Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dwn 42070 jackson databind #1601

Draft
wants to merge 154 commits into
base: master
Choose a base branch
from
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
154 commits
Select commit Hold shift + click to select a range
d13e21d
Add French messages
Nov 23, 2017
6385fd9
Merge pull request #1325 from patfrat/1.3.x
jricher Nov 26, 2017
1cc3b8f
Merge remote-tracking branch 'upstream/1.3.x' into 1.3.x
gkatiyar May 28, 2018
d9d48cb
Upgraded libraries for mitigating known vulnerabilities
gkatiyar May 30, 2018
67f584f
Added jenkins file
gkatiyar May 30, 2018
98021f4
Modified Jenkins file
gkatiyar May 30, 2018
7cab117
Modified Jenkins file
gkatiyar May 30, 2018
2393a4d
Modified Jenkins file
gkatiyar May 30, 2018
65fbca8
Modified Jenkins file
gkatiyar May 30, 2018
6ea19c7
Modified Jenkins file
gkatiyar May 30, 2018
e6b816e
Created internal release for MitreID Connect
gkatiyar Sep 26, 2018
6e60beb
Jenkinsfile fix for repo address
gkatiyar Sep 26, 2018
34d1425
Jenkinsfile and maven build fixes
gkatiyar Sep 26, 2018
b13874b
DWN-26583: Upgraded spring oauth to version 2.1.3 for security
gkatiyar Nov 1, 2018
b7b2c2d
DWN-25303: Bumps a couple versions
gresham-Carling Nov 13, 2018
028972c
DWN-26566: Added password encoded to the client entity service and ch…
gkatiyar Nov 14, 2018
0ae12c2
DWN-25861: Manually specifies the scope column name
gresham-Carling Nov 28, 2018
c12cb18
DWN-27040: Changes when the client secret is given to the UI
gresham-Carling Dec 3, 2018
5abebb7
DWN-27040: Adds the same secret key limiting to client registration
gresham-Carling Dec 4, 2018
2008404
DWN-27040: Bit of refactoring, Protected Resources now protected
gresham-Carling Dec 5, 2018
12f91b1
Merge pull request #2 from gresham-computing/client-secret-security
gresham-Carling Dec 14, 2018
3aa9cb9
DWN-27799 - update spring-security-oauth2 for CVE-2019-3778
dmurch-gresham Mar 6, 2019
a628162
Appends our changes to the CHANGELOG
gresham-Carling Mar 14, 2019
976d439
Merge pull request #3 from gresham-computing/spring-oauth-update
dmurch-gresham Mar 19, 2019
18c7993
DWN-30296 : upgrade jackson to 2.10.0
hsmith-gresham Oct 25, 2019
e91a153
DWN-30463 : update spring security bom
hsmith-gresham Oct 25, 2019
df84942
DWN-30574 : upgrade nimbus-jose-jwt to 7.9
hsmith-gresham Oct 29, 2019
a30b999
No Jira : alter building mechanism to be independent on Jenkins build…
hsmith-gresham Dec 4, 2019
d451075
Merge pull request #4 from gresham-computing/nexusIqUpgrades
hsmith-gresham Dec 4, 2019
28e69c3
DWN-31929 : mitigate open id common XSS vulnerability
hsmith-gresham Feb 17, 2020
dd92d84
DWN-31929 : updated dependencies and made method void
hsmith-gresham Feb 17, 2020
acaa64b
DWN-31929 : move whitelist to class level
hsmith-gresham Feb 17, 2020
2c8c545
DWN-31929 : add further XSS attacks to test
hsmith-gresham Feb 17, 2020
7f75f4d
DWN-31921 : bump open id connect to next version
hsmith-gresham Mar 25, 2020
e135d67
Merge pull request #5 from gresham-computing/sanitseUserName
hsmith-gresham Mar 25, 2020
5014043
DWN-33305 : upgrade spring security to 4.2.16.RELEASE
hsmith-gresham May 26, 2020
acd47e0
DWN-32967: compile with JDK 252.
asheppard-gresham Jun 5, 2020
642760f
DWN-32967: update changelog.
asheppard-gresham Jun 5, 2020
8721fdd
DWN-33428 : improve open id connect release process
