Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using policy enforcer without security constraint #4

Open
MoatazAbdallh opened this issue Jul 8, 2020 · 0 comments
Open

Using policy enforcer without security constraint #4

MoatazAbdallh opened this issue Jul 8, 2020 · 0 comments

Comments

@MoatazAbdallh
Copy link

Hi,
I am facing an issue after I have updated keycloak to v10 as previously I was able to user policy-enforcer in application.properties without configuring security constraints, as now if I didn't add security constraint config the AbstractPolicyEnforcer will retrieve null securityContext
KeycloakSecurityContext securityContext = httpFacade.getSecurityContext();
& hence it will delegate the authZ to userManagmentAccess which by the way is null so at the end I got 403 if I didn't add

keycloak.securityConstraints[0].authRoles[0]=*
#keycloak.securityConstraints[0].securityCollections[0].patterns[0]=/*

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant