Compare commits
1 commit
main
...
renovate/k
| Author | SHA1 | Date | |
|---|---|---|---|
| 1ea041dc7c |
7 changed files with 13 additions and 81 deletions
|
|
@ -1,19 +1,17 @@
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
push:
|
push:
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ansible-lint:
|
ansible-lint:
|
||||||
name: Verify
|
name: Verify
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v7
|
- uses: actions/checkout@v6
|
||||||
- name: Install maven
|
- name: Install maven
|
||||||
run: |
|
run: |
|
||||||
apt update
|
apt update
|
||||||
apt install -y maven
|
apt install -y maven
|
||||||
- name: Run maven verify
|
- name: Run maven verify
|
||||||
run: |
|
run: |
|
||||||
mvn -f attribute-endpoints-provider --batch-mode --no-transfer-progress verify
|
mvn -f attribute-endpoints-provider verify
|
||||||
|
|
|
||||||
|
|
@ -17,7 +17,7 @@
|
||||||
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
|
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
|
||||||
<maven.compiler.source>17</maven.compiler.source>
|
<maven.compiler.source>17</maven.compiler.source>
|
||||||
<maven.compiler.target>17</maven.compiler.target>
|
<maven.compiler.target>17</maven.compiler.target>
|
||||||
<keycloak.version>26.6.0</keycloak.version>
|
<keycloak.version>26.7.0</keycloak.version>
|
||||||
</properties>
|
</properties>
|
||||||
|
|
||||||
<dependencies>
|
<dependencies>
|
||||||
|
|
@ -86,7 +86,7 @@
|
||||||
</plugin>
|
</plugin>
|
||||||
<plugin>
|
<plugin>
|
||||||
<artifactId>maven-surefire-plugin</artifactId>
|
<artifactId>maven-surefire-plugin</artifactId>
|
||||||
<version>3.5.6</version>
|
<version>3.5.5</version>
|
||||||
</plugin>
|
</plugin>
|
||||||
<plugin>
|
<plugin>
|
||||||
<artifactId>maven-jar-plugin</artifactId>
|
<artifactId>maven-jar-plugin</artifactId>
|
||||||
|
|
@ -104,7 +104,7 @@
|
||||||
https://maven.apache.org/ref/current/maven-core/lifecycles.html#site_Lifecycle -->
|
https://maven.apache.org/ref/current/maven-core/lifecycles.html#site_Lifecycle -->
|
||||||
<plugin>
|
<plugin>
|
||||||
<artifactId>maven-site-plugin</artifactId>
|
<artifactId>maven-site-plugin</artifactId>
|
||||||
<version>3.22.0</version>
|
<version>3.21.0</version>
|
||||||
</plugin>
|
</plugin>
|
||||||
<plugin>
|
<plugin>
|
||||||
<artifactId>maven-project-info-reports-plugin</artifactId>
|
<artifactId>maven-project-info-reports-plugin</artifactId>
|
||||||
|
|
|
||||||
|
|
@ -109,7 +109,6 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider
|
||||||
|
|
||||||
UserModel authUser = auth.getUser();
|
UserModel authUser = auth.getUser();
|
||||||
if (!authUser.hasRole(authRole)) {
|
if (!authUser.hasRole(authRole)) {
|
||||||
LOG.info("User " + authUser.getUsername() + " does not have required role " + authRole.getName());
|
|
||||||
throw new ForbiddenException("User does not have required auth role.");
|
throw new ForbiddenException("User does not have required auth role.");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -23,26 +23,12 @@ The copying of the database is necessary to avoid locking errors.
|
||||||
docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env -i -- /opt/keycloak/bin/kc.sh export --db dev-file --db-url 'jdbc:h2:file:/tmp/h2/keycloakdb;NON_KEYWORDS=VALUE' --file /opt/keycloak/data/import/testing.json --realm testing"
|
docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env -i -- /opt/keycloak/bin/kc.sh export --db dev-file --db-url 'jdbc:h2:file:/tmp/h2/keycloakdb;NON_KEYWORDS=VALUE' --file /opt/keycloak/data/import/testing.json --realm testing"
|
||||||
```
|
```
|
||||||
|
|
||||||
## Running Integration Tests
|
## Testing Realm Configuration
|
||||||
|
|
||||||
This directory also contains shell scripts that exercise the attribute endpoint.
