Deny access by default if no scope binding defined with Quarkus and Keycloak

Viewed 39

I'm exploring Keycloak as an authorization solution for my Quarkus application.

Let's say, I have an endpoint:

@Path("document")
@Authenticated
class DocumentEndpoint {
    @GET
    @Produces(MediaType.TEXT_PLAIN)
    fun get(id: Long): String {
        return "Document #$id"
    }

    @POST
    fun create(doc: String) {
        println("Received document $doc")
    }
}

Here is my application.yaml (HTTP is used only for test purposes):

quarkus:
  oidc:
    auth-server-url: http://keycloak:8080/realms/MyRealm
    client-id: document-storage
    credentials:
      secret: secret

  keycloak:
    policy-enforcer:
      enable: true
      enforcement-mode: enforcing
      paths:
        document:
          path: "/document"
          methods:
            GET:
              method: GET
              scopes: [view]

As you can see, there is no POST method mapping, yet the POST request to the /document endpoint is executing just fine if a user have a scope-based permission to use any scope on the /document resource. As you can imagine, if a user was granted only the view permission, but in fact he is able to call the create method, this may be very troublesome.

So, if someone forgets to add a mapping for a method, the access for it is granted by default.

In Java EE I could set the @DenyAll on a class and then adding the @RolesAllowed annotation for the methods I'd like to expose. In this case, forgetting to annotate a new method will result in access denied exception.

Is it possible to implement this behavior using the Keycloak Policy enforcer in Quarkus?

0 Answers
Related