-
Notifications
You must be signed in to change notification settings - Fork 0
docs: correct the Keycloak client redirect URIs in the setup guide #119
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -50,28 +50,61 @@ Click **Next** | |
|
|
||
| Configure these URLs based on your environment domain: | ||
|
|
||
| For test environments (e.g., `test1.theia-test.artemis.cit.tum.de`): | ||
| Four settings, derived from the environment's **landing host**. Every value | ||
| carries the `https://` scheme. | ||
|
|
||
| ``` | ||
| Root URL: https://<landing-host> | ||
| Home URL: https://<landing-host> | ||
| Valid redirect URIs: | ||
| https://<landing-host>/* | ||
| https://instance.<landing-host>/* | ||
| Valid post logout redirect URIs: | ||
| https://<landing-host>/ | ||
| https://<landing-host>/* | ||
| Web origins: | ||
| https://<landing-host> | ||
| https://instance.<landing-host> | ||
| ``` | ||
|
Comment on lines
+53
to
+68
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win Correct the URL setting count. This block lists five Keycloak settings: 🧰 Tools🪛 markdownlint-cli2 (0.23.2)[warning] 56-56: Fenced code blocks should have a language specified (MD040, fenced-code-language) 🤖 Prompt for AI Agents |
||
|
|
||
| The post-logout entries need **both** forms, the bare `/` and the `/*`. | ||
|
|
||
| For `test1`, whose landing host is `test1.eduide.student.k8s.aet.cit.tum.de`: | ||
|
|
||
| ``` | ||
| Root URL: https://test1.theia-test.artemis.cit.tum.de | ||
| Home URL: https://test1.theia-test.artemis.cit.tum.de | ||
| Valid redirect URIs: | ||
| - https://test1.theia-test.artemis.cit.tum.de/* | ||
| - https://instance.test1.theia-test.artemis.cit.tum.de/* | ||
| Valid post logout redirect URIs: + | ||
| Web origins: + | ||
| https://test1.eduide.student.k8s.aet.cit.tum.de/* | ||
| https://instance.test1.eduide.student.k8s.aet.cit.tum.de/* | ||
| Valid post logout redirect URIs: | ||
| https://test1.eduide.student.k8s.aet.cit.tum.de/ | ||
| https://test1.eduide.student.k8s.aet.cit.tum.de/* | ||
| Web origins: | ||
| https://test1.eduide.student.k8s.aet.cit.tum.de | ||
| https://instance.test1.eduide.student.k8s.aet.cit.tum.de | ||
| ``` | ||
|
|
||
| For production: | ||
| and for `tum-production`, whose landing host is `eduide.artemis.aet.cit.tum.de`: | ||
|
|
||
| ``` | ||
| Root URL: https://theia.artemis.cit.tum.de | ||
| Home URL: https://theia.artemis.cit.tum.de | ||
| Valid redirect URIs: | ||
| - https://theia.artemis.cit.tum.de/* | ||
| - https://instance.theia.artemis.cit.tum.de/* | ||
| Valid post logout redirect URIs: + | ||
| Web origins: + | ||
| https://eduide.artemis.aet.cit.tum.de/* | ||
| https://instance.eduide.artemis.aet.cit.tum.de/* | ||
| Valid post logout redirect URIs: | ||
| https://eduide.artemis.aet.cit.tum.de/ | ||
| https://eduide.artemis.aet.cit.tum.de/* | ||
| Web origins: | ||
| https://eduide.artemis.aet.cit.tum.de | ||
| https://instance.eduide.artemis.aet.cit.tum.de | ||
| ``` | ||
|
|
||
| > **The service and webview hosts are deliberately absent.** An installation | ||
| > serves four hostnames, but only the landing and instance hosts take part in | ||
| > the browser redirect flow. Four is the right number for DNS and for | ||
| > certificates; the Keycloak client names two. Do not pad this list out. | ||
|
|
||
| Landing hosts for every environment are listed in | ||
| [environments.md](environments.md). | ||
|
|
||
| Click **Save** | ||
|
|
||
|
|
||
|
|
@@ -190,7 +223,7 @@ After deploying with Keycloak configuration: | |
|
|
||
| ### Access the Landing Page | ||
|
|
||
| 1. Navigate to your environment URL (e.g., `https://test1.theia-test.artemis.cit.tum.de`) | ||
| 1. Navigate to your environment URL (e.g., `https://test1.eduide.student.k8s.aet.cit.tum.de`) | ||
| 2. You should be redirected to Keycloak login page | ||
| 3. Log in with valid credentials | ||
|
|
||
|
|
@@ -222,7 +255,7 @@ After successful login, you can verify that user information is correctly passed | |
|
|
||
| **Solutions:** | ||
| - Verify all redirect URIs are correctly configured in Keycloak | ||
| - Check that wildcard redirect URIs include `/*` suffix | ||
| - Check the redirect URIs end in `/*`, that the post logout list has both `https://<landing-host>/` and `https://<landing-host>/*`, and that the web origins carry no path suffix at all | ||
| - Ensure cookie secret is correctly base64-encoded | ||
| - Verify all URLs use HTTPS | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Add language identifiers to the fenced examples.
The three fenced code blocks omit language identifiers. Add
textor another suitable identifier after each opening fence to satisfy markdownlint MD040.Also applies to: 74-74, 88-88
🧰 Tools
🪛 markdownlint-cli2 (0.23.2)
[warning] 56-56: Fenced code blocks should have a language specified
(MD040, fenced-code-language)
🤖 Prompt for AI Agents
Source: Linters/SAST tools