Allow to query users with both search and q parameters#48852
Draft
matlipowski wants to merge 1 commit into
Draft
Allow to query users with both search and q parameters#48852matlipowski wants to merge 1 commit into
search and q parameters#48852matlipowski wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Enables combining general user search with custom-attribute filters.
Changes:
- Merges
qattributes into user search and count parameters. - Adds integration coverage for combined filtering.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
UsersResource.java |
Combines search and attribute filters. |
UserSearchTest.java |
Tests combined list and count queries. |
Contributor
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 6 out of 6 changed files in this pull request and generated 1 comment.
Comments suppressed due to low confidence (2)
services/src/main/java/org/keycloak/services/resources/admin/UsersResource.java:330
- The non-
qfilters above are still included in this map, so providers now apply them together withsearcheven though this endpoint documents that onlyqis combined. For example, a no-import LDAP request withsearchandemailVerifiednow returns no users because LDAP treatsemailVerifiedas an unmapped filter; construct this branch fromSEARCHandsearchAttributesonly.
attributes.putAll(searchAttributes);
services/src/main/java/org/keycloak/services/resources/admin/UsersResource.java:464
- The count path has the same regression as the listing path:
enabled,emailVerified, and creation-time parameters are now applied withsearch, contrary to the retained API contract that other criteria are ignored. Keep onlySEARCHplus fields originating fromqso count and list preserve the same semantics across storage providers.
parameters.putAll(searchAttributes);
…ameters (keycloak#45345) Signed-off-by: Mateusz Lipowski <matlipowski@gmail.com>
Contributor
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 6 out of 6 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (1)
services/src/main/java/org/keycloak/services/resources/admin/UsersResource.java:538
- This makes an exact
id:,username:, oremail:lookup run an unbounded realm-wideqsearch and materialize every matching ID just to check a small candidate list. For a broad attribute value this can query—and for LDAP potentially import—large user populations despite the endpoint'smaxlimit; constrain the attribute query to the candidate IDs or evaluate the candidate set directly instead.
Set<String> matchingIds = session.users().searchForUserStream(realm, searchAttributes)
.map(UserModel::getId)
.filter(candidateIds::contains)
.collect(Collectors.toSet());
matlipowski
marked this pull request as draft
July 18, 2026 21:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #45345
Change is super simple and has no breaking changes, so I'm just throwing it in. Refer to issue and many related closed issues for more details.
I'm not sure if I should update anything in documentation, since old behavior is not mentioned there.
I used Codex AI agent for assistance.