Real Keycloak to Rust identity authority (#853)
Real Keycloak to Rust identity authority (#853)
The production `KeycloakDesktopAuthority` passes a live component test against the pinned Keycloak 26.7.3 issuer and browser-binding provider. It verifies the real exchanged delegation through HTTPS introspection, obtains gateway service-account credentials and reads actual user, session and group state through the Admin API.
The result and source/log hashes record:
- Initial valid user, session and workspace membership.
- Group removal makes membership false for the same already-verified delegation.
- Group restoration becomes visible without refreshing that delegation.
- Logout makes session status false while the delegation is still unexpired.
- Subsequent introspection rejects the logged-out delegation.
The opt-in test is `live_keycloak_membership_and_session_are_fresh`. Start the owned issuer fixture with the provider JAR using the issuer provider procedure, wait for realm readiness, and run:
AGENTIC_DESKTOP_ISSUER_FIXTURE=/tmp/owned-issuer-fixture cargo test --manifest-path management/Cargo.toml --lib live_keycloak_membership_and_session_are_fresh -- --ignored
The fixture has a fixed synthetic group ID, a gateway service account with native client-role mapping, and a private gateway secret file. Its `manage-users` role is for the fixture's membership mutations; production gateway readers should receive only the read permissions required for user/session/group lookup. No production realm, groups, credentials or server configuration were changed.
The test checks the fixture directory's ownership/mode and the live Docker container's ownership label. It uses a synthetic password login and supplies the fixture leaf directly to the adapter's typed evidence constructor. This proves the adapter's issuer interaction, not TLS listener admission, browser login, attachment shutdown timing, RDP or full Cockpit. Those remain separate gates.
The first run reached the issuer before startup finished and received a connection reset. Container inspection confirmed it was running; after its HTTPS-ready log, the same container passed the test in 1.16 seconds. The issuer's full browser- binding regression also passed afterward. The container was then removed and its exact ID verified absent. Private synthetic credentials and logs remain in the private fixture directory.
No production Rust logic changed. Existing adapter regressions, formatting, Python compilation and documentation checks are recorded with this delivery. This does not close #853 or its dependent desktop scope; remaining APIs/lifecycle, real combined listener/issuer admission, browser and runtime qualification and coverage gates remain open.