Problem
deploy/keycloak/keycloak-init-values.yaml defines every client scope eSignet enforces except get_oidc_client. It's neither created nor assigned to mosip-pms-client, so on a fresh install no token can satisfy GET /client-mgmt/client/{client_id} — always HTTP 403.
Present on develop-go, release-2.0.x and master (grep -c get_oidc_client → 0 on all three).
Evidence
eSignet enforces the scope — esignet-service/data/deployment.yaml:178-180:
- endpoint: "/client-mgmt/client/{client_id}"
method: GET
scope: get_oidc_client
But keycloak-init-values.yaml declares only:
add_oidc_client, update_oidc_client, get_certificate,
upload_certificate, send_binding_otp, wallet_binding
and assigns only these to mosip-pms-client:
assign_client_scopes:
- update_oidc_client
- add_oidc_client
- get_certificate
- upload_certificate
get_oidc_client is in neither list. Every other enforced scope has a Keycloak counterpart — this is the only one that doesn't.
Confirmed live. A client_credentials token for mosip-pms-client returns:
scope: profile email add_oidc_client upload_certificate update_oidc_client get_certificate
and the call fails:
{"errors":[{"errorCode":"forbidden",
"errorMessage":"token must carry scope \"get_oidc_client\""}]}
Impact
The GET endpoint is blocked out of the box — no operator configuration fixes it short of editing Keycloak by hand. In the api-test harness this alone causes 19 client-mgmt failures + 4 e2e scenarios that read a client back after a status patch.
Fix
Two additions to deploy/keycloak/keycloak-init-values.yaml, mirroring the existing entries:
1. Declare the scope under keycloak.realms.mosip.client_scopes:
- name: get_oidc_client
description: Scope required to get OIDC client
protocol: openid-connect
"Include In Token Scope": on
attributes: {
display.on.consent.screen: "false",
include.in.token.scope: "true"
}
2. Assign it to mosip-pms-client under assign_client_scopes:
Problem
deploy/keycloak/keycloak-init-values.yamldefines every client scope eSignet enforces exceptget_oidc_client. It's neither created nor assigned tomosip-pms-client, so on a fresh install no token can satisfyGET /client-mgmt/client/{client_id}— always HTTP 403.Present on
develop-go,release-2.0.xandmaster(grep -c get_oidc_client→ 0 on all three).Evidence
eSignet enforces the scope —
esignet-service/data/deployment.yaml:178-180:But
keycloak-init-values.yamldeclares only:and assigns only these to
mosip-pms-client:get_oidc_clientis in neither list. Every other enforced scope has a Keycloak counterpart — this is the only one that doesn't.Confirmed live. A
client_credentialstoken formosip-pms-clientreturns:and the call fails:
{"errors":[{"errorCode":"forbidden", "errorMessage":"token must carry scope \"get_oidc_client\""}]}Impact
The GET endpoint is blocked out of the box — no operator configuration fixes it short of editing Keycloak by hand. In the api-test harness this alone causes 19 client-mgmt failures + 4 e2e scenarios that read a client back after a status patch.
Fix
Two additions to
deploy/keycloak/keycloak-init-values.yaml, mirroring the existing entries:1. Declare the scope under
keycloak.realms.mosip.client_scopes:2. Assign it to
mosip-pms-clientunderassign_client_scopes:- get_oidc_client