796 B
796 B
AP1 internal SPA direct: Google-federated profile
SPA -> Keycloak -> Google
SPA <- Keycloak code/token <- Keycloak
SPA -> Spring API with Keycloak access token
Google은 upstream authentication만 담당한다. SPA와 Resource Server의 trust anchor는 계속 Keycloak issuer/JWKS/audience다. 따라서 Spring이 Google ID token을 직접 받거나 Google JWKS를 검증하지 않는다.
추가 운영 항목은 Google client secret, exact broker redirect URI, safe First
Broker Login, sub account key, claim mapper다. 로컬에서는 두 번째 Keycloak
realm이 Google 역할을 하므로 외부 credential 없이 같은 hop을 재현한다.
verify-internal-spa-google-contract.sh는 broker 설정과 기존 AP1 SPA의
zero-change federation E2E를 함께 실행한다.