Commit 0d7c792
committed
fix: Fix Keycloak JWT authentication in production
🔐 Fix Production Authentication
## Issue Fixed:
- 401 Unauthorized errors in production
- JWT strategy trying to validate Keycloak tokens with wrong secret
- Keycloak tokens signed by Keycloak, not our JWT_SECRET
## Solution:
- Modified JwtAuthGuard to validate Keycloak tokens directly
- Bypass JWT strategy validation for production
- Use AuthService.verifyToken() to validate with Keycloak
- Extract Bearer token from Authorization header
## Key Changes:
- JwtAuthGuard: Direct Keycloak token validation
- JwtStrategy: Simplified for development mode only
- Production: Validates tokens against Keycloak userinfo endpoint
- Development: Still uses DISABLE_AUTH bypass
## Authentication Flow:
1. Extract Bearer token from Authorization header
2. Call Keycloak userinfo endpoint with token
3. Parse user information from Keycloak response
4. Set request.user with validated user data
This fixes the 401 errors by properly validating Keycloak
JWT tokens in production environment.1 parent adac7bd commit 0d7c792
2 files changed
Lines changed: 36 additions & 10 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
7 | | - | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
8 | 12 | | |
9 | 13 | | |
10 | 14 | | |
11 | | - | |
| 15 | + | |
12 | 16 | | |
13 | 17 | | |
14 | 18 | | |
| |||
21 | 25 | | |
22 | 26 | | |
23 | 27 | | |
24 | | - | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
25 | 49 | | |
26 | 50 | | |
27 | 51 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
37 | 39 | | |
38 | 40 | | |
39 | 41 | | |
0 commit comments