Migrate from keycloak-js to oidc-spa
This commit is contained in:
1 parent
be386fd8ac
commit
ab4b205980
8 files changed
+170
-422
No files matched your search
@@ -220,4 +220,4 @@ jobs:
|
|||||||
EOF
|
EOF
|
||||||
```
|
```
|
||||||
|
|
||||||
You can also remove `jwt-decode`, `keycloak-js`, `powerhooks` and `tsafe` from your dependencies.
|
You can also remove `oidc-spa`, `powerhooks` and `tsafe` from your dependencies.
|
||||||
+1
-2
@@ -27,8 +27,7 @@
|
|||||||
"keywords": [],
|
"keywords": [],
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"evt": "^2.4.15",
|
"evt": "^2.4.15",
|
||||||
"jwt-decode": "^3.1.2",
|
"oidc-spa": "^1.0.1",
|
||||||
"keycloak-js": "^21.0.1",
|
|
||||||
"keycloakify": "^8.1.3",
|
"keycloakify": "^8.1.3",
|
||||||
"powerhooks": "^0.26.8",
|
"powerhooks": "^0.26.8",
|
||||||
"react": "18.1.0",
|
"react": "18.1.0",
|
||||||
|
|||||||
+122
-58
@@ -1,86 +1,69 @@
|
|||||||
import "./App.css";
|
import "./App.css";
|
||||||
import logo from "./logo.svg";
|
import logo from "./logo.svg";
|
||||||
import myimg from "./myimg.png";
|
import myimg from "./myimg.png";
|
||||||
import { createOidcClientProvider, useOidcClient } from "./oidc";
|
import { useMemo } from "react";
|
||||||
import { addFooToQueryParams, addBarToQueryParams } from "../keycloak-theme/login/valuesTransferredOverUrl";
|
import { createOidcProvider, useOidc } from "oidc-spa/react";
|
||||||
import jwt_decode from "jwt-decode";
|
import { addQueryParamToUrl } from "oidc-spa/tools/urlQueryParams";
|
||||||
import { addParamToUrl } from "powerhooks/tools/urlSearchParams";
|
import { decodeJwt } from "oidc-spa";
|
||||||
|
import { assert } from "tsafe/assert";
|
||||||
|
|
||||||
//On older Keycloak version you need the /auth (e.g: http://localhost:8080/auth)
|
//On older Keycloak version you need the /auth (e.g: http://localhost:8080/auth)
|
||||||
//On newer version you must remove it (e.g: http://localhost:8080 )
|
//On newer version you must remove it (e.g: http://localhost:8080 )
|
||||||
const keycloakUrl = "https://auth.code.gouv.fr/auth";
|
const keycloakUrl = "https://auth.code.gouv.fr/auth";
|
||||||
const keycloakRealm = "keycloakify";
|
const keycloakRealm = "keycloakify";
|
||||||
const keycloakClient= "starter";
|
const keycloakClientId= "starter";
|
||||||
|
|
||||||
const { OidcClientProvider } = createOidcClientProvider({
|
const { OidcProvider } = createOidcProvider({
|
||||||
url: keycloakUrl,
|
issuerUri: `${keycloakUrl}/realms/${keycloakRealm}`,
|
||||||
realm: keycloakRealm,
|
clientId: keycloakClientId,
|
||||||
clientId: keycloakClient,
|
transformUrlBeforeRedirect: url => {
|
||||||
//This function will be called just before redirecting,
|
|
||||||
//it should return the current langue.
|
// This adding ui_locales to the url will ensure the consistency of the language between the app and the login pages
|
||||||
//kcContext.locale.currentLanguageTag will be what this function returned just before redirecting.
|
// If your app implements a i18n system (like i18nifty.dev for example) you should use this and replace "en" by the
|
||||||
getUiLocales: () => "en",
|
// current language of the app.
|
||||||
transformUrlBeforeRedirect: url =>
|
// On the other side you will find kcContext.locale.currentLanguageTag to be whatever you set here.
|
||||||
[url]
|
url = addQueryParamToUrl({
|
||||||
//Instead of foo and bar you could have isDark for example or any other state that you wish to
|
url,
|
||||||
//transfer from the main app to the login pages.
|
"name": "ui_locales",
|
||||||
.map(url => addFooToQueryParams({ url, value: { foo: 42 } }))
|
"value": "en",
|
||||||
.map(url => addBarToQueryParams({ url, value: "value of bar transferred to login page" }))
|
}).newUrl;
|
||||||
[0],
|
|
||||||
log: console.log
|
// If you want to pass some custom state to the login pages...
|
||||||
|
// See in src/keycloak-theme/pages/Login.tsx how it's retrieved.
|
||||||
|
url = addQueryParamToUrl({
|
||||||
|
url,
|
||||||
|
"name": "my_custom_param",
|
||||||
|
"value": "value of foo transferred to login page",
|
||||||
|
}).newUrl;
|
||||||
|
|
||||||
|
return url;
|
||||||
|
|
||||||
|
},
|
||||||
|
// Uncomment if your app is not hosted at the origin and update /foo/bar/baz.
|
||||||
|
//silentSsoUrl: `${window.location.origin}/foo/bar/baz/silent-sso.html`,
|
||||||
});
|
});
|
||||||
|
|
||||||
export default function App() {
|
export default function App() {
|
||||||
return (
|
return (
|
||||||
<OidcClientProvider>
|
<OidcProvider>
|
||||||
<ContextualizedApp />
|
<ContextualizedApp />
|
||||||
</OidcClientProvider>
|
</OidcProvider>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
function ContextualizedApp() {
|
function ContextualizedApp() {
|
||||||
|
|
||||||
const { oidcClient } = useOidcClient();
|
const { oidc } = useOidc();
|
||||||
|
|
||||||
let accountUrl = `${keycloakUrl}/realms/${keycloakRealm}/account`;
|
|
||||||
|
|
||||||
// Set the language the user will get on the account page
|
|
||||||
accountUrl = addParamToUrl({
|
|
||||||
url: accountUrl,
|
|
||||||
name: "kc_locale",
|
|
||||||
value: "en"
|
|
||||||
}).newUrl;
|
|
||||||
|
|
||||||
// Enable to redirect to the app from the account page we'll get the referrer_uri under kcContext.referrer.url
|
|
||||||
// It's useful to avoid hard coding the app url in the keycloak config
|
|
||||||
accountUrl = addParamToUrl({
|
|
||||||
url: accountUrl,
|
|
||||||
name: "referrer",
|
|
||||||
value: keycloakClient
|
|
||||||
}).newUrl;
|
|
||||||
|
|
||||||
accountUrl = addParamToUrl({
|
|
||||||
url: accountUrl,
|
|
||||||
name: "referrer_uri",
|
|
||||||
value: window.location.href
|
|
||||||
}).newUrl;
|
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="App">
|
<div className="App">
|
||||||
<header className="App-header">
|
<header className="App-header">
|
||||||
{
|
{
|
||||||
oidcClient.isUserLoggedIn ?
|
oidc.isUserLoggedIn ?
|
||||||
<>
|
<AuthenticatedRoute logout={() => oidc.logout({ redirectTo: "home" })} />
|
||||||
<h1>You are authenticated !</h1>
|
|
||||||
{/* On older Keycloak version its /auth/realms instead of /realms */}
|
|
||||||
<a href={accountUrl}>Link to your Keycloak account</a>
|
|
||||||
<pre style={{ textAlign: "left" }}>{JSON.stringify(jwt_decode(oidcClient.getAccessToken()), null, 2)}</pre>
|
|
||||||
<button onClick={() => oidcClient.logout({ redirectTo: "home" })}>Logout</button>
|
|
||||||
</>
|
|
||||||
:
|
:
|
||||||
<>
|
<button onClick={() => oidc.login({ doesCurrentHrefRequiresAuth: false })}>Login</button>
|
||||||
<button onClick={() => oidcClient.login({ doesCurrentHrefRequiresAuth: false })}>Login</button>
|
|
||||||
</>
|
|
||||||
}
|
}
|
||||||
<img src={logo} className="App-logo" alt="logo" />
|
<img src={logo} className="App-logo" alt="logo" />
|
||||||
<img src={myimg} alt="test_image" />
|
<img src={myimg} alt="test_image" />
|
||||||
@@ -90,4 +73,85 @@ function ContextualizedApp() {
|
|||||||
</header>
|
</header>
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
function AuthenticatedRoute(props: { logout: () => void; }) {
|
||||||
|
|
||||||
|
const { logout } = props;
|
||||||
|
|
||||||
|
const { user } = useUser();
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<h1>Hello {user.name} !</h1>
|
||||||
|
<a href={buildAccountUrl({ locale: "en" })}>Link to your Keycloak account</a>
|
||||||
|
<button onClick={logout}>Logout</button>
|
||||||
|
<pre style={{ textAlign: "left" }}>{JSON.stringify(user, null, 2)}</pre>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
function useUser() {
|
||||||
|
const { oidc } = useOidc();
|
||||||
|
|
||||||
|
assert(oidc.isUserLoggedIn, "This hook can only be used when the user is logged in");
|
||||||
|
|
||||||
|
const { idToken } = oidc.getTokens();
|
||||||
|
|
||||||
|
const user = useMemo(
|
||||||
|
() =>
|
||||||
|
decodeJwt<{
|
||||||
|
// Use https://jwt.io/ to tell what's in your idToken
|
||||||
|
// It will depend of your Keycloak configuration.
|
||||||
|
// Here I declare only two field on the type but actually there are
|
||||||
|
// Many more things available.
|
||||||
|
sub: string;
|
||||||
|
name: string;
|
||||||
|
preferred_username: string;
|
||||||
|
// This is a custom attribute set up in our Keycloak configuration
|
||||||
|
// it's not present by default.
|
||||||
|
// See https://docs.keycloakify.dev/realtime-input-validation#getting-your-custom-user-attribute-to-be-included-in-the-jwt
|
||||||
|
favorite_pet: "cat" | "dog" | "bird";
|
||||||
|
}>(idToken),
|
||||||
|
[idToken]
|
||||||
|
);
|
||||||
|
|
||||||
|
return { user };
|
||||||
|
}
|
||||||
|
|
||||||
|
function buildAccountUrl(
|
||||||
|
params: {
|
||||||
|
locale: string;
|
||||||
|
}
|
||||||
|
){
|
||||||
|
|
||||||
|
const { locale } = params;
|
||||||
|
|
||||||
|
let accountUrl = `${keycloakUrl}/realms/${keycloakRealm}/account`;
|
||||||
|
|
||||||
|
// Set the language the user will get on the account page
|
||||||
|
accountUrl = addQueryParamToUrl({
|
||||||
|
url: accountUrl,
|
||||||
|
name: "kc_locale",
|
||||||
|
value: locale
|
||||||
|
}).newUrl;
|
||||||
|
|
||||||
|
// Enable to redirect to the app from the account page we'll get the referrer_uri under kcContext.referrer.url
|
||||||
|
// It's useful to avoid hard coding the app url in the keycloak config
|
||||||
|
accountUrl = addQueryParamToUrl({
|
||||||
|
url: accountUrl,
|
||||||
|
name: "referrer",
|
||||||
|
value: keycloakClientId
|
||||||
|
}).newUrl;
|
||||||
|
|
||||||
|
accountUrl = addQueryParamToUrl({
|
||||||
|
url: accountUrl,
|
||||||
|
name: "referrer_uri",
|
||||||
|
value: window.location.href
|
||||||
|
}).newUrl;
|
||||||
|
|
||||||
|
return accountUrl;
|
||||||
|
|
||||||
}
|
}
|
||||||
Loaded 3 of 8 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user