Repository navigation
feat(admin): bind a keycloak account to an existing wallet - #612
Merged
dadiorchen merged 1 commit intoOct 7, 2026
Merged
Conversation
Legacy wallets carry no keycloak_account_id, and nothing could set one: it is written once at creation, from the caller's own JWT. Adds an admin read and a bind endpoint, both behind the wallet-admin role. Rebinding is allowed, and several wallets may share one account since Greenstand#590 dropped the UNIQUE constraint. Every bind writes a wallet_event, which needs a new value in the wallet_event_type enum.
This was referenced Oct 6, 2026
dadiorchen
reviewed
Oct 7, 2026
dadiorchen
approved these changes
Oct 7, 2026
|
🎉 This PR is included in version 1.44.0-keycloak.44 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of Greenstand/treetracker-admin-client#1241
Problem
Legacy wallets carry no
keycloak_account_id, and nothing could set one. It is written once at creation from the caller's own JWT (Wallet.js:35), andwalletPatchaccepts onlydisplay_name,aboutandadd_to_web_map.Change
Two endpoints on the admin router, both behind the
wallet-adminrole:The list endpoint does not select
keycloak_account_id, so the detail read is new rather than a filter on the list.Per the agreement on the issue: rebinding an already bound wallet is allowed, several wallets may share one account since #590 dropped the UNIQUE constraint, and every bind writes a
wallet_event.Migration
wallet_event.typeis a Postgres enum, so the new event value needsALTER TYPE ... ADD VALUE. The down migration is a no-op: Postgres cannot remove a value from an enum.Verification
7 new integration tests in
__tests__/admin-bind-keycloak-account.spec.js, covering the read, the bind, rebinding, two wallets sharing an account, a non-uuid body, a missing wallet, and a caller without the role.247 unit and 136 integration tests pass. eslint clean.
Next
The admin panel side is #1241 proper: a keycloak user search so the admin picks an account by email instead of pasting a uuid, and the wallet detail page with the bind dialog.