hsmith-gresham Jun 9, 2020
5cef73d
DWN-33428 : fix junitPublisher disabled logic in Jenkinsfile
hsmith-gresham Jun 9, 2020
727b62e
DWN-33428 : add batch mode to maven commands
hsmith-gresham Jun 9, 2020
7e6ad70
DWN-33428 : review comments to tidy Jenkinsfile
hsmith-gresham Jun 9, 2020
f745449
DWN-33428 : convert indents to tabs in Jenkinsfile
hsmith-gresham Jun 9, 2020
57556d9
Merge pull request #7 from gresham-computing/releaseImprovements
hsmith-gresham Jun 10, 2020
8b03274
No Jira : correct junitPublisher typo
hsmith-gresham Jun 10, 2020
36784e4
Merge remote-tracking branch 'origin/1.3.x' into jdk252
asheppard-gresham Jun 10, 2020
1c3b5d3
Merge pull request #6 from gresham-computing/jdk252
asheppard-gresham Jun 11, 2020
79db814
Merge remote-tracking branch 'origin/1.3.x' into pcimademedoit
hsmith-gresham Jun 12, 2020
fec4e9e
No jira: specify release repo for master non release builds.
asheppard-gresham Jun 16, 2020
3d87a18
No jira: bump to 1.3.3.GRESHAM-20.
asheppard-gresham Jun 16, 2020
5ca997f
No jira: temporarily remove version discovery.
asheppard-gresham Jun 16, 2020
513ff5f
Revert "No jira: temporarily remove version discovery."
asheppard-gresham Jun 16, 2020
86fb637
New Development Version 1.3.3.GRESHAM-21-SNAPSHOT.
asheppard-gresham Jun 16, 2020
90f9e16
Merge remote-tracking branch 'origin/1.3.x' into pcimademedoit
hsmith-gresham Jun 17, 2020
2588b12
Creating Release 1.3.3.GRESHAM-21
Jul 16, 2020
e2e9f72
New Development Version 1.3.3.GRESHAM-22-SNAPSHOT
Jul 16, 2020
6726632
DWN-33387 : reinstate spring security bom
hsmith-gresham Aug 26, 2020
bb3edf4
DWN-33387 : bump spring to 4.3.26
hsmith-gresham Aug 28, 2020
8f4930b
DWN-33950 : hoise commons-codec
hsmith-gresham Aug 28, 2020
7e0a871
Merge pull request #8 from gresham-computing/DWN-33950_securityUpdates
hsmith-gresham Sep 22, 2020
c1886ea
DWN-34576 : upgrade commons-io
hsmith-gresham Sep 25, 2020
276e934
Creating Release 1.3.3.GRESHAM-22
Sep 30, 2020
aefdd91
New Development Version 1.3.3.GRESHAM-23-SNAPSHOT
Sep 30, 2020
9150018
DWN-34909: use java8 265.
asheppard-gresham Oct 2, 2020
228022d
Merge remote-tracking branch 'origin/1.3.x' into DWN-34575_commonsIOU…
hsmith-gresham Oct 5, 2020
8bfebea
DWN-34921_implement_guava_upgrade
sivaschuck Oct 6, 2020
379737e
Merge pull request #10 from gresham-computing/DWN-34921_implement_gua…
sivaschuck Oct 9, 2020
ce3e3f5
Merge pull request #9 from gresham-computing/java8265
asheppard-gresham Oct 14, 2020
7b27430
Merge remote-tracking branch 'origin/1.3.x' into DWN-34575_commonsIOU…
hsmith-gresham Oct 15, 2020
5e4ee45
Merge pull request #11 from gresham-computing/DWN-34575_commonsIOUpgrade
hsmith-gresham Oct 20, 2020
ebff342
DWN-35241 : upgrade jUnit to 4.13.1
hsmith-gresham Oct 21, 2020
62dad15
DWN-35242 : bump httpClient to 4.5.13
hsmith-gresham Oct 21, 2020
b4a12b2
DWN-34963: update spring-bom to 4.3.29.
asheppard-gresham Oct 23, 2020
08f32be
DWN-34963: update spring-security-bom to 4.2.19.
asheppard-gresham Oct 26, 2020
5b009db
DWN-35283 : bump jackson components to 2.11.3
hsmith-gresham Oct 26, 2020
1b2fa2b
Creating Release 1.3.3.GRESHAM-23
Nov 2, 2020
239bd75
New Development Version 1.3.3.GRESHAM-24-SNAPSHOT
Nov 2, 2020
269711a
Merge remote-tracking branch 'origin/1.3.x' into DWN-35240_octoberSec…
hsmith-gresham Nov 6, 2020
f3df958
Merge pull request #12 from gresham-computing/DWN-35240_octoberSecurity
