Emit explicit DISABLE/ENABLE events on user enabled-flag transitions (#48855) - #48856
Closed
thomasdarimont wants to merge 1 commit into
Closed
Conversation
(keycloak#48855) Adds OperationType.DISABLE/ENABLE and EventType.USER_DISABLED/USER_ENABLED so listeners can detect user enable/disable transitions without diffing the JSON representation of a generic UPDATE event. UserResource.updateUser now emits an additional cloned AdminEvent (DISABLE or ENABLE) alongside the existing UPDATE on actual transitions only. The new user EventType entries are reserved for system-driven flips (workflow steps, custom SPI code) that have no admin context. Existing USER_DISABLED_BY_*_LOCKOUT events and the UPDATE emission are unchanged for backward compatibility. Fixes keycloak#48855 Signed-off-by: Thomas Darimont <thomas.darimont@googlemail.com>
Contributor
Author
|
The failing tests are caused by emitted AdminEvents with (ResourceType=User,OperationType=Disable) when a user is explicitly disabled during the tests and updateUser(...) is called. |
Contributor
Author
|
Perhaps the better strategy is to introduce two new user admin API endpoints to explicitly enable/disable a user. |
Contributor
Author
|
I'll add another PR later. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds OperationType.DISABLE/ENABLE and EventType.USER_DISABLED/USER_ENABLED so listeners can detect user enable/disable transitions without diffing the JSON representation of a generic UPDATE event.
UserResource.updateUser now emits an additional cloned AdminEvent (DISABLE or ENABLE) alongside the existing UPDATE on actual transitions only. The new user EventType entries are reserved for system-driven flips (workflow steps, custom SPI code) that have no admin context.
Existing USER_DISABLED_BY_*_LOCKOUT events and the UPDATE emission are unchanged for backward compatibility.
Fixes #48855
Co-Authored-By: Claude Opus 4.7 (1M context)