Skip to content

feat(keycloak): opt-in trust_tenant_claim, resolver stays authoritative (#376) [stack 6/11] - #390

Merged
antosubash merged 7 commits into
tenancy/05-usersfrom
tenancy/06-keycloak
Oct 1, 2026
Merged

antosubash merged 7 commits into
tenancy/05-usersfrom
tenancy/06-keycloak

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #376. Stack 6/11 of the tenancy-adoption series (base: #389).

What

  • A new keycloak setting, trust_tenant_claim (SM_KEYCLOAK_TRUST_TENANT_CLAIM), default false and DB-backed. Only when it is true does the JWT tenant_id claim reach UserContext.tenant_id. A claim-only install with no resolver can still opt in deliberately.
  • The tenants resolver stays authoritative whatever the setting: a forged claim never wins (tested).
  • A new test pins keycloak's register_setup_steps opt-out.
  • Docs: docs/modules/keycloak.md has a settings row and a "Tenant claim" section.

Not covered (follow-up)

  • The _upsert_user_cache session-factory question, which the issue marks non-blocking.
  • An end-to-end "Keycloak-only install reaches /tenants" test. That behaviour is documented, not tested.

Tests

make test-py: 3374 passed. All 39 keycloak tests pass. make lint is clean.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

…aim is set (#376)

Adds SM_KEYCLOAK_TRUST_TENANT_CLAIM (default off). Tests cover the claim
ignored by default, honoured when enabled, never beating the tenants
resolver, and keycloak's setup-step opt-out. Documents the setting.

Claude-Session: https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: d6537f7
Status: ✅  Deploy successful!
Preview URL: https://a27f01a6.simple-module-python.pages.dev
Branch Preview URL: https://tenancy-06-keycloak.simple-module-python.pages.dev

View logs

…t roles (review of #376)

- A session's cached tenant_id is dropped unless trust_tenant_claim is on now;
  the provider reads settings through app.state.keycloak, so saves and the
  boot-time hydration take effect instead of the register_settings snapshot.
- A trusted claim must pass is_valid_tenant_id, else it is ignored.
- tenant:* roles produced by role_mapping (or cached in old sessions) are
  stripped, with one warning per offending role.

Claude-Session: https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV
@antosubash
antosubash added this pull request to stack #397 October 1, 2026 16:14
@antosubash
antosubash marked this pull request as ready for review October 1, 2026 16:16
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T16:20:19.997348Z d6537f7 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@antosubash
antosubash merged commit 5f713a0 into main Oct 1, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

keycloak: stop hard-coding UserContext.tenant_id from the tenant_id JWT claim, and check register_setup_steps opt-out still holds

1 participant