hsmith-gresham Nov 10, 2020
5c9e81f
Creating Release 1.3.3.GRESHAM-24
Dec 2, 2020
29ddcd5
Revert "Creating Release 1.3.3.GRESHAM-24"
hsmith-gresham Dec 2, 2020
eeaacb2
Creating Release 1.3.3.GRESHAM-24
Dec 2, 2020
c6345bc
No jira: temporarily remove version discovery.
asheppard-gresham Jun 16, 2020
4276fc6
Revert "No jira: temporarily remove version discovery."
asheppard-gresham Dec 3, 2020
af5c763
New Development Version 1.3.3.GRESHAM-25-SNAPSHOT
asheppard-gresham Dec 3, 2020
646601d
DWN-35825: remove jacoco.
asheppard-gresham Dec 3, 2020
a4afa9f
Merge pull request #13 from gresham-computing/DWN-35825_removeJacoco
asheppard-gresham Dec 8, 2020
6f066d1
DWN-36607 Upgrade Corretto version in Jenkinsfiles
ahinorapl Feb 12, 2021
7f5432e
Merge pull request #14 from gresham-computing/DWN-36507_Corretto275
hsmith-gresham Feb 18, 2021
182f02e
Creating Release 1.3.3.GRESHAM-25
Feb 26, 2021
9d99c51
New Development Version 1.3.3.GRESHAM-26-SNAPSHOT
Feb 26, 2021
dd9eb26
DWN-37025 : mitigate vulnerability in client logo and unauthorised en…
hsmith-gresham Mar 25, 2021
f443981
DWN-37110: CCI migration openid-connect-server (#15)
sivaschuck Apr 1, 2021
674a822
DWN-37110: attempting to fix upload
sivaschuck Apr 1, 2021
7bc12d5
DWN-37183 : apply mitigation from PR #1548 on Open Id base repo
hsmith-gresham Apr 9, 2021
689f38e
Merge remote-tracking branch 'origin/DWN-37025_openIdServer' into 1.3.x
asheppard-gresham Apr 12, 2021
ea7d75c
Merge pull request #16 from gresham-computing/DWN-37183_openIdAgain
hsmith-gresham Apr 16, 2021
dfbe777
New openid-connect-server release: 1.3.3.GRESHAM-26
May 4, 2021
2053b0f
Next openid-connect-server snapshot: 1.3.3.GRESHAM-27-SNAPSHOT
May 4, 2021
922d8da
Updated security groups
sivaschuck May 20, 2021
fc6c3e9
DWN-38621 : bump JSoup to 1.14.2
hsmith-gresham Aug 26, 2021
fe938f6
Updated circle to new Corretto and removed jenkinsfile
fmayo-gresham Sep 2, 2021
536c845
Merge pull request #18 from gresham-computing/DWN-38621_jsoup
hsmith-gresham Sep 10, 2021
d367d43
Updated json-smart to 2.4.7
fmayo-gresham Sep 29, 2021
cec7fbd
New openid-connect-server release: 1.3.3.GRESHAM-27
Oct 6, 2021
6891d10
Next openid-connect-server snapshot: 1.3.3.GRESHAM-28-SNAPSHOT
Oct 6, 2021
c53570b
Merge pull request #17 from gresham-computing/DWN-38686_UpdateCorrett…
fmayo-gresham Oct 7, 2021
d1b249d
DWN-37825: Upgrade bouncycastle to 1.68
matt-gresham Oct 18, 2021
df3433b
Merge pull request #19 from gresham-computing/DWN-37827-upgrade-json-…
fmayo-gresham Oct 19, 2021
da2aa30
Merge branch '1.3.x' into DWN-37825-upgrade-bouncycastle
matt-gresham Nov 2, 2021
b5ff33f
Merge pull request #20 from gresham-computing/DWN-37825-upgrade-bounc…
matt-gresham Nov 19, 2021
aabbe2d
DWN-39058 : upgrade gson to 2.8.9
hsmith-gresham Dec 10, 2021
623557e
Merge pull request #21 from gresham-computing/DWN-39058_gson
hsmith-gresham Dec 23, 2021
2aad651
DWN-39567 : upgrade jackson components to 2.13.1
hsmith-gresham Jan 17, 2022
20ad418
Merge pull request #22 from gresham-computing/DWN-39567_jackson
hsmith-gresham Feb 1, 2022
61865e5
DWN-39716 : bump postgres driver to latest version
hsmith-gresham Feb 14, 2022
6798b90
Merge pull request #23 from gresham-computing/DWN-39716_postgres
hsmith-gresham Feb 21, 2022
6fd0548
feature/DWN-39743 - Upgrade Corretto version to 8.322.06.2
jasontse-greshamtech Feb 25, 2022
9961a80
