Skip to content

feat(admin): bind a keycloak account to an existing wallet - #612

Merged
dadiorchen merged 1 commit into
Greenstand:keycloakfrom
samwel141:feat-bind-keycloak-account-1241
Oct 7, 2026
Merged

dadiorchen merged 1 commit into
Greenstand:keycloakfrom
samwel141:feat-bind-keycloak-account-1241

Conversation

@samwel141

Copy link
Copy Markdown
Collaborator

Part of Greenstand/treetracker-admin-client#1241

Problem

Legacy wallets carry no keycloak_account_id, and nothing could set one. It is written once at creation from the caller's own JWT (Wallet.js:35), and walletPatch accepts only display_name, about and add_to_web_map.

Change

Two endpoints on the admin router, both behind the wallet-admin role:

GET  /admin/wallets/:wallet_id                    wallet incl. keycloak_account_id
POST /admin/wallets/:wallet_id/keycloak-account   { keycloak_account_id }

The list endpoint does not select keycloak_account_id, so the detail read is new rather than a filter on the list.

Per the agreement on the issue: rebinding an already bound wallet is allowed, several wallets may share one account since #590 dropped the UNIQUE constraint, and every bind writes a wallet_event.

Migration

wallet_event.type is a Postgres enum, so the new event value needs ALTER TYPE ... ADD VALUE. The down migration is a no-op: Postgres cannot remove a value from an enum.

Verification

7 new integration tests in __tests__/admin-bind-keycloak-account.spec.js, covering the read, the bind, rebinding, two wallets sharing an account, a non-uuid body, a missing wallet, and a caller without the role.

247 unit and 136 integration tests pass. eslint clean.

Next

The admin panel side is #1241 proper: a keycloak user search so the admin picks an account by email instead of pasting a uuid, and the wallet detail page with the bind dialog.

Legacy wallets carry no keycloak_account_id, and nothing could set one:
it is written once at creation, from the caller's own JWT. Adds an
admin read and a bind endpoint, both behind the wallet-admin role.

Rebinding is allowed, and several wallets may share one account since
Greenstand#590 dropped the UNIQUE constraint. Every bind writes a wallet_event,
which needs a new value in the wallet_event_type enum.
@dadiorchen
dadiorchen merged commit 3c480f7 into Greenstand:keycloak Oct 7, 2026
1 check passed
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.44.0-keycloak.44 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants