Scenario #9031: A Global Admin Can Synchronize a New User Subject

UseCase Synchronize Subject => SubjectSync: sync-alice

The external Keycloak sync program synchronizes a single subject through the UUID-keyed idempotent upsert PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path is the same UUID as in Keycloak. Creating a new subject returns 201 Created, updating an existing subject’s name returns 200 OK. Only a global-admin may synchronize subjects (others are rejected with 403), and only realm-prefixed names are accepted (others are rejected with 400).

Properties

Given

name value
subjectUuid 238a0001-0000-0000-0000-000000000001
subjectName sync-alice
subjectType USER

Synchronize (upsert) the subject via PUT

HTTP PUT "/api/rbac/subjects/238a0001-0000-0000-0000-000000000001" \
  -H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
  `# {` \
  `#   "sub" : "uuid<hsh-alex_superuser>"` \
  `# }` \
  -H 'Content-Type: application/json' \
  --data-binary @- <<EOF
{
  "name" : "sync-alice",
  "type" : "USER"
}
EOF
=> status: 201 CREATED 238a0001-0000-0000-0000-000000000001

generated on 2026-07-17 01:44:28 for branch