Hi Pedro,
Which version of Keycloak are you using?
I am using 4.8.2 Final (see attached screenshot).
I tried to reproduce the problem using upstream and the evaluation
tool
looks correct by reporting only album:view. The same goes if obtaining an
RPT from the token endpoint.
Can you share a screenshot of your evaluation tool result ? Does it correctly
DENY access ?
I can also share my server config json if this helps.
Thanks,
Marek