feat(keycloak): client-secret-rotation validieren #303
Labels
No labels
component/backend
component/docs
component/e2e
component/frontend
component/infra
component/keycloak
prio/high
prio/low
prio/medium
type/bug
type/chore
type/feature
type/refactor
type/test
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
WompSchmiede/FamilienFeierPlaner#303
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Beschreibung
Im Zuge der Keycloak-Haertung (#259) wurde
client-secret-rotationinKC_FEATURES_DISABLEDaufgenommen, da es aktuell nicht genutzt wird.Client Secret Rotation ermoeglicht den automatischen Austausch von Client Secrets ueber einen Endpunkt. Dies koennte die Sicherheit fuer die Backend-API- und Swagger-UI-Clients erhoehen.
Aufgabe
client-secret-rotationin Keycloak testen und bewertenbackend-api) und Swagger-UI-Client von Rotation profitierenkeycloak-provision.ts) und den laufenden Betrieb pruefenKC_FEATURES_DISABLEDohneclient-secret-rotation) oder dauerhaft deaktiviert lassenBetroffene Komponente
component/keycloak, evtl.component/backendMeilenstein
MS-v2: Feature-Validierung