# AP1 internal SPA direct: local identity profile ```text Browser SPA --Authorization Code + PKCE--> Keycloak Browser SPA --Bearer access token-------> Spring Resource Server ``` 이 profile은 Keycloak 로컬 사용자만으로 동작한다. Google client ID/secret, public domain, broker callback이 없어도 AP1의 login, refresh, logout, audience/issuer 검증과 RBAC를 모두 학습할 수 있다. `mock-google` provider가 realm에 함께 존재해도 로컬 로그인은 provider availability에 의존하지 않는다. 실제로 federation 없는 배포를 만들 때는 해당 IdP를 disabled로 두거나 realm overlay에서 제거한다. 빠른 계약 검증은 `verify-internal-spa-no-google-contract.sh`, 실제 브라우저 흐름은 `verify-pattern1.sh`가 담당한다.