Scenario #9045: A Group Organization Which Does Not Match the Group Name Prefix Is Rejected

The external Keycloak sync program synchronizes a single subject through the UUID-keyed idempotent PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path is the same UUID as in Keycloak. Creating a new subject returns 201 Created, updating an existing subject’s name returns 200 OK. Only a global-admin may synchronize subjects (others are rejected with 403). Without an explicit organization, only realm-prefixed names are accepted (others are rejected with 400) and the organization is derived from the name prefix. With an explicit organization, USER names are free except that they must not start with /; GROUP names must start with / directly followed by the organization, because JWTs reference groups just by name and thus the organization must stay derivable from it.

Properties

Given

name value
subjectUuid 239a0006-0000-0000-0000-000000000006
subjectName /example-Operators
organization xyz
subjectType GROUP

Synchronize the subject via HTTP PUT

HTTP PUT "/api/rbac/subjects/239a0006-0000-0000-0000-000000000006" \
  -H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
  `# {` \
  `#   "sub" : "uuid<hsh-alex_superuser>"` \
  `# }` \
  <<EOF
{
  "name" : "/example-Operators",
  "organization" : "xyz",
  "type" : "GROUP"
}
EOF
=> status: 400 BAD_REQUEST 
{
  "timestamp" : "2026-08-10 01:38:10",
  "path" : "",
  "statusCode" : 400,
  "statusPhrase" : "Bad Request",
  "message" : "ERROR: [400] Both (organization, organization derived from the group-name prefix) must be equal, but are (xyz, example)"
}

generated on 2026-08-10 01:38:10 for branch