refactor(k8s): keep the big-demo theme as real files under infra/keycloak/themes (refs #177)
CI / lint (pull_request) Successful in 1m55s
CI / k8s (pull_request) Successful in 9s
CI / build (pull_request) Successful in 1m27s
CI / unit (pull_request) Successful in 1m51s
CI / frontend (pull_request) Successful in 3m24s
CI / mutation (pull_request) Successful in 6m40s
CI / verify-stack (pull_request) Failing after 1m1s
CI / lint (pull_request) Successful in 1m55s
CI / k8s (pull_request) Successful in 9s
CI / build (pull_request) Successful in 1m27s
CI / unit (pull_request) Successful in 1m51s
CI / frontend (pull_request) Successful in 3m24s
CI / mutation (pull_request) Successful in 6m40s
CI / verify-stack (pull_request) Failing after 1m1s
The theme was inline text in a Helm template. It now lives next to the realms and is seeded as rr-kc-theme by seed-configmaps.sh, like every other file input, so it can be edited as a normal Keycloak theme. demo.otpAutofill now only decides whether KC_SPI_THEME_DEFAULT is set (big.env skips values that render empty); off, Keycloak keeps its stock theme. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,4 @@
|
||||
# The chart makes big-demo the default for every theme type, and Keycloak does not
|
||||
# fall back for a type a theme lacks (the account page then fails), so each type is
|
||||
# declared as a plain child of Keycloak 26's own default.
|
||||
parent=keycloak.v3
|
||||
@@ -0,0 +1,4 @@
|
||||
# The chart makes big-demo the default for every theme type, and Keycloak does not
|
||||
# fall back for a type a theme lacks (the admin page then fails), so each type is
|
||||
# declared as a plain child of Keycloak 26's own default.
|
||||
parent=keycloak.v2
|
||||
@@ -0,0 +1,4 @@
|
||||
# The chart makes big-demo the default for every theme type, and Keycloak does not
|
||||
# fall back for a type a theme lacks (the email page then fails), so each type is
|
||||
# declared as a plain child of Keycloak 26's own default.
|
||||
parent=keycloak
|
||||
@@ -0,0 +1,24 @@
|
||||
// RFC 6238 with Keycloak's default policy (HmacSHA1, 6 digits, 30 s) over the
|
||||
// raw bytes of the medewerker fixture secret — same as tests/e2e/keycloak-login.ts.
|
||||
document.addEventListener('DOMContentLoaded', async () => {
|
||||
const input = document.querySelector('input[name="otp"]');
|
||||
if (!input || !input.form) return;
|
||||
const key = await crypto.subtle.importKey('raw',
|
||||
new TextEncoder().encode('BIGMEDEWERKEROTPSEED'), { name: 'HMAC', hash: 'SHA-1' }, false, ['sign']);
|
||||
// A code is single-use, so a second login in the same window spends the next
|
||||
// counter (Keycloak's look-ahead accepts it). Past that, fill but don't submit,
|
||||
// so a rejected code can't turn into a submit loop.
|
||||
const now = Math.floor(Date.now() / 30000);
|
||||
let last = -1;
|
||||
try { last = Number(sessionStorage.getItem('big-otp-counter')) || -1; } catch {}
|
||||
const counter = Math.max(now, last + 1);
|
||||
const msg = new DataView(new ArrayBuffer(8));
|
||||
msg.setBigUint64(0, BigInt(counter));
|
||||
const mac = new Uint8Array(await crypto.subtle.sign('HMAC', key, msg.buffer));
|
||||
const o = mac[19] & 0x0f;
|
||||
const n = ((mac[o] & 0x7f) << 24 | mac[o + 1] << 16 | mac[o + 2] << 8 | mac[o + 3]) % 1e6;
|
||||
input.value = String(n).padStart(6, '0');
|
||||
if (counter > now + 1) return;
|
||||
try { sessionStorage.setItem('big-otp-counter', String(counter)); } catch {}
|
||||
input.form.requestSubmit();
|
||||
});
|
||||
@@ -0,0 +1,11 @@
|
||||
# Demo login theme for the public Talos deployment: keycloak.v2 plus a script that
|
||||
# fills in and submits the medewerker OTP step from the committed fixture secret
|
||||
# (docs/runbooks/keycloak.md). Only used when the chart's demo.otpAutofill is on —
|
||||
# it then becomes Keycloak's default theme. Never enable it anywhere real.
|
||||
#
|
||||
# Add styles, messages or template overrides here as in any Keycloak theme
|
||||
# (https://www.keycloak.org/ui-customization/themes); new files must also be
|
||||
# listed in infra/helm/seed-configmaps.sh and the keycloak `files` in values.yaml.
|
||||
parent=keycloak.v2
|
||||
import=common/keycloak
|
||||
scripts=js/otp-autofill.js
|
||||
Reference in New Issue
Block a user