party-service/esignetService.js | 4 +++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/mock-relying-party-service/clientDetails.js b/mock-relying-party-service/clientDetails.js index 32e9daf8..5d77e77b 100644 --- a/mock-relying-party-service/clientDetails.js +++ b/mock-relying-party-service/clientDetails.js @@ -26,7 +26,7 @@ const scopeRegistration = checkEmptyNullValue( "openid profile", ); const display = checkEmptyNullValue(process.env.DISPLAY, "page"); -const prompt = checkEmptyNullValue(process.env.PROMPT, "consent"); +const prompt = process.env.PROMPT || null; const grantType = checkEmptyNullValue( process.env.GRANT_TYPE, "authorization_code", diff --git a/mock-relying-party-service/esignetService.js b/mock-relying-party-service/esignetService.js index 4ef0b879..7b53eeb9 100644 --- a/mock-relying-party-service/esignetService.js +++ b/mock-relying-party-service/esignetService.js @@ -110,7 +110,9 @@ const post_GetRequestUri = async (clientId, uiLocales, state, dpop_jkt, code_cha params.append("claims", clientDetails.userProfileClaims); params.append("claims_locales", clientDetails.claimsLocales); params.append("display", clientDetails.display); - params.append("prompt", clientDetails.prompt); + if (clientDetails.prompt) { + params.append("prompt", clientDetails.prompt); + } params.append("ui_locales", uiLocales || process.env.DEFAULT_UI_LOCALES); params.append("client_assertion_type", CLIENT_ASSERTION_TYPE); params.append("client_assertion", clientAssertion); From de77647bd272d45fd08d41a5802283f1281c08e8 Mon Sep 17 00:00:00 2001 From: Chetan Kumar Hirematha Date: Mon, 10 Aug 2026 12:19:23 +0530 Subject: [PATCH 26/35] #10670: Add AGENTS.md tree for AI coding assistant guidance MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds a root AGENTS.md hub covering the repository as a whole, plus per-module AGENTS.md guides for mock-identity-system, mock-relying-party-service, mock-relying-party-ui, mock-relying-party-ui-esim, and partner-onboarder — the independently buildable modules in this repo. Each guide documents purpose, layout, how to run/build/test, configuration, and explicit agent do/do-not rules, verified against the actual READMEs, pom.xml/package.json files, and GitHub Actions workflows in this repo. Addresses https://github.com/mosip/mosip-config/issues/10670 Signed-off-by: Chetan Kumar Hirematha --- AGENTS.md | 183 +++++++++++++++++++++++++++ mock-identity-system/AGENTS.md | 91 +++++++++++++ mock-relying-party-service/AGENTS.md | 83 ++++++++++++ mock-relying-party-ui-esim/AGENTS.md | 78 ++++++++++++ mock-relying-party-ui/AGENTS.md | 85 +++++++++++++ partner-onboarder/AGENTS.md | 58 +++++++++ 6 files changed, 578 insertions(+) create mode 100644 AGENTS.md create mode 100644 mock-identity-system/AGENTS.md create mode 100644 mock-relying-party-service/AGENTS.md create mode 100644 mock-relying-party-ui-esim/AGENTS.md create mode 100644 mock-relying-party-ui/AGENTS.md create mode 100644 partner-onboarder/AGENTS.md diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 00000000..1c3938cf --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,183 @@ +# AGENTS.md + +## Repository Overview + +`esignet-mock-services` provides **mock, non-production implementations** that stand in for +real MOSIP eSignet dependencies during development, demos, and testing: + +- A mock identity system that mimics the MOSIP IDA (Identity Authentication) system. +- A mock relying-party backend and two mock relying-party UIs that demonstrate OIDC login + against eSignet. +- A partner-onboarder job that registers the mock relying party as an OIDC client with MOSIP. + +**This is dev/test-only tooling.** None of the services in this repository perform real +identity verification or issue real credentials — they return canned/synthetic identity data +and use test keys. They must never be pointed at, or treated as, a production identity or +credential-issuing system. + +This repo is a small tree of independently-buildable modules rather than one monolithic +service. Each module has its own build tool, run instructions, and README. Use this root file +to find your way to the module that matters for your change; use the module guide for the +actual commands. + +| Module | What it is | Guide | +|---|---|---| +| `mock-identity-system` | Java/Spring Boot mock of the MOSIP IDA system (Maven module, built by the root `pom.xml`) | [mock-identity-system/AGENTS.md](mock-identity-system/AGENTS.md) | +| `mock-relying-party-service` | Node.js/Express backend for the mock relying-party portal (OIDC/OAuth client, DPoP, PAR) | [mock-relying-party-service/AGENTS.md](mock-relying-party-service/AGENTS.md) | +| `mock-relying-party-ui` | React UI for the generic mock relying-party portal | [mock-relying-party-ui/AGENTS.md](mock-relying-party-ui/AGENTS.md) | +| `mock-relying-party-ui-esim` | React UI for the eSIM-branded mock relying-party portal | [mock-relying-party-ui-esim/AGENTS.md](mock-relying-party-ui-esim/AGENTS.md) | +| `partner-onboarder` | Shell/Helm job that onboards the mock relying party as an OIDC partner | [partner-onboarder/AGENTS.md](partner-onboarder/AGENTS.md) | + +Non-module directories: + +- `db_scripts/` — PostgreSQL DDL/DML for `mosip_mockidentitysystem`. See `db_scripts/README.md`. + Deploy locally with `db_scripts/mosip_mockidentitysystem/deploy.sh`. +- `db_upgrade_script/` — versioned DB upgrade scripts. +- `docker-compose/` — Compose files to run the mock stack locally (see `docker-compose/README.md`). +- `deploy/` and `helm/` — Kubernetes/Helm install scripts and charts for cluster deployment. +- `docs/` — supporting images. + +## Technology Stack + +- **mock-identity-system**: Java 21, Spring Boot 3.4.11 (Spring Web, Spring Data JPA, Spring + Data Redis, Spring Cloud Config), Maven, PostgreSQL, springdoc-openapi, Lombok, JSON Schema + validation (`com.networknt:json-schema-validator`). +- **mock-relying-party-service**: Node.js, Express, `jose` (JWT/JWK), `axios`, `joi`, + `node-cache`, `express-rate-limit`. +- **mock-relying-party-ui** / **mock-relying-party-ui-esim**: React 18 (Create React App), + `react-router-dom`, `i18next`, Tailwind CSS. +- **partner-onboarder**: shell scripts + Helm, driven by `values.yaml`. +- **CI**: GitHub Actions, using shared reusable workflows from `mosip/kattu` + (`.github/workflows/push-trigger.yml`, `db-test.yml`, `chart-lint-publish.yml`, + `codeql.yml`, `release-changes.yml`, `tag.yml`). + +## Build & Test Commands + +Root Maven build (builds `mock-identity-system`, the only module declared in the root +`pom.xml`): + +```shell +mvn clean install -Dgpg.skip=true -DskipTests=true +``` + +Run the full test suite for `mock-identity-system` (includes JaCoCo coverage, configured in +the parent `pom.xml`): + +```shell +mvn -pl mock-identity-system test +``` + +Node-based modules (`mock-relying-party-service`, `mock-relying-party-ui`, +`mock-relying-party-ui-esim`) each build independently with `npm install` / `npm start` / +`npm run build` from inside their own directory. See the per-module guides for exact commands +and required environment variables — commands differ per module and none of them share a +single root build script. + +Each service/UI also has a `Dockerfile`; CI (`push-trigger.yml`) builds and pushes images for +`mock-identity-system`, `mock-relying-party-service`, `mock-relying-party-ui`, and +`mock-relying-party-ui-esim` via the shared `mosip/kattu` docker-build workflow. + +## Configuration + +- `mock-identity-system` configuration lives in + `mock-identity-system/src/main/resources/application-default.properties` and + `application-local.properties`, plus `bootstrap.properties` for Spring Cloud Config. The + local profile ships a non-secret local Postgres password (`postgres`) and a local HSM + keystore password (`localtest`) intended only for a throwaway local Postgres/HSM instance — + do not reuse these values, or any value copied from this repo, for a real deployment. +- `mock-relying-party-service` is configured entirely through environment variables (no + committed secrets file) — see `mock-relying-party-service/README.md` for the full list, + including `CLIENT_PRIVATE_KEY` and `JWE_USERINFO_PRIVATE_KEY`, which must be supplied by + whoever runs the service and never committed. +- `mock-relying-party-ui` and `mock-relying-party-ui-esim` are configured via `.env`, + `.env.development`, and (at container runtime) `public/env-config.js`. The tracked `.env` + files only set non-sensitive UI defaults (e.g. `REACT_APP_TOAST_TIMEOUT_IN_SEC`); real + per-environment values (client IDs, redirect URIs, service URLs) are supplied via + `env-config.js` or Docker `-e` flags at deploy time, not committed to the repo. +- `partner-onboarder` is configured through `partner-onboarder/values.yaml` for Helm-based + runs. + +## Project Structure Notes + +- The root `pom.xml` is a Maven **parent/aggregator** POM but currently declares only one + ``, `mock-identity-system`. The Node/React modules are siblings on disk but are not + part of the Maven reactor — they are built and deployed independently (own `Dockerfile`, own + CI matrix entry). +- `mock-relying-party-ui` and `mock-relying-party-ui-esim` are two separate, independently + versioned React apps with overlapping purpose (generic vs. eSIM-branded relying-party demo + UI) — check which one a change actually targets before editing, since their `package.json` + and dependency sets differ. +- CI workflow triggers are scoped by path where relevant: `db-test.yml` only runs on changes + under `db_scripts/**`; `chart-lint-publish.yml` only runs on changes under `helm/**`. + `push-trigger.yml` (the Maven/Docker build) runs on pushes/PRs regardless of path. + `codeql.yml` runs on pushes/PRs to `develop` and a weekly schedule. + +## Development Workflow + +1. Fork and clone the repository; add `upstream` pointing at `mosip/esignet-mock-services`. +2. Branch from `upstream/develop` — `develop` is the integration branch this repo builds and + opens PRs against. +3. Make changes inside the relevant module directory only; each module builds and runs + independently (see the module guide for exact local run steps). +4. To exercise the mock identity system and relying-party portal together locally, use the + Compose files in `docker-compose/` as described in `docker-compose/README.md`. +5. Run the relevant module's tests/build before opening a PR (`mvn -pl mock-identity-system + test` for the Java module; `npm test` / `npm run build` for the Node/React modules). + +## Pull Request Guidelines + +- Target the `develop` branch. +- Keep changes scoped to the module(s) actually touched; avoid unrelated changes across + modules in the same PR. +- CI (`push-trigger.yml`) builds the Maven module and all four Docker images + (`mock-identity-system`, `mock-relying-party-service`, `mock-relying-party-ui`, + `mock-relying-party-ui-esim`) on every PR — make sure each touched module still builds. +- If you touch `db_scripts/**`, the `db-test.yml` workflow will run against PostgreSQL — + verify DDL/DML changes locally with `db_scripts/mosip_mockidentitysystem/deploy.sh` first. +- If you touch `helm/**`, the `chart-lint-publish.yml` workflow will lint the charts. + +## Repository-Specific Considerations + +- Everything here is **mock/test tooling only** — the README states this explicitly + ("Only for non-production use", "This is not for production use"). Do not add code paths, + defaults, or documentation that imply this repo could serve as a real identity provider, + credential issuer, or relying party in production. +- The mock identity system supports OIDC Identity Assurance verified-claims metadata + (`trust_framework`, `assurance_level`, `verification_process`, `time`, `evidence`) — see + `mock-identity-system/README.md` for the semantics before changing identity-schema + validation logic (`mock-identity-schema.json`). +- The relying-party service and UI implement FAPI 2.0-adjacent security features (DPoP per + RFC 9449, PAR per RFC 9126, PKCE). Keep the service and UI README env-variable tables in + sync with actual code if you add/rename an environment variable. +- When deploying multiple eSignet plugins into the same Kubernetes cluster, several Helm + install scripts require manual per-namespace overrides (service names, namespace) — see the + root `README.md` section "When deploying multiple esignet plugins in the same cluster." + +## Agent rules + +### Do + +1. Verify which module(s) a change actually touches (`mock-identity-system`, + `mock-relying-party-service`, `mock-relying-party-ui`, `mock-relying-party-ui-esim`, + `partner-onboarder`, or infra dirs) and read that module's own `README.md`/`AGENTS.md` + before editing. +2. Build and test the specific module you changed before proposing a PR (Maven for + `mock-identity-system`, `npm` for the Node/React modules). +3. Keep any new configuration documented as environment variables or properties files + consistent with the patterns already used in that module (no new secrets committed to the + repo). +4. Preserve the "mock/non-production only" framing in any documentation you write or edit. + +### Do not + +1. Do not commit real credentials, private keys, or production URLs into `.env`, + `application-*.properties`, `values.yaml`, or any other config file — these services are + configured with secrets at deploy time (Docker `-e`, Helm values, environment variables), + not via committed files. +2. Do not assume the root `pom.xml` builds the Node/React modules — it only builds + `mock-identity-system`. Do not add Maven-only build instructions and claim they cover the + whole repo. +3. Do not treat `mock-relying-party-ui` and `mock-relying-party-ui-esim` as the same app — + verify which one you are changing. +4. Do not describe this repository, in code or docs, as suitable for real identity + verification or credential issuance. diff --git a/mock-identity-system/AGENTS.md b/mock-identity-system/AGENTS.md new file mode 100644 index 00000000..f7f66481 --- /dev/null +++ b/mock-identity-system/AGENTS.md @@ -0,0 +1,91 @@ +# AGENTS.md — mock-identity-system + +Parent guide: [../AGENTS.md](../AGENTS.md) + +## Purpose + +Mock implementation of the MOSIP IDA (Identity Authentication) system, used to demonstrate and +test eSignet integration without a real identity backend. Supports `create-identity`, +`get-identity`, `kyc-auth`, `kyc-exchange`, and adding OIDC Identity-Assurance verified-claims +metadata for a user's claims. Supported authentication factors: PIN, OTP, BIO, PWD, WLA. + +This is a mock service — it stores and returns synthetic identity data only. Never point a +production system at this module. + +## Layout + +- `src/main/java/io/mosip/esignet/mock/identitysystem/` — Spring Boot application code + (`controller/`, `service/`, `service/impl/`, `repository/`, `entity/`, `dto/`, `config/`, + `advice/`, `util/`, `exception/`). +- `src/main/resources/` — `application-default.properties`, `application-local.properties`, + `bootstrap.properties`, `messages.properties`, and JSON schemas + (`mock-identity-schema.json`, `mock-identity-signup-schema.json`, + `mock-identity-ui-spec.json`, `mock-identity-signup-ui-spec.json`). +- `src/test/java/...