{"repo":"sventorben/keycloak-restrict-client-auth","free":true,"listed":false,"github":"https://github.com/sventorben/keycloak-restrict-client-auth","clone":"git clone https://github.com/sventorben/keycloak-restrict-client-auth.git","description":"A Keycloak authenticator to restrict authorization on clients","language":"Java","stars":432,"topics":["keycloak","roles","roles-management","authentication","authorization","access-control","access-management","keycloak-authenticator","client","restriction"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Keycloak: Restrict user authorization on clients This is a simple Keycloak authenticator to restrict user authorization on clients. Quick introduction (Video interview with Niko Köbler) What is it good for? As a Keycloak consultant, I often receive inquiries about restricting user authorization for specific clients. People commonly ask, Can I allow certain users to authenticate with a client while denying access to others? While the answer used to be \"no\" for out-of-the-box Keycloak, I have developed this extension to meet this need. but I recommend taking the time to understand the potential security implications before using this extension. So, before using this extension, please take a moment to review the security considerations outlined in the security consideration section. How does it work? The authenticator can work either role-based or policy-based. Role-based mode In this mode, the authenticator uses client roles to restrict authentication. It works like this: The authenticator checks whether a client defines a role named restricted-access If it does the authenticator checks whether the user has that role If it does, the authenticator returns success (i.e. authentication is successful) If it does not, the authenticator returns failure (i.e. authentication is unsuccessful) If it does not, the authenticator returns success (i.e. authentication is successful). This means that you can enable the authenticator on a per-client basis by adding a client role named restricte","default_branch":null,"files":null,"tree":[],"storefront":"/r/sventorben","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sventorben/keycloak-restrict-client-auth/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}