Scenario #9034: A Non Global Admin Cannot Synchronize Subjects

The external Keycloak sync program synchronizes a single subject through the UUID-keyed idempotent PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path is the same UUID as in Keycloak. Creating a new subject returns 201 Created, updating an existing subject’s name returns 200 OK. Only a global-admin may synchronize subjects (others are rejected with 403). Without an explicit organization, only realm-prefixed names are accepted (others are rejected with 400) and the organization is derived from the name prefix. With an explicit organization, USER names are free except that they must not start with /; GROUP names must start with / directly followed by the organization, because JWTs reference groups just by name and thus the organization must stay derivable from it.

Properties

Given

name value
subjectUuid 238a0004-0000-0000-0000-000000000004
subjectName sync-eve
subjectType USER

Synchronize the subject via HTTP PUT

HTTP PUT "/api/rbac/subjects/238a0004-0000-0000-0000-000000000004" \
  -H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
  `# {` \
  `#   "comment" : "an authenticated user without the global-admin role",` \
  `#   "sub" : "uuid<tst-customer_admin_xxx>"` \
  `# }` \
  <<EOF
{
  "name" : "sync-eve",
  "type" : "USER"
}
EOF
=> status: 403 FORBIDDEN 
{
  "timestamp" : "2026-08-10 03:08:49",
  "path" : "",
  "statusCode" : 403,
  "statusPhrase" : "Forbidden",
  "message" : "ERROR: [403] only a global-admin may create or update subjects"
}

generated on 2026-08-10 03:08:49 for branch HEAD