{"id":23013,"date":"2019-09-06T12:00:02","date_gmt":"2019-09-06T03:00:02","guid":{"rendered":"https:\/\/www.techscore.com\/blog\/?p=23013"},"modified":"2019-09-05T17:10:20","modified_gmt":"2019-09-05T08:10:20","slug":"keycloak-oauth-2-0-token-exchange","status":"publish","type":"post","link":"https:\/\/www.techscore.com\/blog\/2019\/09\/06\/keycloak-oauth-2-0-token-exchange\/","title":{"rendered":"Keycloak \u3067 OAuth 2.0 Token Exchange \u3092\u8a66\u3057\u3066\u307f\u308b"},"content":{"rendered":"<h1>OAuth 2.0 Token Exchange \u306e\u6982\u8981<\/h1>\n<p>\u30de\u30a4\u30af\u30ed\u30b5\u30fc\u30d3\u30b9\u30d1\u30bf\u30fc\u30f3\u3067\u306f\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u547c\u3073\u51fa\u3057\u3066\u3044\u308b API \u306f\u3001\u5b9f\u969b\u306b\u306f API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u7d4c\u7531\u3067\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 API \u3092\u547c\u3073\u51fa\u3059\u3053\u3068\u3067\u8981\u6c42\u3059\u308b\u51e6\u7406\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u4e00\u822c\u7684\u3067\u3059\u3002<\/p>\n<p>API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u306f\u5927\u62b5\u306e\u5834\u5408\u3001 OAuth 2.0 \u3084 OpenID Connect \u306b\u3088\u3063\u3066\u4fdd\u8b77\u3055\u308c\u307e\u3059\u3002<br \/>\n\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u4fdd\u8b77\u3055\u308c\u305f API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u3068\u901a\u4fe1\u3057\u3001\u3055\u3089\u306b\u305d\u306e\u5148\u306e\u4ed6\u306e\u4fdd\u8b77\u3055\u308c\u305f\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 API \u3068\u3084\u308a\u53d6\u308a\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u5834\u5408\u306b\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304c\u5229\u7528\u3057\u3066\u3044\u308b OAuth \u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u305d\u306e\u307e\u307e\u518d\u5229\u7528\u3057\u3066\u3057\u307e\u3046\u3068\u3001 \u672c\u6765 API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u3092\u4fdd\u8b77\u5bfe\u8c61\u3068\u3059\u308b\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 API \u304c\u53d7\u3051\u5165\u308c\u308b\u5fc5\u8981\u304c\u3042\u308a\u3001\u3042\u307e\u308a\u826f\u3044\u3068\u306f\u8a00\u3048\u307e\u305b\u3093\u3002<\/p>\n<p>\u4e0a\u8a18\u306e\u554f\u984c\u3092\u89e3\u6c7a\u3059\u3079\u304f\u3001 <a href=\"https:\/\/tools.ietf.org\/wg\/oauth\/\">OAuth \u30ef\u30fc\u30ad\u30f3\u30b0\u30b0\u30eb\u30fc\u30d7<\/a>\u3067\u306f\u3001<a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-19\">OAuth 2.0 Token Exchange<\/a> \u3068\u547c\u3070\u308c\u308b\u4ed5\u69d8\u306e\u6a19\u6e96\u5316\u306b\u53d6\u308a\u7d44\u3093\u3067\u3044\u307e\u3059\u3002<\/p>\n<p>OAuth 2.0 Token Exchange \u306f\u3001\u3042\u308b API \u306b\u5bfe\u3059\u308b\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u3001\u5225\u306e API \u306b\u6e21\u3059\u305f\u3081\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c8\u30fc\u30af\u30f3\u3092 OAuth 2.0 \u8a8d\u53ef\u30b5\u30fc\u30d0\u3068\u3084\u308a\u3068\u308a\u3057\u3066\u53d6\u5f97\u3059\u308b\u65b9\u6cd5\u3092\u5b9a\u7fa9\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><img src=\"https:\/\/www.scottbrady91.com\/img\/oauth\/token-exchange.png\" alt=\"OAuthTokenExchangeExample\" width=\"700px\" \/><\/p>\n<p>\u4e0a\u8a18\u306f\u3001OAuth 2.0 Token Exchange \u306b\u304a\u3051\u308b\u5178\u578b\u7684\u306a\u30d5\u30ed\u30fc\u3092\u793a\u3059\u56f3\u3067\u3059\u3002<br \/>\n\uff08\u5f15\u7528: <a href=\"https:\/\/www.scottbrady91.com\/OAuth\/Delegation-Patterns-for-OAuth-20\">Delegation Patterns for OAuth 2.0(Scott Brady - Identity &amp; Access Control)<\/a>\uff09<\/p>\n<p>1.\u3000\u307e\u305a\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u3001 API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u306b\u5bfe\u3057\u3066 JWT \u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092 Bearer \u30d8\u30c3\u30c0\u3068\u3057\u3066\u4ed8\u4e0e\u3057\u3066\u3001API \u30b3\u30fc\u30eb\u3057\u307e\u3059\u3002<\/p>\n<p>2.\u3000API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u306f\u3001 STS (Security Token Service) \u306e\u30c8\u30fc\u30af\u30f3\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b\u5bfe\u3057\u3066\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u5f62\u5f0f\u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u4ea4\u63db\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u308a\u307e\u3059\u3002(\u898b\u3084\u3059\u3055\u306e\u305f\u3081 URL \u30a8\u30f3\u30b3\u30fc\u30c9\u3092\u5916\u3057\u305f\u5f62\u306b\u3057\u3066\u3044\u307e\u3059\uff09<br \/>\n<code>subject_token<\/code> \u306f API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u306b\u6a29\u9650\u59d4\u4efb\u3059\u308b\u5143\u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u6307\u5b9a\u3057\u3001<code>subject_token_type<\/code> \u306f\u305d\u306e\u30c8\u30fc\u30af\u30f3\u306e\u30bf\u30a4\u30d7\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002\uff08\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u306e\u5834\u5408\u306f\u3001<code>urn:ietf:params:oauth:token-type:access_token<\/code> \u3092\u6307\u5b9a\uff09<\/p>\n<pre class=\"decode:true\">    POST \/as\/token.oauth2 HTTP\/1.1\n    Host: as.example.com\n    Authorization: Basic cnMwODpsb25nLXNlY3VyZS1yYW5kb20tc2VjcmV0\n    Content-Type: application\/x-www-form-urlencoded\n\n    grant_type=urn:ietf:params:oauth:grant-type:token-exchange\n    &amp;resource=https:\/\/backend.example.com\/api\n    &amp;subject_token=accVkjcJyb4BWCxGsndESCJQbdFMogUC5PbRDqceLTC\n    &amp;subject_token_type=urn:ietf:params:oauth:token-type:access_token\n<\/pre>\n<p>3.\u3000STS \u306f\u3001 <code>backend.example.com<\/code> \u5411\u3051\u306e\u6a29\u9650\u59d4\u4efb\u3055\u308c\u305f\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u8fd4\u3057\u307e\u3059\u3002<\/p>\n<pre><code>HTTP\/1.1 200 OK\nContent-Type: application\/json\nCache-Control: no-cache, no-store\n\n{\n\"access_token\":\"eyJhbGciOiJFUzI1NiIsImtpZCI6IjllciJ9.eyJhdWQiOiJo\ndHRwczovL2JhY2tlbmQuZXhhbXBsZS5jb20iLCJpc3MiOiJodHRwczovL2FzLmV\n4YW1wbGUuY29tIiwiZXhwIjoxNDQxOTE3NTkzLCJpYXQiOjE0NDE5MTc1MzMsIn\nN1YiI6ImJkY0BleGFtcGxlLmNvbSIsInNjb3BlIjoiYXBpIn0.40y3ZgQedw6rx\nf59WlwHDD9jryFOr0_Wh3CGozQBihNBhnXEQgU85AI9x3KmsPottVMLPIWvmDCM\ny5-kdXjwhw\",\n\"issued_token_type\":\n\"urn:ietf:params:oauth:token-type:access_token\",\n\"token_type\":\"Bearer\",\n\"expires_in\":60\n}\n<\/code><\/pre>\n<p>4.\u3000API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u306f\u3001\u65b0\u3057\u304f\u53d6\u5f97\u3057\u305f\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092 Bearer \u30d8\u30c3\u30c0\u306b\u4ed8\u4e0e\u3057\u3066\u3001\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 API \u306b\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u4fe1\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"decode:true \">    GET \/api HTTP\/1.1\n    Host: backend.example.com\n    Authorization: Bearer eyJhbGciOiJFUzI1NiIsImtpZCI6IjllciJ9.eyJhdWQ\n       iOiJodHRwczovL2JhY2tlbmQuZXhhbXBsZS5jb20iLCJpc3MiOiJodHRwczovL2\n       FzLmV4YW1wbGUuY29tIiwiZXhwIjoxNDQxOTE3NTkzLCJpYXQiOjE0NDE5MTc1M\n       zMsInN1YiI6ImJkY0BleGFtcGxlLmNvbSIsInNjb3BlIjoiYXBpIn0.40y3ZgQe\n       dw6rxf59WlwHDD9jryFOr0_Wh3CGozQBihNBhnXEQgU85AI9x3KmsPottVMLPIW\n       vmDCMy5-kdXjwhw\n<\/pre>\n<p>\u6a29\u9650\u59d4\u4efb\u3055\u308c\u305f\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u306f JWT \u5f62\u5f0f\u3067\u3001\u305d\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u90e8\u5206\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<pre><code>{\n\"aud\":\"https:\/\/consumer.example.com\",\n\"iss\":\"https:\/\/issuer.example.com\",\n\"exp\":1443904177,\n\"nbf\":1443904077,\n\"sub\":\"user@example.com\",\n\"act\":\n{\n\"sub\":\"admin@example.com\"\n}\n}\n<\/code><\/pre>\n<p><a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-19#section-4.1\"><code>act\uff08actor\uff09<\/code> \u30af\u30ec\u30fc\u30e0<\/a>\u306f\u3001\u59d4\u4efb\u304c\u884c\u308f\u308c\u305f\u3053\u3068\u3092\u610f\u5473\u3059\u308b\u3082\u306e\u3067\u3059\u3002<br \/>\n\u4e0a\u8a18\u306e\u4f8b\u3067\u306f\u3001 <code>admin@example.com<\/code> \u304c\u3001 <code>user@example.com<\/code> \u306b\u4ee3\u308f\u3063\u3066\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 API \u3092\u5b9f\u884c\u3059\u308b\u3001\u3068\u3044\u3046\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<blockquote><p>\n  The outermost \"act\" claim represents the current actor while nested \"act\" claims represent &gt; prior actors.\n<\/p><\/blockquote>\n<p>\u3068\u3042\u308b\u3088\u3046\u306b\u3001 <code>act<\/code> \u30af\u30ec\u30fc\u30e0\u306f\u30cd\u30b9\u30c8\u3059\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u59d4\u4efb\u306e\u5c65\u6b74\u3092\u8868\u73fe\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u307e\u305f\u3001<a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-19#section-4.4\"><code>may_act<\/code> \u30af\u30ec\u30fc\u30e0<\/a> \u3068\u3044\u3046\u3082\u306e\u3082\u5b9a\u7fa9\u3055\u308c\u3066\u3044\u307e\u3059\u3002<br \/>\n\u3053\u306e\u30af\u30ec\u30fc\u30e0\u306f\u3001\u3042\u308b\u5f53\u4e8b\u8005\u304c\u5225\u306e\u5f53\u4e8b\u8005\u3068\u3057\u3066\u632f\u308b\u821e\u3046\u6a29\u9650\u3092\u4e0e\u3048\u3089\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u610f\u5473\u3057\u307e\u3059\u3002<\/p>\n<pre><code>{\n\"aud\":\"https:\/\/consumer.example.com\",\n\"iss\":\"https:\/\/issuer.example.com\",\n\"exp\":1443904177,\n\"nbf\":1443904077,\n\"sub\":\"user@example.com\",\n\"may_act\":\n{\n\"sub\":\"admin@example.com\"\n}\n}\n<\/code><\/pre>\n<p><code>act<\/code> \u30af\u30ec\u30fc\u30e0\u3068 <code>may_act<\/code> \u30af\u30ec\u30fc\u30e0\u306e\u9055\u3044\u304c\u5206\u304b\u308a\u306b\u304f\u3044\u3067\u3059\u304c\u3001<br \/>\n<code>act<\/code> \u30af\u30ec\u30fc\u30e0\u306f\u3001<code>user@example.com<\/code> \u306b\u4ee3\u308f\u3063\u3066\u3001<code>admin@example.com<\/code> \u3068\u3057\u3066 