Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions core/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,10 @@
<groupId>org.eclipse.microprofile.openapi</groupId>
<artifactId>microprofile-openapi-api</artifactId>
</dependency>
<dependency>
<groupId>org.hibernate.validator</groupId>
<artifactId>hibernate-validator</artifactId>
</dependency>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,11 @@
import com.fasterxml.jackson.annotation.JsonInclude;
import com.fasterxml.jackson.annotation.JsonProperty;
import com.fasterxml.jackson.annotation.JsonPropertyDescription;
import com.fasterxml.jackson.core.JsonProcessingException;
import com.fasterxml.jackson.databind.ObjectMapper;
import jakarta.validation.Valid;
import jakarta.validation.constraints.NotBlank;
import jakarta.validation.constraints.NotNull;
import org.hibernate.validator.constraints.URL;
import org.keycloak.representations.admin.v2.validation.CreateClient;

import java.util.LinkedHashSet;
import java.util.Set;
Expand All @@ -13,6 +16,7 @@ public class ClientRepresentation extends BaseRepresentation {

public static final String OIDC = "openid-connect";

@NotBlank(groups = CreateClient.class)
@JsonPropertyDescription("ID uniquely identifying this client")
private String clientId;

Expand All @@ -29,28 +33,31 @@ public class ClientRepresentation extends BaseRepresentation {
@JsonPropertyDescription("Whether this client is enabled")
private Boolean enabled;

@URL
@JsonPropertyDescription("URL to the application's homepage that is represented by this client")
private String appUrl;

@JsonInclude(JsonInclude.Include.NON_EMPTY)
@JsonPropertyDescription("URLs that the browser can redirect to after login")
private Set<String> appRedirectUrls = new LinkedHashSet<String>();
private Set<@NotBlank @URL(message = "Each redirect URL must be valid") String> appRedirectUrls = new LinkedHashSet<String>();

@JsonInclude(JsonInclude.Include.NON_EMPTY)
@JsonPropertyDescription("Login flows that are enabled for this client")
private Set<String> loginFlows = new LinkedHashSet<String>();
private Set<@NotBlank String> loginFlows = new LinkedHashSet<String>();

@Valid
@JsonPropertyDescription("Authentication configuration for this client")
private Auth auth;

@JsonInclude(JsonInclude.Include.NON_EMPTY)
@JsonPropertyDescription("Web origins that are allowed to make requests to this client")
private Set<String> webOrigins = new LinkedHashSet<String>();
private Set<@NotBlank String> webOrigins = new LinkedHashSet<String>();

@JsonInclude(JsonInclude.Include.NON_EMPTY)
@JsonPropertyDescription("Roles associated with this client")
private Set<String> roles = new LinkedHashSet<String>();
private Set<@NotBlank String> roles = new LinkedHashSet<String>();

@Valid
@JsonInclude(JsonInclude.Include.NON_EMPTY)
@JsonPropertyDescription("Service account configuration for this client")
private ServiceAccount serviceAccount;
Expand Down Expand Up @@ -160,6 +167,7 @@ public void setServiceAccount(ServiceAccount serviceAccount) {
@JsonInclude(JsonInclude.Include.NON_ABSENT)
public static class Auth {

@NotNull
@JsonPropertyDescription("Whether authentication is enabled for this client")
private Boolean enabled;

Expand Down Expand Up @@ -208,6 +216,7 @@ public void setCertificate(String certificate) {
@JsonInclude(JsonInclude.Include.NON_ABSENT)
public static class ServiceAccount {

@NotNull
@JsonPropertyDescription("Whether the service account is enabled")
private Boolean enabled;

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
package org.keycloak.representations.admin.v2.validation;

