Compare commits

..

1 commit

Author SHA1 Message Date
1ea041dc7c Update Keycloak packages to v26.7.0
All checks were successful
/ Verify (pull_request) Successful in 57s
/ Verify (push) Successful in 57s
2026-07-18 12:16:57 +00:00
7 changed files with 13 additions and 81 deletions

View file

@ -1,19 +1,17 @@
on: on:
pull_request: pull_request:
push: push:
branches:
- main
jobs: jobs:
ansible-lint: ansible-lint:
name: Verify name: Verify
runs-on: docker runs-on: docker
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v6
- name: Install maven - name: Install maven
run: | run: |
apt update apt update
apt install -y maven apt install -y maven
- name: Run maven verify - name: Run maven verify
run: | run: |
mvn -f attribute-endpoints-provider --batch-mode --no-transfer-progress verify mvn -f attribute-endpoints-provider verify

View file

@ -17,7 +17,7 @@
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<maven.compiler.source>17</maven.compiler.source> <maven.compiler.source>17</maven.compiler.source>
<maven.compiler.target>17</maven.compiler.target> <maven.compiler.target>17</maven.compiler.target>
<keycloak.version>26.6.0</keycloak.version> <keycloak.version>26.7.0</keycloak.version>
</properties> </properties>
<dependencies> <dependencies>
@ -86,7 +86,7 @@
</plugin> </plugin>
<plugin> <plugin>
<artifactId>maven-surefire-plugin</artifactId> <artifactId>maven-surefire-plugin</artifactId>
<version>3.5.6</version> <version>3.5.5</version>
</plugin> </plugin>
<plugin> <plugin>
<artifactId>maven-jar-plugin</artifactId> <artifactId>maven-jar-plugin</artifactId>
@ -104,7 +104,7 @@
https://maven.apache.org/ref/current/maven-core/lifecycles.html#site_Lifecycle --> https://maven.apache.org/ref/current/maven-core/lifecycles.html#site_Lifecycle -->
<plugin> <plugin>
<artifactId>maven-site-plugin</artifactId> <artifactId>maven-site-plugin</artifactId>
<version>3.22.0</version> <version>3.21.0</version>
</plugin> </plugin>
<plugin> <plugin>
<artifactId>maven-project-info-reports-plugin</artifactId> <artifactId>maven-project-info-reports-plugin</artifactId>

View file

@ -109,7 +109,6 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider
UserModel authUser = auth.getUser(); UserModel authUser = auth.getUser();
if (!authUser.hasRole(authRole)) { if (!authUser.hasRole(authRole)) {
LOG.info("User " + authUser.getUsername() + " does not have required role " + authRole.getName());
throw new ForbiddenException("User does not have required auth role."); throw new ForbiddenException("User does not have required auth role.");
} }

