If memory serves me correctly this was on purpose where the thinking 5
years ago was that users would be imported on first login, then managed
from Keycloak after that. That is not always the case though and we should
have some way of controlling if users updated on subsequent logins and
perhaps also be able to fine-tune what is updated.
On Thu, 19 Sep 2019 at 13:21, EXTERNAL Thiele Frank (TNG, INST-CSS/BSV-OS2)
<external.Frank.Thiele(a)bosch-si.com> wrote:
Hello,
In our project, we use the "Hardcoded role" mapper within a configured
Identity Provider (also a Keycloak instance, in our case the same but a
different realm) to describe that each user logging in via Keycloak shall
be given a certain role.
This works perfectly if the mapper is configured before the first login of
the user. The configured role is granted to the (cloned) user when he logs
in the first time via Keycloak.
But when another "Hardcoded role" mapper is added to configure another
role, then the user is not given the other role when he logs in. Only new
users logging in the first time get both roles assigned.
Is this on purpose or a bug?
Mit freundlichen Grüßen / Best regards
Frank Thiele
Open Source Services 2 - Product Group Customer Success Services
(INST-CSS/BSV-OS2) Bosch Software Innovations GmbH | Ullsteinstr. 128 |
12109 Berlin | GERMANY |
www.bosch-si.com<http://www.bosch-si.com<
http://www.bosch-si.com%3chttp:/www.bosch-si.com>>
external.Frank.Thiele(a)bosch-si.com<mailto:
external.Frank.Thiele(a)bosch-si.com<mailto:
external.Frank.Thiele(a)bosch-si.com%
3cmailto:external.Frank.Thiele@bosch-si.com>>
Sitz: Berlin, Registergericht: Amtsgericht Charlottenburg; HRB 148411 B
Aufsichtsratsvorsitzender: Dr.-Ing. Thorsten Lücke; Geschäftsführung: Dr.
Stefan Ferber, Michael Hahn, Dr. Aleksandar Mitrovic
_______________________________________________
keycloak-dev mailing list
keycloak-dev(a)lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-dev