4 ms·
We use Keycloak _a lot_ at work, with many public and private instances. It is an amazing product and I keep discovering features every day. But as I somehow e
by kioleanu 3y ago
We use Keycloak _a lot_ at work, with many public and private instances. It is an amazing product and I keep discovering features every day.
But as I somehow ended up being the de-facto responsible person for all things related frontend, I find that Keycloak is lacking some stuff there. My biggest problem at the moment is that you can’t add an endpoint + new page next to your login/registration process. For example, I now need to add a page that explains what data protection measures we take. My only easy option is to add a normal HTML page and link to it, but then it doesn’t inherit from my template and I have to maintain this file separately. Otherwise I have to extend Keycloak’s functionality to register an endpoint myself and then point this endpoint to a method that reads my ftl template and parses it.
Apart from that, I’ve been struggling with UI changes that made once straight forward functionality hard to work with. For example role assigning inside a client, which is now hidden behind multiple screens, where before it was a matter of picking a user and client and just arranging the roles.
I feel like there’s a good need for a UX expert in the team because it seems that Keycloak is becoming one of those pieces of software we pay consultants to come and explain to us, because it is cheaper than us doing it by reading the manual and trying different combinations
- actidoo 3y agoYou can add custom pages to your login and registration flows by implementing an SPI and customizing your flows in the admin interface. ( We offer consultancy for this..., info@actidoo.com )
- kioleanu 3y agoThis proves my point from the last paragraph. I’ve also found this solution in the past, but it is too complex for me. Just to define a page, I would write an SPI, do a config in the admin panel and the corresponding documentation I would need to write for my colleagues. One of those is bound to get forgotten and not get updated, which brings me to square one, keeping a HTML file updated. That’s why I would prefer a solution in which I register the endpoint programmatically and make it parse the template. I do it once and I don’t need to config the instances afterwards (we have dev, staging and prod)
- ExoticPearTree 3y agoWe gave up on Keycloack because it was hard to maintain and add features to it. Now my colleagues are way more happier with an in-house authentication solution that is pretty nimble and we know all the ins and outs.