From 498fc03e8936be9d1ae71e18d3020977e1148346 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 26 Oct 2022 00:43:36 -0400 Subject: [PATCH 1/6] Updated library, added audiences --- .../EShopOnAbpPublicWebModule.cs | 15 +++--- .../EShopOnAbp.Keycloak.DbMigrator.csproj | 3 +- .../KeycloakDataSeeder.cs | 50 ++++++++----------- .../JwtBearerConfigurationHelper.cs | 4 -- 4 files changed, 28 insertions(+), 44 deletions(-) diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs index b250e7b9..f231a383 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs @@ -154,14 +154,13 @@ public class EShopOnAbpPublicWebModule : AbpModule options.Scope.Add("phone"); options.Scope.Add("roles"); options.Scope.Add("offline_access"); - // Audiences couldn't be seeded -> TODO: Update when library is updated - // options.Scope.Add("AccountService"); - // options.Scope.Add("AdministrationService"); - // options.Scope.Add("BasketService"); - // options.Scope.Add("CatalogService"); - // options.Scope.Add("PaymentService"); - // options.Scope.Add("OrderingService"); - // options.Scope.Add("CmskitService"); + + options.Scope.Add("AdministrationService"); + options.Scope.Add("BasketService"); + options.Scope.Add("CatalogService"); + options.Scope.Add("PaymentService"); + options.Scope.Add("OrderingService"); + options.Scope.Add("CmskitService"); options.SaveTokens = true; //Token response type, will sometimes need to be changed to IdToken, depending on config. diff --git a/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj b/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj index f7f9c1ba..47d14f09 100644 --- a/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj +++ b/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj @@ -8,12 +8,11 @@ - + - diff --git a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs index 32aff192..80051883 100644 --- a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs +++ b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs @@ -43,7 +43,6 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency private async Task CreateClientScopesAsync() { - await CreateScopeAsync("AccountService"); await CreateScopeAsync("AdministrationService"); await CreateScopeAsync("IdentityService"); await CreateScopeAsync("BasketService"); @@ -78,16 +77,11 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency Name = scopeName, Protocol = "openid-connect", _ProtocolMapper = "oidc-audience-mapper", - // Config = new Dictionary() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - // { - // { "id.token.claim", "false" }, - // { "access.token.claim", "true" }, - // { "included.custom.audience", scopeName } - // } - Config = new Config() // This should be dictionary -> Outdated library + Config = new Dictionary() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged { - AccessTokenClaim = "true", - IdTokenClaim = "false" + { "id.token.claim", "false" }, + { "access.token.claim", "true" }, + { "included.custom.audience", scopeName } } } } @@ -133,15 +127,14 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, webClient); - //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - // await AddOptionalClientScopesAsync( - // "PublicWeb", - // new List - // { - // "AdministrationService", "IdentityService", "BasketService", "CatalogService", - // "OrderingService", "PaymentService", "CmskitService" - // } - // ); + await AddOptionalClientScopesAsync( + "PublicWeb", + new List + { + "AdministrationService", "IdentityService", "BasketService", "CatalogService", + "OrderingService", "PaymentService", "CmskitService" + } + ); } } @@ -219,15 +212,14 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, publicWebClient); - //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - // await AddOptionalClientScopesAsync( - // "PublicWeb", - // new List - // { - // "AdministrationService", "IdentityService", "BasketService", "CatalogService", - // "OrderingService", "PaymentService", "CmskitService" - // } - // ); + await AddOptionalClientScopesAsync( + "PublicWeb", + new List + { + "AdministrationService", "IdentityService", "BasketService", "CatalogService", + "OrderingService", "PaymentService", "CmskitService" + } + ); } } @@ -264,8 +256,6 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency var adminUser = users.FirstOrDefault(); if (adminUser == null) { - _logger.LogError( - "Keycloak admin user is not provided, check if KEYCLOAK_ADMIN environment variable is passed properly."); throw new Exception( "Keycloak admin user is not provided, check if KEYCLOAK_ADMIN environment variable is passed properly."); } diff --git a/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs b/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs index 0cc48603..f87c63f4 100644 --- a/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs +++ b/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs @@ -20,10 +20,6 @@ public static class JwtBearerConfigurationHelper options.Authority = configuration["AuthServer:Authority"]; options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); options.Audience = audience; - options.TokenValidationParameters = new TokenValidationParameters() - { - ValidateAudience = false //Disabled since seeding audience is not possible with the current keycloak.net library version - }; }); } } \ No newline at end of file From b30c78b86a69dd0a106346934c66d5188805ec5c Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 26 Oct 2022 03:54:47 -0400 Subject: [PATCH 2/6] added tye configration --- tye.yaml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/tye.yaml b/tye.yaml index de0f4014..73ac37d4 100644 --- a/tye.yaml +++ b/tye.yaml @@ -94,14 +94,14 @@ services: - Kestrel__Certificates__Default__Path=../../../../etc/dev-cert/localhost.pfx - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 -- name: public-web - project: apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbp.PublicWeb.csproj - bindings: - - protocol: https - port: 44335 - env: - - Kestrel__Certificates__Default__Path=../../../../etc/dev-cert/localhost.pfx - - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 +# - name: public-web +# project: apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbp.PublicWeb.csproj +# bindings: +# - protocol: https +# port: 44335 +# env: +# - Kestrel__Certificates__Default__Path=../../../../etc/dev-cert/localhost.pfx +# - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - name: keycloak-seeder project: shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj \ No newline at end of file From 5931c61b30d3821ec523ea2490a30ead6ebdab57 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 26 Oct 2022 03:56:17 -0400 Subject: [PATCH 3/6] updated cors configurations --- .../appsettings.json | 2 +- services/basket/src/EShopOnAbp.BasketService/appsettings.json | 2 +- .../src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json | 2 +- .../src/EShopOnAbp.CmskitService.HttpApi.Host/appsettings.json | 2 +- .../IdentityServiceHttpApiHostModule.cs | 2 +- .../EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json index 9368fc53..6794a32d 100644 --- a/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json +++ b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json @@ -1,7 +1,7 @@ { "App": { "SelfUrl": "https://localhost:44353", - "CorsOrigins": "https://localhost:44372,https://localhost:44373" + "CorsOrigins": "https://localhost:44372,https://localhost:44373,http://localhost:4200" }, "AuthServer": { "Authority": "http://localhost:8080/realms/master", diff --git a/services/basket/src/EShopOnAbp.BasketService/appsettings.json b/services/basket/src/EShopOnAbp.BasketService/appsettings.json index 983d031c..7ef6ff5f 100644 --- a/services/basket/src/EShopOnAbp.BasketService/appsettings.json +++ b/services/basket/src/EShopOnAbp.BasketService/appsettings.json @@ -1,7 +1,7 @@ { "App": { "SelfUrl": "https://localhost:44355", - "CorsOrigins": "https://localhost:44372,https://localhost:44373,https://localhost:44335" + "CorsOrigins": "https://localhost:44372,https://localhost:44373,,http://localhost:4200" }, "AuthServer": { "Authority": "http://localhost:8080/realms/master", diff --git a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json index 2a8273b1..7a8b88c1 100644 --- a/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json +++ b/services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/appsettings.json @@ -1,7 +1,7 @@ { "App": { "SelfUrl": "https://localhost:44354", - "CorsOrigins": "https://localhost:44372,https://localhost:44373,https://localhost:44335,http://localhost:4200" + "CorsOrigins": "https://localhost:44372,https://localhost:44373,http://localhost:4200" }, "AuthServer": { "Authority": "http://localhost:8080/realms/master", diff --git a/services/cmskit/src/EShopOnAbp.CmskitService.HttpApi.Host/appsettings.json b/services/cmskit/src/EShopOnAbp.CmskitService.HttpApi.Host/appsettings.json index 2558921d..750d9c24 100644 --- a/services/cmskit/src/EShopOnAbp.CmskitService.HttpApi.Host/appsettings.json +++ b/services/cmskit/src/EShopOnAbp.CmskitService.HttpApi.Host/appsettings.json @@ -1,7 +1,7 @@ { "App": { "SelfUrl": "https://localhost:44358", - "CorsOrigins": "https://localhost:44372,https://localhost:44373,http://localhost:4200,https://localhost:44335" + "CorsOrigins": "https://localhost:44372,https://localhost:44373,http://localhost:4200" }, "AuthServer": { "Authority": "http://localhost:8080/realms/master", diff --git a/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/IdentityServiceHttpApiHostModule.cs b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/IdentityServiceHttpApiHostModule.cs index 98ed74e0..1d837bb5 100644 --- a/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/IdentityServiceHttpApiHostModule.cs +++ b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/IdentityServiceHttpApiHostModule.cs @@ -40,7 +40,7 @@ public class IdentityServiceHttpApiHostModule : AbpModule { { "IdentityService", "Identity Service API" } }, - apiTitle: "IdentityService Gateway API" + apiTitle: "IdentityService API" ); diff --git a/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json index 014033f8..9cdfa28f 100644 --- a/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json +++ b/services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/appsettings.json @@ -1,7 +1,7 @@ { "App": { "SelfUrl": "https://localhost:44351", - "CorsOrigins": "https://localhost:44372,https://localhost:44373" + "CorsOrigins": "https://localhost:44372,https://localhost:44373,http://localhost:4200" }, "AuthServer": { "Authority": "http://localhost:8080/realms/master", From 84cc16ece6191253bb8d1891bb6e10a3ff2245f7 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 26 Oct 2022 03:57:25 -0400 Subject: [PATCH 4/6] removed unnecessery usings --- .../EShopOnAbpPublicWebModule.cs | 24 ++++++++++--------- .../JwtBearerConfigurationHelper.cs | 1 - 2 files changed, 13 insertions(+), 12 deletions(-) diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs index f231a383..b0078b9b 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs @@ -72,8 +72,6 @@ namespace EShopOnAbp.PublicWeb; typeof(CmskitServiceHttpApiClientModule), typeof(CmsKitDomainModule), typeof(CmsKitPublicWebModule) - - )] public class EShopOnAbpPublicWebModule : AbpModule { @@ -147,6 +145,7 @@ public class EShopOnAbpPublicWebModule : AbpModule options.ClientId = configuration["AuthServer:ClientId"]; options.MetadataAddress = configuration["AuthServer:MetaAddress"]; options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); + options.ResponseType = OpenIdConnectResponseType.CodeIdToken; options.GetClaimsFromUserInfoEndpoint = true; options.Scope.Add("openid"); options.Scope.Add("profile"); @@ -154,17 +153,16 @@ public class EShopOnAbpPublicWebModule : AbpModule options.Scope.Add("phone"); options.Scope.Add("roles"); options.Scope.Add("offline_access"); - + options.Scope.Add("AdministrationService"); options.Scope.Add("BasketService"); options.Scope.Add("CatalogService"); options.Scope.Add("PaymentService"); options.Scope.Add("OrderingService"); options.Scope.Add("CmskitService"); - + options.SaveTokens = true; - //Token response type, will sometimes need to be changed to IdToken, depending on config. - options.ResponseType = OpenIdConnectResponseType.Code; + //SameSite is needed for Chrome/Firefox, as they