Merge pull request #25 from gresham-computing/DWN-39743_corretto_circ…
jasontse-greshamtech Mar 3, 2022
877d955
DWN-40025: corretto 8 332.
asheppard-gresham Apr 28, 2022
025225e
Bump bouncy castle
fmayo-gresham Apr 29, 2022
d494901
Merge pull request #26 from gresham-computing/corretto8.332
asheppard-gresham May 5, 2022
6b31059
DWN-39872: updated jackson-databind version to fix vulnerability
jjuaniveson-gresham May 9, 2022
22a2cb8
DWN-39872 : upgrade jackson components to 2.13.3
hsmith-gresham May 17, 2022
a4b482c
Merge remote-tracking branch 'origin/DWN-39974_bouncy-castle' into 1.3.x
asheppard-gresham May 19, 2022
a963114
Merge pull request #27 from gresham-computing/DWN-39872_Jackson_Databind
hsmith-gresham May 20, 2022
d4f84ed
No JIRA: prepare for 2208 release
hsmith-gresham Sep 2, 2022
517cdcb
Merge pull request #28 from gresham-computing/2208
hsmith-gresham Sep 6, 2022
f2491ce
New openid-connect-server release: 1.3.3.GRESHAM-28
Sep 6, 2022
19eb4bf
Next openid-connect-server snapshot: 1.3.3.GRESHAM-29-SNAPSHOT
Sep 6, 2022
6d102fb
DWN-41034 : upgrade JSoup to 1.15.3
hsmith-gresham Sep 13, 2022
f647a49
DWN-41040 corretto 8u342 (#29)
lrundellgresham Sep 15, 2022
7aa191b
Merge remote-tracking branch 'origin/1.3.x' into DWN-41034_jsoup
hsmith-gresham Sep 26, 2022
8ad0c43
Merge pull request #30 from gresham-computing/DWN-41034_jsoup
hsmith-gresham Sep 27, 2022
b6f361b
DWN-39926 : validate whitelist scopes are alphabet characters
hsmith-gresham Jan 3, 2023
0bea906
DWN-39926 : amend exception name in log messages
hsmith-gresham Jan 4, 2023
32240a5
DWN-39926 : use put rather than addAttribute for updating whitelists
hsmith-gresham Jan 4, 2023
9325917
DWN-39926 : validate create and update scope directly
hsmith-gresham Jan 18, 2023
42b6aa5
DWN-39926 : use patterns to avoid multiple compilation
hsmith-gresham Jan 23, 2023
9119ddd
DWN-39926 : validate scopes on manage client page
hsmith-gresham Jan 26, 2023
46b0312
DWN-39926 : pass whole exception not just the message
hsmith-gresham Jan 26, 2023
d9d1df3
Merge pull request #31 from gresham-computing/DWN-39926_inputValidation
hsmith-gresham Feb 1, 2023
c51ffb4
DWN-42625 : introduce Gresham Orb and update build executor image
hsmith-gresham Apr 28, 2023
40e6740
Revert "DWN-42625 : introduce Gresham Orb and update build executor i…
hsmith-gresham Apr 28, 2023
15c310d
DWN-42625 : introduce Gresham Orb and update build executor image
hsmith-gresham Apr 28, 2023
0eb7a45
Merge pull request #32 from gresham-computing/orbUpgrade
hsmith-gresham May 2, 2023
88856da
DWN-42070: bumped jackson-databind version
jjuaniveson-gresham Sep 13, 2023
8fd42f7
DWN-42070: changelog updated
jjuaniveson-gresham Sep 14, 2023
10647b3
DWN-42070: core version
jjuaniveson-gresham Sep 14, 2023
79638b8
DWN-42070: update core version
jjuaniveson-gresham Sep 15, 2023
4b82762
DWN-42070: update core version
jjuaniveson-gresham Sep 15, 2023
898a352
Update corretto version (#33)
wgoddard-gresham Sep 15, 2023
d65db96
DWN-42070: update core version
jjuaniveson-gresham Sep 18, 2023
e83bf64
Merge branch '1.3.x' into DWN-42070-Jackson-databind
jjuaniveson-gresham Sep 19, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .circleci/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# How to make changes?
##### Install the CircleCI CLI:
https://circleci.com/docs/2.0/local-cli/#installation

