[keycloak-dev] Access original session

Stian Thorgersen stian at redhat.com
Tue Dec 30 07:38:21 EST 2014


The session cookie (assuming you're talking about JSESSIONID) should be set to the context-path of your WAR not a specific protected resource. Is your protected resources in the same WAR as the unprotected resources?

----- Original Message -----
> From: "Christian Beikov" <christian.beikov at gmail.com>
> To: keycloak-dev at lists.jboss.org
> Sent: Sunday, 28 December, 2014 11:01:54 AM
> Subject: [keycloak-dev] Access original session
> 
> Hello there!"
> 
> I have an application that has protected resources on the pattern
> "/protected/*" and I receive a session cookie for the path "/protected",
> which makes sense. Now my problem is, that I want the path of the cookie to
> be "/" so I can access the user information even outside of the protected
> resources.
> Since I think this might introduce some problems, the only other way to
> realize that I could think of is, to get access to the underlying servlet
> session. Not only would that session have to be created properly, which I am
> not sure is happening when browsing in the protected resources, I would also
> need to access it on the server, so that I can save the currently logged in
> user into it.
> 
> Is there a possibility to access the servlet session within the Keycloak
> context? If so, could you please share some code or point me to an API?
> --
> 
> Mit freundlichen Grüßen,
> 
> Christian Beikov
> 
> _______________________________________________
> keycloak-dev mailing list
> keycloak-dev at lists.jboss.org
> https://lists.jboss.org/mailman/listinfo/keycloak-dev



More information about the keycloak-dev mailing list