Skip to content

Added RESOURCE_OWNER_PASSWORD_CREDENTIALS_REQUEST - Fixes policy enforcement gap for direct access grant flows#46283

Open
msdaly200 wants to merge 2 commits intokeycloak:mainfrom
msdaly200:45750
Open

Added RESOURCE_OWNER_PASSWORD_CREDENTIALS_REQUEST - Fixes policy enforcement gap for direct access grant flows#46283
msdaly200 wants to merge 2 commits intokeycloak:mainfrom
msdaly200:45750

Conversation

@msdaly200
Copy link
Contributor

Apply ClientAccessTypeCondition to password grant requests

Add RESOURCE_OWNER_PASSWORD_CREDENTIALS_REQUEST event handling to
ClientAccessTypeCondition for consistent policy enforcement.

Closes #45740

@msdaly200 msdaly200 requested review from a team as code owners February 12, 2026 11:58
@mposolda mposolda self-assigned this Feb 12, 2026
@ahus1 ahus1 changed the title 45750 Added RESOURCE_OWNER_PASSWORD_CREDENTIALS_REQUEST - Fixes policy enforcement gap for direct access grant flows Feb 12, 2026
@msdaly200 msdaly200 requested review from a team as code owners February 13, 2026 13:33
…rcement gap for direct access grant flows.

Signed-off-by: Marie Daly <marie.daly1@ibm.com>
Signed-off-by: Marie Daly <marie.daly1@ibm.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

client-access-type condition in Client Policy does not trigger for token request events

2 participants