Scott Rossillo
4d32ac8765
Add Servlet 2.x support to the Spring Security adapter
...
Cookie.setHttpOnly() was added in Servlet 3.0. Make setting a
cookie as HttpOnly dependent on servlet version.
2015-05-11 19:48:16 -04:00
Thomas Raehalme
78999537f0
Added support for GrantedAuthoritiesMapper in KeycloakAuthenticationProvider.
2015-05-09 13:42:09 +03:00
Bill Burke
e3b0cc7093
Merge pull request #1236 from Smartling/KEYCLOAK-1291
...
Improve Spring Security adapter default configuration
2015-05-08 20:53:36 -04:00
Bill Burke
50014f4398
Merge pull request #1235 from Smartling/KEYCLOAK-1290
...
Use backchannel logout for Spring Security SSO
2015-05-08 20:53:26 -04:00
Bill Burke
833c276424
Merge pull request #1234 from mstruk/wfly-subs-split-master
...
Wildfly 9 - subsystem split + feature packs
2015-05-08 20:53:17 -04:00
Scott Rossillo
d37a9eada3
Improve Spring Security adapter default configuration
2015-05-08 18:24:49 -04:00
Scott Rossillo
a7bfae2f56
Use backchannel logout for Spring Security SSO
...
Use backchannel logout for Keycloak's Spring Security adapter
single sign-out to allow Spring Security's logout complete handler
to fire.
2015-05-08 18:20:17 -04:00
Stian Thorgersen
58fc4520c9
Merge pull request #1232 from Smartling/KEYCLOAK-1287
...
Enable Spring Security adapter to register nodes
2015-05-08 07:09:42 +02:00
Stian Thorgersen
53716697ca
Merge pull request #1222 from Smartling/KEYCLOAK-1273
...
Improve Spring Security adapter client to client authorization
2015-05-08 07:01:14 +02:00
Scott Rossillo
8ca9a6a64a
Enable Spring Security adapter to register nodes
...
Enable dynamic application node registration and unregistration
from Spring Security protected applications.
2015-05-07 20:09:16 -04:00
Scott Rossillo
2ce3925ba9
Permit Spring Security adapter to process admin tasks with CSRF enabled
...
Spring Security's CSRF protection blocks Keycloak administrative
actions when configured with the default request matcher.
This provides a CSRF request matcher that permits Keycloak
administrative actions without the CSRF token.
2015-05-07 19:58:27 -04:00
Scott Rossillo
b05da425b9
Improve Spring Security adapter client to client authorization
2015-05-06 16:54:55 -04:00
Marko Strukelj
4e58bed39e
Move keycloak modules under integration/keycloak
2015-05-05 20:48:13 +02:00
Marko Strukelj
7d2942e1be
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- Rename keycloak-server-subsystem dir to wildfly-server-subsystem
- Rename keycloak-agent-subsystem dir to keycloak-wildfly-agent-subsystem
- Rename artifacts accordingly (keycloak- prefix)
Only maven artifacts are renamed, jboss-modules modules are still called keycloak-server-subsystem, and keycloak-agent-subsystem
2015-05-05 20:43:23 +02:00
Marko Strukelj
943404689e
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- Use WildFly 9.0.0.CR1
2015-05-05 20:40:05 +02:00
Marko Strukelj
89875aea02
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- Fix deprecated uses, and more code cleanup
2015-05-05 20:40:05 +02:00
Marko Strukelj
70ce96caa0
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- Fix overlooked file renames causing subsystem tests to fail
2015-05-05 20:40:05 +02:00
Stan Silvert
3a7bba041f
Create builds based on WildFly 9 feature packs.
2015-05-05 20:40:04 +02:00
Marko Strukelj
87cb28eaab
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- Fix server-subsystem tests
2015-05-05 20:40:04 +02:00
Marko Strukelj
03fa58a271
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- POM dependencies cleanup
2015-05-05 20:40:03 +02:00
Marko Strukelj
3c76a85674
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- More code and pom cleanup
2015-05-05 20:40:03 +02:00
Marko Strukelj
c571ad9902
KEYCLOAK-1183 Split subsystem into separate server and adapter subsystems
...