// Jakarta Validation Group - validation is done only when creating a client
public interface CreateClient {
}
17 changes: 17 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,8 @@
<h2.version>2.3.230</h2.version>
<hibernate-orm.plugin.version>6.2.13.Final</hibernate-orm.plugin.version>
<hibernate.c3p0.version>6.2.13.Final</hibernate.c3p0.version>
<hibernate-validator.version>9.0.1.Final</hibernate-validator.version>
<expressly.version>6.0.0</expressly.version>
<infinispan.version>15.0.18.Final</infinispan.version>
<protostream.version>5.0.14.Final</protostream.version> <!-- For the annotation processor: keep in sync with the version shipped with Infinispan -->
<protostream.plugin.version>${protostream.version}</protostream.plugin.version>
Expand Down Expand Up @@ -579,6 +581,21 @@
<artifactId>h2</artifactId>
<version>${h2.version}</version>
</dependency>
<dependency>
<groupId>org.hibernate.validator</groupId>
<artifactId>hibernate-validator</artifactId>
<version>${hibernate-validator.version}</version>
</dependency>
<dependency>
<groupId>org.hibernate.validator</groupId>
<artifactId>hibernate-validator-cdi</artifactId>
<version>${hibernate-validator.version}</version>
</dependency>
<dependency>
<groupId>org.glassfish.expressly</groupId>
<artifactId>expressly</artifactId>
<version>${expressly.version}</version>
</dependency>
<dependency>
<groupId>org.hibernate.orm</groupId>
<artifactId>hibernate-c3p0</artifactId>
Expand Down
4 changes: 4 additions & 0 deletions quarkus/deployment/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,10 @@
<groupId>io.quarkus</groupId>
<artifactId>quarkus-rest-jackson-deployment</artifactId>
</dependency>
<dependency>
<groupId>io.quarkus</groupId>
<artifactId>quarkus-hibernate-validator-deployment</artifactId>
</dependency>
<dependency>
<groupId>io.quarkus</groupId>
<artifactId>quarkus-hibernate-orm-deployment</artifactId>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,7 @@
import org.keycloak.userprofile.config.UPConfigUtils;
import org.keycloak.util.JsonSerialization;
import org.keycloak.utils.StringUtil;
import org.keycloak.validation.jakarta.HibernateValidatorProviderFactory;
import org.keycloak.vault.FilesKeystoreVaultProviderFactory;
import org.keycloak.vault.FilesPlainTextVaultProviderFactory;

Expand Down Expand Up @@ -189,6 +190,7 @@ class KeycloakProcessor {
JBossJtaTransactionManagerLookup.class,
DefaultJpaConnectionProviderFactory.class,
DefaultLiquibaseConnectionProvider.class,
//HibernateValidatorProviderFactory.class,
FolderThemeProviderFactory.class,
LiquibaseJpaUpdaterProviderFactory.class,
FilesKeystoreVaultProviderFactory.class,
Expand Down
6 changes: 6 additions & 0 deletions quarkus/runtime/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,12 @@
<artifactId>mapstruct</artifactId>
</dependency>

<!-- Hibernate validator -->
<dependency>
<groupId>io.quarkus</groupId>
<artifactId>quarkus-hibernate-validator</artifactId>
</dependency>

<!-- SmallRye -->
<dependency>
<groupId>io.smallrye.config</groupId>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,11 +1,13 @@
package org.keycloak.admin.api.client;

import jakarta.validation.Valid;
import jakarta.ws.rs.Consumes;
import jakarta.ws.rs.GET;
import jakarta.ws.rs.PATCH;
import jakarta.ws.rs.PUT;
import jakarta.ws.rs.PathParam;
import jakarta.ws.rs.Produces;
import jakarta.ws.rs.QueryParam;
import jakarta.ws.rs.core.MediaType;

import org.keycloak.admin.api.FieldValidation;
Expand All @@ -25,11 +27,12 @@ public interface ClientApi {
@PUT
@Consumes(MediaType.APPLICATION_JSON)
@Produces(MediaType.APPLICATION_JSON)
ClientRepresentation createOrUpdateClient(ClientRepresentation client, @PathParam("fieldValidation") FieldValidation fieldValidation);
ClientRepresentation createOrUpdateClient(@Valid ClientRepresentation client,
@QueryParam("fieldValidation") FieldValidation fieldValidation);

