bcgov / ocp-sso

BCGov Single Sign-On KeyCloak
http://oidc.gov.bc.ca/
Apache License 2.0
8 stars 8 forks source link

Create a new client for the SRWT app in KeyCloak #413

Closed ConradBoydElliottGustafson closed 3 years ago

ConradBoydElliottGustafson commented 3 years ago

@jlangy was trying to set up a backend validation to enforce that you have to log in with KeyCloak. We were looking for the IDP mapper so that we could use the "identity_provider" claim in the token to make sure the login was through IDIR. The mapper does not exist on the tmp-sso-requests client in the onestopauth realm.

AC

  1. tmp-sso-requests -- remove it if no longer being used
  2. create a real client for the sso-requests app that is public key PKCE using terraform

image.png