` — JUnit tests for controllers, services, and utilities. +- `src/test/resources/` — `application-test.properties`, `bootstrap.properties`, `data.sql`, + `schema.sql` (H2 in-memory DB for tests), `mock-identity-test-schema.json`. +- `Dockerfile`, `configure_start.sh`, `softhsm-application.conf` — container/runtime setup. + +## How to run + +Local setup (from the repo root, matching `docker-compose/README.md`): + +```shell +docker compose --file ../docker-compose/dependent-docker-compose.yml up +mvn clean install -Dgpg.skip=true -DskipTests=true +``` + +Then start `MockIdentitySystemApplication` from your IDE, or run the packaged jar. Swagger UI +is served at: + +```text +http://localhost:8082/v1/mock-identity-system/swagger-ui.html +``` + +Add a test identity: + +```shell +curl -X 'POST' \ + 'http://localhost:8082/v1/mock-identity-system/identity' \ + -H 'accept: application/json' \ + -H 'Content-Type: application/json' \ + -d '{"requestTime": "2023-07-24T08:53:05.142Z", "request": {"individualId":"8267411571","pin":"111111"}}' +``` + +Run tests only (from repo root): + +```shell +mvn -pl mock-identity-system test +``` + +## Configuration + +- `src/main/resources/application-local.properties` points at a local Postgres + (`localhost:5455`, db `mosip_mockidentitysystem`) and local Redis (`spring.cache.type=simple` + is explicitly a non-production cache mode). The Postgres password (`postgres`) and HSM + keystore password (`localtest`) in this file are throwaway values for a local dev database + only — never reuse them for a real deployment. +- Schema validation is driven by `mosip.mock.ida.identity.schema.url` (defaults to + `classpath:/mock-identity-schema.json`). Create operations validate all fields against the + schema; update operations validate mandatory fields, and validate non-mandatory fields only + if present (see `mosip.mock.ida.update-identity.non-mandatory.fields`). +- Database DDL/DML live outside this module, under `../db_scripts/mosip_mockidentitysystem/`. + +## Agent rules + +### Do + +1. Run `mvn -pl mock-identity-system test` after any change under `src/main/java` or + `src/main/resources`. +2. Keep `mock-identity-schema.json` (and the corresponding test schema in + `src/test/resources/mock-identity-test-schema.json`) in sync when adding/removing identity + fields. +3. Add new JUnit tests alongside existing ones under + `src/test/java/io/mosip/esignet/mock/identitysystem/...`, mirroring the package of the code + under test. + +### Do not + +1. Do not commit real Postgres/HSM/Redis credentials into `application-*.properties`. +2. Do not add production-facing identity-verification logic here — this module exists purely + to mock IDA responses for eSignet integration testing. diff --git a/mock-relying-party-service/AGENTS.md b/mock-relying-party-service/AGENTS.md new file mode 100644 index 00000000..bd96bfe8 --- /dev/null +++ b/mock-relying-party-service/AGENTS.md @@ -0,0 +1,83 @@ +# AGENTS.md — mock-relying-party-service + +Parent guide: [../AGENTS.md](../AGENTS.md) + +## Purpose + +Node.js/Express backend for the Mock Relying Party portal. Provides OAuth 2.0/OIDC integration +with eSignet, including DPoP (RFC 9449) and PAR (RFC 9126) support. This is a reference/demo +relying-party backend, not a production OIDC client implementation. + +## Layout + +- `app.js` — Express app entry point and route wiring. +- `esignetService.js` — calls out to the eSignet OIDC endpoints (token, PAR, userinfo). +- `cacheClient.js` — in-memory cache (`node-cache`) for DPoP key pairs, keyed by `clientId` + + `state`, TTL 10 minutes (not configurable). +- `clientDetails.js`, `config.js`, `utils.js` — client/config helpers. +- `package.json` — declares `start` (`node app.js`) and `devstart` (`node app.js && nodemon .`) + scripts. There is no test script (`npm test` currently just exits with an error placeholder). + +## Endpoints + +- `GET /dpopJKT?clientId=&state=` — generates a DPoP key pair, returns the JWK thumbprint. +- `GET /requestUri/:clientId` — retrieves the PAR request URI. +- `POST /fetchUserInfo` — exchanges an authorization code for a token and user info. + +See `README.md` in this directory for full request/response shapes and error codes. + +## How to run + +```shell +npm install +export PORT=8888 +export ESIGNET_SERVICE_URL='https://esignet.example-domain.test/v1/esignet' +export ESIGNET_AUD_URL='https://esignet.example-domain.test/v1/esignet/oauth/v2/token' +export CLIENT_PRIVATE_KEY='base64-encoded-private-key-jwk' +export REDIRECT_URI='https://your-domain.example.test/userprofile' +export SCOPE_USER_PROFILE='openid profile' +export ACRS='mosip:idp:acr:linked-wallet mosip:idp:acr:knowledge mosip:idp:acr:generated-code mosip:idp:acr:password' +npm start +``` + +For PAR-enabled setups, also set `ESIGNET_PAR_ENDPOINT` and `ESIGNET_PAR_AUD_URL`. The full +environment-variable list (including the optional FAPI 2.0 / PAR / DPoP variables) is +documented in this directory's `README.md`. + +Docker: + +```shell +docker build -t mock-relying-party-service:local . +docker run -it -d -p 8888:8888 \ + --env ESIGNET_SERVICE_URL='https://esignet.example-domain.test/v1/esignet' \ + --env ESIGNET_AUD_URL='https://esignet.example-domain.test/v1/esignet/oauth/v2/token' \ + --env CLIENT_PRIVATE_KEY='base64-encoded-private-key-jwk' \ + --env REDIRECT_URI='https://your-domain.example.test/userprofile' \ + --env SCOPE_USER_PROFILE='openid profile' \ + --env ACRS='mosip:idp:acr:linked-wallet mosip:idp:acr:knowledge mosip:idp:acr:generated-code mosip:idp:acr:password' \ + mock-relying-party-service:local +``` + +## Configuration + +All configuration is via environment variables — there is no committed secrets file. +`CLIENT_PRIVATE_KEY` is required; `JWE_USERINFO_PRIVATE_KEY` is required only when +`USERINFO_RESPONSE_TYPE=jwe`. Never commit real values for these into the repo, `Dockerfile`, +or any compose file. + +## Agent rules + +### Do + +1. Keep the environment-variable table in `README.md` in sync with any new/renamed variable + read from `process.env` in `app.js`/`config.js`. +2. Preserve the 10-minute, non-configurable TTL behavior of the DPoP cache in `cacheClient.js` + unless the change explicitly intends to make it configurable — and if so, update the + `README.md` accordingly. + +### Do not + +1. Do not commit `CLIENT_PRIVATE_KEY`, `JWE_USERINFO_PRIVATE_KEY`, or any other secret value + into source, `Dockerfile`, or example compose files. +2. Do not add a real test script without checking whether `package.json`'s current placeholder + `test` script is intentionally deferred — coordinate the change with the module README. diff --git a/mock-relying-party-ui-esim/AGENTS.md b/mock-relying-party-ui-esim/AGENTS.md new file mode 100644 index 00000000..f855a8a4 --- /dev/null +++ b/mock-relying-party-ui-esim/AGENTS.md @@ -0,0 +1,78 @@ +# AGENTS.md — mock-relying-party-ui-esim + +Parent guide: [../AGENTS.md](../AGENTS.md) + +## Purpose + +React (Create