Groups keyboard shortcuts have been updated
Dismiss
See shortcuts

compatible keycloak version for cbioportal version 6.0.24

79 views
Skip to first unread message

Harika Gannu

unread,
Mar 26, 2025, 10:04:13 AMMar 26
to cBioPortal for Cancer Genomics Discussion Group

Hi,

I would like to confirm the compatible Keycloak version for cBioPortal version 6.0.24.

Based on the documentation and related issues:

It appears that cBioPortal does not yet support Keycloak v21. A separate ticket has been filed to enable support for v22. The suggested workaround is to use an older Keycloak version for compatibility:

"I don't think cBioPortal works with Keycloak v21 yet unfortunately. I filed a separate ticket for enabling v22 support: cBioPortal/cbioportal#10360. Is it possible for you to use an older version of Keycloak for now? Thanks!"

Could you confirm which Keycloak version is officially supported for cBioPortal 6.0.24?

Thank you,

Harika

Pieter Lukasse

unread,
Mar 31, 2025, 5:54:22 AMMar 31
to Harika Gannu, cBioPortal for Cancer Genomics Discussion Group
Hi Harika,

Thank you for highlighting this issue. I checked the documentation today and could not find a consistent answer to your question. We will work on improving that part. 

The highest documented version I found was v16, here: https://github.com/cBioPortal/cbioportal/blame/98f396cc25d46162e9c084ac62743c0d126cd521/docs/deployment/docker/using-keycloak.md#L40 , which is consistent with this PR https://github.com/cBioPortal/cbioportal-docker-compose/pull/25/files, but was recently overwritten (to v11?) by   https://github.com/cBioPortal/cbioportal-docker-compose/pull/41/files . I'm investigating why this happened (likely a mistake). For now, please assume v16.

Best,



--
You received this message because you are subscribed to the Google Groups "cBioPortal for Cancer Genomics Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cbioportal+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cbioportal/5393cccf-6604-4344-a59a-06ea3892a28dn%40googlegroups.com.

Zain-ul-Abideen Nasir

unread,
Apr 2, 2025, 9:39:29 AMApr 2
to cBioPortal for Cancer Genomics Discussion Group
Hi Pieter and Harika,
Yes, this downgrade from v16 to v11 was done by mistake. This will be fixed soon and the documentation will be updated.

Thanks,
Zain.

de Bruijn, Ino

unread,
Apr 2, 2025, 9:42:58 AMApr 2
to cBioPortal for Cancer Genomics Discussion Group, ghari...@gmail.com, pie...@se4.bio, Zain-ul-Abideen Nasir

Looping Harika back in

 

From: 'Zain-ul-Abideen Nasir' via cBioPortal for Cancer Genomics Discussion Group <cbiop...@googlegroups.com>
Date: Wednesday, April 2, 2025 at 9:39 AM
To: cBioPortal for Cancer Genomics Discussion Group <cbiop...@googlegroups.com>
Subject: [EXTERNAL] Re: [cbioportal] compatible keycloak version for cbioportal version 6.0.24

Hi Pieter and Harika, Yes, this downgrade from v16 to v11 was done by mistake. This will be fixed soon and the documentation will be updated. Thanks, Zain. On Monday, March 31, 2025 at 5: 54: 22 AM UTC-4 Pieter Lukasse wrote: Hi Harika, Thank

Hi Pieter and Harika,

Yes, this downgrade from v16 to v11 was done by mistake. This will be fixed soon and the documentation will be updated.

 

Thanks,

Zain.

On Monday, March 31, 2025 at 5:54:22 AM UTC-4 Pieter Lukasse wrote:

Hi Harika,

 

Thank you for highlighting this issue. I checked the documentation today and could not find a consistent answer to your question. We will work on improving that part. 

The highest documented version I found was v16, here: https://github.com/cBioPortal/cbioportal/blame/98f396cc25d46162e9c084ac62743c0d126cd521/docs/deployment/docker/using-keycloak.md#L40 , which is consistent with this PR https://github.com/cBioPortal/cbioportal-docker-compose/pull/25/files
, but was recently overwritten (to v11?) by   https://github.com/cBioPortal/cbioportal-docker-compose/pull/41/files . I'm investigating why this happened (likely a mistake). For now, please assume v16.



Best,



Pieter


Image removed by sender.