##### Making a change
Change the areas of the .circleci/config.yml file that need to be edited

##### To verify your changes
Any config can be verified, to ensure your changes are valid against the yaml and orb schemas,
from the root of the project, run: `circleci config validate .circleci/config.yml --org-slug gh/gresham-computing --token $CIRCLE_TOKEN`

##### Possible errors:
- Your file must be encoded in UTF-8 (powershell defaulted to UTF-16)
- Must use Unix style line endings (LF, not CRLF)
40 changes: 40 additions & 0 deletions .circleci/cci_create_release_and_snapshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
#!/bin/bash

REPOSITORY=https://github.com/gresham-computing/openid-connect-server
MASTER_BRANCH=1.3.x

function get_version {
local currentVersion=$(mvn -Dexec.executable='echo' -Dexec.args='${project.version}' --non-recursive exec:exec -q)
IFS='-' read -r -a parts <<< "$currentVersion"

local NEXT_NUMBER="$((${parts[1]} + 1))"
RELEASE_VERSION="${parts[0]}"-"${parts[1]}"
NEXT_SNAPSHOT_VERSION="${parts[0]}"-$NEXT_NUMBER-SNAPSHOT
}

function bump_to_release {
mvn -s gresham-nexus-settings/ctc.plugins.settings.xml versions:set -DnewVersion=$RELEASE_VERSION
git tag v$RELEASE_VERSION
echo -e "\nopenid-connect-server release: $RELEASE_VERSION\n"
}