API \u3092\u5b9f\u884c\u3067\u304d\u308b\u3053\u3068\u3092\u793a\u3057\u3001<br \/>\n<code>may_act<\/code> \u30af\u30ec\u30fc\u30e0\u306f\u3001<code>admin@example.com<\/code> \u304c<code>user@example.com<\/code> \u306e\u6a29\u9650\u3067 API \u3092\u5b9f\u884c\u3067\u304d\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u308b\u3068\u79c1\u306f\u89e3\u91c8\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>Keycloak \u3067 OAuth 2.0 Token Exchange \u3092 \u8a66\u3057\u3066\u307f\u308b<\/h2>\n<p><a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-19\">OAuth 2.0 Token Exchange<\/a> \u306f\u307e\u3060\u30c9\u30e9\u30d5\u30c8\u7248\u3067\u3059\u304c\u3001 OSS \u306e\u30a2\u30a4\u30c7\u30f3\u30c6\u30a3\u30c6\u30a3\u30fb\u30a2\u30af\u30bb\u30b9\u7ba1\u7406\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3067\u3042\u308b <a href=\"https:\/\/www.keycloak.org\/\">Keycloak<\/a> \u3067\u5b9f\u88c5\u3055\u308c\u3066\u3044\u308b\u307f\u305f\u3044\u3067\u3059\u306e\u3067\u3001\u8a66\u3057\u3066\u307f\u307e\u3057\u305f\u3002<\/p>\n<p>\u4eca\u56de\u8a66\u3059\u30d5\u30ed\u30fc\u56f3\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002 Google \u304b\u3089\u767a\u884c\u3055\u308c\u305f\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u3001 Keycloak \u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u306b\u5909\u63db\u3057\u3066\u307f\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/OAuth2.0TokenExchangeExample.png\" rel=\"facebox\" rel=\"attachment wp-att-23092\"><img class=\"alignleft size-large wp-image-23092\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/OAuth2.0TokenExchangeExample-1024x708.png\" alt=\"\" width=\"700\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/OAuth2.0TokenExchangeExample-1024x708.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/OAuth2.0TokenExchangeExample-300x208.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/OAuth2.0TokenExchangeExample-768x531.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/OAuth2.0TokenExchangeExample.png 1106w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<h2>Google \u306e OAuth \u8a8d\u8a3c\u60c5\u5831\u53d6\u5f97<\/h2>\n<p>\u4ea4\u63db\u5143\u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u767a\u884c\u306f\u3001\u4eca\u56de\u306f Google \u3092\u5229\u7528\u3057\u3066\u8a66\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/console.developers.google.com\/apis\/dashboard\">Google Developer Console<\/a> \u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3001<br \/>\n\u307e\u305a\u306f\u3001\u300c OAuth \u540c\u610f\u753b\u9762\u300d\u306b\u3066\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u540d\u3068\u3001\u627f\u8a8d\u6e08\u307f\u30c9\u30e1\u30a4\u30f3\u3092\u5165\u529b\u3057\u307e\u3059\u3002<\/p>\n<p>\u203b \u627f\u8a8d\u6e08\u307f\u30c9\u30e1\u30a4\u30f3\u306f\u3001Google \u3068\u306e OpenID Connect Authrization Code \u30d5\u30ed\u30fc\u306b\u304a\u3051\u308b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URL \u306b\u6307\u5b9a\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URL \u306b\u5bfe\u3057\u3066 Authrization Code \u304c\u767a\u884c\u3055\u308c\u308b\u306e\u3067\u3001\u8a66\u3059\u5834\u5408\u3067\u3082\u5b9f\u5728\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u304c\u3084\u308a\u3084\u3059\u3044\u3067\u3057\u3087\u3046\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthConsent.png\" rel=\"facebox\" rel=\"attachment wp-att-23041\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23041\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthConsent-1024x716.png\" alt=\"\" width=\"530\" height=\"371\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthConsent-1024x716.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthConsent-300x210.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthConsent-768x537.png 768w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u6b21\u306b\u3001\u300c\u8a8d\u8a3c\u60c5\u5831\u300d\u306b\u3066\u3001 OAuth \u30af\u30e9\u30a4\u30a2\u30f3\u30c8 ID \u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<br \/>\n\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u7a2e\u985e\u306f\u300c\u30a6\u30a7\u30d6\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300d\u3092\u9078\u629e\u3057\u3001\u627f\u8a8d\u6e08\u307f\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URI \u3092\u5165\u529b\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthClient.png\" rel=\"facebox\" rel=\"attachment wp-att-23042\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23042\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthClient-975x1024.png\" alt=\"\" width=\"530\" height=\"557\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthClient-975x1024.png 975w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthClient-286x300.png 286w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthClient-768x807.