A Consumer Data Right OpenID and FAPI 1.0 Advanced compliant Identity Provider
6.1K

This project contains source code, documentation and deployment artefacts for a FAPI 1.0 compliant Authorisation Server, built to conform to the Consumer Data Standards and CDR.
The project is used in the Participant Tooling Authorisation Server, providing the Infosec functionality. The repository is also provided to the CDR community for use within participant solutions.
The Authorisation Server:
Note: Consumer Data Standards FAPI 1.0 Migration Phase 1 is no longer supported.

The Authorisation Server is certified by OpenID using OpenID FAPI conformance testing. Testing was completed and passed using:
Full test results for the Authorisation Server can be seen on the OpenID website. Certification for the Authorisation Server can be seen under the Australia CDR profile section on the OpenID website

The Authorisation Server can be used for providing authentication to the Banking and Energy Mock Data Holders. You can swap out any of the Mock Data Holders and Mock Data Recipient solutions with a solution of your own.
Please note that the Authorisation Server can also run as an embedded component of the Banking and Energy Mock Data Holders solution. This is not covered in this guide.
There are a number of ways that the artefacts within this project can be used:
To get started, clone the source code.
git clone https://github.com/ConsumerDataRight/authorisation-server.git
To get help on launching and debugging the solution, see the help guide.
If you would like to contribute features or fixes back to the Authorisation Server repository, consult the contributing guidelines.
A version of the Authorisation Server is built into a single Docker image that is made available via docker hub.
docker pull consumerdataright/authorisation-server
To get help on launching the solution in a container, see the help guide.
The OpenID Connect Discovery document for Authorisation Server can be viewed by accessing:
https://localhost:8001/.well-known/openid-configuration
Since the Authorisation Server is an embedded component of the Banking and Energy Mock Data Holder solutions, the Authorisation Server's functionality can be further explored by using the Mock CDR Ecosystem. The Mock Data Recipient has been built as a test harness to demonstrate the interactions between the Register and Mock Data Holders with an embedded Authorisation Server. The Mock Data Recipient can be used to perform a Dynamic Client Registration, create Consent Arrangements and explore Mock Data Holder API's. The provided help guide will assist in setting up the Mock CDR Ecosystem in Docker.
Consult the Certificate Management documentation for more information about how certificates are used for the Authorisation Server.
The Authorisation Server contains seed data files in a json format. The Authorisation Server will read directly from these files when:
The following steps required to load your own data into the container instance or code running in Visual Studio:
/Source/CdrAuthServer/Data folder of the container or source code directory, make a copy of the customer-seed-data.json file for banking customers or the customer-seed-data-energy.json file for energy customers, renaming to a name of your choice, e.g. my-new-customer-seed-data.json./Source/CdrAuthServer/appsettings.json file to load the new data file for use in the APIs:"SeedData": {
"FilePath": "Data/my-new-customer-seed-data.json",
},
/Source/CdrAuthServer.UI/.env.* file to load the new data file for use in the User Interface:REACT_APP_DATA_FILE_NAME=my-new-customer-seed-data.json
To get help on launching the solution in a container, see the help guide.
The following diagram outlines the high level architecture of the Authorisation Server

The following diagram illustrates the docker container for the Authorisation Server

The following diagram illustrates the high level features for the Authorisation Server

The Authorisation Server contains the following components:
https://localhost:8001cdr-auth-serverhttps://localhost:8002https://localhost:8001Get Customer endpoint.https://localhost:3000The following technologies have been used to build the Authorisation Server:
C# using the .Net 8 framework.Ocelot.SQL instance.xUnit is the framework used for writing and running tests.Microsoft Playwright is the framework used for Web Testing.The Authorisation Server contains the following features:
The Authorisation Server has the following endpoints:
| Endpoint | Methods | Transport | Authorisation | Description |
|---|---|---|---|---|
| /.well-known/openid-configuration | GET | TLS | None | Open ID Discovery Document |
| /jwks | GET | TLS | None | JWKS endpoint |
| /auth | GET | TLS | None | Authorization endpoint |
| /registration | POST | mTLS | None | Create registration endpoint (DCR) |
| /registration | GET, PUT, DELETE | mTLS | Bearer | Create registration endpoint (DCR) |
| /par | POST | mTLS | Client Assertion | Pushed Authorization Request endpoint (PAR) |
| /token | POST | mTLS | Client Assertion | Token endpoint |
| /userinfo | POST | mTLS | Bearer | Userinfo endpoint |
| /introspect | POST | mTLS | Client Assertion | Introspection endpoint |
| /token/revocation | POST | mTLS | Client Assertion | Token revocation endpoint |
| /arrangement/revocation | POST | mTLS | Client Assertion | Arrangement revocation endpoint |
Standard, "out-of-the-box" Authorisation Server functionality needs to be customised in order to meet the Consumer Data Standards.
The information below lists the customisation required for each endpoint:
cdr_arrangement_id, sharing_duration) from the request object.cdr_arrangement_id claim in the payload.sub claim needs to be obfuscated using the PPID rules of the CDS.cdr_arrangement_id claim.Automated tests have been created as part of this solution. See the Test Automation Execution Guide documentation for more information.
By default the application logs to console as well as into tables within the application database.
However, OpenTelemetry can be configured by setting the environment variables appropriately.
The example below uses Seq for simplicity, we do not endorse any particular product. Choose an OpenTelemetry vendor is suitable for your needs.
For example, you may set up a local OTLP ingestion endpoint
docker run -e ACCEPT_EULA=Y --rm -p 4318:80 5341:5341 datalust/seq
and then set the following
| Environment variable | Value |
|---|---|
OTEL_EXPORTER_OTLP_ENDPOINT | http://localhost:5341/ingest/otlp |
OTEL_EXPORTER_OTLP_PROTOCOL | http/protobuf |
After which you should be able to view telemetry.
We encourage contributions from the community. See our contributing guidelines.
This project has adopted the Contributor Covenant. For more information see the code of conduct.
See our security policy for information on security controls, reporting a vulnerability and supported versions.
The Authorisation Server is provided as a development tool only. It conforms to the Consumer Data Standards.
Content type
Image
Digest
sha256:110a7dd13…
Size
189.9 MB
Last updated
3 months ago
docker pull consumerdataright/authorisation-server