I have a Keycloak instance with :
user1/password1user2/password2client/secretwith Direct Access Grants Enable and scopes :resourceA,resourceB
When I do a password grant flow like :
curl --location --request POST 'https://keycloak.instance/auth/realms/my-realm/protocol/openid-connect/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=password' \
--data-urlencode 'client_id=client' \
--data-urlencode 'client_secret=secret' \
--data-urlencode 'username=user1' \
--data-urlencode 'password=password1'
I want to retrieve a token with the scope : resourceA and NOT resourceB.
And when the same call is made using user2, I want ONLY resourceB scope.
Is there a way to configure this rule in Keycloak to only have a token with an intersection of scope/role of the client and the grant user ?