Support opt-in MFA per browser client with authoritative enrollment checks
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
e1e292919a
commit
ac8ed65203
14 changed files with 298 additions and 12 deletions
|
|
@ -372,6 +372,10 @@ func mapClient(c domain.Client) (KeycloakClient, []string) {
|
|||
if c.EnrollmentURL != "" {
|
||||
kc.Attributes["keycape.enrollmentUrl"] = c.EnrollmentURL
|
||||
}
|
||||
if c.MFAOptional {
|
||||
kc.Attributes["keycape.mfaOptional"] = "true"
|
||||
unpreserved = append(unpreserved, fmt.Sprintf("client %q: mfaOptional requires a manually verified conditional MFA authentication flow; enrollment policy is not enforced by import", c.ClientID))
|
||||
}
|
||||
if c.MFARequired != nil && *c.MFARequired {
|
||||
// Keycloak expresses this as an authentication flow binding, which a
|
||||
// realm import cannot synthesise from a boolean.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue