Login and token
How a person or a service gets a token, how it is renewed and ended, and what happens with the token on every request.
Topics in this subject area
- 1.Sign in in the browser
The path from “open page” to “signed in” via Keycloak with authorization code, with all variants of the login page.
- 2.Sign in as a service (client credentials)
How a server gets a token without a person, what this is meant for, and why user-owned models usually return nothing with it.
- 3.Session in the BFF and cookies
Why the token lives in the frontend's server and not in the browser, what the session cookie looks like, and why every portal has its own cookie prefix.
- 4.Renew the token
When and how the token is renewed before it expires, and what happens when a refresh is rejected or fails.
- 5.Sign out
How signing out deletes cookies, how Keycloak ends the session, and why the login page does not sign you in again right away.
- 6.What happens with the token on every request
The filter chain step by step: read the header, validate, exchange, read the identity, resolve the tenant, admit the tenant, build the roles, perform the switch, clean up.
- 7.Token exchange
Why CIAS exchanges every user token for one for its own client, how long the result is cached, and what happens with a misconfigured realm.
- 8.What is read from the token
Which claim goes where in the RequestContext: user, name, realm roles, business roles, organization, tenant, allowed tenants, attributes.
- 9.Effective roles: global or in the tenant
How CIAS builds the valid roles from global roles and roles of the organization, and why globally granted roles can drop away under a dynamic tenant.
- 10.Why revoking permissions takes effect with a delay
Revoked permissions stay in the token until it expires or the exchange cache runs out. How long this takes and how to block someone immediately.