Support opt-in MFA per browser client with authoritative enrollment checks
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-13 00:27:28 +02:00
parent e1e292919a
commit ac8ed65203
14 changed files with 298 additions and 12 deletions

View file

@ -372,6 +372,10 @@ func mapClient(c domain.Client) (KeycloakClient, []string) {
if c.EnrollmentURL != "" {
kc.Attributes["keycape.enrollmentUrl"] = c.EnrollmentURL
}
if c.MFAOptional {
kc.Attributes["keycape.mfaOptional"] = "true"
unpreserved = append(unpreserved, fmt.Sprintf("client %q: mfaOptional requires a manually verified conditional MFA authentication flow; enrollment policy is not enforced by import", c.ClientID))
}
if c.MFARequired != nil && *c.MFARequired {
// Keycloak expresses this as an authentication flow binding, which a
// realm import cannot synthesise from a boolean.