React App) UI for the eSIM-branded mock relying-party portal, showcasing OIDC +protocol integration with eSignet. Same two-page flow as `mock-relying-party-ui` (Home page +with "Sign in with MOSIP", User Profile page after authentication), packaged as a distinct app +(`package.json` name: `fyntel-app`). + +This is a demo/reference UI, not a production relying-party frontend. + +## Layout + +- `src/` — React application source. +- `public/` — static assets, including `env-config.js` for runtime configuration. +- `.env`, `.env.development` — build-time defaults. +- `nginx/` — nginx config used by the `Dockerfile`. +- `package.json` — CRA scripts: `start`, `build`, `test`, `eject`. Distinct dependency set + from `mock-relying-party-ui` (e.g. TypeScript, `workbox-webpack-plugin`, `ajv` devDependencies + present here but not in the sibling UI module). + +## How to run + +```shell +npm install +npm start +``` + +Runs on port 5000 by default. Update `public/env-config.js` per this directory's `README.md` +before running: `ESIGNET_UI_BASE_URL`, `MOCK_RELYING_PARTY_SERVER_URL`, `REDIRECT_URI`, +`CLIENT_ID`, `ACRS`, `SCOPE_USER_PROFILE`, and optional `MAX_AGE`, `DISPLAY`, `PROMPT`, +`GRANT_TYPE`, `SIGN_IN_BUTTON_PLUGIN_URL`. + +Docker: + +```shell +docker build -t mock-relying-party-ui-esim:local . +docker run -it -d -p 5000:5000 \ + -e ESIGNET_UI_BASE_URL='http://localhost:3000' \ + -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 \ + -e REDIRECT_URI=http://localhost:5000/userprofile \ + -e CLIENT_ID=esim \ + -e ACRS="mosip:esignet:acr:static-code" \ + -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' \ + mock-relying-party-ui-esim:local +``` + +To host on a context path, edit the nginx `location /` block and pass `MOCK_RP_UI_PUBLIC_URL` +at `docker run` time — see this directory's `README.md`. + +Run tests: + +```shell +npm test +``` + +## Configuration + +Runtime configuration is read from `public/env-config.js`, populated at container start. See +this directory's `README.md` for the full variable list. + +## Agent rules + +### Do + +1. Update this directory's `README.md` environment-variable list whenever you add, rename, or + remove a variable read from `env-config.js`. +2. Treat this module as independent from `mock-relying-party-ui` — do not assume a fix here + also applies there, or vice versa. + +### Do not + +1. Do not hardcode real client IDs, redirect URIs, or private keys into source or committed + `.env`/`env-config.js`. +2. Do not assume this module's `package.json` matches `mock-relying-party-ui`'s — verify + before copying dependency or script changes across. diff --git a/mock-relying-party-ui/AGENTS.md b/mock-relying-party-ui/AGENTS.md new file mode 100644 index 00000000..52144181 --- /dev/null +++ b/mock-relying-party-ui/AGENTS.md @@ -0,0 +1,85 @@ +# AGENTS.md — mock-relying-party-ui + +Parent guide: [../AGENTS.md](../AGENTS.md) + +## Purpose + +React (Create React App) reference implementation of a relying party's portal, demonstrating +OIDC-based login against MOSIP eSignet. Two pages: a Home page with "Sign in with MOSIP", and +a User Profile page shown after successful authentication. + +This is a demo/reference UI, not a production relying-party frontend — do not present it as +one. + +## Layout + +- `src/` — React application source. +- `public/` — static assets, including `env-config.js`, which holds runtime-configurable + values consumed at container start (as opposed to build-time `.env` values). +- `.env`, `.env.development` — build-time defaults (only non-sensitive values are tracked, + e.g. `REACT_APP_TOAST_TIMEOUT_IN_SEC`). +- `nginx/` — nginx config used by the `Dockerfile` to serve the built app and proxy to the + mock relying-party backend. +- `package.json` — CRA scripts: `start`, `build`, `test`, `eject`. + +## How to run + +```shell +npm install +npm start +``` + +The app runs on port 5000 by default. Before running, update +`mock-relying-party-ui/public/env-config.js` with the required values (see README table below +for the full variable list): `ESIGNET_UI_BASE_URL`, `MOCK_RELYING_PARTY_SERVER_URL`, +`AUTHORIZE_ENDPOINT`, `REDIRECT_URI`, `CLIENT_ID`, `ACRS`, `SCOPE_USER_PROFILE`, `GRANT_TYPE`, +and the optional `MAX_AGE`, `DISPLAY`, `PROMPT`, `PAR_CALLBACK_NAME`, `PAR_CALLBACK_TIMEOUT`, +`DPOP_CALLBACK_NAME`, `CODE_CHALLENGE`. + +Docker: + +```shell +docker build -t mock-relying-party-ui:local . +docker run -it -d -p 5000:5000 \ + -e ESIGNET_UI_BASE_URL='http://localhost:3000' \ + -e MOCK_RELYING_PARTY_SERVER_URL=http://localhost:8888 \ + -e REDIRECT_URI=http://localhost:5000/userprofile \ + -e CLIENT_ID=healthservices \ + -e ACRS="mosip:esignet:acr:static-code" \ + -e SCOPE_USER_PROFILE='openid%20profile%20resident-service' \ + mock-relying-party-ui:local +``` + +To host on a context path, edit the nginx `location /` block in `nginx/` and pass +`MOCK_RP_UI_PUBLIC_URL` at `docker run` time — see this directory's `README.md` for the exact +nginx snippet. + +Run tests: + +```shell +npm test +``` + +## Configuration + +Runtime configuration is read from `public/env-config.js` (populated at container start), not +rebuilt into the JS bundle per environment. See the full variable table in this directory's +`README.md`, including which flags are feature toggles with hardcoded callback names +(`PAR_CALLBACK_NAME`, `DPOP_CALLBACK_NAME`, `CODE_CHALLENGE`). + +## Agent rules + +### Do + +1. Update `README.md`'s environment-variable table whenever you add, rename, or remove a + variable read from `env-config.js`. +2. Keep this module's dependency set (`package.json`) independent from + `mock-relying-party-ui-esim` — they are separate apps with separate release cadences even + though the code is similar. + +### Do not + +1. Do not hardcode a real `ESIGNET_UI_BASE_URL`, `CLIENT_ID`, or private key value into source + or committed `.env`/`env-config.js` — these are supplied at deploy time. +2. Do not merge changes intended for `mock-relying-party-ui-esim` into this module or vice + versa without checking both READMEs — they diverge in dependencies and branding. diff --git a/partner-onboarder/AGENTS.md b/partner-onboarder/AGENTS.md new file mode 100644 index 00000000..b7261a5b --- /dev/null +++ b/partner-onboarder/AGENTS.md @@ -0,0 +1,58 @@ +# AGENTS.md — partner-onboarder + +Parent guide: [../AGENTS.md](../AGENTS.md) + +## Purpose + +Onboards the mock relying party as an OIDC partner with MOSIP by exchanging certificates, so +that the mock relying-party portal can be used against a real eSignet deployment (identity +plugin). See the [mosip-onboarding repo](https://github.com/mosip/mosip-onboarding) for the +underlying onboarding job this wraps. Only needed when the `mosip-identity` plugin is used +(per the root `README.md`). + +## Layout + +- `install.sh` — runs the onboarding job. +- `delete.sh` — removes the onboarding job/resources. +- `values.yaml` — Helm values controlling which modules the onboarder runs for. + +## How to run + +```shell +# edit values.yaml to select the modules to onboard, then: +./install.sh +``` + +Onboarding produces an HTML report, stored at the configured S3 bucket / NFS directory. Check +this report to confirm onboarding succeeded before assuming the job passed. + +## Configuration + +All configuration is via `values.yaml` (Helm values) — set it before running `install.sh`. + +## Troubleshooting + +(From