Skip to content

Commit b4aa2c2

Browse files
committed
Add README for keycloak auth flow
1 parent 22f4727 commit b4aa2c2

1 file changed

Lines changed: 25 additions & 0 deletions

File tree

‎dev/keycloak/README.md‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
# Keycloak Testing for NABat Integration
2+
3+
The integration with the NABat platform requires some trickier auth to test fully. This directory contains some helpful tools for local development testing.
4+
5+
## Running with a local Keycloak server
6+
7+
In the top-level directory of the repository there is a docker compose file that can be used in conjunction with whichever docker compose files you already use for development. This means that you only need to spin up a local KC service when required. To chain docker compose files, simply use the `-f` flag multiple times. For example, with local development:
8+
9+
```bash
10+
docker compose -f docker-compose.yml -f docker-compose-keycloak.yml up
11+
```
12+
13+
## Keycloak Configuration
14+
15+
Keycloak configuration is defined in [NABAT-realm.json](./NABAT-realm.json). It sets up 2 clients: a proxy "NABat" and a client for the locally running BatAI application. It also sets up a test user (this would be the analog to your account with NABat). The username and password for this user are both `testuser`.
16+
17+
## Testing Local Keycloak Flow
18+
19+
Once your keycloak service is running alongside BatAI, you can simulate the keycloak login/token exchange workflow, start by running [./print-nabat-auth-url.sh](./print-nabat-auth-url.sh) to generate a URL.
20+
21+
Paste the URL into your browser, and if this is the first time you're going through the workflow or KC doesn't have an active token for `testuser` you'll need to log in as `testuser`. This will redirect to your local BatAI application and begin the login flow.
22+
23+
To verify this authentication flow works correctly, look at your server's logs. You should see a `200` response from the `/nabat/authorize` endpoint.
24+
25+
Since we don't actually have a proxied NABat application to run locally, this is about as far as we can go at the moment.

0 commit comments

Comments
 (0)