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/GoogleOAuthClient.png 1354w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u30af\u30e9\u30a4\u30a2\u30f3\u30c8 ID \u3068\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30b7\u30fc\u30af\u30ec\u30c3\u30c8\u304c\u767a\u884c\u3055\u308c\u308b\u306e\u3067\u63a7\u3048\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/IssuedGoogleOAuthClient.png\" rel=\"facebox\" rel=\"attachment wp-att-23043\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23043\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/IssuedGoogleOAuthClient-1024x754.png\" alt=\"\" width=\"530\" height=\"390\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/IssuedGoogleOAuthClient-1024x754.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/IssuedGoogleOAuthClient-300x221.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/IssuedGoogleOAuthClient-768x566.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/IssuedGoogleOAuthClient.png 1032w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<h2>Keycloak \u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7<\/h2>\n<p>\u6b21\u306b Keycloak \u5074\u306e\u8a2d\u5b9a\u3092\u884c\u306a\u3063\u3066\u3044\u304d\u307e\u3059\u3002<br \/>\n\uff08\u4eca\u56de\u306f\u3001Keycloak \u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u8a18\u4e8b\u57f7\u7b46\u6642\u70b9(2019\/09)\u306e\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u3042\u308b7.0.0\u3067\u8a66\u3057\u3066\u3044\u307e\u3059\u3002)<\/p>\n<p>\u307e\u305a\u306f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/p>\n<pre><code>wget https:\/\/downloads.jboss.org\/keycloak\/7.0.0\/keycloak-7.0.0.tar.gz\ntar xvpf keycloak-7.0.0.tar.gz\nmv keycloak-7.0.0 keycloak\ncd keycloak\nvi bin\/standalone.sh\n<\/code><\/pre>\n<p>\u6b21\u306b <code>bin\/standalone.sh<\/code> \u306e\u4ee5\u4e0b\u306e\u884c\u3092\u4fee\u6b63\u3057\u307e\u3059\u3002<br \/>\n( Keycloak \u306e Token Exchange \u6a5f\u80fd\u306f\u30c6\u30af\u30ce\u30ed\u30b8\u30fc\u30d7\u30ec\u30d3\u30e5\u30fc\u7248\u306e\u305f\u3081\u3001\u5229\u7528\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u305f\u3081\u306b\u8d77\u52d5\u30aa\u30d7\u30b7\u30e7\u30f3\u3092\u4ed8\u4e0e\u3057\u3066\u3044\u307e\u3059\u3002\uff09<\/p>\n<pre><code># \u4fee\u6b63\u524d\nJAVA_OPTS=\"$PREPEND_JAVA_OPTS $JAVA_OPTS\"\n\u2193\u2193\u2193\n# \u4fee\u6b63\u5f8c\nJAVA_OPTS=\"$PREPEND_JAVA_OPTS $JAVA_OPTS -Dkeycloak.profile=preview\"\n<\/code><\/pre>\n<p>\u6b21\u306b Keycloak \u306e\u30e6\u30fc\u30b6\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/p>\n<pre><code>USER_ID=shirakawa.hiroaki\nUSER_PASSWORD=********\nbin\/add-user-keycloak.sh -r master -u ${USER_ID} -p ${USER_PASSWORD}\n<\/code><\/pre>\n<p><code>bin\/standalone.sh<\/code> \u3092\u5b9f\u884c\u3057\u3066\u3001 Keycloak \u3092\u8d77\u52d5\u3057\u307e\u3059\u3002<br \/>\n8080\u756a\u30dd\u30fc\u30c8\u3067 Keycloak \u306e\u7ba1\u7406\u753b\u9762\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u306e\u3067\u3001\u30d6\u30e9\u30a6\u30b6\u306b <code>http:\/\/localhost:8080\/auth\/admin<\/code> \u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3001\u5148\u307b\u3069\u767b\u9332\u3057\u305f\u30e6\u30fc\u30b6\u3067\u30ed\u30b0\u30a4\u30f3\u3057\u307e\u3059\u3002<br \/>\n\u30ed\u30b0\u30a4\u30f3\u6210\u529f\u3059\u308b\u3068\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u753b\u9762\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakLoginSucceeded.png\" rel=\"facebox\" rel=\"attachment wp-att-23051\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23051\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakLoginSucceeded-1024x452.png\" alt=\"\" width=\"530\" height=\"234\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakLoginSucceeded-1024x452.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakLoginSucceeded-300x132.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakLoginSucceeded-768x339.png 768w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u6b21\u306b\u3001Keycloak \u5074\u306e OAuth \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3092\u767b\u9332\u3057\u307e\u3059\u3002<\/p>\n<p>\u5de6\u5074\u306e\u30e1\u30cb\u30e5\u30fc\u306e <code>Clients<\/code> \u304b\u3089\u65b0\u898f\u767b\u9332\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakAddClient.png\" rel=\"facebox\" rel=\"attachment wp-att-23052\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23052\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakAddClient-1024x338.png\" alt=\"\" width=\"530\" height=\"175\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakAddClient-1024x338.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakAddClient-300x99.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakAddClient-768x253.