Scenario #9034: A Non Global Admin Cannot Synchronize Subjects

The external Keycloak sync program synchronizes a single subject through the UUID-keyed idempotent upsert PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path is the same UUID as in Keycloak. Creating a new subject returns 201 Created, updating an existing subject’s name returns 200 OK. Only a global-admin may synchronize subjects (others are rejected with 403), and only realm-prefixed names are accepted (others are rejected with 400).

Properties

Given

name value
subjectUuid 238a0004-0000-0000-0000-000000000004
subjectName sync-eve
subjectType USER

Synchronize (upsert) the subject via PUT

HTTP PUT "/api/rbac/subjects/238a0004-0000-0000-0000-000000000004" \
  -H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
  `# {` \
  `#   "comment" : "an authenticated user without the global-admin role",` \
  `#   "sub" : "uuid<tst-customer_admin_xxx>"` \
  `# }` \
  -H 'Content-Type: application/json' \
  --data-binary @- <<EOF
{
  "name" : "sync-eve",
  "type" : "USER"
}
EOF
=> status: 403 FORBIDDEN 
{
  "timestamp" : "2026-07-17 01:44:28",
  "path" : "",
  "statusCode" : 403,
  "statusPhrase" : "Forbidden",
  "message" : "ERROR: [403] only a global-admin may upsert subjects"
}

generated on 2026-07-17 01:44:28 for branch