Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-381

Incorrect page after failed login due to missing role

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • RH-SSO-7.1.0.DR2
    • None
    • Quickstarts
    • None

      For app-jee _keycloak-examples) or app-jee-jsp (keycloak-quickstarts) , if you attempt to login but the user does not have the proper roles (i.e. user) you get a Forbidden (as expected). But then if you go to xxx/app-jee or xxx/app-jsp it looks like you are logged in (page shows Logout and Account buttons). This is the case with keycloak-examples and keycloak-quickstarts. I suspect this is an issue with the example/quickstart app itself.

            boliveir_managed_kafka_security (inactive user) Bruno Oliveira Silva (Inactive)
            wdecoste1@redhat.com William Decoste (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: