Hi @jive,
thanks a lot for the reply. This sounds great and we’ll test with the new release candidate as soon as possible.
One thing we’ll be missing from the current implementation is the Keycloak role service. Synchronizing Keycloak’s available roles is the one missing puzzle piece to us as it’s not part of the OAuth spec and therefore not part of the OIDC module implementation. We’re thinking about keeping the Keycloak role service alive and porting it to GeoServer 3. If you have any alternatives in mind, I’ll be happy to know.
Thanks so much and best regards
André