Configuration flags that enable and disable various S3 features are properties of the TutorialAppPlus class. You can find this class in the file app/src/main/java/com/noknok/android/tutorialappplus/TutorialAppPlus.java. By default, Tutorial App is set up to use the FIDO UAF protocol with most features turned off.
Using your server
The Tutorial App default server settings are located in
AppSDK/android-studio/app_tutorial_plus/app/src/main/res/raw/config.json.
A convenient way to override these values is to open the Tutorial App and click on Scan QR Code from the menu in the upper left corner. Then follow the instructions at Configuring iOS or Android Tutorial App to point your Tutorial App to your Digipass S3 Server.
Supporting AppAuth
Google AppAuth is a method for providing integration with OpenID Connect. The Nok Nok Labs S3 Solution supports AppAuth. Performing FIDO Authentication using AppAuth requires that you provide a set of parameters. All server-specific parameters, which should be modified for each particular OpenID Connect server, are defined as properties of the TutorialAppPlus class to be easily maintainable and grouped in one place. You can find this class in the file app/src/main/java/com/noknok/android/tutorialappplus/TutorialAppPlus.java. Listed below are names and descriptions for AppAuth parameters.
appauth_auth_endpoint: an endpoint to which the AppAuth authorization request should be sent. (for a particular OIDC server integration, this value needs to be in the following form https://hostname/as/authorization.oauth2)
appauth_token_endpoint: an endpoint to which token exchange request should be sent. For a particular OIDC server integration this value needs to be in the following form https://hostname/as/token.oauth2.
appauth_redirect_uri: The redirect URI to use for receiving the authorization response. This can either be a custom scheme URI or an HTTPS app link. Custom scheme URIs are better supported across all versions of Android. For OIDC server integration, this value needs to be in the following form: app.tutorialappplus://hostname/redirectpath. To handle redirections by AppAuth, declare the redirect URI custom scheme in defaultConfig of app_tutorial_plus/build.gradle as shown below.
manifestPlaceholders = ['appAuthRedirectScheme': 'app.tutorialappplus']appauth_client_id: The OAuth2 client id used to identify the client to the authorization server.
client_secret: Client secret value used on OAuth2 client registration
appauth_scope: The scope string to use for the authorization request. Any value understood by your authorization server can be used. Scope value should contain "openid", in case if multiple scopes should be specified, values should be separated with spaces (for example, "rlwp openid")
The current implementation does not support dynamic client registration, because the registration endpoint is set to null. Therefore, the client_id and client_secret values must be provided.
There is also the RESPONSE_TYPE_CODE = "code" parameter, which is a constant not dependent on the server, so it is set in the code and not added to the string resources.
There could also be additional parameters specific to one server which are not applicable to other server implementations (for example, the operation = "INIT_OOB_GUI" parameter for a Ping server implementation). These kinds of parameters are not declared in string resources, as they are not common and should instead be added in the code as additional parameters using the setAdditionalParameters method.
Using a FIDO client for credential sharing
Tutorial App can be configured to use a FIDO Client for Credential Sharing.
Add the "clientOrder" field in mfac_config.json and set its value to "REMOTE"
e.g. "clientOrder": ["REMOTE"]Rebuild Tutorial App
Using Tutorial app with the FIDO client for credential sharing
Ensure that FIDO Client has been installed on the target device prior to testing. Launch Tutorial App and observe it switching context over to the FIDO Client when performing a FIDO operation (e.g. prompting the user to register or authenticate, etc.).
Note that in this configuration, no authenticators embedded in your app are available for the operation. A standalone ASM should be installed on the device if the FIDO Client does not embed any ASM.
Using Passport app for credential sharing
When you have multiple mobile apps, you can designate one of the apps to perform authentication for the related apps. FIDO credentials are shared between the apps. In this scenario, the user registers once using the designated authentication app and does not have to register into each app. The designated authentication app owns and manages the FIDO credentials for the related apps.
This section outlines how to use the Passport App as the designated authentication app. You can also use your own app instead of the Passport App using the same approach.
Building Tutorial app to use Passport app for credential sharing
Tutorial App can use the Passport App as a FIDO client, as follows:
Open the Tutorial App in Android Studio
Open mfac_config.json and:
Set the "clientOrder" field to "REMOTE"
e.g. "clientOrder": ["REMOTE"]Set the "customClient" field to "com.noknok.android.passport2"
Rebuild the Tutorial App
Using Tutorial app with Passport app for credential sharing
Ensure that Passport App has been installed on the target device prior to testing. Launch Tutorial App and observe it switching context over to Passport App when performing a FIDO operation (e.g. prompting the user to register or authenticate, when scanning a QR code during OOB operations, etc.).
Server Configuration
Besides the client-side changes shown here, successful implementation of the credential sharing feature also requires assigning the AppID on the Digipass S3 Server. See Configure Apps.
Enabling the Photo ID authentication method
The S3 Suite has built-in integration with Jumio™'s Netverify service to implement the Photo ID authentication method. You need to configure Tutorial App to use your Net Verify API token and secret.
Edit TutorialAppPlus.kt. Search for the following code block:
object NetVerifySettings {
val net_verify_api_token: String? = null
val net_verify_api_secret: String? = null
}Assign your Net Verify API token and API secret to netverify_api_token and net_verify_api_secret, respectively.
How the Photo ID method works
Using Tutorial App, the user submits a photo ID and selfie to Jumio's Netverify service. Netverify validates the uploaded images and returns a scan reference ID to your app. Your app sends that ID to the Server which requests the results of the scan from the Netverify service.
Enabling Quick FIDO authentication
You can configure Tutorial App to support Quick FIDO Authentication. Set the Quick mode found in Registering for Quick Authentication to any value except None from the Settings screen. As a result, the Tutorial App passes the following extra arguments to the IAppSDKPlus and to the AdaptiveUI:
Registration: EXTRA_KEY_QUICK_ENABLE:"true" key value is passed to getRegistrationFragment() in the extras parameter.
Authentication: EXTRA_KEY_SIGN_IN_QUICK_MODE: “<Quick mode>” key value is passed to the getAuthenticationFragment() function in the authOpts parameter. For more information, see Implementing Quick Authentication.
Working examples in Tutorial app
SettingsFragment.kt
RegControllerFragment.kt