[keycloak-user] Roles without "Full Scope Allowed"?

Michael Poettgen Michael.Poettgen at oeconnection.com
Tue Feb 20 07:07:27 EST 2018


All,

I've got Keycloak 3.4.3 configured to return client roles in a "role" Claim to an OpenID Connect client. (The client has got a list of roles, these are assigned to the user and I've got a User Client Role Token mapper that maps the roles of that client into the "role" claim.) Everything works until I turn "Full Scope Allowed" off. Then all roles disappear and trying to request the roles via the "scope" (with or without client ID prefix) doesn't seem to work.

Am I doing something stupid or is there something that does not work as (I) expected?

Thanks for your help!

Michael


This message may contain confidential information. If you are not the intended recipient, do not disseminate, distribute, or copy this e-mail or its attachments. Please notify the sender of the error immediately by e-mail or at the telephone number listed below, and delete this e-mail and any attachments from your system. Receipt by anyone other than the intended recipient(s) is not a waiver of any trade secrets, proprietary interests, or other applicable rights.  E-mail transmission is not necessarily secure or error-free, as information could be intercepted, corrupted, lost, destroyed, delayed, incomplete, or may contain viruses. The sender disclaims all liability for any errors or omissions arising as a result of the e-mail transmission. 

OEConnection LLC, (888) 776-5792, www.oeconnection.com



More information about the keycloak-user mailing list