Keycloak http Claim information provider

Viewed 892

We have chosen keycloak to do Authentication & Authorization for spring-boot services. We have successfully implemented RBAC usecase. But we want to move onto ABAC where it gives us lot of control. We looked at CIP (Claim Information Point) and tested it with pushing claim from app.properties and verifying it in js policy. But our requirement is to get the http method type and verify whether it is GET/POST/PUT/DELETE etc and then decide whether to allow or not by role. We achived it throw below config in application.properties

keycloak.policy-enforcer-config.paths[0].path=/*
keycloak.policy-enforcer-config.paths[0].claimInformationPointConfig.claims[claim-from-method]={request.method}

And verifying that in js policy as below

var context = $evaluation.context;

var attributes = context.attributes;

if (attributes.containsValue('some-claim', 'claim-value')) {
    $evaluation.grant();
}

But i have seen there is HttpClaimInformationPointProvider and so wants to find out is there any way that we can verify it directly in js-policy without pushing it from app.properties.

0 Answers
Related