keycloak-hs

[ bsd3, library, program, unclassified ] [ Propose Tags ]

Please see the README on GitHub at https://github.com/cdupont/keycloak-hs#readme


[Skip to Readme]

Modules

[Last Documentation]

  • Keycloak
    • Keycloak.Authorizations
    • Keycloak.Tokens
    • Keycloak.Types
    • Keycloak.Users
    • Keycloak.Utils

Downloads

Maintainer's Corner

Package maintainers

For package maintainers and hackage trustees

Candidates

Versions [RSS] 0.0.0.0, 0.0.0.1, 0.0.0.2, 0.0.0.3, 0.0.0.4, 0.0.0.5, 0.1.0.0, 0.1.1, 0.2.0, 1.0.0, 1.0.1, 1.1.0, 1.1.1, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.1.0, 3.0.0, 3.0.1, 3.0.2
Change log ChangeLog.md
Dependencies aeson (>=1.4 && <1.5), aeson-casing (>=0.1 && <0.3), base (>=4.9.1.0 && <5), base64-bytestring (>=1.0 && <1.1), bytestring (>=0.10 && <0.11), containers (>=0.5.9 && <0.7), exceptions (>=0.10 && <0.11), hashable, hslogger (>=1.2 && <1.4), http-api-data (>=0.4 && <0.5), http-client (>=0.5 && <0.7), http-types (>=0.12 && <0.13), jose, keycloak-hs, lens (>=4.17 && <4.19), lens-aeson, mtl (>=2.2 && <2.3), safe (>=0.3 && <0.4), string-conversions (>=0.4 && <0.5), text (>=1.2 && <1.3), unordered-containers, word8 (>=0.1 && <0.2), wreq (>=0.5 && <0.6) [details]
License BSD-3-Clause
Copyright 2019 Corentin Dupont
Author Corentin Dupont
Maintainer corentin.dupont@gmail.com
Home page https://github.com/cdupont/keycloak-hs#readme
Bug tracker https://github.com/cdupont/keycloak-hs/issues
Source repo head: git clone https://github.com/cdupont/keycloak-hs
Uploaded by CorentinDupont at 2020-10-28T13:39:55Z
Distributions
Executables example
Downloads 6391 total (62 in the last 30 days)
Rating (no votes yet) [estimated by Bayesian average]
Your Rating
  • λ
  • λ
  • λ
Status Docs not available [build log]
All reported builds failed as of 2020-10-28 [all 3 reports]

Readme for keycloak-hs-2.0.0

[back to package description]

Keycloak-hs

Keycloak-hs is an Haskell library for connecting to Keycloak. Keycloak allows to authenticate users and protect API resources. This library allows you to retrieve and analyse Keycloak authentication tokens, and to protect resources in your API.

Install

Installation follows the standard approach to installing Stack-based projects.

  1. Install the Haskell stack tool.
  2. Run stack install --fast to install this package.

Tutorial

In this tutorial we'll learn how to use Keycloak-hs with a small example. First you should install and run Keycloak: follow this tutorial.

Authentication

Authentication with Keycloak is based on JWTs.

In Keycloak admin panel, create the following:

  • a realm named "demo"
  • a client named "demo".
  • a user "demo" with password "demo"

In the user, add an attribute, such as "phone". In order for this attribute to appear in the token claims, we should also add a client "mapper". In the client "demo", click on "Mappers"/"add mappers". Fill the name="demo", Mapper Type=User attribute, Token Claim Name="demo", Claim JSON Type=String, and save.

At this point, you should be able to retrieve tokens from Keycloak, verify them using this library, and extract a User from the tokens.

Authorizations

In the client "demo":

  • change "Access Type" to confidential
  • turn "Authorization Enabled" ON.

A new "Authorization" tab should appear.

Let's set up some authorization policies in order to demonstrate the capacity of Keycloak-hs. We want to authorize our user "demo" to "view" any resource. First go in the new "Authorization" tab that appeared. Flip ON "Remote Resource Management".

Create a new Scope in the "Authorization Scopes" tab:

  • Name it "view".

Create a new "User" policy in the "Policies" tab with the following settings:

  • Name it "Demo user have access".
  • Select user "demo" in the drop box.
  • Logic should be positive.

Create a new scope-based permission in the "Permissions" tab:

  • Name it "View resources".
  • Select "view" in Scopes.
  • Select your previous policy "Demo user have access" in "Apply Policy".

That's it for the confguration of Keycloak. Keycloak is very complex, so you'll have fun exploring all the possibilities ;)

Example code

The folder example contains an exemple of usage. You should first input your "client secret", that can be found in the demo client "Credentials" tab in Keycloak admin panel.

Then run the example:

stack run example

The example first create a "client" token, necessary to create a resource in Keycloak. It then create a Resourse, with a name, an optional type, URIs, scopes, owner and attributes.

We can then check if our user can access this resource, according to policies. Finally, the example shows how to retrieve all permissions for a user.

Enjoy!