Skip to content

Commit bdff688

Browse files
committed
log organization details
1 parent 23909aa commit bdff688

3 files changed

Lines changed: 46 additions & 11 deletions

File tree

‎backend/api/context.py‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
import asyncio
2+
import logging
23
from typing import Any
34

45
import strawberry
@@ -82,6 +83,11 @@ async def get_context(
8283
picture = user_payload.get("picture")
8384

8485
organizations_raw = user_payload.get("organization")
86+
logger = logging.getLogger(__name__)
87+
if organizations_raw:
88+
logger.info(f"Organization claim found for user {user_payload.get('sub', 'unknown')}: {organizations_raw}")
89+
else:
90+
logger.info(f"No organization claim found for user {user_payload.get('sub', 'unknown')}")
8591
organizations = None
8692
if organizations_raw:
8793
if isinstance(organizations_raw, list):

‎keycloak/README.md‎

Lines changed: 34 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -62,17 +62,40 @@ The organization scope should be included in the default client scopes for `task
6262

6363
### Adding Users to Organizations
6464

65-
To assign a user to one or more organizations:
66-
67-
1. Navigate to **Users** in the left sidebar
68-
2. Select the user you want to configure (or create a new user)
69-
3. Go to the **Attributes** tab
70-
4. Click **Add** to add a new attribute
71-
5. Set the **Key** to: `organization`
72-
6. Set the **Value** to a comma-separated list of organization IDs (e.g., `test-org-1,test-org-2`)
73-
7. Click **Save**
74-
75-
**Note**: The organization attribute is multivalued, so you can add multiple values. Each value should be a single organization ID. For multiple organizations, add them as separate attribute entries or use a comma-separated string.
65+
In newer versions of Keycloak (25+), the **Attributes** tab is hidden by default due to the Declarative User Profile feature. You have two options to add organization attributes to users:
66+
67+
#### Option 1: Enable Unmanaged Attributes (Shows Attributes Tab)
68+
69+
1. Navigate to **Realm Settings** in the left sidebar
70+
2. Go to the **User Profile** tab
71+
3. Toggle **Unmanaged Attributes** to **ON**
72+
4. Click **Save**
73+
5. Navigate to **Users** in the left sidebar
74+
6. Select the user you want to configure (or create a new user)
75+
7. Go to the **Attributes** tab (now visible)
76+
8. Click **Add** to add a new attribute
77+
9. Set the **Key** to: `organization`
78+
10. Set the **Value** to a comma-separated list of organization IDs (e.g., `test-org-1,test-org-2`)
79+
11. Click **Save**
80+
81+
#### Option 2: Configure via User Profile (Recommended for newer Keycloak versions)
82+
83+
1. Navigate to **Realm Settings** in the left sidebar
84+
2. Go to the **User Profile** tab
85+
3. Click **Create attribute** or find the **organization** attribute if it already exists
86+
4. Configure the attribute:
87+
- **Name**: `organization`
88+
- **Display name**: `Organization`
89+
- **Multivalued**: Enabled (to allow multiple organization values)
90+
- **Permissions**: Set as needed (e.g., **View** for users, **Edit** for admins)
91+
5. Click **Save**
92+
6. Navigate to **Users** in the left sidebar
93+
7. Select the user you want to configure (or create a new user)
94+
8. The **organization** field should now be visible in the user form
95+
9. If **Multivalued** is enabled, you will see multiple input boxes - enter one organization ID per box (e.g., `test-org-1` in the first box, `test-org-2` in the second box)
96+
10. Click **Save**
97+
98+
**Note**: When **Multivalued** is enabled, Keycloak provides separate input boxes for each organization value. You do not need to use comma-separated values. Each input box should contain a single organization ID. If **Multivalued** is disabled, you can use a comma-separated string in a single input box.
7699

77100
### Verifying Organization Claim in Tokens
78101

‎web/hooks/useTasksContext.tsx‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -172,6 +172,12 @@ export const TasksContextProvider = ({ children }: PropsWithChildren) => {
172172
setState(prevState => {
173173
let selectedRootLocationIds = prevState.selectedRootLocationIds || []
174174

175+
if (data?.me?.organizations) {
176+
console.log(`[Organization] User ${data.me.id} has organizations: ${data.me.organizations}`)
177+
} else {
178+
console.log(`[Organization] User ${data?.me?.id || 'unknown'} has no organizations`)
179+
}
180+
175181
if (rootLocations.length > 0 && selectedRootLocationIds.length === 0 && storedSelectedRootLocationIds.length === 0) {
176182
selectedRootLocationIds = [rootLocations[0]!.id]
177183
}

0 commit comments

Comments
 (0)