Scenario #9032: A Global Admin Can Synchronize a New Group Subject

UseCase Synchronize Subject => SubjectSync: /sync-Team

The external Keycloak sync program synchronizes a single subject through the UUID-keyed idempotent upsert PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path is the same UUID as in Keycloak. Creating a new subject returns 201 Created, updating an existing subject’s name returns 200 OK. Only a global-admin may synchronize subjects (others are rejected with 403), and only realm-prefixed names are accepted (others are rejected with 400).

Properties

Given

name value
subjectUuid 238a0002-0000-0000-0000-000000000002
subjectName /sync-Team
subjectType GROUP

Synchronize (upsert) the subject via PUT

HTTP PUT "/api/rbac/subjects/238a0002-0000-0000-0000-000000000002" \
  -H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
  `# {` \
  `#   "sub" : "uuid<hsh-alex_superuser>"` \
  `# }` \
  -H 'Content-Type: application/json' \
  --data-binary @- <<EOF
{
  "name" : "/sync-Team",
  "type" : "GROUP"
}
EOF
=> status: 201 CREATED 238a0002-0000-0000-0000-000000000002

generated on 2026-07-17 01:44:28 for branch