[keycloak-user] Recommendations for protecting REST service with bearer token and basic auth