[keycloak-dev] Don't show KEYCLOAK_APPLICATION and KEYCLOAK_IDENTITY_REQUESTER externally
Stian Thorgersen
stian at redhat.com
Thu Nov 14 11:51:32 EST 2013
Should KEYCLOAK_APPLICATION or KEYCLOAK_IDENTITY_REQUESTER be visible at all externally (both in REST endpoints and admin console)?
I was thinking that these roles should be removed from the list of roles returned, and if anyone tries to delete a role starting with "KEYCLOAK_" a not found should be returned.
More information about the keycloak-dev
mailing list