Setup:
- We have a HTTPS strapi application and keycloak is configured as an identity provider with the corresponding client id and secret from the keycloak client. Both strapi and keycloak are behind nginx.
- We have a keycloak server, where the strapi is added as a client with the necessary redirect URIs configured.
- Also, the provider.js and bootstrap.js is setup as suggested in the reference:
Issue:
- Strapi throws an error when trying to access the client:
{"statusCode":400,"error":"Bad Request","message":{"message":"No access_token."},"data":{"message":"No access_token."}}
https://our.website.domain/strapi/auth/keycloak/callback?error=request-compose%3A%20timeout
- In the logs, we see that the access token is not received and hence the error is thrown from strapi end. example provider.js line
Verification:
- Strapi is able to use other social identity providers like GitHub to authenticate as expected.
- We are able to use Postman to get the access token from keycloak by posting to https://our.website.domain/auth/realms/exampleRealmName/protocol/openid-connect/token as suggested in this comment (step1).
- We are able to use the access token to get response from Strapi through Postman. https://our.website.domain/connect/IDP-Name/callback as suggested here (step 2)
Any inputs or advise on what could be the issue?
Thank you in advance.