Keycloak two Frontend Clients and one Backend Client

Viewed 2865

i've got following setup:

enter image description here

Frontends are Angular1 Frontends. Backend is Spring Boot in use with the Keycloak Sring Boot Adapter in Combination of Spring Security.

The process is the standard OAUTH2:

  1. Frontend sends credentials to Keycloak
  2. If valid Keycloak sends Token to Frontend
  3. Frontend sends requests with this token to backend
  4. Backend sends token to keycloak for validation
  5. keycloak accepts token after validation
  6. backend is responding to frontend

This is working fine with one Frontend. You have to config the Keycloak Adapter of the Spring Backend via "keycloak.auth-server-url" in application.properties. My keycloak.auth-server-url of the Keycloak Adapter is pointing to an WebServer which is delivering the Frontend1 and is configured as reverse proxy. So it is forwarding in step 3 to the keycloak server with this config:

keycloak.auth-server-url=www.UrlOfFrontend1.com/auth

'/auth' is the forwarding path to keycloak. It is working fine for one frontend.

My problem is step 4 with two frontends. Every Frontend is delivered by a own WebServer which is configured as reverse proxy. If i deliver a second frontend with a second reverse proxy which delivers Frontend2 keycloak is throwing the error:

[org.keycloak.adapters.BearerTokenRequestAuthenticator] (default task-39) Failed to verify token: org.keycloak.common.VerificationException: Invalid token issuer. Expected 'http://www.UrlOfFrontend1.com/auth/realms/myrealm', but was 'http://www.UrlOfFrontend2.com/auth/realms/myrealm' at org.keycloak.TokenVerifier.verify(TokenVerifier.java:156) at org.keycloak.RSATokenVerifier.verify(RSATokenVerifier.java:89)

I need the Spring Boot Keycloak Adapter configuration for both frontends. I have got two public Frontend Clients in Keycloak configured. What am I missing?

0 Answers
Related