How to prevent login in homepage in Keycloak?

Viewed 47

I'm learning to use Keycloak and I'm trying to use it within Apache Tomcat.

Considering that I have done the following steps:

  1. Valve for Keycloak in context.xml
<Context path="/KeycloakExample">
    <Valve className="org.keycloak.adapters.tomcat.KeycloakAuthenticatorValve"/>
</Context>
  1. Security constraints in web.xml
 <security-constraint>
        <web-resource-collection>
            <web-resource-name>risorsenonprotette</web-resource-name>
            <url-pattern>/*</url-pattern>
            <http-method>GET</http-method>
            <http-method>POST</http-method>
        </web-resource-collection>
    </security-constraint>
  
    <security-constraint>
        <web-resource-collection>
            <web-resource-name>risorseprotette</web-resource-name>
            <url-pattern>/protected/*</url-pattern>
            <http-method>GET</http-method>
            <http-method>POST</http-method>
        </web-resource-collection>
        <auth-constraint>
            <role-name>ruolo_utente</role-name>
            <role-name>ruolo_amministratore</role-name>
        </auth-constraint>
    </security-constraint>
    

    <login-config>
        <auth-method>BASIC</auth-method>
        <realm-name>this is ignored currently</realm-name>
    </login-config>

    <security-role>
        <role-name>ruolo_amministratore</role-name>
    </security-role>
    <security-role>
        <role-name>ruolo_utente</role-name>
    </security-role>
    
    <error-page>
        <error-code>403</error-code>
        <location>/errore403.jsp</location>
    </error-page>
  1. Added adapters in tomcat folder/lib

How can I prevent keycloak from asking authentication when I'm on index.jsp? My project structure is the following:

KeycloakExample
└── src
    └── main
        ├── java
        └── webapp
            ├── css
            │   └── style.css
            ├── META-INF
            │   └── context.xml
            ├── protected
            │   ├── pagine
            │   │   └── home.jsp
            │   └── riservata
            │       └── riservata.jsp
            ├── WEB-INF
            │   ├── keycloak.json
            │   └── web.xml
            ├── index.jsp
            ├── errore403.jsp
            ├── AccessDenied.jsp
            └── logout.jsp

There are two role: users and admin. Both can access everything inside "pagine" folder but only admin can access "riservata"

What I'm trying to get right now is that everyone can access my index.jsp but I don't know what I'm doing wrong.

Any tips?

0 Answers
Related