53 lines
6.5 KiB
Markdown
53 lines
6.5 KiB
Markdown
# Evidence Matrix
|
|
|
|
범위 정의: `raw/branch-notes/` 아래 Markdown 중 파일명 또는 본문에 대소문자 무관 `keycloak`이 있는 파일. `rg -il --glob '*.md' 'keycloak' raw/branch-notes | sort` 결과를 고정 입력으로 사용했다.
|
|
|
|
| Path | Status | Evidence | Extracted facts |
|
|
|---|---|---|---|
|
|
| `raw/branch-notes/experiment-nplus1-highlight-feed.md` | READ_FULL | L1-L233 | N+1 실험·측정 계약이며 Keycloak은 예정 형제 주제로만 등장한다. |
|
|
| `raw/branch-notes/feature-authentication-authorization-contract.md` | READ_FULL | L1-L341 | application authz PEP, raw role→permission registry, Keycloak role claim 입력 경계. |
|
|
| `raw/branch-notes/feature-boundary-validation-mapping-contract.md` | READ_FULL | L1-L407 | validation/mapping 경계 계약이며 Keycloak은 sample seed 설명에 등장한다. |
|
|
| `raw/branch-notes/feature-keycloak-account-linking-spa-ux.md` | READ_FULL | L1-L228 | SPA account-link UX, First Broker Login, link/unlink, CIAL, linked-account read path. |
|
|
| `raw/branch-notes/feature-keycloak-account-linking-sub-vs-email.md` | READ_FULL | L1-L279 | `sub` federation key, local-account collision, re-auth, unlink lockout, Sync Mode. |
|
|
| `raw/branch-notes/feature-keycloak-bff-vs-spa-direct.md` | READ_FULL | L1-L274 | SPA Direct/BFF 선택, token holder, session, OAuth 2.1 조건. |
|
|
| `raw/branch-notes/feature-keycloak-docker-compose-stack.md` | READ_FULL | L1-L287 | Keycloak/Postgres/app/nginx Compose topology, health, import, issuer/network. |
|
|
| `raw/branch-notes/feature-keycloak-edge-forwardauth-google-federation.md` | READ_FULL | L1-L325 | P1B Google brokering, P1A 불변식, account matching, child-owner 위임. |
|
|
| `raw/branch-notes/feature-keycloak-edge-forwardauth-no-google.md` | READ_FULL | L1-L316 | P1A header-trust ForwardAuth, oauth2-proxy/nginx/Traefik, cookie session. |
|
|
| `raw/branch-notes/feature-keycloak-federation-spa-zero-change.md` | READ_FULL | L1-L193 | P2A→P2B login-path zero-change, token claim baseline, account-link exclusion. |
|
|
| `raw/branch-notes/feature-keycloak-first-broker-login-flow.md` | READ_FULL | L1-L261 | Confirm Link 소유증명, silent auto-link 차단, hard-reject SPI 별도 트랙. |
|
|
| `raw/branch-notes/feature-keycloak-google-claim-attribute-mapping.md` | READ_FULL | L1-L238 | attribute-mapping owner, IdP default IMPORT, role mapping 위임. |
|
|
| `raw/branch-notes/feature-keycloak-google-redirect-uri-policy.md` | READ_FULL | L1-L261 | exact redirect URI, basic-scope 예외, JavaScript origins 비움. |
|
|
| `raw/branch-notes/feature-keycloak-header-spoofing-defense.md` | READ_FULL | L1-L255 | NetworkPolicy·SG·shared secret·trusted proxy 방어 경계. |
|
|
| `raw/branch-notes/feature-keycloak-https-termination-caddy-nginx.md` | READ_FULL | L1-L284 | TLS 종단 대안과 명시적 HSTS 구성. |
|
|
| `raw/branch-notes/feature-keycloak-idp-brokering-google-client.md` | READ_FULL | L1-L251 | Google IdP client, `trustEmail=false`, callback·origin 위임. |
|
|
| `raw/branch-notes/feature-keycloak-idp-mappers-claim-to-role.md` | READ_FULL | L1-L148 | role/RBAC owner, FORCE, email verification 강제 주장. |
|
|
| `raw/branch-notes/feature-keycloak-internal-spa-direct-google-federation.md` | READ_FULL | L1-L512 | P2B composition hub, zero-change brokering, SMTP 사실, foreign-decision 상세. |
|
|
| `raw/branch-notes/feature-keycloak-internal-spa-direct-no-google.md` | READ_FULL | L1-L416 | P2A SPA Direct 정의, refresh-token 저장, brokering 비교. |
