I'm learning to use Keycloak and I'm trying to use it within Apache Tomcat.
Considering that I have done the following steps:
- Valve for Keycloak in context.xml
<Context path="/KeycloakExample">
<Valve className="org.keycloak.adapters.tomcat.KeycloakAuthenticatorValve"/>
</Context>
- Security constraints in web.xml
<security-constraint>
<web-resource-collection>
<web-resource-name>risorsenonprotette</web-resource-name>
<url-pattern>/*</url-pattern>
<http-method>GET</http-method>
<http-method>POST</http-method>
</web-resource-collection>
</security-constraint>
<security-constraint>
<web-resource-collection>
<web-resource-name>risorseprotette</web-resource-name>
<url-pattern>/protected/*</url-pattern>
<http-method>GET</http-method>
<http-method>POST</http-method>
</web-resource-collection>
<auth-constraint>
<role-name>ruolo_utente</role-name>
<role-name>ruolo_amministratore</role-name>
</auth-constraint>
</security-constraint>
<login-config>
<auth-method>BASIC</auth-method>
<realm-name>this is ignored currently</realm-name>
</login-config>
<security-role>
<role-name>ruolo_amministratore</role-name>
</security-role>
<security-role>
<role-name>ruolo_utente</role-name>
</security-role>
<error-page>
<error-code>403</error-code>
<location>/errore403.jsp</location>
</error-page>
- Added adapters in tomcat folder/lib
How can I prevent keycloak from asking authentication when I'm on index.jsp? My project structure is the following:
KeycloakExample
└── src
└── main
├── java
└── webapp
├── css
│ └── style.css
├── META-INF
│ └── context.xml
├── protected
│ ├── pagine
│ │ └── home.jsp
│ └── riservata
│ └── riservata.jsp
├── WEB-INF
│ ├── keycloak.json
│ └── web.xml
├── index.jsp
├── errore403.jsp
├── AccessDenied.jsp
└── logout.jsp
There are two role: users and admin. Both can access everything inside "pagine" folder but only admin can access "riservata"
What I'm trying to get right now is that everyone can access my index.jsp but I don't know what I'm doing wrong.
Any tips?