Skip to content

[Bug] keycloak-init never creates the get_oidc_client scope, so GET /client-mgmt/client/{client_id} is unusable on every deployment #2590

Description

@nandhu-kumar

Problem

deploy/keycloak/keycloak-init-values.yaml defines every client scope eSignet enforces except get_oidc_client. It's neither created nor assigned to mosip-pms-client, so on a fresh install no token can satisfy GET /client-mgmt/client/{client_id} — always HTTP 403.

Present on develop-go, release-2.0.x and master (grep -c get_oidc_client → 0 on all three).

Evidence

eSignet enforces the scope — esignet-service/data/deployment.yaml:178-180:

- endpoint: "/client-mgmt/client/{client_id}"
  method: GET
  scope: get_oidc_client

But keycloak-init-values.yaml declares only:

add_oidc_client, update_oidc_client, get_certificate,
upload_certificate, send_binding_otp, wallet_binding

and assigns only these to mosip-pms-client:

assign_client_scopes:
  - update_oidc_client
  - add_oidc_client
  - get_certificate
  - upload_certificate

get_oidc_client is in neither list. Every other enforced scope has a Keycloak counterpart — this is the only one that doesn't.

Confirmed live. A client_credentials token for mosip-pms-client returns:

scope: profile email add_oidc_client upload_certificate update_oidc_client get_certificate

and the call fails:

{"errors":[{"errorCode":"forbidden",
            "errorMessage":"token must carry scope \"get_oidc_client\""}]}

Impact

The GET endpoint is blocked out of the box — no operator configuration fixes it short of editing Keycloak by hand. In the api-test harness this alone causes 19 client-mgmt failures + 4 e2e scenarios that read a client back after a status patch.

Fix

Two additions to deploy/keycloak/keycloak-init-values.yaml, mirroring the existing entries:

1. Declare the scope under keycloak.realms.mosip.client_scopes:

- name: get_oidc_client
  description: Scope required to get OIDC client
  protocol: openid-connect
  "Include In Token Scope": on
  attributes: {
    display.on.consent.screen: "false",
    include.in.token.scope: "true"
  }

2. Assign it to mosip-pms-client under assign_client_scopes:

  - get_oidc_client

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Fields

Priority

Medium

End Date

None yet

Severity

MAJOR

Complexity

None yet

Start Date

None yet

Original Estimate

None yet

Time Tracking

None yet

Resolved By

None yet

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions