為Keycloak添加自定義API

添加機(jī)制 Service Provider Interfaces (SPI)

創(chuàng)建 REST API

我們創(chuàng)建一個(gè)不需要認(rèn)證授權(quán)就可以訪問(wèn)的API,然后返回用戶列表

添加依賴

<dependencies>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-core</artifactId>
        <scope>provided</scope>
        <version>${keycloak.version}</version>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-server-spi</artifactId>
        <scope>provided</scope>
        <version>${keycloak.version}</version>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-server-spi-private</artifactId>
        <scope>provided</scope>
        <version>${keycloak.version}</version>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-services</artifactId>
        <scope>provided</scope>
        <version>${keycloak.version}</version>
    </dependency>
</dependencies>

整體文件結(jié)構(gòu)如下

+--- pom.xml
 +--- src
 | +--- main
 | | +--- java
 | | | +--- gaurav
 | | | | +--- keycloak
 | | | | | +--- DemoRestProvider.java
 | | | | | +--- DemoRestProviderFactory.java
 | | +--- resources
 | | | +--- META-INF
 | | | | +--- jboss-deployment-structure.xml
 | | | | +--- services
 | | | | | +--- org.keycloak.services.resource.RealmResourceProviderFactor

DemoRestProviderFactoryDemoRestProvider 分別實(shí)現(xiàn)接口org.keycloak.services.resource.RealmResourceProviderFactoryorg.keycloak.services.resource.RealmResourceProvider

DemoRestProviderFactory 將會(huì)定義 REST API 名稱,并且在構(gòu)造器中創(chuàng)建DemoRestProvider實(shí)例

需要注意的是,factory 實(shí)例的生命周期是和keycloak server 生命周期同步的,而DemoRestProvider 則是沒(méi)個(gè)請(qǐng)求都會(huì)生成與一個(gè)實(shí)例。

DemoRestProviderFactory.java

package gaurav.keycloak;

import org.keycloak.Config.Scope;
import org.keycloak.models.KeycloakSession;
import org.keycloak.models.KeycloakSessionFactory;
import org.keycloak.services.resource.RealmResourceProvider;
import org.keycloak.services.resource.RealmResourceProviderFactory;

public class DemoRestProviderFactory implements RealmResourceProviderFactory {
    public static final String ID = "gaurav-rest";

    public RealmResourceProvider create(KeycloakSession session) {
        return new DemoRestProvider(session);
    }

    public void init(Scope config) {
    }

    public void postInit(KeycloakSessionFactory factory) {
    }

    public void close() {
    }

    public String getId() {
        return ID;
    }

}

DemoRestProvider.java

package gaurav.keycloak;

import gaurav.keycloak.model.UserDetails;
import org.jboss.resteasy.annotations.cache.NoCache;
import org.keycloak.models.KeycloakSession;
import org.keycloak.models.UserModel;
import org.keycloak.services.resource.RealmResourceProvider;
import org.keycloak.utils.MediaType;

import javax.ws.rs.Encoded;
import javax.ws.rs.GET;
import javax.ws.rs.Path;
import javax.ws.rs.Produces;
import java.util.List;
import java.util.stream.Collectors;

public class DemoRestProvider implements RealmResourceProvider {
    private final KeycloakSession session;


    public DemoRestProvider(KeycloakSession session) {
        this.session = session;
    }


    public void close() {

    }

    public Object getResource() {
        return this;
    }

    @GET
    @Path("users")
    @NoCache
    @Produces({MediaType.APPLICATION_JSON})
    @Encoded
    public List<UserDetails> getUsers() {
        List<UserModel> userModel = session.users().getUsers(session.getContext().getRealm());
        return userModel.stream().map(e -> toUserDetail(e)).collect(Collectors.toList());
    }

    private UserDetails toUserDetail(UserModel um) {
        return new UserDetails(um.getUsername(), um.getFirstName(), um.getLastName());

    }

}

UserDetails.java

package gaurav.keycloak.model;

public class UserDetails {
    private String userName;
    private String firstName;
    private String lastName;

    public UserDetails(String userName, String firstName, String lastName) {
        this.userName = userName;
        this.firstName = firstName;
        this.lastName = lastName;
    }

    public String getFirstName() {
        return firstName;
    }

    public String getUserName() {
        return userName;
    }

    public String getLastName() {
        return lastName;
    }


}

使用 SPI 機(jī)制添加factory class 到keycloak
添加文件org.keycloak.services.resource.RealmResourceProviderFactory 到 src\main\resources\META-INF

| +--- resources
| | +--- META-INF
| | | +--- services
| | | | +--- org.keycloak.services.resource.RealmResourceProviderFactory

添加文件jboss-deployment-structure.xml到 src\main\resources

jboss-deployment-structure.xml

<jboss-deployment-structure>
    <deployment>
        <dependencies>
            <module name="org.keycloak.keycloak-core"/>
            <module name="org.keycloak.keycloak-server-spi"/>
            <module name="org.keycloak.keycloak-server-spi-private"/>
            <module name="org.keycloak.keycloak-services"/>
        </dependencies>
    </deployment>
</jboss-deployment-structure>

org.keycloak.services.resource.RealmResourceProviderFactory 的內(nèi)容為
gaurav.keycloak.DemoRestProviderFactory

運(yùn)行 maven package,生成的jar包放入keycloak-12.0.2\standalone\deployments 內(nèi)會(huì)自動(dòng)生成keycloak-rest-api-1.0.jar.deployed 文件

進(jìn)入keycloak


image.png

image.png

測(cè)試

創(chuàng)建一個(gè)realm GW,然后在GW下隨便添加幾個(gè)用戶。

curl-s -X GET"http://localhost:8180/auth/realms/GW/gaurav-rest/users" | jq
[
  { 
    "userName": "gaurav",
    "firstName": "gaurav",
    "lastName": "wadhone"
  },
  {
    "userName": "testuser",
    "firstName": "test",
    "lastName": "user"
  },
  {
    "userName": "testuser2",
    "firstName": "test",
    "lastName": "user2"
  }
]

參考
參考2
源碼

?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
【社區(qū)內(nèi)容提示】社區(qū)部分內(nèi)容疑似由AI輔助生成,瀏覽時(shí)請(qǐng)結(jié)合常識(shí)與多方信息審慎甄別。
平臺(tái)聲明:文章內(nèi)容(如有圖片或視頻亦包括在內(nèi))由作者上傳并發(fā)布,文章內(nèi)容僅代表作者本人觀點(diǎn),簡(jiǎn)書系信息發(fā)布平臺(tái),僅提供信息存儲(chǔ)服務(wù)。

相關(guān)閱讀更多精彩內(nèi)容

友情鏈接更多精彩內(nèi)容