yasithdev opened a new pull request, #685:
URL: https://github.com/apache/airavata/pull/685

   The dev realm's `default-admin` had the `admin-rw` role but no 
`realm-management` client roles. Server-side IAM operations call the Keycloak 
admin API using the caller's own access token (`IamAdminService.getUsers` → 
`TenantManagementKeycloakImpl.getUsers` → 
`client.realm(tenantId).users().search(...)`), so without those roles the admin 
users page (`/admin/users`) failed with HTTP 403. Production gateway admins 
receive all realm-management roles via `createTenantAdminAccount`; this mirrors 
that for the dev admin by granting the `realm-management` `realm-admin` 
composite.
   
   Test plan: recreate the keycloak container; a fresh `default-admin` token 
now carries `resource_access.realm-management.roles` (incl. 
`view-users`/`manage-users`), and `GET /api/iam-user-profiles/` returns 200 
with the user list (previously 403). Verified live.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to