| 1 |
branch |
target |
delivery |
| 2 |
feature/keycloak-account-linking-spa-ux |
ap1 |
documented-and-contract-tested |
| 3 |
feature/keycloak-account-linking-sub-vs-email |
common |
documented-and-contract-tested |
| 4 |
feature/keycloak-bff-csrf-samesite-defense |
ap3 |
locally-verified |
| 5 |
feature/keycloak-bff-oauth2login-session |
ap3 |
locally-verified |
| 6 |
feature/keycloak-bff-vs-spa-direct |
ap3 |
documented |
| 7 |
feature/keycloak-docker-compose-stack |
common |
locally-verified |
| 8 |
feature/keycloak-edge-forwardauth-google-federation |
ap4 |
documented-and-config-tested |
| 9 |
feature/keycloak-edge-forwardauth-no-google |
ap4 |
documented-and-config-tested |
| 10 |
feature/keycloak-federation-spa-zero-change |
ap1 |
contract-tested |
| 11 |
feature/keycloak-first-broker-login-flow |
common |
locally-verified-with-mock-idp |
| 12 |
feature/keycloak-four-pattern-tradeoff-matrix |
common |
documented-and-evidence-linked |
| 13 |
feature/keycloak-google-claim-attribute-mapping |
common |
locally-verified-with-mock-idp |
| 14 |
feature/keycloak-google-redirect-uri-policy |
common |
config-tested |
| 15 |
feature/keycloak-header-spoofing-defense |
ap4 |
locally-verified |
| 16 |
feature/keycloak-https-termination-caddy-nginx |
common |
config-tested |
| 17 |
feature/keycloak-idp-brokering-google-client |
common |
locally-verified-with-mock-idp |
| 18 |
feature/keycloak-idp-mappers-claim-to-role |
common |
locally-verified-with-mock-idp |
| 19 |
feature/keycloak-internal-spa-direct-google-federation |
ap1 |
documented-and-contract-tested |
| 20 |
feature/keycloak-internal-spa-direct-no-google |
ap1 |
documented-and-contract-tested |
| 21 |
feature/keycloak-iss-claim-hostname-mismatch |
ap1 |
locally-verified |
| 22 |
feature/keycloak-nginx-auth-request-integration |
ap4 |
locally-verified |
| 23 |
feature/keycloak-oauth2-proxy-oidc-flow |
ap4 |
locally-verified |
| 24 |
feature/keycloak-patterns |
common |
governance |
| 25 |
feature/keycloak-pkce-flow-stages |
ap1 |
contract-tested |
| 26 |
feature/keycloak-public-domain-tunneling |
common |
config-tested |
| 27 |
feature/keycloak-realm-client-export |
common |
locally-verified |
| 28 |
feature/keycloak-refresh-rotation-and-logout |
ap1 |
locally-verified |
| 29 |
feature/keycloak-refresh-token-rotation |
ap1 |
contract-tested |
| 30 |
feature/keycloak-reverse-proxy-headers |
common |
config-tested |
| 31 |
feature/keycloak-single-ec2-google-federation |
ap1 |
documented-and-config-tested |
| 32 |
feature/keycloak-single-ec2-no-google |
ap1 |
documented-and-contract-tested |
| 33 |
feature/keycloak-spa-token-storage-tradeoff |
ap1 |
locally-verified |
| 34 |
feature/keycloak-spring-rs-audience-validator |
ap1 |
locally-verified |
| 35 |
feature/keycloak-spring-rs-role-mapping |
ap1 |
locally-verified |
| 36 |
feature/keycloak-three-leg-trust-chain |
ap1 |
documented-and-contract-tested |
| 37 |
feature/keycloak-token-mediating-access-handoff |
ap2 |
locally-verified |
| 38 |
feature/keycloak-token-mediating-confidential-client |
ap2 |
locally-verified |
| 39 |
feature/keycloak-traefik-forwardauth-alternative |
ap4 |
config-tested |
| 40 |
feature/keycloak-vanilla-js-spa-pkce |
ap1 |
locally-verified |