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakAddClient.png 1456w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u30a2\u30af\u30bb\u30b9\u30bf\u30a4\u30d7\u304c Public \u3068\u306a\u3063\u3066\u3044\u308b\u305f\u3081\u3001 Confidential \u306b\u5909\u66f4\u3057\u307e\u3059\u3002<br \/>\n\u203b Valid Redirect URIs \u3092\u4e00\u3064\u4ee5\u4e0a\u767b\u9332\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u4f7f\u7528\u3057\u306a\u3044\u305f\u3081\u4eca\u56de\u306f\u9069\u5f53\u3067\u69cb\u3044\u307e\u305b\u3093\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakConfidential.png\" rel=\"facebox\" rel=\"attachment wp-att-23053\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23053\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakConfidential-1024x470.png\" alt=\"\" width=\"530\" height=\"243\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakConfidential-1024x470.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakConfidential-300x138.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakConfidential-768x352.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakConfidential.png 1678w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u30a2\u30af\u30bb\u30b9\u30bf\u30a4\u30d7\u3092 Confidential \u306b\u5909\u66f4\u3059\u308b\u3068\u3001 Credentials \u30bf\u30d6\u304c\u5897\u3048\u307e\u3059\u306e\u3067\u3001\u305d\u3053\u3067\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30b7\u30fc\u30af\u30ec\u30c3\u30c8\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakCredential.png\" rel=\"facebox\" rel=\"attachment wp-att-23057\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23057\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakCredential-1024x263.png\" alt=\"\" width=\"530\" height=\"136\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u6b21\u306b <code>Identity Provider<\/code> \u3092\u767b\u9332\u3057\u307e\u3059\u3002<br \/>\n\u3053\u3053\u3067\u5148\u307b\u3069\u306e Google OAuth \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u60c5\u5831\u3092\u8a2d\u5b9a\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakGoogleAddIdentityProvider.png\" rel=\"facebox\" rel=\"attachment wp-att-23062\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23062\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakGoogleAddIdentityProvider-1024x998.png\" alt=\"\" width=\"530\" height=\"517\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakGoogleAddIdentityProvider-1024x998.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakGoogleAddIdentityProvider-300x292.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakGoogleAddIdentityProvider-768x749.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakGoogleAddIdentityProvider.png 1418w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>Google OAuth \u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8 ID \u3068\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30b7\u30fc\u30af\u30ec\u30c3\u30c8\u3092\u5165\u529b\u3057\u3066\u4fdd\u5b58\u3059\u308b\u3068\u3001 Permission \u30bf\u30d6\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002<br \/>\nPermission \u3092 Enabled \u306b\u5909\u66f4\u3059\u308b\u3068\u3001<code>token-exchange<\/code> \u3068\u3044\u3046\u30b9\u30b3\u30fc\u30d7\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakIdentityProviderPermissionEnabled.png\" rel=\"facebox\" rel=\"attachment wp-att-23064\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23064\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakIdentityProviderPermissionEnabled-1024x217.png\" alt=\"\" width=\"530\" height=\"112\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakIdentityProviderPermissionEnabled-1024x217.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakIdentityProviderPermissionEnabled-300x64.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakIdentityProviderPermissionEnabled-768x163.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakIdentityProviderPermissionEnabled.png 1876w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p><code>token-exchange<\/code> \u3092\u30af\u30ea\u30c3\u30af\u3057\u3066\u3001 Token Exchange \u306e\u8a2d\u5b9a\u3092\u884c\u306a\u3044\u307e\u3059\u3002<\/p>\n<p><code>create policy<\/code> -&gt; <code>client<\/code> \u3092\u9078\u629e\u3057\u3066\u3001\u30dd\u30ea\u30b7\u30fc\u306e\u767b\u9332\u3092\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloackTokenExchangeCreatePolicy.png\" rel=\"facebox\" rel=\"attachment wp-att-23069\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23069\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloackTokenExchangeCreatePolicy-1024x527.png\" alt=\"\" width=\"530\" height=\"273\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloackTokenExchangeCreatePolicy-1024x527.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloackTokenExchangeCreatePolicy-300x154.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloackTokenExchangeCreatePolicy-768x395.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloackTokenExchangeCreatePolicy.png 1344w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p>\u3053\u3053\u3067\u5148\u307b\u3069\u767b\u9332\u3057\u305f Keycloak \u306e \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u3001 Google \u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3092\u7d10\u4ed8\u3051\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeCreateNewPolicy.png\" rel=\"facebox\" rel=\"attachment wp-att-23070\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23070\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeCreateNewPolicy-1024x493.png\" alt=\"\" width=\"530\" height=\"255\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeCreateNewPolicy-1024x493.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeCreateNewPolicy-300x145.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeCreateNewPolicy-768x370.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeCreateNewPolicy.png 1370w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeSave.png\" rel=\"facebox\" rel=\"attachment wp-att-23071\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-23071\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeSave-1024x576.png\" alt=\"\" width=\"530\" height=\"298\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeSave-1024x576.png 1024w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeSave-300x169.png 300w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeSave-768x432.png 768w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2019\/09\/KeycloakTokenExchangeSave.png 1308w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><br clear=\"all\" \/><\/a><\/p>\n<h2>\u4ea4\u63db\u3057\u3066\u307f\u308b<\/h2>\n<p>\u3053\u3053\u307e\u3067\u3067\u4e8b\u524d\u6e96\u5099\u5b8c\u4e86\u3067\u3059\u3002<br \/>\n\u5b9f\u969b\u306b\u8a66\u3057\u3066\u3044\u304d\u307e\u3057\u3087\u3046\u3002<\/p>\n<p>\u6700\u521d\u306b\u3001Google \u306e Authorization Code \u30d5\u30ed\u30fc\u3092\u5b9f\u884c\u3057\u3066\u3001Google \u304b\u3089\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002<br \/>\n\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u4ee5\u4e0b\u306e URL \u306b\u30a2\u30af\u30bb\u30b9\u3057\u307e\u3059\u3002(\u898b\u3084\u3059\u3055\u306e\u305f\u3081 URL \u30a8\u30f3\u30b3\u30fc\u30c9\u3092\u5916\u3057\u305f\u308a\u9069\u5b9c\u6539\u884c\u3092\u5165\u308c\u305f\u308a\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u5b9f\u969b\u306b\u306f\u6539\u884c\u3092\u5165\u308c\u305a\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u304f\u3060\u3055\u3044\uff09<\/p>\n<pre class=\"decode:true \">https:\/\/accounts.google.com\/o\/oauth2\/v2\/auth\n?client_id=[Google OAuth \u8a8d\u8a3c\u60c5\u5831\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8 ID]\n&amp;response_type=code\n&amp;scope=openid email\n&amp;state=138r5719ru3e1\n&amp;redirect_uri=[Google OAuth \u8a8d\u8a3c\u60c5\u5831\u306b\u767b\u9332\u3057\u305f\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URI ]\n<\/pre>\n<p>Google \u306e\u30ed\u30b0\u30a4\u30f3\u753b\u9762\u304c\u8868\u793a\u3055\u308c\u308b\u306e\u3067\u3001\u30ed\u30b0\u30a4\u30f3\u3059\u308b\u3068\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URI \u306b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3055\u308c\u307e\u3059\u3002<br \/>\n\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u5148\u3067\u8a8d\u53ef\u30b3\u30fc\u30c9\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3068\u601d\u3044\u307e\u3059\u3002(\u898b\u3084\u3059\u3055\u306e\u305f\u3081 URL \u30a8\u30f3\u30b3\u30fc\u30c9\u3092\u5916\u3057\u3066\u9069\u5b9c\u6539\u884c\u3092\u5165\u308c\u3066\u3044\u307e\u3059\uff09<\/p>\n<pre class=\"decode:true \">[\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URI]?state=138r5719ru3e1\n&amp;code=[\u8a8d\u53ef\u30b3\u30fc\u30c9]\n&amp;scope=email openid https:\/\/www.googleapis.com\/auth\/userinfo.email\n&amp;authuser=0\n&amp;hd=synergy101.jp\n&amp;session_state=5012174bf5befddcdee06e14276146ad6c63ede8..8a95\n&amp;prompt=consent\n<\/pre>\n<p>\u8a8d\u53ef\u30b3\u30fc\u30c9\u3092\u53d6\u5f97\u3067\u304d\u305f\u306e\u3067\u3001 Google \u306e\u30c8\u30fc\u30af\u30f3\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b curl \u3067\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u53d6\u5f97\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u308a\u307e\u3059\u3002<\/p>\n<pre><code>curl -H 'Content-Type:application\/x-www-form-urlencoded' \\\n-d \"code=[\u8a8d\u53ef\u30b3\u30fc\u30c9]\" \\\n-d \"client_id=[Google OAuth \u8a8d\u8a3c\u60c5\u5831\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8 ID]\" \\\n-d \"client_secret=[Google OAuth \u8a8d\u8a3c\u60c5\u5831\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30b7\u30fc\u30af\u30ec\u30c3\u30c8]\" \\\n-d \"redirect_uri=[Google OAuth \u8a8d\u8a3c\u60c5\u5831\u306b\u767b\u9332\u3057\u305f\u30ea\u30c0\u30a4\u30ec\u30af\u30c8 URI ]\" \\\n-d \"grant_type=authorization_code\" \\\nhttps:\/\/www.googleapis.com\/oauth2\/v4\/token\n<\/code><\/pre>\n<p>\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u5f97\u308b\u3053\u3068\u304c\u3067\u304d\u308c\u3070\u3001 Google \u304b\u3089\u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u53d6\u5f97\u6210\u529f\u3067\u3059\u3002<\/p>\n<pre><code>{\n\"access_token\": \"ya29...