Skip to content

Validate the Keycloak OIDC flow with real parallel sessions #5

Description

@4nass

Goal

Validate the first real IdP integration with a pinned Keycloak image.

Scope

  • Run Keycloak with Docker Compose.
  • Test two parallel logins with authuser=new.
  • Test callback and redirect handling for each session index.
  • Test account switching for authuser=0 and authuser=1.
  • Test refresh, userinfo, token, and logout requests.
  • Capture and document every Keycloak cookie needed by each flow.
  • Test two IdMux replicas behind a load balancer.

Done when

  • The complete browser flow passes with two accounts.
  • Targeted logout keeps the other account active.
  • Failover between two proxy replicas does not lose routing state.
  • The Keycloak profile and test setup are documented.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestidentity-providerKeycloak, Authentik, OIDC, or SAML integrationtestingUnit, integration, fuzz, load, or conformance tests

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions