Add Dependabot for every example, build badges and the docs drift checklist - #43
Merged
Merged
Conversation
pnzrr
self-requested a review
October 5, 2026 16:35
pnzrr
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge this last. It builds on #28, whose commit the branch includes, and adds repo-wide files for every example PR (#44, #45 and #46). Review the last two commits.
Summary
.github/dependabot.ymlnow covers every example. Add shared CI workflows, local Keycloak and contributing guide #28 only set it up for GitHub Actions and the shared Keycloak.react-routerand@react-router/*, because the Vercel preset supports only React Router 7;@eslint/jsand Vitest, because Nx's plugins cap them.@types/nodemajors and wait 7 days after a release.keycloak/README.md: notes that the SAML example's Keycloak also uses port 8080, so the shared one has to be stopped first.Test plan
.github/dependabot.ymlvalidates against the SchemaStore schema.Merge order and follow-ups
Outside the code:
VERCEL_DEPLOYMENT_TOKENand the project ID secrets are still valid.p2examplesrealm login, which rejects every valid login with "Unexpected error when handling authentication request to identity provider". Until then, the live demos can't log in, although the local Keycloak works.Shared templates (all tutorials)
templates/blog/_phase_two_starter_instructions.mdx(imported by 11 posts): still says "free Phase Two Starter instance… Create a Shared Deployment". Free shared realms were shut down on 2026-07-30.templates/blog/_oidc_client_creation*.mdx:+", since every example now logs out through Keycloak;keycloak/of the examples repo as an alternative.React (oidc-client-ts): #44
blog/2023-08-02-secure-reactjs.mdx(L60–99):npm install/npm start→pnpm install/pnpm dev;src/index.tsxsnippet is nowsrc/main.tsxand readsVITE_OIDC_ISSUER_URI/VITE_OIDC_CLIENT_IDfrom.env;…/authenticated;signoutRedirect();euc1.auth.achost.docs/securing-applications/react.md: documents@react-keycloak/web+ keycloak-js, which no example uses. Rewrite around react-oidc-context or oidc-spa.React (oidc-spa) and the tutorial starter: #44
blog/2024-10-10-oidc-spa.mdx(L57–222). It shows the oidc-spa v5 API, andnpm install oidc-spanow installs v10, so the post fails as written. Update it:createReactOidc({ issuerUri, clientId, publicUrl })→src/oidc.tswithoidcSpa.withExpectedDecodedIdTokenShape(…).createUtils(), theoidcSpa()Vite plugin and<OidcInitializationGate>;oidcTokens.decodedIdToken→decodedIdToken;logout({ redirectTo: "current page" })→logout({ redirectTo: "home" });getOidc().getTokens()→await getAccessToken()orfetchWithAuth;frameworks/reactjs/oidc-spa-starter/README.md;Vue (oidc-client-ts): #44
blog/2023-09-14-secure-vue.mdxandtemplates/frameworks/_vuejs.mdx(L5–88):/nuxt/oidc-client-tsfolder;.env;client_secretin the browser → removed (public client with PKCE);app.config.globalProperties.$authand the Options API →useAuth()and<script setup>;renewToken()→signinSilentCallback();/unauthenticated→ removed;Header.vue→AppHeader.vue,Links.vue→AppFooter.vue,User.vue→UserStatus.vue,Token.vue→TokenPanels.vue.Nuxt (keycloak-js, oidc-client-ts): #44
blog/2023-09-08-secure-nuxt.mdxanddocs/securing-applications/nuxt.md. All paths move underapp/(Nuxt 4).euc1.auth.acconfig →runtimeConfig.public(NUXT_PUBLIC_KEYCLOAK_*);nuxtApp.$keycloak =→provide;initwithsilentCheckSsoRedirectUri, PKCE and token refresh;composables/keycloak-c.ts→app/composables/useKeycloak.ts.services/auth-service.tswithclient_secret→app/plugins/oidc.client.ts, no secret;stores/auth/index.ts→app/stores/auth.ts(Pinia 4);useServices()→useAuthStore();pages/logout.vueremoved;KEYCLOAK_*env vars →NUXT_PUBLIC_OIDC_*.Angular: #44
blog/2024-08-01-secure-angular.mdxandtemplates/frameworks/_angular.mdx(L9–93):authCodeFlowConfig(/index.htmlredirect,offline_access, debug output) →src/app/auth/auth.config.tsplus environment files;provideAppInitializerandAuthService(signals);*ngIf→@if;user.component.ts→user-status/user-status.ts;UserActivation.component.ts.Next.js: #45
blog/2023-08-14-secure-nextjs.mdx(L63–111) anddocs/securing-applications/next.md(L10–58):src/lib/auth.ts(hardcodedreg-example-1) → env-basedsrc/auth.tswith token refresh, a claims-only session and Keycloak logout;NextAuth(authOptions);AuthProvider {...oidcConfig}React snippet and theSessionProvidersnippet;NEXTAUTH_SECRETis a random value, not the client secret;npm→pnpm.SvelteKit: #45
