| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [View Raw Code] [Original HTTPS Page] |
The Authentication module provides functionality for handling authentication flows with Keycloak, including client credentials flow, resource owner password flow, and token management.
All authentication operations return either KcResponse<T> or KcOperationResponse<T> where T is the specific response type for the operation. For detailed information about response types and error handling, see Response Types.
For information about monitoring and metrics available in responses, see Monitoring and Metrics.
The module supports various token types for different authentication scenarios:
var response = await keycloakClient.Auth.GetClientCredentialsTokenAsync(
"your-realm",
new KcClientCredentials
{
ClientId = "your-client-id",
ClientSecret = "your-client-secret"
});
if (!response.IsError)
{
var token = response.Response;
// Use token.AccessToken, token.RefreshToken, etc.
}var response = await keycloakClient.Auth.GetResourceOwnerPasswordTokenAsync(
"your-realm",
new KcClientCredentials
{
ClientId = "your-client-id",
ClientSecret = "your-client-secret"
},
"username",
"password");
if (!response.IsError)
{
var token = response.Response;
// Use token.AccessToken, token.RefreshToken, etc.
}var response = await keycloakClient.Auth.ValidatePasswordAsync(
"your-realm",
new KcClientCredentials
{
ClientId = "your-client-id",
ClientSecret = "your-client-secret"
},
"username",
"password");
if (!response.IsError)
{
var isValid = response.Response;
// Handle password validation result
}var response = await keycloakClient.Auth.RefreshAccessTokenAsync(
"your-realm",
"refresh-token",
"client-id");
if (!response.IsError)
{
var newToken = response.Response;
// Use newToken.AccessToken, newToken.RefreshToken, etc.
}// Revoke access token
var revokeAccessResponse = await keycloakClient.Auth.RevokeAccessTokenAsync(
"your-realm",
new KcClientCredentials
{
ClientId = "your-client-id",
ClientSecret = "your-client-secret"
},
"access-token");
// Revoke refresh token
var revokeRefreshResponse = await keycloakClient.Auth.RevokeRefreshTokenAsync(
"your-realm",
new KcClientCredentials
{
ClientId = "your-client-id",
ClientSecret = "your-client-secret"
},
"refresh-token");Obtain a token with additional permissions:
var response = await keycloakClient.Auth.GetRequestPartyTokenAsync(
"your-realm",
new KcClientCredentials
{
ClientId = "your-client-id",
ClientSecret = "your-client-secret"
},
"audience");
if (!response.IsError)
{
var rptToken = response.Response;
// Use the RPT token
}The main token model returned by authentication operations:
public class KcIdentityProviderToken
{
// Access token for API requests
public string AccessToken { get; set; }
// Token expiration time in seconds
public long? ExpiresIn { get; set; }
// Refresh token for obtaining new access tokens
public string RefreshToken { get; set; }
// Token type (usually "Bearer")
public string TokenType { get; set; }
// OpenID Connect ID token
public string IdToken { get; set; }
// Keycloak session state
public string SessionState { get; set; }
// Token scope
public string Scope { get; set; }
}Common claims available in the access token:
public class KcAccessToken
{
// User ID
public string Subject { get; set; }
// Username
public string PreferredUsername { get; set; }
// User email
public string Email { get; set; }
// Email verification status
public bool? EmailVerified { get; set; }
// User roles
public string[] RealmRoles { get; set; }
// Resource roles
public Dictionary<string, string[]> ResourceRoles { get; set; }
// Token scope
public string Scope { get; set; }
}Token Storage:
Token Handling:
Token Validation:
All operations return a KcResponse<T> or KcOperationResponse<T> that includes error information and monitoring metrics. Here's how to handle errors:
try
{
var response = await keycloakClient.Auth.GetClientCredentialsTokenAsync(
realm,
credentials);
if (response.IsError)
{
// Handle error using response.Exception
logger.LogError($"Authentication failed: {response.Exception.Message}");
// Handle specific error cases
if (response.Exception is KcAuthenticationException)
{
// Handle authentication-specific errors
}
}
else
{
// Process successful response
var token = response.Response;
}
}
catch (Exception ex)
{
// Handle unexpected errors
logger.LogError($"Unexpected error during authentication: {ex.Message}");
}| Back | FazBrowse Home | New Git URL |