From c0f8afcbe22b168a97f13af69f3b4d2a0bc94200 Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 19:52:41 +0200 Subject: [PATCH] docs: correct the Keycloak client redirect URIs in the setup guide The client needs redirect URIs for the landing and instance hosts only. The two settings the guide showed as a bare `+`, and therefore never described, are required: Valid post logout redirect URIs https:/// https:///* Web origins https:// https://instance. The post-logout list needs both the bare `/` and the `/*` form. Every value carries the https:// scheme, and the web origins carry no path suffix. Also replaces the pre-restructure hostnames throughout: the worked examples were still `test1.theia-test.artemis.cit.tum.de` and `theia.artemis.cit.tum.de`, and now use test1's and tum-production's real landing hosts. Matches EduIDE/Docs#12. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_019qeiQRFu8xAMRYWPdZewjG --- docs/keycloak-setup.md | 65 +++++++++++++++++++++++++++++++----------- 1 file changed, 49 insertions(+), 16 deletions(-) diff --git a/docs/keycloak-setup.md b/docs/keycloak-setup.md index 24eb381..3b6cee6 100644 --- a/docs/keycloak-setup.md +++ b/docs/keycloak-setup.md @@ -50,28 +50,61 @@ Click **Next** Configure these URLs based on your environment domain: -For test environments (e.g., `test1.theia-test.artemis.cit.tum.de`): +Four settings, derived from the environment's **landing host**. Every value +carries the `https://` scheme. + +``` +Root URL: https:// +Home URL: https:// +Valid redirect URIs: + https:///* + https://instance./* +Valid post logout redirect URIs: + https:/// + https:///* +Web origins: + https:// + https://instance. +``` + +The post-logout entries need **both** forms, the bare `/` and the `/*`. + +For `test1`, whose landing host is `test1.eduide.student.k8s.aet.cit.tum.de`: + ``` -Root URL: https://test1.theia-test.artemis.cit.tum.de -Home URL: https://test1.theia-test.artemis.cit.tum.de Valid redirect URIs: - - https://test1.theia-test.artemis.cit.tum.de/* - - https://instance.test1.theia-test.artemis.cit.tum.de/* -Valid post logout redirect URIs: + -Web origins: + + https://test1.eduide.student.k8s.aet.cit.tum.de/* + https://instance.test1.eduide.student.k8s.aet.cit.tum.de/* +Valid post logout redirect URIs: + https://test1.eduide.student.k8s.aet.cit.tum.de/ + https://test1.eduide.student.k8s.aet.cit.tum.de/* +Web origins: + https://test1.eduide.student.k8s.aet.cit.tum.de + https://instance.test1.eduide.student.k8s.aet.cit.tum.de ``` -For production: +and for `tum-production`, whose landing host is `eduide.artemis.aet.cit.tum.de`: + ``` -Root URL: https://theia.artemis.cit.tum.de -Home URL: https://theia.artemis.cit.tum.de Valid redirect URIs: - - https://theia.artemis.cit.tum.de/* - - https://instance.theia.artemis.cit.tum.de/* -Valid post logout redirect URIs: + -Web origins: + + https://eduide.artemis.aet.cit.tum.de/* + https://instance.eduide.artemis.aet.cit.tum.de/* +Valid post logout redirect URIs: + https://eduide.artemis.aet.cit.tum.de/ + https://eduide.artemis.aet.cit.tum.de/* +Web origins: + https://eduide.artemis.aet.cit.tum.de + https://instance.eduide.artemis.aet.cit.tum.de ``` +> **The service and webview hosts are deliberately absent.** An installation +> serves four hostnames, but only the landing and instance hosts take part in +> the browser redirect flow. Four is the right number for DNS and for +> certificates; the Keycloak client names two. Do not pad this list out. + +Landing hosts for every environment are listed in +[environments.md](environments.md). + Click **Save** @@ -190,7 +223,7 @@ After deploying with Keycloak configuration: ### Access the Landing Page -1. Navigate to your environment URL (e.g., `https://test1.theia-test.artemis.cit.tum.de`) +1. Navigate to your environment URL (e.g., `https://test1.eduide.student.k8s.aet.cit.tum.de`) 2. You should be redirected to Keycloak login page 3. Log in with valid credentials @@ -222,7 +255,7 @@ After successful login, you can verify that user information is correctly passed **Solutions:** - Verify all redirect URIs are correctly configured in Keycloak -- Check that wildcard redirect URIs include `/*` suffix +- Check the redirect URIs end in `/*`, that the post logout list has both `https:///` and `https:///*`, and that the web origins carry no path suffix at all - Ensure cookie secret is correctly base64-encoded - Verify all URLs use HTTPS