Acosix Alfresco Keycloak
by Acosix GmbH
Community
Alfresco addon providing Keycloak-based authentication and authorisation for Repository and Share, including OIDC SSO, Bearer token auth, user/group sync, and back-channel logout.
About
Custom Keycloak authentication subsystem for Repository and Share (separate from Alfresco’s built-in identity-service).
Repository features:
- User+password login, Bearer token, and OIDC redirect authentication
- Mapping of person properties and authorities from Keycloak access tokens
- Back-channel logout and bulk token invalidation
- Active user/group synchronisation against Keycloak directory (including federated directories)
Share features:
- OIDC SSO redirect and login dialog enhancement
- OAuth 2.0 Token Exchange (RFC 8693) to delegate Share auth to Repository
- Share logout triggering Keycloak single sign-out
Compatible with Keycloak 6.0.1+. Version 1.2.0-rc1+ targets ACS 23.1+; earlier versions target ACS 6.0–7.4.