[feat]: Config Keycloak OIDC client settings - #141
Merged
Merged
Conversation
gcgoncalves
force-pushed
the
6913-sso-config
branch
2 times, most recently
from
September 21, 2026 10:20
9e3c4f2 to
ca8af45
Compare
Signed-off-by: Gabriel Costa <gabrielcg@proton.me>
gcgoncalves
force-pushed
the
6913-sso-config
branch
from
September 21, 2026 10:34
ca8af45 to
0db8c4b
Compare
vishu-bh
requested changes
Sep 21, 2026
vishu-bh
left a comment
Contributor
There was a problem hiding this comment.
Code looks good and well scoped just some minor things nothing blocking
| ] as const) { | ||
| if (!value) continue; // public base URL is optional | ||
| try { | ||
| new URL(value); |
Contributor
There was a problem hiding this comment.
new URL(value) validates syntax but accepts unsafe or unsupported schemes such as http:, file:, ftp:, javascript:, and data:. Once SSO routes consume this config, an HTTP browser-facing URL could expose credentials and authorization codes to network interception, while non-HTTP(S) schemes may cause unsafe redirects or runtime failures.
Can we use https: for the browser-facing URL, allowing http: only for explicit loopback development, and allowlist only http:/https: for the internal URL.
| LOG_LEVEL=info | ||
|
|
||
| # Keycloak SSO login. Leave SSO_ENABLED=false to skip -- otherwise every | ||
| # SSO_KEYCLOAK_* var below except SCOPES/TTL is required. |
Contributor
There was a problem hiding this comment.
Can we add this bit as well
# Keycloak SSO login. Leave SSO_ENABLED=false to skip. When enabled,
# BASE_URL, REALM, CLIENT_ID, and CLIENT_SECRET are required.
# PUBLIC_BASE_URL is optional; SCOPES and TTL have defaults.
Signed-off-by: Gabriel Costa <gabrielcg@proton.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes IBM/mcp-context-forge#6913
Adds BFF-side configuration for Keycloak SSO login, disabled by default. No routes or login flow yet — this is the config foundation the login/callback routes (Task 1.2+) will consume.
Changes
Why
First slice of the Keycloak SSO plan (agent-output/sso-keycloak-plan.md, Phase 1). The BFF will act as its own independent OIDC/PKCE client of Keycloak — ContextForge's own /auth/sso/* flow redirects to its own admin UI and isn't usable cross-origin from this SPA. Landing config first, gated behind SSO_ENABLED=false, keeps this a no-op for existing deployments.