- Renamed keycloak-subsystem into keycloak-server-subsystem
- Added keycloak-adapter-subsystem without auth-server support
- Removed adapter config from keycloak-server subsystem
- Added proper .xsd for server subsystem
2015-05-05 20:40:03 +02:00
Tomaz Cerar
355c440c3d
Update subsystem code to reflect latest standards
2015-05-05 20:38:52 +02:00
Tomaz Cerar
9a17658f84
remove eap6 dup
2015-05-05 20:38:52 +02:00
Stian Thorgersen
035529d7a2
Version bump
2015-05-05 11:45:21 +02:00
Bill Burke
761be66362
Merge pull request #1199 from patriot1burke/master
...
apache http client fixes
2015-04-29 21:59:50 -04:00
Bill Burke
666827b7cb
remove resteasy ClientRequest
2015-04-29 20:46:14 -04:00
Bill Burke
10998eb35b
Merge pull request #1193 from behana/master
...
Let admin-client acquire new token if refresh_token is stale
2015-04-29 16:33:20 -04:00
behana
8dfc7d9e8d
Let admin-client acquire new token if refresh_token is stale
2015-04-29 05:01:59 +02:00
Scott Rossillo
06a7938aa6
Add Spring Security adapter
2015-04-28 15:05:56 -04:00
Stian Thorgersen
215a3497ae
KEYCLOAK-1189 Add apache httpclient module with slot 4.3
2015-04-27 16:33:48 +02:00
Stian Thorgersen
870f29d797
Merge pull request #1172 from stianst/master
...
Dist work
2015-04-23 12:40:38 +02:00
Stian Thorgersen
e17105cc8e
Updated distribution and cleaning of maven modules
2015-04-23 11:15:05 +02:00
Stian Thorgersen
cf75a97f08
Merge pull request #1169 from gkfirst8/KEYCLOAK-1220
...
log the right value when keycloak.config.file could not be found or read
2015-04-22 14:08:29 +02:00
gkfirst8
0b782e9910
Fix logging call
2015-04-22 10:54:43 +02:00
Leonardo Loch Zanivan
642fc996fb
Basic Auth token fix
2015-04-21 16:22:14 -03:00
Leonardo Loch Zanivan
6ce0285315
Basic Auth token fix
2015-04-21 12:32:17 -03:00
gkfirst8
aef61411e9
log the right value when keycloak.config.file could not be found or read
...
Fix for [KEYCLOAK-1220]
2015-04-21 11:46:33 +02:00
Stian Thorgersen
5ed864fbbc
KEYCLOAK-1208 Allow same-origin if cors is enabled
2015-04-21 10:42:13 +02:00
Dane Barentine
4fe328002a
[KEYCLOAK-1206] Change role mapping path in admin client to match API changes
2015-04-14 22:21:28 -07:00
Dane Barentine
b1b149e0c3
[KEYCLOAK-1205] Fix BearerAuthFilter refreshing token after it's expired
2015-04-14 22:19:07 -07:00
Stian Thorgersen
46e386cd43
KEYCLOAK-1187
2015-04-13 13:54:30 +02:00
Stian Thorgersen
4fbbf39c51
KEYCLOAK-1187 Admin console and endpoints
2015-04-13 13:29:31 +02:00
Stian Thorgersen
a18715a774
Deprecate OAuthClientRepresentation and ApplicationRepresentation and added ClientRepresentation
2015-04-10 13:33:29 +02:00
Stian Thorgersen
1567982f0b
Merge pull request #1128 from ssilvert/KEYCLOAK-1174-NPE-on-WF9
...
KEYCLOAK-1174: NPE on WildFly 9
2015-04-10 07:05:46 +02:00
Stan Silvert
875aae91fc
Add owner attribute to Keycloak server deployment
2015-04-09 14:52:47 -04:00
Stan Silvert
bbef4e2be1
KEYCLOAK-1174: Refactor KeycloakAdapterConfigService to be a simple
...
singleton
2015-04-09 10:30:39 -04:00
Stian Thorgersen
6fbc0975c0
KEYCLOAK-1187 First round: Combined ApplicationModel and OAuthClientModel into ClientModel. Removed OAuth Clients from Admin console and renamed Applications to Clients.
2015-04-09 12:27:30 +02:00
mposolda
d0ead0f0a0
More logging
2015-04-07 08:46:39 +02:00
Bill Burke
326818ea45
bump pom versio
2015-04-02 09:36:43 -04:00
mposolda
6a34ad36f5
Fix clustering when auth-server-url-for-backend-requests is used
2015-04-02 13:02:24 +02:00
Stian Thorgersen
48c7bd1b5e
KEYCLOAK-1171 Missing parameters: response_type login to oauth-client and oauth-client-cdi
2015-04-01 13:50:50 +02:00
mposolda
3256337614
CookieTokenStore not working correctly on EAP 6.3
2015-03-31 14:53:37 +02:00
Bill Burke
9d7db174e1
merged
2015-03-26 13:06:50 -04:00
Bill Burke
c20ab4a9a6
fix query parsing
2015-03-26 13:05:09 -04:00
Stian Thorgersen
b727087f04
KEYCLOAK-1150
...
'iss' should be URL not just realm name
2015-03-26 13:50:36 +01:00
mposolda
477d8b35e3
KEYCLOAK-1116 KEYCLOAK-1117 JSON migration and removal of ClientModel.claimsMask
2015-03-26 11:49:22 +01:00
Bill Burke
97d5f4aafc
broker refactor
2015-03-20 18:56:25 -04:00
Stian Thorgersen
8ed1c475e4
KEYCLOAK-498 Package theme as a JAR
2015-03-20 14:13:25 +01:00
Stian Thorgersen
1714ce91d1
KEYCLOAK-1076 XML tag <enable-basic-auth> needed in secure-deployments for AS-7 subsystem
2015-03-20 07:37:16 +01:00
Stian Thorgersen
93f9706297
KEYCLOAK-1110 Fix role not removed from default roles when not deleted
2015-03-20 06:17:35 +01:00
Stian Thorgersen
1d4e8118f0
Updated admin-client to use new token endpoint
2015-03-20 06:04:36 +01:00
Bill Burke
b26277a17c
broker fixes
2015-03-18 21:58:04 -04:00
Bill Burke
ce2c4188fb
saml broker import/export, and module fixes
2015-03-17 19:20:46 -04:00
mposolda
4da566ae4d
KEYCLOAK-1094 Rename k_idp_hint to kc_idp_hint
2015-03-16 20:00:20 +01:00
Stian Thorgersen
e2b02d414f
Change adapters to use auth and token endpoints
2015-03-16 09:23:12 +01:00
mposolda
9b74393add
KEYCLOAK-1102 Used just one ResteasyClient in admin client
2015-03-13 19:56:05 +01:00
Stian Thorgersen
1f5fedb0b0
Module provider loader
2015-03-06 05:30:17 +01:00
Stian Thorgersen
4cb3d51781
KEYCLOAK-1082
...
Make sure session is valid if keycloak.js is initialized with tokens
2015-03-05 07:42:31 +01:00
Bill Burke
98831ec05a
fix other claims in IDToken
2015-03-04 20:27:06 -05:00
mposolda
03d607b022
Fix showing federation links of users in admin console
2015-02-11 13:03:31 +01:00
girirajsharma
c3d7ef8066
Updated BC provider versions and deprecated CertificateUtil methods.
2015-02-10 18:44:54 +05:30
pedroigor
ff1f10d7a7
[KEYCLOAK-883] - Refactoring to services endpoints and exposing them through admin client.
2015-02-09 21:30:21 -02:00
pedroigor
4ce2e76a2d
[KEYCKOAK-883] - Adding idpHint config option when configuring login url.
2015-02-08 20:52:44 -02:00
mposolda
1d8ebd441d
KEYCLOAK-1023 Improve osgi packaging for hawtio. Fix typos in fuse example docs.
2015-02-02 23:25:56 +01:00
Pedro Igor
e452165c4a
Merge pull request #941 from pedroigor/KEYCLOAK-996
...
[KEYCLOAK-996] - Allow application to select provider.
2015-01-30 14:28:50 -02:00
pedroigor
99a457c5c1
[KEYCLOAK-996] - Allow application to select provider.
2015-01-30 14:02:53 -02:00
Stian Thorgersen
4dfb4a91ea
KEYCLOAK-1018 Update JS adapter to use protocol/openid-connect urls
2015-01-30 14:29:58 +01:00
Stian Thorgersen
e2998a09b6
KEYCLOAK-1019 Fix to keycloak.js if auth-server-url ends with '/'
2015-01-30 10:02:27 +01:00
Stian Thorgersen
eb695f12f7
KEYCLOAK-1000 Module provider loader
2015-01-28 11:26:46 +01:00
mposolda
ee4fbca868
Improve OOTB experience for ssh and jmx authentication in fuse
2015-01-23 20:57:40 +01:00
mposolda
efb6ec8099
Added docs and example for SSH and JMX authentication on fuse
2015-01-21 13:43:38 +01:00
mposolda
715482e371
Have fuse example working on newest fuse 6.2. Refactoring of ServletReregistrationService to work on fuse 6.1, 6.2 and karaf 3.0.2
2015-01-20 21:45:08 +01:00
Stian Thorgersen
c8d879a82d
KEYCLOAK-977 Use reflection to find constructor for JBossGenericPrincipal to support EAP 6.4
2015-01-20 13:24:58 +01:00
Bill Burke
42bdb7731d
Merge pull request #916 from jimmidyson/spring-boot-integration
...
Spring boot adapter
2015-01-16 19:01:04 -05:00
Bill Burke
ef2698936b
Merge pull request #919 from pedroigor/KEYCLOAK-884
...
[KEYCLOAK-884] - OpenID Connect UserInfo Endpoint.
2015-01-16 14:28:30 -05:00
pedroigor
4f432775ed
[KEYCLOAK-884] - OpenID Connect UserInfo Endpoint.
2015-01-16 15:45:27 -02:00
mposolda
2e04ac549e
Make it easier to run demo on different host then auth-server
2015-01-16 18:02:23 +01:00
Jimmi Dyson
81849ae631
Configure resource constraints via Spring Boot properties
2015-01-16 12:43:47 +00:00
Jimmi Dyson
a5246b8075
Working external configuration through Spring Boot application.properties
2015-01-16 12:42:59 +00:00
Jimmi Dyson
273e945850
First stab - now just to make it configurable
2015-01-16 12:42:54 +00:00
Stian Thorgersen
bf6c46da1c
KEYCLOAK-962 Changed access token request to use redirect_uri from initial request instead of the resolved redirect_uri
2015-01-16 11:01:03 +01:00
mposolda
522e24017c
Rebase with master
2015-01-15 20:29:34 +01:00
mposolda
7faee110d5
KEYCLOAK-853 Documentation for login modules
2015-01-15 19:03:11 +01:00
mposolda
d928c26e27
KEYCLOAK-539 Fuse adapter. OSGI bundling. OSGI headers in keycloak adapter maven artifacts. Rename package in jetty-core
2015-01-15 19:02:45 +01:00
Stian Thorgersen
c3c6d4cbba
Add redirect_uri to access token request in keycloak.js
2015-01-14 15:18:22 +01:00
pedroigor
fa2533ed11
[KEYCLOAK-883] - Initial changes.
2015-01-13 00:58:19 -02:00
Stian Thorgersen
959933a227
Version bump
2015-01-12 10:35:50 +01:00
Michael Gerber
9c484b9938
add test
2015-01-09 14:03:36 +01:00
Michael Gerber
7ce1502bc5
pass login_hint parameter to the keycloak login page
2015-01-09 11:58:44 +01:00
mposolda
e62858cefd
KEYCLOAK-900 Fix resolving of current hostname
2015-01-08 11:09:11 +01:00
Stian Thorgersen
526e25abc7
Fixes for commons-io dep issues in KeycloakServer
2015-01-08 09:53:43 +01:00
Stian Thorgersen
b7dae5c88f
Fixes for regression introduced by KEYCLOAK-923
2015-01-07 14:54:18 +01:00
Stian Thorgersen
2b1ae89608
KEYCLOAK-933 expose-token setting not working - empty string returned instead of token
2015-01-07 12:58:42 +01:00
Bill Burke
2a7fc53300
Merge pull request #908 from patriot1burke/master
...
fix cached principal adapter
2015-01-06 15:57:56 -05:00
Bill Burke
0f4953dcd2
fix cached principal adapter
2015-01-06 13:47:02 -05:00
mposolda
c7b0c4fb05
KEYCLOAK-929 Don't remove principal on session passivation
2015-01-06 19:44:07 +01:00
Stian Thorgersen
74ba508e4a
KEYCLOAK-918 Reverse proxy triggers NPE in undertow adapter
2015-01-06 10:14:57 +01:00
Stian Thorgersen
992455e273
KEYCLOAK-923 Login redirect should support query param in keycloak.js
2015-01-06 09:56:03 +01:00
Stian Thorgersen
f97b71c207
KEYCLOAK-903
...
No client session for direct grant
2014-12-30 13:28:08 +01:00
Bill Burke
ec9ce6ef2f
error page adapter support
2014-12-23 16:33:08 -05:00
Bill Burke
8a1b7e39af
RESTEASY-901
2014-12-22 15:59:25 -05:00
Michael Gerber
512a68c5fa
Not required authentication bugfix
2014-12-20 14:12:35 +01:00
gerbermichi
1eaafcd3d9
bugfix for excluded post rest services
2014-12-19 16:55:46 +01:00
Bill Burke
28a56289d9
Merge pull request #897 from patriot1burke/master
...
saved requests
2014-12-17 22:29:46 -05:00
Bill Burke
08be04b337
saved requests
2014-12-17 22:29:18 -05:00
Stan Silvert
0082892f7c
KEYCLOAK-880 Fix use of ${..} props in subsystem XML
2014-12-17 15:40:02 -05:00
Stian Thorgersen
ee62f5b1a1
Merge pull request #891 from nilspreusker/ie9-compatibility
...
