diff --git a/devfront/src/features/clients/ClientGeneralPage.claims.test.tsx b/devfront/src/features/clients/ClientGeneralPage.claims.test.tsx index 726bfe06..b0d02820 100644 --- a/devfront/src/features/clients/ClientGeneralPage.claims.test.tsx +++ b/devfront/src/features/clients/ClientGeneralPage.claims.test.tsx @@ -450,6 +450,46 @@ describe("ClientGeneralPage RP claims", () => { expect(scopeInputs.some((input) => input.value === "old_claim")).toBe(true); }); + it("shows the offline_access guide in the scopes section and expands its details", async () => { + const { container } = await renderPage(); + + expect(container.textContent).toContain( + "Refresh token 사용 시 offline_access scope가 필요합니다.", + ); + expect(container.textContent).toContain( + "scope 목록에 offline_access를 포함하고", + ); + + const guideToggleButton = Array.from( + container.querySelectorAll("button"), + ).find((button) => + (button.getAttribute("aria-label") ?? "").includes( + "offline_access 상세 안내 보기", + ), + ); + expect(guideToggleButton).toBeDefined(); + + await act(async () => { + guideToggleButton?.dispatchEvent( + new MouseEvent("click", { bubbles: true }), + ); + }); + await flush(); + + expect(container.textContent).toContain( + "Hydra 기준으로 refresh token 발급 조건", + ); + expect(container.textContent).toContain( + "authorization request scope에 offline 또는 offline_access 포함", + ); + expect(container.textContent).toContain( + "consent accept의 granted_scope에 offline 또는 offline_access 포함", + ); + expect(container.textContent).toContain( + "client grant_types에 refresh_token 포함", + ); + }); + it("blocks saving a number RP claim default value that is not numeric", async () => { const { container } = await renderPage(); diff --git a/devfront/src/features/clients/ClientGeneralPage.tsx b/devfront/src/features/clients/ClientGeneralPage.tsx index c68afeec..ca917138 100644 --- a/devfront/src/features/clients/ClientGeneralPage.tsx +++ b/devfront/src/features/clients/ClientGeneralPage.tsx @@ -639,6 +639,8 @@ function ClientGeneralPage() { const [headlessLoginEnabled, setHeadlessLoginEnabled] = useState(false); const [isScopePickerOpen, setIsScopePickerOpen] = useState(false); + const [isOfflineAccessGuideOpen, setIsOfflineAccessGuideOpen] = + useState(false); const [scopes, setScopes] = useState(() => [ { id: "1", @@ -1970,6 +1972,77 @@ function ClientGeneralPage() { +
+
+
+
+ + + {t( + "ui.dev.clients.general.scopes.offline_access_title", + "Refresh token 사용 시 offline_access scope가 필요합니다.", + )} + +
+

+ {t( + "msg.dev.clients.general.scopes.offline_access_summary", + "RP가 refresh token을 사용하려면 scope 목록에 offline_access를 포함하고, consent와 grant type 설정도 함께 맞아야 합니다.", + )} +

+
+ +
+ {isOfflineAccessGuideOpen ? ( +
+

+ {t( + "msg.dev.clients.general.scopes.offline_access_conditions_title", + "Hydra 기준으로 refresh token 발급 조건", + )} +

+
    +
  • + {t( + "msg.dev.clients.general.scopes.offline_access_condition_request", + "authorization request scope에 offline 또는 offline_access 포함", + )} +
  • +
  • + {t( + "msg.dev.clients.general.scopes.offline_access_condition_consent", + "consent accept의 granted_scope에 offline 또는 offline_access 포함", + )} +
  • +
  • + {t( + "msg.dev.clients.general.scopes.offline_access_condition_grant_type", + "client grant_types에 refresh_token 포함", + )} +
  • +
+
+ ) : null} +
+ {isScopePickerOpen && (
diff --git a/devfront/src/locales/en.toml b/devfront/src/locales/en.toml index 4f2b0c60..8636a13d 100644 --- a/devfront/src/locales/en.toml +++ b/devfront/src/locales/en.toml @@ -452,6 +452,11 @@ session_required_off = "Off: process logout using sub even if sid is missing." empty = "No scopes registered." subtitle = "Define the permission scopes this application can request." tenant = "Tenant access claim" +offline_access_summary = "If the RP needs refresh tokens, include offline_access in the scope list and align the consent and grant type settings as well." +offline_access_conditions_title = "Hydra conditions for issuing refresh tokens" +offline_access_condition_request = "Include offline or offline_access in the authorization request scope." +offline_access_condition_consent = "Include offline or offline_access in the consent accept granted_scope." +offline_access_condition_grant_type = "Include refresh_token in the client grant_types." [msg.dev.clients.general.id_token_claims] subtitle = "Manage RP-specific extension claims separately." @@ -1590,6 +1595,8 @@ add = "Scope Add" description_placeholder = "Description Placeholder" name_placeholder = "e.g. profile" title = "Scopes" +offline_access_title = "offline_access scope is required when using refresh tokens." +offline_access_toggle = "Show offline_access help" [ui.dev.clients.general.scopes.table] description = "Scope Description" diff --git a/devfront/src/locales/ko.toml b/devfront/src/locales/ko.toml index bc5638ca..0b65dd9f 100644 --- a/devfront/src/locales/ko.toml +++ b/devfront/src/locales/ko.toml @@ -452,6 +452,11 @@ session_required_off = "끄면: sid가 없어도 sub만으로 로그아웃 처 empty = "등록된 스코프가 없습니다." subtitle = "이 앱이 요청할 수 있는 권한 범위를 정의합니다." tenant = "소속 테넌트 정보 접근" +offline_access_summary = "RP가 refresh token을 사용하려면 scope 목록에 offline_access를 포함하고, consent와 grant type 설정도 함께 맞아야 합니다." +offline_access_conditions_title = "Hydra 기준으로 refresh token 발급 조건" +offline_access_condition_request = "authorization request scope에 offline 또는 offline_access 포함" +offline_access_condition_consent = "consent accept의 granted_scope에 offline 또는 offline_access 포함" +offline_access_condition_grant_type = "client grant_types에 refresh_token 포함" [msg.dev.clients.general.id_token_claims] subtitle = "RP 전용 확장 claim을 구분해서 관리합니다." @@ -1589,6 +1594,8 @@ add = "스코프 추가" description_placeholder = "권한에 대한 설명" name_placeholder = "e.g. profile" title = "스코프" +offline_access_title = "Refresh token 사용 시 offline_access scope가 필요합니다." +offline_access_toggle = "offline_access 상세 안내 보기" [ui.dev.clients.general.scopes.table] description = "설명" diff --git a/devfront/src/locales/template.toml b/devfront/src/locales/template.toml index bb8af261..1a84e467 100644 --- a/devfront/src/locales/template.toml +++ b/devfront/src/locales/template.toml @@ -499,6 +499,11 @@ session_required_off = "" empty = "" subtitle = "" tenant = "" +offline_access_summary = "" +offline_access_conditions_title = "" +offline_access_condition_request = "" +offline_access_condition_consent = "" +offline_access_condition_grant_type = "" [msg.dev.clients.general.security] private_help = "" @@ -1638,6 +1643,8 @@ add = "" description_placeholder = "" name_placeholder = "" title = "" +offline_access_title = "" +offline_access_toggle = "" [ui.dev.clients.general.scopes.table] description = ""