\",\n\"expires_in\": 3600,\n\"scope\": \"openid https:\/\/www.googleapis.com\/auth\/userinfo.email\",\n\"token_type\": \"Bearer\",\n\"id_token\": \"eyJh...\"\n}\n<\/code><\/pre>\n<p>\u3067\u306f\u3001 Google \u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092 Keycloak \u306e\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u306b\u4ea4\u63db\u3057\u3066\u307f\u307e\u3057\u3087\u3046\u3002<br \/>\ncurl \u3067\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u30c8\u30fc\u30af\u30f3\u4ea4\u63db\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u308a\u307e\u3059\u3002<\/p>\n<pre><code>curl -X POST \\\n-d \"client_id=[Keycloak \u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8 ID]\" \\\n-d \"client_secret=[Keycloak \u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30b7\u30fc\u30af\u30ec\u30c3\u30c8]\" \\\n--data-urlencode \"grant_type=urn:ietf:params:oauth:grant-type:token-exchange\" \\\n-d \"subject_token=ya29...\" \\\n-d \"subject_issuer=google\" \\\n--data-urlencode \"subject_token_type=urn:ietf:params:oauth:token-type:access_token\" \\\nhttp:\/\/localhost:8080\/auth\/realms\/master\/protocol\/openid-connect\/token\n<\/code><\/pre>\n<p>\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30ec\u30b9\u30dd\u30f3\u30b9\u304c\u8fd4\u3063\u3066\u304d\u307e\u3059\u3002<\/p>\n<pre><code>{\n\"access_token\": \"eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJiU1Nka05FMjNfUkNzMXlaUzJOdkJJNnJQTHpmZXlsSGtheHNwNlAzd3hZIn0.eyJqdGkiOiJiMmE1MmVjMS1jMTY1LTQ0NGItOGNhNC02YzkwNDU1N2YyODYiLCJleHAiOjE1Njc1MDQ3ODcsIm5iZiI6MCwiaWF0IjoxNTY3NTA0NzI3LCJpc3MiOiJodHRwOi8vbG9jYWxob3N0OjgwODAvYXV0aC9yZWFsbXMvbWFzdGVyIiwiYXVkIjoiYWNjb3VudCIsInN1YiI6ImMwNDIwNWQxLTBlNmMtNDFjMy04NTkzLTFkYmZhNGZkZjdlMyIsInR5cCI6IkJlYXJlciIsImF6cCI6InRhcmdldGNsaWVudCIsImF1dGhfdGltZSI6MCwic2Vzc2lvbl9zdGF0ZSI6IjI5MTI2ZWRkLWQyZWYtNDkwMS05NzU5LTdjNTM1MzFlODNiOCIsImFjciI6IjEiLCJyZWFsbV9hY2Nlc3MiOnsicm9sZXMiOlsib2ZmbGluZV9hY2Nlc3MiLCJ1bWFfYXV0aG9yaXphdGlvbiJdfSwicmVzb3VyY2VfYWNjZXNzIjp7ImFjY291bnQiOnsicm9sZXMiOlsibWFuYWdlLWFjY291bnQiLCJtYW5hZ2UtYWNjb3VudC1saW5rcyIsInZpZXctcHJvZmlsZSJdfX0sInNjb3BlIjoicHJvZmlsZSBlbWFpbCIsImVtYWlsX3ZlcmlmaWVkIjpmYWxzZSwibmFtZSI6IueZveW3neWkp-aclyIsInByZWZlcnJlZF91c2VybmFtZSI6InNoaXJha2F3YS5oaXJvYWtpQHN5bmVyZ3kxMDEuanAiLCJnaXZlbl9uYW1lIjoi55m95bed5aSn5pyXIiwiZW1haWwiOiJzaGlyYWthd2EuaGlyb2FraUBzeW5lcmd5MTAxLmpwIn0.FgSMLzt3qRRI7i6paCATZWQIw6fChWwwooYeH4skcXHrSeuV2Ovhn1oWwtet6gme9j8kaVjv0BsDCjJzfeFFcPrVVv3O_sj4OLvCZ7Y_u2H51XfaqqB_gAwukutxbCBF6eoNdsFguoHHEdQ_ikmxxSm5-s68BA74xU3VTa65_FNYOXARlAj28GDlpf6A_Fo6xfLJ19cwbhGlsoroNu_IFoI18dZfx3bDnFQ2L7XPzsNw_XHT31YlDXjnegBzc-E_tSAqKYV8sur6hi2p3Hg7z_eH0GpaGScYRgGu6iDMXlRFXO3hJNqcd7uQ4332xDTaXlnmVPdhdSVIumTgFsl3CQ\",\n\"expires_in\": 60,\n\"refresh_expires_in\": 1800,\n\"refresh_token\": \"eyJhbGciOiJIUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICIyNTFjMWNlNy1kZjNjLTRiNDYtOTRiNC04MWVlN2M4MGYyYWUifQ.eyJqdGkiOiJiM2RhNGE0NC0wZGU5LTRkNzMtYjcxNi0xYjE2ZWRkYzQwNWMiLCJleHAiOjE1Njc1MDY1MjcsIm5iZiI6MCwiaWF0IjoxNTY3NTA0NzI3LCJpc3MiOiJodHRwOi8vbG9jYWxob3N0OjgwODAvYXV0aC9yZWFsbXMvbWFzdGVyIiwiYXVkIjoiaHR0cDovL2xvY2FsaG9zdDo4MDgwL2F1dGgvcmVhbG1zL21hc3RlciIsInN1YiI6ImMwNDIwNWQxLTBlNmMtNDFjMy04NTkzLTFkYmZhNGZkZjdlMyIsInR5cCI6IlJlZnJlc2giLCJhenAiOiJ0YXJnZXRjbGllbnQiLCJhdXRoX3RpbWUiOjAsInNlc3Npb25fc3RhdGUiOiIyOTEyNmVkZC1kMmVmLTQ5MDEtOTc1OS03YzUzNTMxZTgzYjgiLCJyZWFsbV9hY2Nlc3MiOnsicm9sZXMiOlsib2ZmbGluZV9hY2Nlc3MiLCJ1bWFfYXV0aG9yaXphdGlvbiJdfSwicmVzb3VyY2VfYWNjZXNzIjp7ImFjY291bnQiOnsicm9sZXMiOlsibWFuYWdlLWFjY291bnQiLCJtYW5hZ2UtYWNjb3VudC1saW5rcyIsInZpZXctcHJvZmlsZSJdfX0sInNjb3BlIjoicHJvZmlsZSBlbWFpbCJ9.FRiA5EZwZpX8Vopqts8RH1l5NaPFYDlnQaSoPvkvoOc\",\n\"token_type\": \"bearer\",\n\"not-before-policy\": 0,\n\"session_state\": \"29126edd-d2ef-4901-9759-7c53531e83b8\",\n\"scope\": \"profile email\"\n}\n<\/code><\/pre>\n<p>\u767a\u884c\u3055\u308c\u305f\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u90e8\u5206\u306f\u3053\u3093\u306a\u611f\u3058\u3067\u3059\u3002<br \/>\n\u5148\u8ff0\u3057\u305f <code>act<\/code> \u30af\u30ec\u30fc\u30e0\u3084\u3001<code>may_act<\/code> \u30af\u30ec\u30fc\u30e0\u304c\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u4e2d\u306b\u73fe\u308c\u3066\u3053\u306a\u3044\u3067\u3059\u306d\u3002<\/p>\n<pre><code>{\n\"jti\": \"b2a52ec1-c165-444b-8ca4-6c904557f286\",\n\"exp\": 1567504787,\n\"nbf\": 0,\n\"iat\": 1567504727,\n\"iss\": \"http:\/\/localhost:8080\/auth\/realms\/master\",\n\"aud\": \"account\",\n\"sub\": \"c04205d1-0e6c-41c3-8593-1dbfa4fdf7e3\",\n\"typ\": \"Bearer\",\n\"azp\": \"targetclient\",\n\"auth_time\": 0,\n\"session_state\": \"29126edd-d2ef-4901-9759-7c53531e83b8\",\n\"acr\": \"1\",\n\"realm_access\": {\n\"roles\": [\n\"offline_access\",\n\"uma_authorization\"\n]\n},\n\"resource_access\": {\n\"account\": {\n\"roles\": [\n\"manage-account\",\n\"manage-account-links\",\n\"view-profile\"\n]\n}\n},\n\"scope\": \"profile email\",\n\"email_verified\": false,\n\"name\": \"\u767d\u5ddd\u5927\u6717\",\n\"preferred_username\": \"shirakawa.hiroaki@synergy101.jp\",\n\"given_name\": \"\u767d\u5ddd\u5927\u6717\",\n\"email\": \"shirakawa.hiroaki@synergy101.jp\"\n}\n<\/code><\/pre>\n<p><code>act<\/code> \u30af\u30ec\u30fc\u30e0\u3084\u3001<code>may_act<\/code> \u30af\u30ec\u30fc\u30e0\u304c\u30da\u30a4\u30ed\u30fc\u30c9\u306e\u4e2d\u306b\u73fe\u308c\u3066\u3044\u306a\u3044\u7406\u7531\u3067\u3059\u304c\u3001<a href=\"https:\/\/keycloak-documentation.openstandia.jp\/master\/ja_JP\/securing_apps\/index.html#_token-exchange\">Keyclock \u306e\u30b5\u30fc\u30d3\u30b9\u30ac\u30a4\u30c9<\/a> (<a href=\"https:\/\/www.keycloak.org\/docs\/latest\/securing_apps\/index.html#_token-exchange\">\u539f\u6587<\/a>) \u306e\u4ee5\u4e0b\u5f15\u7528\u306b\u3042\u308b\u901a\u308a\u3001 OAuth Token Exchange \u306e\u4ed5\u69d8\u3092\u7121\u8996\u3057\u3066\u3044\u308b\u305f\u3081\u3060\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n<blockquote><p>\n  Keycloak\u306eToken Exchange\u306f\u3001 OAuth Token Exchange \u306e\u4ed5\u69d8\u306e\u975e\u5e38\u306b\u30eb\u30fc\u30ba\u306a\u5b9f\u88c5\u3067\u3059\u3002<br \/>\n  Keycloak\u3067\u306f\u3001\u305d\u308c\u3092\u5c11\u3057\u62e1\u5f35\u3057\u3001\u4e00\u90e8\u3092\u7121\u8996\u3057\u3001\u4ed5\u69d8\u306e\u4ed6\u306e\u90e8\u5206\u3092\u30eb\u30fc\u30ba\u306b\u89e3\u91c8\u3057\u307e\u3057\u305f\u3002\n<\/p><\/blockquote>\n<h2>\u7d42\u308f\u308a\u306b<\/h2>\n<p><a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-19\">OAuth 2.0 Token Exchange<\/a> \u81ea\u4f53\u304c\u30c9\u30e9\u30d5\u30c8\u3067\u3042\u308b\u70b9\u3001\u307e\u305f Keycloak \u304c\u5b9f\u88c5\u3057\u3066\u3044\u308b\u4ed5\u69d8\u306f OAuth Token Exchange \u306e\u4ed5\u69d8\u306e\u4e00\u90e8\u3092\u7121\u8996\u3057\u305f\u308a\u3057\u3066\u3044\u308b\u70b9\u304b\u3089\u3001\u5b9f\u7528\u30ec\u30d9\u30eb\u306b\u306f\u307e\u3060\u307e\u3060\u9060\u3044\u5370\u8c61\u3067\u3059\u3002<br \/>\n\u73fe\u72b6\u3067\u3053\u306e\u3088\u3046\u306a\u5404\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u304b\u3089\u306e\u6a29\u9650\u59d4\u4efb\u3092\u884c\u306a\u3046\u5834\u5408\u306f\u3001\u4f55\u3089\u304b\u306e\u65b9\u6cd5\u3067\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u306e\u4ea4\u63db\u306e\u4ed5\u7d44\u307f\u3092\u81ea\u524d\u3067\u5b9f\u88c5\u3059\u308b\u3057\u304b\u306a\u3044\u3067\u3057\u3087\u3046\u3002<br \/>\n\u3057\u304b\u3057\u3001\u5916\u90e8\u3067\u767a\u884c\u3055\u308c\u305f\u30a2\u30af\u30bb\u30b9\u30c8\u30fc\u30af\u30f3\u3092\u5185\u90e8\u5411\u3051 API \u7528\u306b\u4ea4\u63db\u3067\u304d\u308b\u306e\u306f\u9b45\u529b\u7684\u306a\u306e\u3067\u3001\u3053\u308c\u304b\u3089\u8b70\u8ad6\u304c\u9032\u307f\u4ed5\u69d8\u304c\u6a19\u6e96\u5316\u3055\u308c\u3066\u3001\u69d8\u3005\u306a OAuth \/ OpenID Connect \u306e\u30d7\u30ed\u30c0\u30af\u30c8\u3067\u5b9f\u88c5\u3055\u308c\u308b\u3088\u3046\u306b\u306a\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>\u6700\u5f8c\u306b\u7406\u89e3\u306e\u52a9\u3051\u3068\u306a\u308b\u53c2\u8003\u6587\u732e\u3092\u8f09\u305b\u3066\u304a\u304d\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-oauth-token-exchange-19\">OAuth 2.0 Token Exchange draft-ietf-oauth-token-exchange-19<\/a><\/li>\n<li><a href=\"https:\/\/www.scottbrady91.com\/OAuth\/Delegation-Patterns-for-OAuth-20\">Delegation Patterns for OAuth 2.0<\/a><\/li>\n<li><a href=\"https:\/\/keycloak-documentation.openstandia.jp\/master\/ja_JP\/server_installation\/index.html\">Server Installation and Configuration Guide(Keycloak)<\/a><\/li>\n<li><a href=\"https:\/\/keycloak-documentation.openstandia.jp\/master\/ja_JP\/securing_apps\/index.html\">Securing Applications and Services Guide(Keycloak)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>OAuth 2.0 Token Exchange \u306e\u6982\u8981<\/p>\n<p>\u30de\u30a4\u30af\u30ed\u30b5\u30fc\u30d3\u30b9\u30d1\u30bf\u30fc\u30f3\u3067\u306f\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u547c\u3073\u51fa\u3057\u3066\u3044\u308b API \u306f\u3001\u5b9f\u969b\u306b\u306f API \u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u7d4c\u7531\u3067\u30d0\u30c3\u30af\u30a8\u30f3\u30c9 A<br \/><a href=\"https:\/\/www.techscore.com\/blog\/2019\/09\/06\/keycloak-oauth-2-0-token-exchange\/\">\u7d9a\u304d\u3092\u8aad\u3080...<\/a><\/p>\n","protected":false},"author":40,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[18],"tags":[328,327,325],"_links":{"self":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts\/23013"}],"collection":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/comments?post=23013"}],"version-history":[{"count":50,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts\/23013\/revisions"}],"predecessor-version":[{"id":23136,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts\/23013\/revisions\/23136"}],"wp:attachment":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/media?parent=23013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/categories?post=23013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/tags?post=23013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}