August 20, 2014
java, javaee, JAX-RS, Keycloak, oauth, openid connect, opensource, REST, RESTEasy, security, SSO
Many bugs fixes and cleanup. Not much for features although we did add a ton of tooltips to the admin console. We’re getting very close to a final release and are still on schedule to release 2nd week on September.
See keycloak.org for links to download and documentation.
August 6, 2014
java, JAX-RS, jboss, Keycloak, oauth, openid connect, REST, security, SSO, wildfly
After a summer of multiple vacations from various team members, we’re finally ready to release Keycloak 1.0 Beta 4. There’s not a lot of new features in the release because we focused mainly on performance, creating new SPIs, refactoring code, improving usability, and lastly fixing bugs. 64 issues completed. As usually go to the main keycloak.org page to find download links and to browse our documentation, release notes, or view our screencast tutorials. Here are some of the highlights of the release:
- Server side memory cache for all UI pages.
- Cache-control settings for UI pages
- Server side cache for all backend metadata: realms, applications, and users.
- In-memory implementation for user sessions
- New Federation SPI. Gives you a lot of flexibility to federation external stores into Keycloak
- Improved LDAP/Active Directory support
- Token validation REST API
- Support for HttpServletRequest.logout()
- Lots and lots of bugs fixes and minor improvements
You should see a big performance increase with this release as everything is cachable in memory and the database can be fully bypassed.
1.0 Final is on the way!
What’s next for Keycloak? This month we will be focusing on resolving the remaining issues logged in Jira, improving our test coverage, and updating our documentation and screencasts. No new major features. We’ll have a RC release around 3rd week of August, then our first Final release 2nd week of September!
May 29, 2014
java, JAX-RS, Keycloak, oauth, openid connect, opensource, REST, security, SSO
Keycloak Beta-1 has been released! We’re edging closer to 1.0! Please visit the Keycloak website for links to documentation and downloads. A lot of hard work the last few months by Stian, Marek, myself and other contributors to bring you loads of new features and improvements:
- LDAP/Active Directory integration built on Picketlink. Thanks Marek!
- User Session management – can now view login IP address and which applications and oauth clients have open tokens. Works with any type of app too. Can view and manage sessions through user account pages or admin console
- Audit log for important events. Integration with admin console and ability to receive emails on certain events.
- Account log viewable in user account management pages
- Export database. Allows you to export a full dump of keycloak database into an encrypted file. Will help out tremendously to migrate between Keycloak versions.
- Authentication SPI. Allows you to plug in different mechanisms to retrieve and authenticate users.
- Theme support for the admin console and any sent email.
- Per-realm admin console. You can now designate a user within a realm that is an admin of that realm.
- Documented the Admin REST API finally. (Docs still kinda suck here)
- CORS support for Admin REST API
- Support for relative URLs when configuring admin console
- Server configuration file
- Social Only Logins
- Installed application adapter
- Expanded the number of example projects
What’s next? This is the last major feature release of Keycloak. We will now be focusing on performance, clustering, security audits, testing, documentation, and usability for the next few releases. We hope to release 1.0 Final sometime in July.
January 23, 2014
jboss, Keycloak, opensource, REST, security, SSO, wildfly
Keycloak is an SSO authentication server and appliance for securing web applications and RESTful web services. After 7 months of hard work, the Keycloak team (Bill Burke, Stian Thorgersen, Gabriel Cardoso, Viliam Rockai, Alexandre Mendonca, and Bolesław Dawidowicz) is proud to announce our first release, Alpha-1! There’s still a lot to do, but there’s a lot you of features you can try out. Besides written documentation, we’ve put together a bunch of video screencasts that you can view to learn and experience the features of Keycloak.
These are some of the core feature of Keycloak:
- SSO and Single Log Out for browser applications
- Social Broker. Enable Google, Facebook, Yahoo, Twitter social login with no code required.
- Openshift Quick Start so you can deploy Keycloak on the cloud
- Optional User Registration
- Password and TOTP support (via Google Authenticator). Client cert auth coming soon.
- Forgot password management
- OAuth Bearer token auth for REST Services
- Integrated Browser App to REST Service token propagation
- OAuth Bearer token auth for REST Services
- OAuth 2.0 Grant requests
- CORS Support
- CORS Web Origin management and validation
- Completely centrally managed user and role mapping metadata. Minimal configuration at the application side
- Admin Console for managing users, roles, role mappings, applications, user sessions, allowed CORS web origins, and OAuth clients.
- Deployable as a WAR, appliance, or on Openshift.
- Supports JBoss AS7, EAP 6.x, and Wildfly applications. Plans to support Node.js, RAILS, GRAILS, and other non-Java application
Go to the Keycloak website and follow the links to download, view documentation and videos, browse our source code, and submit bugs.
As I said before, there’s still a lot to do, but here’s some things that will get in sooner rather than later:
- Stan Silvert has written a Wildfly subsystem for Keycloak that didn’t get into the Alpha 1 release. When we get this in, it will be super easy to secure web applications within a Wildfly environment. You won’t have to crack open your WARs to add Keycloak configuration and enabling Keycloak security may be as easy as a doing a few clicks in the admin console.
