LV 1.1.8 — Identity- und Access-Management (Redaktion)
REQ-1.1.8-IAM
Proof level: TECHNICAL POC
Demonstrates
- ✓ real Authorization Code OIDC login against local Keycloak (no plugin — a custom OidcClient)
- ✓ Redakteur / Content-Creator roles mapped to distinct Craft permissions (saveEntries granted only to Redakteure — real publish-vs-draft-only enforcement, not cosmetic)
Mocked
- ◐ Sachsenforst Identity Provider (local Keycloak realm "nnl-editorial" used instead)
Pending external information
- ○ real IdP protocol, issuer, client registration, claims, role mapping
- ○ which Craft CMS edition (Team/Pro/Enterprise) the client licenses for production — this PoC runs in a trial edition locally to exercise User Groups/permissions
- ○ KNOWN GAP (not external — a build gap): Bieterfrage 35's official answer confirms a separate ADDRESS for the editorial area (e.g. redaktion.*) reachable only via the client's Keycloak is sufficient — it does not require a separate codebase/deployment. This MVP built /redaktion as a path on the same host, not a distinct subdomain, purely because a local dev stack has no wildcard DNS/vhost setup. The identity/permission logic itself (OidcClient, IdentityController, the group/permission model) is host-agnostic and reusable as-is; fronting it with a real redaktion.<domain> Ingress/vhost rule is a small, well-understood follow-up, not an architecture rewrite — but it is not yet built, so this requirement is not fully closed.
- ○ KNOWN GAP on the public demo host (decided: out of scope for the PoC, to be changed for development): the Craft control panel (/admin, username/password) is reachable on the same host as the public site. LV 1.1.8 / Bieterfrage 35 require the editorial area on a separate site behind the client's Keycloak. Planned: serve the CP only on a separate host (redaktion.*), block /admin on the public host.
Technical documentation
docs/integrations.md