yasithdev opened a new pull request, #683:
URL: https://github.com/apache/airavata/pull/683

   Renames the dev Keycloak realm's coarse-authorization roles 
(`admin`→`admin-rw`, `admin-read-only`→`admin-ro`, `gateway-user`→`user`), adds 
`user` to the realm default-role composite so every authenticated user inherits 
it, and grants `default-admin` the `admin-rw` role. This is the first step of 
moving gateway-admin determination off the sharing-registry group lookup and 
onto Keycloak realm roles carried in the JWT (`realm_access.roles`); subsequent 
changes update the portal and server to read these roles.
   
   Test plan: recreate the keycloak container (re-imports the realm via 
`--import-realm --db=dev-mem`); a fresh `default-admin` token now carries 
`realm_access.roles` = `[admin-rw, user, …]`. No live consumer reads these 
roles yet, so there is no behavior change.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to