blog/2024-04-29-secure-sveltekit.mdxandtemplates/frameworks/_sveltekit.mdx(L9–84):SvelteKitAuth({ secret, providers: [Keycloak(kcConfig)] })→providers: [Keycloak], withAUTH_KEYCLOAK_*read automatically;jwt/session/eventscallbacks;event.locals.getSession()→event.locals.auth();export let data→$props();signIn/signOut→ form actions;usw2.auth.ac/shared-deployment-001values.React Router v7 (formerly Remix): #45
blog/2024-04-24-secure-remix.mdxandtemplates/frameworks/_remix.mdx(L1–50):KeycloakStrategy→OAuth2Strategy.discover(issuer, …)from remix-auth-oauth2;new Authenticator(sessionStorage)/isAuthenticated/logout→new Authenticator()plus a cookie session;KEYCLOAK_ISSUER_DOMAIN+KEYCLOAK_REALM→KEYCLOAK_ISSUER, plusSESSION_SECRET;/auth/signout→ POST/logoutwith Keycloak end-session;npm run dev -- --port 3000→pnpm dev.Django: #45
blog/2023-08-31-secure-django.mdxanddocs/securing-applications/django.md:cp .env.example .envand a venv step;OIDC_ISSUER, plusOIDC_USE_PKCE,OIDC_STORE_ID_TOKEN,OIDC_OP_LOGOUT_URL_METHODandOIDC_RP_SCOPES;mozilla_django_oidc.decorators(@oidc_protected,@oidc_logout) andrequest.oidc_userdo not exist in mozilla-django-oidc 5.0.2 → uselogin_required/LoginRequiredMixinand theoidc_logoutview;fragalysis.auth…→locallibrary.auth.KeycloakOIDCAuthenticationBackend;locallibrary/auth.py;http://localhost:8000/*, post logout+, no direct access grants.Multi-tenancy with Organizations: #44
blog/2024-11-11-multi-tenancy-with-organizations.md:*redirect URIs → the local Keycloak (--profile orgs) comes preconfigured; clients use PKCE withhttp://localhost:4200/*orhttp://localhost:4201/*;newyork, display name "New York");.env/.env.local;orgs.pngshows the old UI;Spring Boot + Angular: #46
blog/2024-05-09-secure-spring-boot.mdx:spring-boot-starter-security,spring-boot-starter-security-oauth2-resource-serverandspring-boot-starter-webmvc, plus the*-teststarters;com.example.spring-boot-keycloak), and the screenshot is outdated;demo-realmwith userstest/testandnoaccess/noaccess. The client is the publicdemo-spa(PKCE,http://localhost:4200/*, web origin and post-logout+), not the confidential client of_oidc_client_creation_client_auth.mdx. The non-admin user needs the realm roleuser;templates/frameworks/_springboot.mdx:${KEYCLOAK_ISSUER_URI:…}, dropsjwk-set-uri, and addsapp.cors.allowed-origins;src/main/java/com/example/springbootkeycloak;SecurityConfighas CORS, public/errorandGET /api/test/anonymous, andanyRequest().denyAll().@EnableWebSecurityand the constructor injection are gone;JwtClaimsConverteris no longer a@Componentand has no unchecked cast;TestControlleruses@GetMapping, returns JSON records, and/anonymousis public (the post says both endpoints need a token, which was a bug);APP_INITIALIZER/HttpClientModule/ localStorage /disablePKCE: true→ standaloneapp.config.tswithprovideOAuthClient,provideAppInitializer, PKCE and sessionStorage;npm run start→pnpm start;user.componentwith*ngIfand a guard that always returnedof(true)→homewith@if, API call buttons, and a functionalauthGuardon/protected.SAML IdP-initiated SSO: #46
blog/2025-02-25-saml-idp-initiated-flow.mdx:/auth. Point it to the example'sdocker compose up -d --wait, which runs Keycloak on 8080 withtest-realmimported. Hosted Phase Two URLs include/auth.okta-brokerclashes with the disabled placeholder the realm now contains. Readers edit it (entity ID, SSO URL, certificate, then enable it) or delete it first../scripts/generate-sp-credentials.shand start Keycloak before the SP. The SP serves its metadata at/saml2/metadata.saml-client.json, which is gone.keycloak/test-realm-export.json).http://localhost:8081/saml2/metadata, which also turns "Client signature required" on, and set the IdP-initiated SSO URL name tookta-client.http://localhost:8080/realms/test-realm/protocol/saml/clients/okta-client, usertest/test.okta-broker,okta-client,/login/saml2/sso,/saml2/metadata, the example link and the client screenshots.#service-provider-initated-flowand#identity-provider-initated-flow(L26–27) are misspelled;ACS", "a OIDC".Outside the tutorials
p2examplesrealm's login is fixed. Every valid login currently fails with "Unexpected error when handling authentication request to identity provider".