|
|
||||||
|
|
||||||
Bring up Keycloak with `docker compose up -d`, then run one of the `client-test-export-`*`.sh` scripts.
|
|
||||||
|
|
||||||
```shell
|
|
||||||
$ ./client-test-export-dooris.sh
|
|
||||||
[
|
|
||||||
"hacker-ssh-key-1",
|
|
||||||
"hacker-ssh-key-2"
|
|
||||||
]
|
|
||||||
```
|
|
||||||
|
|
||||||
## Realm `testing` Configuration
|
|
||||||
|
|
||||||
The realm contains these objects:
|
The realm contains these objects:
|
||||||
|
|
||||||
* Clients:
|
* Clients:
|
||||||
* `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and user `service-account-export-dooris-ssh-keys`
|
* `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and role `export-dooris-ssh-keys`
|
||||||
* `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses`
|
* `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses`
|
||||||
* Realm Roles:
|
* Realm Roles:
|
||||||
* `dooris-authorized`
|
* `dooris-authorized`
|
||||||
|
|
@ -68,34 +54,3 @@ The realm contains these objects:
|
||||||
* Dooris SSH Keys:
|
* Dooris SSH Keys:
|
||||||
* SSH Key 1: `hacker-ssh-key-1`
|
* SSH Key 1: `hacker-ssh-key-1`
|
||||||
* SSH Key 2: `hacker-ssh-key-2`
|
* SSH Key 2: `hacker-ssh-key-2`
|
||||||
* `service-account-export-dooris-ssh-keys`
|
|
||||||
* Role `export-dooris-ssh-keys`
|
|
||||||
* `service-account-export-mailing-list-addresses`
|
|
||||||
* Role `export-mailing-list-addresses`
|
|
||||||
* Realm Settings:
|
|
||||||
* User Profile:
|
|
||||||
* Attribute Groups:
|
|
||||||
* `dooris-ssh-keys`
|
|
||||||
* `mailing-list-addresses`
|
|
||||||
* Attributes:
|
|
||||||
* `mailing-list-address-chaos`
|
|
||||||
* Attribute Group `mailing-list-addresses`
|
|
||||||
* `mailing-list-address-intern`
|
|
||||||
* Attribute Group `mailing-list-intern`
|
|
||||||
* `ssh-key-1`
|
|
||||||
* Attribute Group `dooris-ssh-keys`
|
|
||||||
* `ssh-key-2`
|
|
||||||
* Attribute Group `dooris-ssh-keys`
|
|
||||||
* Custom Attributes:
|
|
||||||
* Slug `dooris-ssh-keys`
|
|
||||||
* Attribute Group `dooris-ssh-keys`
|
|
||||||
* Match Role `dooris-authorized`
|
|
||||||
* Auth Role `export-dooris-ssh-keys`
|
|
||||||
* Slug `mailing-list-addresses-chaos`
|
|
||||||
* Attribute Group `mailing-list-addresses`
|
|
||||||
* Match Role `mailing-list-chaos-member`
|
|
||||||
* Auth Role `export-mailing-list-addresses`
|
|
||||||
* Slug `mailing-list-addresses-intern`
|
|
||||||
* Attribute Group `mailing-list-addresses`
|
|
||||||
* Match Role `mailing-list-intern-member`
|
|
||||||
* Auth Role `export-mailing-list-addresses`
|
|
||||||
|
|
|
||||||
|
|
@ -1,20 +0,0 @@
|
||||||
#!/bin/sh
|
|
||||||
|
|
||||||
#
|
|
||||||
# Use curl to run a test export of Dooris ssh keys
|
|
||||||
#
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
ACCESS_TOKEN="$(curl -s --request POST \
|
|
||||||
--url http://localhost:8080/realms/testing/protocol/openid-connect/token \
|
|
||||||
--header 'content-type: application/x-www-form-urlencoded' \
|
|
||||||
--data scope=openid \
|
|
||||||
--data client_id=export-dooris-ssh-keys \
|
|
||||||
--data client_secret=export-dooris-ssh-keys-secret \
|
|
||||||
--data grant_type=client_credentials | jq --raw-output .access_token -)"
|
|
||||||
|
|
||||||
curl -s --request GET \
|
|
||||||
--url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys \
|
|
||||||
--header "authorization: Bearer ${ACCESS_TOKEN}" \
|
|
||||||
--header "content-type: application/json" | jq . -
|
|
||||||
|
|
@ -1,6 +1,6 @@
|
||||||
services:
|
