fix(keycloak): org create must send a domain (KC 26 rejects domainless) (#20)
ci / shared (push) Successful in 12s
ci / test (push) Successful in 21m24s
ci / image (push) Successful in 17s

This commit was merged in pull request #20.
This commit is contained in:
2026-09-01 09:18:15 +00:00
parent 84516e9b4f
commit 80565fdbf2
2 changed files with 25 additions and 0 deletions
+10
View File
@@ -4,6 +4,7 @@ import (
"context"
"encoding/json"
"errors"
"io"
"net/http"
"net/http/httptest"
"strings"
@@ -24,6 +25,7 @@ type stubKC struct {
emailCalls atomic.Int32
healthCalls atomic.Int32
syncCalls atomic.Int32
lastOrgBody string
tokenFails atomic.Bool // when true, /token returns 401 once
}
@@ -53,6 +55,8 @@ func newStubKC(t *testing.T) *stubKC {
mux.HandleFunc("/admin/realms/test-realm/organizations", func(w http.ResponseWriter, r *http.Request) {
s.orgCalls.Add(1)
if r.Method == http.MethodPost {
body, _ := io.ReadAll(r.Body)
s.lastOrgBody = string(body)
w.Header().Set("Location", s.srv.URL+"/admin/realms/test-realm/organizations/org-xyz")
w.WriteHeader(http.StatusCreated)
return
@@ -135,6 +139,12 @@ func TestHTTPAdapter_createOrgAndInvite(t *testing.T) {
t.Errorf("call counts: org=%d user=%d member=%d email=%d",
s.orgCalls.Load(), s.userCalls.Load(), s.memberCalls.Load(), s.emailCalls.Load())
}
// KC 26 rejects a domainless org; the adapter must send a synthetic
// per-slug domain so onboarding actually provisions.
if !strings.Contains(s.lastOrgBody, `"domains"`) ||
!strings.Contains(s.lastOrgBody, "acme.tenant.breakpilot.com") {
t.Errorf("org create body missing synthetic domain: %s", s.lastOrgBody)
}
}
func TestHTTPAdapter_emailMissingAdminEmailRejected(t *testing.T) {