
I am trying to implement POC with keycloak as auth* server.

Here is my set up / use case:
So my questions are: 

1. Is this correct description of what's going on or am I missing something?

2. If this is the behavior by design wouldn't it be better instead of the 400 error to redirect user to some themed page on the keycloak server with a nice explanation, like "We're sorry, but you cannot access this resource without authentication, blablabla "

Thank you,
Roman Usatenko.