services:
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.0
|
image: quay.io/keycloak/keycloak:26.7.0
|
||||||
pull_policy: always
|
pull_policy: always
|
||||||
command: "start-dev --features=declarative-ui --import-realm"
|
command: "start-dev --features=declarative-ui --import-realm"
|
||||||
environment:
|
environment:
|
||||||
|
|
|
||||||
|
|
@ -470,7 +470,7 @@
|
||||||
"credentials" : [ ],
|
"credentials" : [ ],
|
||||||
"disableableCredentialTypes" : [ ],
|
"disableableCredentialTypes" : [ ],
|
||||||
"requiredActions" : [ ],
|
"requiredActions" : [ ],
|
||||||
"realmRoles" : [ "export-dooris-ssh-keys", "default-roles-testing" ],
|
"realmRoles" : [ "default-roles-testing" ],
|
||||||
"notBefore" : 0,
|
"notBefore" : 0,
|
||||||
"groups" : [ ]
|
"groups" : [ ]
|
||||||
}, {
|
}, {
|
||||||
|
|
@ -484,7 +484,7 @@
|
||||||
"credentials" : [ ],
|
"credentials" : [ ],
|
||||||
"disableableCredentialTypes" : [ ],
|
"disableableCredentialTypes" : [ ],
|
||||||
"requiredActions" : [ ],
|
"requiredActions" : [ ],
|
||||||
"realmRoles" : [ "export-mailing-list-addresses", "default-roles-testing" ],
|
"realmRoles" : [ "default-roles-testing" ],
|
||||||
"notBefore" : 0,
|
"notBefore" : 0,
|
||||||
"groups" : [ ]
|
"groups" : [ ]
|
||||||
}, {
|
}, {
|
||||||
|
|
@ -1478,7 +1478,7 @@
|
||||||
"subType" : "authenticated",
|
"subType" : "authenticated",
|
||||||
"subComponents" : { },
|
"subComponents" : { },
|
||||||
"config" : {
|
"config" : {
|
||||||
"allowed-protocol-mapper-types" : [ "oidc-sha256-pairwise-sub-mapper", "saml-user-attribute-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper" ]
|
"allowed-protocol-mapper-types" : [ "saml-user-property-mapper", "saml-user-attribute-mapper", "oidc-usermodel-attribute-mapper", "oidc-address-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-property-mapper" ]
|
||||||
}
|
}
|
||||||
}, {
|
}, {
|
||||||
"id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b",
|
"id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b",
|
||||||
|
|
@ -1538,7 +1538,7 @@
|
||||||
"subType" : "anonymous",
|
"subType" : "anonymous",
|
||||||
"subComponents" : { },
|
"subComponents" : { },
|
||||||
"config" : {
|
"config" : {
|
||||||
"allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-attribute-mapper", "oidc-full-name-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "saml-user-attribute-mapper" ]
|
"allowed-protocol-mapper-types" : [ "oidc-sha256-pairwise-sub-mapper", "oidc-full-name-mapper", "oidc-address-mapper", "saml-role-list-mapper", "oidc-usermodel-attribute-mapper", "saml-user-property-mapper", "oidc-usermodel-property-mapper", "saml-user-attribute-mapper" ]
|
||||||
}
|
}
|
||||||
}, {
|
}, {
|
||||||
"id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5",
|
"id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5",
|
||||||
|
|
@ -1625,8 +1625,8 @@
|
||||||
"subComponents" : { },
|
"subComponents" : { },
|
||||||
"config" : {
|
"config" : {
|
||||||
"match-role" : [ "mailing-list-chaos-member" ],
|
"match-role" : [ "mailing-list-chaos-member" ],
|
||||||
"auth-role" : [ "export-mailing-list-addresses" ],
|
|
||||||
"attribute-group" : [ "mailing-list-addresses" ],
|
"attribute-group" : [ "mailing-list-addresses" ],
|
||||||
|
"auth-role" : [ "export-mailing-list-addresses" ],
|
||||||
"slug" : [ "mailing-list-addresses-chaos" ]
|
"slug" : [ "mailing-list-addresses-chaos" ]
|
||||||
}
|
}
|
||||||
} ]
|
} ]
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue