Skip to content

[feat]: Config Keycloak OIDC client settings - #141

Merged
gcgoncalves merged 2 commits into
mainfrom
6913-sso-config
Sep 21, 2026
Merged

gcgoncalves merged 2 commits into
mainfrom
6913-sso-config

Conversation

@gcgoncalves

@gcgoncalves gcgoncalves commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

closes IBM/mcp-context-forge#6913

Adds BFF-side configuration for Keycloak SSO login, disabled by default. No routes or login flow yet — this is the config foundation the login/callback routes (Task 1.2+) will consume.

Changes

  • server/src/config.ts: 8 new SSO_* settings (ssoEnabled, Keycloak base URL + optional public base URL, realm, client id/secret, scopes, login-state TTL), following the existing optional/optionalUnset pattern.
  • Fail-closed startup check: SSO_ENABLED=true without all required Keycloak vars throws at boot, naming the missing var(s) — mirrors the existing COOKIE_SECURE check.
  • .env.example / .env.prod.example: documented the new vars.
  • server/test/config.test.ts: covers default-off boot, one case per missing required var, a fully-configured boot, and login-state TTL validation.

Why

First slice of the Keycloak SSO plan (agent-output/sso-keycloak-plan.md, Phase 1). The BFF will act as its own independent OIDC/PKCE client of Keycloak — ContextForge's own /auth/sso/* flow redirects to its own admin UI and isn't usable cross-origin from this SPA. Landing config first, gated behind SSO_ENABLED=false, keeps this a no-op for existing deployments.

@gcgoncalves
gcgoncalves force-pushed the 6913-sso-config branch 2 times, most recently from 9e3c4f2 to ca8af45 Compare September 21, 2026 10:20
Signed-off-by: Gabriel Costa <gabrielcg@proton.me>
@gcgoncalves gcgoncalves changed the title 6913 - Config Keycloak OIDC client settings [feat]: Config Keycloak OIDC client settings Sep 21, 2026

@vishu-bh vishu-bh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code looks good and well scoped just some minor things nothing blocking

Comment thread server/src/config.ts Outdated
] as const) {
if (!value) continue; // public base URL is optional
try {
new URL(value);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

new URL(value) validates syntax but accepts unsafe or unsupported schemes such as http:, file:, ftp:, javascript:, and data:. Once SSO routes consume this config, an HTTP browser-facing URL could expose credentials and authorization codes to network interception, while non-HTTP(S) schemes may cause unsafe redirects or runtime failures.

Can we use https: for the browser-facing URL, allowing http: only for explicit loopback development, and allowlist only http:/https: for the internal URL.

Comment thread .env.prod.example Outdated
LOG_LEVEL=info

# Keycloak SSO login. Leave SSO_ENABLED=false to skip -- otherwise every
# SSO_KEYCLOAK_* var below except SCOPES/TTL is required.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we add this bit as well

# Keycloak SSO login. Leave SSO_ENABLED=false to skip. When enabled,
# BASE_URL, REALM, CLIENT_ID, and CLIENT_SECRET are required.
# PUBLIC_BASE_URL is optional; SCOPES and TTL have defaults.

Signed-off-by: Gabriel Costa <gabrielcg@proton.me>

@vishu-bh vishu-bh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@gcgoncalves
gcgoncalves merged commit f335cd2 into main Sep 21, 2026
5 checks passed
@gcgoncalves
gcgoncalves deleted the 6913-sso-config branch September 21, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Config: Keycloak OIDC client settings

2 participants