claims
module wittgenstein_oidc_backend.claims
Generic Keycloak claim extractors.
Only claim shapes generic to any Keycloak realm live here. Domain-specific readings of a claim (e.g. a tax-id-from-groups convention) are business logic for the consuming service, not this library.
Functions
-
get_roles — Realm roles (
realm_access.roles) — the only place Keycloak puts a role NAME in the token (see wittgenstein-core's own KEYCLOAK_KNOWN_ROLE_NAMES comment); permission strings for each name are a local concern of whoever maps roles to permissions. -
get_groups — Raw Keycloak group paths (e.g.
['/12345678901234']) — callers that need to derive something from a group name (like a tax-id-from-group convention) do that parsing themselves.
wittgenstein_oidc_backend.claims.get_roles
get_roles(payload: dict[str, Any]) → list[str]
Realm roles (realm_access.roles) — the only place Keycloak puts
a role NAME in the token (see wittgenstein-core's own
KEYCLOAK_KNOWN_ROLE_NAMES comment); permission strings for each name
are a local concern of whoever maps roles to permissions.
wittgenstein_oidc_backend.claims.get_groups
get_groups(payload: dict[str, Any]) → list[str]
Raw Keycloak group paths (e.g. ['/12345678901234']) — callers
that need to derive something from a group name (like a
tax-id-from-group convention) do that parsing themselves.