function bump_to_next_snapshot {
mvn -s gresham-nexus-settings/ctc.plugins.settings.xml versions:set -DnewVersion=$NEXT_SNAPSHOT_VERSION
echo -e "\nopenid-connect-server snapshot: $NEXT_SNAPSHOT_VERSION\n"
}

function commit_changes {
git commit -a -m "$1"
}

function push_changes {
git push $REPOSITORY $MASTER_BRANCH --tags
}

get_version
bump_to_release
commit_changes "New openid-connect-server release: ${RELEASE_VERSION}"
push_changes
bump_to_next_snapshot
commit_changes "Next openid-connect-server snapshot: $NEXT_SNAPSHOT_VERSION"
push_changes
51 changes: 51 additions & 0 deletions .circleci/cci_generate_artifact_links.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
#!/bin/bash
HOME=~/project
DOWNLOAD_PAGE=$HOME/download.html
LOG=$HOME/mavenOutput.log
SEARCH_TERMS=(openid-connect uma)

function generate_artifact_links {
EXTENSION=$1
echo "<!DOCTYPE html><html><body><h2>Last Deployed Artifacts</h2>" >> $DOWNLOAD_PAGE

for searchTerm in ${SEARCH_TERMS[@]}; do
jarUrls+=($(grep -Eo '(http|https).*'${searchTerm}'.*[^-sources].'${EXTENSION}' | sort --unique' $LOG))
done

if [[ ! -z $jarUrls ]]; then
echo "<ul>" >> $DOWNLOAD_PAGE

for jarUrl in "${jarUrls[@]}"; do
jarName=$(basename $jarUrl)
echo "<li><a href="$jarUrl">$jarName</a></li>" >> $DOWNLOAD_PAGE
done
echo "</ul>" >> $DOWNLOAD_PAGE
else
echo "No uploaded artifacts found." >> $DOWNLOAD_PAGE
fi

echo "<h2>Last Deployed Sources</h2>" >> $DOWNLOAD_PAGE

# get all sources upload URLs into an array.
for searchTerm in ${SEARCH_TERMS[@]}; do
sourceUrls+=($(grep -Eo '(http|https).*'${searchTerm}'.*[-sources].'${EXTENSION}' | sort --unique' $LOG))
done

#if download links are found
if [[ ! -z $sourceUrls ]]; then
echo "<ul>" >> $DOWNLOAD_PAGE

# write each array entry as a list item URL
for sourceUrl in "${sourceUrls[@]}"
do
sourceName=$(basename $sourceUrl)
echo "<li><a href="$sourceUrl">$sourceName</a></li>" >> $DOWNLOAD_PAGE
done
echo "</ul>" >> $DOWNLOAD_PAGE
else
echo "No uploaded artifacts found." >> $DOWNLOAD_PAGE
fi
echo "</body></html>" >> $DOWNLOAD_PAGE
}

generate_artifact_links $@
175 changes: 175 additions & 0 deletions .circleci/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,175 @@
version: 2.1

parameters:
release:
type: boolean
default: false

orbs:
gresham: gresham-computing/[email protected]

executors:
docker-executor:
docker:
- image: 399104266609.dkr.ecr.eu-west-1.amazonaws.com/circleci-build-images:corretto-8u382
aws_auth:
aws_access_key_id: $GIS_PRD_ECR_INT_BUILD_ACCESS_KEY
aws_secret_access_key: $GIS_PRD_ECR_INT_BUILD_SECRET_ACCESS_KEY

