I'm exploring Keycloak as an authorization solution for my Quarkus application.
Let's say, I have an endpoint:
@Path("document")
@Authenticated
class DocumentEndpoint {
@GET
@Produces(MediaType.TEXT_PLAIN)
fun get(id: Long): String {
return "Document #$id"
}
@POST
fun create(doc: String) {
println("Received document $doc")
}
}
Here is my application.yaml (HTTP is used only for test purposes):
quarkus:
oidc:
auth-server-url: http://keycloak:8080/realms/MyRealm
client-id: document-storage
credentials:
secret: secret
keycloak:
policy-enforcer:
enable: true
enforcement-mode: enforcing
paths:
document:
path: "/document"
methods:
GET:
method: GET
scopes: [view]
As you can see, there is no POST method mapping, yet the POST request to the /document endpoint is executing just fine if a user have a scope-based permission to use any scope on the /document resource.
As you can imagine, if a user was granted only the view permission, but in fact he is able to call the create method, this may be very troublesome.
So, if someone forgets to add a mapping for a method, the access for it is granted by default.
In Java EE I could set the @DenyAll on a class and then adding the @RolesAllowed annotation for the methods I'd like to expose. In this case, forgetting to annotate a new method will result in access denied exception.
Is it possible to implement this behavior using the Keycloak Policy enforcer in Quarkus?