1.2 KiB
Google IdP brokering
Keycloak is the only issuer trusted by AP1–AP4. Google is an upstream Identity Provider; applications do not receive or validate a Google token.
Two verification profiles
The default local profile imports a second Keycloak realm named mock-google.
It acts as a controllable OIDC provider and allows tests to choose claims such
as a duplicate email, email_verified=false, hd, and picture. This is the
safe way to reproduce an unsafe email auto-link without impersonating a real
Google account.
The real-Google profile is configured explicitly:
- Create a Google OAuth Web application.
- Register the exact redirect URI printed by
./scripts/configure-google-idp.sh. - Put
GOOGLE_CLIENT_IDandGOOGLE_CLIENT_SECRETin ignored.env. - Start the stack and run the configuration script.
The script writes providerId=google, trustEmail=false, minimal
openid profile email scopes, and syncMode=IMPORT through the Keycloak Admin
API. Credentials are never written to the realm export or repository.
Google requires a public HTTPS redirect for non-local deployments. Local mock verification proves the Keycloak brokering boundary; a real Google login is a separate credentialed acceptance profile.