View file

@ -23,26 +23,12 @@ The copying of the database is necessary to avoid locking errors.
docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env -i -- /opt/keycloak/bin/kc.sh export --db dev-file --db-url 'jdbc:h2:file:/tmp/h2/keycloakdb;NON_KEYWORDS=VALUE' --file /opt/keycloak/data/import/testing.json --realm testing" docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env -i -- /opt/keycloak/bin/kc.sh export --db dev-file --db-url 'jdbc:h2:file:/tmp/h2/keycloakdb;NON_KEYWORDS=VALUE' --file /opt/keycloak/data/import/testing.json --realm testing"
``` ```
## Running Integration Tests ## Testing Realm Configuration
This directory also contains shell scripts that exercise the attribute endpoint.
Bring up Keycloak with `docker compose up -d`, then run one of the `client-test-export-`*`.sh` scripts.
```shell
$ ./client-test-export-dooris.sh
[
"hacker-ssh-key-1",
"hacker-ssh-key-2"
]
```
## Realm `testing` Configuration
The realm contains these objects: The realm contains these objects:
* Clients: * Clients:
* `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and user `service-account-export-dooris-ssh-keys` * `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and role `export-dooris-ssh-keys`
* `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses` * `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses`
* Realm Roles: * Realm Roles:
* `dooris-authorized` * `dooris-authorized`
@ -68,34 +54,3 @@ The realm contains these objects:
* Dooris SSH Keys: * Dooris SSH Keys:
* SSH Key 1: `hacker-ssh-key-1` * SSH Key 1: `hacker-ssh-key-1`
* SSH Key 2: `hacker-ssh-key-2` * SSH Key 2: `hacker-ssh-key-2`
* `service-account-export-dooris-ssh-keys`
* Role `export-dooris-ssh-keys`
* `service-account-export-mailing-list-addresses`
* Role `export-mailing-list-addresses`
* Realm Settings:
* User Profile:
* Attribute Groups:
* `dooris-ssh-keys`
* `mailing-list-addresses`
* Attributes:
* `mailing-list-address-chaos`
* Attribute Group `mailing-list-addresses`
* `mailing-list-address-intern`
* Attribute Group `mailing-list-intern`
* `ssh-key-1`
* Attribute Group `dooris-ssh-keys`
* `ssh-key-2`
* Attribute Group `dooris-ssh-keys`
* Custom Attributes:
* Slug `dooris-ssh-keys`
* Attribute Group `dooris-ssh-keys`
* Match Role `dooris-authorized`
* Auth Role `export-dooris-ssh-keys`
* Slug `mailing-list-addresses-chaos`
* Attribute Group `mailing-list-addresses`
* Match Role `mailing-list-chaos-member`
* Auth Role `export-mailing-list-addresses`
* Slug `mailing-list-addresses-intern`
* Attribute Group `mailing-list-addresses`
* Match Role `mailing-list-intern-member`
* Auth Role `export-mailing-list-addresses`

View file

@ -1,20 +0,0 @@
#!/bin/sh
#
# Use curl to run a test export of Dooris ssh keys
#
set -e
ACCESS_TOKEN="$(curl -s --request POST \
--url http://localhost:8080/realms/testing/protocol/openid-connect/token \
--header 'content-type: application/x-www-form-urlencoded' \
--data scope=openid \
--data client_id=export-dooris-ssh-keys \
--data client_secret=export-dooris-ssh-keys-secret \
--data grant_type=client_credentials | jq --raw-output .access_token -)"
curl -s --request GET \
--url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys \
--header "authorization: Bearer ${ACCESS_TOKEN}" \
--header "content-type: application/json" | jq . -

View file

@ -1,6 +1,6 @@
services: services:
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.6.0 image: quay.io/keycloak/keycloak:26.7.0
pull_policy: always pull_policy: always
command: "start-dev --features=declarative-ui --import-realm" command: "start-dev --features=declarative-ui --import-realm"
environment: environment:

View file

@ -470,7 +470,7 @@
"credentials" : [ ], "credentials" : [ ],
"disableableCredentialTypes" : [ ], "disableableCredentialTypes" : [ ],
"requiredActions" : [ ], "requiredActions" : [ ],
"realmRoles" : [ "export-dooris-ssh-keys", "default-roles-testing" ], "realmRoles" : [ "default-roles-testing" ],
"notBefore" : 0, "notBefore" : 0,
"groups" : [ ] "groups" : [ ]
}, { }, {
@ -484,7 +484,7 @@
"credentials" : [ ], "credentials" : [ ],
"disableableCredentialTypes" : [ ], "disableableCredentialTypes" : [ ],
"requiredActions" : [ ], "requiredActions" : [ ],
"realmRoles" : [ "export-mailing-list-addresses", "default-roles-testing" ], "realmRoles" : [ "default-roles-testing" ],
"notBefore" : 0, "notBefore" : 0,
"groups" : [ ] "groups" : [ ]
}, { }, {
@ -1478,7 +1478,7 @@
"subType" : "authenticated", "subType" : "authenticated",
"subComponents" : { }, "subComponents" : { },
"config" : { "config" : {
"allowed-protocol-mapper-types" : [ "oidc-sha256-pairwise-sub-mapper", "saml-user-attribute-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper" ] "allowed-protocol-mapper-types" : [ "saml-user-property-mapper", "saml-user-attribute-mapper", "oidc-usermodel-attribute-mapper", "oidc-address-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-property-mapper" ]
} }
}, { }, {
"id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b", "id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b",
@ -1538,7 +1538,7 @@
"subType" : "anonymous", "subType" : "anonymous",
"subComponents" : { }, "subComponents" : { },
"config" : { "config" : {
"allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-attribute-mapper", "oidc-full-name-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "saml-user-attribute-mapper" ] "allowed-protocol-mapper-types" : [ "oidc-sha256-pairwise-sub-mapper", "oidc-full-name-mapper", "oidc-address-mapper", "saml-role-list-mapper", "oidc-usermodel-attribute-mapper", "saml-user-property-mapper", "oidc-usermodel-property-mapper", "saml-user-attribute-mapper" ]
} }
}, { }, {
"id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5", "id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5",
@ -1625,8 +1625,8 @@
"subComponents" : { }, "subComponents" : { },
"config" : { "config" : {
"match-role" : [ "mailing-list-chaos-member" ], "match-role" : [ "mailing-list-chaos-member" ],
"auth-role" : [ "export-mailing-list-addresses" ],
"attribute-group" : [ "mailing-list-addresses" ], "attribute-group" : [ "mailing-list-addresses" ],
"auth-role" : [ "export-mailing-list-addresses" ],
"slug" : [ "mailing-list-addresses-chaos" ] "slug" : [ "mailing-list-addresses-chaos" ]
} }
} ] } ]