spring-security-workshop
spring-security-workshop copied to clipboard
Change Keycloak JWT to include "groups" attribute with valid roles
Instead of using the nested structure of realm_access/realm_roles we can introduce a new "groups" attribute of type string array.
{... "groups": ["HR"] .. }
We can do this with client scopes or protocol mappers on the client.