adorsys / adorsys/keycloak-config-cli

AuthenticationFlow with script execution import not work

未关闭
#854 2 条评论 0 个 reaction 已指派 1 人 已被 @Motouom 认领 在 GitHub 查看
bug
主要语言
Java
星标
1.2k
派生
200
PR 合并指标
30 天内没有已合并 PR

描述

### Current Behavior

when i import a realm with authenticationflow i get an error.

Error Message:
**Cannot create execution '' for non-top-level-flow 'myclientflow forms' in realm 'myrealm': HTTP 400 Bad Request**

Sample Part of import sample.yaml

```
---
realm: "myrealm"
displayName: "wallis"
displayNameHtml: "

Keycloak
"
enabled: true
authenticationFlows:
- id: xxxx-xxx-xxx-xx-xxx
alias: myclientflow
description: browser based authentication
providerId: basic-flow
topLevel: true
builtIn: false
authenticationExecutions:
- authenticator: auth-cookie
authenticatorFlow: false
requirement: DISABLED
priority: 0
autheticatorFlow: false
userSetupAllowed: false
- authenticator: auth-spnego
authenticatorFlow: false
requirement: DISABLED
priority: 1
autheticatorFlow: false
userSetupAllowed: false
- authenticator: identity-provider-redirector
authenticatorFlow: false
requirement: ALTERNATIVE
priority: 2
autheticatorFlow: false
userSetupAllowed: false
- authenticatorFlow: true
requirement: ALTERNATIVE
priority: 3
autheticatorFlow: true
flowAlias: confluencetest jiraprod jiratest Grafana forms
userSetupAllowed: false
- id: xxxxxxx-xxxx-xxx-xxxx-xxxxx
alias: myclientflow forms
description: Username, password, otp and other auth forms.
providerId: basic-flow
topLevel: false
builtIn: false
authenticationExecutions:
- authenticator: auth-username-password-form
authenticatorFlow: false
requirement: REQUIRED
priority: 0
autheticatorFlow: false
userSetupAllowed: false
- authenticatorConfig: myclientflow
authenticator: script-myclientflow.js
authenticatorFlow: false
requirement: REQUIRED
priority: 1
autheticatorFlow: false
userSetupAllowed: false
authenticatorConfig:
- id: xxxxxx-xxx-xxx-xx-xxxxxxxxxx
alias: myclientflow
config:
scriptName: script-myclientflow.js
scriptCode: >-
/*
* Template for JavaScript based authenticator's.
* See org.keycloak.authentication.authenticators.browser.ScriptBasedAuthenticatorFactory
*/

// import enum for error lookup

AuthenticationFlowError = Java.type("org.keycloak.authentication.AuthenticationFlowError");

/**
* An example authenticate function.
*
* The following variables are available for convenience:
* user - current user {@see org.keycloak.models.UserModel}
* realm - current realm {@see org.keycloak.models.RealmModel}
* session - current KeycloakSession {@see org.keycloak.models.KeycloakSession}
* httpRequest - current HttpRequest {@see org.jboss.resteasy.spi.HttpRequest}
* script - current script {@see org.keycloak.models.ScriptModel}
* authenticationSession - current authentication session {@see org.keycloak.sessions.AuthenticationSessionModel}
* LOG - current logger {@see org.jboss.logging.Logger}
*
* You one can extract current http request headers via:
* httpRequest.getHttpHeaders().getHeaderString("Forwarded")
*
* @param context {@see org.keycloak.authentication.AuthenticationFlowContext}
*/
function authenticate(context) {

var username = user ? user.username : "anonymous";
LOG.info(script.name + " trace auth for: " + username);

var authShouldFail = true;

for each (var role in user.getRoleMappings())
{

//if(role.getName().startsWith("Log"))
if(role.getName().indexOf('myclient') !== -1)
{
authShouldFail = false;
}
}

if (authShouldFail) {

context.failure(AuthenticationFlowError.INVALID_USER);

return;
}

context.success();
}
scriptDescription: myclient
```

### Expected Behavior

_No response_

### Steps To Reproduce

```markdown
1. create Keycloak X Image with 19.0.1 and build myclientflow.js into jar and add to provider folder
3. start keycloak in a docker container
2. try to import with java -jar keycloak-config-cli-19.0.1.jar --keycloak.url=http://localhost/auth --keycloak.user=*** --keycloak.password=*** --import.files.locations=sample.yaml
```

### Environment

- Keycloak Version: 19.0.1
- keycloak-config-cli Version: 19.0.1
- Java Version: 11

### Anything else?

_No response_

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。