Not having any clue why is that.
Help would be appreciated. Thanks
Use
-Djdk.serialSetFilterAfterRead=true
See the following for more details
https://issues.redhat.com/browse/KEYCLOAK-15901
Seems like the problem is caused by ObjectInputStream.setObjectFilter (on Java 9 - 11) respective ObjectInputStream.setInternalObjectInputFilter (in Java 8) throws IllegalStateException("filter can not be set after an object has been read")
Now I don't see the warnings after I did some changes. This is what I did in my pom.xml and made some changes to the Config class which extends the KeycloakWebSecurityConfigurerAdapter
public class ResourceServerConfig extends KeycloakWebSecurityConfigurerAdapter {
public final KeycloakClientRequestFactory keycloakClientRequestFactory;
// keycloakClientRequestFactory injected via constructor
public ResourceServerConfig(KeycloakClientRequestFactory keycloakClientRequestFactory) {
this.keycloakClientRequestFactory = keycloakClientRequestFactory;
}
...
...
/**
* To simplify communication between clients, Keycloak provides an extension of Spring’s RestTemplate that handles
* bearer token authentication for you. To enable this feature your security configuration must add the
* KeycloakRestTemplate bean. Note that it must be scoped as a prototype to function correctly.
* <p>
* Refer: https://www.keycloak.org/docs/latest/securing_apps/#_spring_security_adapter (Spring Security Adapter)
*
* @return
*/
@Bean
@Scope(ConfigurableBeanFactory.SCOPE_PROTOTYPE)
public KeycloakRestTemplate keycloakRestTemplate() {
return new KeycloakRestTemplate(keycloakClientRequestFactory);
}
}
And in the pom.xml file
<dependency>
<groupId>org.keycloak</groupId>
<artifactId>keycloak-spring-boot-starter</artifactId>
<version>12.0.4</version>
</dependency>
<dependency>
<groupId>org.keycloak</groupId>
<artifactId>keycloak-spring-security-adapter</artifactId>
<version>13.0.1</version>
</dependency>