Keycloak: how to authorize a client resource by using the resource url and access_token only?

Viewed 274

I'm trying to use keycloak as my authorization server (on a gateway level) and intercept all requests to determine if the user is authorized or not.

I've done all the configuration right on keycloak side and when using its UI evaluate, I get the desired access control.

My problem is with this code I've to provide the requested resource_Id which is not a dynamic way to do so.

Here is my code snappit.

PermissionRequest request = new PermissionRequest(resourceId);
String ticket = authzClient.protection().permission().create(request).getTicket();

authzClient.authorization(req.user().principal().getString("access_token"))
  .authorize(new AuthorizationRequest(ticket));

If the user is not authorized to use this resources I get 'UnauthorizedException', I would like to use the requested resource URI instead of the resourceId, is there a way to do so?

Note that I'm using Vertx framework not Spring boot.

0 Answers
Related