Lets say we have two realms:
- R1: consists resource confidential application and authorisation enable, which has policies defined at keyclock for authorisation. Authorisation is claim based regex policy. As shown in the screenshot
- R2: consists client application which creates token with defined claim.
Our requirement is if tokens created in R2 to be allowed in R1 using policy enforcer.
Error I am getting:
2024-07-09 08:57:31,150 WARN [org.keycloak.events] (executor-thread-153) type=PERMISSION_TOKEN_ERROR, realmId=46190167-c712-47bc-8d40-ae0980c08195, clientId=promotion-engine-be, userId=null, ipAddress=172.17.0.1, error=invalid_token, reason=’HTTP 500 Internal Server Error’, auth_method=oauth_credentials, audience=promotion-engine-be, grant_type=urn:ietf:params:oauth:grant-type:uma-ticket, permission=e17acf24-9b14-48b8-bb3e-f6cb3ab0ffa8#GET, client_auth_method=client-secret