[keycloak-dev] User actions
Stian Thorgersen
stian at redhat.com
Wed Sep 11 08:24:28 EDT 2013
Unless someone else has already started to work on (or is very interested) I plan to work on account workflows. This work includes:
* Email verification
* Reset password
* Configure TOTP after registration if required by realm
* Marking user as requiring actions before they can login to applications
I've outlined a proposal on:
https://github.com/keycloak/keycloak/wiki/User-Actions
Finally, when an account is in the state of requiring actions (read the above wiki page to understand what I'm talking about!) the user should have access to the account management pages, but not to applications themselves. I was thinking in this case the accessCodeId could be passed as a query parameter, which would allow the account management pages to verify that the user is logged in, but at the same not enable SSO to applications (as the cookie isn't set yet). An alternative I was thinking of was that the SkeletonKeyToken could have the status added to it, but I don't like that approach as that would require applications to check the status. Any other suggestions?
More information about the keycloak-dev
mailing list