[keycloak-user] Spring Boot adapter with HTTP verb based authorization

Andreea Ciuprina aciuprin at mpi-bremen.de
Tue Feb 21 11:18:49 EST 2017


Hello!



We are building an online application for which we are using Keycloak for authentification and authorization, connected

to our Spring Boot backend using the Spring Boot adapter.


We would like to achive more fine-grained authorization, more specifically, we would like to set-up HTTP verb based 

authorization, for example, allow only GET requests for some end-points, GET and POST for others, only POST for other end-points etc.



I am aware of the Policy Enforcer adapter, but I could not find any specific documentation regarding how to use that with Spring Boot, where there is 

not keycloak.json file used for configuration.



Therefore, my questions are:

1. Can HTTP verb based authorization be achieved using the Spring Boot adapter? 

2. If the answer to question 1 is yes, then could you please provide a minimal configuration example?



Thank you!

Best regards, 

Andreea

---------------------------------------------------------

Andreea Ciuprina
 
Bioinformatics Group
Max Planck Institute for Marine Microbiology 

Celsiusstraße 1
28359 Bremen
Germany
 
Phone: +49(0) 421 2028 982
Email: aciuprin at mpi-bremen.de

& 

Jacobs University Bremen, 
28759 Bremen, Germany
Email: a.ciuprina at jacobs-university.de



More information about the keycloak-user mailing list