IE9 Compatibility
2014-12-17 10:56:14 +01:00
Bill Burke
17a8a92bb3
common eap code
2014-12-16 12:26:56 -05:00
Nils Preusker
ce1fd8eedc
using JSON.stringify(...) and JSON.parse(...)
...
see
http://lists.jboss.org/pipermail/keycloak-user/2014-December/thread.html
#1355
2014-12-16 16:14:13 +01:00
Bill Burke
6c04e26376
bump
2014-12-05 21:09:38 -05:00
Bill Burke
c0059a875b
bump version
2014-12-05 19:03:13 -05:00
Stan Silvert
952436f129
Restore old AS7 subystem.
2014-12-04 14:53:50 -05:00
Bill Burke
82c3e4c1bc
adapter testsuite port and adapter fixes
2014-12-02 14:38:33 -05:00
objectiser
8e01f8ecf1
KEYCLOAK-861 Support basic authentication against user credentials managed by KeyCloak.
2014-12-01 11:43:19 +00:00
mposolda
c5d000cefc
Allow login modules to be more flexible
2014-11-28 20:06:18 +01:00
Stian Thorgersen
6b3e7c76bd
Merge pull request #870 from ssilvert/eap-subsys
...
KEYCLOAK-856 Merge WildFly and EAP subsystems
2014-11-27 10:02:01 +01:00
Bill Burke
e14c5adf55
Merge remote-tracking branch 'upstream/master'
2014-11-24 19:16:34 -05:00
Bill Burke
d0856e024f
proxy distro
2014-11-24 18:12:17 -05:00
Stan Silvert
d53b01eb2b
KEYCLOAK-856 Rename wildfly-subsystem to keycloak-subsystem
2014-11-24 16:52:16 -05:00
mposolda
2a78d0d4d0
KEYCLOAK-859 Added DirectAccessGrantsLoginModule
2014-11-24 18:56:51 +01:00
Stan Silvert
34e18c176d
KEYCLOAK-856 Remove EAP subsystem
2014-11-23 09:35:19 -05:00
Bill Burke
4bad1fea86
Merge remote-tracking branch 'upstream/master'
2014-11-21 18:45:02 -05:00
Bill Burke
bc6e7c249b
proxy config 2
2014-11-21 18:44:39 -05:00
mposolda
f1378a6092
KEYCLOAK-858 avoid creating inner DeploymentDelegate for each request
2014-11-21 23:49:29 +01:00
mposolda
829f9f4386
KEYCLOAK-857 add getter/setter for principalAttribute to AdapterDeploymentContext
2014-11-21 22:51:22 +01:00
Stan Silvert
f537661341
KEYCLOAK-856 Merge WildFly and EAP subsystems
2014-11-21 13:33:14 -05:00
Bill Burke
21279fc9ed
proxy
2014-11-20 21:48:59 -05:00
Stian Thorgersen
ed1073ca92
KEYCLOAK-791 Denial of Service by invalid character injection
2014-11-18 14:58:20 +01:00
Bill Burke
7244e2f173
Merge pull request #859 from patriot1burke/master
...
tomcat6
2014-11-15 12:00:18 -05:00
Bill Burke
5be045c42b
tomcat6
2014-11-15 11:59:33 -05:00
mposolda
b08930961f
Fixes to login module
2014-11-14 21:06:07 +01:00
mposolda
68bff44b2e
KEYCLOAK-853 Added jaas login module BearerTokenLoginModule
2014-11-14 13:40:12 +01:00
Bill Burke
e2045907d4
tomcat8
2014-11-12 18:56:18 -05:00
Stan Silvert
67c0182a49
KEYCLOAK-839 Auth Server overlay enhancements
2014-11-12 13:39:39 -05:00
Stan Silvert
c85a31be7f
KEYCLOAK-839 Auth Server overlay enhancements
2014-11-12 13:39:38 -05:00
Bill Burke
3b6f10913c
merge
2014-11-10 17:09:00 -05:00
Bill Burke
3fbffc9d7d
jetty 8
2014-11-10 16:59:31 -05:00
mposolda
07fd8ae9d7
KEYCLOAK-836 Added OsgiJaxrsBearerTokenFilterImpl to be used in fuse
2014-11-10 22:16:20 +01:00
mposolda
a94ab5883d
KEYCLOAK-835 Move AdapterConstants to different package
2014-11-10 22:16:20 +01:00