SPA: inject nonce into implicit-flow login URLs (KC26 requires it) #16
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/kc-implicit-nonce"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Keycloak 26 rejects implicit-flow auth requests without a nonce parameter ("Missing parameter: nonce"). keycloak-js 23.0.7 only sends it with useNonce:true, which then validates the nonce on the access_token (Keycloak only puts it in the id_token) -> clearToken loop. Fix: keep useNonce:false, inject nonce= into every kc.createLoginUrl() result. Includes PROBLEMS.md.
Keycloak 26 rejects implicit-flow auth requests without a nonce parameter ('Missing parameter: nonce'). keycloak-js 23.0.7 only sends it when useNonce:true, which then also validates the nonce on the access_token (Keycloak only puts it in the id_token) -> clearToken -> redirect loop. Keep useNonce:false and inject a fresh nonce=<uuid v4> into every URL produced by kc.createLoginUrl() (the single funnel for all login redirects). UUID via crypto.getRandomValues (randomUUID needs a secure context; app is plain HTTP). Also add PROBLEMS.md documenting the issues found/fixed and verification.