this directory's `README.md`.) + +- `KER-ATH-401: Authentication Failed` — provide the correct secret key for + `mosip-deployment-client`. +- "Certificate dates are not valid" — check with the admin about adding a grace period in + configuration. +- "Upload of certificate will not be allowed to update other domain certificate" — expected + when re-uploading an `ida-cred` certificate a second time; the onboarding job should only run + once, and this can be ignored if the cert is already present. + +## Agent rules + +### Do + +1. Confirm `values.yaml` targets the correct namespace and module list before running + `install.sh` against any shared cluster. +2. Check the generated HTML onboarding report after every run to confirm success — a + completed job is not the same as a successful onboarding. + +### Do not + +1. Do not commit real `mosip-deployment-client` secret keys or certificates into `values.yaml`. +2. Do not re-run onboarding for an already-onboarded `ida-cred` certificate expecting a clean + result — the "upload not allowed" error on a second run is expected, not a failure to fix. From 563baf1b96f89802a50c31645619aba1b8b483c0 Mon Sep 17 00:00:00 2001 From: Chetan Kumar Hirematha Date: Tue, 11 Aug 2026 13:16:52 +0530 Subject: [PATCH 27/35] #10670: Address CodeRabbit review feedback on AGENTS.md - Stop prescribing npm test for every Node/React module; point to each module's own AGENTS.md/README.md since scripts differ (mock-relying-party-service has no test script at all). - Fix docker-compose path in mock-identity-system/AGENTS.md: from the repo root it's docker-compose/, not ../docker-compose/. - Use MOCK_RELYING_PARTY_SERVER_URL in the mock-relying-party-ui-esim Docker example, matching the variable the Dockerfile/UI actually read (MOCK_RELYING_PARTY_BASE_URL has no effect). - Note that partner-onboarder targets a non-production eSignet deployment only, per the root README's repo-wide scope. Addresses review comments on https://github.com/mosip/esignet-mock-services/pull/601 Signed-off-by: Chetan Kumar Hirematha --- AGENTS.md | 7 +++++-- mock-identity-system/AGENTS.md | 2 +- mock-relying-party-ui-esim/AGENTS.md | 2 +- partner-onboarder/AGENTS.md | 6 ++++-- 4 files changed, 11 insertions(+), 6 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 1c3938cf..e414937f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -121,8 +121,11 @@ Each service/UI also has a `Dockerfile`; CI (`push-trigger.yml`) builds and push independently (see the module guide for exact local run steps). 4. To exercise the mock identity system and relying-party portal together locally, use the Compose files in `docker-compose/` as described in `docker-compose/README.md`. -5. Run the relevant module's tests/build before opening a PR (`mvn -pl mock-identity-system - test` for the Java module; `npm test` / `npm run build` for the Node/React modules). +5. Run the relevant module's documented test/build commands before opening a PR. For + `mock-identity-system`, run `mvn -pl mock-identity-system test`. For each Node/React + module, follow its own `AGENTS.md`/`README.md` — the available npm scripts differ + per module (e.g. `mock-relying-party-service` has no test script; `npm test` there + just exits with an error placeholder). ## Pull Request Guidelines diff --git a/mock-identity-system/AGENTS.md b/mock-identity-system/AGENTS.md index f7f66481..d91cd457 100644 --- a/mock-identity-system/AGENTS.md +++ b/mock-identity-system/AGENTS.md @@ -31,7 +31,7 @@ production system at this module. Local setup (from the repo root, matching `docker-compose/README.md`): ```shell -docker compose --file ../docker-compose/dependent-docker-compose.yml up +docker compose --file docker-compose/dependent-docker-compose.yml up mvn clean install -Dgpg.skip=true -DskipTests=true ``` diff --git a/mock-relying-party-ui-esim/AGENTS.md b/mock-relying-party-ui-esim/AGENTS.md index f855a8a4..c34b33d0 100644 --- a/mock-relying-party-ui-esim/AGENTS.md +++ b/mock-relying-party-ui-esim/AGENTS.md @@ -39,7 +39,7 @@ Docker: docker build -t mock-relying-party-ui-esim:local . docker run -it -d -p 5000:5000 \ -e ESIGNET_UI_BASE_URL='http://localhost:3000' \ - -e MOCK_RELYING_PARTY_BASE_URL=http://localhost:8888 \ + -e MOCK_RELYING_PARTY_SERVER_URL=http://localhost:8888 \ -e REDIRECT_URI=http://localhost:5000/userprofile \ -e CLIENT_ID=esim \ -e ACRS="mosip:esignet:acr:static-code" \ diff --git a/partner-onboarder/AGENTS.md b/partner-onboarder/AGENTS.md index b7261a5b..beec7727 100644 --- a/partner-onboarder/AGENTS.md +++ b/partner-onboarder/AGENTS.md @@ -5,8 +5,10 @@ Parent guide: [../AGENTS.md](../AGENTS.md) ## Purpose Onboards the mock relying party as an OIDC partner with MOSIP by exchanging certificates, so -that the mock relying-party portal can be used against a real eSignet deployment (identity -plugin). See the [mosip-onboarding repo](https://github.com/mosip/mosip-onboarding) for the +that the mock relying-party portal can be used against a non-production eSignet deployment +(identity plugin) — this repo is only for non-production use (per the root `README.md`), even +though `install.sh`/`values.yaml` accept inputs (public domains, certificates, S3/NFS config) +that could target a production-style cluster. See the [mosip-onboarding repo](https://github.com/mosip/mosip-onboarding) for the underlying onboarding job this wraps. Only needed when the `mosip-identity` plugin is used (per the root `README.md`). From 2185dec465254805242081e95710fabba16594d3 Mon Sep 17 00:00:00 2001 From: Bhuminathan M <111699703+bhumi46@users.noreply.github.com> Date: Tue, 18 Aug 2026 17:13:49 +0530 Subject: [PATCH 28/35] fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps (#603) * fix: 602 convert extraEnvVars/extraEnvVarsAdditional to maps Helm merges map keys across values layers but replaces lists wholesale, so any downstream override of extraEnvVars/extraEnvVarsAdditional had to re-declare the whole list just to change one entry. Convert both to maps keyed by env var name in mock-identity-system, mock-relying-party-service, and mock-relying-party-ui, and render them with a range loop that auto-detects plain scalars vs. valueFrom, matching the existing domainConfig pattern already used in these charts. Same fix already applied to mosip/esignet (issue #2380). Signed-off-by: bhumi46 * fix: 602 update mock-identity-system installer for extraEnvVarsAdditional map contract deploy/mock-identity-system/install.sh generated extraEnvVarsAdditional as a list in two places (PKCS12 and softhsm branches), which produced broken index-keyed env entries against the chart's map-shaped default introduced in this PR. Convert both to the map contract (KEY: value / KEY: {valueFrom: ...