- Storage protection. We’ll be adding support for more secure password hashing as well as storage encryption capabilities for the Keycloak database. Its uber important to be able to have a 2nd level of defense for hacks.
- Revocation policies. We need to be able to expire all tokens just in case somebody gets hacked and broadcast this information to deployed applications.
- User session management. This will allow you to view which users are logged in and give you the ability to log out one or more users.
- Composite roles. This will be the concept of a role group. This will make it easier to change role mappings for a large set of users.
Finally, I want to give a huge thank you to everybody that helped make this release possible (Stian Thorgersen, Gabriel Cardoso, Viliam Rockai, Alexandre Mendonca, and Bolesław Dawidowicz). Especially Stian for being such a great co-lead and Gabriel for doing such awesome design work. This has been the best team I’ve been on since the good old JBoss Group days years and years ago, pre-aquisition when JBoss was young.
November 12, 2013
java, javaee, JAX-RS, REST
My 2nd edition of RESTful Java is out! RESTful Java with JAX-RS 2.0 covers the spec additions to JAX-RS 2.0 including 3 new chapters:
- JAX-RS 2.0 Client API
- Asynchronous Client and Server APIs
- Filters and Interceptors
The book has also been revised here and there to cover some of the smaller features that were added to JAX-RS 2.0 like ParamConverters, Link, an the extensions added to UriBuilder. The workbook examples and chapters have been revised and expanded to cover this new content as well, so you really get 6 new chapters in total. Many thanks to Fernando Nasser, Melanie Yarborough, Meghan Blanchette, Meghan Connolly, and Charlie Roumeliotis for making this happen. I’d also like to thank the JAX-RS 2.0 JSR Expert Group, especially Marek Potociar, Santiago Pericas-Geertsen, and Sergey Beryozkin.
June 18, 2013
java, javaee, JAX-RS, REST, RESTEasy
Resteasy 3.0 has been released, follow links on the Resteasy web page to find downloads etc. After sitting on the JAX-RS 2.0 JSR for two years and implementing it in the Resteasy master branch we’re finally ready to release! I’d like to first thank the JAX-RS 2.0 JSR especially Marek, Santiago, and Sergey. We butted heads a lot on the JSR and I could be difficult at times, but I think JAX-RS 2.0 is a great spec because of it. I’d also like to thank Weinan Li, Ron Sigal, and Gunnar Morling for fixing bugs and getting Bean Validation integration working in the last minute.
It is really really really important that you read the migration guide. We had to change a bunch of stuff and behavior because the JAX-RS 2.0 got really strict, specifically the request dispatch algorithm, so you really need to view it. We also refactored some SPIs and such. So, again, read the migration guide!
- JAX-RS 2.0 compliance. Once Wildfly supports HTTP Digest Authentication we can officially certify Resteasy 3.0.Final. Since this is really just red tape, I decided to release 3.0 now instead of waiting, weeks for another Wildfly release.
- SSO and OAuth2 for browser and RESTful web services. Built to work on AS7 and EAP 6.1, allows you to add these features on top of existing AS7 security domains
- Bean Validation 1.1. integration support
- More comprehensive generics support for all component types
JAX-RS 2.0 standardized many features that existed in Resteasy 2.3.x and earlier. Going forward we will not support these deprecated APIs in Resteasy 3.0. They are there to ease your migration from proprietary Resteasy APIs to the JAX-RS 2.0 equivalent. If you have a bug, you need to either provide a patch/pull request yourself, or upgrade to the JAX-RS 2.0 equivalent API. As soon as Resteasy 3.0 gets into our commercial distribution, we will be removing these deprecated APIs from Resteasy, so you should switch sooner rather than later.
- Resteasy Client API org.jboss.resteasy.client.ClientRequest etc. Proxy API has been ported to work on top of JAX-RS 2.0 api.
- Resteasy interceptor framework: MessageBodyReaderInterceptor, MessageBodyWriterIntereptor, PostProcessorInterceptor, etc… These all have JAX-RS 2.0 equivalents
- Resteasy async API. This also has a JAX-RS 2.0 equivalent
Next few months we’ll be focusing on some point releases to mature 3.0. I’ll also be finishing a revision of my O’Reilly JAX-RS book and you’ll see some new workbook examples in the distribution soon. I’m also starting a new project that is going to pull in the OAuth2 work I’ve done. More on that later though. As for future Resteasy features, I’m looking for somebody to drive a RESTful database service interface. If you’re interested, please ping me or our development list.
May 7, 2013
JAX-RS, REST, RESTEasy
Did a bit of refactoring of the SPIs to improve generics support among other bug fixes. A side effect to this is that there is now a programmatic interface that allows you to register un-annotated resource classes. Also, bumped Jackson to 1.9.12 and also added an additional Jackson2 provider. See docs for more details.