 

On Wed, Mar 26, 2025 at 3:04 PM Harika Gannu <ghari...@gmail.com> wrote:

Hi,

I would like to confirm the compatible Keycloak version for cBioPortal version 6.0.24.

Based on the documentation and related issues:

It appears that cBioPortal does not yet support Keycloak v21. A separate ticket has been filed to enable support for v22. The suggested workaround is to use an older Keycloak version for compatibility:

"I don't think cBioPortal works with Keycloak v21 yet unfortunately. I filed a separate ticket for enabling v22 support: cBioPortal/cbioportal#10360. Is it possible for you to use an older version of Keycloak for now? Thanks!"

Could you confirm which Keycloak version is officially supported for cBioPortal 6.0.24?

Thank you,

Harika

--
You received this message because you are subscribed to the Google Groups "cBioPortal for Cancer Genomics Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cbioportal+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/cbioportal/5393cccf-6604-4344-a59a-06ea3892a28dn%40googlegroups.com.

--
You received this message because you are subscribed to the Google Groups "cBioPortal for Cancer Genomics Discussion Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cbioportal+...@googlegroups.com.

=====================================================================

Please note that this e-mail and any files transmitted from
Memorial Sloan Kettering Cancer Center may be privileged, confidential,
and protected from disclosure under applicable law. If the reader of
this message is not the intended recipient, or an employee or agent
responsible for delivering this message to the intended recipient,
you are hereby notified that any reading, dissemination, distribution,
copying, or other use of this communication or any of its attachments
is strictly prohibited. If you have received this communication in
error, please notify the sender immediately by replying to this message
and deleting this message, any attachments, and all copies and backups
from your computer.

Disclaimer ID:MSKCC

Zain-ul-Abideen Nasir

unread,
Apr 3, 2025, 10:57:16 AMApr 3
to de Bruijn, Ino, cBioPortal for Cancer Genomics Discussion Group, ghari...@gmail.com, pie...@se4.bio
Hi Harika,
cBioPortal Docker Compose setup has been updated to use Keycloak v16 (https://github.com/cBioPortal/cbioportal-docker-compose/pull/54).

Please reach out if you have any questions or run into any issues.

Best,
Zain Nasir
Software Engineer | Memorial Sloan Kettering
M.S. Computer Science | Binghamton University


niels bohr

unread,
May 13, 2025, 4:10:25 AM (9 days ago) May 13
to cBioPortal for Cancer Genomics Discussion Group
Due to security concerns regarding keycloak 18.0.2,
but also Unprotected LDAP Credential Transmission and other vulnerabilties, we are pressured by our security officers to move to a newer keycloak version.
However cBioPortal has become a center piece of our research pipeline.. I am getting a bit desperate..

de Bruijn, Ino

unread,
May 13, 2025, 2:36:39 PM (8 days ago) May 13
to niels bohr, cBioPortal for Cancer Genomics Discussion Group, ghari...@gmail.com

Hi Niels,

 

Thanks for checking in – replied here:

 

https://github.com/cBioPortal/cbioportal/issues/10360#issuecomment-2877556887

 

We’re definitely interested in upgrading, just haven’t found the time yet. If you feel like giving it a try, please go for it. Happy to help address issues you might run into

 

We did see one user who tried v21  (Icebox Issue #572), but not sure if that issue was specific to their setup or for all keycloak v21 configurations

 

Thanks!

Ino

 

From: cbiop...@googlegroups.com <cbiop...@googlegroups.com> on behalf of niels bohr <niels...@gmail.com>
Date: Tuesday, May 13, 2025 at 4:10

AM


To: cBioPortal for Cancer Genomics Discussion Group <cbiop...@googlegroups.com>

Subject: [EXTERNAL] Re: [External Email] Re: [cbioportal] compatible keycloak version for cbioportal version 6.0.24

Due to security concerns regarding keycloak 18.0.2, e.g.: https://www.cvedetails.com/vulnerability-list/vendor_id-25/product_id-46161/version_id-1391639/year-2023/opbyp-1/Redhat-Keycloak-18.0.2.html but also Unprotected LDAP Credential Transmission

Looping Harika back in

 

Hi Harika,

 

Pieter

Error! Filename not specified.

 

Reply all
Reply to author
Forward
0 new messages