jobs:
build-and-deploy:
executor: docker-executor
steps:
- checkout
- get-maven-settings-file
- restore-cache
- gresham/get-whitelister
- gresham/whitelist-add:
pattern: OpenId
- run:
name: "Setting Maven version"
command: |
MASTER_BRANCH=1.3.x
VERSION=$(mvn -s gresham-nexus-settings/ctc.plugins.settings.xml -Dexec.executable='echo' -Dexec.args='${project.version}' --non-recursive exec:exec -q)
if [[ "${CIRCLE_BRANCH}" != "${MASTER_BRANCH}" && "${VERSION}" == *-SNAPSHOT ]]; then
mvn -s gresham-nexus-settings/ctc.plugins.settings.xml versions:set -DnewVersion=${CIRCLE_BRANCH}.GRESHAM-SNAPSHOT -B
fi
- run:
name: "Running Maven build and deploy"
command: |
mvn -s gresham-nexus-settings/ctc.plugins.settings.xml clean deploy \
-B -V -U -DskipTests -DskipITs \
-DaltSnapshotDeploymentRepository=snapshots::default::https://nexus.greshamtech.com/repository/thirdparty-maven-snapshots/ \
-DaltReleaseDeploymentRepository=releases::default::https://nexus.greshamtech.com/repository/thirdparty-maven-releases/ \
|& tee -a /home/circleci/project/mavenOutput.log
- generate-download-urls:
extension: jar
- save-cache
- gresham/whitelist-remove:
pattern: OpenId
- persist-workspace

test:
executor: docker-executor
steps:
- attach_workspace:
at: .
- restore-cache
- gresham/get-whitelister
- gresham/whitelist-add:
pattern: OpenId
- run:
name: "Running tests"
command: mvn -fae -s gresham-nexus-settings/ctc.plugins.settings.xml test -B -V -U
- save-test-results
- save-cache
- persist-workspace
- gresham/whitelist-remove:
pattern: OpenId

release:
executor: docker-executor
steps:
- checkout
- get-maven-settings-file
- gresham/get-whitelister
- gresham/whitelist-add:
pattern: OpenId
- restore-cache
- run:
name: Creating openid-connect-server release and next snapshot
command: chmod +x .circleci/cci_create_release_and_snapshot.sh && .circleci/cci_create_release_and_snapshot.sh
- save-cache
- gresham/whitelist-remove:
pattern: OpenId

workflows:
build-and-test:
unless: << pipeline.parameters.release >>
jobs:
- build-and-deploy:
context:
- gresham-aws
- CTC
- CircleCi-Gresham-Credentials
- test:
requires:
- build-and-deploy
context:
- gresham-aws
- CTC
- CircleCi-Gresham-Credentials

build-release:
when: << pipeline.parameters.release >>
jobs:
- release:
context:
- gresham-aws
- CTC
- CircleCi-Gresham-Credentials
filters:
branches:
only: 1.3.x

commands:
setup-git-credentials:
steps:
- run:
name: Setting up Git credentials
command: |
git config --global user.name "CircleCI"
git config --global user.email "$GITHUB_GRESHAM_USER"

get-maven-settings-file:
steps:
- setup-git-credentials
- run:
name: Getting Maven settings file
command: |
git config --global url."https://api:${GITHUB_GRESHAM_PW}@github.com/".insteadOf "https://github.com/"
git clone https://github.com/gresham-computing/gresham-nexus-settings

save-cache:
steps:
- save_cache:
paths:
- ~/.m2
key: v1-m2-{{ .Branch }}-{{ .Environment.CIRCLE_JOB }}-{{ checksum "pom.xml" }}

restore-cache:
steps:
- restore_cache:
keys:
- v1-m2-{{ .Branch }}-{{ .Environment.CIRCLE_JOB }}-{{ checksum "pom.xml" }}
- v1-m2-{{ .Branch }}-{{ .Environment.CIRCLE_JOB }}
- v1-m2-

persist-workspace:
steps:
- persist_to_workspace:
root: .
paths:
- .

