I want my users being able to sign in on a keycloak authorization server with single sign on:
<a href="http://localhost:8180/realms/myrealm/protocol/openid-connect/auth?response_type=code
&scope=openid&client_id=myclient&redirect_uri=http%3A%2F%2Flocalhost%3A8080%2Fbookings">SSO</a>
After the login, the user is successfully redirected to localhost:8080/bookings. Works fine.
Now I want to send a sub http request in behalf of the user from my backend as soon as the secured /bookings is accessed.
Question: how can I fetch the Bearer token from the single sign on action the user just made?
I tried reading the cookies, but they don't contain any useful data.
@Controller
public class BookingControler {
@GetMapping("/bookings")
public String bookings(Model model, HttpServletRequest req) {
Arrays.stream(req.getCookies()).forEach(cookie -> System.out.println(cookie.getName() + ": " + cookie.getValue()));
//TODO
//externalWebService.fetchBookings(bearerToken);
return "bookings";
}
}
So how can I intercept the "result" of the sign on? Or as an alternative, let the user click another button in frontend that sends the bearer token to my backend, so I can fetch data from external service on behalf of the user?