<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000"><div><span class="Object" role="link"><span class="Object" role="link">Hi,</span></span></div><div><span class="Object" role="link"><span class="Object" role="link"><br data-mce-bogus="1"></span></span></div><div><b><span class="Object" role="link" id="OBJ_PREFIX_DWT929_com_zimbra_date"><span class="Object" role="link" id="OBJ_PREFIX_DWT938_com_zimbra_date">2020-11-18</span></span> 00:23:07,119 - 212.47.237.47 - ERROR [org.geant.idpextension.oidc.profile.impl.ValidateGrant:177] - Profile Action ValidateGrant: Obtaining authz code failed Unwrapped data has expired</b><b><br></b></div><div><b><br data-mce-bogus="1"></b></div><div>Assuming Idp is otherwise healthy this implies that as your client performs the token request the authorization code has already expired. The default lifetime in the extension for it is 5 minutes. This should happen only if you are playing around with it, debugging and stuff. If that is not the case and you are returning freshly minted authorization code.. then it is something else ;-)<br></div><div><br data-mce-bogus="1"></div><div>BR Janne<br data-mce-bogus="1"></div><div><br></div><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>From: </b>"Julien COCHENNEC" <julien.cochennec@ac-orleans-tours.fr><br><b>To: </b>"Shib Users" <users@shibboleth.net><br><b>Sent: </b>Wednesday, 18 November, 2020 22:30:17<br><b>Subject: </b>Re : Python OIDC client and Shibboleth Idp with OIDC plugin<br></div><div><br></div><div data-marker="__QUOTED_TEXT__"><div>Oh BTW I forgot to mention I found the same message almost here https://shibboleth.1660669.n2.nabble.com/unwrapped-data-has-expired-td7621954.html</div><div>I was not sure it could be related.<br></div><br><span>Le 18/11/20, <b class="name">Julien COCHENNEC </b> <julien.cochennec@ac-orleans-tours.fr> a écrit :</span><blockquote cite="mid:4616445f3988457d.5fb590a8@ac-orleans-tours.fr" class="iwcQuote" style="border-left: 1px solid #00F; padding-left: 13px; margin-left: 0;"><div class="mimepart text html"><div>Hi,</div><div>We're testing a Python client that is developed with Flask (web microframework) and Flask-OIDC (OIDC add-on with oauth-client lib embedded).</div><div>We're trying to make it work, the client ask for a authorization code, the response looks "wrong", the add-on displays "Not Authorized".</div><div>Not expecting a complete solution, any lead would be appreciated, thanks.</div><div>I'm aware that it is a OIDC plugin question more than a Shibboleth question, but I'm totally clueless here.</div><div>Have a nice day.<br></div><br><div>A - On the idp side, we have this :</div><br><div>
<b>2020-11-18 00:23:07,119 - 212.47.237.47 - ERROR
[org.geant.idpextension.oidc.profile.impl.ValidateGrant:177] -
Profile Action ValidateGrant: Obtaining authz code failed
Unwrapped data has expired</b><b><br>
</b><b>2020-11-18 00:23:07,122 - 212.47.237.47 - WARN
[org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed
event occurred while processing the request: InvalidGrant</b><br>
</div><br><div>B - And in the client logs we have errors like this (sorry for the time not corresponding, logs are a mess) :</div><br><div><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"> 1) Invalid
Grant error :</span></span></div><div><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"></span></span><br><span><p> <span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto">File
"/opt/conda/envs/b3desk/lib/python3.7/site-packages/oauth2client/<a class="linkified" href="http://client.py" rel="noreferrer nofollow noopener" target="_blank">client.py</a>", line 2089, in
step2_exchange raise FlowExchangeError(error_msg)
oauth2client.client.FlowExchangeError:
invalid_grantInvalid grant</span></span></span></span></p><p><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"><br></span></span></span></span></p>
<p><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"> 2) Strange error on Cookie, already happened with Flask https://github.com/olipo186/Git-Auto-Deploy/issues/221 could be an attack but I'd like to know if it rings a bell to any of you :<br></span></span></p><p><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"></span></span><br> <span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto">Invalid request
from ip=185.202.2.147: Invalid HTTP request line:
'\x03\x00\x00/*à\x00\x00\x00\x00\x00Cookie:
mstshash=Administr'</span></span></span></span></p><p><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"><br></span></span></span></span></p>
<p><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"> 3) 401 Error (replaced server name with ***) :<br>
</span></span></p>
<p><span class="mx_MTextBody mx_EventTile_content"><span class="mx_EventTile_body" dir="auto"> HTTP/1.1" 401 14 "<a class="linkified" href="https://extranet.ac-versailles.fr/sso/SSO?SAMLRequest=fVJba8IwFP4rJe%2B9r1qDLYgyEHYRK3vYW0yPGGiSLid17t8v6eYQJj4Fcr6T75Y5Mtn1dDHYo9rCxwBog7PsFFI%2FqMhgFNUMBVLFJCC1nDaL5yeaRQlliGCs0IpcrfT3d3qjrea6I8Hisr3UCgcJpgFzEhzWqoVzRRISrJwYoZjHVORobY80juFsDVNgI8bDExhkousAo4OJEXXcNK8kWK8qAiUv2rJ4mE1n5T7b7zln2YSlLJ8W07YoWodCHBwZWqZsRbIkS8I0DdPpLstpNqF5%2BU6CN0cwsjvppJ57f3TcM7U3eUB6HPZHleQ0jZJ5fD2f%2FwT74hJYrza6E%2FwreNRGMns%2FIH8j2vAwQqn3igKUdezx%2FxcvLL%2FNQTv26AK1LqZgqWXPjEBvQAol5CAvJq5xy84VuYVDfbdrTrnHueuNOz61aTeuSuCOdOdF9trY3wRuPn6Rf1Pq3%2FT6H9bf&RelayState=f5b0efa9645a6a81e5ed2c5e1d3e9f29" rel="noreferrer
nofollow noopener" target="_blank">https://******/sso/SSO?SAMLRequest=fVJba8IwFP4rJe%2B9r1qDLYgyEHYRK3vYW0yPGGiSLid17t8v6eYQJj4Fcr6T75Y5Mtn1dDHYo9rCxwBog7PsFFI%2FqMhgFNUMBVLFJCC1nDaL5yeaRQlliGCs0IpcrfT3d3qjrea6I8Hisr3UCgcJpgFzEhzWqoVzRRISrJwYoZjHVORobY80juFsDVNgI8bDExhkousAo4OJEXXcNK8kWK8qAiUv2rJ4mE1n5T7b7zln2YSlLJ8W07YoWodCHBwZWqZsRbIkS8I0DdPpLstpNqF5%2BU6CN0cwsjvppJ57f3TcM7U3eUB6HPZHleQ0jZJ5fD2f%2FwT74hJYrza6E%2FwreNRGMns%2FIH8j2vAwQqn3igKUdezx%2FxcvLL%2FNQTv26AK1LqZgqWXPjEBvQAol5CAvJq5xy84VuYVDfbdrTrnHueuNOz61aTeuSuCOdOdF9trY3wRuPn6Rf1Pq3%2FT6H9bf&RelayState=f5b0efa9645a6a81e5ed2c5e1d3e9f29</a>"
"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"</span></span></p></span></div><br><br><br>
</div></blockquote>
<br>-- <br>For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></div></body></html>