Skip to content

claims

module wittgenstein_oidc_backend.claims

Generic Keycloak claim extractors.

Only claim shapes generic to any Keycloak realm live here. Domain-specific readings of a claim (e.g. a tax-id-from-groups convention) are business logic for the consuming service, not this library.

Functions

  • get_roles — Realm roles (realm_access.roles) — the only place Keycloak puts a role NAME in the token (see wittgenstein-core's own KEYCLOAK_KNOWN_ROLE_NAMES comment); permission strings for each name are a local concern of whoever maps roles to permissions.

  • get_groups — Raw Keycloak group paths (e.g. ['/12345678901234']) — callers that need to derive something from a group name (like a tax-id-from-group convention) do that parsing themselves.

wittgenstein_oidc_backend.claims.get_roles

get_roles(payload: dict[str, Any]) → list[str]

Realm roles (realm_access.roles) — the only place Keycloak puts a role NAME in the token (see wittgenstein-core's own KEYCLOAK_KNOWN_ROLE_NAMES comment); permission strings for each name are a local concern of whoever maps roles to permissions.

wittgenstein_oidc_backend.claims.get_groups

get_groups(payload: dict[str, Any]) → list[str]

Raw Keycloak group paths (e.g. ['/12345678901234']) — callers that need to derive something from a group name (like a tax-id-from-group convention) do that parsing themselves.