Scenario #9044: A Group Subject Name Without a Leading Slash Is Rejected Despite an Explicit Organization

The external Keycloak sync program synchronizes a single subject through the UUID-keyed idempotent PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path is the same UUID as in Keycloak. Creating a new subject returns 201 Created, updating an existing subject’s name returns 200 OK. Only a global-admin may synchronize subjects (others are rejected with 403). Without an explicit organization, only realm-prefixed names are accepted (others are rejected with 400) and the organization is derived from the name prefix. With an explicit organization, USER names are free except that they must not start with /; GROUP names must start with / directly followed by the organization, because JWTs reference groups just by name and thus the organization must stay derivable from it.

Properties

Given

name value
subjectUuid 239a0005-0000-0000-0000-000000000005
subjectName example-Operators
organization example
subjectType GROUP

Synchronize the subject via HTTP PUT

HTTP PUT "/api/rbac/subjects/239a0005-0000-0000-0000-000000000005" \
  -H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
  `# {` \
  `#   "sub" : "uuid<hsh-alex_superuser>"` \
  `# }` \
  <<EOF
{
  "name" : "example-Operators",
  "organization" : "example",
  "type" : "GROUP"
}
EOF
=> status: 400 BAD_REQUEST 
{
  "timestamp" : "2026-08-10 01:38:10",
  "path" : "",
  "statusCode" : 400,
  "statusPhrase" : "Bad Request",
  "message" : "ERROR: [400] [GROUP subject name 'example-Operators' does not match required pattern]"
}

generated on 2026-08-10 01:38:10 for branch