feat(keycloak): audience mapper for forte-drop-mcp on forte-cli (fallback)
AI Code Review / ai-review (pull_request) Skipped
scan.yaml / test (pull_request) Successful in 6s

Adds an oidc-audience-mapper to the forte-cli client so its access
tokens carry aud=https://mcp.drop.forteapps.net/mcp, the audience the
forte-drop-mcp auth sidecar verifies. Fallback for the case where
Keycloak ignores the RFC 8707 resource= parameter the skill sends.
Stacks on #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Jørgen Stensrud
2026-10-01 10:37:12 +00:00
committed by danijel.simeunovic
co-authored by Claude Opus 5.5
parent 0bf8c3988e
commit 95db80fb53
+15 -1
View File
@@ -200,7 +200,21 @@ keycloakConfigCli:
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
}
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
}
],
"browserFlow": "browser-auto-idp",