Currently, I'm having a web-application with SSO. The Authorization for the users has many hierarchical levels and is therefore very granular.
I want to move towards central Authentication with Keycloak to connect the existing web-app-service with other web-apps. The authorization and authorization-management should still be happening in the existing Web-Application.
What is the state of the art solution to have Authentication in Keycloak and Authorization in the existing web-application?
How would a new user be created / synced so that it exists in Keycloak and in the existing Web-Application?
My idea would be to have a third server which handles the creation of users (see image). Is there a better/simpler solution?