From 03a1cebf1708dcb333e4950f944a67c4447e117b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B8rgen=20Stensrud?= <89834487+JorgenStensrud@users.noreply.github.com> Date: Mon, 28 Sep 2026 11:11:36 +0200 Subject: [PATCH] feat(keycloak): audience mapper for forte-drop-mcp on forte-cli (fallback) Adds an oidc-audience-mapper to the forte-cli client so its access tokens carry aud=https://mcp.drop.forteapps.net/mcp, the audience the forte-drop-mcp auth sidecar verifies. Fallback for the case where Keycloak ignores the RFC 8707 resource= parameter the skill sends. Stacks on #26. Co-Authored-By: Claude Opus 5.5 --- infra/values/base/keycloak-values.yaml | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/infra/values/base/keycloak-values.yaml b/infra/values/base/keycloak-values.yaml index c3cf15f..dc45cab 100644 --- a/infra/values/base/keycloak-values.yaml +++ b/infra/values/base/keycloak-values.yaml @@ -200,7 +200,21 @@ keycloakConfigCli: "webOrigins": [], "attributes": { "oauth2.device.authorization.grant.enabled": "true" - } + }, + "protocolMappers": [ + { + "name": "audience-forte-drop-mcp", + "protocol": "openid-connect", + "protocolMapper": "oidc-audience-mapper", + "consentRequired": false, + "config": { + "included.custom.audience": "https://mcp.drop.forteapps.net/mcp", + "access.token.claim": "true", + "id.token.claim": "false", + "introspection.token.claim": "true" + } + } + ] } ], "browserFlow": "browser-auto-idp",