kayx23 commented on issue #10319:
URL: https://github.com/apache/apisix/issues/10319#issuecomment-1872399278

   >  it seems that the "openid-connect" just allow all keycloak users without 
restricting roles.
   
   As for `openid-connect`, I played around but also wasn't able to make RBAC 
works. This might be of interest for you: 
https://github.com/zmartzone/lua-resty-openidc/issues/222
   
   Alternatively, you could implement scope based access with `required_scope`: 
https://github.com/apache/apisix/pull/10493


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to