|
|
| `raw/branch-notes/feature-keycloak-iss-claim-hostname-mismatch.md` | READ_FULL | L1-L287 | issuer/JWKS 분리 대안, 미승인 대안, 외부 owner 충돌. |
|
|
| `raw/branch-notes/feature-keycloak-nginx-auth-request-integration.md` | READ_FULL | L1-L306 | `auth_request` body handling, browser/API failure routing, upstream ownership edges. |
|
|
| `raw/branch-notes/feature-keycloak-oauth2-proxy-oidc-flow.md` | READ_FULL | L1-L275 | bearer-token 용어, nginx decision references, discovery startup dependency. |
|
|
| `raw/branch-notes/feature-keycloak-patterns.md` | READ_FULL | L1-L205 | retired numbered naming과 retained D2. |
|
|
| `raw/branch-notes/feature-keycloak-pkce-flow-stages.md` | READ_FULL | L1-L167 | PKCE S256 ownership과 Admin Console terminology. |
|
|
| `raw/branch-notes/feature-keycloak-public-domain-tunneling.md` | READ_FULL | L1-L220 | quick/named Cloudflare Tunnel domain과 tunnel-choice ownership. |
|
|
| `raw/branch-notes/feature-keycloak-realm-client-export.md` | READ_FULL | L1-L238 | import wiring ownership, credential export assertions, PKCE terminology. |
|
|
| `raw/branch-notes/feature-keycloak-refresh-rotation-and-logout.md` | READ_FULL | L1-L254 | rotation demonstration, Max Reuse semantics, back-channel logout scope. |
|
|
| `raw/branch-notes/feature-keycloak-refresh-token-rotation.md` | READ_FULL | L1-L284 | rotation contract, family invalidation, receiver endpoint delegation. |
|
|
| `raw/branch-notes/feature-keycloak-reverse-proxy-headers.md` | READ_FULL | L1-L297 | Caddy path behavior, Keycloak proxy variables, delegated security decisions. |
|
|
| `raw/branch-notes/feature-keycloak-single-ec2-google-federation.md` | READ_FULL | L1-L370 | parent integration decisions와 delegated tunnel/proxy details. |
|
|
| `raw/branch-notes/feature-keycloak-single-ec2-no-google.md` | READ_FULL | L1-L342 | base topology, issuer reachability, PKCE order, component ownership. |
|
|
| `raw/branch-notes/feature-keycloak-spa-token-storage-tradeoff.md` | READ_FULL | L1-L256 | access/refresh token storage, TMB 경계, CSRF 위임. |
|
|
| `raw/branch-notes/feature-keycloak-spring-rs-audience-validator.md` | READ_FULL | L1-L268 | audience 검증 owner와 property/custom 구현 선택. |
|
|
| `raw/branch-notes/feature-keycloak-spring-rs-role-mapping.md` | READ_FULL | L1-L231 | RBAC/role mapping과 audience-owner 위임. |
|
|
| `raw/branch-notes/feature-keycloak-three-leg-trust-chain.md` | READ_FULL | L1-L229 | federation/API validation hop, nonce, foreign claim/linking 정책. |
|
|
| `raw/branch-notes/feature-keycloak-traefik-forwardauth-alternative.md` | READ_FULL | L1-L237 | Traefik ForwardAuth routing과 P3A pattern 비교. |
|
|
| `raw/branch-notes/feature-keycloak-vanilla-js-spa-pkce.md` | READ_FULL | L1-L257 | oidc-client-ts/manual PKCE, API/token URL, silent renew. |
|
|
| `raw/branch-notes/feature-security-operational-baseline.md` | READ_FULL | L1-L417 | auth code/CORS/redaction/JWT/public-path operational contracts. |
|
|
|
|
## Completeness
|
|
|
|
- Enumerated `N=38`
|
|
- Evidence rows `M=38`
|
|
- `READ_FULL R=38`, `BLOCKED B=0`
|
|
- Path-set difference: missing `0`, duplicate `0`, extra `0`
|
|
- Completeness formula: `M == N AND P == R`에서 per-file index section `P=38`; 결과 `38 == 38 AND 38 == 38`.
|