feat(keycloak): audience mapper for forte-drop-mcp on forte-cli (fallback)
/ test (pull_request) Successful in 23s

Adds an oidc-audience-mapper to the forte-cli client so its access
tokens carry aud=https://mcp.drop.forteapps.net/mcp, the audience the
forte-drop-mcp auth sidecar verifies. Fallback for the case where
Keycloak ignores the RFC 8707 resource= parameter the skill sends.
Stacks on #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Jørgen Stensrud
2026-09-28 11:11:36 +02:00
co-authored by Claude Opus 5.5
parent 46eab199ee
commit 03a1cebf17
+15 -1
View File
@@ -200,7 +200,21 @@ keycloakConfigCli:
"webOrigins": [], "webOrigins": [],
"attributes": { "attributes": {
"oauth2.device.authorization.grant.enabled": "true" "oauth2.device.authorization.grant.enabled": "true"
} },
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
} }
], ],
"browserFlow": "browser-auto-idp", "browserFlow": "browser-auto-idp",