Issue #3624171 by daniel.pernold: Saving a user wipes the Keycloak attributes that aren't mapped

updateUser() sent a user representation whose attributes array was built from the configured field mappings alone. Keycloak takes that array as the complete set, so every attribute this module does not map was dropped from the account the first time Drupal saved that user.

Read the attributes the account already carries and merge them underneath the mapped ones, so a mapped value still wins and everything else survives. The user lookup updateUser() already performs returns them, so this normally costs no extra request; when they are missing from that response, the user is fetched once. When they cannot be read at all, the update is skipped and logged rather than sent, because sending it would delete them.

Closes #3624171

Merge request reports

Loading
Loading