generate-download-urls:
parameters:
extension:
type: string
steps:
- run:
name: "Generating artifact download URLs"
command: chmod +x .circleci/cci_generate_artifact_links.sh && .circleci/cci_generate_artifact_links.sh << parameters.extension >>
- store_artifacts:
path: download.html

save-test-results:
steps:
- run:
name: Save test results
command: |
mkdir -p ~/test-results/junit/
find . -type f -regex ".*/target/surefire-reports/.*xml" -exec cp {} ~/test-results/junit/ \;
when: always
- store_test_results:
path: ~/test-results
29 changes: 29 additions & 0 deletions .circleci/run_release_workflow.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
#!/bin/bash

if [[ -z "${CIRCLE_TOKEN}" ]]; then
echo Cannot trigger release workflow. CircleCI user token not found.
exit 1
fi

BRANCH=1.3.x

echo -e "\nTriggering release workflow on branch: ${BRANCH}.\n"

status_code=$(curl --request POST \
--url https://circleci.com/api/v2/project/github/gresham-computing/openid-connect-server/pipeline \
--header 'Circle-Token: '${CIRCLE_TOKEN}'' \
--header 'content-type: application/json' \
--data '{"branch":"'${BRANCH}'","parameters":{"release": true}}' \
-o response.json \
-w "%{http_code}")

if [ "${status_code}" -ge "200" ] && [ "${status_code}" -lt "300" ]; then
echo -e "\nAPI call succeeded [${status_code}]. Response:\n"
cat response.json
rm response.json
else
echo -e "\nAPI call failed [${status_code}]. Response:\n"
cat response.json
rm response.json
exit 1
fi
16 changes: 16 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,21 @@
Unreleased:

- Updated JDK to Corretto 1.8.342
- Upgraded Jackson Databind Component to 2.13.4.2


*1.3.3-GRESHAM-28:
- Updated JDK to Corretto 1.8.332
- Uprgaded Jackson Components to 2.13.3

*1.3.3-GRESHAM:
- Upgraded libraries with known vulnerabilities
- Added a Gresham specific Jenkinsfile
- Added a password encoder to the client entity service
- Fixes a bug by specifying the name of the scope columnn
- Removed functionality that passed the client secret down to the UI
- Updated JDK to Corretto 1.8.252

*1.3.2:
- Added changelog
- Set default redirect URI resolver strict matching to true
Expand Down
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,3 +29,9 @@ The authors and key contributors of the project include:


Copyright &copy;2017, [MIT Internet Trust Consortium](http://www.trust.mit.edu/). Licensed under the Apache 2.0 license, for details see `LICENSE.txt`.

## Release Process

Here at Gresham, we use this component for a base for the auth server, our developing branch is 1.3.x and any feature branches should be made off of that branch.

A release build can be invoked by running .circleci/run_release_workflow.sh shell script. It uses CircleCI API to trigger the release workflow and it requires a CIRCLE_TOKEN environment variable with a personal CircleCI API token to be set. Once triggered, the build will bump appropriate versions to release and then proceed to bump them to next snapshot.
8 changes: 4 additions & 4 deletions openid-connect-client/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
<parent>
<artifactId>openid-connect-parent</artifactId>
<groupId>org.mitre</groupId>
<version>1.3.3-SNAPSHOT</version>
<version>1.3.3.GRESHAM-29-SNAPSHOT</version>
<relativePath>..</relativePath>
</parent>
<artifactId>openid-connect-client</artifactId>
Expand All @@ -45,7 +45,7 @@
<target>${java-version}</target>
</configuration>
</plugin>
<!-- BUILD SOURCE FILES -->
<!--&lt;!&ndash; BUILD SOURCE FILES &ndash;&gt;
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-source-plugin</artifactId>
Expand All @@ -58,7 +58,7 @@
</execution>
</executions>
</plugin>
<!-- BUILD JavaDoc FILES -->
&lt;!&ndash; BUILD JavaDoc FILES &ndash;&gt;
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-javadoc-plugin</artifactId>
Expand All @@ -70,7 +70,7 @@
</goals>
</execution>
</executions>
</plugin>
</plugin>-->
</plugins>
</build>
</project>
Loading