Keycloak Authorization Service - Dynamic Resource and Resource attributes

Viewed 397

I have a Spring Boot application, and I am using Keycloak's Authorisation Services.

Let's say I have a Report called Report1, with id 1, created by user1.

The URL to access the resource would be /app/{reportId}. To access the report one will use /app/1

I want to restrict access to this url to the owner/creator of the report only (user1). Since this is kind of "dynamic" url, and the ID is not determined beforehand, I can't create a resource with static url (app/1) in Keycloak.

I would like to introduce a JS policy something like:

    var context = $evaluation.context;
    var identity = context.identity;
    var permission = $evaluation.permission;
    var resource = <Report1>

    if (resource.<created_by_user_id> == identity.id) {
        $evaluation.grant();
    }

From the above code:

  • Report1 should be determined dynamically from DB
  • created_by_user_id is an attribute of Report1 which contains user1

Any ideas?

1 Answers

Dynamic url when creating resources are supported, that I know of. Regarding the resource attributes, you can use something like this:

var attributes = resource.getAttributes();

You could attach a dedicated attribute, like ownership, where the value is the creator (user1).

Related