}), matching the fix already applied to esignet's legacy installer scripts. Signed-off-by: bhumi46 --------- Signed-off-by: bhumi46 --- deploy/mock-identity-system/install.sh | 13 +++---- .../templates/deployment.yaml | 18 +++++++-- helm/mock-identity-system/values.yaml | 38 ++++++++++--------- .../templates/deployment.yaml | 9 ++++- helm/mock-relying-party-service/values.yaml | 7 ++-- .../templates/deployment.yaml | 9 ++++- helm/mock-relying-party-ui/values.yaml | 7 ++-- 7 files changed, 59 insertions(+), 42 deletions(-) diff --git a/deploy/mock-identity-system/install.sh b/deploy/mock-identity-system/install.sh index e26d0524..19f836ec 100755 --- a/deploy/mock-identity-system/install.sh +++ b/deploy/mock-identity-system/install.sh @@ -95,11 +95,9 @@ function installing_mock-identity-system() { pkcs12_env_file=$(mktemp) cat < "$pkcs12_env_file" extraEnvVarsAdditional: - - name: MOSIP_KERNEL_KEYMANAGER_HSM_KEYSTORE_TYPE - value: "PKCS12" - - name: MOSIP_KERNEL_KEYMANAGER_HSM_CONFIG_PATH - value: "${volume_mount_path}keystore.p12" - - name: MOSIP_KERNEL_KEYMANAGER_HSM_KEYSTORE_PASS + MOSIP_KERNEL_KEYMANAGER_HSM_KEYSTORE_TYPE: "PKCS12" + MOSIP_KERNEL_KEYMANAGER_HSM_CONFIG_PATH: "${volume_mount_path}keystore.p12" + MOSIP_KERNEL_KEYMANAGER_HSM_KEYSTORE_PASS: valueFrom: secretKeyRef: name: mockid-pkcs12-secret @@ -121,13 +119,12 @@ EOF softhsm_env_file=$(mktemp) cat < "$softhsm_env_file" extraEnvVarsAdditional: - - name: SOFTHSM_MOCK_IDENTITY_SYSTEM_SECURITY_PIN + SOFTHSM_MOCK_IDENTITY_SYSTEM_SECURITY_PIN: valueFrom: secretKeyRef: name: softhsm-mock-identity-system key: security-pin - - name: hsm_local_dir_name - value: hsm-client + hsm_local_dir_name: hsm-client extraEnvVarsCM: - softhsm-mock-identity-system-share EOF diff --git a/helm/mock-identity-system/templates/deployment.yaml b/helm/mock-identity-system/templates/deployment.yaml index 0439553f..34b3419e 100644 --- a/helm/mock-identity-system/templates/deployment.yaml +++ b/helm/mock-identity-system/templates/deployment.yaml @@ -96,11 +96,21 @@ spec: value: {{ .Values.containerSecurityContext.runAsUser }} - name: JDK_JAVA_OPTIONS value: {{ .Values.additionalResources.javaOpts }} - {{- if .Values.extraEnvVars }} - {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }} + {{- range $key, $val := .Values.extraEnvVars }} + - name: {{ $key }} + {{- if kindIs "map" $val }} + {{- include "common.tplvalues.render" (dict "value" $val "context" $) | nindent 14 }} + {{- else }} + value: {{ $val | quote }} + {{- end }} {{- end }} - {{- if .Values.extraEnvVarsAdditional }} - {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVarsAdditional "context" $) | nindent 12 }} + {{- range $key, $val := .Values.extraEnvVarsAdditional }} + - name: {{ $key }} + {{- if kindIs "map" $val }} + {{- include "common.tplvalues.render" (dict "value" $val "context" $) | nindent 14 }} + {{- else }} + value: {{ $val | quote }} + {{- end }} {{- end }} {{- range $key, $val := .Values.domainConfig }} - name: {{ $key }} diff --git a/helm/mock-identity-system/values.yaml b/helm/mock-identity-system/values.yaml index 419b29cd..0ec370df 100644 --- a/helm/mock-identity-system/values.yaml +++ b/helm/mock-identity-system/values.yaml @@ -234,69 +234,71 @@ customReadinessProbe: {} updateStrategy: type: RollingUpdate -## Additional environment variables to set +## Additional environment variables to set, keyed by env var name. ## Example: ## extraEnvVars: -## - name: FOO -## value: "bar" +## FOO: "bar" +## BAZ: +## valueFrom: +## configMapKeyRef: +## name: some-configmap +## key: some-key ## extraEnvVars: - - name: DATABASE_HOST + DATABASE_HOST: valueFrom: configMapKeyRef: name: mockid-postgres-config key: database-host - - name: DATABASE_PORT + DATABASE_PORT: valueFrom: configMapKeyRef: name: mockid-postgres-config key: database-port - - name: DATABASE_NAME + DATABASE_NAME: valueFrom: configMapKeyRef: name: mockid-postgres-config key: database-name - - name: DATABASE_USERNAME + DATABASE_USERNAME: valueFrom: configMapKeyRef: name: mockid-postgres-config key: database-username - - name: DB_DBUSER_PASSWORD + DB_DBUSER_PASSWORD: valueFrom: secretKeyRef: name: db-common-secrets key: db-dbuser-password - - name: MOSIP_ESIGNET_MOCK_SUPPORTED_FIELDS - value: individualId,password - - name: MOSIP_ESIGNET_HOST + MOSIP_ESIGNET_MOCK_SUPPORTED_FIELDS: individualId,password + MOSIP_ESIGNET_HOST: valueFrom: configMapKeyRef: name: esignet-global key: mosip-esignet-host - - name: REDIS_HOST + REDIS_HOST: valueFrom: configMapKeyRef: name: redis-config key: redis-host - - name: REDIS_PORT + REDIS_PORT: valueFrom: configMapKeyRef: name: redis-config key: redis-port - - name: REDIS_PASSWORD + REDIS_PASSWORD: valueFrom: secretKeyRef: name: redis key: redis-password ## Additional environment variables to append on top of extraEnvVars, without -## having to restate the entries already declared there +## having to restate the entries already declared there. Keyed by env var name. ## Example: ## extraEnvVarsAdditional: -## - name: FOO -## value: "bar" +## FOO: "bar" ## -extraEnvVarsAdditional: [] +extraEnvVarsAdditional: {} ## ConfigMap with extra environment variables that used ## diff --git a/helm/mock-relying-party-service/templates/deployment.yaml b/helm/mock-relying-party-service/templates/deployment.yaml index fb6d09ca..3aceeebe 100644 --- a/helm/mock-relying-party-service/templates/deployment.yaml +++ b/helm/mock-relying-party-service/templates/deployment.yaml @@ -104,8 +104,13 @@ spec: name: jwe-userinfo-service-secrets - name: USERINFO_RESPONSE_TYPE value: {{ .Values.mock_relying_party_service.USERINFO_RESPONSE_TYPE }} - {{- if .Values.extraEnvVars }} - {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }} + {{- range $key, $val := .Values.extraEnvVars }} + - name: {{ $key }} + {{- if kindIs "map" $val }} + {{- include "common.tplvalues.render" (dict "value" $val "context" $) | nindent 14 }} + {{- else }} + value: {{ $val | quote }} + {{- end }} {{- end }} {{- range $key, $val := .Values.domainConfig }} - name: {{ $key }} diff --git a/helm/mock-relying-party-service/values.yaml b/helm/mock-relying-party-service/values.yaml index 4d015da4..43230873 100644 --- a/helm/mock-relying-party-service/values.yaml +++ b/helm/mock-relying-party-service/values.yaml @@ -241,14 +241,13 @@ customReadinessProbe: {} updateStrategy: type: RollingUpdate -## Additional environment variables to set +## Additional environment variables to set, keyed by env var name. ## Example: ## extraEnvVars: -## - name: FOO -## value: "bar" +## FOO: "bar" ## ## TODO: the below env variable is not used, but required. Remove it later -extraEnvVars: [] +extraEnvVars: {} ## ConfigMap with extra environment variables ## diff --git a/helm/mock-relying-party-ui/templates/deployment.yaml b/helm/mock-relying-party-ui/templates/deployment.yaml index 76fa4d32..dc55c95a 100644 --- a/helm/mock-relying-party-ui/templates/deployment.yaml +++ b/helm/mock-relying-party-ui/templates/deployment.yaml @@ -127,8 +127,13 @@ spec: - name: FALLBACK_LANG value: {{ .Values.mock_relying_party_ui.FALLBACK_LANG | quote }} - {{- if .Values.extraEnvVars }} - {{- include "common.tplvalues.render" (dict "value" .Values.extraEnvVars "context" $) | nindent 12 }} + {{- range $key, $val := .Values.extraEnvVars }} + - name: {{ $key }} + {{- if kindIs "map" $val }} + {{- include "common.tplvalues.render" (dict "value" $val "context" $) | nindent 14 }} + {{- else }} + value: {{ $val | quote }} + {{- end }} {{- end }} envFrom: {{- if .Values.extraEnvVarsCM }} diff --git a/helm/mock-relying-party-ui/values.yaml b/helm/mock-relying-party-ui/values.yaml index 8e356ab0..82856b06 100644 --- a/helm/mock-relying-party-ui/values.yaml +++ b/helm/mock-relying-party-ui/values.yaml @@ -234,13 +234,12 @@ customReadinessProbe: {} updateStrategy: type: RollingUpdate -## Additional environment variables to set +## Additional environment variables to set, keyed by env var name. ## Example: ## extraEnvVars: -## - name: FOO -## value: "bar" +## FOO: "bar" ## -extraEnvVars: [] +extraEnvVars: {} ## ConfigMap with extra environment variables ## From c92a99b86b7a7a303fd9d916055dc1ad28f58cb4 Mon Sep 17 00:00:00 2001 From: Praful Rakhade Date: Fri, 21 Aug 2026 13:11:41 +0530 Subject: [PATCH 29/35] Change image tag from release-0.10.x to develop Signed-off-by: Praful Rakhade --- helm/mock-identity-system/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/mock-identity-system/values.yaml b/helm/mock-identity-system/values.yaml index 0ec370df..638036ad 100644 --- a/helm/mock-identity-system/values.yaml +++ b/helm/mock-identity-system/values.yaml @@ -53,7 +53,7 @@ service: image: registry: docker.io repository: mosipdev/mock-identity-system - tag: release-0.10.x + tag: develop ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images From d8771a79a78fed63bdda075511cffdddbf2bc40b Mon Sep 17 00:00:00 2001 From: Praful Rakhade Date: Fri, 21 Aug 2026 13:12:32 +0530 Subject: [PATCH 30/35] Change image tag from release-0.10.x to develop Signed-off-by: Praful Rakhade --- helm/mock-relying-party-service/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/mock-relying-party-service/values.yaml b/helm/mock-relying-party-service/values.yaml index 43230873..4cfcce6d 100644 --- a/helm/mock-relying-party-service/values.yaml +++ b/helm/mock-relying-party-service/values.yaml @@ -52,7 +52,7 @@ service: image: registry: docker.io repository: mosipdev/mock-relying-party-service - tag: release-0.10.x + tag: develop ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images From dcaa43d77b58e104677ce676d246b613f1db921b Mon Sep 17 00:00:00 2001 From: Praful Rakhade Date: Fri, 21 Aug 2026 13:13:02 +0530 Subject: [PATCH 31/35] Change image tag from release-0.10.x to develop Signed-off-by: Praful Rakhade --- helm/mock-relying-party-ui/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/mock-relying-party-ui/values.yaml b/helm/mock-relying-party-ui/values.yaml index 82856b06..9faf055b 100644 --- a/helm/mock-relying-party-ui/values.yaml +++ b/helm/mock-relying-party-ui/values.yaml @@ -52,7 +52,7 @@ service: image: registry: docker.io repository: mosipdev/mock-relying-party-ui - tag: release-0.10.x + tag: develop ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' From 8125c7f6718032926a70fecbb587e506337e14d6 Mon Sep 17 00:00:00 2001 From: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> Date: Mon, 24 Aug 2026 21:20:50 +0530 Subject: [PATCH 32/35] #2347 Update database host and clean up configuration (#610) Updated the host to include the namespace and removed unused service configurations. Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> --- deploy/postgres/init_values.yaml | 41 +------------------------------- 1 file changed, 1 insertion(+), 40 deletions(-) diff --git a/deploy/postgres/init_values.yaml b/deploy/postgres/init_values.yaml index 626284f9..d195aea6 100644 --- a/deploy/postgres/init_values.yaml +++ b/deploy/postgres/init_values.yaml @@ -8,7 +8,7 @@ databases: dbName: mosip_mockidentitysystem # customize e.g. mosip_mockidentitysystem02 dbUser: mockidentityuser # customize e.g. mockidentityuser02 defaultDb: postgres - host: "postgres-postgresql" + host: "postgres-postgresql.postgres" port: 5432 su: user: postgres @@ -18,42 +18,3 @@ databases: dml: 1 repoUrl: https://github.com/mosip/esignet-mock-services.git branch: develop - - mosip_master: - enabled: false - - mosip_audit: - enabled: false - - mosip_keymgr: - enabled: false - - mosip_kernel: - enabled: false - - mosip_idmap: - enabled: false - - mosip_prereg: - enabled: false - - mosip_idrepo: - enabled: false - - mosip_ida: - enabled: false - - mosip_credential: - enabled: false - - mosip_regprc: - enabled: false - - mosip_pms: - enabled: false - - mosip_resident: - enabled: false - - mosip_hotlist: - enabled: false From 17b3d2f980ee7c684ff12bc4bc07d68531e4f652 Mon Sep 17 00:00:00 2001 From: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> Date: Tue, 25 Aug 2026 13:07:58 +0530 Subject: [PATCH 33/35] #2347 Update database username in postgres config (#611) * #2347 Update database username in postgres config Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> * #2347 Update database username in deploy.properties Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> --------- Signed-off-by: Abhishek S <127825992+abhishek8shankar@users.noreply.github.com> --- db_scripts/mosip_mockidentitysystem/deploy.properties | 2 +- deploy/postgres/postgres-config.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/db_scripts/mosip_mockidentitysystem/deploy.properties b/db_scripts/mosip_mockidentitysystem/deploy.properties index 64f0de81..3eec802c 100644 --- a/db_scripts/mosip_mockidentitysystem/deploy.properties +++ b/db_scripts/mosip_mockidentitysystem/deploy.properties @@ -3,5 +3,5 @@ DB_PORT=5432 SU_USER=postgres DEFAULT_DB_NAME=postgres MOSIP_DB_NAME=mosip_mockidentitysystem -DB_UNAME=mockidsystemuser +DB_UNAME=mockidentityuser DML_FLAG=1 diff --git a/deploy/postgres/postgres-config.yaml b/deploy/postgres/postgres-config.yaml index 013be4fc..c7bae7ba 100644 --- a/deploy/postgres/postgres-config.yaml +++ b/deploy/postgres/postgres-config.yaml @@ -8,5 +8,5 @@ metadata: data: database-host: "postgres-postgresql.postgres" database-port: "5432" - database-username: "mockidsystemuser" + database-username: "mockidentityuser" database-name: "mosip_mockidentitysystem" From 1d0f18c16c4195a9c9804430072a178508ad4c1d Mon Sep 17 00:00:00 2001 From: Sachin Rana Date: Thu, 27 Aug 2026 11:52:25 +0530 Subject: [PATCH 34/35] updated version 0.13.0 to 0.14.0 Signed-off-by: Sachin Rana --- .../sql/0.13.0_to_0.14.0_rollback.sql | 1 + .../mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_upgrade.sql | 1 + docker-compose/docker-compose.yml | 2 +- docker-compose/mock-relying-party-portal-docker-compose.yml | 4 ++-- .../mock-relying-party-portal-fapi2-docker-compose.yml | 4 ++-- helm/mock-identity-system/values.yaml | 4 ++-- helm/mock-relying-party-service/values.yaml | 4 ++-- helm/mock-relying-party-ui/values.yaml | 4 ++-- mock-identity-system/pom.xml | 4 ++-- pom.xml | 2 +- 10 files changed, 16 insertions(+), 14 deletions(-) create mode 100644 db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_rollback.sql create mode 100644 db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_upgrade.sql diff --git a/db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_rollback.sql b/db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_rollback.sql new file mode 100644 index 00000000..1a2e0a41 --- /dev/null +++ b/db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_rollback.sql @@ -0,0 +1 @@ +\echo 'Rollback Queries not required for transition from $CURRENT_VERSION to $UPGRADE_VERSION' \ No newline at end of file diff --git a/db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_upgrade.sql b/db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_upgrade.sql new file mode 100644 index 00000000..381e2be1 --- /dev/null +++ b/db_upgrade_script/mosip_mockidentitysystem/sql/0.13.0_to_0.14.0_upgrade.sql @@ -0,0 +1 @@ +\echo 'Upgrade Queries not required for transition from $CURRENT_VERSION to $UPGRADE_VERSION' \ No newline at end of file diff --git a/docker-compose/docker-compose.yml b/docker-compose/docker-compose.yml index 53f04d89..2a30fdd4 100644 --- a/docker-compose/docker-compose.yml +++ b/docker-compose/docker-compose.yml @@ -10,7 +10,7 @@ services: - ./init.sql:/docker-entrypoint-initdb.d/init.sql mock-identity-system: - image: "mosipid/mock-identity-system:0.13.0" + image: "mosipqa/mock-identity-system:0.14.x" user: root ports: - 8082:8082 diff --git a/docker-compose/mock-relying-party-portal-docker-compose.yml b/docker-compose/mock-relying-party-portal-docker-compose.yml index cb2bcbfa..33857dfa 100644 --- a/docker-compose/mock-relying-party-portal-docker-compose.yml +++ b/docker-compose/mock-relying-party-portal-docker-compose.yml @@ -1,6 +1,6 @@ services: mock-relying-party-service: - image: "mosipid/mock-relying-party-service:0.13.0" + image: "mosipqa/mock-relying-party-service:0.14.x" user: root ports: - 8888:8888 @@ -13,7 +13,7 @@ services: - USERINFO_RESPONSE_TYPE=jwt mock-relying-party-ui: - image: "mosipid/mock-relying-party-ui:0.13.0" + image: "mosipqa/mock-relying-party-ui:0.14.x" user: root ports: - 3000:3000 diff --git a/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml b/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml index 216c5055..50e53f8a 100644 --- a/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml +++ b/docker-compose/mock-relying-party-portal-fapi2-docker-compose.yml @@ -1,6 +1,6 @@ services: mock-relying-party-service: - image: "mosipid/mock-relying-party-service:0.13.0" + image: "mosipqa/mock-relying-party-service:0.14.x" user: root ports: - 8888:8888 @@ -18,7 +18,7 @@ services: - CLAIMS_USER_PROFILE={"userinfo":{"name":{"essential":true},"phone_number":{"essential":true},"verified_claims":[{"verification":{"trust_framework":{"value":"ABC TF"}},"claims":{"phone_number":{"essential":true}}},{"verification":{"trust_framework":{"value":"XYZ TF"}},"claims":{"name":{"essential":true}}}]},"id_token":{}} mock-relying-party-ui: - image: "mosipid/mock-relying-party-ui:0.13.0" + image: "mosipqa/mock-relying-party-ui:0.14.x" user: root ports: - 3000:3000 diff --git a/helm/mock-identity-system/values.yaml b/helm/mock-identity-system/values.yaml index 021757d9..ec20f7e0 100644 --- a/helm/mock-identity-system/values.yaml +++ b/helm/mock-identity-system/values.yaml @@ -52,8 +52,8 @@ service: image: registry: docker.io - repository: mosipid/mock-identity-system - tag: 0.13.0 + repository: mosipqa/mock-identity-system + tag: 0.14.x ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images diff --git a/helm/mock-relying-party-service/values.yaml b/helm/mock-relying-party-service/values.yaml index b6ddc6dd..c9fc7858 100644 --- a/helm/mock-relying-party-service/values.yaml +++ b/helm/mock-relying-party-service/values.yaml @@ -51,8 +51,8 @@ service: image: registry: docker.io - repository: mosipid/mock-relying-party-service - tag: 0.13.0 + repository: mosipqa/mock-relying-party-service + tag: 0.14.x ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images diff --git a/helm/mock-relying-party-ui/values.yaml b/helm/mock-relying-party-ui/values.yaml index b4ad13ba..eb6c0462 100644 --- a/helm/mock-relying-party-ui/values.yaml +++ b/helm/mock-relying-party-ui/values.yaml @@ -51,8 +51,8 @@ service: image: registry: docker.io - repository: mosipid/mock-relying-party-ui - tag: 0.13.0 + repository: mosipqa/mock-relying-party-ui + tag: 0.14.x ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' diff --git a/mock-identity-system/pom.xml b/mock-identity-system/pom.xml index d26958ee..f79f7748 100644 --- a/mock-identity-system/pom.xml +++ b/mock-identity-system/pom.xml @@ -5,11 +5,11 @@ io.mosip.esignet.mock esignet-mock-parent - 0.13.0 + 0.14.0-SNAPSHOT mock-identity-system - 0.13.0 + 0.14.0-SNAPSHOT jar mock-identity-system diff --git a/pom.xml b/pom.xml index ff4cc1c6..83fe104d 100644 --- a/pom.xml +++ b/pom.xml @@ -16,7 +16,7 @@ 4.0.0 io.mosip.esignet.mock esignet-mock-parent - 0.13.0 + 0.14.0-SNAPSHOT pom esignet-mock Parent project of MOSIP e-Signet Mock Services From 0baabe9580c94a3d40739a12d9a52f99af22d6ba Mon Sep 17 00:00:00 2001 From: Sachin Rana Date: Thu, 27 Aug 2026 12:26:54 +0530 Subject: [PATCH 35/35] updated helm chart version Signed-off-by: Sachin Rana --- deploy/mock-identity-system/install.sh | 2 +- deploy/mock-relying-party-service/install.sh | 2 +- deploy/mock-relying-party-ui/install.sh | 2 +- deploy/postgres/init_values.yaml | 2 +- helm/mock-identity-system/Chart.yaml | 2 +- helm/mock-relying-party-service/Chart.yaml | 2 +- helm/mock-relying-party-ui/Chart.yaml | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/deploy/mock-identity-system/install.sh b/deploy/mock-identity-system/install.sh index efe92289..2ccbd68f 100755 --- a/deploy/mock-identity-system/install.sh +++ b/deploy/mock-identity-system/install.sh @@ -7,7 +7,7 @@ if [ $# -ge 1 ] ; then fi NS=mockid -CHART_VERSION=0.13.0 +CHART_VERSION=0.14.0-develop echo Create $NS namespace kubectl create ns $NS diff --git a/deploy/mock-relying-party-service/install.sh b/deploy/mock-relying-party-service/install.sh index a1b4f58e..c45b2132 100755 --- a/deploy/mock-relying-party-service/install.sh +++ b/deploy/mock-relying-party-service/install.sh @@ -24,7 +24,7 @@ function installing_mock-relying-party-service() { NS=esignet MOCK_REPLYING_PARTY_SERVICE_NAME=mock-relying-party-service - CHART_VERSION=0.13.0 + CHART_VERSION=0.14.0-develop echo Create $NS namespace kubectl create ns $NS || true diff --git a/deploy/mock-relying-party-ui/install.sh b/deploy/mock-relying-party-ui/install.sh index 2a74f339..9baf8f61 100755 --- a/deploy/mock-relying-party-ui/install.sh +++ b/deploy/mock-relying-party-ui/install.sh @@ -25,7 +25,7 @@ function installing_mock-relying-party-ui() { NS=esignet MOCK_REPLYING_PARTY_UI_SERVICE_NAME=mock-relying-party-ui MOCK_REPLYING_PARTY_SERVICE_NAME=mock-relying-party-service - CHART_VERSION=0.13.0 + CHART_VERSION=0.14.0-develop read -p "Please provide mock relying party ui domain (eg: healthservices.sandbox.xyz.net ) : " MOCK_UI_HOST if [ -z "$MOCK_UI_HOST" ]; then diff --git a/deploy/postgres/init_values.yaml b/deploy/postgres/init_values.yaml index 017f7cff..c43003a8 100644 --- a/deploy/postgres/init_values.yaml +++ b/deploy/postgres/init_values.yaml @@ -17,4 +17,4 @@ databases: key: postgres-password dml: 1 repoUrl: https://github.com/mosip/esignet-mock-services.git - branch: 0.13.0 + branch: release-0.14.x diff --git a/helm/mock-identity-system/Chart.yaml b/helm/mock-identity-system/Chart.yaml index c62d25dd..16dfaf1a 100644 --- a/helm/mock-identity-system/Chart.yaml +++ b/helm/mock-identity-system/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: mock-identity-system description: A Helm chart for MOSIP mock-identity-system module type: application -version: 0.13.0 +version: 0.14.0-develop appVersion: "" dependencies: - name: common diff --git a/helm/mock-relying-party-service/Chart.yaml b/helm/mock-relying-party-service/Chart.yaml index 0097db20..88fe0f82 100644 --- a/helm/mock-relying-party-service/Chart.yaml +++ b/helm/mock-relying-party-service/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: mock-relying-party-service description: A Helm chart to file server application. type: application -version: 0.13.0 +version: 0.14.0-develop appVersion: "" dependencies: - name: common diff --git a/helm/mock-relying-party-ui/Chart.yaml b/helm/mock-relying-party-ui/Chart.yaml index 1206b45e..74f11155 100644 --- a/helm/mock-relying-party-ui/Chart.yaml +++ b/helm/mock-relying-party-ui/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: mock-relying-party-ui description: A Helm chart for MOSIP OIDC UI module type: application -version: 0.13.0 +version: 0.14.0-develop appVersion: "" dependencies: - name: common