will give http error 500 back, if not set to unspecified. // options.NonceCookie.SameSite = SameSiteMode.Unspecified; // options.CorrelationCookie.SameSite = SameSiteMode.Unspecified; @@ -175,7 +173,7 @@ public class EShopOnAbpPublicWebModule : AbpModule // RoleClaimType = ClaimTypes.Role, // ValidateIssuer = true // }; - + if (AbpClaimTypes.UserName != "preferred_username") { options.ClaimActions.MapJsonKey(AbpClaimTypes.UserName, "preferred_username"); @@ -194,18 +192,21 @@ public class EShopOnAbpPublicWebModule : AbpModule options.Events.OnRedirectToIdentityProvider = async ctx => { // Intercept the redirection so the browser navigates to the right URL in your host - ctx.ProtocolMessage.IssuerAddress = configuration["AuthServer:Authority"].EnsureEndsWith('/') + "connect/authorize"; + ctx.ProtocolMessage.IssuerAddress = configuration["AuthServer:Authority"].EnsureEndsWith('/') + + "connect/authorize"; if (previousOnRedirectToIdentityProvider != null) { await previousOnRedirectToIdentityProvider(ctx); } }; - var previousOnRedirectToIdentityProviderForSignOut = options.Events.OnRedirectToIdentityProviderForSignOut; + var previousOnRedirectToIdentityProviderForSignOut = + options.Events.OnRedirectToIdentityProviderForSignOut; options.Events.OnRedirectToIdentityProviderForSignOut = async ctx => { // Intercept the redirection for signout so the browser navigates to the right URL in your host - ctx.ProtocolMessage.IssuerAddress = configuration["AuthServer:Authority"].EnsureEndsWith('/') + "connect/endsession"; + ctx.ProtocolMessage.IssuerAddress = configuration["AuthServer:Authority"].EnsureEndsWith('/') + + "connect/endsession"; if (previousOnRedirectToIdentityProviderForSignOut != null) { @@ -250,7 +251,8 @@ public class EShopOnAbpPublicWebModule : AbpModule private void ConfigureBasketHttpClient(ServiceConfigurationContext context) { context.Services.AddStaticHttpClientProxies( - typeof(BasketServiceContractsModule).Assembly, remoteServiceConfigurationName: BasketServiceConstants.RemoteServiceName + typeof(BasketServiceContractsModule).Assembly, + remoteServiceConfigurationName: BasketServiceConstants.RemoteServiceName ); Configure(options => diff --git a/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs b/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs index f87c63f4..b00229f1 100644 --- a/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs +++ b/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs @@ -1,7 +1,6 @@ using Microsoft.AspNetCore.Authentication.JwtBearer; using Microsoft.Extensions.DependencyInjection; using System; -using Microsoft.IdentityModel.Tokens; using Volo.Abp.Modularity; namespace EShopOnAbp.Shared.Hosting.Microservices; From adfc00eaa0e3468a17714af86e21a0b758db070e Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 26 Oct 2022 03:57:51 -0400 Subject: [PATCH 5/6] added scope and role mapping seeding --- .../KeycloakDataSeeder.cs | 64 ++++++++++++++----- 1 file changed, 49 insertions(+), 15 deletions(-) diff --git a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs index 80051883..2956e3d4 100644 --- a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs +++ b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs @@ -21,7 +21,8 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency private readonly ILogger _logger; private readonly IConfiguration _configuration; - public KeyCloakDataSeeder(IOptions keycloakClientOptions, ILogger logger, IConfiguration configuration) + public KeyCloakDataSeeder(IOptions keycloakClientOptions, ILogger logger, + IConfiguration configuration) { _logger = logger; _configuration = configuration; @@ -37,10 +38,38 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency public async Task SeedAsync(DataSeedContext context) { await UpdateAdminUserAsync(); + await CreateRoleMapperAsync(); await CreateClientScopesAsync(); await CreateClientsAsync(); } + private async Task CreateRoleMapperAsync() + { + var roleScope = (await _keycloakClient.GetClientScopesAsync(_keycloakOptions.RealmName)) + .FirstOrDefault(q => q.Name == "roles"); + if (roleScope == null) + return; + + if (!roleScope.ProtocolMappers.Any(q => q.Name == "roles")) + { + await _keycloakClient.CreateProtocolMapperAsync(_keycloakOptions.RealmName, roleScope.Id, + new ProtocolMapper() + { + Name = "roles", + Protocol = "openid-connect", + _ProtocolMapper = "oidc-usermodel-realm-role-mapper", + Config = new Dictionary() + { + { "access.token.claim", "true" }, + { "id.token.claim", "true" }, + { "claim.name", "roles" }, + { "multivalued", "true" }, + { "userinfo.token.claim", "true" }, + } + }); + } + } + private async Task CreateClientScopesAsync() { await CreateScopeAsync("AdministrationService"); @@ -77,12 +106,15 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency Name = scopeName, Protocol = "openid-connect", _ProtocolMapper = "oidc-audience-mapper", - Config = new Dictionary() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - { - { "id.token.claim", "false" }, - { "access.token.claim", "true" }, - { "included.custom.audience", scopeName } - } + Config = + new + Dictionary() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged + { + { "id.token.claim", "false" }, + { "access.token.claim", "true" }, + { "included.custom.audience", scopeName } + } } } }; @@ -126,9 +158,9 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency }; await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, webClient); - + await AddOptionalClientScopesAsync( - "PublicWeb", + "Web", new List { "AdministrationService", "IdentityService", "BasketService", "CatalogService", @@ -140,9 +172,10 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency private async Task CreateSwaggerClientAsync() { - var swaggerClient = (await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "SwaggerClient")) + var swaggerClient = + (await _keycloakClient.GetClientsAsync(_keycloakOptions.RealmName, clientId: "SwaggerClient")) .FirstOrDefault(); - + if (swaggerClient == null) { var webGatewaySwaggerRootUrl = _configuration[$"Clients:WebGateway:RootUrl"].TrimEnd('/'); @@ -155,7 +188,7 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency var orderingServiceRootUrl = _configuration[$"Clients:OrderingService:RootUrl"].TrimEnd('/'); var paymentServiceRootUrl = _configuration[$"Clients:PaymentService:RootUrl"].TrimEnd('/'); var cmskitServiceRootUrl = _configuration[$"Clients:CmskitService:RootUrl"].TrimEnd('/'); - + swaggerClient = new Client { ClientId = "SwaggerClient", @@ -197,13 +230,14 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency Name = "Public Web Application", Protocol = "openid-connect", Enabled = true, - BaseUrl = publicWebRootUrl, + BaseUrl = publicWebRootUrl, RedirectUris = new List { $"{publicWebRootUrl.TrimEnd('/')}/signin-oidc" }, FrontChannelLogout = true, - PublicClient = true + PublicClient = true, + ImplicitFlowEnabled = true // for hybrid flow }; publicWebClient.Attributes = new Dictionary { @@ -211,7 +245,7 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency }; await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, publicWebClient); - + await AddOptionalClientScopesAsync( "PublicWeb", new List From bd7290f6377e66d018bd62fe865ca4c84c2474d8 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Wed, 26 Oct 2022 03:58:02 -0400 Subject: [PATCH 6/6] updated angular scopes --- apps/angular/src/environments/environment.ts | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/apps/angular/src/environments/environment.ts b/apps/angular/src/environments/environment.ts index 243cea14..61d849c6 100644 --- a/apps/angular/src/environments/environment.ts +++ b/apps/angular/src/environments/environment.ts @@ -13,8 +13,7 @@ export const environment = { redirectUri: baseUrl, clientId: 'Web', responseType: 'code', - scope: 'offline_access openid profile email phone', - // scope: 'offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService', //TODO: Update when https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged + scope: 'offline_access openid profile email phone roles AdministrationService IdentityService BasketService CatalogService OrderingService PaymentService CmskitService', //requireHttps: true, }, apis: {