[keycloak-dev] Keycloak large token issue

tushar dhole tushardhole at hotmail.com
Tue Sep 4 22:56:58 EDT 2018


Oh that's great .. Thanks.. I will try latest...

Get Outlook for Android<https://aka.ms/ghei36>



From: Stian Thorgersen
Sent: Wednesday, 5 September, 12:41 am
Subject: Re: [keycloak-dev] Keycloak large token issue
To: tushardhole at hotmail.com
Cc: keycloak-dev


This should already be resolved and the tokens issues to the admin console should not contain all roles anymore. Have you tried this with the latest release?

On Tue, 4 Sep 2018 at 14:30, tushar dhole <tushardhole at hotmail.com<mailto:tushardhole at hotmail.com>> wrote:
Hello Community,

There is a limitation with keycloak to support large number of realms. Following is the existing jira issue related to same,


https://issues.jboss.org/browse/KEYCLOAK-1268


I was wondering if we can solve this following approach,


  1.  Make the token for users under "master" realm not return all realm info.
  2.  We can just allow a token from "realm": "master" any for cross realm authorization
  3.  For all other non master realm the token will be same as that of today


If this approach is feasible/doable, then I can dig into the code and try to implement this.
But would first like to know if this is really a feasible/doable one.

Thanks a lot,
Tushar Dhole
<https://issues.jboss.org/browse/KEYCLOAK-1268>
[KEYCLOAK-1268] Token for admin becomes to large with many ...<https://issues.jboss.org/browse/KEYCLOAK-1268>
issues.jboss.org<http://issues.jboss.org>
I have a big problem here because of bearer token size. I'm using keycloak within a SaaS application, so I need create alot of realms.





_______________________________________________
keycloak-dev mailing list
keycloak-dev at lists.jboss.org<mailto:keycloak-dev at lists.jboss.org>
https://lists.jboss.org/mailman/listinfo/keycloak-dev




More information about the keycloak-dev mailing list