@PATCH
@Consumes({MediaType.APPLICATION_JSON_PATCH_JSON, CONENT_TYPE_MERGE_PATCH})
@Produces(MediaType.APPLICATION_JSON)
ClientRepresentation patchClient(JsonNode patch, @PathParam("fieldValidation") FieldValidation fieldValidation);
ClientRepresentation patchClient(JsonNode patch, @QueryParam("fieldValidation") FieldValidation fieldValidation);

}
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,9 @@

import java.util.stream.Stream;

import jakarta.validation.Valid;
import jakarta.validation.groups.ConvertGroup;
import jakarta.ws.rs.QueryParam;
import org.keycloak.admin.api.FieldValidation;
import org.keycloak.provider.Provider;
import org.keycloak.representations.admin.v2.ClientRepresentation;
Expand All @@ -13,6 +16,7 @@
import jakarta.ws.rs.PathParam;
import jakarta.ws.rs.Produces;
import jakarta.ws.rs.core.MediaType;
import org.keycloak.representations.admin.v2.validation.CreateClient;

public interface ClientsApi extends Provider {

Expand All @@ -24,7 +28,8 @@ public interface ClientsApi extends Provider {
@POST
@Consumes(MediaType.APPLICATION_JSON)
@Produces(MediaType.APPLICATION_JSON)
ClientRepresentation createClient(ClientRepresentation client, @PathParam("fieldValidation") FieldValidation fieldValidation);
ClientRepresentation createClient(@Valid @ConvertGroup(to = CreateClient.class) ClientRepresentation client,
@QueryParam("fieldValidation") FieldValidation fieldValidation);

@Path("{id}")
ClientApi client(@PathParam("id") String id);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,14 @@

import java.util.stream.Stream;

import jakarta.validation.Valid;
import jakarta.validation.groups.ConvertGroup;
import org.keycloak.admin.api.FieldValidation;
import org.keycloak.http.HttpResponse;
import org.keycloak.models.KeycloakSession;
import org.keycloak.models.RealmModel;
import org.keycloak.representations.admin.v2.ClientRepresentation;
import org.keycloak.representations.admin.v2.validation.CreateClient;
import org.keycloak.services.ServiceException;
import org.keycloak.services.client.ClientService;

Expand Down Expand Up @@ -35,7 +38,8 @@ public Stream<ClientRepresentation> getClients() {
}

@Override
public ClientRepresentation createClient(ClientRepresentation client, FieldValidation fieldValidation) {
public ClientRepresentation createClient(@Valid @ConvertGroup(to = CreateClient.class) ClientRepresentation client,
FieldValidation fieldValidation) {
try {
response.setStatus(Response.Status.CREATED.getStatusCode());
return clientService.createOrUpdate(realm, client, false).representation();
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
package org.keycloak.validation.jakarta;

import jakarta.validation.Validator;
import org.keycloak.provider.Provider;

public interface JakartaValidatorProvider extends Provider {

Validator getValidator();
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
package org.keycloak.validation.jakarta;

import org.keycloak.provider.ProviderFactory;

public interface JakartaValidatorProviderFactory extends ProviderFactory<JakartaValidatorProvider> {
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
package org.keycloak.validation.jakarta;

import org.keycloak.provider.Provider;
import org.keycloak.provider.ProviderFactory;
import org.keycloak.provider.Spi;

public class JakartaValidatorSpi implements Spi {
@Override
public boolean isInternal() {
return true;
}

@Override
public String getName() {
return "jakarta-validator";
}

@Override
public Class<? extends Provider> getProviderClass() {
return JakartaValidatorProvider.class;
}

@Override
public Class<? extends ProviderFactory<?>> getProviderFactoryClass() {
return JakartaValidatorProviderFactory.class;
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -107,4 +107,5 @@ org.keycloak.securityprofile.SecurityProfileSpi
org.keycloak.logging.MappedDiagnosticContextSpi
org.keycloak.services.KeycloakServicesSpi
org.keycloak.services.client.ClientServiceSpi
org.keycloak.models.mapper.ModelMapperSpi
org.keycloak.models.mapper.ModelMapperSpi
org.keycloak.validation.jakarta.JakartaValidatorSpi
Original file line number Diff line number Diff line change
Expand Up @@ -10,22 +10,22 @@

public interface ClientService extends Service {

public static class ClientSearchOptions {
class ClientSearchOptions {
// TODO
}

public static class ClientProjectionOptions {
class ClientProjectionOptions {
// TODO
}

public static class ClientSortAndSliceOptions {
class ClientSortAndSliceOptions {
// order by
// offset
// limit
// NOTE: this is not always the most desirable way to do pagination
}

public record CreateOrUpdateResult(ClientRepresentation representation, boolean created) {}
record CreateOrUpdateResult(ClientRepresentation representation, boolean created) {}

Optional<ClientRepresentation> getClient(RealmModel realm, String clientId, ClientProjectionOptions projectionOptions);

Expand Down
10 changes: 10 additions & 0 deletions services/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,16 @@
<artifactId>mapstruct</artifactId>
<version>${org.mapstruct.version}</version>
</dependency>
<dependency>
<groupId>org.hibernate.validator</groupId>
<artifactId>hibernate-validator-cdi</artifactId>
<version>${hibernate-validator.version}</version> <!--Not sure why we need to set it as it should be part of dependencyManagement-->
</dependency>
<dependency>
<groupId>org.glassfish.expressly</groupId>
<artifactId>expressly</artifactId>
<version>${expressly.version}</version>
</dependency>
<dependency>
<groupId>org.jboss.logging</groupId>
<artifactId>jboss-logging</artifactId>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,14 +1,23 @@
package org.keycloak.services.client;

import jakarta.enterprise.inject.spi.CDI;
import jakarta.inject.Inject;
import jakarta.validation.Validation;
import jakarta.validation.Validator;
import jakarta.validation.ValidatorFactory;
import jakarta.ws.rs.core.Response;

import org.hibernate.validator.HibernateValidator;
import org.hibernate.validator.HibernateValidatorFactory;
import org.keycloak.models.ClientModel;
import org.keycloak.models.KeycloakSession;
import org.keycloak.models.RealmModel;
import org.keycloak.models.mapper.ClientModelMapper;
import org.keycloak.models.mapper.ModelMapper;
import org.keycloak.representations.admin.v2.ClientRepresentation;
import org.keycloak.representations.admin.v2.validation.CreateClient;
import org.keycloak.services.ServiceException;
import org.keycloak.validation.jakarta.HibernateValidatorProvider;
import org.keycloak.validation.jakarta.JakartaValidatorProvider;

import java.util.Optional;
import java.util.stream.Stream;
Expand All @@ -17,10 +26,12 @@
public class DefaultClientService implements ClientService {
private final KeycloakSession session;
private final ClientModelMapper mapper;
private final Validator validator;

public DefaultClientService(KeycloakSession session) {
this.session = session;
this.mapper = session.getProvider(ModelMapper.class).clients();
this.validator = session.getProvider(JakartaValidatorProvider.class).getValidator();
}

@Override
Expand All @@ -45,6 +56,7 @@ public CreateOrUpdateResult createOrUpdate(RealmModel realm, ClientRepresentatio
throw new ServiceException("Client already exists", Response.Status.CONFLICT);
}
} else {
validator.validate(client, CreateClient.class); // TODO improve it to avoid second validation when we know it is create and not update
model = realm.addClient(client.getClientId());
created = true;
}
Expand Down
Loading
Loading