Gestion d'identité et SSO
Find a file
Johannes Knutsen 973e9ad176 Add a global filter which throws bad request if a query parameter value has a control character
Closes #41117

Signed-off-by: Johannes Knutsen <johannes@kodet.no>
2025-09-04 10:19:51 -03:00
.github Bump actions/cache from 4.2.3 to 4.2.4 2025-09-03 16:22:35 -03:00
.idea Add Intellij project icon 2023-09-18 12:39:16 +02:00
.mvn Update custom Maven build cache configuration for js directory 2024-12-10 10:07:02 +00:00
adapters Add missing artifact descriptions to allow Maven Central Portal Publisher pass validation process. (#40822) 2025-08-12 16:50:17 +02:00
authz Add missing javadocs to published artifacts to allow Maven Central Portal Publisher pass validation process. 2025-08-12 16:50:17 +02:00
boms Add publishing plugin for Maven Central Repository migration (#40029) 2025-06-02 14:57:10 +02:00
common Experimental SPIFFE identity provider (#42314) 2025-09-04 14:48:18 +02:00
core [OID4VCI]: Add DPoP nonce header support to OID4VCI nonce endpoint (#41999) 2025-09-04 14:52:10 +02:00
crypto Removed redundant null checks 2025-08-14 17:03:27 +02:00
dependencies Add missing artifact descriptions to allow Maven Central Portal Publisher pass validation process. (#40822) 2025-08-12 16:50:17 +02:00
distribution Add missing javadocs to published artifacts to allow Maven Central Portal Publisher pass validation process. 2025-08-12 16:50:17 +02:00
docs feat(FGAPv2): introduce RESET_PASSWORD scope and evaluation 2025-09-03 15:10:56 -03:00
federation Make sure inner transactions are using their own session 2025-09-03 17:38:19 +02:00
integration DPoP verification support for admin/account REST API endpoints. Java admin-client DPoP support 2025-09-02 14:29:30 +02:00
js Bump lint-staged from 16.1.5 to 16.1.6 in /js (#42333) 2025-09-04 08:09:52 -04:00
misc Add workflows and utils to review stability of testsuite (#40268) 2025-08-13 08:33:26 +02:00
model Lock the database before doing migrations 2025-09-03 15:22:04 -03:00
operator chore: fix some typos in comment (#42279) 2025-09-02 13:20:17 +00:00
quarkus fix: removing script logic for determining if a build is necessary (#41771) 2025-09-04 08:23:04 -04:00
rest Use MgmtPermissionsV2 by default 2025-07-07 11:07:21 -03:00
saml-core Adjusted null checks 2025-08-19 16:31:59 +00:00
saml-core-api Adjusted null checks 2025-08-19 16:31:59 +00:00
server-spi Add support for generic event-based policies and conditions 2025-09-02 17:45:59 -03:00
server-spi-private Experimental SPIFFE identity provider (#42314) 2025-09-04 14:48:18 +02:00
services Add a global filter which throws bad request if a query parameter value has a control character 2025-09-04 10:19:51 -03:00
test-framework Experimental SPIFFE identity provider (#42314) 2025-09-04 14:48:18 +02:00
tests Experimental SPIFFE identity provider (#42314) 2025-09-04 14:48:18 +02:00
testsuite Add a global filter which throws bad request if a query parameter value has a control character 2025-09-04 10:19:51 -03:00
themes [RLM] Provide a action to notify users by email based on a configurable time 2025-09-03 16:38:41 -03:00
util Remove commons-lang v2 2025-08-14 09:56:02 -03:00
.editorconfig Disable trim_trailing_whitespace in editorconfig 2024-11-07 17:48:17 +01:00
.gitattributes Use lf as line-ending for sh files 2022-07-19 08:57:57 +02:00
.gitignore Rename .env-test to .env.test (#36975) 2025-02-03 07:41:56 +01:00
.gitleaks.toml Updated .gitleaks.toml to ignore false positive in RedirectUtilsTest (#33346) 2024-09-27 14:32:36 +02:00
ADOPTERS.md Add Xata to ADOPTERS.md (#40802) 2025-06-30 19:32:32 +02:00
CONTRIBUTING.md Add reason for issue requirement to CONTRIBUTING.md 2024-11-25 08:36:45 +01:00
get-version.sh Use Maven wrapper instead of platform dependent Maven version (#29988) 2024-06-03 15:45:39 +02:00
GOVERNANCE.md Update governance model around changes in maintainership (#29292) 2024-05-22 08:24:10 +02:00
LICENSE.txt Added text version of ASL2 license 2019-11-08 12:43:10 +01:00
MAINTAINERS.md Update MAINTAINERS.md (#40800) 2025-07-08 13:46:58 +02:00
maven-settings.xml [KEYCLOAK-11764] Upgrade to Wildfly 19 2020-04-24 08:19:43 -03:00
mvnw Upgrade Maven and wrapper to latest version 2024-06-19 10:42:33 +02:00
mvnw.cmd Upgrade Maven and wrapper to latest version 2024-06-19 10:42:33 +02:00
pom.xml Upgrade to Quarkus 3.26.1 2025-09-01 14:05:08 +02:00
PR-CHECKLIST.md Introduce CODEOWNERS (#16637) 2023-01-30 13:05:45 +01:00
README.md Add CLOMonitor Badge to the README 2025-02-20 12:31:58 -03:00
SECURITY-INSIGHTS.yml Provide an OpenSSF security insights manifest file 2024-02-15 11:02:33 -03:00
set-version.sh Remove Keycloak JS from repository (#37057) 2025-02-12 16:31:21 +00:00

Keycloak

GitHub Release OpenSSF Best Practices CLOMonitor OpenSSF Scorecard Artifact Hub GitHub Repo stars GitHub commit activity Translation status

Open Source Identity and Access Management

Add authentication to applications and secure services with minimum effort. No need to deal with storing users or authenticating users.

Keycloak provides user federation, strong authentication, user management, fine-grained authorization, and more.

Help and Documentation

Reporting Security Vulnerabilities

If you have found a security vulnerability, please look at the instructions on how to properly report it.

Reporting an issue

If you believe you have discovered a defect in Keycloak, please open an issue. Please remember to provide a good summary, description as well as steps to reproduce the issue.

Getting started

To run Keycloak, download the distribution from our website. Unzip and run:

bin/kc.[sh|bat] start-dev

Alternatively, you can use the Docker image by running:

docker run quay.io/keycloak/keycloak start-dev

For more details refer to the Keycloak Documentation.

Building from Source

To build from source, refer to the building and working with the code base guide.

Testing

To run tests, refer to the running tests guide.

Writing Tests

To write tests, refer to the writing tests guide.

Contributing

Before contributing to Keycloak, please read our contributing guidelines. Participation in the Keycloak project is governed by the CNCF Code of Conduct.

Joining a community meeting is a great way to get involved and help shape the future of Keycloak.

Other Keycloak Projects

License